Concealed Identifier Onboarding for Cellular Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cellular communication networks face challenges in enabling unauthenticated access for devices during the onboarding process, particularly in scenarios where a subscriber profile is not available.

Innovation Solution

The implementation of a concealed identifier, such as a Subscriber Concealed Identity (SUCI), by user equipment (UE) to request unauthenticated access to the onboarding network, coupled with the execution of a key generating authentication protocol that does not require UE authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If unauthenticated access is enabled for onboarding devices, then network accessibility is improved, but security control deteriorates

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication process into two distinct phases: initial unauthenticated access for onboarding, and subsequent authenticated access for full service. This allows devices to join the network without prior credentials while ensuring security controls are applied after onboarding completes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by establishing unauthenticated access rights temporarily during onboarding, then immediately follows with authentication to establish permanent secure access. The unauthenticated phase is a preliminary step that is superseded by authenticated access

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication is required for network access, then security is improved, but ease of onboarding deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of onboarding
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent inverts the conventional authentication sequence by allowing access before authentication. Instead of requiring credentials to gain access, the system grants temporary unauthenticated access and then performs authentication, effectively reversing the traditional security model for onboarding scenarios

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If subscriber profile is required for access, then service control is improved, but device onboarding capability deteriorates

Engineering Contradiction:
Improveservice controlVSAvoiddevice onboarding capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by establishing unauthenticated access rights and temporary service permissions before the subscriber profile is fully provisioned. The profile creation and authentication occur after initial access is granted, allowing devices to onboard without pre-existing profiles

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic access control where service permissions evolve from unauthenticated to authenticated state. The system adaptively adjusts security levels and service controls based on the device's onboarding status, transitioning from permissive initial access to restricted authenticated access

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12212961B2Enhanced onboarding in cellular communication networks
Publication Date: 2025.01.28 NOKIA TECHNOLOGIES OY
  • US12212961B2 patent drawing
  • US12212961B2 patent drawing
  • US12212961B2 patent drawing

AI summary

According to an example aspect of the present invention, there is provided an apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus at least to transmit, by a user equipment, a concealed identifier of the user equipment to an onboarding network, wherein the concealed identifier of the user equipment indicates that the user equipment is requesting unauthenticated access to the onboarding network and execute, by the user equipment, a key generating authentication protocol to access the onboarding network without performing authentication of the user equipment.