Subscriber Certificate Provisioning via Layer 2 Connection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional subscriber certificate provisioning techniques for user equipment (UE) in 3GPP and MulteFire networks require IP connectivity and service discovery, which can lead to unauthorized access and introduce additional network states, making them undesirable for secure and efficient provisioning.
Innovation Solution
A system and method that allows UE to request and receive subscriber certificates via a layer two connection without IP connectivity or service discovery, using an access point to route certificate requests to a Public Key Infrastructure (PKI) portal through an EAP authenticator, eliminating the need for preloaded certificates and IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional 3GPP provisioning techniques are used, then IP connectivity and service discovery are enabled, but unauthorized access and network security risks increase
Solution Approach 1:
The patent applies preliminary action by establishing a Layer 2 connection and obtaining IP connectivity AFTER the certificate provisioning process is complete. The UE first establishes a Layer 2 connection with the EAP authenticator, then receives the certificate through this connection, and only afterward obtains IP connectivity. This reverses the conventional sequence where IP connectivity is required first, thereby preventing unauthorized access while enabling provisioning.
2Device complexity
If conventional MulteFire provisioning techniques are used, then service discovery and IP connectivity are established, but device complexity and network state management increase
Solution Approach 1:
The patent extracts and removes the requirement for service discovery from the provisioning process. Instead of requiring the UE to discover services and obtain IP connectivity before provisioning, the system uses a pre-established Layer 2 connection between the UE and EAP authenticator to deliver the certificate directly. This eliminates the service discovery step and reduces network state complexity while maintaining provisioning efficiency.
3Ease of operation
If UE is given IP connectivity before certificate provisioning, then network access is enabled, but unauthorized access and misuse risks increase
Solution Approach 1:
The patent applies preliminary action by completing certificate provisioning BEFORE granting IP connectivity. The sequence is: (1) UE establishes Layer 2 connection, (2) UE receives certificate through EAP authentication, (3) UE then obtains IP connectivity. This ensures the UE is properly authenticated and certified before gaining network access, preventing unauthorized access while enabling smooth network entry.
Data Source
AI summary
A system for provisioning a device is provided. The system includes a computer device. The computer device is programmed to receive, from a user equipment, a connection request via a layer two connection. The computer device is also programmed to accept the connection request. The computer device is further programmed to receive, from the user equipment, a certificate request via the layer two connection. Additionally, the computer device is programmed to determine a destination for the certificate request, and to route the certificate request to the destination.

