UE Onboarding via Default Manufacturer Credentials in Non-Public Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G systems lack defined system architecture and solutions for UE onboarding and provisioning in Non-Public Networks (NPNs), particularly for Stand-alone Non-Public Networks (SNPNs), which hinders on-demand connectivity and secure identity provisioning for IoT devices and 3GPP connectivity.
Innovation Solution
The proposed solution provides system architecture and mechanisms for UE onboarding and provisioning in NPNs, including secure and verifiable onboarding mechanisms, API exposure for remote provisioning, and network entity involvement for subscription management, enabling secure 3GPP connectivity and credential provisioning based on operator policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UE onboarding mechanisms are implemented in NPNs, then secure identity provisioning and connectivity are enabled, but system complexity increases due to lack of defined architecture
Solution Approach 1:
The UE onboarding process is divided into distinct phases: initial network selection using default manufacturer credentials, authentication phase, and credential provisioning phase. This segmentation allows the complex onboarding process to be managed through manageable steps with clear transition points between phases.
Solution Approach 2:
Default manufacturer credentials are pre-provisioned in UEs before deployment to NPNs. These preliminary credentials enable UEs to perform initial network selection and authentication without requiring prior network-specific credentials, thereby simplifying the onboarding process while maintaining security.
2Adaptability or versatility
If remote provisioning mechanisms are exposed via APIs, then on-demand connectivity is enabled, but network entity involvement increases complexity
Solution Approach 1:
A provisioning server acts as an intermediary between the UE and the network entities. The server receives API requests from UEs, processes provisioning logic, and coordinates with network entities to deliver credentials and configure connectivity. This intermediary approach enables on-demand connectivity while managing the complexity of network entity involvement through a centralized coordination point.
3Ease of manufacture
If default manufacturer credentials are used for initial access, then ease of device deployment is improved, but security risks increase
Solution Approach 1:
Default manufacturer credentials are pre-provisioned in UEs during manufacturing to enable initial network selection and authentication. These preliminary credentials facilitate ease of deployment but are designed to be temporary and are subsequently replaced with network-specific credentials after authentication, thereby mitigating security risks.
Solution Approach 2:
The system incorporates a time-limited and scope-restricted usage of default manufacturer credentials, with automatic transition to secure network-specific credentials. This beforehand cushioning approach allows devices to be deployed easily without compromising long-term security, as the default credentials are invalidated after the provisioning process completes.
Data Source
AI summary
Disclosed embodiments are related to user equipment (UE) onboarding and remote provisioning for non-public networks (NPNs). The embodiments allow UEs to get network connectivity to an onboarding server and/or onboarding NPN so that the UEs can be provisioned with subscription credentials and configuration information for establishing connectivity with the NPN. Other embodiments may be described and/or claimed.


