SNPN UE Onboarding Through DCS-Based Credential Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G standards for standalone non-public networks (SNPNs) lack defined procedures for network selection, traffic routing, and security measures to prevent rogue UEs from accessing unauthorized networks, necessitating a method for provisioning UEs with credentials without pre-provisioning network information.

Innovation Solution

A Default Credential Server (DCS) maintains a binding of UE onboarding credentials with network information, allowing UEs to send an onboarding request to retrieve network information and initiate a provisioning procedure after verification, preventing unauthorized access by rogue UEs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If UEs are pre-provisioned with network information at manufacturing, then provisioning can be initiated immediately, but device complexity increases and firmware updates are required

Engineering Contradiction:
Improveprovisioning speedVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning UEs with a generic onboarding credential and a onboarding identifier during manufacturing, rather than specific network information. This allows the UE to immediately register with an onboarding network without requiring firmware updates, while the specific SNPN network information is retrieved dynamically later from the DCS during the onboarding process.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If UEs can access any NPN, then network accessibility is improved, but security deteriorates due to rogue UEs accessing unauthorized networks

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an onboarding network and a Default Credential Server (DCS) as intermediary components between the UE and the SNPN. The onboarding network acts as a trusted mediator that verifies the UE's onboarding identifier against the DCS, ensures the UE is authorized to access the specific SNPN, and routes traffic appropriately. This intermediary mechanism enables secure network selection and prevents rogue UEs from accessing unauthorized networks while maintaining ease of access for legitimate UEs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If network information is stored in UE firmware, then network selection is simplified, but adaptability deteriorates when network changes occur

Engineering Contradiction:
Improvenetwork selection simplicityVSAvoidnetwork adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by providing UEs with a generic onboarding credential and identifier during manufacturing, rather than specific network information. This keeps device complexity low while enabling adaptability, as the UE can register with any onboarding network and dynamically retrieve the appropriate SNPN network information from the DCS based on its onboarding identifier, allowing the system to adapt to different networks without firmware updates.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If authorization verification is implemented, then security is improved, but provisioning time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring the UE with an onboarding identifier during manufacturing and pre-populating the DCS with the mappings between onboarding identifiers and SNPN network information. During onboarding, the verification process is streamlined because the DCS can quickly look up the onboarding identifier and provide the authorized SNPN information without complex real-time verification, thus maintaining security while minimizing provisioning time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12389230B2Onboarding devices in standalone non-public networks
Publication Date: 2025.08.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12389230B2 patent drawing
  • US12389230B2 patent drawing
  • US12389230B2 patent drawing

AI summary

The present disclosure relates to supporting provisioning of a User Equipment (UE) with credentials to access a communication network, such as a Standalone Non-Public Network (SNPN). A credential server stores a binding associating UE device information, including an onboarding identifier, with network information for the SNPN. The credential server receives, from a network function in an onboarding network, a request for authentication of the UE that includes the onboarding identifier. The credential server responds with a message comprising the network information bound to the device information to enable provisioning of the credentials to the UE.