US 12,015,917 B2
Delivering standalone non-public network (SNPN) credentials from an enterprise authentication server to a user equipment over extensible authentication protocol (EAP)
Srinath Gundavelli, San Jose, CA (US); Indermeet Singh Gandhi, San Jose, CA (US); Timothy Peter Stammers, Raleigh, NC (US); and Vimal Srivastava, Bangalore (IN)
Assigned to CISCO TECHNOLOGY, INC., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Jul. 25, 2023, as Appl. No. 18/358,569.
Application 18/358,569 is a continuation of application No. 17/101,071, filed on Nov. 23, 2020, granted, now 11,785,456.
Claims priority of provisional application 63/066,893, filed on Aug. 18, 2020.
Prior Publication US 2023/0370841 A1, Nov. 16, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. H04W 12/06 (2021.01); H04W 12/04 (2021.01); H04W 84/04 (2009.01)
CPC H04W 12/06 (2013.01) [H04W 12/04 (2013.01); H04W 84/042 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
determining, by an authentication server of an enterprise, that a user equipment (UE) for the enterprise is to receive credentials to enable the UE to connect to a wireless wide area (WWA) access network of a standalone non-public network (SNPN) of the enterprise, wherein the determining is performed through connection of the UE to an access network that is different than the WWA access network of the SNPN of the enterprise;
performing a first authentication process between the authentication server and the UE to obtain a first authentication response from the UE to initiate a credential management procedure with the UE;
upon obtaining the first authentication response from the UE, communicating, by the authentication server, a request to a credential manager of the enterprise that includes a location of the UE and indication of whether electronic Subscriber Identity Module (eSIM) credentials or non-SIM credentials are to be generated for the UE to obtain a signed credentials object including the credentials from the credential manager; and
performing a second authentication process between the authentication server and the UE to send the signed credentials object to the UE and obtain a second authentication response from the UE that includes an indication of successful provisioning of the credentials.