UE Onboarding via One-Way Authentication for Non-Public Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of wireless networks, particularly in 5G and emerging 6G systems, is exacerbated by the increasing diversity and number of communication devices, leading to challenges in securely provisioning non-public networks (NPNs) for user equipment (UE) without pre-provisioned credentials.
Innovation Solution
A method for UE onboarding in non-public networks (NPNs) using one-way authentication with manufacturer-provided credentials, involving an onboarding server that validates UE authenticity and provisions network credentials, allowing secure connection establishment without requiring pre-provisioned subscriptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional mutual authentication is used for UE onboarding in NPNs, then security is improved, but device complexity increases due to requiring pre-provisioned credentials and UICC cards
Solution Approach 1:
The patent extracts the authentication capability from the UICC card requirement, allowing UE to perform authentication using only manufacturer-provided credentials stored in the device. This removes the need for physical SIM cards while maintaining security through one-way authentication where the network validates the UE without requiring mutual credential exchange.
Solution Approach 2:
The patent introduces an onboarding server as an intermediary that facilitates credential validation and provisioning. The onboarding server acts as a mediator between the UE and the network, validating manufacturer credentials and enabling secure onboarding without requiring traditional mutual authentication protocols that depend on pre-provisioned credentials.
2Ease of operation
If one-way authentication with manufacturer credentials is used, then ease of operation is improved by allowing devices without UICC, but network security may be compromised
Solution Approach 1:
The patent applies preliminary action by having the network perform validation of manufacturer credentials during the onboarding process before granting full network access. The onboarding server validates the UE's manufacturer credentials in advance, establishing trust before the UE operates in the network, thus maintaining security while enabling easier device operation.
Solution Approach 2:
The patent applies local quality by implementing different authentication mechanisms for different network access scenarios. For initial onboarding, one-way authentication with manufacturer credentials is used. For subsequent network operations, the provisioned credentials are used. This localized approach to authentication quality balances ease of operation with network security.
Data Source
AI summary
An apparatus and system for onboarding based on UE default manufacturer credentials are described. A UE sends default manufacturer credentials and an indication to proceed with restricted onboarding to an onboarding non-public network (O-SNPN). An Onboarding Server validates the authenticity of the UE based on the manufacturer credentials and sends a certificate. The UE is provisioned with a set of roots of trust certificate information to use to authenticate the certificate using one way authentication. After authentication, the UE receives network credentials and performs mutual authentication to register with a NPN while being authenticated by a home network. The UE identity is indicated as anonymous in response to an indication by the O-SNPN for subscriber identifier privacy.


