US 11,785,456 B2
Delivering standalone non-public network (SNPN) credentials from an enterprise authentication server to a user equipment over extensible authentication protocol (EAP)
Srinath Gundavelli, San Jose, CA (US); Indermeet Singh Gandhi, San Jose, CA (US); Timothy Peter Stammers, Raleigh, NC (US); and Vimal Srivastava, Bangalore (IN)
Assigned to CISCO TECHNOLOGY, INC., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on Nov. 23, 2020, as Appl. No. 17/101,071.
Claims priority of provisional application 63/066,893, filed on Aug. 18, 2020.
Prior Publication US 2022/0060893 A1, Feb. 24, 2022
Int. Cl. H04W 12/06 (2021.01); H04W 12/04 (2021.01); H04W 84/04 (2009.01)
CPC H04W 12/06 (2013.01) [H04W 12/04 (2013.01); H04W 84/042 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method comprising:
determining, by an authentication server of an enterprise, that a user equipment (UE) for the enterprise is to receive credentials to enable the UE to connect to a wireless wide area (WWA) access network of a standalone non-public network (SNPN) of the enterprise, wherein the determining is performed through connection of the UE to an access network that is different than the WWA access network of the SNPN of the enterprise;
communicating, by the authentication server via the access network that is different than the WWA access network of the SNPN of the enterprise, a first extensible authentication protocol (EAP) request to the UE to obtain a first EAP response from the UE to initiate a credential management procedure with the UE;
upon obtaining the first EAP response from the UE, communicating, by the authentication server, a request to a credential manager of the enterprise that includes a location of the UE and indication of whether electronic Subscriber Identity Module (eSIM) credentials or non-SIM credentials are to be generated for the UE to obtain a response from the credential manager comprising a signed credentials object including the credentials;
communicating, by the authentication server via the access network that is different than the WWA access network of the SNPN of the enterprise, a second EAP request to the UE comprising the signed credentials object; and
obtaining a second EAP response from the UE that includes an indication of successful provisioning of the credentials and a signed key identifying the credentials.