Terminal Onboarding Access to Private Networks via Public Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
A terminal cannot access a private network due to the lack of necessary information, such as authentication credentials, during the onboarding process.
Innovation Solution
The terminal sends first network information to a first network, performs onboarding delivery authentication, and obtains configuration information and credentials through the first network, enabling access to a second network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a terminal uses a public network to access services, then network coverage and basic connectivity are improved, but network security and data isolation are worsened
Solution Approach 1:
The network is segmented into public network parts and private network parts. The terminal can access public network services through the public network while accessing private network services through the private network, achieving both connectivity and security. The public network and private network are divided into separate access paths and resource pools.
Solution Approach 2:
A network selection function and network slice selection function act as intermediaries between the terminal and networks. These functions determine whether to route traffic through the public network or private network based on service requirements, providing both connectivity and security through intelligent mediation.
2Reliability
If a terminal accesses a private network with pre-configured credentials, then access security is improved, but ease of onboarding new users is worsened
Solution Approach 1:
Network credentials, authentication information, and access policies are pre-configured in the terminal during the onboarding process. The terminal obtains private network access credentials through the public network before actually accessing private network services, ensuring both security and ease of onboarding.
Solution Approach 2:
The terminal autonomously manages its own credentials and authentication. During onboarding, the terminal self-registers with the private network through the public network, obtains necessary credentials, and configures itself for future private network access without requiring manual intervention for each access event.
3Ease of operation
If a terminal obtains private network credentials through online registration, then ease of onboarding is improved, but network complexity and authentication overhead are worsened
Solution Approach 1:
The public network infrastructure is made multi-functional by enabling it to serve both as a general communication network and as an onboarding channel for private network access. The same public network path used for regular services is also used for credential distribution and authentication, reducing the need for separate dedicated onboarding infrastructure.
Solution Approach 2:
Network exposure functions and authentication service functions act as intermediaries that simplify the onboarding process. These intermediaries handle the complex authentication and credential distribution tasks, presenting a simple interface to the terminal while managing the complexity in the network infrastructure.
Data Source
AI summary
This application provides a communication method and apparatus. The method includes: a terminal sending first network information of a second network to a first network, where the first network information includes first indication information of the second network, and the first indication information indicating that the terminal requests to access the second network. The terminal performs onboarding delivery authentication of the second network through the first network. After onboarding delivery authentication of the second network succeeds, the terminal receives configuration information of the first network through the first network, and obtains a credential of the second network through the first network from an online sign-up server in the second network.


