UE Onboarding via Default Manufacturer Credentials in Non-Public Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G systems lack defined system architecture and solutions for UE onboarding and provisioning in Non-Public Networks (NPNs), particularly for Stand-alone Non-Public Networks (SNPNs), which hinders on-demand connectivity and secure identity provisioning for IoT devices and 3GPP connectivity.

Innovation Solution

The proposed solution provides system architecture and mechanisms for UE onboarding and provisioning in NPNs, including secure and verifiable onboarding mechanisms, API exposure for remote provisioning, and network entity involvement for subscription management, enabling secure 3GPP connectivity and credential provisioning based on operator policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UE onboarding mechanisms are implemented in NPNs, then secure identity provisioning and connectivity are enabled, but system complexity increases due to lack of defined architecture

Engineering Contradiction:
Improvesecure identity provisioningVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The UE onboarding process is divided into distinct phases: initial network selection using default manufacturer credentials, authentication phase, and credential provisioning phase. This segmentation allows the complex onboarding process to be managed through manageable steps with clear transition points between phases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Default manufacturer credentials are pre-provisioned in UEs before deployment to NPNs. These preliminary credentials enable UEs to perform initial network selection and authentication without requiring prior network-specific credentials, thereby simplifying the onboarding process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If remote provisioning mechanisms are exposed via APIs, then on-demand connectivity is enabled, but network entity involvement increases complexity

Engineering Contradiction:
Improveon-demand connectivityVSAvoidnetwork entity involvement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A provisioning server acts as an intermediary between the UE and the network entities. The server receives API requests from UEs, processes provisioning logic, and coordinates with network entities to deliver credentials and configure connectivity. This intermediary approach enables on-demand connectivity while managing the complexity of network entity involvement through a centralized coordination point.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If default manufacturer credentials are used for initial access, then ease of device deployment is improved, but security risks increase

Engineering Contradiction:
Improvedevice deploymentVSAvoidsecurity risks
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

Default manufacturer credentials are pre-provisioned in UEs during manufacturing to enable initial network selection and authentication. These preliminary credentials facilitate ease of deployment but are designed to be temporary and are subsequently replaced with network-specific credentials after authentication, thereby mitigating security risks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates a time-limited and scope-restricted usage of default manufacturer credentials, with automatic transition to secure network-specific credentials. This beforehand cushioning approach allows devices to be deployed easily without compromising long-term security, as the default credentials are invalidated after the provisioning process completes.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS20210058784A1User equipment onboarding based on default manufacturer credentials unlicensed
Publication Date: 2021.02.25 INTEL CORP
  • US20210058784A1 patent drawing
  • US20210058784A1 patent drawing
  • US20210058784A1 patent drawing

AI summary

Disclosed embodiments are related to user equipment (UE) onboarding and remote provisioning for non-public networks (NPNs). The embodiments allow UEs to get network connectivity to an onboarding server and/or onboarding NPN so that the UEs can be provisioned with subscription credentials and configuration information for establishing connectivity with the NPN. Other embodiments may be described and/or claimed.