Passwordless wireless authentication
By managing multiple access tokens and assigning device tokens through an identity proxy server, the cumbersome password authentication problem in wireless networks is solved, enabling seamless passwordless wireless network access and improving user experience and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-04-16
- Publication Date
- 2026-04-07
AI Technical Summary
In existing wireless networks, users need to enter a password or perform other interactions to access the network, which makes the access process cumbersome and inconvenient, especially in environments with multiple identity providers, where credential management is complex.
The identity proxy server receives multiple access tokens, stores them in the user profile, assigns policies, and provides device tokens to achieve seamless passwordless authentication. It uses device tokens to communicate securely with the network, simplifying the network access process for user devices.
It enables seamless, passwordless wireless network access, simplifies the authentication process for user devices, improves user experience, reduces the complexity of credential management, and enhances the security and convenience of network access.
Smart Images

Figure CN115462108B_ABST
Abstract
Description
[0001] Cross Reference to Related Applications
[0002] This application is being filed on April 16, 2021 as a PCT International Patent Application and claims priority to U.S. Non-Provisional Patent Application Serial No. 16 / 856,773 filed on April 23, 2020, the entire disclosure of which is incorporated by reference in its entirety. TECHNICAL FIELD
[0003] The present disclosure relates generally to wireless authentication. BACKGROUND
[0004] In computer networking, a wireless access point (AP) is a networking hardware device that allows Wi-Fi-compatible client devices to connect to a wired network. The AP is usually connected to a router (either directly or indirectly through a wired network), but it can also be an integral component of the router itself. Multiple APs can also work in conjunction, either through direct wired connections or wireless connections or through a central system, often called a wireless local area network (WLAN) controller. An AP is distinct from a hotspot, which is a physical location where people can access a WLAN using Wi-Fi.
[0005] Prior to wireless networks, setting up a computer network in a business, home, or school often required running many cables through walls and ceilings in order to provide network access to all network-enabled devices in a building. With the creation of wireless APs, network users were able to add devices that had access to the network with little or no cabling. APs are usually connected directly to a wired Ethernet connection, and then the AP provides a wireless connection using radio frequency links for other devices to use that wired connection. Most APs support connecting multiple wireless devices to one wired connection. APs are built to support standards for transmitting and receiving data using these radio frequencies. BRIEF DESCRIPTION OF DRAWINGS
[0006] The accompanying drawings, which are incorporated in and constitute a part of this disclosure, illustrate various embodiments of the present disclosure. In the drawings:
[0007] Figure 1 is a block diagram of an operating environment for providing passwordless wireless authentication;
[0008] Figure 2 is a flow diagram of a method for providing passwordless wireless authentication;
[0009] Figure 3 shows a workflow for obtaining an access token;
[0010] Figure 4 is a block diagram showing a profile;
[0011] Figure 5The workflow for providing authentication is shown; and
[0012] Figure 6 It is a block diagram of a computing device. Detailed Implementation
[0013] SUMMARY
[0014] First, multiple access tokens can be received from various identity provider services. Each of these access tokens can be associated with a user. Then, the multiple access tokens can be stored in a profile associated with the user. Next, user policies associated with the use of the multiple access tokens can be assigned. Device tokens can then be provided to the user device associated with the user. Device tokens can be associated with a profile.
[0015] Example Embodiments
[0016] The following detailed description refers to the accompanying drawings. Where possible, the same reference numerals are used in the drawings and the following description to refer to the same or similar elements. Although embodiments of the present disclosure may be described, modifications, adaptations, and other implementations are possible. For example, elements shown in the drawings may be substituted, added, or modified, and the methods described herein may be modified by substituting, reordering, or adding stages to the disclosed methods. Therefore, the following detailed description does not limit the present disclosure. Rather, the appropriate scope of the present disclosure is defined by the appended claims.
[0017] Embodiments of this disclosure can provide passwordless and secure access to wireless networks utilizing identity provider services. For example, identity provider services may include social media or web browser cloud-based identity provider services or enterprise identity provider services. For example, wireless networks may include, but are not limited to, Wi-Fi-based networks, 4G-based networks, or 5G-based networks.
[0018] From a user's perspective, users can provide a set of identities they might be willing to use for wireless access. Users can also configure policies regarding which types of identities they might be willing to reveal to service providers, such as wireless service providers. Furthermore, users can define how much personal information (e.g., name, email address, and phone number) they can share with wireless service providers.
[0019] From a wireless service provider's perspective, the provider can configure what identities or combinations of identities it might be willing to accept in its network, and what minimum information it might request about a user. For example, a provider might accept a combination of two verified cloud provider identities or enterprise identities. It may also require an email address to connect to the user. Nevertheless, embodiments of this disclosure can provide seamless wireless access by matching user policies with wireless service provider policies.
[0020] Therefore, embodiments of this disclosure can provide passwordless access to resources (e.g., network resources, such as wireless networks). This access may not be based on a single credential, but rather on a profile comprising multiple credentials, accompanied by policies regarding where and how they can be used. The profile may not contain any actual credentials or personally identifiable information (PII), but may contain access tokens from the actual credential holder that allow the identity proxy service to authenticate against its application programming interface (API). Thus, the service may not use any specific PII.
[0021] Figure 1 A block diagram of an operating environment 100 for providing passwordless wireless authentication is shown. Figure 1 As shown, the operating environment 100 may include an access device 105, a network 110, a user device 115 operated by a user 120, an identity proxy server 125, an identity provider server 130, and a domain name server (DNS) 135.
[0022] In some embodiments of this disclosure, access device 105 may include a Wi-Fi access point (AP) configured to support a wireless (e.g., Wi-Fi) hotspot. The Wi-Fi hotspot may include a physical location where a user 120 operating user equipment 115 can use Wi-Fi technology to gain access to network 110 (e.g., Internet access) by using a wireless local area network (WLAN) connected to a service provider's router.
[0023] In other embodiments of this disclosure, access device 105 may include a device capable of connecting to a cellular network that can directly and wirelessly communicate with a terminal user device (e.g., user equipment 115 operated by user 120) to provide access to network 110 (e.g., internet access). For example, access device 105 may include, but is not limited to, an eNodeB (eNB) or a gNodeB (gNB). The aforementioned cellular network may include, but is not limited to, a Long Term Evolution (LTE) broadband cellular network, a fourth-generation (4G) broadband cellular network, or a fifth-generation (5G) broadband cellular network operated by a service provider.
[0024] User equipment 115 may include, but is not limited to, smartphones, tablets, personal computers, mobile devices, cellular base stations, telephones, remote control devices, set-top boxes, digital video recorders, cable modems, network computers, mainframes, routers, or other similar microcomputer-based devices capable of accessing and using Wi-Fi or cellular networks. Network 110 may include, for example, the Internet.
[0025] Identity proxy server 125 can provide passwordless access to resources (e.g., network resources, such as wireless networks). As will be described in more detail below, consistent with embodiments of this disclosure, such access may not be based on a single credential, but may be based on a profile including multiple credentials with policies regarding where and how they can be used.
[0026] Identity provider server 130 can create, maintain, and manage identity information for subjects (i.e., users such as user 120), while providing authentication services to dependent applications within a federated or distributed network. The identity provider can offer user authentication as a service. Dependent applications (e.g., web applications) can outsource the user authentication steps to a trusted identity provider. For example, identity provider server 130 could be operated by a social media or web browser-based cloud-based identity provider service or an enterprise identity provider service. Although... Figure 1 An identity provider server 130 is shown, but embodiments of this disclosure may include multiple identity provider servers, each operated by a plurality of identity provider services.
[0027] The Internet maintains two main namespaces: the Domain Name System (DNS) and the Internet Protocol (IP) Address System. The DNS maintains the DNS hierarchy namespace and provides translation services between these two namespaces. Internet name servers (e.g., DNS 135) implement the DNS. For example, DNS 135 translates (i.e., resolves) human-readable domain names and hostnames into corresponding numeric IP addresses, which is the Internet's second main namespace, used to identify and locate computer systems and resources on the Internet.
[0028] The aforementioned components of operating environment 100 (e.g., access device 105, user equipment 115, identity proxy server 125, identity provider server 130, and domain name server 135) can be implemented in hardware and / or software (including firmware, resident software, microcode, etc.) or any other circuit or system. The components of operating environment 100 can be implemented in circuits including discrete electronic components, packaged or integrated electronic chips containing logic gates, circuits utilizing microprocessors, or on a single chip containing electronic components or a microprocessor. Furthermore, the components of operating environment 100 can also be implemented using other technologies (including but not limited to mechanical, optical, fluid, and quantum technologies) capable of performing logical operations (e.g., AND, OR, and NOT). See below for details. Figure 6 In more detail, the components of operating environment 100 can be implemented in computing device 600.
[0029] Figure 2 This is a flowchart illustrating the general stages involved in a method 200 for providing passwordless wireless authentication, consistent with embodiments of this disclosure. Method 200 may use the methods described above regarding... Figure 1 The identity proxy server 125 is implemented in more detail, and the identity proxy server 125 may be provided by the following: Figure 6 The computing device 600 is described in more detail below. The implementation method 200 will be described in more detail below for each stage.
[0030] Method 200 may begin at start box 205 and proceed to stage 210, in which identity proxy server 125 may receive multiple access tokens from corresponding multiple identity provider services. Each of the multiple access tokens may be associated with user 120. Figure 3 A workflow 300 for obtaining an access token is illustrated. For example, using user device 115, user 120 can register for a service that includes an identity proxy and can select an initial identity provider service from a list provided by identity proxy server 125. Figure 3 Phase 302). Identity proxy server 125 can then redirect user 120 to identity provider server 130 by providing user 120 with a redirect Uniform Resource Locator (URL). Figure 3 Stage 304). User 120 can then open the redirect URL ( Figure 3 (Stage 306). In response to user 120 opening the redirect URL, identity provider server 130 can present an authorization user interface to user 120 on user device 115 (stage 308 of Figure 3). User 120 can then enter authorization data into the user interface and submit the entered authorization data to identity provider server 130. Figure 3Phase 310). In response, the identity provider server 130 may provide the user equipment 115 with a redirected network proxy with an authorization code ( Figure 3 Phase 312). User equipment 115 can follow the redirection network proxy to identity proxy 125 ( Figure 3 Phase 314). In response, identity agent 125 can present the authorization code to identity provider server 130 ( Figure 3 In phase 316), the identity provider server 130 can return the access token and refresh token to the identity agent 125. The user can reuse these tokens to obtain... Figure 3 The workflow for access tokens (and refresh tokens) is different identity provider services with multiple identity provider services, so that multiple access tokens can be obtained from the corresponding multiple identity provider services.
[0031] Method 200 can proceed from stage 210 to stage 220, in which the identity proxy server 125 receives multiple access tokens from the corresponding multiple identity provider services, and in stage 220, the identity proxy server 125 can store the multiple access tokens in a profile associated with the user 120. Figure 4 This is a block diagram illustrating document 405. For example, user 120 can repeat... Figure 3 The workflow can be repeated multiple times to create a more complete identity profile (405). For example, it can be repeated... Figure 3 The workflow is implemented in four steps to establish processes including, for example, Figure 4 The diagram shows multiple access tokens: a first access token 410, a second access token 415, a third access token 420, and a fourth access token 425. Profile 405 may store access tokens for user 120 used for services from the corresponding multiple identity providers. Profile 405 may contain access tokens and refresh tokens that enable identity proxy service 125 to authenticate user 120 using a specific identifier and to grant access to profile information for that specific identifier.
[0032] Once identity proxy server 125 has stored multiple access tokens (e.g., first access token 410, second access token 415, third access token 420, and fourth access token 425) in a profile 405 associated with user 120 in phase 220, method 200 can proceed to phase 230, where identity proxy server 125 can assign a policy 430 to user 120 associated with the use of the multiple access tokens. For example, user 120 may have a set of credentials (e.g., multiple access tokens from various identity provider services) that can be combined into profile 405. Policy 430 can now be assigned for: which credentials (or combinations thereof) can be provided for which types of services, and with whom which personal attributes can be shared. Therefore, in this case, authentication may not occur for a specific identity, but rather for user 120's entire profile 405, along with the associated credentials and policy 430.
[0033] After identity proxy server 125 assigns policy 430 to user 120 associated with the use of multiple access tokens in phase 230, method 200 may proceed to phase 240, in which identity proxy server 125 may provide a device token to user device 115 associated with user 120. The device token may be associated with profile 405. For example, user 120 may now delegate trust to one or more of user 120's devices 430 (first device 435, second device 440, third device 445, and fourth device 450) based on profile 405. User device 115 may include any of the first device 435, second device 440, third device 445, and fourth device 450. Trust can be delegated by generating a device token bound to user 120's profile 405 and providing the device token to user device 115. User device 115 with the device token may instruct user device 115 to be trusted by user 120 and attached to user 120's profile 405. The device token can be securely downloaded to user device 115 and can be used for authentication of network services of user device 115 for mapping to profile 405 of user 120.
[0034] After creating a 405 profile, seamless authentication for the identity proxy service can be provided. Figure 5 The workflow 500 for providing authentication is shown. Although Figure 5Authentication of a Wi-Fi network may be demonstrated, but other types of wireless networks consistent with embodiments of this disclosure may be used. Consistent with embodiments of this disclosure, when user 120 attempts to authenticate a service (e.g., a wireless service) using user 120's device token, the identity proxy service can understand that user device 115 belongs to user 120 (e.g., through the presented device token). Therefore, the identity proxy service may attempt to authenticate the wireless service based on user 120's profile 405 and policies by utilizing the identity verification made when user 120 registered one or more network identities in profile 405. Therefore, user 120 may not need a password or other interaction, thus providing a seamless experience.
[0035] Method 200 can proceed from stage 240 to stage 250, in which identity proxy server 125 provides a device token to user device 125 associated with user 120, and in stage 250, identity proxy server 125 can receive the device token and network policy. For example, after creating profile 405 and distributing the device token as described above, user 120 (and user device 115) can enter the coverage area of an access device (e.g., similar to access device 105 described above) belonging to a Wi-Fi access network 505 controlled, for example by an enterprise (e.g., a retail store). User device 115 can attempt to attach its device token to network 505. Figure 5 As shown, network 505 can send a beacon or message to the device, which instructs user equipment 115 to support the service. Figure 5 Phase 502). In response, user equipment 115 can attach to a network or service (in the Wi-Fi context, Service Set Identifier (SSID)) using the beacon. Figure 5 Phase 504). Next, network 505 can send an identity request to user equipment 115 (in the WiFi context, this is an EAP identity request) ( Figure 5 Phase 506), thus indicating which credentials the network 505 can support. User equipment 115 can respond with appropriate credentials (in the WiFi context, including EAP authorization for supported credentials). Figure 5 Phase 508). Network 505 can then use DNS 135 to look up the address of the identity proxy server 125 ( Figure 5 Phase 510). A secure communication tunnel (e.g., a Transport Layer Security (TLS) tunnel certified by ID federated certificates) can then be established between network 505 and identity proxy server 125. Figure 5Phase 512). Identity proxy server 125 can receive device tokens and network policies in messages via the secure tunnel (in the Wi-Fi context, this is an EAP message via a TLS tunnel). Figure 5 Phase 514).
[0036] Once identity proxy server 125 receives the device token and network policy in phase 250, method 200 can proceed to phase 260, where identity proxy server 125 can determine that user policy 430 and network policy are consistent. For example, as an authentication source, network policy 505 can instruct network 505 to trust both the first and second identity provider services, but not the third identity provider service. Network policy 505 can also instruct that user 120 can receive a premium experience if user 120 provides an email address. User policy 430 can instruct user 120 to provide a certificate as an authentication source for any of the first, second, and third identity provider services. User policy 430 can also instruct user 120 to allow sharing user 120's email address with the retail store. Therefore, identity proxy server 125 can determine that user policy 430 and network policy (i.e., network policy 505) are consistent.
[0037] After identity proxy server 125 determines in stage 260 that user policy 430 and network policy are consistent, method 200 can proceed to stage 270, in which identity proxy server 125 can authenticate at least one of multiple identity provider services in response to determining that the user policy and network policy are consistent. For example, identity proxy server 125 can check whether user 120's profile 405 has an authentication token for a first identity provider service or a second identity provider service. If so, identity proxy server 125 can attempt to authenticate to one of the APIs of the first identity provider service or the second identity provider service. Figure 6 (Phase 516). Since user 120's profile 405 allows sharing of an email address with the retail store, user 120's email address can also be retrieved from the first identity provider service or the second identity provider service and returned to network 505 via a secure tunnel. Therefore, user device 115 can be allowed to join network 505 and can be given premium services (Phase 520 of Figure 5).
[0038] Consistent with other embodiments of this disclosure, an enterprise network may trust only its own credentials; however, to ensure user credentials are not compromised, the enterprise network may also wish to verify user identity using auxiliary credentials from, for example, a first identity provider service or a second identity provider service. A user may access the enterprise network, and the user's device may attempt to attach to the enterprise network using its device token. The identity proxy server may receive the device token and enterprise network policies. The identity proxy server may check to see if the user has a first identity provider service access token or a second identity provider service access token, and authenticate with the enterprise and with one of the first or second identity provider services. If the enterprise credentials have not been revoked, and one of the first or second identity provider service credentials matches, the user may be allowed access to the enterprise network. Consistent with embodiments of this disclosure, biometric verification may also be added for identity verification. Once the identity proxy server 125 has authenticated at least one of the multiple identity provider services in stage 270, method 200 may end in stage 280.
[0039] Figure 6 A computing device 600 is shown. (For example...) Figure 2 As shown, computing device 600 may include a processing unit 610 and a memory unit 615. Memory unit 615 may include software module 620 and database 625. When executed on processing unit 610, software module 620 may perform functions such as providing services as described above. Figure 1 The aforementioned passwordless wireless authentication process. For example, computing device 600 can provide an operating environment for access device 105, user device 115, identity proxy server 125, identity provider server 130, and domain name server 135. Access device 105, user device 115, identity proxy server 125, identity provider server 130, and domain name server 135 can operate in other environments and are not limited to computing device 600.
[0040] Computing device 600 can be implemented using Wi-Fi access points, cellular base stations, tablet devices, mobile devices, smartphones, telephones, remote control devices, set-top boxes, digital video recorders, cable modems, personal computers, network computers, mainframes, routers, switches, server clusters, smart TVs, network storage devices, network relay devices, or other similar microcomputer-based devices. Computing device 600 can include any computer operating environment, such as handheld devices, multiprocessor systems, microprocessor-based or programmable transmitter electronics, minicomputers, mainframes, etc. Computing device 600 can also be implemented in a distributed computing environment, where tasks are performed by remote processing devices. The foregoing systems and devices are examples, and computing device 600 can include other systems or devices.
[0041] For example, embodiments of this disclosure can be implemented as a computer process (method), computing system, or article of manufacture, such as a computer program product or a computer-readable medium. A computer program product can be a computer storage medium readable by a computer system and encoded with a program of computer instructions for executing a computer process. A computer program product can also be a propagated signal on a carrier readable by a computer system and encoded with a program of computer instructions for executing a computer process. Therefore, this disclosure can be embodied in hardware and / or software (including firmware, resident software, microcode, etc.). In other words, embodiments of this disclosure can take the form of a computer program product on a computer-usable or computer-readable storage medium having computer-usable or computer-readable program code embodied in the medium for use by or in conjunction with an instruction execution system. A computer-usable or computer-readable medium can be any medium that can contain, store, transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0042] Computer-usable or computer-readable media can be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, apparatuses, or propagation media. In more specific examples of computer-readable media (a non-exhaustive list), computer-readable media can include: electrical connections having one or more wires, portable computer floppy disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, and portable optical disc read-only memory (CD-ROM). Note that computer-usable or computer-readable media can even be paper or other suitable media on which programs are printed, because programs can be captured electronically by, for example, optical scanning of paper or other media, and then compiled, interpreted, or otherwise processed as necessary, and then stored in computer memory.
[0043] While some embodiments of this disclosure have been described, other embodiments may exist. Furthermore, although the embodiments of this disclosure have been described in association with data stored in memory and other storage media, data may also be stored on or read from other types of computer-readable media, such as auxiliary storage devices like hard disks, floppy disks or CD-ROMs, media from the Internet, or other forms of RAM or ROM. Additionally, stages of the disclosed method may be modified in any way without departing from this disclosure, including through reordering stages and / or insertion or deletion stages.
[0044] Furthermore, embodiments of this disclosure can be practiced in circuits including discrete electronic components, in packages or integrated electronic chips containing logic gates, in circuits utilizing microprocessors, or on a single chip containing electronic components or a microprocessor. Embodiments of this disclosure can also be practiced using other techniques (including, but not limited to, mechanical, optical, fluid, and quantum technologies) capable of performing logical operations (e.g., AND, OR, and NOT). Additionally, embodiments of this disclosure can be practiced in general-purpose computers or any other circuit or system.
[0045] Embodiments of this disclosure can be practiced via a system-on-a-chip (SOC), wherein in Each or more components shown herein can be integrated onto a single integrated circuit. Such a SoC device may include one or more processing units, graphics units, communication units, system virtualization units, and various application functions, all of which can be integrated (or “burned in”) as a single integrated circuit onto a chip substrate. When operating via the SoC, the functions described herein with respect to embodiments of this disclosure can be performed by dedicated logic integrated on a single integrated circuit (chip) along with other components of the computing device 600.
[0046] For example, embodiments of the present disclosure have been described above with reference to block diagrams and / or operational illustrations of methods, systems, and computer program products according to embodiments of the present disclosure. Functions / actions indicated in the boxes may not appear in the order shown in any flowchart. For example, depending on the functions / actions involved, two consecutively displayed boxes may actually be executed substantially simultaneously, or these boxes may sometimes be executed in reverse order.
[0047] While the specification includes examples, the scope of this disclosure is indicated by the appended claims. Furthermore, although the specification has been described in language specific to structural features and / or method actions, the claims are not limited to the features or actions described above. Rather, the specific features and actions described above are disclosed as examples of embodiments of this disclosure.
Claims
1. A method for wireless authentication, comprising: The computing device receives multiple access tokens from various identity provider services, each of which is associated with a user. The multiple access tokens are stored in a profile associated with the user; Assign user policies associated with the use of the multiple access tokens; Provide a device token to the user device associated with the user, the device token being associated with the profile; Receive the device token and network policy; as well as It is determined that the user policy and the network policy are consistent.
2. The method according to claim 1, wherein, Receiving the multiple access tokens also includes receiving corresponding and multiple refresh tokens.
3. The method according to claim 2, further comprising: The multiple refresh tokens are stored in a profile associated with the user.
4. The method according to claim 2, further comprising: Use the refresh token to refresh the plurality of access tokens.
5. The method according to claim 1, wherein, Receiving the device token and the network policy includes: receiving the device token and the network policy in response to the user equipment attempting to attach to the network using the device token.
6. The method according to claim 1, further comprising: In response to determining that the user policy and the network policy are consistent, authentication is performed on at least one of the plurality of identity provider services.
7. A system for wireless authentication, comprising: Memory storage devices; as well as A processing unit, coupled to the memory storage device, wherein the processing unit is operable to: Receive device tokens and network policies. Determine that the user policy and the network policy are consistent, and In response to determining that the user policy and the network policy are consistent, authentication is performed on at least one of the multiple identity provider services.
8. The system according to claim 7, wherein, The processing unit is operable to receive the device token and the network policy, including: the processing unit is operable to receive the device token and the network policy in response to a user equipment attempting to attach to the network using the device token.
9. The system according to claim 7 or 8, wherein, The processing unit is also capable of operating for: Receive multiple access tokens from the corresponding multiple identity provider services, each of which is associated with the user; The multiple access tokens are stored in a profile associated with the user; Assign the user policy associated with the use of the multiple access tokens; as well as The device token, which is associated with the profile, is provided to the user device associated with the user.
10. The system according to claim 9, wherein, The processing unit is operable to receive the plurality of access tokens, and also operable to receive corresponding and multiple refresh tokens.
11. The system according to claim 10, wherein, The processing unit is also capable of storing the plurality of refresh tokens in a profile associated with the user.
12. The system according to claim 10 or 11, wherein, The processing unit is also capable of operating to refresh the plurality of access tokens using the refresh token.
13. A computer-readable medium storing an instruction set, which, when executed, performs a method executed by the instruction set, the method comprising: The computing device receives multiple access tokens from various identity provider services, each of which is associated with a user. The multiple access tokens are stored in a profile associated with the user; Assign user policies associated with the use of the multiple access tokens; Provide a device token to the user device associated with the user, the device token being associated with the profile; Receive the device token and network policy; as well as It is determined that the user policy and the network policy are consistent.
14. The computer-readable medium according to claim 13, wherein, Receiving the multiple access tokens also includes receiving corresponding and multiple refresh tokens.
15. The computer-readable medium of claim 14, further comprising: The multiple refresh tokens are stored in a profile associated with the user.
16. The computer-readable medium according to claim 14 or 15, further comprising: Use the refresh token to refresh the plurality of access tokens.
17. The computer-readable medium of claim 13, wherein, Receiving the device token and the network policy includes: receiving the device token and the network policy in response to the user equipment attempting to attach to the network using the device token.
18. The computer-readable medium according to claim 13 or 17, further comprising: In response to determining that the user policy and the network policy are consistent, authentication is performed on at least one of the plurality of identity provider services.
Citation Information
Patent Citations
Identity management over multiple identity providers
US20170099281A1
Generating and Managing a Composite Identity Token for Multi-Service Use
US20190097802A1