Credential Generation for 5G Non-Public Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased isolation of 5G Non-Public Networks (NPNs) from Public Land Mobile Networks (PLMNs) complicates the authentication and registration of User Equipment (UEs) across both network types, requiring manual credential generation and provisioning, which is inefficient and labor-intensive.

Innovation Solution

The system automatically generates temporary and permanent credentials for UEs using existing UE credentials, allowing for seamless authentication and registration across PLMNs and NPNs, with the Mobile Network Operator (MNO) offloading authentication processes to NPNs, leveraging components like the Authentication Server Function (AUSF) and Default Credentials Server (DCS) for credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 5G Non-Public Networks are isolated from Public Land Mobile Networks, then network security and performance are improved, but authentication and registration complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the MNO network acts as a trusted mediator that facilitates credential generation and provisioning between the isolated NPN and UE. The system uses a credential repository and automated credential generation process that mediates the authentication interaction, allowing isolated networks to maintain security while simplifying the authentication process through centralized credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual credential generation and provisioning is used, then network isolation is maintained, but operational efficiency deteriorates

Engineering Contradiction:
Improvenetwork isolationVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-generating and storing credentials in a credential repository before they are needed for authentication. The system provisions credentials in advance through automated processes, so that when a UE needs to access an isolated NPN, the authentication can proceed efficiently without manual intervention. This preliminary credential preparation maintains network isolation while dramatically improving operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service through automated credential generation and provisioning processes. The credential repository and authentication server automatically generate credentials for UEs without requiring manual administrator intervention. The system serves itself by automating the credential management lifecycle, including generation, storage, and distribution, thereby maintaining security isolation while eliminating labor-intensive manual processes.

Inventive Principle:
Principle #25Self-service

3Productivity

If automated credential generation is implemented, then operational efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: a credential repository for storing credentials, an authentication server for generating and verifying credentials, and a credential management module for coordinating between them. This segmentation allows automated credential generation to proceed efficiently while distributing system complexity across separate, manageable modules rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11979743B2Systems and methods for secure access to 5G non-public networks using mobile network operator credentials
Publication Date: 2024.05.07 VERIZON PATENT & LICENSING INC
  • US11979743B2 patent drawing
  • US11979743B2 patent drawing
  • US11979743B2 patent drawing

AI summary

One or more devices may include a credentials server. The credentials server may be configured to: receive primary Standalone Non-Public Network (SNPN) credentials for a User Equipment device (UE) and SNPN information. The primary SNPN credentials and the SNPN information are associated with the UE and an SNPN. The devices may be configured to generate temporary SNPN credentials based on the primary SNPN credentials and the SNPNN information. The devices may forward the temporary SNPN credentials to the SNPN.