IP Library Granted Patent US 12,477,334
Granted Patent B2
US 12,477,334 · App. 18/261,214 · Granted Nov 18, 2025

Indication of provisioning protocol for credentials to access a non-public network

Inventors: Vesa Lehtovirta (Espoo, FI); Christine Jost (Dalby, SE); Helena Vahidi Mazinani (Lund, SE)
Assignee: Telefonaktiebolaget LM Ericsson (Publ)
H04W12/08H04W12/06H04W12/106H04L63/0892H04W12/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,334
App. No.
18/261,214
Granted
Nov 18, 2025
Kind
B2
Abstract

A method for a user equipment (UE) to obtain security credentials for accessing a non-public network (NPN) is provided. The method comprises sending, to an onboarding network (ON), a registration request that includes an identifier of the UE, and obtaining an indication of a credential provisioning protocol (CPP) used by a provisioning server (PS) for provisioning security credentials to access the NPN. The method further comprises obtaining, from the PS via the ON using the indicated CPP, security credentials for the UE to access the NPN.

Claims (44)

1 . A method for a user equipment (UE) to obtain security credentials for accessing a non-public network (NPN), the method comprising:

sending, to an onboarding network (ON), a registration request that includes an identifier of the UE;

obtaining an indication of a credential provisioning protocol (CPP) used by a provisioning server (PS) for provisioning security credentials to access the NPN; and

obtaining security credentials for the UE to access the NPN, wherein the security credentials are obtained from the PS via the ON using the indicated CPP.

2 . The method of any of claim 1 , wherein:

the registration request includes an indication of one or more UE-supported CPPs; and

the indicated CPP is one of the UE-supported CPPs.

3 . The method of claim 1 , wherein obtaining the indication of a CPP used by the PS includes receiving an indication of a PS-supported CPP from the PS or from a default credential server (DCS).

4 . The method according to claim 1 , wherein the DCS comprises an authentication, authorization, and accounting (AAA) server.

5 . The method of claim 1 , wherein the obtained indication is integrity-protected based on one of the following:

key material known to the UE and to a default credential server (DCS),

key material known to the UE and to the PS, or

key material known to the UE and to the ON.

6 . The method of claim 1 , wherein the indication of the CPP used by the PS is obtained from the ON.

7 . The method of claim 6 , wherein the indication of the CPP used by the PS is obtained from the ON in one of the following:

a message in a non-access stratum security mode command (NAS SMC) procedure; or

a registration accept that is responsive to the registration request.

8 . The method of claim 1 , wherein the indication of the CPP used by the PS is obtained from the PS.

9 . The method of claim 8 , wherein obtaining the indication of the CPP used by the PS comprises:

after registration with the ON, sending to the PS a request for security credentials for the UE to access the NPN; and

receiving the indication in response to the request.

10 . The method of claim 1 , wherein the indicated CPP is one of the following: CMPv2, ACME, EST, SCEP, GSMA eSIM, or OMA LwM2M.

11 . The method of claim 1 , wherein the indication of the CPP used by the PS includes an indication of whether the CPP is performed via control plane communications with the UE or via user plane communications with the UE.

12 . A method for a default credential server (DCS) to facilitate provisioning of security credentials for a user equipment (UE) to access a non-public network (NPN), the method comprising:

receiving, from an onboarding network (ON), an authentication request that includes an identifier of the UE;

performing a primary authentication with the UE via the ON, using an authentication method based on the identifier of the UE;

determining a credential provisioning protocol (CPP) used by a provisioning server (PS) for provisioning security credentials to access the NPN; and

sending to the ON an indication of the CPP used by the PS.

13 . A method for a provisioning server (PS) for a non-public network (NPN) to facilitate user equipment (UE) access to the NPN, the method comprising:

determining a credential provisioning protocol (CPP) to be used by the PS for provisioning security credentials for the UE to access the NPN;

sending to the UE an indication of the CPP to be used by the PS; and

providing security credentials for the UE to access the NPN, wherein the security credentials are provided to the UE via an onboarding network (ON) using the indicated CPP.

14 . A user equipment (UE) configured to obtain security credentials for accessing a non-public network (NPN), the UE comprising:

radio interface circuitry configured to communicate with an onboarding network (ON) and the NPN; and

processing circuitry operably coupled to the radio interface circuitry, whereby the processing circuitry and radio interface circuitry are configured to perform operations corresponding to method of claim 1 .

15 . A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a user equipment (UE) configured to obtain security credentials for accessing a non-public network (NPN), configure the UE to perform operations corresponding to the method of claim 1 .

16 . A default credential server (DCS) configured to facilitate provisioning of security credentials for a user equipment (UE) to access a non-public network (NPN), the DCS comprising:

interface circuitry configured to communicate at least win an onboarding network (ON) and the UE; and

processing circuitry operably coupled to the interface circuitry, wherein the processing circuitry and the interface circuitry are configured to perform operations corresponding to the method of claim 12 .

17 . A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a default credential server (DCS) configured to facilitate provisioning of security credentials for a user equipment (UE) to access a non-public network (NPN), configure the DCS to perform operations corresponding to the method of claim 12 .

18 . A provisioning server (PS) configured to facilitate user equipment (UE) access to a non-public network (NPN), the DCS comprising:

interface circuitry configured to communicate with at least an onboarding network (ON) and the UE; and

processing circuitry operably coupled to the interface circuitry, wherein the processing circuitry and the interface circuitry are configured to perform operations corresponding to the method of claim 13 .

19 . A non-transitory, computer-readable medium storing computer-executable instructions that, when executed by processing circuitry of a provisioning server (PS) configured to facilitate user equipment (UE) access to a non-public network (NPN), configure the PS to perform operations corresponding to the method of claim 13 .

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2023
From: JOST, CHRISTINE; MAZINANI, HELENA VAHIDI
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064230/0427 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2023
From: LEHTOVIRTA, VESA
To: OY L M ERICSSON AB
Reel/Frame 064230/0450 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2023
From: OY L M ERICSSON AB
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064230/0480 →
Continuity (2)
Provisional Application 63151284 · Feb 19, 2021
Related Publication 20240073691A1 · Feb 29, 2024
References Cited (31)
US 10764821B2 · Xiang · 2020 [cited by examiner]
US 10986568B1 · Jagannatha · 2021 [cited by examiner]
US 11050631B2 · Rooney · 2021 [cited by examiner]
US 11622272B2 · Zisimopoulos · 2023 [cited by examiner]
US 12015917B2 · Gundavelli · 2024 [cited by examiner]
US 12096220B2 · Zisimopoulos · 2024 [cited by examiner]
US 20110252230A1 · Segre · 2011 [cited by examiner]
US 20190059067A1 · Lee · 2019 [cited by examiner]
US 20190223063A1 · Palanigounder · 2019 [cited by examiner]
US 20190268835A1 · Shan · 2019 [cited by examiner]
US 20190335392A1 · Qiao · 2019 [cited by examiner]
US 20200053083A1 · Kunz · 2020 [cited by examiner]
US 20200351653A1 · Khan · 2020 [cited by examiner]
US 20200389865A1 · Kunz · 2020 [cited by examiner]
US 20210058784A1 · Kedalagudde · 2021 [cited by examiner]
US 20210092707A1 · Ryu · 2021 [cited by examiner]
US 20210144593A1 · Ahn · 2021 [cited by examiner]
US 20210211975A1 · Prabhakar · 2021 [cited by examiner]
US 20210226860A1 · Lee · 2021 [cited by examiner]
US 20220150684A1 · Palanigounder · 2022 [cited by examiner]
“3GPP TR 23.700-07 V0.4.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhanced support of non-public networks (Release 17), Jun. 2020, pp. 1-159. [cited by applicant]
“3GPP TR 33.857 V0.3.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on enhanced security support for Non-Public Networks; (NPN); (Release 17), Nov. 2020, pp. 1-4… [cited by applicant]
“3GPP TS 33.501 V15.11.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15), Dec. 2020, pp. 1-193. [cited by applicant]
“3GPP TS 33.535 V16.1.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for applications (AKMA) based on 3GPP credentials in the 5G Syst… [cited by applicant]
“KI#4, evaluations and conclusions update”, 3GPP TSG-WG SA2 Meeting #141E e-meeting, S2-2007048, Elbonia, (revision of S2-200xxxx), Oct. 12-23, 2020, pp. 1-9. [cited by applicant]
“KI#4, Update to Solution #27”, SA WG2 Meeting #S2-140E, S2-2005584r01, Electronic, Elbonia, Aug. 19-Sep. 1, 2020, pp. 1-12. [cited by applicant]
“Update to Solution #5: UE Onboarding and provisioning for an SNPN”, SA WG2 Meeting #139E, S2-2004379, E-meeting, (revison of S2-2004174), Jun. 1-12, 2020, pp. 1-6. [cited by applicant]
“3GPP TS 38.401 V15.6.0”, 3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NG-RAN; Architecture description (Release 15), Jul. 2019, pp. 1-46. [cited by applicant]
“3GPP TR 38.801 V14.0.0”, 3rd Generation Partnership Project; Technical Specification Group Radio Access Network; Study on new radio access technology: Radio access architecture and interfaces (Release 14), Mar. 2017, p… [cited by applicant]
“3GPP TS 33.401 V15.8.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 15), Jun. 2019, pp. 1-163. [cited by applicant]
“3GPP TS 23.501 V15.5.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15), Mar. 2019, pp. 1-241. [cited by applicant]
Cited By (1)
US 12,652,637