IP Library › Granted Patent US 12,284,518
Granted Patent B2
US 12,284,518 · App. 17/570,631 · Granted Apr 22, 2025

UE onboarding and provisioning using one way authentication

Inventors: Abhijeet Ashok Kolekar (Hillsboro, OR); Alexandre Saso Stojanovski (Paris, FR); Meghashree Dattatri Kedalagudde (Hillsboro, OR)
Assignee: Intel Corporation
H04W12/069H04W4/50H04W12/71H04W60/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,518
App. No.
17/570,631
Granted
Apr 22, 2025
Kind
B2
Abstract

An apparatus and system for onboarding based on UE default manufacturer credentials are described. A UE sends default manufacturer credentials and an indication to proceed with restricted onboarding to an onboarding non-public network (O-SNPN). An Onboarding Server validates the authenticity of the UE based on the manufacturer credentials and sends a certificate. The UE is provisioned with a set of roots of trust certificate information to use to authenticate the certificate using one way authentication. After authentication, the UE receives network credentials and performs mutual authentication to register with a NPN while being authenticated by a home network. The UE identity is indicated as anonymous in response to an indication by the O-SNPN for subscriber identifier privacy.

Claims (43)

1. An apparatus for a user equipment (UE), the apparatus comprising:

processing circuitry configured to, during initial access to an onboarding Stand-alone Non-Public Network (O-SNPN) via an access and mobility function (AMF):

select the O-SNPN;

determine whether subscriber identifier privacy is to be used during onboarding with the O-SNPN;

in response to a determination that subscriber identifier privacy is to be used during the onboarding with the O-SNPN, set a UE identity to an anonymous value;

encode, for transmission to the O-SNPN after selection of the O-SNPN, a registration request that includes an indication of registration of the UE for onboarding and UE information that includes a default UE credential;

decode, from the O-SNPN, an O-SNPN certificate in response to the registration request; and

authenticate the O-SNPN using one way authentication based on the O-SNPN certificate, the UE provisioned with a set of roots of trust certificate information to authenticate the O-SNPN using the O-SNPN certificate; and

a memory configured to store the UE information.

2. The apparatus of claim 1 , wherein the registration request includes the UE identity encoded in a Subscription Permanent Identifier (SUPI) format.

3. The apparatus of claim 2 , wherein the SUPI format is a Network Access Identifier (NAI) in a form of “username@realm”.

4. The apparatus of claim 1 , wherein the processing circuitry is configured to encode, for transmission to the O-SNPN, at least one of an application identifier or a Service Provider Identifier.

5. The apparatus of claim 1 , wherein the processing circuitry is configured to perform, with the O-SNPN, primary authentication using non-Authentication and Key Agreement (AKA) communications.

6. The apparatus of claim 5 , wherein the non-AKA communications comprise an Extensible Authentication Protocol-Transport Layer Security (EAP-TLS).

7. The apparatus of claim 1 , wherein the processing circuitry is configured to automatically discover and select the O-SNPN based on information in a system information broadcast (SIB) from the O-SNPN.

8. The apparatus of claim 1 , wherein the processing circuitry is configured to present, via a user interface, available onboarding networks for manual selection of the O-SNPN.

9. The apparatus of claim 1 , wherein the processing circuitry is configured to use a set of roots of trust certificate information stored in the memory to authenticate the O-SNPN during primary authentication.

10. The apparatus of claim 1 , wherein the processing circuitry is configured to:

perform primary authentication of the O-SNPN using the one way authentication; and

perform secondary authentication after the primary authentication, the secondary authentication including mutual authentication with a Default Credential Server (DCS) using Extensible Authentication Protocol (EAP) communications.

11. The apparatus of claim 10 , wherein the processing circuitry is configured to obtain network credentials after the primary authentication, the network credentials comprising a Subscription Permanent Identifier (SUPI) and an associated key for Authentication and Key Agreement (AKA) communications.

12. The apparatus of claim 10 , wherein the processing circuitry is configured to obtain network credentials after the primary authentication, the network credentials comprising a Network Access Identifier (NAI) and associated digital certificate.

13. The apparatus of claim 1 , wherein the registration request indicates a connection request for a restricted onboarding service in a radio resource control (RRC) Establishment procedure that enables selection of an appropriate AMF in the O-SNPN.

14. The apparatus of claim 1 , wherein the processing circuitry is configured to, after validation by an onboarding server of authenticity of the UE based on manufacturer credentials stored in the memory:

decode network credentials that allow the UE to register with a non-public network (NPN) while being authenticated by a home network (HN) of the UE, and initiate registration with the HN based on the network credentials.

15. An apparatus for an access and mobility function (AMF) of an onboarding Stand-alone Non-Public Network (O-SNPN), the apparatus comprising:

processing circuitry configured to:

encode, for transmission, a system information broadcast indicating support for a restricted onboarding service, the support for the restricted onboarding service indicating subscriber privacy is to be used;

decode, from a user equipment (UE), a registration request that includes an indication of registration of the UE for onboarding using the restricted onboarding service and manufacturer UE credentials, a UE identity in the registration request being anonymous;

encode, for transmission to the UE, an initial authentication request that contains an O-SNPN certificate for one way authentication by the UE based on the O-SNPN certificate; and

decode, from the UE, an initial authentication response to the O-SNPN certificate; and

a memory configured to store the O-SNPN certificate.

16. The apparatus of claim 15 , wherein the processing circuitry is configured to encode, for transmission to the UE, network credentials comprising one of:

a Subscription Permanent Identifier (SUPI) and an associated key for Authentication and Key Agreement (AKA) communications, or

a Network Access Identifier (NAI) and an associated digital certificate.

17. A non-transitory computer-readable storage medium that stores instructions for execution by one or more processors of a user equipment (UE), the one or more processors to configure the UE to, when the instructions are executed:

decode a system information broadcast from an onboarding Stand-alone Non-Public Network (O-SNPN), the system information broadcast indicating support for a restricted onboarding service;

select the O-SNPN;

determine, based on the system information broadcast whether subscriber identifier privacy is to be used during onboarding with the O-SNPN;

in response to a determination that subscriber identifier privacy is to be used during the onboarding with the O-SNPN, set a UE identity to be anonymous in UE information;

encode, for transmission to the O-SNPN after selection of the O-SNPN, a registration request that includes an indication of registration of the UE for onboarding and the UE information that includes manufacturer UE credentials;

decode, from the O-SNPN, an O-SNPN certificate in response to the registration request; and

authenticate the O-SNPN using one way authentication based on the O-SNPN certificate, the UE provisioned with a set of roots of trust certificate information to authenticate the O-SNPN using the O-SNPN certificate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2022
From: KOLEKAR, ABHIJEET ASHOK; STOJANOVSKI, ALEXANDRE SASO; KEDALAGUDDE, MEGHASHREE DATTATRI
To: INTEL CORPORATION
Reel/Frame 060505/0005 →
Continuity (2)
Provisional Application 63135436 · Jan 8, 2021
Related Publication 20220330022A1 · Oct 13, 2022
References Cited (10)
US 20110252230A1 · Segre · 2011 [cited by examiner]
US 20130262850A1 · Canpolat · 2013 [cited by examiner]
US 20140051391A1 · Torres · 2014 [cited by examiner]
US 20200351653A1 · Khan · 2020 [cited by examiner]
US 20200389865A1 · Kunz · 2020 [cited by examiner]
US 20210058784A1 · Kedalagudde · 2021 [cited by examiner]
US 20210211975A1 · Prabhakar · 2021 [cited by examiner]
US 20210368434A1 · Kweon · 2021 [cited by examiner]
US 20220159460A1 · Ben Henda · 2022 [cited by examiner]
US 20220201593A1 · Baek · 2022 [cited by examiner]