Network-Based UE Credential Provisioning Without HSS Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communications, non-operator entities face challenges in provisioning devices for network access when they lack access to a Home Subscriber Server (HSS) for verifying credentials, especially when using unlicensed spectrum for LTE/LTE-A communications, as they cannot authenticate devices without pre-existing security credentials.

Innovation Solution

A method and apparatus for provisioning devices by identifying and transmitting device parameters to a network element, which then connects to a subscription server to obtain verification and subscription parameters, such as a Globally Unique Temporary Identity (GUTI) and International Mobile Subscriber Identity (IMSI), to authenticate and provision the device for network access, even in the absence of a traditional HSS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-operator entities use unlicensed spectrum for LTE/LTE-A communications, then network capacity and access flexibility are improved, but the ability to authenticate devices is worsened due to lack of access to Home Subscriber Server (HSS)

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoiddevice authentication capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a subscription server as an intermediary component that mediates between the non-operator network and the device. This server stores subscription information and credentials, enabling authentication without requiring direct access to a traditional operator's HSS. The subscription server acts as a trusted third party that verifies device credentials and authorizes network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the traditional operator network functions by separating the authentication and subscription management capabilities from the core network infrastructure. Instead of requiring full operator-grade HSS access, the system divides functionality into modular components including the subscription server, network element, and device, allowing non-operators to implement authentication using only essential components.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If devices are provisioned without pre-existing operator credentials, then ease of device deployment is improved, but security credential verification becomes more difficult

Engineering Contradiction:
Improvedevice provisioning simplicityVSAvoidcredential verification complexity
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary provisioning where devices are pre-configured with essential identification parameters (such as IMEI, MEID, or other device identifiers) during manufacturing, but complete authentication credentials are obtained dynamically from the subscription server during initial network attachment. This preliminary setup simplifies device deployment while maintaining security through server-based verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service provisioning where devices automatically obtain their authentication credentials from the subscription server without requiring manual configuration or pre-provisioning by operators. The device initiates the provisioning process by presenting its device parameters, and the subscription server automatically provides the necessary credentials, reducing human intervention and simplifying deployment.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If network-based provisioning is implemented to provide credentials, then device access capability is improved, but network element complexity increases

Engineering Contradiction:
Improvedevice network access capabilityVSAvoidnetwork element structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and credential management functionality from the complex core network infrastructure and places it in a dedicated subscription server. This extraction allows the main network elements to remain relatively simple while delegating the complex credential verification tasks to the specialized server, which handles all authentication logic and credential storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9445443B2Network based provisioning of UE credentials for non-operator wireless deployments
Publication Date: 2016.09.13 QUALCOMM INC
  • US9445443B2 patent drawing
  • US9445443B2 patent drawing
  • US9445443B2 patent drawing

AI summary

Methods, systems, and devices are described for provisioning of devices, such as UEs, for service at a wireless network. One or more device parameters may be identified for use in provisioning the device on the wireless network, which may be provided to a network element. The network element may use the provided parameters to access a subscription server. The subscription server may provide verification and/or subscription parameters of the device that may then be used by the device to verify that the device is authorized to access the wireless network.