-
公开(公告)号:US20250113187A1
公开(公告)日:2025-04-03
申请号:US18978726
申请日:2024-12-12
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Rainer Liebhart , Sumesh Parameswaran Nair , Bo Holm Bjerrum
Abstract: Techniques are disclosed for security management during an onboarding process for user equipment. For example, from a perspective of an onboarding network, a method comprises authenticating, via the onboarding network, user equipment based on an onboarding record previously configured for the user equipment or a set of user equipment and maintained by the onboarding network. Upon successful authentication, a communication session is established from the onboarding network to a provisioning server for remote provisioning of the user equipment. Advantageously, the onboarding process is performed without a default credential server.
-
公开(公告)号:US12212961B2
公开(公告)日:2025-01-28
申请号:US17674640
申请日:2022-02-17
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Bo Holm Bjerrum
IPC: H04W12/02 , H04W12/041 , H04W12/06 , H04W12/08 , H04W12/72
Abstract: According to an example aspect of the present invention, there is provided an apparatus comprising at least one processing core, at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processing core, cause the apparatus at least to transmit, by a user equipment, a concealed identifier of the user equipment to an onboarding network, wherein the concealed identifier of the user equipment indicates that the user equipment is requesting unauthenticated access to the onboarding network and execute, by the user equipment, a key generating authentication protocol to access the onboarding network without performing authentication of the user equipment.
-
公开(公告)号:US20230137814A1
公开(公告)日:2023-05-04
申请号:US17514024
申请日:2021-10-29
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Rainer Liebhart , Devaki Chandramouli , Markus Isomaki , Pekka Korja
Abstract: Techniques for facilitating onboarding to a non-public network is provided. Provisioning parameters may be provided to User Equipment (UE) from a Default Credential Server (DCS) via a secure communication tunnel. Additionally or alternatively, provisioning parameter container(s) including readable provisioning parameters for an Onboarding Network (ONN), and secure provisioning parameters for the UE, may be transmitted to the UE via the ONN. The disclosed methods and apparatuses enable the UE to onboard to a non-public network using the provisioning parameters, and to verify the integrity of the provisioning parameters and ensure the provisioning parameters are not modified by an unauthorized device.
-
公开(公告)号:US20240414633A1
公开(公告)日:2024-12-12
申请号:US18696895
申请日:2022-09-29
Applicant: Nokia Technologies Oy
Inventor: Devaki Chandramouli , Markus Staufer , Rainer Liebhart , Sumesh Parameswaran Nair , Jürgen Merkel
Abstract: Methods, systems, apparatuses, and computer program products are provided for discovery and/or access to localized services provided by a communication network. In this regard, based on a tracking area code associated with a local network configured to provide localized services, a registration update process, a handover, or a state transition is initiated with respect to user equipment that is served by a mobile network. Furthermore, network information for the local network during the registration update process, during the handover, or during the state transition of the user equipment is determined. Network information is also provided to the user equipment during the registration update process, during the handover, or during the state transition of the user equipment. Additionally, a connection between the user equipment and the local network is established based on the network information.
-
公开(公告)号:US12003961B2
公开(公告)日:2024-06-04
申请号:US17514024
申请日:2021-10-29
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Rainer Liebhart , Devaki Chandramouli , Markus Sakari Isomäki , Pekka Juhani Korja
Abstract: Techniques for facilitating onboarding to a non-public network is provided. Provisioning parameters may be provided to User Equipment (UE) from a Default Credential Server (DCS) via a secure communication tunnel. Additionally or alternatively, provisioning parameter container(s) including readable provisioning parameters for an Onboarding Network (ONN), and secure provisioning parameters for the UE, may be transmitted to the UE via the ONN. The disclosed methods and apparatuses enable the UE to onboard to a non-public network using the provisioning parameters, and to verify the integrity of the provisioning parameters and ensure the provisioning parameters are not modified by an unauthorized device.
-
公开(公告)号:US20240056301A1
公开(公告)日:2024-02-15
申请号:US18447374
申请日:2023-08-10
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Peter Schneider , Ranganathan Mavureddi Dhanasekaran , Saurabh Khare
IPC: H04L9/32
CPC classification number: H04L9/32
Abstract: Method comprising:
monitoring whether a network receives an authorization request for establishing a session of an AF with a UE, wherein the authorization request comprises a permanent identifier of the AF, a received temporary identifier of the AF, and a temporary identifier of a UE;
if the authorization request is received:
forming a key identifier based on the temporary identifier of the UE;
retrieving, based on the key identifier, a stored key and a first permanent identifier of the UE;
calculating a calculated temporary identifier of the AF based on the permanent identifier of the AF and the stored key;
checking whether the calculated temporary identifier of the AF is identical with the received temporary identifier of the AF;
inhibiting authorizing the AF for the establishing the session with the UE if the calculated temporary identifier of the AF is not identical with the received temporary identifier of the AF.-
公开(公告)号:US20230045417A1
公开(公告)日:2023-02-09
申请号:US17879101
申请日:2022-08-02
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Rainer Liebhart , Sumesh Parameswaran Nair , Bo Holm Bjerrum
Abstract: Techniques are disclosed for security management during an onboarding process for user equipment. For example, from a perspective of an onboarding network, a method comprises authenticating, via the onboarding network, user equipment based on an onboarding record previously configured for the user equipment or a set of user equipment and maintained by the onboarding network. Upon successful authentication, a communication session is established from the onboarding network to a provisioning server for remote provisioning of the user equipment. Advantageously, the onboarding process is performed without a default credential server.
-
-
-
-
-
-