Secured Packet Provisioning via NEF Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP procedures for secure packet retrieval in wireless communications expose user privacy and do not allow service-specific credential provisioning, as they rely on exposing the Subscriber Permanent Identity (SUPI) and lack service-specific information for provisioning across multiple service types.

Innovation Solution

The proposed solution enhances secure packet retrieval by using privacy-protected UE identifiers and introducing new service operation messages (e.g., Nnef_Provisioning_Data) to request and receive credentials/configuration parameters from external or third-party SP-AFs via NEFs, ensuring UE privacy and supporting service-specific provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the current 3GPP procedure uses SUPI for secure packet retrieval, then the credential provisioning can be established, but user privacy is exposed

Engineering Contradiction:
Improvecredential provisioningVSAvoiduser privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a NEF (Network Exposure Function) as an intermediary between the consumer NF and SP-AF. The NEF receives the request from consumer NF, forwards it to SP-AF, and receives the secured packet back, thereby mediating the communication and enabling credential provisioning without directly exposing SUPI to external systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the identifier parameter from SUPI (Subscriber Permanent Identity) to GPSI (Generic Public Subscription Identity) in the request message sent to SP-AF. This parameter change allows the system to maintain credential provisioning capability while using a less sensitive identifier that does not directly expose user privacy information.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the current 3GPP procedure is used, then the basic credential retrieval is possible, but service-specific credential provisioning is not supported

Engineering Contradiction:
Improveservice-specific provisioningVSAvoidprocedure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the credential retrieval procedure into distinct components: a request message containing service descriptor, a secured packet containing credentials, and separate handling for different service types. This segmentation enables service-specific provisioning by allowing the service descriptor to identify the specific service while maintaining a standardized overall procedure structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal procedure that can handle multiple service types through the service descriptor parameter. The same basic request-response mechanism between consumer NF and SP-AF can serve different services (e.g., voice, data, messaging) by simply changing the service descriptor, thereby achieving multi-functionality without requiring separate procedures for each service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If SUPI is exposed for credential retrieval, then the authentication can be performed, but sensitive information is disclosed

Engineering Contradiction:
ImproveauthenticationVSAvoidsensitive information disclosure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the sensitive SUPI identifier from the communication between consumer NF and SP-AF. By using GPSI instead of SUPI in the request message and by having the SP-AF generate credentials based on the service descriptor rather than directly using the extracted SUPI, the system maintains authentication capability while removing the sensitive information from the transmission path.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a copy of the identifier (GPSI) that serves the functional purpose of SUPI in the authentication process but without the privacy risks. The GPSI acts as a functional equivalent that allows the authentication mechanism to work while avoiding the disclosure of the actual sensitive SUPI information.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20240397322A1Provisioning a secured packet
Publication Date: 2024.11.28 LENOVO (SINGAPORE) PTE LTD
  • US20240397322A1 patent drawing
  • US20240397322A1 patent drawing
  • US20240397322A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for provisioning a Secured Packet. One method includes sending, to a Secured Packet Application Function, a request for a credential related to a device and a service descriptor and receiving, from the Secured Packet Application Function, a secured packet and credential information, the credential information including: a subscriber identity corresponding to the device, a lifetime for the Secured Packet, a network service identifier, a device storage requirement indication, or a combination thereof. The method includes storing the secured packet and the credential information and provisioning the secured packet to the device via an update procedure, where the secured packet including the valid credential.