I. Core objectives
In African markets with weak infrastructure, poor traditional broadband coverage and a user-paying habit unique (high reliance on mobile payments, cash), low-orbit satellite networks in the SpaceX chain are used as backbones to build stable local WIFI hotspots and to commercialize and sustainably develop services through efficient, flexible, localized certification and billing systems.
Ø Price sensitivity: Users are highly price-sensitive and require flexible pricing strategies.
Ø Poor network coverage: Target areas lack reliable fixed or mobile broadband.
Ø User groups: Diversity, including residents, tourists, small businesses, schools, health institutions, mining/tourism camps.
Ø Infrastructure constraints: The supply of electricity is unstable and the physical environment may be harsh (high temperature, dust).
Ø Regulatory differences: Countries have different telecommunications policies and data regulations.
Ø Performance is better: delays are lower and bandwidth higher than traditional satellites.
Ø Quick deployment: terminal equipment installed relatively simply.
Ø Available bandwidth: Based on shared networks, bandwidth may be influenced by the number of users and the network status of the chain itself.
Ø Physical limitations: Terminals require relatively empty horizons and equipment is at risk of theft.
Ø Performance fluctuations: Extreme weather may affect connectivity stability.
Ø Policy risk: Service licensing may be subject to local regulations (spectral use, foreign share, etc.).

Ø Local gateways/routers:As a core of the network, connects the star chain terminal to WIFI AP. The following key functions are required:
Ø Flow integer and QoS:Manage limited upper-line bandwidth (star chain terminal to satellite), prioritize key applications (video calls, online learning etc.) and implement equitable use strategies.
Ø VLAN/IPManagement:Segregate user traffic to ensure safety.
Ø Connect to the billing system:Support for RADIAS protocol communications with back-office Authentication & Billing system.
Ø Support for PORTAL authentication::: User PORTAL certification, self-service opening and payment.
Ø Switches:Connects to several APs and gateways.
Ø Power management equipment:Given the power instability, stable UPS or solar + battery solutions are needed.
Ø Optional - Local Cache/Context Server:For popular/static content, such as educational materials and software updates, local caches can be deployed to reduce the consumption of satellite bandwidth and enhance user experience.
Ø NATHHELL_AUTH_BILLING SET: Core!
Ø Flexible pricing: by time (minutes/hours/day/week/month), by flow (MB/GB), combination of meals, dynamic speed limits (re-use of a continuous net), free value added strategies (e.g., no charge for speed limit and fee-for-speed acceleration).
Ø Multilingual authentication interface (English, French, Arabic, Portuguese, native language, etc.).
Ø User management: self-service registration, data modification, package purchase, account status query (flow/long-term usage).
Ø Security: Protection against misuse and theft of accounts.
Ø Reliability and expansion: Systems need to be stable, supporting growth in multiple hot spots and user sizes.
Ø The NatShell Authentication & Billing system is a widely used AAA server that performs user certification, authorization and billing. It can be fully integrated with various gateway devices.
Ø User portal: A strong user management system and authentication portal.
Ø Cloud service platforms: If local IT carriers are limited or require rapid deployment of multiple nodes, a mature cloud WIFI management and billing service platform may be considered.
Ø Certification portal: Users complete login, purchase, registration, etc. by forcing redirection to the login page after connecting to WIFI.
Ø Payment gateway integration: SDK/API, which integrates local mainstream mobile payment platforms (API interfaces such as M-Pesa, MTN Mobile Money, Airtel Money, Orange Money), and possible proxy systems to manage advance vouchers.
Ø The interface should be visual.
Ø API interface: facilitate integration with other systems (e.g., operator agent system, APP).
Ø User access layer:
Ø Scrap-free experience: user connection to SSID -> AutoPoltal-> Select Login/Registration -> Finalization/payment -> Online.
Ø Phone number + text message check: enter cell phone number -> Received a text message with login links or authentication code -> login. (Integration is strong, relying on SMS costs).
Ø Move payments directly: Select length/flow package on Portal page -> Re-locate cell phones to pay for APP (e.g. M-Pesa)> Automatically open/continuing.
Ø Social login/one key registration: fast-tracked entry via accounts such as Facebook/Google (with possible concern for data privacy).
Ø Account password: suitable for permanent fixed users such as enterprises, shops.
Ø User experience optimization: the portal is simple and clear, payment processes are simplified, local language support is provided, balances/residual flow/long-terms are clearly demonstrated.
Ø (a) Pricing strategy: A small sum, a short-time package (e.g. 10 minutes, 50 MB, 1 hour), starting with flexible options such as day bags, week bags, night cats.
Ø Languages and culture: Certification portals, operational guidelines, customer service must be in local languages and conform to user habits.
Ø Content optimization: to work with local content providers, if possible.
Ø Financial reconciliation: daily/regular reconciliation mobile payment platforms, cash charge agents to ensure clarity of accounts.
Ø Security and compliance: user data storage and transmission requires encryption; network security measures are implemented.
Ø Physical safety: ensuring that the star chain terminals and equipment are anti-piracy, anti-destructive (fixed, monitored, community cooperation).
Ø Alternative power supply: ensuring continuity of electricity supply.
Ø Client services: Establish local client service teams (or outsource them) to respond in a timely manner to problems via telephone, WhatsApp, social media.
Ø Free value added/community services: free basic connectivity in clinics, schools etc. to enhance branding.
Ø Cooperation with local ISPs/operators: they provide local transport or distribution.
Ø Collaboration with small business/hotel/camp: deployed by owners to provide networks (shared income).
Ø B2G (Government/School/Project): Customized connectivity solutions for schools, health institutions and government projects.
Ø Differential advantages (as opposed to traditional programmes).
Ø Broad coverage: crossing geographical limits and covering areas that are inaccessible to fibre-optic/mobile networks.
Ø Rapid deployment: WIFI+ is deployed faster than a cable or base station.
Ø Cost advantages (compared to traditional satellites): The cost of using a star chain is lower than VSAT and performance is better.
Ø Flexibility and adaptability: NATSHEL_AUTH_BILLING can be customized on demand, with highly localized pricing and payment methods.
Ø Open ecology: open source technology store, highly scalable.
Ø Effective local bandwidth/QoS management: services as many users as possible with a bandwidth on limited star chains.
Ø Local pay integration depth: Whether or not it is perfect to support mainstream mobile wallets and cash channels is a key user experience.
Ø Price reasonableness: A user-affordable package is available on the basis of coverage of operating costs.
Ø Reliable local infrastructure: durable equipment, stable power supply, physical security.
Ø Local operating capacity: teams of distribution, customer service and maintenance are close to the local level.
Ø Support for mainstream Chinese markets in Portal 1.0, 2.0, CMCC 1.0, 2.0 and standard Raidus certification codes that can be docked with AC, switchboard, BRAS and other gateway equipment supporting China as the Portal or CMCC agreements to achieve flexible deployment and rapid delivery;
Ø Supports the docking of NAS devices using arbitrary use such as HTTP submissions.
Support AAA forwarding
Ø Supports the integration of AC/BRAS with a third party AAA server for authentication and record-keeping, as well as data recording during transmission.
Support for SMS authentication
Ø Supports the use of built-in account password login.
Ø Supports a key login by clicking on the New York button after showing the PORTAL page.
Support account password/ key login
Ø Supports the integration of AC/BRAS with a third party AAA server for authentication and record-keeping, as well as data recording during transmission.
Support for PEAP and EAP-SIM certification
Ø Support mobile terminals to achieve higher-level security certification by either PEAP or EAP-SIM certification.
802.1X certification supported
Ø 802.1X certification is achieved through connection with the switchboard or NAC.
Support for APP authentication
Ø Based on a strategic judgement, it is possible to achieve the NATSHEL_SEAMLESS_AUTH based on the MAC address, to access NATSHELL_SEAMLESES_AUTH and to apply PORTAL for authentication.
Support LDAP authentication
Ø The uniform identification and licensing of enterprises is achieved through the integration of WINDOWS domain certification.
Support third-party data source authentication
Ø Connect to any third party data source, and achieve authentication such as a cartoon, OA or arbitrary third party database, as well as card certification based on identity cards.
Support for secondary authentication
Ø Support for multiple secondary accreditation modalities, including:
n AAA forwards, user requests for PORTAL certification sent directly to the school ' s AAA server authentication and, upon certification by the AAA server, to the operator ' s AAA server.
n User's PORTAL authentication request, first completed the first certification within school AAA, successful certification, and PORTAL server initiated the certification to Bras, which was transferred from BRAS to operator AAA
n Users are given access to in-school resources, which is free of charge. One can access internal and complete Internet resources, which are fee-paying users.
n The outer network is connected to two or three operators, and may be mobile, connected, or mobile. The practice is to set a different area on the AAA of the school, such as moving, connecting and moving three areas, where users can only belong to one region with attributes unique to that area. After PORTAL has been cross-exactly completed with BARS, AAAAA, the school AAA returns the certification results and sends this property to BARS equipment, which will be accredited in a second place at AA, the operator designated by BRAS once it receives the properties.
Support multi-producer NAS equipment
Ø MultiNAS support: Support docking multiple NAS devices and sending different authentication pages to multiple NAC network users (a) Fahrenheit;
Ø Supports the interface between mainstream producers AC/BRAS/COMN, RADUS and PORTAL for H3C, JUNIPER, Ericsson, Dip, Kyoshin, UAA, Sicaga, Hanming, Sharp, TPLINK, PANABIT, Quick, NatShell, Microtik...;
Excellent front-end editing experience
Ø Authentication Page Custom: In accordance with the NATSHEL_BRAND authentication page customization, users can easily use any web editing language to design their own certification page styles and authenticate successful pages, while also setting the time when a successful version of the authentication page will be displayed;
Ø WEBEdit: PORTAL authentication page, edited through the WEB management interface, which can modify and edit images, text, links, colours, authentication methods etc. to match the use needs of different scenarios;
Ø URLJump: Force to jump to a URL after user authentication is successfully supported;
Ø Terminal adaptation: different authentication page formats, such as PC and mobile phones for PORTAL pages or Andre and IOS for PORTAL pages, depending on the end type;
Ø Authenticate frontend separation: Supports the separation of the authentication frontend page and Portal server, allowing users to specify the preend WEB certification page address;
Flexible PORTAL template push policy
Ø PORTALPush strategy: Set up the end user ' s authentication page display policy according to the 4W (Wen, Where, What) rules, i.e., time, AP group, SSID and content for push;
Ø Default policy: when the current strategy cannot match, the port authentication page content from the terminal is a template specified in the default policy;
Ø Strategic Elements Management: multiple elements of the strategy set can be configured to include:
n AP Group
n SSID
n APID
n User Group
n Time group
Ø Redirect URL parameter configuration:The PORTAL parameters for the interface with AC/BRAS can be modified to facilitate the interface with various brands of AC/BRAS products.
Support in multiple authentication modalities
Ø Text authentication: SMS certification is basic and the most widely used.
Ø Micromail Authentication: Because of the strong marketing value of micro-credit, WiFi is often used in large marketing sites such as mega-business squares, supermarket chains, banking network shops, commercial property and smart cities;
Ø Account password authentication: For enterprise staff, use username password authentication and temporary account numbers is recommended to separate staff members and visitors on certification, and to adjust network bandwidth, traffic, Internet access time etc. to meet operational requirements, using traditional methods“Network resources are oriented”♪ Become as“Business orientation”The network controls also allow for the integration of multi-branch staff into the web, through Seamless Authentication, a full-network structure, one certification and mobile access;
Ø One key login authentication_: access certification for steps to simplify customer access to wireless networks, save client time and protect client privacy;
Ø Visitors Scanning Certification• When visitors enter the network space, they need to be scanned and authorized by the interviewee before visitors can use the network. This one-to-one access format allows visitors to be visible and ensures maximum security of access;
Ø ADDomain authentication: The application of the online accreditation and auditing of enterprise staff, which is implemented through a combination of NATSHEL_BRAND Authentication & Billing platform with the enterprise ' s domain certification function, not only to achieve employee status access, rights control, security audit, but also to achieve corporate workforce management, reducing duplication of management problems and reducing the burden on managers
Ø APPAuthenticationAPP certification is the enterprise-owned APP as a login to the WIFI authentication portal, which helps increase downloads of APP;
Ø Third-party data source authentication• To facilitate the harmonization of business management by validating third-party data sources such as enterprise OAs or user databases;
Ø Second authentication: The user account is usually used to match the operator with a fee setting such as schools of higher learning, landscapes and factories, first certified at NATSHEL_BRAND certification platform, then failed certification is rejected directly and successful before requests for accreditation are submitted to operators ' Bras and AAAA for certification;
Ø MACSecond decertification: MAC secondary exemption is a method of authentication based on the MAC address for controlling user ' s access to the network, which does not require the user to install any client-end software. The second time that you can achieve a user ' s successful first certification is an advertisement page, without user ' s need to use authentication to log in, and only one key to authenticate or to complete automatic authentication when the page countdowns;
Ø MACNATHHELL_SEAMLESS_AUTH: Authentication method for controlling user's network access at the MAC address, which does not require the user to install any client-end software. The authentication operation is initiated for the user after the device that has started the MAC address certification has been online. The user does not need to manually enter a user's name or password in the authentication process. If the user authenticates successfully, it will be allowed to access the network resources, otherwise the user's MAC address will be added to the silent MAC;
Humanized billing system
Ø Text Management: SMS passwords can be used to keep users valid for use of SMS and access SMS rules, preventing users from receiving SMS passwords in large numbers over time and consuming SMS resources;
Ø NATHHELL_AUTH_BILLING: completion of the certification and billing of end-users through the Radius Authentication & Billing system, which is attached to Portal servers, supporting the standard Radius protocol;
Ø Opening management: accounts can be created directly in the NATSHELLL_AUTH_BILLING system and a corresponding package selected, users can authenticate online on the certified page based on account information, and users of SMS are automatically opened;
Ø Package management: A strong package management function that supports the setting of parameters such as uploading, downloading, access cycle, cumulative time, maximum online time, password validity and meeting user access control needs in various settings;
Ø Terminal MAC tied: user account can bind the user 's MAC address at first line to prevent users from ending in multiple times (b) Use of an account on end-of-end device for authentication on the Internet;
Ø NASTie it.: The user account can bind the user ' s NAS IP address at first access;
Ø AP MACTie it.: the user account can bind the user ' s APMAC address at first line;
Ø Max. Online Users: The maximum number of online users allowed by the account can be set up in a package management to facilitate access to one account at the same time on different end-of-life devices or limit the use of one user account at the same time at different end-of-services;
Ø Online users: The online user information in the current network, including username, NAS address, client-end IP, upload traffic, download flow, booking start time, online duration etc., can be readily accessed and users can be forced off manually;
Ø History: Users can be consulted at any time over the last 1 month for online historical records, including user names, NAS addresses, client IP, upload traffic, download traffic, start of bookkeeping, online duration etc. and for details of each record.
Sound financial management function
In the system, financial aspects are as follows:
Ø User-filled account opening
Ø User-Current Retention
Ø Financial order records
Ø Business statement statistics
Ø User billing records
Ø User self-service fee
Ø Business reconciliation function
Fillcard Function
In this system, the charge card account function provides users with a charge card feature:
Ø Card Generation
Ø Card sales
Ø Sales statistics
Ø Fill Log
Statistical analysis of data
The system has detailed statistical analysis functions that can help managers to effectively conduct policy-making analyses, including, inter alia, the following:
Ø Trends in enrolment
Ø Trends in online numbers
Ø Statistics on type of registration
Ø Access Terminal Statistics
Ø Accounts Online Rate Statistics
Ø Web-based user statistics
Ø PORTAL POLISTY OF SUSTAINABLES
Ø Cumulative number of successful certifications
Ø Per capita length of Internet access
Ø Net traffic per capita
Ø Authentication failure log sheet
Ø PORTAL DRIVER
Ø Proportion of users of the package
Ø User statistics for maturity
Ø Statistics on the number of families continued
Payment for third-party net.
In the context of fee scenarios, where payments are required, the following types of fees are currently being supported in the system:
Ø We're paying for it.
Ø Pay the treasure.
Ø Other third party payments required
Note: Payment is made by the user on its own basis and requires application for a micro-public or a payment account number.
Interface Functions
The WEBSERVICE interface is available for other systems and the following interfaces are possible:
User-managed interface:
Ø Opening interface
Ø Remove user interface
Ø Determining whether the user has an interface
Ø User Underline Interface
Ø Modify User Information Interface
Ø Package Change Interface
Ø User-distribute interface
Ø Force down interface
Ø Account Basic Information Query Interface
Ø Daily use of the length/flow query interface
Ø Use traffic query interface per hour
Ø Account Fill Flow Interface
Ø Day/month traffic query interface
Ø Set the date/month traffic warning interface
Ø Send SMS Interface
PORTALAuthentication interface:
Ø Submit authentication interface
Log management
The system provides a well-developed log function, including the following:
Ø Online records: User history of access
Ø Operation Log: Administrator's operating log on the system
Ø Interface Log: WEBSERVICE interface calls and operating log
Ø Text log: Log for text messages
Ø Login log: Manager login
Ø Visitors ' Authorization Log: Log authorized by internal staff to scan company visitors
Ø Identification Log: Identifier interface call and result log
Ø Due reminder log: alerting users of due by text
Ø Proxy log: agent login and operation log record
Ø Empty log: empty logs according to time conditions
Authentication of real names
The system provides a physical name authentication function that allows for strong physical identification as required by national policy and connects to the third-party certification platform interface, enabling three-in-one certifications of cellular numbers, identity numbers and faces recognition.
Decentralization
The integration of role management in the system enables different levels of users to have different managerial competencies over the functionality of the system, facilitating the classification and management of client authority according to project and business.
Different delegation roles can be defined in advance to facilitate the administrator setting.
Agent management
Accounts may be opened for secondary agents and group management privileges assigned;
The agent ' s authority is distinct from that of the administrator and belongs to a separate module, which is usually set up for third-party cooperation agencies to manage their users;
These include:
Organisation
Cannot initialise Evolution's mail component.
Proxy login and operation records
Agent bulletin and circular management
Agent charge discount management
Warning function
Supports the e-mail, text message alert function for equipment offline events and assists users in offline incident processing of equipment, effectively handling problems and protecting equipment assets and reducing operating costs.
Public Security NATSHEL_LOG_AUDIT docking functionality
Support the data docking with equipment manufacturers (such as Ryoshi) identified by the Ministry of Public Security for compliance with Decree No. 32, which will be used to send user certification and access logs to the Internet, including:
Ø Username
Ø Internet time
Ø IP Address
Data Backup
Support multiple data backup functions, including:
Ø Manual backup to local computer
Ø Automatic backup to server local storage
Ø Automail Key Data Backup
Ø Double hot.
Ø Double cooling.
Self-service systems
The system carries its own user self-service platform, and users use their own account to log in to achieve the following:
Ø Query basic information
Ø Query order information
Ø Help off the line.
Ø Query Internet History
Ø Realizing self-service contribution functions
Ø New users register fees online
In African markets with weak infrastructure, poor traditional broadband coverage and a user-paying habit unique (high reliance on mobile payments, cash), low-orbit satellite networks in the SpaceX chain are used as backbones to build stable local WIFI hotspots and to commercialize and sustainably develop services through efficient, flexible, localized certification and billing systems.
Market characteristics
Ø Payment habits: Mobile payments (e.g. M-Pesa, Airtel Money, MTN Mobile Money) are the main payment mode, credit card penetration is low and cash payments remain important.Ø Price sensitivity: Users are highly price-sensitive and require flexible pricing strategies.
Ø Poor network coverage: Target areas lack reliable fixed or mobile broadband.
Ø User groups: Diversity, including residents, tourists, small businesses, schools, health institutions, mining/tourism camps.
Ø Infrastructure constraints: The supply of electricity is unstable and the physical environment may be harsh (high temperature, dust).
Ø Regulatory differences: Countries have different telecommunications policies and data regulations.
III. QUALITY OF THE SET
Advantages
Ø Wide coverage: it covers remote villages, islands and roads.Ø Performance is better: delays are lower and bandwidth higher than traditional satellites.
Ø Quick deployment: terminal equipment installed relatively simply.
Disadvantaged
Ø Operating costs: Terminal equipment cost, monthly rental rate is fixed expenditure.Ø Available bandwidth: Based on shared networks, bandwidth may be influenced by the number of users and the network status of the chain itself.
Ø Physical limitations: Terminals require relatively empty horizons and equipment is at risk of theft.
Ø Performance fluctuations: Extreme weather may affect connectivity stability.
Ø Policy risk: Service licensing may be subject to local regulations (spectral use, foreign share, etc.).
IV. STRUCTURE OF SOLUTIONS
The core of the solution lies in linking the localised WIFI infrastructure and smart Authentication & Billing platform between the star chain network and end-users.Network Tung

Infrastructure floor
Ø Starlink user terminal:SpaceX's satellite antenna and router, which is responsible for access to the satellite network of the Star Chain. This is the point of entry to the network.Local network (WLAN) devices
Ø High-performance WIFI access point:It is recommended that you choose industrial or enterprise-level wireless equipment to support high-density users in co-distribution, good QoS management and multiple authentication methods.Ø Local gateways/routers:As a core of the network, connects the star chain terminal to WIFI AP. The following key functions are required:
Ø Flow integer and QoS:Manage limited upper-line bandwidth (star chain terminal to satellite), prioritize key applications (video calls, online learning etc.) and implement equitable use strategies.
Ø VLAN/IPManagement:Segregate user traffic to ensure safety.
Ø Connect to the billing system:Support for RADIAS protocol communications with back-office Authentication & Billing system.
Ø Support for PORTAL authentication::: User PORTAL certification, self-service opening and payment.
Ø Switches:Connects to several APs and gateways.
Ø Power management equipment:Given the power instability, stable UPS or solar + battery solutions are needed.
Ø Optional - Local Cache/Context Server:For popular/static content, such as educational materials and software updates, local caches can be deployed to reduce the consumption of satellite bandwidth and enhance user experience.
Ø NATHHELL_AUTH_BILLING SET: Core!
Needs analysis
Ø (c) Adapt to multiple payment modes: mobile payments, prepaid vouchers (cod/passwords), cash charge (through agents), needs-based fees (long time/flow).Ø Flexible pricing: by time (minutes/hours/day/week/month), by flow (MB/GB), combination of meals, dynamic speed limits (re-use of a continuous net), free value added strategies (e.g., no charge for speed limit and fee-for-speed acceleration).
Ø Multilingual authentication interface (English, French, Arabic, Portuguese, native language, etc.).
Ø User management: self-service registration, data modification, package purchase, account status query (flow/long-term usage).
Ø Security: Protection against misuse and theft of accounts.
Ø Reliability and expansion: Systems need to be stable, supporting growth in multiple hot spots and user sizes.
Costing programme
Ø Open Source Core (mainstream selection):Ø The NatShell Authentication & Billing system is a widely used AAA server that performs user certification, authorization and billing. It can be fully integrated with various gateway devices.
Ø User portal: A strong user management system and authentication portal.
Ø Cloud service platforms: If local IT carriers are limited or require rapid deployment of multiple nodes, a mature cloud WIFI management and billing service platform may be considered.
Key component integration
Ø RADIUS server: User-in-board requests for AP/Consistence forwarding.Ø Certification portal: Users complete login, purchase, registration, etc. by forcing redirection to the login page after connecting to WIFI.
Ø Payment gateway integration: SDK/API, which integrates local mainstream mobile payment platforms (API interfaces such as M-Pesa, MTN Mobile Money, Airtel Money, Orange Money), and possible proxy systems to manage advance vouchers.
Ø The interface should be visual.
Ø API interface: facilitate integration with other systems (e.g., operator agent system, APP).
Ø User access layer:
Ø Scrap-free experience: user connection to SSID -> AutoPoltal-> Select Login/Registration -> Finalization/payment -> Online.
Certification
Ø Prepaid vouchers: purchase of an entity/electronic voucher with the only password, which is entered on the portal.Ø Phone number + text message check: enter cell phone number -> Received a text message with login links or authentication code -> login. (Integration is strong, relying on SMS costs).
Ø Move payments directly: Select length/flow package on Portal page -> Re-locate cell phones to pay for APP (e.g. M-Pesa)> Automatically open/continuing.
Ø Social login/one key registration: fast-tracked entry via accounts such as Facebook/Google (with possible concern for data privacy).
Ø Account password: suitable for permanent fixed users such as enterprises, shops.
Ø User experience optimization: the portal is simple and clear, payment processes are simplified, local language support is provided, balances/residual flow/long-terms are clearly demonstrated.
V. IMPLEMENTATION AND OPERATIONAL STRATEGY
Localize fit
Ø Payment modalities: support for one or two mainstream local mobile payment methods and consider proxy charging channels.Ø (a) Pricing strategy: A small sum, a short-time package (e.g. 10 minutes, 50 MB, 1 hour), starting with flexible options such as day bags, week bags, night cats.
Ø Languages and culture: Certification portals, operational guidelines, customer service must be in local languages and conform to user habits.
Ø Content optimization: to work with local content providers, if possible.
Risk management
Ø Bandwidth management: Strictly enforces a tactical QoS to prevent abuse and safeguard fairness.Ø Financial reconciliation: daily/regular reconciliation mobile payment platforms, cash charge agents to ensure clarity of accounts.
Ø Security and compliance: user data storage and transmission requires encryption; network security measures are implemented.
Ø Physical safety: ensuring that the star chain terminals and equipment are anti-piracy, anti-destructive (fixed, monitored, community cooperation).
Ø Alternative power supply: ensuring continuity of electricity supply.
Marketing and services
Ø Channel promotion: through local proxy sites, APP promotion, social media, school/business collaboration.Ø Client services: Establish local client service teams (or outsource them) to respond in a timely manner to problems via telephone, WhatsApp, social media.
Ø Free value added/community services: free basic connectivity in clinics, schools etc. to enhance branding.
Business model
Ø B2C (direct users): Deployment of hot spots in village squares, fairs, traffic hubs and independent shops.Ø Cooperation with local ISPs/operators: they provide local transport or distribution.
Ø Collaboration with small business/hotel/camp: deployed by owners to provide networks (shared income).
Ø B2G (Government/School/Project): Customized connectivity solutions for schools, health institutions and government projects.
Ø Differential advantages (as opposed to traditional programmes).
Ø Broad coverage: crossing geographical limits and covering areas that are inaccessible to fibre-optic/mobile networks.
Ø Rapid deployment: WIFI+ is deployed faster than a cable or base station.
Ø Cost advantages (compared to traditional satellites): The cost of using a star chain is lower than VSAT and performance is better.
Ø Flexibility and adaptability: NATSHEL_AUTH_BILLING can be customized on demand, with highly localized pricing and payment methods.
Ø Open ecology: open source technology store, highly scalable.
Key success factors
Ø A strong back-office system: core requirements are stable, flexible and seamlessly integrated with local payments.Ø Effective local bandwidth/QoS management: services as many users as possible with a bandwidth on limited star chains.
Ø Local pay integration depth: Whether or not it is perfect to support mainstream mobile wallets and cash channels is a key user experience.
Ø Price reasonableness: A user-affordable package is available on the basis of coverage of operating costs.
Ø Reliable local infrastructure: durable equipment, stable power supply, physical security.
Ø Local operating capacity: teams of distribution, customer service and maintenance are close to the local level.
VII. SUMMIT
The use of the Star Chain to provide access to WIFI in Africa is relatively mature in technology programmes (Store Terminal + WIFI AP+ Billing System + Mobile Payment Integration), which have been successful in relying heavily on localised operational capabilities (payment channel access, pricing, customer service, agent network, hot spot selection) and the realization of a strong backstage Authentication & Billing platform. Selection of reliable, flexible, cost-effective start-up fee systems is the core of technology. Clear knowledge of user needs, payment practices and regulatory environments in target areas is fundamental.VIII. List of major equipment used (selection according to actual situation)
| Product name type | Function Description |
| AAAAccess to the authentication system | AAA unified authentication system, software deployment version, which can be deployed using server or cloud host Support for CMCC 2.0, PORTAL, NatShell PORTAL, etc. Support Portal page customisation, uploading PORTAL page on its own Business Micromail Twinning Certification, MAC Seamless Authentication Supports PPOE/PORTAL/802.1X/L2TP authentication 1 server permit, with no limitations on server performance Support for docking multi-project and multi-NAS devices |
| Cloud Host | Installation of AAAA access certification system for deployment |
| Lower NATSHEL_AUTH_GATEWAY, selecting different specifications according to the actual situation | |
| NATHHELL_AUTH_GATEWAY NE-20-200 |
Multifunctional Authentication Gateway ⁇ 9-inch desktop ⁇ Small support for two-way 2G traffic, (five gigawatts) outsource power source, supporting 200 users online |
| NATHHELL_AUTH_GATEWAY NE-20-300 |
Multifunctional Authentication Gateway ⁇ 9-inch desktop ⁇ Small support for two-way 2G traffic (5 gigawatts) outlet power source, supporting 300 users online |
| NATHHELL_AUTH_GATEWAY NE-80-500 |
NATSHEL_AUTH_GATEWAY ⁇ 19-inch 1U rack 8G memory ⁇ 60G flash ⁇ maximum support for two-way 6G traffic, (8 gigawatts) built-in power source to support 500 users online |
| NATHHELL_AUTH_GATEWAY NE-80-1K |
NATSHEL_AUTH_GATEWAY ⁇ 19-inch 1U rack 8G memory ⁇ 60G flashy stubble support two-way 6G traffic, (8 gigabytes and 2 megagrams) supporting 1,000 users online |
| AC, AP, CloudAC below, selected according to the actual situation | |
| Cloud AC controller | CloudAC platform to support cross-regional management of NatShell wireless AP equipment |
| CloudAC Platform Authorization | CloudAC Platform authorization to support 100 AP equipment management Support equipment on-line, configuration and release, upgrade of equipment, group management, multi-user management, worksheet management, map management, off-line early warning of equipment, operations management etc. A user-owned cloud host or server is required |
| Wireless AP | WIFI6Wireless AP, 3,000M, top-of-sort installation |
| No wire by | WIFI6Unwired by, 3,000 M, desktop installation |
| Lightcats and related equipment below, selected according to the actual situation | |
| Lightcat. | WIFI5 light cat, gigameter cable interface, single-frequency WIFI |
| Photovoltaic converter | 1 light-1 PV, light mouth for cat bats |
| OLTCat-stick. | 32 light cat access, direct access to spectrometers |
IX. Features of solutions
Support multi-agreementsØ Support for mainstream Chinese markets in Portal 1.0, 2.0, CMCC 1.0, 2.0 and standard Raidus certification codes that can be docked with AC, switchboard, BRAS and other gateway equipment supporting China as the Portal or CMCC agreements to achieve flexible deployment and rapid delivery;
Ø Supports the docking of NAS devices using arbitrary use such as HTTP submissions.
Support AAA forwarding
Ø Supports the integration of AC/BRAS with a third party AAA server for authentication and record-keeping, as well as data recording during transmission.
Support for SMS authentication
Ø Supports the use of built-in account password login.
Ø Supports a key login by clicking on the New York button after showing the PORTAL page.
Support account password/ key login
Ø Supports the integration of AC/BRAS with a third party AAA server for authentication and record-keeping, as well as data recording during transmission.
Support for PEAP and EAP-SIM certification
Ø Support mobile terminals to achieve higher-level security certification by either PEAP or EAP-SIM certification.
802.1X certification supported
Ø 802.1X certification is achieved through connection with the switchboard or NAC.
Support for APP authentication
Ø Based on a strategic judgement, it is possible to achieve the NATSHEL_SEAMLESS_AUTH based on the MAC address, to access NATSHELL_SEAMLESES_AUTH and to apply PORTAL for authentication.
Support LDAP authentication
Ø The uniform identification and licensing of enterprises is achieved through the integration of WINDOWS domain certification.
Support third-party data source authentication
Ø Connect to any third party data source, and achieve authentication such as a cartoon, OA or arbitrary third party database, as well as card certification based on identity cards.
Support for secondary authentication
Ø Support for multiple secondary accreditation modalities, including:
n AAA forwards, user requests for PORTAL certification sent directly to the school ' s AAA server authentication and, upon certification by the AAA server, to the operator ' s AAA server.
n User's PORTAL authentication request, first completed the first certification within school AAA, successful certification, and PORTAL server initiated the certification to Bras, which was transferred from BRAS to operator AAA
n Users are given access to in-school resources, which is free of charge. One can access internal and complete Internet resources, which are fee-paying users.
n The outer network is connected to two or three operators, and may be mobile, connected, or mobile. The practice is to set a different area on the AAA of the school, such as moving, connecting and moving three areas, where users can only belong to one region with attributes unique to that area. After PORTAL has been cross-exactly completed with BARS, AAAAA, the school AAA returns the certification results and sends this property to BARS equipment, which will be accredited in a second place at AA, the operator designated by BRAS once it receives the properties.
Support multi-producer NAS equipment
Ø MultiNAS support: Support docking multiple NAS devices and sending different authentication pages to multiple NAC network users (a) Fahrenheit;
Ø Supports the interface between mainstream producers AC/BRAS/COMN, RADUS and PORTAL for H3C, JUNIPER, Ericsson, Dip, Kyoshin, UAA, Sicaga, Hanming, Sharp, TPLINK, PANABIT, Quick, NatShell, Microtik...;
Excellent front-end editing experience
Ø Authentication Page Custom: In accordance with the NATSHEL_BRAND authentication page customization, users can easily use any web editing language to design their own certification page styles and authenticate successful pages, while also setting the time when a successful version of the authentication page will be displayed;
Ø WEBEdit: PORTAL authentication page, edited through the WEB management interface, which can modify and edit images, text, links, colours, authentication methods etc. to match the use needs of different scenarios;
Ø URLJump: Force to jump to a URL after user authentication is successfully supported;
Ø Terminal adaptation: different authentication page formats, such as PC and mobile phones for PORTAL pages or Andre and IOS for PORTAL pages, depending on the end type;
Ø Authenticate frontend separation: Supports the separation of the authentication frontend page and Portal server, allowing users to specify the preend WEB certification page address;
Flexible PORTAL template push policy
Ø PORTALPush strategy: Set up the end user ' s authentication page display policy according to the 4W (Wen, Where, What) rules, i.e., time, AP group, SSID and content for push;
Ø Default policy: when the current strategy cannot match, the port authentication page content from the terminal is a template specified in the default policy;
Ø Strategic Elements Management: multiple elements of the strategy set can be configured to include:
n AP Group
n SSID
n APID
n User Group
n Time group
Ø Redirect URL parameter configuration:The PORTAL parameters for the interface with AC/BRAS can be modified to facilitate the interface with various brands of AC/BRAS products.
Support in multiple authentication modalities
Ø Text authentication: SMS certification is basic and the most widely used.
Ø Micromail Authentication: Because of the strong marketing value of micro-credit, WiFi is often used in large marketing sites such as mega-business squares, supermarket chains, banking network shops, commercial property and smart cities;
Ø Account password authentication: For enterprise staff, use username password authentication and temporary account numbers is recommended to separate staff members and visitors on certification, and to adjust network bandwidth, traffic, Internet access time etc. to meet operational requirements, using traditional methods“Network resources are oriented”♪ Become as“Business orientation”The network controls also allow for the integration of multi-branch staff into the web, through Seamless Authentication, a full-network structure, one certification and mobile access;
Ø One key login authentication_: access certification for steps to simplify customer access to wireless networks, save client time and protect client privacy;
Ø Visitors Scanning Certification• When visitors enter the network space, they need to be scanned and authorized by the interviewee before visitors can use the network. This one-to-one access format allows visitors to be visible and ensures maximum security of access;
Ø ADDomain authentication: The application of the online accreditation and auditing of enterprise staff, which is implemented through a combination of NATSHEL_BRAND Authentication & Billing platform with the enterprise ' s domain certification function, not only to achieve employee status access, rights control, security audit, but also to achieve corporate workforce management, reducing duplication of management problems and reducing the burden on managers
Ø APPAuthenticationAPP certification is the enterprise-owned APP as a login to the WIFI authentication portal, which helps increase downloads of APP;
Ø Third-party data source authentication• To facilitate the harmonization of business management by validating third-party data sources such as enterprise OAs or user databases;
Ø Second authentication: The user account is usually used to match the operator with a fee setting such as schools of higher learning, landscapes and factories, first certified at NATSHEL_BRAND certification platform, then failed certification is rejected directly and successful before requests for accreditation are submitted to operators ' Bras and AAAA for certification;
Ø MACSecond decertification: MAC secondary exemption is a method of authentication based on the MAC address for controlling user ' s access to the network, which does not require the user to install any client-end software. The second time that you can achieve a user ' s successful first certification is an advertisement page, without user ' s need to use authentication to log in, and only one key to authenticate or to complete automatic authentication when the page countdowns;
Ø MACNATHHELL_SEAMLESS_AUTH: Authentication method for controlling user's network access at the MAC address, which does not require the user to install any client-end software. The authentication operation is initiated for the user after the device that has started the MAC address certification has been online. The user does not need to manually enter a user's name or password in the authentication process. If the user authenticates successfully, it will be allowed to access the network resources, otherwise the user's MAC address will be added to the silent MAC;
Humanized billing system
Ø Text Management: SMS passwords can be used to keep users valid for use of SMS and access SMS rules, preventing users from receiving SMS passwords in large numbers over time and consuming SMS resources;
Ø NATHHELL_AUTH_BILLING: completion of the certification and billing of end-users through the Radius Authentication & Billing system, which is attached to Portal servers, supporting the standard Radius protocol;
Ø Opening management: accounts can be created directly in the NATSHELLL_AUTH_BILLING system and a corresponding package selected, users can authenticate online on the certified page based on account information, and users of SMS are automatically opened;
Ø Package management: A strong package management function that supports the setting of parameters such as uploading, downloading, access cycle, cumulative time, maximum online time, password validity and meeting user access control needs in various settings;
Ø Terminal MAC tied: user account can bind the user 's MAC address at first line to prevent users from ending in multiple times (b) Use of an account on end-of-end device for authentication on the Internet;
Ø NASTie it.: The user account can bind the user ' s NAS IP address at first access;
Ø AP MACTie it.: the user account can bind the user ' s APMAC address at first line;
Ø Max. Online Users: The maximum number of online users allowed by the account can be set up in a package management to facilitate access to one account at the same time on different end-of-life devices or limit the use of one user account at the same time at different end-of-services;
Ø Online users: The online user information in the current network, including username, NAS address, client-end IP, upload traffic, download flow, booking start time, online duration etc., can be readily accessed and users can be forced off manually;
Ø History: Users can be consulted at any time over the last 1 month for online historical records, including user names, NAS addresses, client IP, upload traffic, download traffic, start of bookkeeping, online duration etc. and for details of each record.
Sound financial management function
In the system, financial aspects are as follows:
Ø User-filled account opening
Ø User-Current Retention
Ø Financial order records
Ø Business statement statistics
Ø User billing records
Ø User self-service fee
Ø Business reconciliation function
Fillcard Function
In this system, the charge card account function provides users with a charge card feature:
Ø Card Generation
Ø Card sales
Ø Sales statistics
Ø Fill Log
Statistical analysis of data
The system has detailed statistical analysis functions that can help managers to effectively conduct policy-making analyses, including, inter alia, the following:
Ø Trends in enrolment
Ø Trends in online numbers
Ø Statistics on type of registration
Ø Access Terminal Statistics
Ø Accounts Online Rate Statistics
Ø Web-based user statistics
Ø PORTAL POLISTY OF SUSTAINABLES
Ø Cumulative number of successful certifications
Ø Per capita length of Internet access
Ø Net traffic per capita
Ø Authentication failure log sheet
Ø PORTAL DRIVER
Ø Proportion of users of the package
Ø User statistics for maturity
Ø Statistics on the number of families continued
Payment for third-party net.
In the context of fee scenarios, where payments are required, the following types of fees are currently being supported in the system:
Ø We're paying for it.
Ø Pay the treasure.
Ø Other third party payments required
Note: Payment is made by the user on its own basis and requires application for a micro-public or a payment account number.
Interface Functions
The WEBSERVICE interface is available for other systems and the following interfaces are possible:
User-managed interface:
Ø Opening interface
Ø Remove user interface
Ø Determining whether the user has an interface
Ø User Underline Interface
Ø Modify User Information Interface
Ø Package Change Interface
Ø User-distribute interface
Ø Force down interface
Ø Account Basic Information Query Interface
Ø Daily use of the length/flow query interface
Ø Use traffic query interface per hour
Ø Account Fill Flow Interface
Ø Day/month traffic query interface
Ø Set the date/month traffic warning interface
Ø Send SMS Interface
PORTALAuthentication interface:
Ø Submit authentication interface
Log management
The system provides a well-developed log function, including the following:
Ø Online records: User history of access
Ø Operation Log: Administrator's operating log on the system
Ø Interface Log: WEBSERVICE interface calls and operating log
Ø Text log: Log for text messages
Ø Login log: Manager login
Ø Visitors ' Authorization Log: Log authorized by internal staff to scan company visitors
Ø Identification Log: Identifier interface call and result log
Ø Due reminder log: alerting users of due by text
Ø Proxy log: agent login and operation log record
Ø Empty log: empty logs according to time conditions
Authentication of real names
The system provides a physical name authentication function that allows for strong physical identification as required by national policy and connects to the third-party certification platform interface, enabling three-in-one certifications of cellular numbers, identity numbers and faces recognition.
Decentralization
The integration of role management in the system enables different levels of users to have different managerial competencies over the functionality of the system, facilitating the classification and management of client authority according to project and business.
Different delegation roles can be defined in advance to facilitate the administrator setting.
Agent management
Accounts may be opened for secondary agents and group management privileges assigned;
The agent ' s authority is distinct from that of the administrator and belongs to a separate module, which is usually set up for third-party cooperation agencies to manage their users;
These include:
Organisation
Cannot initialise Evolution's mail component.
Proxy login and operation records
Agent bulletin and circular management
Agent charge discount management
Warning function
Supports the e-mail, text message alert function for equipment offline events and assists users in offline incident processing of equipment, effectively handling problems and protecting equipment assets and reducing operating costs.
Public Security NATSHEL_LOG_AUDIT docking functionality
Support the data docking with equipment manufacturers (such as Ryoshi) identified by the Ministry of Public Security for compliance with Decree No. 32, which will be used to send user certification and access logs to the Internet, including:
Ø Username
Ø Internet time
Ø IP Address
Data Backup
Support multiple data backup functions, including:
Ø Manual backup to local computer
Ø Automatic backup to server local storage
Ø Automail Key Data Backup
Ø Double hot.
Ø Double cooling.
Self-service systems
The system carries its own user self-service platform, and users use their own account to log in to achieve the following:
Ø Query basic information
Ø Query order information
Ø Help off the line.
Ø Query Internet History
Ø Realizing self-service contribution functions
Ø New users register fees online