Network-Based UE Credential Provisioning Without HSS Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communications, non-operator entities face challenges in provisioning devices for network access when they lack access to a Home Subscriber Server (HSS) for verifying credentials, especially when using unlicensed spectrum for LTE/LTE-A communications, as they cannot authenticate devices without pre-existing security credentials.
Innovation Solution
A method and apparatus for provisioning devices by identifying and transmitting device parameters to a network element, which then connects to a subscription server to obtain verification and subscription parameters, such as a Globally Unique Temporary Identity (GUTI) and International Mobile Subscriber Identity (IMSI), to authenticate and provision the device for network access, even in the absence of a traditional HSS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-operator entities use unlicensed spectrum for LTE/LTE-A communications, then network capacity and access flexibility are improved, but the ability to authenticate devices is worsened due to lack of access to Home Subscriber Server (HSS)
Solution Approach 1:
The patent introduces a subscription server as an intermediary component that mediates between the non-operator network and the device. This server stores subscription information and credentials, enabling authentication without requiring direct access to a traditional operator's HSS. The subscription server acts as a trusted third party that verifies device credentials and authorizes network access.
Solution Approach 2:
The patent segments the traditional operator network functions by separating the authentication and subscription management capabilities from the core network infrastructure. Instead of requiring full operator-grade HSS access, the system divides functionality into modular components including the subscription server, network element, and device, allowing non-operators to implement authentication using only essential components.
2Ease of manufacture
If devices are provisioned without pre-existing operator credentials, then ease of device deployment is improved, but security credential verification becomes more difficult
Solution Approach 1:
The patent implements preliminary provisioning where devices are pre-configured with essential identification parameters (such as IMEI, MEID, or other device identifiers) during manufacturing, but complete authentication credentials are obtained dynamically from the subscription server during initial network attachment. This preliminary setup simplifies device deployment while maintaining security through server-based verification.
Solution Approach 2:
The system enables self-service provisioning where devices automatically obtain their authentication credentials from the subscription server without requiring manual configuration or pre-provisioning by operators. The device initiates the provisioning process by presenting its device parameters, and the subscription server automatically provides the necessary credentials, reducing human intervention and simplifying deployment.
3Adaptability or versatility
If network-based provisioning is implemented to provide credentials, then device access capability is improved, but network element complexity increases
Solution Approach 1:
The patent extracts the authentication and credential management functionality from the complex core network infrastructure and places it in a dedicated subscription server. This extraction allows the main network elements to remain relatively simple while delegating the complex credential verification tasks to the specialized server, which handles all authentication logic and credential storage.
Data Source
AI summary
Methods, systems, and devices are described for provisioning of devices, such as UEs, for service at a wireless network. One or more device parameters may be identified for use in provisioning the device on the wireless network, which may be provided to a network element. The network element may use the provided parameters to access a subscription server. The subscription server may provide verification and/or subscription parameters of the device that may then be used by the device to verify that the device is authorized to access the wireless network.


