Terminal Onboarding Access to Private Networks via Public Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

A terminal cannot access a private network due to the lack of necessary information, such as authentication credentials, during the onboarding process.

Innovation Solution

The terminal sends first network information to a first network, performs onboarding delivery authentication, and obtains configuration information and credentials through the first network, enabling access to a second network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a terminal uses a public network to access services, then network coverage and basic connectivity are improved, but network security and data isolation are worsened

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The network is segmented into public network parts and private network parts. The terminal can access public network services through the public network while accessing private network services through the private network, achieving both connectivity and security. The public network and private network are divided into separate access paths and resource pools.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network selection function and network slice selection function act as intermediaries between the terminal and networks. These functions determine whether to route traffic through the public network or private network based on service requirements, providing both connectivity and security through intelligent mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a terminal accesses a private network with pre-configured credentials, then access security is improved, but ease of onboarding new users is worsened

Engineering Contradiction:
Improveaccess securityVSAvoiduser onboarding
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Network credentials, authentication information, and access policies are pre-configured in the terminal during the onboarding process. The terminal obtains private network access credentials through the public network before actually accessing private network services, ensuring both security and ease of onboarding.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal autonomously manages its own credentials and authentication. During onboarding, the terminal self-registers with the private network through the public network, obtains necessary credentials, and configures itself for future private network access without requiring manual intervention for each access event.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If a terminal obtains private network credentials through online registration, then ease of onboarding is improved, but network complexity and authentication overhead are worsened

Engineering Contradiction:
Improveonboarding processVSAvoidauthentication system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The public network infrastructure is made multi-functional by enabling it to serve both as a general communication network and as an onboarding channel for private network access. The same public network path used for regular services is also used for credential distribution and authentication, reducing the need for separate dedicated onboarding infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Network exposure functions and authentication service functions act as intermediaries that simplify the onboarding process. These intermediaries handle the complex authentication and credential distribution tasks, presenting a simple interface to the terminal while managing the complexity in the network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12477329B2Communication method and apparatus
Publication Date: 2025.11.18 HUAWEI TECH CO LTD
  • US12477329B2 patent drawing
  • US12477329B2 patent drawing
  • US12477329B2 patent drawing

AI summary

This application provides a communication method and apparatus. The method includes: a terminal sending first network information of a second network to a first network, where the first network information includes first indication information of the second network, and the first indication information indicating that the terminal requests to access the second network. The terminal performs onboarding delivery authentication of the second network through the first network. After onboarding delivery authentication of the second network succeeds, the terminal receives configuration information of the first network through the first network, and obtains a credential of the second network through the first network from an online sign-up server in the second network.