Secured Packet Provisioning via NEF Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP procedures for secure packet retrieval in wireless communications expose user privacy and do not allow service-specific credential provisioning, as they rely on exposing the Subscriber Permanent Identity (SUPI) and lack service-specific information for provisioning across multiple service types.
Innovation Solution
The proposed solution enhances secure packet retrieval by using privacy-protected UE identifiers and introducing new service operation messages (e.g., Nnef_Provisioning_Data) to request and receive credentials/configuration parameters from external or third-party SP-AFs via NEFs, ensuring UE privacy and supporting service-specific provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the current 3GPP procedure uses SUPI for secure packet retrieval, then the credential provisioning can be established, but user privacy is exposed
Solution Approach 1:
The patent introduces a NEF (Network Exposure Function) as an intermediary between the consumer NF and SP-AF. The NEF receives the request from consumer NF, forwards it to SP-AF, and receives the secured packet back, thereby mediating the communication and enabling credential provisioning without directly exposing SUPI to external systems.
Solution Approach 2:
The patent changes the identifier parameter from SUPI (Subscriber Permanent Identity) to GPSI (Generic Public Subscription Identity) in the request message sent to SP-AF. This parameter change allows the system to maintain credential provisioning capability while using a less sensitive identifier that does not directly expose user privacy information.
2Adaptability or versatility
If the current 3GPP procedure is used, then the basic credential retrieval is possible, but service-specific credential provisioning is not supported
Solution Approach 1:
The patent segments the credential retrieval procedure into distinct components: a request message containing service descriptor, a secured packet containing credentials, and separate handling for different service types. This segmentation enables service-specific provisioning by allowing the service descriptor to identify the specific service while maintaining a standardized overall procedure structure.
Solution Approach 2:
The patent creates a universal procedure that can handle multiple service types through the service descriptor parameter. The same basic request-response mechanism between consumer NF and SP-AF can serve different services (e.g., voice, data, messaging) by simply changing the service descriptor, thereby achieving multi-functionality without requiring separate procedures for each service.
3Reliability
If SUPI is exposed for credential retrieval, then the authentication can be performed, but sensitive information is disclosed
Solution Approach 1:
The patent extracts the sensitive SUPI identifier from the communication between consumer NF and SP-AF. By using GPSI instead of SUPI in the request message and by having the SP-AF generate credentials based on the service descriptor rather than directly using the extracted SUPI, the system maintains authentication capability while removing the sensitive information from the transmission path.
Solution Approach 2:
The patent creates a copy of the identifier (GPSI) that serves the functional purpose of SUPI in the authentication process but without the privacy risks. The GPSI acts as a functional equivalent that allows the authentication mechanism to work while avoiding the disclosure of the actual sensitive SUPI information.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for provisioning a Secured Packet. One method includes sending, to a Secured Packet Application Function, a request for a credential related to a device and a service descriptor and receiving, from the Secured Packet Application Function, a secured packet and credential information, the credential information including: a subscriber identity corresponding to the device, a lifetime for the Secured Packet, a network service identifier, a device storage requirement indication, or a combination thereof. The method includes storing the secured packet and the credential information and provisioning the secured packet to the device via an update procedure, where the secured packet including the valid credential.


