UE Onboarding via One-Way Authentication for Non-Public Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of wireless networks, particularly in 5G and emerging 6G systems, is exacerbated by the increasing diversity and number of communication devices, leading to challenges in securely provisioning non-public networks (NPNs) for user equipment (UE) without pre-provisioned credentials.

Innovation Solution

A method for UE onboarding in non-public networks (NPNs) using one-way authentication with manufacturer-provided credentials, involving an onboarding server that validates UE authenticity and provisions network credentials, allowing secure connection establishment without requiring pre-provisioned subscriptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional mutual authentication is used for UE onboarding in NPNs, then security is improved, but device complexity increases due to requiring pre-provisioned credentials and UICC cards

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication capability from the UICC card requirement, allowing UE to perform authentication using only manufacturer-provided credentials stored in the device. This removes the need for physical SIM cards while maintaining security through one-way authentication where the network validates the UE without requiring mutual credential exchange.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an onboarding server as an intermediary that facilitates credential validation and provisioning. The onboarding server acts as a mediator between the UE and the network, validating manufacturer credentials and enabling secure onboarding without requiring traditional mutual authentication protocols that depend on pre-provisioned credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If one-way authentication with manufacturer credentials is used, then ease of operation is improved by allowing devices without UICC, but network security may be compromised

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by having the network perform validation of manufacturer credentials during the onboarding process before granting full network access. The onboarding server validates the UE's manufacturer credentials in advance, establishing trust before the UE operates in the network, thus maintaining security while enabling easier device operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by implementing different authentication mechanisms for different network access scenarios. For initial onboarding, one-way authentication with manufacturer credentials is used. For subsequent network operations, the provisioned credentials are used. This localized approach to authentication quality balances ease of operation with network security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250234199A1UE onboarding and provisioning using one way authentication
Publication Date: 2025.07.17 INTEL CORP
  • US20250234199A1 patent drawing
  • US20250234199A1 patent drawing
  • US20250234199A1 patent drawing

AI summary

An apparatus and system for onboarding based on UE default manufacturer credentials are described. A UE sends default manufacturer credentials and an indication to proceed with restricted onboarding to an onboarding non-public network (O-SNPN). An Onboarding Server validates the authenticity of the UE based on the manufacturer credentials and sends a certificate. The UE is provisioned with a set of roots of trust certificate information to use to authenticate the certificate using one way authentication. After authentication, the UE receives network credentials and performs mutual authentication to register with a NPN while being authenticated by a home network. The UE identity is indicated as anonymous in response to an indication by the O-SNPN for subscriber identifier privacy.