Restricted Access Registration with Onboarding Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in LTE and NR technologies, face challenges in providing efficient restricted access procedures, as existing methods like PaRLOS do not permit authenticated access and result in excessive delays and limitations for MTC, D2D, and V2X UEs.
Innovation Solution
The proposed solution involves a UE transmitting a registration request for restricted access that includes an onboarding access request, enabling selective communication with the network for authentication and authorization, and completing the registration based on this communication, using network slice-specific authentication and authorization procedures to allow both unauthenticated and authenticated access, thereby improving flexibility and reducing delays.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PaRLOS procedure is used for restricted access, then access control is provided, but authentication is not permitted and excessive delays occur
Solution Approach 1:
The patent introduces dynamic access levels (unauthenticated, onboarding with default credentials, onboarding with credentials) that allow the system to adapt its authentication requirements based on the UE's current state and network conditions. This dynamic approach enables faster access when authentication is not strictly necessary while maintaining security when needed.
Solution Approach 2:
The access procedure is segmented into distinct phases: unauthenticated access for immediate connectivity, onboarding with default credentials for temporary access, and onboarding with credentials for full authentication. This segmentation allows UEs to bypass lengthy authentication processes when only restricted access is needed, reducing delays while maintaining security boundaries.
2Reliability
If traditional PaRLOS procedure is used for restricted access, then access control is provided, but flexibility is limited for MTC, D2D, and V2X UEs
Solution Approach 1:
The patent creates a universal onboarding framework that serves multiple UE types (MTC, D2D, V2X) through a common set of procedures and access levels. The network can selectively apply different authentication requirements based on the specific needs of each UE type, providing both unified management and tailored flexibility.
Solution Approach 2:
The system changes key parameters such as authentication requirements, credential types, and access permissions based on the UE's service type and network conditions. This allows the same basic procedure to adapt to different scenarios, providing flexibility for MTC devices, D2D communications, and V2X applications while maintaining controlled access.
3Reliability
If network slice-specific authentication and authorization procedures are implemented, then authenticated access is enabled, but system complexity increases
Solution Approach 1:
The patent implements preliminary onboarding procedures where UEs receive default credentials or onboarding information before full authentication is required. This preliminary action establishes a trusted baseline that simplifies subsequent authentication processes, as the UE and network already have established communication channels and basic trust relationships.
Solution Approach 2:
The network introduces intermediary elements such as onboarding servers and credential distribution mechanisms that mediate between the UE and core authentication systems. These intermediaries handle complex authentication logic and credential management, shielding UEs from direct interaction with complex authentication protocols while still enabling secure authenticated access.
Data Source
AI summary
Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may transmit a registration request for restricted access (RA), wherein the registration request selectively includes an onboarding access request. The UE may selectively communicate with an onboarding network to authenticate and authorize a particular network based at least in part on whether the registration request includes the onboarding access request. The UE may complete the RA registration after transmitting the registration request and based at least in part on selectively communicating with the onboarding network to authenticate and authorize the particular network. Numerous other aspects are described.


