Shared RAN Onboarding for Network Slice Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G networks face challenges in efficiently onboarding and authenticating user equipment for network slices, particularly in Non-Public Networks (NPNs), due to the lack of standardized procedures for transmitting and receiving onboarding and authentication information between user equipment and network functions.

Innovation Solution

The method involves broadcasting onboarding support information and authentication requirements via radio access networks and access and mobility management functions to user equipment, allowing for the registration and connection establishment with selected network slices, including the transmission of network slice-specific credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If standardized procedures for transmitting onboarding and authentication information are implemented, then network access efficiency is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork access efficiencyVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the onboarding and authentication information into distinct standardized message formats (e.g., System Information Blocks, RRC messages) that can be independently processed. This segmentation allows user equipment to handle complex authentication procedures through modular message exchanges, improving network access efficiency while managing device complexity through structured information organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universal standardized procedures that can be applied across multiple network types (PLMN, SNPN, PNI-NPN) and authentication scenarios. These multi-functional procedures enable user equipment to handle diverse onboarding and authentication requirements using a unified framework, improving overall network access efficiency without proportionally increasing device complexity through reuse of common processing logic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If onboarding procedures are carried out for all user equipment accessing NPNs, then network security is improved, but loss of time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by broadcasting onboarding support information and authentication requirements before actual user equipment access attempts. Network functions pre-configure and transmit authentication parameters, credential requirements, and onboarding procedures in advance (e.g., through system information broadcasts), so that user equipment can prepare appropriate authentication credentials beforehand, reducing onboarding time while maintaining security through pre-established authentication frameworks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables user equipment to autonomously perform onboarding and authentication procedures by providing self-service capabilities. User equipment can independently retrieve broadcasted authentication requirements, select appropriate network slices, and execute credential verification without manual intervention. This self-service approach maintains network security through standardized authentication while significantly reducing the time loss associated with manual onboarding processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If network slice-specific credentials are transmitted during registration, then authentication reliability is improved, but loss of information increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidloss of information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by transmitting network slice-specific credentials and authentication information targeted to particular network slices rather than universally. Each network slice receives only the credentials and parameters relevant to its specific authentication requirements, minimizing unnecessary information transmission. This targeted approach improves authentication reliability for each slice while reducing overall information loss by avoiding redundant credential distribution across all slices.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12532254B2Methods, apparatuses, and computer program products for supporting onboarding and authentication of user equipment for networks and network slices
Publication Date: 2026.01.20 NOKIA TECHNOLOGIES OY
  • US12532254B2 patent drawing
  • US12532254B2 patent drawing
  • US12532254B2 patent drawing

AI summary

Methods, apparatuses, and computer program products are described that support transmission and receipt of onboarding support and/or authentication requirement information to a UE for registration with a network, such as a PLMN and/or SNPN, and/or network slice, via a RAN and/or the like. The onboarding support and/or authentication requirement information may be specifically configured for one or more networks, and/or network slices thereof, that utilize a shared RAN in communication with the UE. The UE selects a cell and network and/or network slice based on the onboarding support and/or authentication requirement information. The UE may camp on the shared RAN. The one or more networks comprise at least a RAN and respective AMF that provide the onboarding support and/or authentication requirement information to the UE before, or when, the UE contacts the AMF associated with the network and/or network slice.