Subscriber Certificate Provisioning via Layer 2 Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional subscriber certificate provisioning techniques for user equipment (UE) in 3GPP and MulteFire networks require IP connectivity and service discovery, which can lead to unauthorized access and introduce additional network states, making them undesirable for secure and efficient provisioning.

Innovation Solution

A system and method that allows UE to request and receive subscriber certificates via a layer two connection without IP connectivity or service discovery, using an access point to route certificate requests to a Public Key Infrastructure (PKI) portal through an EAP authenticator, eliminating the need for preloaded certificates and IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional 3GPP provisioning techniques are used, then IP connectivity and service discovery are enabled, but unauthorized access and network security risks increase

Engineering Contradiction:
Improvenetwork securityVSAvoidprovisioning process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by establishing a Layer 2 connection and obtaining IP connectivity AFTER the certificate provisioning process is complete. The UE first establishes a Layer 2 connection with the EAP authenticator, then receives the certificate through this connection, and only afterward obtains IP connectivity. This reverses the conventional sequence where IP connectivity is required first, thereby preventing unauthorized access while enabling provisioning.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If conventional MulteFire provisioning techniques are used, then service discovery and IP connectivity are established, but device complexity and network state management increase

Engineering Contradiction:
Improvenetwork stateVSAvoidprovisioning efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent extracts and removes the requirement for service discovery from the provisioning process. Instead of requiring the UE to discover services and obtain IP connectivity before provisioning, the system uses a pre-established Layer 2 connection between the UE and EAP authenticator to deliver the certificate directly. This eliminates the service discovery step and reduces network state complexity while maintaining provisioning efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If UE is given IP connectivity before certificate provisioning, then network access is enabled, but unauthorized access and misuse risks increase

Engineering Contradiction:
Improvenetwork accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by completing certificate provisioning BEFORE granting IP connectivity. The sequence is: (1) UE establishes Layer 2 connection, (2) UE receives certificate through EAP authentication, (3) UE then obtains IP connectivity. This ensures the UE is properly authenticated and certified before gaining network access, preventing unauthorized access while enabling smooth network entry.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12052568B2Systems and methods for subscriber certificate provisioning
Publication Date: 2024.07.30 CABLE TELEVISION LAB INC
  • US12052568B2 patent drawing
  • US12052568B2 patent drawing

AI summary

A system for provisioning a device is provided. The system includes a computer device. The computer device is programmed to receive, from a user equipment, a connection request via a layer two connection. The computer device is also programmed to accept the connection request. The computer device is further programmed to receive, from the user equipment, a certificate request via the layer two connection. Additionally, the computer device is programmed to determine a destination for the certificate request, and to route the certificate request to the destination.