Control Plane Remote Provisioning for 5G UE Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G mobile communication systems face challenges in efficiently managing user equipment (UE) onboarding for standard non-public network (SNPN) credentials and user subscription data, particularly in providing secure and efficient control plane-based remote provisioning.
Innovation Solution
A method and device for network registration that performs control plane-based remote provisioning, enabling UE to receive SNPN credentials and user subscription data during onboarding by utilizing a series of network functions such as the Access and Mobility Management Function (AMF), Authentication Server Function (AUSF), and Provisioning Server (PVS), which communicate to authenticate and authorize the UE and provide necessary credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If control plane-based remote provisioning is implemented for UE onboarding, then security and efficiency of credential distribution is improved, but device complexity and network configuration complexity increases
Solution Approach 1:
The patent segments the onboarding process into distinct phases: initial network access, authentication, credential provisioning, and service activation. By dividing the complex remote provisioning process into manageable segments handled by different network functions (AMF, AUSF, PVS), the system achieves high security while maintaining operational clarity and reducing overall complexity.
Solution Approach 2:
The patent introduces intermediary network functions (AMF as access and mobility management function, AUSF as authentication server function, and PVS as provisioning server) that mediate between the UE and the credential distribution system. These intermediaries handle security-sensitive operations, allowing the system to maintain high security standards while simplifying the interface between devices and the provisioning infrastructure.
2Reliability
If multiple network functions (AMF, AUSF, PVS) are involved in the onboarding process, then authentication and authorization security is improved, but processing time and network overhead increases
Solution Approach 1:
The patent merges the authentication and credential provisioning operations into a unified control plane procedure. By combining these functions and allowing them to operate in an integrated manner with parallel processing capabilities, the system maintains strong authentication security while reducing the cumulative time impact of multiple separate operations.
Solution Approach 2:
The patent performs preliminary authentication and authorization checks before initiating the full credential provisioning process. The AMF and AUSF conduct initial security verification in advance, which allows the subsequent PVS credential distribution to proceed more efficiently, thereby reducing total onboarding time while maintaining security standards.
3Reliability
If control plane-based provisioning is used instead of user plane, then security of NAS messaging is improved, but flexibility in provisioning methods is reduced
Solution Approach 1:
The patent implements a universal control plane-based provisioning framework that can handle multiple credential types (subscription credentials, service credentials, device credentials) and multiple provisioning scenarios through a single standardized interface. This multi-functional approach maintains the security advantages of control plane NAS messaging while providing the flexibility to support diverse provisioning requirements.
Data Source
AI summary
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. An operation method of an access and mobility management function (AMF) in a wireless communication network according to the disclosure includes: receiving, from a base station, a registration request message including a parameter indicating that a terminal supports control plane-based remote provisioning; determining the control plane-based remote provisioning, based on the parameter; and determining an authentication server function (AUSF) for onboarding of the terminal, based on the control plane-based remote provisioning.


