IP Library › Granted Patent US 12,445,847
Granted Patent B2
US 12,445,847 · App. 17/987,558 · Granted Oct 14, 2025

Method and apparatus for UE authentication for remote provisioning

Inventor: Kisuk Kweon (Gyeonggi-do, KR)
Assignee: Samsung Electronics Co., Ltd.
H04W12/08H04W8/18H04W12/06H04W12/72H04W60/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,847
App. No.
17/987,558
Granted
Oct 14, 2025
Kind
B2
Abstract

The disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). A method is provided for operating a terminal in a wireless network, including configuring a restricted packet data unit session with a provisioning server (PVS); transmitting a remote provisioning request message including a subscription permanent identifier to the PVS; and receiving a remote provisioning response message in response to the remote provisioning request message. The remote provisioning response message includes standalone non-public network credentials and subscription data of a terminal in case that a remote provisioning for the terminal is approved.

Claims (30)

1. A method for operating a terminal in a wireless network, the method comprising:

configuring a restricted packet data unit (PDU) session with a provisioning server (PVS);

transmitting a remote provisioning request message including a subscription permanent identifier (SUPI) to the PVS; and

receiving a remote provisioning response message in response to the remote provisioning request message,

wherein the remote provisioning response message includes standalone non-public network (SNPN) credentials and subscription data of a terminal in case that remote provisioning for the terminal is approved,

wherein the remote provisioning response message is determined based on an authentication response message received from a default credentials server (DCS),

wherein the DCS is selected by the PVS based on the SUPI,

wherein an authentication request message is transmitted after mutual authentication between the PVS and the DCS is performed, and

wherein the authentication response message is transmitted in response to the authentication request message transmitted from the PVS to the DCS based on the SUPI.

2. The method of claim 1 , wherein the DCS is selected by the PVS based on a realm part of the SUPI.

3. The method of claim 1 , wherein the remote provisioning response message includes a terminal authentication result indicating authentication failure for the terminal in case that the remote provisioning for the terminal is not approved.

4. A method for operating a provisioning server (PVS) in a wireless network, the method comprising:

configuring a restricted packet data unit (PDU) session with a terminal;

receiving a remote provisioning request message including a subscription permanent identifier (SUPI) from the terminal;

selecting a default credentials server (DCS), based on the SUPI;

performing mutual authentication with the DCS;

transmitting an authentication request message to the DCS including the SUPI after performing the mutual authentication;

receiving an authentication response message including a terminal authentication result from the DCS;

transmitting a remote provisioning response message to the terminal in response to the remote provisioning request message,

wherein the remote provisioning response message includes standalone non-public network (SNPN) credentials and subscription data of the terminal in case that remote provisioning for the terminal is approved, and

wherein the remote provisioning response message is determined based on the authentication response message.

5. The method of claim 4 , wherein the DCS is selected based on a realm part of the SUPI.

6. The method of claim 4 , wherein the remote provisioning response message includes a terminal authentication result indicating authentication failure for the terminal in case that the remote provisioning for the terminal is not approved.

7. A method for operating a default credentials server (DCS) in a wireless network, the method comprising:

performing mutual authentication with a provisioning server (PVS);

receiving an authentication request message including a subscription permanent identifier (SUPI) from the PVS; and

transmitting an authentication response message including an authentication result to the PVS in response to the authentication request message,

wherein the authentication request message is transmitted based on a remote provisioning request message received from a terminal, and the authentication response message includes standalone non-public network (SNPN) credentials and subscription data of the terminal in case that the authentication result indicates authentication success, and

wherein the mutual authentication is performed after the PVS selects the DCS based on a realm part of the SUPI.

8. The method of claim 7 , wherein a remote provisioning response message received in response to the remote provisioning request message includes a terminal authentication result indicating authentication failure for the terminal in case that remote provisioning for the terminal is not approved.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2022
From: KWEON, KISUK
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 061820/0476 →
Priority Claims (1)
KR 10-2021-0157875 · Nov 16, 2021 · national
Continuity (1)
Related Publication 20230156470A1 · May 18, 2023
References Cited (24)
US 11848909B2 · Korja · 2023 [cited by examiner]
US 12015917B2 · Gundavelli · 2024 [cited by examiner]
US 20210058784A1 · Kedalagudde · 2021 [cited by examiner]
US 20210105712A1 · Speicher et al. · 2021 [cited by applicant]
US 20220330022A1 · Kolekar · 2022 [cited by examiner]
US 20220360493A1 · Sung · 2022 [cited by examiner]
US 20230087052A1 · Korja · 2023 [cited by examiner]
US 20230137814A1 · Staufer · 2023 [cited by examiner]
US 20230199484A1 · Kweon · 2023 [cited by examiner]
US 20230199632A1 · Talebi · 2023 [cited by examiner]
US 20240073691A1 · Lehtovirta · 2024 [cited by examiner]
US 20240292219A1 · Kim · 2024 [cited by examiner]
US 20240314560A1 · Gundavelli · 2024 [cited by examiner]
US 20240314720A1 · Sethi · 2024 [cited by examiner]
WO WO2023058974 · 2023 [cited by applicant]
Ericsson et al., “Rapporteur's Editorial Cleanup for eNPN”, S2-2108465, 3GPP TSG-WG SA 2 Meeting #148E, Nov. 15-22, 2021, 11 pages. [cited by applicant]
3GPP TS 33.501 V17.3.0, 3GPP, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security Architecture and Procedures for 5G System (Release 17), Sep. 2021, 258 pages. [cited by applicant]
ZTE, Ericsson, “Clarification on the UE Remote Provisioning”, S2-2108105, SA WG2 Meeting #S2-147E, Oct. 18-22, 2021, 4 pages. [cited by applicant]
Huawei, HiSilicon, “23.501 Proposal in Case DCS Provide the PVS Address”, S2-2106243, 3GPP TSG-WG SA2 Meeting #146E, Aug. 16-27, 2021, 4 pages. [cited by applicant]
Ericsson, Nokia, Nokia Shanghai Bell, “Registration Procedure for Onboarding SNPN”, S2-2106721, 3GPP TSG-SA WG2 Meeting #146E, Aug. 16-27, 2021, 4 pages. [cited by applicant]
International Search Report dated Jan. 31, 2023 issued in counterpart application No. PCT/KR2022/018006, 7 pages. [cited by applicant]
Ericsson et al., “UE Boarding”, S2-2104217, 3GPP TSG-WG SA2 Meeting #145E e-meeting, May 17-28, 2021, 14 pages. [cited by applicant]
Huawei et al., “KI#4, Evaluations and Conclusions Update”, S2-2007048, 3GPP TSG-WG SA2 Meeting #141E e-meeting, Oct. 12-23, 2020, 9 pages. [cited by applicant]
European Search Report dated Nov. 19, 2024 issued in counterpart application No. 22896026.6-1215, 16 pages. [cited by applicant]