Neutral host network for private cellular network
By establishing an indirect connection between the private cellular network and the MNO core network, and utilizing Passpoint technology and the NHN connection system, the challenges of traditional NHN deployments are solved, enabling efficient and secure neutral host network expansion and meeting enterprises' needs for reliable and high-capacity connectivity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEWLETT PACKARD ENTERPRISE DEV LP
- Filing Date
- 2025-09-22
- Publication Date
- 2026-05-22
Smart Images

Figure CN122073682A_ABST
Abstract
Description
Cross-references to related applications
[0001] This application claims priority and benefit to U.S. Provisional Patent Application No. 63 / 724,262, filed November 22, 2024, and U.S. Non-Provisional Patent Application No. 19 / 096,122, filed March 31, 2025, the contents of which are incorporated herein by reference in their entirety. Background Technology
[0002] A Neutral Host Network (NHN) is a shareable wireless infrastructure that allows one or more Communication Service Providers (CSPs) to use it to provide services to their customers. Typically, an NHN is owned and operated by a third party, who allows CSP subscribers to extend the CSP's network coverage to the NHN. Attached Figure Description
[0003] This disclosure is described in detail with reference to the following figures, based on one or more various examples. These figures are provided for illustrative purposes only and merely depict common, non-limiting aspects of such examples.
[0004] Figure 1 An example network installation of the systems and methods disclosed herein is shown that may be implemented in various applications.
[0005] Figure 2 An example communication system in which the examples of this disclosure can be implemented is shown.
[0006] Figure 3 Examples of methods for use in accordance with the disclosure herein are shown. Figure 2 An example message stream on a communication system for authenticating user equipment for access to a neutral host network.
[0007] Figure 4 Examples of methods for use in accordance with the disclosure herein are shown. Figure 2 Another example message stream on a communication system that authenticates user equipment for access to a neutral host network.
[0008] Figure 5 Examples of methods for use in accordance with the disclosure herein are shown. Figure 2 This is yet another example message stream used in communication systems to authenticate user equipment for access to neutral host networks.
[0009] Figure 6 Another example of a communication system in which the examples of this disclosure can be implemented is shown.
[0010] Figure 7 Examples of methods for use in accordance with the disclosure herein are shown. Figure 6An example message stream on a communication system for authenticating user equipment for access to a neutral host network.
[0011] Figure 8 Computing components that can be used to implement neutral host networks on private cellular networks are shown, according to various examples of the disclosed technology.
[0012] Figure 9 A block diagram of an example computer system in which various examples of the techniques disclosed herein can be implemented is depicted.
[0013] The accompanying drawings are not exhaustive and do not limit this disclosure to the precise form disclosed. Detailed Implementation
[0014] With the demand for reliable and high-capacity mobile connectivity surging, NHN can provide seamless and high-quality wireless services by extending CSP networks to NHN. For example, cellular networks suffer from poor connectivity in indoor environments due to interference from surrounding structures. NHN can extend cellular network coverage to such indoor environments by utilizing private mobile networks (such as NHN) available in those environments.
[0015] As used herein, a CSP refers to an operator (or entity) that provides communication services, such as, but not limited to, mobile phone services, internet services, satellite communications, and cable television. As used herein, a Mobile Network Operator (MNO) refers to a category or type of CSP (e.g., Verizon, AT&T, T-Mobile, etc.) that provides mobile services (including infrastructure, customer service, and billing) through cellular communication networks. MNOs own and maintain their own cellular network infrastructure, known as the core network (or MNO core network). A cellular network can consist of two component networks: the Radio Access Network (RAN) and the core network. In fifth-generation (5G) cellular network systems, these components are the 5G Radio Access Network (5G-RAN) and the 5G Core Network (5GC). In fourth-generation / Long Term Evolution (4G / LTE, or 4G for short) cellular network systems, these components are the Radio Access Network (RAN) and the Evolved Packet Core Network (EPC).
[0016] In some cases, such as stadiums and conference centers, businesses can provide NHN (Natural Radio Networking) through Distributed Antenna Systems (DAS). A DAS is a network of spatially separated antenna nodes connected to a common source, used to provide wireless service within a specific geographic area or structure. Mobile Network Operator (MNO) subscribers can use the DAS to access the network operated by the MNO upon entering the geographic area or structure. However, deploying a DAS can present several challenges, including high installation costs, complex design requirements due to the structure, extensive cabling, potential signal interference, managing multiple MNOs involved, and ensuring proper optimization to balance coverage and capacity within the system—all of which can significantly impact overall project cost and success rate. Therefore, DAS may not be feasible for small and medium-sized enterprises (SMEs).
[0017] An alternative to DAS is a Multi-Carrier Core Network (MOCN). An MOCN can be a single RAN deployed within an enterprise and shared by multiple MNOs. An MOCN includes an MOCN gateway that provides direct connectivity to the core networks of one or more MNOs, allowing subscribers of those MNOs to access their respective core networks within areas covered by the private enterprise network. By providing direct connectivity to the MNO core networks for the MOCN gateway, MOCN deployments can bypass the core network's network functions and authentication protocols.
[0018] However, deploying an MOCN can face several challenges that may hinder enterprise adoption. For example, enterprises may need to ensure device compatibility, manage Service Level Agreements (SLAs) across various MNOs, guarantee Quality of Service (QoS) on shared networks across different MNOs, complete complex interoperability testing, and face potential challenges regarding spectrum allocation, handover management between MNO core networks, and security risks related to bypassing authentication protocols. For instance, if a hospital deploys an MOCN to provide NHN to patients and staff within the hospital, the hospital may need to establish direct connections to each MNO's cellular network via SLAs and resolve the aforementioned complexities. Extending this to multiple different enterprises, each establishing its own direct connections and deploying its own MOCN, can lead to bottlenecks in MOCN deployment. This could be because if MNO subscribers experience poor connectivity or other SLA violations, the MNO may become uninterested in deployment, especially since the MNO does not receive additional revenue or incentives from deploying the MOCN. Additionally, establishing direct connections can be an obstacle for enterprises due to the management of direct connections with different MNOs. Therefore, MOCN adoption progresses slowly.
[0019] Another approach is to extend the MNO's core network to a Wi-Fi network. Passpoint® is a solution released by the Wi-Fi Alliance that allows Wi-Fi networks to be used as an NHN (Normally Accessible Network). For example, when an MNO subscriber enters the coverage area of a specific Wi-Fi network, if the MNO has already enabled Passpoint® for that specific Wi-Fi network, the subscriber can use their MNO credentials to connect to the MNO's core network via the Wi-Fi network. Therefore, the MNO's core network can be extended to a Wi-Fi network. However, because Passpoint® is a protocol defined by the Wi-Fi standard, Passpoint has traditionally been limited to Wi-Fi networks.
[0020] However, with the growing demand for reliable, secure, and high-capacity connectivity, enterprises may seek to deploy private cellular networks within specific geographic areas or structures. Compared to Wi-Fi networks, private cellular networks, especially private 5G cellular networks, can offer improved coverage, higher speeds, and enhanced security due to dedicated radio frequency (RF) spectrum, superior mobility capabilities, and stricter access control via subscriber identification module (SIM) card authentication. These aspects make private cellular networks attractive for enterprise applications where reliable, high-bandwidth connectivity may be critical.
[0021] The examples of techniques disclosed herein provide ways to enable a private cellular network as an NHN by facilitating a connection between the private cellular network and the MNO core network to authenticate the UE for access to the private cellular network using authentication credentials used for accessing the MNO core network. Without the examples disclosed herein, the MNO core network might be located far from the private cellular network (e.g., not connected to it). The examples herein can leverage Passpoint technology, combined with the use of an external credential server (e.g., an authentication, authorization, and accounting (AAA) server located outside the private cellular network to which the subscriber seeks access), to establish an indirect connection between the private cellular network and the MNO core network, so that the private cellular network can use this connection to authenticate unknown UEs.
[0022] For example, 3GPP Release 17 (a standard published by 3GPP) provides a standardized protocol for authenticating UEs using an external credential server. Specifically, when a UE provided to an MNO (e.g., associated with a subscriber to that MNO) attempts to connect to a private cellular network, the examples in this paper can establish an authentication channel, thereby providing an indirect connection between the private cellular network and the MNO. The access request can be routed from the private cellular network to the MNO's core network through this authentication channel for verification of authentication credentials at the MNO's core network. Once verified, the private cellular network can use the authentication credentials to grant the UE access to the private cellular network for accessing the MNO's core network. Therefore, the private cellular network can provide an NHN that extends the MNO's core network to the coverage area of the private cellular network.
[0023] However, traditionally, enterprises using private cellular networks may need to provide a separate SIM card (physical SIM card or eSIM card) for each UE seeking access to the private cellular network. In addition to the cost and complexity of issuing and managing multiple SIM cards, users must also switch back and forth between SIM cards to switch between the private cellular network and the MNO core network depending on which network the UE is trying to connect to at a given time.
[0024] In the illustrative examples of the technology disclosed herein, when a UE provided by an MNO attempts to connect to a base station of a private cellular network, an NHN connectivity system (sometimes referred to herein as the connectivity system) can be configured to facilitate a connection between the private cellular network and the MNO core network for authenticating the UE using authentication credentials provided by the MNO for access to the private cellular network. In this scenario, the NHN connectivity system can establish an authentication channel that provides an indirect connection between the private cellular network and the MNO. The NHN connectivity system can transmit authentication credentials provided by the MNO (e.g., credentials that can be used to authenticate access to the MNO's core network) to the MNO's core network via the private cellular network. The MNO's core network can then use the authentication credentials to authenticate the UE and notify the private cellular network of the authentication via the NHN connectivity system. The private cellular network can then use the authentication with the MNO's core network to grant the UE access to the private cellular network.
[0025] The NHN connectivity system can be configured with Passpoint technology, which can be used to authenticate the UE using authentication credentials from the MNO's core network. For example, the NHN connectivity system can be configured by associating an NHN indicator with a network identifier (referred to herein as the MNO network identifier) that identifies the MNO's core network, based on service information received from the MNO or otherwise corresponding to the MNO. Service information (such as service definitions) can be included in the Service Agreements (SLAs) defining the NHN services provided by the MNO, and the NHN connectivity system can receive these SLAs, which can be used to create a profile for the MNO. The profile can be associated with the MNO network identifier and can include an NHN indicator indicating whether the MNO has enabled (e.g., provided) NHN services to its subscribers. If provided, the configuration can include the NHN indicator, which the NHN connectivity system can use to verify or otherwise determine whether the MNO corresponding to the profile provides NHN services. The absence of an NHN indicator may indicate that NHN services are not provided.
[0026] In the illustrative implementation, a SIM-enabled UE can initiate registration for a mobility function with a private cellular network by sending an authorization request message to the mobility function. The mobility function can refer to, for example, a Private Access and Mobility Management Function (AMF) in the case of a private 5G cellular network or a Mobility Management Entity (MME) in the case of a private 4G cellular network. The authorization request message can include authentication credentials, which include the UE's identifier (referred to herein as the UE identifier) and the MNO network identifier provided to the MNO's core network. In the examples, the UE identifier can be a SIM credential, a Subscriber Hidden Identifier (SUCI), an International Mobile Subscriber Identity (IMSI), etc., depending on the authentication / authorization protocol to be used at the MNO core network. In some examples, the MNO network identifier can be a Public Land Mobile Network (PLMN) ID.
[0027] A private cellular network can translate authorization request messages from mobility functions into access request messages requesting access to the core network of an MNO. The private cellular network can use a desired authentication / authorization protocol (e.g., Remote Authentication Dial-In Subscriber Service (RADIUS), DIAMETER, etc.) to provide the access request message to an NHN connection system configured before receiving the access request message. The NHN connection system can process the access request message to obtain an MNO network identifier, and use the MNO network identifier to locate and check the corresponding profile to verify whether the MNO provides NHN services to its subscribers. If an NHN indicator is found in the profile, the NHN connection system can establish an indirect connection between the private cellular network and the core network of the MNO specified by the MNO network identifier for authenticating authentication credentials (e.g., authentication channels) received from the private cellular network. The NHN can then route the access request message to the MNO's core network via the authentication channel.
[0028] The MNO's core network can authenticate the UE against a database and send an access acceptance message to the NHN connectivity system. The NHN connectivity system can route the access acceptance message to the private cellular network via an authentication channel. Based on the access acceptance message, the private cellular network's mobility functions can grant the UE access to the private cellular network using authentication credentials used to access the MNO's core network.
[0029] As used herein, a “message” or “multiple messages” provided or received from network components (such as private cellular networks and / or MNO core networks) may be provided as one or more data packets. The message and its content may be included in the payload of the corresponding one or more data packets. Data packets may be transmitted through certain interfaces and according to implemented communication protocols as described herein. Example protocols include, but are not limited to, RADIUS, DIAMETER, TLS-based SBI, etc. Additionally, the messages mentioned herein may be transmitted over the RF spectrum via network interfaces.
[0030] The example network installation described herein may be useful, as it can be used to implement the systems and methods disclosed herein in a variety of applications. Figure 1 An example of a network configuration 100 that can be implemented for businesses such as companies, educational institutions, government entities, healthcare facilities or other organizations is shown. Figure 1 An example configuration implemented for an organization with multiple user equipment (or at least multiple UE102A-102J) and physical or geographic sites 110 is shown. Network configuration 100 may include a master site 110 communicating with network 120. Network configuration 100 may also include one or more remote sites (not shown) communicating with network 120.
[0031] The main site 110 may include a main network, which may be, for example, an office network, a home network, or another network installation. The main network may be a private network, such as a network that may include security and access controls to restrict access to authorized users of the private network. Authorized users may include employees of the company located at the main site 110, residents of a residence, customers at the company, etc.
[0032] exist Figure 1 In the example, master site 110 includes controller 115, which communicates with network 120. Controller 115 may provide communication between master site 110 and network 120. In addition to controller 115, master site 110 may also have other communication points with network 120. Although a single device associated with controller 115 is shown, master site 110 may include multiple controllers and / or multiple communication points with network 120. In some examples, controller 115 may communicate with network 120 via a router. In other examples, controller 115 provides router functionality to devices in master site 110. In this specification, the term "tunnel" refers to the encapsulation mode for transmitting data between the AP and the controller.
[0033] Controller 115 is operable for configuring and managing network devices, such as those at the main site 110, and can also manage network devices at remote sites. Controller 115 is operable for configuring and / or managing switches, routers, access points, and / or UEs connected to the network. Controller 115 itself may be an access point (AP), or provide access point (AP) functionality.
[0034] Controller 115 can communicate with one or more switches 118 and / or wireless APs 106A-C. Switches 118 and wireless APs 106A-C provide network connectivity for various UEs 102A-J (sometimes referred to herein as sites or STAs). Using connections to switches 118 or APs 116A-C, UEs 102A-J can access network resources, including the (main site 110) network and other devices on network 120.
[0035] Examples of UEs 102A-102J may include: desktop computers, laptop computers, servers, web servers, tablet computers, e-readers, netbooks, televisions and similar monitors (e.g., smart TVs), content receivers, set-top boxes, personal digital assistants (PDAs), mobile phones, smartphones, smart terminals, dumb terminals, virtual terminals, video game consoles, virtual assistants, Internet of Things (IoT) devices, any SIM-enabled device, and so on. One or more UEs in UEs 102A-102J may be SIM-enabled UEs that have a SIM provided by, for example, an MNO.
[0036] Within the main site 110, switch 118 is included as an example of an access point to the network established in the main site 110 for wired UE 102I-J. UE 102I-J can connect to switch 118 and, through switch 118, can access other devices within network configuration 100. UE 102I-J can also access network 120 through switch 118. UE 102I-J can communicate with switch 118 via wired or wireless connection 112. In the example shown, switch 118 communicates with controller 115 via wired or wireless connection 112.
[0037] Wireless AP 106A-C is included as another example of an access point to the network established for UE 102A-H at main site 110. Each AP in AP 106A-C can be a combination of hardware, software, and / or firmware configured to provide wireless network connectivity to wireless UE 102a-h. Figure 1 In the example, AP 106A-C can be managed and configured by controller 115. AP 106A-C communicates with controller 115 and the network via connection 114, which can be a wired or wireless interface.
[0038] Network configuration 100 may include one or more remote sites (not shown). Remote sites may be located in a different physical or geographical location than the main site 110. In some cases, a remote site may be located in the same geographical location as the main site 110, or in the same building, but lacks a direct connection to the network within the main site 110. Instead, the remote site may utilize a connection through a different network (e.g., network 120). For example, a remote site could be a satellite office or another floor or suite within a building. Remote sites may include gateway devices for communicating with network 120, such as routers, analog-to-digital modems, cable modems, digital subscriber line (DSL) modems, or other network devices configured to communicate with network 120. Remote sites may also include switches (e.g., similar to switch 118) and / or access points (e.g., similar to AP 116A-C) that communicate with the gateway devices via wired or wireless connections. Switches and APs can provide network connectivity for various UEs. Therefore, UEs at remote sites can access network resources at the main site 110 as if they were located at the main site. In such an example, the remote site can be managed by a controller 115 at the main site 110, and the controller 115 provides the necessary connectivity, security, and accessibility, enabling the connection between the remote site and the main site 110. Once connected to the main site 110, the remote site can be used as part of a private network provided by the main site 110.
[0039] Network 120 may be a private cellular network to allow connectivity between the main site 110 (and any remote sites). Network 120 may include third-party telecommunications lines, such as telephone lines, broadcast coaxial cables, fiber optic cables, satellite communications, cellular communications, etc. Network 120 may include any number of intermediate network devices, such as switches, routers, gateways, servers, and / or controllers, which are not directly part of network configuration 100 but facilitate communication between the various parts of network configuration 100 and between network configuration 100 and other network-connected entities.
[0040] In the example, network 120 can be a private cellular network, such as a private 5G cellular network, a private 4G cellular network, etc. In the example, APs 116A-C, switches 118, and controller 115 can be configured as Passpoint APs, Passpoint switches, and Passpoint controllers, respectively, which can provide the ability to extend one or more core networks from core networks 140A-140C (collectively referred to herein as core network 140) to the private cellular network 120. One or more core networks 140 can be core networks operated by one or more MNOs.
[0041] Private cellular network 120 can communicate with NHN connectivity system 130, which is configured to enable the private cellular network as an NHN. For example, NHN connectivity system 130 can be configured to facilitate an indirect connection between private cellular network 120 and MNO core network 140 to authenticate UE 102A-102J for access to private cellular network 120 using authentication credentials provided by MNO core network 140. NHN connectivity system can utilize Passpoint technology to authenticate UE 102A-102J using authentication credentials from one or more core networks 140. In this case, UE 102A-102J can subscribe to one or more MNOs operating core network 140.
[0042] In the example, NHN connectivity system 130 can be configured to facilitate the provision of an indirect connection between a private cellular network and an MNO core network. This indirect connection could be an authentication mechanism used by the private cellular network to authenticate unknown UEs. NHN connectivity system 130 can be configured to associate NHN indicators (e.g., tags, flags, or other indicators) with the MNO network identifiers of one or more MNOs based on service information received from or otherwise corresponding to one or more MNOs. In some examples, service information (such as service definitions) can be included in SLAs that define the NHN services provided by one or more MNOs (e.g., whether such services are provided to subscribers). NHN connectivity system 130 can receive these SLAs and create profiles for one or more MNOs. These profiles can be associated with the MNO network identifiers (e.g., PLMN IDs) associated with one or more MNOs and can include indicators specifying whether the MNO has enabled (e.g., provided) NHN services to subscribers. If provided, the configuration can include the indicator, which NHN connectivity system 130 can process to verify other information; otherwise, it determines that the MNO corresponding to the profile provides NHN services.
[0043] Private cellular network 120 can utilize the authentication channel established by NHN connection system 130 to authenticate UE 102A-J for access to private cellular network 120 using authentication credentials for accessing at least one core network in core network 140. In other words, when a UE provided by an MNO operating one of the core networks in core network 140 attempts to connect to private cellular network 120, private cellular network 120 can grant UE access based on authentication credentials from the UE transmitted through the authentication channel established by NHN connection system 130 configured as described above, using one of the core networks in core network 140. In this example, NHN connection system 130 can be implemented as one or more instances of a cloud-based server or other computer system.
[0044] In the example, private cellular network 120 may include various virtualized network functions (NFs), including but not limited to mobility functions (e.g., AMF in the case of a private 5G cellular network or MME in the case of a private 4G cellular network). As an example, assume UE 102A subscribes to core network 140A operated by a first MNO. When UE 102A enters the coverage area of private cellular network 120 (e.g., primary site 110) and loses connectivity to the RAN of core network 140A, UE 102A can initiate a connection with the mobility functions of private cellular network 120 by sending an authorization request to the mobility functions of private cellular network 120. The authorization request may include authentication credentials from the UE, which may include the UE's identifier (e.g., SIM credentials, SUCI, etc., depending on the authentication / authorization protocol used) and the MNO network identifier of core network 140A (e.g., PLMN ID), as well as other data. Private cellular network 120 can translate the authorization request into an access request, which represents the UE's request to access the core network operated by the MNO specified by the MNO network identifier.
[0045] Private cellular network 120 can send access requests to NHN connectivity system 130 using a desired authentication / authorization protocol (e.g., RADIUS, DIAMETER, TLS-based SBI, etc.). In one example, when using RADIUS as the authentication / authorization protocol, the UE's identifier can be the SIM credential. In another example, when using TLS-based SBI as the authentication / authorization protocol, the UE's identifier can be the SUCI associated with the UE. In yet another example, when using DIAMETER as the authentication / authorization protocol, the UE's identifier can be the IMSI associated with the UE.
[0046] NHN connection system 130 processes access requests to obtain an MNO network identifier and verifies whether the MNO specified by the MNO network identifier allows or provides NHN services to its subscribers. For example, NHN connection system 130 can extract the MNO network identifier from the access request and locate the profile corresponding to the MNO network identifier. NHN connection system 130 determines whether the profile includes an NHN indicator, and if so, determines that the MNO corresponding to the MNO network identifier has enabled NHN services for its subscribers. Based on (e.g., in response to) this determination, NHN connection system 130 can establish an indirect connection between the private cellular network and the MNO core network specified by the MNO network identifier for verifying authentication credentials received from the private cellular network 120. In this case, NHN connection system 130 can then route the access request to the core network 140A, as specified by the MNO network identifier. However, if the profile does not include an NHN indicator, or if the profile cannot be located for the MNO network identifier, NHN connection system 130 may fail to establish an authentication channel and may send an error code back to the private cellular network 120.
[0047] Core network 140A can authenticate the UE against its database and send an access acceptance message to NHN connectivity system 130, which routes the access acceptance message to private cellular network 120. Core network 140A can use any authentication method known in the art. For example, core network 140A can use, but is not limited to, Extensible Authentication Protocol Authentication and Key Negotiation (EAP-AKA); EAP-AKA', which is an updated version of EAP-AKA; 5G-AKA; Evolved Packet System Authentication and Key Negotiation (EPS-AKA), etc. Core network 140A can be configured to select the desired authentication method based on subscriber data and access registration context data stored in its database.
[0048] Then, private cellular network 120 can grant UE 102A access to the private cellular network based on (for example, in response to) an access acceptance message indicating that UE 102A has been authenticated by access core network 140A. In the example, once the UE is granted access to private cellular network 120, the UE can exchange data with Internet 150 (or other external networks) through private cellular network 120.
[0049] Figure 2 An example communication system 200 in which the examples of this disclosure can be implemented is shown. The communication system 200 includes a private network configuration 210, which can be implemented for use by enterprises, such as companies, educational institutions, government entities, healthcare institutions, or other organizations. Network configuration 210 may be... Figure 1An example of network configuration 100 for operating one or more private networks. Figure 2 In the example, network configuration 210 includes a private 5G cellular network 220. Network configuration 210 can grant access to one or more mobile devices 202A-202C to the private 5G cellular network 220.
[0050] Although Figure 2 The example illustrates a private network, but the examples in this document can include multiple networks. For example, network configuration 210 can include a private 5G cellular network 220, as well as a private 4G cellular network and / or a private Wi-Fi network. In another example, network configuration 210 can also include a legacy cellular network (e.g., a private 3G or older network) and / or a future generation cellular network (e.g., a private 6G network).
[0051] A cellular network may include two component networks: a RAN and a core network. In the case of a private 5G cellular network 220, these components are depicted as a private 5G RAN 222 and a private 5G core network (private 5GC), the latter shown as an aggregation of NFs. The private 5G RAN 222 operates to connect individual UEs to the private 5GC. The private 5G RAN 222 may include base stations configured according to 5G standards and connected to the private 5GC network interface. In various examples, a passpoint function may be enabled on the base station. The private 5G RAN 222 can provide wireless communication coverage for the geographic coverage area (e.g., a geographic area or structure of an enterprise) of the network configuration 210. The base stations of the private 5G RAN 222 may include APs (e.g., as described above in conjunction with...). Figure 1 The base station can be described as an eNB, gNodeB (gNB), or another type of base station. The base station can operate in 5G spectrum, which includes low-band spectrum (i.e., sub-1 GHz spectrum), mid-band spectrum (i.e., sub-6 GHz spectrum), and / or high-band spectrum (e.g., millimeter wave (mmWave) operating between 25 GHz and 100 GHz).
[0052] As described above, the private 5GC can include various NFs, including, for example, AMF 224 communicating with Unified Data Manager (UDM) 221 via Authentication Server Function (AUSF) 226. AMF 224 can receive connection and mobility management tasks from UE202A-202C via the private 5G RAN 222 and can process these tasks while forwarding session management tasks / messages to the Session Management Function (SMF). AMF 224 can communicate with AMF 226 via a service-based interface (SBI) (such as the Nasuf interface). Similarly, AMF 226 can communicate with UDM 221 via an SBI (such as the Nudm interface). AMF 224 can authenticate the UE and manage UE handover between access points, base stations, and gNBs in the private 5G RAN 222.
[0053] UDM 221 provides services to other functions of the Service-Based Architecture (SBA), such as AMF 224 and other network functions. UDM 221 can store information in local storage. UDM 221 can also store information externally, such as within the UDR. UDM 221 can provide authentication credentials and is also used by AMF 224 to retrieve user data and access registration context data. That is, for example, UDM 221 can store authentication credentials authorized for access to the private 5G cellular network 220.
[0054] AUSF 226 verifies the identity of the UE user by handling the authentication process. AUSF 226 can determine whether to allow the user to access the private 5G cellular network 220 based on authentication credentials and by interacting with other network functions (such as UDM 221) to retrieve the subscriber data required to complete the process. Typically, AUSF 226 can verify authentication credentials using a SIM card installed on the UE and provided by the operator of the private 5G cellular network 220. When the UE attempts to access the private 5G cellular network 220, AMF 224 can send an authentication request to AUSF 226.
[0055] The private 5GC may also include a proxy signaling controller 229, which can be used to control the flow of messages between the private 5G cellular network 220 and an external network by routing messages between components according to an implemented AAA protocol (e.g., RADIUS, DIAMETER, SBI based on Transport Layer Security (TLS), etc.). For example, the proxy signaling controller 229 can convert messages received from the NF of the private 5G cellular network 220 according to the HTTP protocol into the desired authentication / authorization protocol. For example, messages received by the proxy signaling controller 229 from the AUSF 226 via the Nausf interface according to the HTTP protocol can be converted into the RADIUS protocol and sent to external components via the RadSec (e.g., TLS-based RADIUS) interface. In another example, the proxy signaling controller 229 can convert messages received according to the HTTP protocol into the TLS-based SBI protocol and send them via the SBI.
[0056] The private 5GC may also include a User Planning Function (UPF) 223, which connects the private 5GC to a data network (DN) 225, such as the Internet 250 or other external networks. UPF 223 is a network function that manages data traffic on the private 5G cellular network. UPF 223 can be responsible for packet routing and forwarding, packet inspection, and QoS processing. In the example, once the UE is granted access to the private 5G cellular network 220, UPF 223 can connect the UE to DN 225, which can then be used to exchange data with the Internet 250 (or other external networks).
[0057] Private 5GC may also include other NFs commonly included in the 5G core network, such as, but not limited to, Policy Control Function (PCF), Session Management Function (SMF), Unified Data Repository (UDR), and Network Repository Function (NRF).
[0058] A private 5GC's network function (NF) can be implemented as a computing system, such as one or more servers. The private 5GC's NF can communicate using protocols such as Hypertext Transfer Protocol (HTTP). The NF can be configured according to 5G standards and interfaces. For example, the interface of the NF can be configured according to the protocol used for AAA messages. For instance, AAA messages can be provided via a RadSec (e.g., TLS-based RADIUS) interface according to the RADIUS protocol. In another example, AAA messages can be provided via a TLS-based SBI interface using the TLS-based SBI protocol.
[0059] The communication system 200 also includes one or more cellular networks operated by one or more MNOs. These cellular networks may include corresponding RANs and MNO core networks 240A-240C operated by one or more MNOs (collectively referred to herein as MNO core network 240 or simply MNO core network 240). MNO core network 240 may be part of a respective cellular network operated by the respective MNO. MNO core network 240 may be implemented as any generation of cellular network (e.g., 4G / LTE, 5G, 3G, etc.). MNO core network 240 may include various virtualized NFs.
[0060] For example, as an illustrative example, the MNO core network 240A can be implemented as a 5G core network. In this case, the MNO core network 240A may include an Authentication-Authorization-Accounting (AAA) server 242, an AUSF 244, and a UDM 246, as well as other network functionalities (NFs). The NFs of the MNO core network 240A can be implemented as computing systems, such as one or more servers, which can communicate with each other using protocols such as Hypertext Transfer Protocol (HTTP). The AAA 242 can receive AAA messages provided according to the RADIUS protocol via the RadSec interface, or receive AAA messages provided according to the TLS-based SBI protocol via the TLS-based SBI interface. The AAA 242 facilitates access control over the MNO core network 240A, authenticates valid subscribers of the MNO operating the MNO core network 240A to use the MNO's services, and monitors, audits, and logs operations performed by subscribers. The AUSF 244 provides the means to verify the identity of subscribers by handling the authentication process. The AUSF 244 can determine whether an MNO subscriber is allowed to access the corresponding network based on authentication credentials, and interact with other network functions (such as the UDM 246 of the core network 140A) to retrieve subscriber data, thus completing this process. Typically, the AUSF 244 verifies authentication credentials using the SIM credentials of the SIM card installed on the UE and provided by the operator of the MNO core network 240A. When the UE or other network devices attempt to access the MNO core network 240A, the AMF of the MNO core network 240A can send an authentication request to the AUSF 244. The UDM 246 provides services for other functions of the SBA (such as the AMF of the MNO core network 240A and other network functions). The UDM 246 can store subscriber data, access registration context data, and other information in local memory. The UDM 246 can also store information externally, such as within the UDR. The UDM 246 can provide authentication credentials for access registration context data. In other words, for example, UDM 246 can store authentication credentials authorized for use by subscribers accessing the MNO core network 240A. The MNO core network 240A may also include other NFs, such as, but not limited to, AMF, UPF, PCF, SMF, UDR, NFR, etc., as known in the art.
[0061] MNO core networks 240B and 240C can include configurations similar to those of MNO core network 240A. For example, MNO core networks 240B and / or 240C can be 5G core networks including AMF, UDM, AUSF, UPF, PCF, SMF, UDR, NFR, etc. In another example, one or more MNO core networks among MNO core networks 240A-240B can be different core networks, such as EPC or other traditional cellular networks (e.g., as follows). Figure 6(As described in the example). In the case of EPC, the core network may include AAA, MME, and HSS, as well as other NFs known in the art.
[0062] In the example, the private 5G cellular network 220 can be configured to provide an NHN that extends one or more MNO core networks 240A-240C to the private 5G cellular network 220. For example, the communication system 200 includes an NHN connectivity system 230, which may be... Figure 1 An example implementation of the NHN connectivity system 130 is provided. The NHN connectivity system 230 can be configured to provide a Passpoint solution to authenticate the UE using authentication credentials provided by one or more MNO core networks 240 for access to the private 5G network 220. In this case, UEs 202A-202C can subscribe to one or more MNOs operating the MNO core network 240. The NHN connectivity system 230 can be configured with service information (e.g., SLAs) corresponding to the MNOs, specifying those MNOs that have enabled NHN services using the NHN connectivity system 230. In the example, service information can be extracted from the SLAs and used to generate profiles, which can be stored based on the MNO network identifier (e.g., PLMNID) of the MNO party to the SLA, as described above. The profiles and MNO network identifiers can be stored in a data repository 234.
[0063] As an illustrative example, UE 202A can connect to MNO core network 240A via 5G RAN 270. In this case, UE 202A can be provided by the MNO operating MNO core network 240A, and therefore, MNO core network 240A can store UE 202A's authentication credentials. When UE 202A moves to a geographic area or structure served by private network configuration 210, for example, when connectivity with MNO core network 240A via 5G RAN 270 is lost (e.g., the connection to 5G RAN 270 falls below a threshold RSSI value or a similar metric), UE 202A can attempt to switch from MNO core network 240A to private 5G cellular network 220. UE 202A can establish a connection with private 5G RAN 222 according to known technologies.
[0064] Once the connection is established, UE 202A can initiate registration with the private 5G cellular network 220. For example, UE 202A can send a registration request message to AMF 224. AMF 224 can send a UE ID request message to UE 202A, and UE 202A can send a UE response message. The UE response message may include authentication credentials, such as the identifier of UE 202A (e.g., SIM credentials, SUCI, etc., depending on the authentication / authorization protocol used at the MNO core network) and the MNO network identifier (e.g., PLMN ID) provided to the MNO's core network by the UE.
[0065] AMF 224 can extract the UE identifier and construct an authorization request message, which requests authentication of the UE identifier using the UE identifier. The private 5G network 220 can convert the authorization request message into an access request message, which requests access to the MNO core network 240 corresponding to the MNO network identifier.
[0066] Access request messages can be sent to NHN connection system 230 using a desired authentication / authorization protocol (e.g., RADIUS, DIAMETER, etc.). NHN connection system 230 processes the authorization request to obtain an MNO network identifier and checks the configuration file corresponding to that MNO network identifier in data repository 234. As described above, the configuration file is generated based on service information in the SLA with the MNO. If a configuration file for the MNO network identifier is found in data repository 234, NHN connection system 230 checks if the configuration file contains an NHN indicator indicating whether the MNO has enabled NHN services. If NHN services are enabled, NHN connection system routes the authorization request to the core network of the MNO specified by the MNO network identifier (e.g., MNO core network 240A in this example, as shown in authentication path 204). MNO core network 240A authenticates UE 202A against its database using the UE's identifier according to the desired authentication / authorization protocol, and once authenticated, sends an access acceptance message to NHN connection system 230. During the above process, the NHN connection system 230 can maintain the association between the authorization request and the private network identifier.
[0067] NHN connectivity system 230 uses a private network identifier to route the access acceptance message to AMF 224 to locate the initiating private 5G cellular network 220. AMF 224 can grant UE 202A access to the private 5G cellular network 220 based on (e.g., in response to) the access acceptance message. Once granted, data traffic from UE 202A can be routed to DN 225 via UPF 223 (and ultimately to the Internet 250 or other external networks), as shown in data traffic path 206.
[0068] Figure 3 An example message flow 300 for authenticating a UE to access the NHN, according to the examples disclosed herein, is shown. Message flow 300 can be executed by communication system 200, and therefore will be referenced to... Figure 2 Described as an illustrative example. Figure 3 An authentication method is shown in which a UE (such as UE 202A) can be authenticated using the 5G-AKA method for use as an NHN access private 5G cellular network 220.
[0069] exist Figure 3 In the example, the private 5G cellular network 220 can initiate the authentication process after receiving a signaling message from UE 202A. For instance, UE 202A can establish a connection with the private 5G RAN 222 when entering the coverage area of the private 5G cellular network 220 and attempting to hand over from the MNO core network. After the connection is established, AMF 224 can initiate UE 202A's registration 302 on the private 5G cellular network by requesting authentication credentials from UE 202A, and UE 202A can respond using its authentication credentials.
[0070] exist Figure 3 In the example, the authentication credential can be the SIM credential of UE 202A, which may include the identifier of UE 202A and, for example, the MNO network identifier provided to the MNO core network 240A in this example.
[0071] exist Figure 3In the example, once AMF 224 receives the SIM credentials of UE 202A, AMF 224 forwards an authentication request message 304a, including the SIM credentials, to AUSF 226. In this example, AMF 224 can forward the authentication request message 304a via the Nausf interface. AUSF 226 can attempt to verify the SIM credentials by interacting with UDM 221. For example, AUSF 226 can send an authentication request message 304b to UDM 221 via the Nudm interface to verify the SIM credentials. The authentication request message 304b can be a Nudm_UEAuthentication_Get_Request including the SIM credentials. At procedure 304c, UDM 221 attempts to authenticate the SIM credentials by decrypting the SUCI and checking the access registration context data against the SUPI. However, in this case, UDM 221 cannot authenticate the SIM credentials because it does not have the corresponding private key, and UE 202A has not registered with UDM 221. UDM 221 sends an authentication failure response message 304d to AUSF 226 via the Nudm interface, for example as Nudm_UEAuthentication_Get_Response.
[0072] In response to authentication failure, AUSF 226 constructs an authentication request message 304e and sends the authentication request message 304a to the proxy signaling controller 229. For example, AUSF 226 can provide the authentication request message 304e through the Nausf interface as a Nausf_UEAuthentication_authentication_request (SIM credential).
[0073] The proxy signaling controller 229 forwards the authentication request message 304e as an access request message 306 to the NHN connection system 230. For example, the proxy signaling controller 229 converts the authentication request message 304e, which was sent using the HTTP protocol, to the RADIUS protocol and sends the access request message 306 through the RadSec interface. In one example, the access request message can be provided as "RADIUS: Access-Request (SIM credential)". The access request message 306 can be operated to request access to the MNO core network 240A to obtain the SIM credential included in the access request message 306.
[0074] NHN connection system 230 can be configured to identify the MNO core network 240 for access request message 306 by processing access request message 306. NHN connection system 230 can execute process 308 to obtain SIM credentials and extract the MNO network identifier from them (e.g., extract the PLMN ID from the "domain" of the SIM credentials). NHN connection system 230 can be configured with the service information and configuration file as described above before receiving access request 306. Process 308 can check data repository 234 to obtain the configuration file corresponding to the MNO network identifier of MNO core network 240A. If the configuration file is located, NHN connection system 230 determines whether the configuration file contains an NHN indicator that indicates that the MNO has provided NHN services to its subscribers. If the NHN indicator exists, NHN connection system 230 determines that the MNO corresponding to the MNO network identifier has enabled NHN services for its subscribers. Based on (e.g., in response to) this determination, NHN connection system 230 establishes an authentication channel (e.g., an indirect connection) between the private cellular network and the core network of the MNO designated by the MNO network identifier, for authenticating authentication credentials received from the private cellular network 120. This indirect connection (e.g., the authentication channel) in... Figure 2 The portion 204A-204C of the authentication path 204 is illustratively depicted. In this case, the NHN connection system routes the access request message 306 to the MNO core network 240A, identified by the SLA as access request message 310. Access request message 310 may be substantially similar to access request message 306. In some examples, the NHN connection system 230 may route the access request directly to the MNO core network 240. In another example, the NHN connection system 230 may forward the authorization request to the MNO core network 240A via optional roaming proxy hubs 260A and / or 260B. These roaming proxy hubs 260A and 260B may be proxy partners connected to multiple MNOs to handle intermediate routing to the appropriate network, as known in the art.
[0075] If the configuration file for the MNO network identifier does not exist in the data repository 234, or if the located configuration file does not include the NHN indicator, the NHN connection system 230 can use the private network identifier to send an error code back to the private 5G cellular network 220. Therefore, UE 204A may not be granted access to the private 5G cellular network 220.
[0076] Upon receiving the access request message 310, the MNO core network 240A can authenticate the UE 202A against its database using SIM credentials according to the 5G-AKA method. For example, AAA 242 receives the access request message 310 via the RadSec interface according to the RADIUS protocol and converts it into HTTP protocol for transmission as an authentication request message 312 to AUSF 244 via the Nausf interface of the MNO core network 240A. For example, AAA 242 converts the access request message 310 into an authentication request message 312, which can be provided as Nausf_UEAuthenticate_AuthenticateRequest via the Nausf interface. Message 312 may include the SNid of the private 5G cellular network 220 and the SIM credentials of the UE 202A.
[0077] AUSF 244 receives authentication request message 312 and verifies whether the private 5G cellular network 220 requesting authentication service is authorized to obtain such service. AUSF 244 can check the SNid against a stored identifier of an authorized private cellular network, and if present, verify the private 5G cellular network 220. After verification, AUSF 244, for example, uses the Nudm interface of the MNO core network 240A to send an authentication request message 314 to UDM 246 to authenticate the SIM credentials. The authentication request message 314 can be a Nudm_UEAuthentication_Get_Request that includes the SIM credentials and SNid.
[0078] Upon receiving message 314, UDM 246 can obtain the SIM credentials and extract the SUCI. The SUCI can be decrypted to obtain the SUPI, which can be used to select the authentication method configured for the subscriber corresponding to the SUPI. In this case, the authentication method is 5G-AKA. 5G-AKA can be initiated by sending an Authentication Response Message 316 with an Authentication Vector (AV) and the SUPI to AUSF 244. The AV may include an Authentication (AUTH) token, an Expected Response (XRES) token, and other data. The XRES token may be subscriber-specific and obtained by the UDM, for example, obtained from the access registration context data using the SUPI to locate subscriber-specific information. The AUTH token may be associated with the MNO core network 240A. In one example, UDM 246 can send the Authentication Response Message 316 via the Nudm interface, for example, as Nudm_UEAuthentication_Get_Response(AV,SUPI).
[0079] AUSF 244 executes process 317 to obtain the AV from the retrieval authentication response message 316 and calculates the hash (HXRES) of the XRES. AUSF 244 stores the XRES and HXRES and constructs the authentication response message 318. The authentication response message 318 may include the AV, as well as HXRES, SUCI, and SNid. AUSF 244 can provide the authentication response message 318 as Nausf_UEAuthentication_AuthenticateResponse(AV, SUCI, SNid) to AAA 242 via the Nausf interface.
[0080] AAA 242 converts the authentication response message 318 sent using the HTTP protocol into the RADIUS protocol and sends the authentication response message 318 as an Access Challenge message 320 to the NHN connection system 230 via the RadSec interface. The Access Challenge message 320 may include AV, as well as HXRES, SUCI, and SNid. In one example, the Access Challenge message 320 may be provided as "RADIUS:Access-Challenge(AV, SUPI, SNid)".
[0081] The NHN connectivity system 230 routes the access challenge message 320 to the proxy signaling controller 229 via authentication channels 204A-204C. For example, the NHN connectivity system 230 executes process 322 to obtain the SNid from the access challenge message 320 and identify the private 5G cellular network 220 that issued the authentication request message corresponding to the access challenge message 320 (e.g., message 306). The network management 220 can locate the corresponding authentication channel and forward the access challenge message 320 as access challenge message 324 to the proxy signaling controller 229 of the identified private 5G cellular network 220.
[0082] The proxy signaling controller 229 forwards the access challenge message 320 as an authentication response message 326 to the AMF 224. For example, the proxy signaling controller 229 converts the access challenge message 324 received via the RadSec interface according to the RADIUS protocol into HTTP protocol and sends the authentication response message 326 via the Niwf interface. The authentication response message 326 can be provided as Niwf_UEAuthenticate_authenticate_Response(AV, SUPI).
[0083] AMF 224 authenticates UE 202A 328 based on the content of authentication response message 326. For example, AMF 224 obtains AV from authentication response message 326 and extracts HXRES and AUTH token. HXRES can be stored in memory, and the AUTH token can be sent to UE 202A as an authentication request. UE 202A uses the key (K) shared with MNO core network 240A. i The AUTH token is verified. If the AUTH token verification is successful, UE 202A considers the private 5G cellular network to be authenticated. UE 202A can continue authentication by calculating a response (RES) token and sending the RES token to AMF 224 in the authentication response message. AMF 224 calculates the hash (HRES) of the RES token and compares HRES with HXRES to verify the response at procedure 329. If HRES and HXRES are substantially equal, AMF 224 considers UE 202A to be authenticated.
[0084] Based on successful authentication, AMF 224 then constructs an authentication request message 330 including the RES token, SIM credential, and SNid. The authentication request message 330 can be provided to the proxy signaling controller 229, for example, via the Niwf interface as Niwf_UEAUthenticate_authenticate_Request(RES, SIM credential, SNid).
[0085] The proxy signaling controller 229 forwards the authentication request message 330 as an access request message 332 to the NHN connectivity system 230. For example, the proxy signaling controller 229 converts the authentication request message 330, which was sent using the HTTP protocol, into the RADIUS protocol and sends the access request message 332 through the RadSec interface. In one example, the access request message could be provided as "RADIUS:Access-Request(RES, SIM credential)".
[0086] NHN connectivity system 230 can be configured to identify the MNO core network 240 for access request message 332 by processing access request message 332. For example, NHN connectivity system 230 can perform process 334 to obtain SIM credentials and extract the MNO network identifier from them, similar to process 308 described above. NHN connectivity system 230 can route access request message 332 as access request message 336 to AAA 242 via authentication channels 204A-204C. AAA 242 converts access request message 332 into HTTP protocol for transmission to AUSF 244 as authentication request message 338 via the Nausf interface, for example, as described above in conjunction with authentication request message 312. Authentication request message 338 may include the SNid of private 5G cellular network 220, SIM credentials of UE 202A, and RES.
[0087] AUSF 244 performs procedure 340 to make a final decision regarding authentication. For example, AUSF 244 obtains the RES token from the authentication request message 338 and verifies whether the RES token matches the XRES token (e.g., is substantially equal). If the RES token is valid, AUSF 244 calculates the anchor key (K). SEAF This message, along with the SUPI, is sent as authentication response message 342 to the private 5G cellular network 220. The AUSF 244 can then use the Nausf interface to send authentication response message 342 as Nausf_UEAuthentication_AuthenticateResponse(Success, SUPI, K...). SEAF The authentication response message 342 (SNid) is provided to AAA242. AAA244 converts the authentication response message 342 sent using the HTTP protocol into the RADIUS protocol and sends the authentication response message 342 as an access acceptance message 344 to NHN connection system 230 via the RadSec interface. The access acceptance message 344 may include a success identifier, as well as SUCI, SNid, and K. SEAF In one example, the access acceptance message 344 can be provided as "RADIUS:Access-Accept(Success, SUPI, K..." SEAF )".
[0088] The NHN connectivity system 230 routes the access acceptance message 344 to the proxy signaling controller 229 via authentication channels 204A-204C. For example, the NHN connectivity system 230 executes process 346 to obtain the SNid from the access acceptance message 344 and identify the private 5G cellular network 220. The NHN connectivity system 230 can then forward the access acceptance message 344 as an access acceptance message 348 to the proxy signaling controller 229 of the identified private 5G cellular network 220.
[0089] The proxy signaling controller 229 forwards the access acceptance message 348 as an authentication response message 350 to the AMF 224. For example, the proxy signaling controller 229 converts the access acceptance message 348 received via the RadSec interface according to the RADIUS protocol into HTTP protocol and sends the authentication response message 350 via the Niwf interface. The authentication response message 350 can be provided as Niwf_UEAuthenticate_authenticate_Response(Success, SUPI, K) SEAF The authentication process is completed (352) upon receiving the authentication response message (350), and the UE 202A can be granted access to the private 5G cellular network.
[0090] Figure 4 An example message flow 400 for authenticating a UE to access the NHN, according to the examples disclosed herein, is shown. Message flow 400 can be executed by communication system 200, and therefore will be referenced to... Figure 2 Described as an illustrative example. Figure 4 An authentication method is shown in which a UE, such as UE 202A, can be authenticated for access to a private 5G cellular network 220 using the EAP-AKA method.
[0091] Figure 4 The message can be similar to Figure 3 The message stream contains 300 messages. Therefore, Figure 4 Following the numbering convention, the first number corresponds to Figure 4 The remaining numbers identify the messages in the diagram. For example, reference numeral 306 refers to... Figure 3 The message "306" in the middle, and similar messages can be generated by Figure 4 The reference numeral 406 is used to identify the element. Unless otherwise stated herein, the description of a similar element may apply to other similar messages. For example, messages 406-414 may resemble... Figure 3 The same applies to messages 306-314, and the above description of messages 306-314 can also be applied to messages 406-414.
[0092] Similarly, messages 416-452 can be similar to messages 316-352, and the above regarding... Figure 3 The description can be applied to messages 416-452. However, in Figure 4 In the example, upon receiving message 414, UDM 246 can extract SUCI and obtain SUPI (as described above), and select the authentication method configured for the subscriber. Figure 4 In this case, the method is the EAP-AKA' method. The EAP-AKA' can be initiated by UDM 246 to generate an EAP-AKA'AV at procedure 415 based on the Acquire Authentication Request message 315. The EAP-AKA'AV may include the expected AKA' response and AKA' challenge, as well as other data. The AKA' challenge may include an AUTH token, a key derivation function (KDF), a MAC (Message Authentication Code), and the network identifier of the MNO core network 240A, as well as other data. UDM 246 may send the Acquire Authentication Response message 416 along with the EAP-AKA'AV and SUPI to AUSF 244. The EAP-AKA'AV can replace the AV used in the 5G-AKA method. Therefore, messages 418-426 are substantially similar to messages 318-326, except that messages 418-426 include an AKA' challenge instead of an AV.
[0093] At authentication 428, AMF 224 authenticates UE 202A based on the content of authentication response message 426. For example, AMF 224 obtains the AKA' challenge from authentication response message 426 and provides the AKA' challenge to UE 202A, which provides the AKA' challenge response to AMF 224. The AKA' challenge sent to UE 202A at authentication 428 may include the AUTH token, MAC address, KDF (Key Authentication Function), and network identifier. UE 202A uses a shared key (KDF) to... i The AUTH token is verified, and a response (RES) token to the AKA' challenge is calculated, which is included in the AKA' challenge response. Then, the AMF 224 constructs an authentication request message 430, which includes the AKA' challenge response, SIM credentials, and SNid. The authentication request message 430 can be provided to the proxy signaling controller 229 via the Niwf interface as Niwf_UEAUthenticate_authenticate_Request(AKA' challenge response, SIM credentials, SNid).
[0094] Messages 432-438 can be similar to messages 332-338, except that the RES token in each message can be replaced with an AKA' challenge response (which may include the RES token). Upon receiving authentication request message 338 with an AKA' challenge response, AUSF 244 executes procedure 340 to make a final decision about authentication by verifying the EAP-AKA' response against the expected EAP-AKA' response. If the EAP-AKA' response is valid (e.g., substantially the same as the expected EAP-AKA' response), AUSF 244 will calculate the anchor key (K). SEAF This is then sent along with SUPI as authentication response message 442 to the private 5G cellular network 220, similar to authentication response message 342 described above. Then, messages 444-452 are... Figure 3 The messages 344-352 are presented in a similar manner.
[0095] Additionally, in Figure 4 In the example, UE 202A and AMF 224 initiate registration 402 in a manner similar to the aforementioned registration 302. Figure 4 In the example, once AMF 224 receives the SIM credentials of UE 202A, AMF 224 sends an authentication request message 404 to the proxy signaling controller 229. Authentication request message 404 is substantially similar to authentication request message 304e, except that authentication request message 404 can be provided by AMF 224 via the Niwf interface as Niwf_UEAuthentication_authentication_reqeust(SNid, SIM credentials). In this case, AMF 224 can be configured to determine that UE 202A has not been authenticated to access the private 5G cellular network 220. For example, AMF 224 can be configured to obtain the MNO network identifier from the SIM credentials. In this example, the SIM credentials will include the MNO network identifier (e.g., PLMN ID), and AMF 224 can determine that the network specified by the MNO network identifier in the SIM credentials is not part of the private 5G cellular network 220 (e.g., the PLMN ID is not recognized by AMF 224). Based on this determination, AMF 224 can construct an authentication request message 404 and send it to the agent signaling controller 229 without querying AMF 226 and / or UDM 221.
[0096] In another example, message flow 400 may include messages 304a-304e in place of authentication request message 404. Therefore, message flow 400 may reference AUSF 226 and / or UDM 221, as described above. Figure 3As described. Similarly, message flow 300 can replace messages 304a-304e with authentication request message 404, thereby sending the authentication request message directly to the proxy signaling controller 229.
[0097] Figure 5 Another example message flow 500 for authenticating a UE to access the NHN, based on the examples disclosed herein, is shown. Message flow 500 can be executed by communication system 200, and therefore will be referenced to... Figure 2 Described as an illustrative example. Figure 5 An authentication method is shown, in which the EAP-AKA method via SBI (in combination with, for example) can be used. Figure 4 The described RADIUS method (in contrast) authenticates UEs such as UE 202A for access to a private 5G cellular network 220, which acts as an NHN. Therefore, for example, the private 5G cellular network 220 can use a TLS-based SBI protocol to provide messages to the MNO core network 240 (e.g., MNO core network 240A in this example) via SBI. More specifically, in Figure 5 In the example, AMF 224 can send messages to AUSF 244 via NHN connection system 230.
[0098] Figure 5 The message can be similar to a message in message stream 400. Therefore, Figure 5 Following the numbering convention, the first number corresponds to Figure 4 The remaining numbers identify the messages in the diagram. For example, reference numeral 404 refers to... Figure 4 The message "404" in the text, and similar messages can be generated by Figure 5 The reference numeral 506 is used to identify it. Unless otherwise stated herein, the description of a similar element may apply to other similar messages. Note that because SBI is used to transmit messages between the private 5G cellular network 220 and the MNO core network 240A, Figure 4 Some of the messages shown were not included. Figure 5 middle.
[0099] For example, messages 502-552 can be similar to Figure 4 Messages 402-452, and the description of messages 402-452 above also applies to messages 502-552. However, in Figure 5In the example, SUCI can be included in authentication request message 504 using SBI. In this case, authentication request message 504 can be provided by AMF 224 via the Nausf interface of MNO core network 240A as Nausf_UEAuthentication_authentication_Reqeust(SNid, SUCI). Message flow 500 proceeds in a similar manner to message flow 400, except that some messages with AAA 242 and proxy signaling controller 229 may be excluded due to the use of SBI for communication.
[0100] Figure 6 An example of a communication system 600 in which the embodiments of this disclosure can be implemented is shown. The communication system 600 includes a private network configuration 610, which can be implemented for use by enterprises, such as companies, educational institutions, government entities, healthcare institutions, or other organizations. Network configuration 610 may be... Figure 1 An example of network configuration 100 for operating one or more private networks. Figure 6 In the example, network configuration 610 includes a private 4G cellular network 620. Network configuration 610 can grant privileges to one or more UEs 602A-602C (which can be connected to...). Figure 2 (UE 202A-202C is the same or substantially similar) accesses the private 4G cellular network 620.
[0101] Although Figure 6 The example shown here is of only one private network, but the examples in this document can include multiple networks. For example, network configuration 610 can include a private 4G cellular network 620, and a private 5G cellular network (e.g., Figure 2 A private 5G cellular network 220 and / or a private Wi-Fi network. In another example, network configuration 610 may also include a legacy cellular network (e.g., a private 3G or older network) and / or a future generation cellular network (e.g., a private 6G network).
[0102] exist Figure 6 In this context, the private 4G cellular network 620 may include a private RAN 622 and a private EPC (shown as an aggregation of NFs). The private RAN 622 operates to connect individual UEs to the private EPC. The private RAN 622 may include base stations configured according to 4G / LTE standards and interfaced with the private EPC. In various examples, a passpoint function may be enabled on the base station. The private RAN 622 can provide wireless communication coverage for the geographic coverage area of network configuration 610 (e.g., a geographic area or structure of an enterprise). The base station of the private RAN 622 may include APs (e.g., as described above in conjunction with...). Figure 1These can be described as eNB, gNodeB (gNB), or another type of base station. These base stations can operate in the 4G / LTE spectrum.
[0103] The private EPC includes various network functions (NFs), including, but not limited to, one or more MME 624s (sometimes called Mobility Management Devices (MMDs)), Home Subscriber Servers (HSS) 626, and Diameter Routing Agents (DRAs) 629. The private EPC may also include Serving Gateways (S-GWs), Packet Data Network (PDN) gateways, and other network function entities. The MME 624 can receive connection and mobility management tasks from UEs 602A-602C via the private RAN 622 and can process connection and mobility management tasks while forwarding them.
[0104] The MME 624 can communicate with the HSS 626 via a designated interface (e.g., the DIAMETER interface), which is used to exchange subscriber authentication, location, and server information between the HSS 626 and the MME 624. The MME 624 can act as a control node, handling signaling between the UE 602A-602C and the proprietary EPC, including providing bearer and connection management functions. The PDN gateway can connect to IP services such as the Internet, intranets, IP Multimedia Subsystem (IMS), packet-switched (PS) streaming services, and / or other IP services.
[0105] HSS 626 can be a database for storing subscriber information. Subscriber information may include authentication keys, service profiles, and location data, as well as other data indexed according to the subscriber. For example, subscriber data can be indexed by a UE identifier (such as IMSI). Therefore, HSS 626 can store subscription information for subscribers that has been authenticated through access to the private 4G cellular network 620.
[0106] DRA 629 is an NF that provides routing functionality and ensures that messages are correctly routed between NFs. For example, DRA 629 can be configured to ensure that received messages are routed to internal functions or external systems as appropriate.
[0107] A private EPC's NF can be implemented as a computing system, such as one or more servers. The EPC's NF can communicate using protocols such as the DIAMETER protocol. For example, the DIAMETER protocol can be used for messages between MME 624 and HSS 626, or DRA629 and HSS 626. Data included in messages on the EPC can be formatted according to the American Standard Code for Information Interchange (ASCII) protocol.
[0108] The communication system 600 also includes one or more cellular networks operated by one or more MNOs. These cellular networks may include corresponding RANs and MNO core networks 640A-640C operated by one or more MNOs (collectively referred to herein as MNO core network 640, or simply as MNO core network 640). MNO core network 640 can be combined with the above. Figure 2 The MNO core network 240 described is the same as or substantially similar to that described above. Therefore, the MNO core network 640 can be part of a cellular network operated by a respective MNO and can include virtualized NFs as described above.
[0109] As an example, the MNO core network 640B can be implemented as an EPC. In this case, the MNO core network 640B may include an HSS 644 and other NFs as known in the art. The NFs of the MNO core network 640B can be implemented as computing systems, such as one or more servers, which can communicate with each other using protocols such as the DIAMETER protocol. The HSS 644 is a database that stores subscriber information of the MNO corresponding to the MNO core network 640B, which can be used to authenticate UEs attempting to connect to the EPC. The HSS 644 can be accessed to verify the identity of a subscriber by retrieving the subscriber information used for authentication. In the context of a Global System for Mobile Communications (GSM) network, the HSS functionality can be provided by a Certification Authority (AuC).
[0110] In the example, a private 4G cellular network 620 can be configured to provide an NHN that extends one or more MNO core networks 640 to the private 4G cellular network 620. For example, communication system 600 includes an NHN connectivity system 630 configured to provide a Passpoint solution for authenticating the UE using authentication credentials provided by one or more MNO core networks in the MNO core network 640. The NHN connectivity system 630 can be combined with the above. Figure 2 The NHN connectivity system 230 described is the same as or substantially similar to this system. UEs 602A-602C can subscribe to one or more MNOs operating the MNO core network 640, and these MNOs can provide Passpoint profiles. The NHN connectivity system 630 can be configured according to an SLA with the MNOs, which specifies which MNOs have enabled NHN services, and these services utilize the NHN connectivity system 630's storage based on the MNO network identifier (e.g., PLMN ID), for example, as described above. Figures 1 to 3 As described.
[0111] In some examples, the NHN connectivity system 630 can establish authentication channels 604A-604C and forward access requests to the MNO core network 640 via optional roaming proxy hubs 660A and / or 660B. These roaming proxy hubs 660A and 660B can interact with... Figure 2 The roaming agent hubs 260A and / or 260B are the same or substantially similar.
[0112] Figure 7 An example of a message flow 700 for authenticating a UE on a communication system 600 for accessing an NHN, according to the examples disclosed herein, is shown. Message flow 700 can be performed by the communication system 600. Figure 6 An authentication method is shown in which a UE such as UE 602B can be authenticated via the DIAMETER interface using the EPS-AKA method and the DIAMETER protocol for access to a private 5G cellular network 220 of the NHN.
[0113] Prior to message flow 700, UE 602B can connect to the MNO core network 640B via RAN 670. In this case, UE 602B can be configured by the MNO operating the MNO core network 640B, and therefore, the MNO core network 640B can store the authentication credentials of UE 602B at HSS 644. When UE 602B moves to a geographic area or structure served by private network configuration 610, UE 602B can attempt to switch from the MNO core network 640B to the private 4G cellular network 620. UE 602A can establish a connection with the private RAN 622 by completing the Radio Resource Control (RRC) procedure according to known techniques.
[0114] Once the connection is established, UE 602B can initiate an attachment to the private 4G cellular network 620. For example, the UE sends an attachment request message 702 to MME 624. This attachment request message 702 may include authentication credentials for UE 602B. Among other data, these credentials may also include the identifier of UE 602B (e.g., the UE's IMSI) and the MNO network identifier of the core network to which the UE is provided (e.g., the PLMN ID of the MNO core network 640B in this example). In one example, the authentication credentials may be SIM credentials provided by UE 602B in NAI format. For example, the SIM credentials may be provided as "username@realm", where "username" is the UE identifier (e.g., the IMSI in this example), and "realm" includes the MNO network identifier that configures the MNO core network. In this example, "realm" may be provided as "epc.mnc". <mnc>.mcc <mcc>.3ggpnetwork.org, where "epc" indicates that the SIM certificate is a 4G certificate.
[0115] MME 624 can send an authentication request message 704 (an example of an access request message in this example) to HSS 644, which is destined for MNO core network 640B. The authentication request message 704 may include a UE identifier and a private network identifier of the private 4G cellular network 620 (e.g., the SNid of the private 4G cellular network 620). The authentication request message 704 can communicate using a desired authentication / authorization protocol (e.g., DIAMETER, etc.). For example, the authentication request message 704 can be provided as an "Authentication Information Request (SNid, IMSI)" communicated according to the DIAMETER protocol.
[0116] Authentication request message 704 is sent to DRA 629, which routes it via, for example, the DIAMETER interface to NHN connection system 630 as authentication request message 706. NHN connection system 630 processes authentication request message 706 at process 708 to obtain the MNO network identifier and checks the configuration file corresponding to that MNO network identifier in data repository 634. Process 708 can be related to the above... Figure 3 The process 308 is essentially similar. If the configuration file for the MNO network identifier is found in the data repository 634 and it is determined that it includes the NHN indicator, then the NHN connection system 630 establishes authentication channels 604A-604C and routes the authentication request message 706 to the HSS 644 on the MNO core network (e.g., MNO core network 640B in this example) of the MNO specified by the MNO network identifier, as authentication request message 710 (e.g., MNO core network 640B in this example, as...). Figure 6 The authentication path is shown in 604.
[0117] At procedure 712, HSS 644 generates an AV based on authentication request message 710. For example, HSS 644 generates an AV based on a key shared with the UE (K). i Perform encryption operations to export the AV. The AV may include the AUTH token and XRES token, as well as other data.
[0118] HSS 644 sends the AV in the authentication response message to the MME via authentication channels 604A-604C. For example, HSS 644 sends the authentication response message 714 to NHN connection system 630. For example, the authentication response message 714 can be provided as an "Authentication Information Response (SNid, AV)" communicated according to the DIAMETER protocol. NHN connection system 630 routes the authentication response message 714 as authentication response message 718 to DRA 629. For example, NHN connection system 630 performs process 716 (which can be substantially similar to process 322) to obtain the SNid from the authentication response message 714 and identify the private 4G cellular network 620 that issued the authentication request message 706. Then, NHN connection system 630 forwards the authentication response message 714 as authentication response message 718 to DRA 629. DRA 629 forwards the authentication response message 718 as authentication response message 720 to MME 624.
[0119] Upon receiving the authentication response message 720, MME 624 and UE 602B perform authentication 722 on the UE for access to the MNO core network 640B, and grant UE 602B access to the private 4G cellular network 620 based on the authentication with the MNO core network 640B. For example, MME 624 sends an authentication request to UE 602B including an AUTH token. UE 602B then authenticates the AUTH token with a key-based authentication method (K). i The generated token is compared to verify the AUTH token. If the verification is successful (e.g., the generated token matches or is substantially equal to the AUTH token), the UE 602B considers the network legitimate and sends an authentication response message back to the MME 624, including the RES token, which can also be based on the key (K). i )generate.
[0120] MME 624 compares the RES token with the XRES token. If they match or are substantially equal, MME 664 considers UE 602B to have been authenticated for access to the MNO core network 640B, and grants UE 602B access to the private 4G cellular network 620 based on this authentication. Once granted, data traffic from UE 602B can be routed to the PDN gateway (and ultimately to the Internet or other external networks), similar to... Figure 2 DN 225.
[0121] Figure 8 A computing component is shown that can be used to implement a neutral host network on a private cellular network according to various examples of the disclosed technologies. Reference is now made to... Figure 8 The computing component 800 can be, for example, a server computer, a controller, or any other similar computing component capable of processing data. Figure 8 In the example implementation, computing component 800 includes hardware processor 802 and machine-readable storage medium 804.
[0122] The hardware processor 802 may be one or more central processing units (CPUs), semiconductor-based microprocessors, and / or other hardware devices suitable for retrieving and executing instructions stored in the computer-readable storage medium 804. The hardware processor 802 may retrieve, decode, and execute instructions, such as instructions 806-814, to control the processes or operations disclosed herein. As an alternative to or supplement to retrieving and executing instructions, the hardware processor 802 may include one or more electronic circuits comprising electronic components for performing the functions of one or more instructions, such as field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other electronic circuits.
[0123] A computer-readable storage medium (such as computer-readable storage medium 804) can be any electronic, magnetic, optical, or other physical storage device that contains or stores executable instructions. Therefore, computer-readable storage medium 804 can be, for example, random access memory (RAM), non-volatile RAM (NVRAM), electrically erasable programmable read-only memory (EEPROM), storage devices, optical discs, etc. In some examples, machine-readable storage medium 804 can be a non-transitory storage medium, where the term "non-transitory" excludes transient propagation signals. As described in detail below, machine-readable storage medium 804 can be encoded with executable instructions, such as instructions 806-814.
[0124] Hardware processor 802 can execute instructions 806 to configure the connectivity system by associating NHN indicators with the MNO network identifiers of one or more MNOs based on service information corresponding to one or more MNOs. For example, as described above... Figure 1 and Figure 2 As described, a connectivity system (e.g., one of NHN connectivity systems 130, 230, and / or 630) can receive one or more SLAs from one or more MNOs, which include service information defining the NHN services provided by the one or more MNOs. The connectivity system can create one or more profiles for the one or more MNOs based on the NHN services provided by the one or more MNOs, which include NHN indicators. The connectivity system can be configured using one or more profiles, for example, by associating the one or more profiles with the MNO network identifiers of the one or more MNOs. In the example, the MNO network identifier may include a PLMN ID.
[0125] Hardware processor 802 can execute instructions 808 to receive an access request message from a private cellular network by the connectivity system. This access request message includes the UE identifier of the UE and the MNO network identifier of the MNO associated with the UE. In the example, the private cellular network can be a private 5G cellular network (e.g., private 5G cellular network 220), a private 4G cellular network (e.g., private 4G cellular network 620), a legacy cellular network, and / or a future cellular network. The access request message can be, for example, access request messages 306, 406, 506, or authentication request message 706. In the example, the UE identifier can be the UE's Subscriber Identity Module (SIM) credential, Subscriber Hidden Identifier (SUCI), and / or International Mobile Subscriber Identity (IMSI). The access request message can communicate using the RadSec interface, the DIAMETER interface, or the SBI, according to the RADIUS protocol, the DIAMETER protocol, or the TLS-based SBI.
[0126] In the example, the access request message can be based on a mobility function (e.g., MME or AMF) that receives an authentication request from the UE via a private cellular network. For example, as combined with Figure 4 , Figure 5 and Figure 7 As described, the mobility function can receive authentication requests from users as part of a Registration 302, 402, 502, or Attachment Request message 702. Based on these messages, the mobility function can send authentication requests to other functions within the private cellular network, which ultimately translate the authentication request message into an Access Request message, as described above. Figures 2 to 7 As described.
[0127] The hardware processor 802 can execute instructions 810 to verify whether the MNO allows NHN services, based on an NHN indicator associated with the MNO network identifier included in the location and access request message.
[0128] Hardware processor 802 can execute instruction 812 to establish an authentication channel between the private cellular network and the core network corresponding to the MNO network identifier, based on authentication, and route access request messages to the core network through this authentication channel. For example, the connectivity system can extract the MNO network identifier from the access request message, use this network identifier to locate the profile corresponding to the MNO, and determine that the profile includes an NHN indicator. If the connectivity system determines that the profile contains an NHN indicator, it can establish an authentication channel between the private cellular network and the MNO core network specified by the MNO network identifier for authenticating the UE based on the access request message received from the private cellular network. Alternatively, if the NHN indicator is not present, the connectivity system can send an error code back to the private cellular network.
[0129] The hardware processor 802 can execute instructions 812 to receive one or more messages from the core network operated by the MNO via an authentication channel, which authenticate the UE for access to the core network. For example, the MNO core network can authenticate the UE using any authentication protocol known in the art, such as, but not limited to, EAP-AKA, 5G-AKA, and EPS-AKA, as described above. Figures 3 to 5 and Figure 7 As described. Based on the desired authentication protocol, the MNO core network can send one or more messages to the private cellular network to authenticate the UE at the private cellular network and allow access to the private cellular network, for example, as in combination with Figures 3 to 5 and Figure 7 As described. Once authenticated by the MNO core network, the private cellular network can grant the UE access to the private cellular network using the authentication credentials provided by the MNO core network.
[0130] Figure 9 A block diagram of an example computer system 900 is depicted, illustrating various examples in which the techniques disclosed herein may be implemented. The computer system 900 includes a bus 902 or other communication mechanism for transmitting information, and one or more hardware processors 904 coupled to the bus 902 for processing information. The hardware processors 904 may be, for example, one or more general-purpose microprocessors. The computer system 900 may be implemented in combination with... Figure 1 , Figure 2 and Figure 6 The network configuration 100, communication system 200 and / or communication system 600 described are one or more components.
[0131] Computer system 900 also includes main memory 906, such as random access memory (RAM), cache, and / or other dynamic storage devices, coupled to bus 902, for storing information and instructions to be executed by processor 904. Main memory 906 can also be used to store temporary variables or other intermediate information during the execution of instructions to be executed by processor 904. When such instructions are stored in a storage medium accessible to processor 904, they cause computer system 900 to become a dedicated machine customized for executing the operations specified in the instructions. For example, main memory 906 can store instructions that, when executed by processor(s) 904, cause computer system 900 to perform a combination of... Figures 3 to 5 , Figure 7 and Figure 8 One or more operations described.
[0132] The computer system 900 also includes a read-only memory (ROM) 908 or other static storage device coupled to the bus 902 for storing static information and instructions of the processor 904. Additionally, a storage device 910, such as a disk, optical disk, or USB thumb drive (flash drive), is provided and coupled to the bus 902 for storing information and instructions.
[0133] Computer system 900 can be coupled to display 912, such as a liquid crystal display (LCD) (or touchscreen), via bus 902 for displaying information to the computer user. Input device 914 (including alphanumeric and other keys) is coupled to bus 902 for transmitting information and command selections to processor 904. Another type of user input device is cursor control 916, such as a mouse, trackball, or arrow keys, for transmitting directional information and command selections to processor 904 and for controlling cursor movement on display 912. In some examples, the same directional information and command selections as cursor control can be achieved via touch on a cursorless touchscreen.
[0134] The computing system 900 may include a user interface module to implement a GUI, which may be stored as executable software code executed by (multiple) computing devices in a mass storage device. This module and other modules may include, for example, components such as software components, object-oriented software components, class components and task components, processes, functions, properties, flows, subroutines, program code segments, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables.
[0135] Generally, terms such as "component," "engine," "system," "database," and "data repository" as used herein can refer to logic embedded in hardware or firmware, or to a collection of software instructions that may have entry and exit points, written in a programming language such as Java, C, or C++. Software components can be compiled and linked into an executable program, installed in a dynamic link library, or written in an interpreted programming language such as, for example, BASIC, Perl, or Python. It will be understood that software components can be invoked from other components or from themselves, and / or can be invoked in response to detected events or interrupts. Software components configured to execute on a computing device can be provided on computer-readable media, such as optical discs, digital video discs, flash drives, disks, or any other tangible media, or as digital downloads (and may be initially stored in a compressed or installable format, requiring installation, decompression, or decryption before execution). Such software code can be stored, in part or in whole, on a memory device executing the computing device for execution by the computing device. Software instructions can be embedded in firmware such as EPROM. As will be further understood, hardware components can consist of connected logic units (such as gates and flip-flops), and / or can consist of programmable units (such as programmable gate arrays or processors).
[0136] Computer system 900 may implement the techniques described herein using custom hardwired logic, one or more ASICs or FPGAs, firmware, and / or program logic, which, when combined with the computer system, enable computer system 900 or program it as a special-purpose machine. According to one example of the disclosed techniques, the techniques herein are executed by computer system 900 in response to processor(s) 904 executing one or more instruction sequences contained in main memory 906. Such instructions may be read into main memory 906 from another storage medium, such as storage device 910. Execution of the sequence of instructions contained in main memory 906 causes processor(s) 904 to perform the process steps described herein. In alternative examples, hardwired circuitry may be used in place of or in combination with software instructions.
[0137] As used herein, the term "non-transitory media" and similar terms refer to any medium that stores data and / or instructions that cause a machine to operate in a particular manner. Such non-transitory media can include non-volatile media and / or volatile media. Non-volatile media include, for example, optical discs or magnetic disks, such as storage device 910. Volatile media include dynamic memory, such as main memory 906. Common forms of non-transitory media include, for example, floppy disks, flexible disks, hard disks, solid-state drives, magnetic tape or any other magnetic data storage media, CD-ROMs, any other optical data storage media, any physical media with a perforated pattern, RAM, PROMs and EPROMs, FLASH-EPROMs, NVRAMs, any other memory chips or cartridges, and their networking versions.
[0138] Non-transient media differ from transmission media, but can be used in conjunction with them. Transmission media participate in the transfer of information between non-transient media. For example, transmission media include coaxial cables, copper wires, and optical fibers, including the lines that constitute bus 902. Transmission media can also take the form of sound waves or light waves, such as those generated during radio wave and infrared data communication.
[0139] Computer system 900 also includes a network interface 918 (also called a communication interface) coupled to bus 902. Network interface 918 provides bidirectional data communication coupling with one or more network links connected to one or more local networks. For example, communication interface 918 may be an Integrated Services Digital Network (ISDN) card, a cable modem, a satellite modem, or a modem for providing data communication connectivity with a corresponding type of telephone line. As another example, network interface 918 may be a Local Area Network (LAN) card to provide data communication connectivity with a compatible LAN (or a WAN component communicating with a WAN). Wireless links may also be implemented. In any such implementation, network interface 918 transmits and receives electrical, electromagnetic, or optical signals carrying streams of digital data representing various types of information.
[0140] Network links typically provide data communication to other data devices over one or more networks. For example, a network link can provide connectivity to a host or a data device operated by an Internet Service Provider (ISP) over a local network. The ISP then provides data communication services over a global packet data communication network now commonly referred to as the "Internet." Both local networks and the Internet use electrical, electromagnetic, or optical signals that carry digital data streams. Signals over various networks, as well as signals on network links and through network interface 918 (which transport digital data to or from computer system 900), are example forms of transmission media.
[0141] Computer system 900 can send messages and receive data (including program code) through (multiple) networks, network links, and network interface 918. In the Internet example, the server can send application request codes through the Internet, ISP, local network, and network interface 918.
[0142] The received code may be executed by processor 904 upon receipt and / or stored in storage device 910 or other non-volatile storage device for later execution.
[0143] Each process, method, and algorithm described in the foregoing sections can be embodied in code components executed by one or more computer systems or computer processors, including computer hardware, and executed fully or partially automatically by these code components. One or more computer systems or computer processors can also operate to support the execution of related operations in a "cloud computing" environment or as "Software as a Service" (SaaS). These processes and algorithms can be implemented, partially or entirely, in dedicated circuitry. The various features and processes described above can be used independently of each other or can be combined in various ways. Different combinations and sub-combinations are intended to fall within the scope of this disclosure, and certain method or process blocks may be omitted in some implementations. The methods and processes described herein are not limited to any particular order, and the blocks or states associated with them can be executed in other suitable orders, or can be executed in parallel, or can be executed in other ways. Blocks or states can be added or removed in the disclosed examples. The execution of certain operations or processes can be distributed across computer systems or computer processors that reside not only in a single machine but are deployed across multiple machines.
[0144] As used herein, the circuits can be implemented using any form of hardware, software, or a combination thereof. For example, one or more processors, controllers, ASICs, PLAs, PALs, CPLDs, FPGAs, logic components, software routines, or other mechanisms can be used to compose the circuits. In implementation, the various circuits described herein can be implemented as discrete circuits, or the described functions and features can be shared partially or wholly among one or more circuits. Although various functional features or elements can be described or declared separately as separate circuits, these features and functions can be shared among one or more common circuits, and such descriptions should not require or imply the need for separate circuits to implement such features or functions. Where the circuits are implemented wholly or partially using software, such software can be implemented to operate in conjunction with a computing or processing system (such as computer system 900) capable of performing the functions described herein.
[0145] As used herein, the term "or" may be understood to mean inclusive or exclusive. Furthermore, singular descriptions of resources, operations, or structures should not be understood to exclude the plural. Unless explicitly stated otherwise or understood in the context, conditional language such as "may," "possibly," "perhaps," or "probably" is generally intended to convey that some examples include certain features, elements, and / or steps, while other examples do not.
[0146] Unless otherwise expressly stated, the terms and phrases used in this document, and their variations thereof, should be understood as open-ended rather than restrictive. Adjectives such as “regular,” “traditional,” “common,” “standard,” “known,” and similar terms should not be construed as limiting the described items to those available for a given time period or up to a given time, but rather as encompassing regular, traditional, common, or standard techniques that may be available or known now or in the future. The presence of broadening words and phrases such as “one or more,” “at least,” “but not limited to,” or other similar phrases in some cases should not be construed as an intention or requirement for a narrower scope where such broadening might not exist.< / mcc> < / mnc>
Claims
1. A method comprising: The connectivity system is configured by associating a Neutral Host Network (NHN) indicator with an MNO network identifier for one or more MNOs based on service information corresponding to one or more mobile network operator (MNO). The connection system receives an access request message from a private cellular network, the access request message including the UE identifier of the user equipment (UE) and the MNO network identifier of the MNO associated with the UE; The connection system verifies that the MNO allows NHN services by locating an NHN indicator associated with the MNO network identifier included in the access request message; Based on the verification, the connection system establishes an authentication channel between the private cellular network and the core network corresponding to the MNO network identifier and routes the access request message to the core network. as well as The connection system receives one or more messages from the core network operated by the MNO, the one or more messages authenticating the UE for access to the core network, wherein the UE is granted access to the private cellular network based on the authentication from the core network.
2. The method according to claim 1, wherein the private cellular network includes one or more of the following: a private 5G cellular network and a private 4G cellular network.
3. The method of claim 1, wherein configuring the connection system comprises: Receive one or more Service Level Agreements (SLAs) from the one or more MNOs, the one or more SLAs including the service information defining the NHN services provided by the one or more MNOs; One or more configuration files are created for the one or more MNOs based on the NHN service provided by the one or more MNOs, the one or more configuration files including the NHN directive; as well as The connectivity system is configured using one or more configuration files, wherein the one or more configuration files are associated with the MNO network identifier of the one or more MNOs.
4. The method of claim 3, wherein verifying that the MNO permits NHN services comprises: The connection system extracts the MNO network identifier from the access request message; Use the network identifier to locate the configuration file corresponding to the MNO; as well as The configuration file is determined to include the NHN indicator.
5. The method of claim 1, wherein the MNO network identifier includes a Public Land Mobile Network (PLMNID).
6. The method according to claim 1, wherein the UE identifier includes the UE's Subscriber Identity Module (SIM) certificate, Subscriber Hidden Identifier (SUCI), or International Mobile Subscriber Identity (IMSI).
7. The method of claim 1, wherein the access request message is transmitted according to one of the following: Remote Authentication Dial-In User Service (RADIUS) protocol, DIAMETER protocol, or Service-Based Interface (SBI) based on Transport Layer Security (TLS) protocol.
8. The method of claim 7, wherein the access request message is received via one of the following: a TLS-based RADIUS (RadSec) interface, a DIAMETER interface, or an SBI.
9. The method of claim 1, wherein the access request message is based on the mobility function of the private cellular network that receives the authentication request message from the UE.
10. The method of claim 1, wherein the one or more messages from the core network authenticating the UE for access are based on one of the following: Extensible Authentication Protocol Authentication and Key Negotiation EAP-AKA, 5G-AKA, or Evolved Packet System Authentication and Key Negotiation EPS-AKA.
11. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to: The connectivity system is configured by associating a Neutral Host Network (NHN) indicator with an MNO network identifier for one or more MNOs based on service information corresponding to one or more mobile network operator (MNO). The connection system receives an access request message from a private cellular network, the access request message including the UE identifier of the user equipment (UE) and the MNO network identifier of the MNO associated with the UE; The connection system verifies that the MNO allows NHN services by locating an NHN indicator associated with the MNO network identifier included in the access request message; Based on the verification, the connection system establishes an authentication channel between the private cellular network and the core network corresponding to the MNO network identifier, and routes the access request message to the core network through the authentication channel. as well as The connection system receives one or more messages from the core network operated by the MNO through the authentication channel, the one or more messages authenticating the UE for access to the core network, wherein the UE is granted access to the private cellular network based on the authentication from the core network.
12. The non-transitory computer-readable medium of claim 11, wherein the private cellular network includes one or more of the following: a private 5G cellular network and a private 4G cellular network.
13. The non-transitory computer-readable medium of claim 11, wherein the MNO network identifier includes a Public Land Mobile Network (PLMN) ID.
14. The non-transitory computer-readable medium of claim 11, wherein the UE identifier includes the UE's Subscriber Identity Module (SIM) certificate, Subscriber Hidden Identifier (SUCI), or International Mobile Subscriber Identity (IMSI).
15. The non-transitory computer-readable medium of claim 11, wherein the access request message is transmitted according to one of the following: Remote Authentication Dial-In User Service (RADIUS) protocol, DIAMETER protocol, or Service-Based Interface (SBI) based on Transport Layer Security (TLS) protocol.
16. The non-transitory computer-readable medium of claim 15, wherein the access request message is received via one of the following: a TLS-based RADIUS (RadSec) interface, a DIAMETER interface, or an SBI.
17. The non-transitory computer-readable medium of claim 11, wherein the access request message is based on the mobility function of the private cellular network that receives an authentication request message from the UE, wherein the mobility function is an Access and Mobility Management Function (AMF) or a Mobility Management Entity (MME).
18. The non-transitory computer-readable medium of claim 11, wherein the one or more messages from the core network authenticating the UE for access are based on one of: Extensible Authentication Protocol Authentication and Key Negotiation EAP-AKA', 5G-AKA, or Evolved Packet System Authentication and Key Negotiation EPS-AKA.
19. A system comprising: A private cellular network, wherein a user equipment (UE) sends an access request message based on a request to access the private cellular network, the access request message including the MNO network identifier of the mobile network operator (MNO) and the UE identifier; A connection system receives the access request message from the private cellular network, obtains the MNO network identifier from the access request message, and forwards the access request message to the core network operated by the MNO corresponding to the MNO network identifier; as well as The core network receives the access request from the connection system and authenticates the UE based on the UE included in the access request for access to the core network; and The private cellular network grants access to the UE based on the authentication performed on the UE for accessing the core network.
20. The system of claim 19, wherein the private cellular network includes one or more of the following: a private 5G cellular network and a private 4G cellular network.