EAP-Based SNPN Credential Provisioning for Enterprise UE Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for efficient and enterprise-friendly methods to deliver network credentials, such as eSIM profiles or non-SIM credentials, to user equipment (UE) for connecting to standalone non-public networks (SNPNs) without relying on public mobile network operator-centric workflows, which are cumbersome and do not support private network deployments.
Innovation Solution
An enterprise authentication server provides SNPN credentials to UE over Extensible Authentication Protocol (EAP), using existing enterprise infrastructure, by generating and delivering eSIM or non-SIM profiles during EAP-based authentication, enabling UE to connect to the enterprise SNPN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If public mobile network operator-centric workflows are used to deliver network credentials, then credential delivery can be achieved, but the process becomes cumbersome and does not support private network deployments
Solution Approach 1:
The patent introduces an enterprise authentication server as an intermediary between the UE and the SNPN network. This server mediates the credential delivery process by receiving authentication requests from UEs connecting via access networks, validating credentials, and distributing appropriate SNPN credentials. This intermediary approach eliminates the need for operator-centric workflows while enabling private network deployments, as the enterprise controls its own authentication infrastructure independently of public mobile network operators.
2Reliability
If new network elements are deployed to deliver SNPN credentials, then credential provisioning can be enhanced, but device complexity and infrastructure requirements increase
Solution Approach 1:
The patent makes the enterprise authentication server multi-functional by enabling it to perform both standard enterprise authentication and SNPN credential delivery through a unified EAP-based mechanism. The server handles multiple credential types (eSIM profiles, non-SIM credentials) and supports multiple access networks (Wi-Fi, cellular) through the same infrastructure. This universal approach enhances credential provisioning reliability without requiring separate dedicated network elements for SNPN operations.
Solution Approach 2:
The system enables UEs to self-provision SNPN credentials automatically through the EAP authentication process. When a UE connects to an access network, it automatically receives SNPN credentials from the authentication server without manual intervention. The server autonomously determines which credentials to distribute based on the UE's authentication status and network context, eliminating the need for complex manual provisioning workflows.
3Ease of operation
If enterprise infrastructure is leveraged to deliver credentials, then on-boarding process is simplified, but the authentication protocol must support multiple network types
Solution Approach 1:
The patent utilizes EAP's parameter flexibility to adapt the authentication protocol for dual-purpose use. By changing EAP parameters such as the authentication type, credential format, and message structure, the same protocol framework supports both traditional enterprise authentication and SNPN credential delivery. The system dynamically adjusts EAP parameters based on the requested service type, enabling simplified on-boarding while maintaining protocol versatility across different network types.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Presented herein are techniques to facilitate delivering standalone non-public network (SNPN) credentials from an enterprise authentication server to a user equipment (UE) using an Extensible Authentication Protocol (EAP) process. In one example, a method may include determining, by an authentication server of an enterprise, that a UE for the enterprise is to receive credentials to enable the UE to connect to a SNPN of the enterprise in which the determining is performed based, at least in part, on connection of the UE to an access network that is different than the SNPN for the enterprise; and performing an authentication process with the UE by the authentication server in which the authentication process includes providing the credentials to the UE via a first authentication message and obtaining confirmation from the UE via a second authentication message that indicates successful provisioning of the credentials for the UE.