| 6.0 | Mapping of Solutions to Key Issues p. 15
|
| 6.1 | Solution #1: Primary authentication between an SNPN and third-party AAA server using EAP p. 15
|
| 6.2 | Solution #2: EAP authentication between UE and external AAA via AUSF p. 19
|
| 6.3 | Solution #3: Primary authentication between an SNPN and third-party AAA server using EAP-TTLS p. 21
|
| 6.4 | Solution #4: Authentication Framework Enhancements to support SNPN access p. 24
| 6.4.1 | Introduction p. 24
|
| 6.4.2 | Solution details p. 24
| 6.4.2.1 | SNPN access using PLMN owned subscription credentials p. 24
|
| 6.4.2.2 | SNPN access using third-party owned subscription credentials p. 25
|
|
| 6.4.3 | System impact p. 26
|
| 6.4.4 | Evaluation p. 26
|
|
| 6.5 | Solution #5: Network Access Authentication with Credentials owned by an AAA external to the SNPN p. 27
|
| 6.6 | Solution #6: Network access authentication with credentials owned by an entity separate from the SNPN p. 29
|
| 6.7 | Solution #7: EAP authentication between UE and external AAA with enhanced security of KAUSF p. 31
|
| 6.8 | Solution #8: UE onboarding for SNPN with AAA-S as DCS p. 34
|
| 6.9 | Solution #9: UE onboarding for SNPN with UDM as DCS p. 37
|
| 6.10 | Solution #10: Secure initial access to an SNPN onboarding network p. 39
|
| 6.11 | Solution #11: Securing initial access by using primary authentication p. 41
|
| 6.12 | Solution #12: Authentication for UE Onboarding for SNPN p. 43
| 6.12.1 | Introduction p. 43
|
| 6.12.2 | Solution details p. 45
| 6.12.2.1 | Authentication for onboarding with default credentials is provisioned in UDM p. 45
|
| 6.12.2.2 | Authentication for onboarding with default credentials is provisioned in DCS p. 46
|
|
| 6.12.3 | System impact p. 47
|
| 6.12.4 | Evaluation p. 47
|
|
| 6.13 | Solution #13: UE Onboarding for an SNPN from Onboarding SNPN with Secondary Authentication using EAP method with UE identity privacy p. 47
|
| 6.14 | Solution #14: Initial access for UE Onboarding for an SNPN from Onboarding SNPN using primary and secondary authentication p. 51
| 6.14.1 | Introduction p. 51
|
| 6.14.2 | Solution details p. 52
| 6.14.2.0 | General p. 52
|
| 6.14.2.1 | Using EAP-TLS Authentication Procedures over 5G Networks for initial one-way authentication p. 54
|
|
| 6.14.3 | System impact p. 56
|
| 6.14.4 | Evaluation p. 57
|
|
| 6.15 | Solution #15: Privacy protection of UE onboarding identifier p. 57
|
| 6.16 | Solution #16: UE onboarding for SNPN with the interaction between PS and DCS p. 58
|
| 6.17 | Solution #17: Solution to Provisioning of PNI-NPN Credentials p. 61
|
| 6.18 | Solution #18 Solution on service authorization for SNPNs p. 63
|
| 6.19 | Solution #19: Secure onboarding without client authentication p. 65
|
| 6.20 | Solution #20: Control plane based provisioning: PS to AUSF p. 68
|
| 6.21 | Solution #21: Control plane based provisioning: PS to UDM p. 71
|
| 6.22 | Solution #22: Solution for onboarding and provisioning p. 73
|
| 6.23 | Solution #23: Solution to enable onboarding and secured UE access based on credentials owned by an external entity p. 76
|
| 6.24 | Solution #24: Secure mutually authenticated onboarding without DCS p. 78
|
| 6.25 | Solution #25: UE Onboarding for an SNPN with EAP-TLS p. 81
|