SNPN Access Control via External Authentication Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communications devices without network credentials cannot access standalone non-public networks (SNPNs) for authentication, leading to resource wastage and potential security threats from illegitimate terminals.
Innovation Solution
The method involves sending index and address information of a second authentication server, along with vendor-related information, to request credentials or indicate restricted access types, enabling authentication and configuration even without initial credentials, using external authentication servers and configuration servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If communications devices without credentials are allowed to access the network for authentication, then authentication capability is improved, but network security deteriorates due to potential illegitimate terminal access
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the terminal and the network. The terminal sends authentication information to the server, which then verifies credentials and communicates with the network. This mediator enables authenticated terminals to access the network while blocking illegitimate access, resolving the contradiction between authentication capability and network security.
2Reliability
If authentication information is collected and processed, then authentication reliability is improved, but information processing complexity increases
Solution Approach 1:
The patent extracts the complex authentication information processing function from the network infrastructure and concentrates it in a dedicated authentication server. The server collects, stores, and processes authentication information centrally, while the network and terminals only need to perform simple verification and communication. This extraction reduces overall system complexity while maintaining high authentication reliability.
Data Source
Figure 1~3
Figure 4~6
Figure 7
AI summary
The present invention provides an access control method and a communications device. The method includes: sending first information and/or first indication information to a first target end, where the first information includes at least one of the following: index information of a second authentication server, vendor-related information of the first communications device, and address-related information of the second authentication server; and the first indication information is used for requesting to obtain a credential related to a first network, or used to indicate that an access type is a restricted service.