IP Library Granted Patent US 12677148
Granted Patent B1
US 12677148 · App. 18/631,936 · Granted Jul 7, 2026

Systems and methods for credential holder support using AAA in non-3GPP access

Inventor: Tao Wan (Ottawa, CA)
Assignee: Cable Television Laboratories, Inc.
H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12677148
App. No.
18/631,936
Granted
Jul 7, 2026
Kind
B1
Abstract

A method is provided for accessing a non-public network (NPN) by a communication device utilizing a credential management system, including steps of (a) receiving, from the device through non-3GPP access means, a first authentication request at an authentication server function (AUSF) of a 5G core (5GC) in communication with the NPN, (b) sending a second authentication request from the AUSF to a network slice-specific authentication and authorization function (NSSAAF) of the 5GC, (c) transmitting, from the NSSAAF, an EAP response/identity message to an AAA server in communication with the credential management system, (d) performing, based on the transmitted EAP response/identity message, EAP-based authentication between the AAA server and the communications device, (e) receiving, at the NSSAAF from the AAA server, and EAP success message, (f) receiving, at the AUSF from the NSSAAF, a first authentication response, and (g) authenticating the communication device with the NPN.

Claims (35)

1 . A method of accessing a non-public network (NPN) by a communication device utilizing a credential management system, comprising the steps of:

receiving, from the communication device through non-Third Generation Partnership Project (N3GPP) access means, a first authentication request at an authentication server function (AUSF) of a 5th generation (5G) core (5GC) in communication with the NPN;

sending a second authentication request from the AUSF to a network slice-specific authentication and authorization function (NSSAAF) of the 5GC;

transmitting, from the NSSAAF, an extensible authentication protocol (EAP) response/identity message to an authentication, authorization, and accounting (AAA) server in communication with the credential management system;

performing, based on the EAP response/identity message, EAP-based authentication between the AAA server and the communications device;

receiving, at the NSSAAF from the AAA server, an EAP success message;

receiving, at the AUSF from the NSSAAF, a first authentication response; and

authenticating the communication device with the NPN.

2 . The method of claim 1 , wherein the step of authenticating the communication device includes a sub-step of registering the communication device.

3 . The method of claim 1 , wherein the AAA server is configured to operate as a credentials holder for the credential management system.

4 . The method of claim 3 , wherein the communication device is one of a user equipment device (UE) and a non-5th generation(5G) capable over Wireless Local Area Network (WLAN) (N5CW) device.

5 . The method of claim 4 , wherein the step of receiving the first authentication request though the N3GPP access means includes an access and mobility management function (AMF) interposed between the N3GPP access means and the AUSF.

6 . The method of claim 5 , wherein the communication device is the UE, and wherein the N3GPP access means includes an untrusted N3GPP access network and an N3GPP Interworking Function (N3IWF).

7 . The method of claim 5 , wherein the communication device is the UE, and wherein the N3GPP access means includes a trusted N3GPP access point (TNAP) and a trusted N3GPP gateway function (TNGF).

8 . The method of claim 5 , wherein the communication device is the N5CW device, and wherein the N3GPP access means includes a trusted WLAN access point and a trusted WLAN interworking function (TWIF).

9 . The method of claim 4 , wherein the communication device is the UE, and wherein the N3GPP access means includes a WLAN access network and a non-seamless WLAN offload function (NSWOF).

10 . The method of claim 9 , wherein the WLAN access network is configured to route authentication messages from the UE to the AAA server indirectly through the 5GC.

11 . The method of claim 9 , wherein the WLAN access network is configured to route authentication messages from the UE directly to the AAA server.

12 . The method of claim 4 , wherein the 5GC further includes a unified data management subsystem (UDM) interposed between the AUSF and the NSSAAF.

13 . The method of claim 12 , further comprising a step of sending, after the step of receiving the first authentication request and prior to sending the second authentication request, a third authentication request from the AUSF to the UDM.

14 . The method of claim 13 , wherein the step of sending the second authentication request is based on a second authentication response to the third authentication request received at the AUSF from the UDM.

15 . The method of claim 14 , wherein the UDM is configured to select an authentication method before sending the second authentication request and after receiving the third authentication request.

16 . The method of claim 14 , wherein the UDM is further configured to store an authentication status in response to a confirmation request from the AUSF.

17 . The method of claim 3 , wherein the first authentication request includes one or more of a subscriber/subscription concealed ID (SUCI), a service network (SN)-name, and a Non-Seamless WLAN Offload indicator (NSWO indicator).

18 . The method of claim 3 , wherein the second authentication request includes a subscriber/subscription Permanent identifier (SUPI).

19 . The method of claim 3 , wherein the NPN is a standalone NPN (SNPN).

20 . A system for enabling a user equipment device (UE) to accessing a standalone non-public network (SNPN) utilizing a credential management subsystem, the system comprising:

an authentication server function (AUSF) of a 5G core (5GC) in communication with the SNPN;

a processor; and

a memory having computer-executable instructions stored therein, which, when executed by the processor, cause the AUSF to:

receive, from the UE through non-Third Generation Partnership Project (N3GPP) access means, a first authentication request, wherein the first authentication request includes a service network (SN)-name and one of (a) a subscriber/subscription concealed identifier (SUCI) and a Non-Seamless WLAN Offload indicator NSWO_indicator), and (b) a subscriber/subscription Permanent ID (SUPI) and an NSWO_indicator;

send a second authentication request to an authentication, authorization, and accounting (AAA) server in communication with the credential management system, wherein the second authentication request includes the SUPI;

enable, based on an extensible authentication protocol (EAP) response/identity message, EAP-based authentication between the AAA server and the UE;

receive, at the AUSF, a first authentication response to the second authentication message, wherein the first authentication response includes at least one of the SUPI, the EAP response/identity message, and a master session key (MSK) provided by the AAA server; and

authenticate the communication device with the SNPN based on the first authentication response.