SNPN UE Onboarding Through DCS-Based Credential Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G standards for standalone non-public networks (SNPNs) lack defined procedures for network selection, traffic routing, and security measures to prevent rogue UEs from accessing unauthorized networks, necessitating a method for provisioning UEs with credentials without pre-provisioning network information.
Innovation Solution
A Default Credential Server (DCS) maintains a binding of UE onboarding credentials with network information, allowing UEs to send an onboarding request to retrieve network information and initiate a provisioning procedure after verification, preventing unauthorized access by rogue UEs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If UEs are pre-provisioned with network information at manufacturing, then provisioning can be initiated immediately, but device complexity increases and firmware updates are required
Solution Approach 1:
The patent applies preliminary action by pre-provisioning UEs with a generic onboarding credential and a onboarding identifier during manufacturing, rather than specific network information. This allows the UE to immediately register with an onboarding network without requiring firmware updates, while the specific SNPN network information is retrieved dynamically later from the DCS during the onboarding process.
2Ease of operation
If UEs can access any NPN, then network accessibility is improved, but security deteriorates due to rogue UEs accessing unauthorized networks
Solution Approach 1:
The patent introduces an onboarding network and a Default Credential Server (DCS) as intermediary components between the UE and the SNPN. The onboarding network acts as a trusted mediator that verifies the UE's onboarding identifier against the DCS, ensures the UE is authorized to access the specific SNPN, and routes traffic appropriately. This intermediary mechanism enables secure network selection and prevents rogue UEs from accessing unauthorized networks while maintaining ease of access for legitimate UEs.
3Device complexity
If network information is stored in UE firmware, then network selection is simplified, but adaptability deteriorates when network changes occur
Solution Approach 1:
The patent applies preliminary action by providing UEs with a generic onboarding credential and identifier during manufacturing, rather than specific network information. This keeps device complexity low while enabling adaptability, as the UE can register with any onboarding network and dynamically retrieve the appropriate SNPN network information from the DCS based on its onboarding identifier, allowing the system to adapt to different networks without firmware updates.
4Reliability
If authorization verification is implemented, then security is improved, but provisioning time increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring the UE with an onboarding identifier during manufacturing and pre-populating the DCS with the mappings between onboarding identifiers and SNPN network information. During onboarding, the verification process is streamlined because the DCS can quickly look up the onboarding identifier and provide the authorized SNPN information without complex real-time verification, thus maintaining security while minimizing provisioning time.
Data Source
AI summary
The present disclosure relates to supporting provisioning of a User Equipment (UE) with credentials to access a communication network, such as a Standalone Non-Public Network (SNPN). A credential server stores a binding associating UE device information, including an onboarding identifier, with network information for the SNPN. The credential server receives, from a network function in an onboarding network, a request for authentication of the UE that includes the onboarding identifier. The credential server responds with a message comprising the network information bound to the device information to enable provisioning of the credentials to the UE.


