Joint strategy exchange
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-22
- Publication Date
- 2026-08-14
Smart Images

Figure CN116458183B_ABST
Abstract
Description
Technical Field
[0001] The embodiments presented in this disclosure generally relate to network management. More specifically, the embodiments disclosed herein provide for the exchange and selection of identity and supplementary data in order to obtain access to a network or services provided by the network as one of several potential identities. Background Technology
[0002] Various networks and services allow users to gain access to services via an associated user equipment (UE) (also referred to as a site (STA) or mobile site) using an associated identity. For example, once a user verifies the identity or information provided by a first service (e.g., a username / password combination), the first service can provide access. However, services can federate to share credentials and user identities to determine how and whether to grant access to an associated service based on identities used by other services in the identity federation. As identity federation is deployed, each user can accumulate an increasingly larger set of possible identities that can be used to log in to a given network or other federated services. Attached Figure Description
[0003] To gain a more detailed understanding of the features described above, the present disclosure, which has been briefly summarized above, can be described in more detail with reference to embodiments, some of which are illustrated in the accompanying drawings. However, it should be noted that the accompanying drawings illustrate typical embodiments and should not be considered limiting; other equivalent embodiments may be contemplated.
[0004] Figure 1 A network environment supporting federated policy exchange according to embodiments of the present disclosure is illustrated.
[0005] Figure 2 This is a flowchart of a method for expanding shared federated identities according to embodiments of the present disclosure.
[0006] Figure 3 This is a flowchart of a method according to an embodiment of the present disclosure, for a UE to process an identity sharing request from a network that supports federated identity for data sharing.
[0007] Figures 4A-4C This is a timing diagram of an AP authenticating a UE in a wireless network that supports federated identity for data sharing, according to an embodiment of the present disclosure.
[0008] Figures 5A to 5C This is a timing diagram for responding to identity and data sharing requests according to embodiments of this disclosure.
[0009] Figure 6 Hardware of a computing device according to an embodiment of the present disclosure is shown.
[0010] For ease of understanding, the same reference numerals are used where possible to designate common elements in the figures. Elements disclosed in one embodiment may be advantageously used in other embodiments without specific description. Detailed Implementation
[0011] Overview
[0012] One embodiment presented in this disclosure is a method comprising: in response to receiving a sharing query from an access point (AP), determining whether the sharing query is within a sharing preference, wherein the AP indicates that the relevant wireless network supports federated identity for data sharing; and in response to determining that the sharing query is within a sharing preference, transmitting an affirmative response to the AP for identity sharing, the affirmative response authorizing the collection and sharing of identity data with at least one entity identified in the sharing policy of the relevant wireless network.
[0013] One embodiment presented in this disclosure is a method comprising: transmitting a support notification via an access point (AP) indicating support for federated identity for data sharing within a wireless network associated with the access point; and transmitting a sharing policy of the wireless network to the UE in response to receiving a first identified sharing preference from a user equipment (UE), the first identified sharing preference indicating that negotiation is preferred.
[0014] One embodiment presented in this disclosure is an apparatus comprising: a processor; and a memory including instructions that, when executed by the processor, configure the apparatus to: determine whether the sharing query is within a sharing preference in response to receiving a sharing query from an access point (AP), wherein the AP indicates that the associated wireless network supports federated identity for data sharing; and, in response to determining that the sharing query is within a sharing preference, transmit an affirmative response to the AP authorizing the collection and sharing of identity data with at least one entity identified in the sharing policy of the associated wireless network.
[0015] Federation policy exchange is provided in response to: determining whether the sharing query is within a sharing preference in response to receiving a sharing query from an access point (AP), wherein the AP indicates that the associated wireless network supports federated identity for data sharing; and transmitting an affirmative response to the AP in response to determining that the sharing query is within the sharing preference, the affirmative response authorizing the collection and sharing of identity data with at least one entity identified in the sharing policy of the associated wireless network. In various embodiments, federated policy exchange includes: transmitting a support notification via the access point (AP) indicating support for federated identity for data sharing within the wireless network associated with the access point; and transmitting the sharing policy of the wireless network to the UE in response to receiving a first identified sharing preference from a user equipment (UE), the first identified sharing preference indicating that negotiation is preferred.
[0016] Example Implementation
[0017] This disclosure provides federated policy exchange to manage several valid identities for users seeking access to a network or services provided by the network. The federated policy exchange described herein enables users to securely exchange credentials with one or more identity providers (IdPs) via an associated user equipment (UE), thereby keeping the credentials hidden from the access provider. However, if identity sharing is allowed, these hidden identities can provide various additional benefits to users, service providers, or various third-party partners. Accordingly, this disclosure provides elements in which the UE (representing the user) shares one or more identities with service providers (e.g., locations providing wireless networks) and partners of the access provider (e.g., providing user incentives based on user identities) while still maintaining control over the user identities.
[0018] Figure 1 A network environment 100 supporting federated policy exchange according to an embodiment of the present disclosure is illustrated. Figure 1 In this context, UE 110 seeks access to wireless network 120 (e.g., a cellular or Wi-Fi-based wireless network provided to users in public or private locations). Service providers may deploy the wireless network via one or more access points (APs) 130a-b (generally or collectively referred to as AP 130) and establish various controls on wireless network 120 to authenticate the user's identity (via UE 110) before granting access. In various embodiments, wireless network 120 includes a network controller 160 that communicates with AP 130 to coordinate network management among AP 130; however, multiple APs 130 may also manage their own network (thus omitting network controller 160 in some embodiments).
[0019] UE 110 may include any computing device configured to wirelessly connect to one or more APs 130. Example UE 110 may include, but is not limited to: smartphones, feature phones, tablets, laptops, desktop computers, Internet of Things (IoT) devices, etc. In various embodiments, UE 110 may also be referred to as a site (STA), client device (CD), or endpoint. Reference will be made to... Figure 6 A more detailed discussion of example hardware that can be included in UE 110.
[0020] AP 130 can provide wireless communication sessions in wireless network 120 according to various radio access technologies and communication standards, such as, but not limited to, "Wi-Fi" networking (various families, substandards, and derivatives of the IEEE 802.11 standard), cellular networking (including its various generations and subtypes, such as Long Term Evolution (LTE) and 5G New Radio (5G) networks, Citizens Broadband Radio Service (CBRS) networks, etc.). References will be made to... Figure 6 A more detailed discussion of example hardware that can be included in the AP 130.
[0021] Network controller 160 (if included) may include any computing device or cloud-based service configured to communicate with two or more APs 130 to coordinate how to share spectrum in environment 100. Network controller 160 may be provided on a separate computing device connected to the individual APs 130 via wired or wireless communication, may be included in a “central” or “command” AP 130, or may provide temporary arrangements for network management through collective negotiation between two or more APs 130. (See reference...) Figure 6 Example hardware that can be included in the network controller 160 will be discussed in more detail.
[0022] When UE 110 attempts to gain access to wireless network 120 and associate with AP 130, the network provider may request UE 110 to provide the user's identity so that services can be tracked and appropriately assigned to UE 110. In various embodiments, UE 110 may authenticate directly on wireless network 120 (e.g., using an identity and credentials set up on the network provider), or may use an externally verified identity confirmed by one or more identity providers 140a-b (generally or collectively referred to as identity provider 140). When a service provider (e.g., a network provider) allows the use of a third-party identity provider 140 (also referred to as IdP) to gain access to the provider's services (e.g., wireless network 120), the service provider is referred to as providing federated services or participating in identity federation.
[0023] Identity provider 140 is an entity through which users can create and manage various identities, and network providers can delegate authentication functions through these identity providers 140. For example, a user can register with identity provider 140 of a social network to gain access to wireless network 120 by authenticating with the social network, in turn, the social network guarantees the user's authenticity and identity to the network provider. Accordingly, the network provider, as a service provider, can avoid the need to create a separate account for each user attempting to access wireless network 120, instead relying on one or more trusted identity providers 140 to verify the identity of the requesting user. In various embodiments, the service of identity provider 140 can be an internal authentication service shared by several service providers in wireless network 120, or an external authentication service used by several service providers providing one or more wireless networks 120. (See also...) Figure 6 Example hardware that can be included in a server providing services to identity provider 140 will be discussed in more detail.
[0024] The identity of a user of UE 110 is generally kept private between identity provider 140 and network provider for gaining access to the wireless network via verified identity. However, with user permission, this identity data may be shared with one or more partners 150a-b (generally or collectively referred to as Partner 150) of the service provider. In various embodiments, Partner 150 may be identity provider 140 or other entities that have agreements with service providers who wish (via the associated UE 110) to know when a user is in a given location or using a given service. With user permission, the network provider may share this supplementary data with one or more authorized partners 150 and may offer various incentives to users who grant such sharing authorization (but not to users who deny authorization). (See reference...) Figure 6 A more detailed discussion of example hardware that can be included in the servers providing services to Partner 150.
[0025] Figure 2This is a flowchart of a method 200 for extending shared federated identity according to embodiments of the present disclosure. Method 200 begins at block 205, where AP 130 sends a notification to one or more UEs 110 that the wireless network 120 supports federated identity. In various embodiments, the support notification is included in a network beacon broadcast to the environment, but the support notification may also be unicast to UEs 110 as part of the onboarding process of the wireless network 120. The support notification may indicate the required levels of identification, the allowed identity providers 140, and some or all of the sharing policies and sharing incentives provided by the wireless network 120. The sharing policies may indicate the sharing frequency, sharing time, with which partners 150 are shared, and what types of data (and combinations thereof) are shared by UEs 110. In various embodiments, the support notification may be sent via multiple messages at different times during the onboarding process and may be updated as incentives change.
[0026] At box 210, AP 130 receives a response from UE 110 indicating the user's sharing preference for data sharing. In various embodiments, the UE may express these preferences during authentication (e.g., via Extensible Authentication Protocol (EAP) exchange), when associated with a given AP 130 in wireless network 120, or via a browser session (e.g., via Acceptable Usage Policy (AUP) selection).
[0027] Identity sharing preferences can be set via message payload, via flags with specific meanings in header (or other designated) fields, and combinations thereof. For example, UE 110 can express a user's identity sharing preferences to indicate to the network provider that: identity information will not be shared with identity provider 140 and other already qualified entities except for authentication purposes; identity sharing is permitted with known (and approved) partners 150; identity sharing is permitted at the network provider's discretion; and more information will be requested from the network provider before committing to the preferences.
[0028] In various embodiments, sharing preferences can be explicitly set by the user (or an administrator acting on behalf of the user) or defined locally on the UE 110, or they can be gradually learned by the UE 110 based on user actions via machine learning or other models. For example, the UE 110 can learn which types of service providers a user prefers to share with, based on the user's tendency to accept sharing in hotels but not in stadiums or shopping malls. In another example, the UE 110 can learn which types of identity and supplementary data a user allows to share, based on the user's frequent permission to share social media presence but never permission to share email accounts. Accordingly, the UE 110 can infer sharing policies based on past user actions to streamline responses to identity sharing policy queries or to allow users to control how or whether to share additional data with service providers. Thus, in various embodiments, the UE 110 can determine whether a query for sharing data is within a sharing policy by requesting user input to authorize data sharing (e.g., "The network wants to share data X; approve / reject"), referencing predefined settings or control panel options set by the user (or an administrator acting on behalf of the user), inferring appropriate actions (e.g., approve / reject) based on historical user choices of approving or rejecting sharing, and combinations thereof.
[0029] At box 215, AP 130 determines what the sharing policy preference indicates in order to determine how to further interact with UE 110. When the policy preference indicates that UE 110 will share its identity only for authentication purposes and that its identity should remain private in other situations, method 200 proceeds to box 220. When the policy preference indicates that UE 110 will share its identity, supplementary data (if collected), and its analysis with certain partners 150 or as determined by the network provider, method 200 proceeds to box 225. Otherwise, when UE 110 indicates that the user wants to know more about the service provider's sharing policy before selecting a positive or negative response to sharing, method 200 proceeds to box 230.
[0030] At box 220, AP 130 collects (and forwards to the selected identity provider 140) the identity and credentials provided by UE 110 to authenticate the user. Upon receiving authentication confirmation (or rejection) from identity provider 140, AP 130 grants (or denies) access to wireless network 120 based on the provided identity. This identity is used to track services provided by the network provider, but otherwise maintains privacy. Thus, when UE 110 is identified, the network provider maintains the privacy of the user's identity and other supplementary data while providing the ability to share data with various UEs 110. Method 200 then proceeds to box 235.
[0031] At box 225, AP 130 collects (and forwards to the selected identity provider 140) the identity and credentials provided by UE 110 to authenticate the user. Upon receiving authentication confirmation (or rejection) from identity provider 140, AP 130 grants (or denies) access to wireless network 120 based on the provided identity. AP 130 may passively collect or actively query UE 110 for further identity, application usage status, location data, etc., and forward this identity data and related supplementary data to various partners 150 based on user-expressed policies (allowing or denying sharing with specific entities) or the service provider's discretion. Method 200 then proceeds to box 235.
[0032] At box 230, AP 130 sends a provider policy for sharing data to UE 110 as part of a negotiation process regarding whether to share data collected from UE 110. In various aspects, the sharing mode may express that the collected data is strictly for internal use by the network provider (e.g., for network monitoring / load balancing / analysis / support) and will be shared with an explicitly listed partner 150, or will be shared with a requesting entity (e.g., a partner 150 not on a publicly disclosed list) based on the network provider's decision.
[0033] Once UE 110 receives the provider's sharing policy, UE 110 can determine how or whether to share data with AP 130. Accordingly, method 200 returns to block 210 so that AP 130 receives the sharing preference from UE 110. In various embodiments, if no response is received from UE 110 within a given time frame, AP 130 treats the lack of response as a denial of permission and proceeds as if UE 110 had provided an explicit response of not sharing data.
[0034] At box 235, AP 130 determines whether the network provider's sharing policy indicates any incentive to provide sharing to UE 110. If no incentive is indicated, method 200 proceeds to box 240. Otherwise, if an incentive is indicated, method 200 proceeds to box 245.
[0035] At block 240, AP 130 continues to collect data permitted by preferences received from UE 110 and shares it according to the network provider's policy agreed upon by the user. In various embodiments, the user (via UE 110) may extend or withdraw permission to share various data, or AP 130 may extend incentives to encourage the user to share additional data. Accordingly, method 200 may return to block 210 in response to receiving updated sharing preferences from UE 110 or updated policies / incentives from the network controller.
[0036] At box 245, AP 130 determines whether prerequisites for providing incentives have been met. In various embodiments, prerequisites may include static data (e.g., data not expected to change over time), such as the identity provided for service access, the operating system of UE 110, form factor details of UE 110 (e.g., device model, laptop / tablet / phone category, etc.), which may be provided once to satisfy multiple checks on whether the prerequisites are met. Additionally or alternatively, prerequisites may include dynamic data (e.g., data that can change over time), such as the location of UE 110, application usage data, or similar data. Accordingly, AP 130 may receive data for comparison with the prerequisites (and permission or denial of sharing this data) once and continuously determine whether to provide or deny incentives based on this data, or may send specific queries from time to time to collect additional dynamic data from UE 110.
[0037] When the preconditions have been met and UE 110 has indicated that it allows sharing of the relevant data, method 200 proceeds to block 250. When UE 110 has refused to use the data, regardless of whether UE 110 actually met the preconditions, method 200 proceeds to block 240. Otherwise, when the preconditions are not met, method 200 proceeds to block 255.
[0038] At box 250, AP 130 implements incentives for UE 110 to meet prerequisites. In various embodiments, incentives may include additional data throughput or bandwidth, higher service levels or quality of experience levels, licenses for various applications, subsidized bandwidth costs, local edge process offloading, required credentials (or links thereof), or virtual elements that can be exchanged for real-world items. Method 200 then proceeds to box 240.
[0039] At box 255, AP 130 notifies UE 110 of available incentives from the service provider. In various embodiments, AP 130 may indicate in more detail the existence of incentives for sharing or specific incentives and their prerequisites, and may send one or more messages to UE 110 to inform UE 110 of available incentives and to gauge the user's interest in receiving these incentives. For example, AP 130 may notify UE 110, "Additional incentives are available for additional sharing - respond if interested," to establish a negotiation session, or may directly indicate, "Incentive X is available for licensed sharing information Y - respond if interested," to send a specific query to UE 110. Method 200 then returns to box 210 so that UE 110 responds to the incentive notification (or does not respond, which is considered a negative response or rejection of the query).
[0040] Figure 3 This is a flowchart of method 300 according to an embodiment of the present disclosure, for UE 110 to process an identity sharing request from a network that supports federated identity for data sharing. Method 300 begins at block 310, where UE 110 receives a sharing query from wireless network 120. In various embodiments, one or more APs 130 in wireless network 120 may send an initial notification to UE 110 (via unicast or broadcast) that wireless network 120 supports data sharing via federated identity, and UE 110 may respond to these notifications with an initial sharing preference. Additionally or alternatively, in some embodiments, AP 130 may send subsequent queries to UE 110 to request new data or to confirm whether UE 110 maintains its initial sharing preference or has been updated regarding how or whether to share data related to the provided identity and other supplementary data.
[0041] In various embodiments, a sharing query can be a general sharing query or a specific sharing query. A general sharing query request is for which some or all of the data collected as part of providing access to the wireless network 120 is authorized for sharing. This data, along with related analyses, may include user identity, user location, data throughput (uplink or downlink) rate, etc. A specific sharing query A may request the UE 110 to provide data relating to: operating system, device form factor, additional user identity, active (or previously active) applications running on the UE 110, and other data that is beyond or exceeds the data transmitted and collected to provide the basic set of services (BSS) of the wireless network 120.
[0042] At box 320, UE 110 determines whether the data requested in the sharing query is within the user's sharing preferences. When the query is for data within the user's sharing preferences, method 300 proceeds to box 330. When the query is for data outside of the sharing preferences, method 300 proceeds to box 340. When UE 110 determines that the information previously provided by AP 130 regarding the sharing policy is insufficient to provide a positive or negative response to the sharing query, method 300 proceeds to box 350.
[0043] In various embodiments, UE 110 may transmit sharing preferences to AP 130 in response to a specific query received from the network to share certain data, as part of a login operation (e.g., via EAP exchange or when associated with a given AP 130 in wireless network 120), or via a browser session and AUP selection. When UE 110 sends sharing preferences to AP 130, wireless network 120 can determine that subsequent queries will be responded to affirmatively or negatively without needing to send additional messages to UE 110, thereby potentially saving bandwidth.
[0044] At block 320, UE 110 determines the user's preference for whether to share data based on the sharing policy provided by AP 130 in block 315. Method 300 then returns to block 305 so that UE 110 transmits its sharing policy based on the service provider's currently known sharing policy. In various embodiments, method 300 may repeat blocks 305-320 several times for UE 110 to progressively gain a greater understanding of the service provider's sharing policy before making a final decision on whether to share data with the service provider. In various embodiments, queries may be within (or outside) sharing preferences based on the requested level of sharing, the partner 150 with which data is to be shared, the entity type of the service provider making the request, the data type of the requested data, and combinations thereof. Users of UE 110 can specifically set various sharing policies, or UE 110 can learn user preferences over time based on the user's acceptance or rejection of various requests (e.g., via a machine learning model) to automatically respond to queries.
[0045] Method 300 may return to box 320 after providing UE 110 with additional information about the service provider's sharing policy (box 360) or the service provider's sharing incentives (box 370). After returning to box 320, UE 110 may update the selected response based on the new information and may choose to further negotiate to understand additional details of the policy and incentives in the wireless network 120.
[0046] At box 330, UE 110 responds to a sharing query with an affirmative response to AP 130. In various embodiments, the affirmative response may include authorization to share data related to UE 110 that has already been collected by wireless network 120, or it may include additional data specifically requested to be shared. For example, the affirmative response may allow the wireless network to share a user's identity (used to gain access to wireless network 120) with one or more partners 150, or it may include a response to a specific query. The specific query may request data such as: whether a specific application is installed on UE 110 or has been previously activated, whether UE 110 is located in a specific area, when a specific application is started or terminated (e.g., for calculating usage time) or the usage time of the application, the capabilities of UE 110 (e.g., whether it is an augmented reality (AR) application), whether UE 110 is paired with an external device (e.g., a screen, watch, glasses, headphones, microphone), and so on.
[0047] After UE 110 transmits an affirmative response, when AP 130 sends a follow-up request for UE 110 to share identity data and related analysis, method 300 can restart from box 310.
[0048] At box 340, if the query in box 320 is not within the user's preferences, UE 110 ignores the query (does not send a response to the shared query to AP 130) or sends a rejection message for the shared query to AP 130. Then, method 300 can proceed to box 370, where AP 130 sends an incentive notification to UE 110, or method 300 can restart at box 310 when AP 130 sends a subsequent request to UE 110 to share identity data, supplementary data (if collected), and related analysis.
[0049] At box 350, UE 110 responds to the sharing query with a negotiation response to AP 130, indicating that UE 110 requests further information before providing a positive or negative response to the authorized data sharing (as per boxes 330 and 340, respectively).
[0050] At box 360, in response to transmitting a preference for negotiating (further) data sharing with the service provider (by box 350), UE 110 receives a sharing policy from AP 130. In various embodiments, the sharing policy may be delivered via one or more messages of varying levels of detail from AP 130. UE 110 may receive general sharing policy details from the service provider or receive specific policies. For example, the sharing policy may indicate that the collected data is strictly for the network provider's internal use (e.g., for network monitoring / load balancing / analysis / support), will be shared with partners 150 on an explicit list, or may be shared by the network provider at its discretion with requesting entities (e.g., partners 150 on an undisclosed list), and may indicate the specific data types to be collected and shared according to each pattern.
[0051] At block 370, UE 110 optionally receives incentive notification from AP 130. In various embodiments, when wireless network 120 has one or more incentives that UE 110 may be eligible for, AP 130 transmits the incentive notification along with details of the sharing policy of wireless network 120 or in a separate transmission. In some embodiments, the sharing incentive is provided in a notification sent prior to a sharing query, or remembered by UE 110 from a transmission prior to the currently analyzed sharing query. In various embodiments, the incentive notification may indicate what data (and according to what sharing mode) UE 110 is requested to share for a specific incentive (e.g., higher bandwidth, higher QoE), or serve as an alert that an incentive is available and UE 110 should enter a negotiation process (e.g., as determined by negotiation at block 320) to learn about the details of the incentive or sharing mode. Method 300 returns to block 320 after block 370 so that UE 110 can analyze whether its sharing preference has been satisfied based on the received sharing incentive.
[0052] Figures 4A-4C This is a timing diagram of an AP 130 for authenticating a UE 110 in a wireless network 120 that supports federated identity for data sharing, according to an embodiment of the present disclosure.
[0053] In various embodiments, the network provider may notify various UEs 110 at several times that they support federated identity in the wireless network 120. The network provider may remind the UE at several different times during the login process that the wireless network 120 supports shared policies or incentives that go beyond baseline use (via the provided identity) for user authentication.
[0054] For example, such as Figure 4A As shown, a network provider can use an enhanced beacon frame 410a (generally or collectively referred to as beacon frame 410) to notify UE 110 in environment 100 of the presence of wireless network 120 and that wireless network 120 supports identity sharing (and other aspects or features of wireless network 120). Alternatively, as Figure 4B and 4C As shown, a network provider can use unenhanced beacon frame 410b to notify UE 110 of the presence and capability of the wireless network, and to provide notification of support for shared identity at another point in the login process. Because beacon frame 410 is sent periodically (e.g., for continuous presence notification and synchronization purposes) and in broadcasts to environment 100 (and any potential UE 110 therein), network providers in some embodiments may prefer to provide minimal details for support in beacon frame 410 (e.g., as flag bits) and provide more details later in the login process (e.g., ...). Figure 4B and 4C(as shown), thereby saving available bandwidth.
[0055] exist Figures 4A-4C In each timing diagram shown, UE 110 and AP 130 exchange probe request 420, probe response 430, and authorization request 440 as part of login. AP 130 forwards authentication request 440, which includes the authorization credentials of the user of UE 110, to identity provider 140. Identity provider 140, in turn, returns a response to AP 130 indicating whether the user is authenticated (in some embodiments via network controller 160) based on the provided credentials. This response may be via authentication response 450 or via identity denial response (not shown).
[0056] In various embodiments, such as Figure 4B As shown, the network provider can use the enhanced authentication response 460a (generally or collectively referred to as authentication response 460) to notify UE 110 that the relevant user has been authenticated by identity provider 140, and to notify UE 110 that wireless network 120 supports shared identity. Alternatively, as... Figure 4A and Figure 4C As shown, the network provider can use the unenhanced authentication response 460b to notify the UE 110 that the relevant user has been authenticated by the identity provider 140, and to provide a notification supporting identity sharing at another point in the login process. In various embodiments, the enhanced authentication response 460a includes a notification supporting identity sharing (e.g., via a flag), or may include more detailed information about specific policies and available incentives for identity sharing.
[0057] Once authenticated in wireless network 120, UE 110 can send an association request 470 to a specific AP 130 in wireless network 120. In various embodiments, such as Figure 4C As shown, the network provider can use the enhanced association response 480a (generally or collectively referred to as association response 480) to confirm the association status between UE 110 and AP 130 and notify UE 110 that wireless network 120 supports shared identity. Alternatively, as... Figure 4A and 4B As shown, the network provider can use the unenhanced association response 480b to confirm the association status between UE 110 and AP 130 and to provide a notification supporting shared identity at another point in the login process. In various embodiments, the association response 480a includes a support notification (e.g., via a flag), or may include more detailed information about specific policies and available incentives for identity sharing.
[0058] although Figures 4A-4CEach timing diagram in the diagram shows how AP 130 notifies UE 110 of support for federated identity and identity sharing at different times, but service providers are free to combine them in other embodiments. Figures 4A-4C Each element in the process. For example, a service provider may use an enhanced beacon frame 410a, an enhanced authentication response 460a, and an enhanced association response 480a, and these enhanced transmissions may each have a different amount or type of information.
[0059] Figures 5A-5C This is a timing diagram for responding to identity and data sharing requests according to embodiments of this disclosure. Although in Figures 5A-5C This includes partner 150, but when a user grants a license to the network provider for internal use, the identity and supplementary data can maintain the privacy of the wireless network 120 for internal use.
[0060] Figure 5A The affirmative response chain is described, in which UE 110 has indicated to AP 130 that an affirmative response 510 indicates that at least some of the collected data and sharing is permitted by the user. In various embodiments, UE 110 transmits an affirmative response 510 to AP 130 to indicate that the data collected, or data collected in the course of providing wireless network services according to a published sharing policy, is acceptable to the user (e.g., as...). Figures 4A-4C (As shown, it is shared). Accordingly, AP 130 can collect data to identify users and data related to the use of wireless network 120, and forward the data to partners 150 permitted according to the sharing policy via a first authorized sharing message 520a (generally or collectively referred to as the authorized sharing message).
[0061] Additionally or alternatively, the affirmative response 510 may indicate to AP 130 that UE 110 permits to receive a follow-up sharing query 530 related to the user and usage of UE 110. The follow-up sharing query 530 may be a general sharing query or a specific query. A general sharing query requests UE 110 to authorize the sharing of some or all of the data collected as part of providing access to the wireless network 120. This data and related analysis may include user identity, user location, data throughput (uplink or downlink) rate, etc. A specific query may request UE 110 to provide data relating to: operating system, device form factor, additional user identity, active (or previously active) applications running on UE 110, and other data beyond or exceeding the data transmitted and collected for providing the BSS of the wireless network 120.
[0062] UE 110 may freely respond to subsequent sharing queries 530 by: a positive sharing query response 540 (sharing the data or allowing further queries in the chain requesting specific data), a negative query response 540 (explicitly indicating that UE 110 will not share the requested data or will not respond to further queries in the chain requesting specific data), or by not responding (AP 130 considers it a negative sharing query response 540 if no response is received within a given time window). If AP 130 receives the responding data and permission (e.g., a positive sharing query response 540) from UE 110 in the sharing query response 540, then AP 130 may share the data with one or more partners 150 via a second permissioned sharing message 520b.
[0063] Once the requested data has been collected for sharing with one or more partners 150, AP 130 may provide incentive confirmation 590 to UE 110. In various embodiments, AP 130 may provide incentives that UE 110 is eligible for (e.g., improving UE 110's download speed without specific notification) without incentive confirmation 590. In other embodiments, incentives may be provided to UE 110 by sending a specific message in machine-readable or human-readable format (e.g., a link to a webpage with incentives or a reading of incentives). Although shown as being provided after the permitted sharing message 520, in various embodiments, AP 130 may provide incentives (with or without incentive confirmation 590) before sharing the collected data with partners, for example: the data is collected and used in batches for later sharing, but the incentive is provided to UE 110 concurrently with the data collection.
[0064] Furthermore, since the incentives can be modified to utilize more data collected from UE 110, AP 130 can operate in different ways. Figure 5A The time transmission incentive confirmation 590 (or the issuance of various incentives) is shown in the figure.
[0065] Figure 5B A negative response chain is described, in which UE 110 has indicated a negative response 550 to AP 130, thereby representing that the user does not authorize the collection and sharing of at least some data. In various embodiments, the negative response 550 may be a negative sharing query response 540 or a negative response to a request from AP 130 (to collect and share already collected data), or data collected in the process of providing wireless network services according to a published sharing policy is not accepted by the user (e.g., according to...). Figures 4A-4C (Shared).
[0066] When a user (via UE 110) indicates via a negative response 550 that they do not wish to share, AP 130 may send a first policy / incentive update 560a (generally or collectively referred to as policy / incentive update 560) to specify in more detail what the sharing policy of wireless network 120 is and any incentives set to encourage receiving a positive or affirmative sharing response from UE 110. In various embodiments, policy details may be provided in a sharing transmission along with incentive details, or in a separate transmission.
[0067] In various embodiments, the policy / incentive update 560 indicates what incentive is provided when UE 110 authorizes the sharing of specific elements of identity data, and may indicate the specific incentive or incentive level available. For example, incentive A may be provided when UE 110 authorizes the sharing of identity data X, and incentives A and B may be provided when UE 110 authorizes the sharing of identity data X and Y.
[0068] In response to receiving the policy / incentive update 560, UE 110 may transmit a sharing response 570 to update AP 130 with the user's preferences after considering the policy / incentive update 560. In various embodiments, the sharing response 570 may be affirmative (allowing data collection and sharing in exchange for incentives, or allowing data collection and sharing once the policy is better understood by the user), negative (again refusing data collection and sharing), confirmatory (requesting more details about the policy or incentives), or nonexistent (AP 130 considers it negative if no response is received within a given time window).
[0069] When the shared response 570 is affirmative, the response chain can continue as follows: Figure 5A As shown, shared response 570 acts as a positive response 510. When shared response 570 is negative, the response chain can be as follows: Figure 5B As shown, shared response 570 acts as a negative response 550. When shared response 570 is illustrative, the response chain is as follows: Figure 5C As shown, the process continues, with the role of negotiation response 580.
[0070] Figure 5C A chain of evidential responses is described, in which UE 110 requests AP 130 to provide more information regarding sharing policies and incentives before making a decision on behalf of the user to authorize at least some data collection and sharing. In various embodiments, negotiation response 580 may be a sharing query response 540 requesting additional information for UE 110, or a response to AP 130's request (to collect and share already collected data).
[0071] When a user (via UE 110) indicates via negotiation response 580 that it requests additional information before being able to authorize sharing, AP 130 may send a second policy / incentive update 560b to specify in more detail what the sharing policy of wireless network 120 is and any incentives set to encourage receiving a positive or affirmative sharing response from UE 110. In various embodiments, the incentive details may specify various specific incentives for various elements of the shared identity data.
[0072] In response to receiving the policy / incentive update 560, UE 110 may transmit a sharing response 570 to update AP 130 with the user's preferences after considering the policy / incentive update 560. In various embodiments, the sharing response 570 may be affirmative (allowing data collection and sharing in exchange for incentives, or allowing data collection and sharing once the policy is better understood by the user), negative (again refusing data collection and sharing), confirmatory (requesting more details about the policy or incentives), or nonexistent (AP 130 considers it negative if no response is received within a given time window).
[0073] In various embodiments, the policy / incentive update 560 indicates what the service provider's policy is, or provides specific answers to questions included in the negotiation response 580. For example, UE 110 may request additional information (concerns regarding whether to share with partner X, collect data element Y, or various other policy aspects), to which the policy / incentive update 560 may answer affirmatively or negatively. In another example, the policy / incentive update 560 may provide general additional information about the sharing policy (e.g., whether data is shared externally, the inclusive or exclusive list of partners 150 sharing data, the type of data shared, etc.).
[0074] When the shared response 570 is affirmative, the response chain can be as follows: Figure 5A The process continues as shown, where shared response 570 acts as a positive response 510. When shared response 570 is negative, the response chain can proceed as follows: Figure 5B The sequence continues as shown, where shared response 570 acts as negative response 550. When shared response 570 is provable, the response chain is as follows: Figure 5C As shown, the process continues, with the role of negotiation response 580.
[0075] Although the data is illustrated as being shared between an AP 130 and a partner 150, it can be transmitted by the network controller 160 (in [location missing]) before being sent to partner 150. Figures 5A-5C(Not illustrated) Further processing, collection, and analysis are performed (e.g., batch processing of data from several UE 110s, data anonymization, and correlation of data from several AP130s). Furthermore, although in Figures 5A-5C The diagram shows a single AP 130 and a single partner, but data can be collected by several APs 130 and shared with several partners 150. Furthermore, data collected by different APs 130 and shared with different partners 150, as well as data collected and shared with a first partner 150a, can be the same as or different from data collected and shared with a second partner 150b.
[0076] Figure 6 The hardware of computing device 600 is shown, which may include, for example, a UE 110, AP 130, network controller 160, or server (for providing services to the identity provider 140 or partner 150 described herein). Computing device 600 includes a processor 610, memory 620, and a communication interface 630. Processor 610 can be any processing element capable of performing the functions described herein. Processor 610 represents a single processor, multiple processors, a processor with multiple cores, and combinations thereof. Communication interface 630 facilitates communication between computing device 600 and other devices. Communication interface 630 represents a wireless communication antenna (both omnidirectional and directional), various antenna directional mechanisms, and various wired communication ports, including output and input pins to a microcontroller. Memory 620 can be volatile or non-volatile memory and may include RAM, flash memory, cache, disk drives, and other computer-readable storage devices. Although shown as a single entity, memory 620 can be divided into different memory storage elements, such as RAM and one or more hard disk drives.
[0077] As shown, the memory 620 includes various instructions executable by the processor 610 to provide an operating system 621 (for managing various functions of the computing device 600) and one or more application programs 622 (for providing various functionalities to users of the computing device 600), including one or more functions and functionalities described in this disclosure.
[0078] Various embodiments have been referenced in this disclosure. However, the scope of this disclosure is not limited to the specific embodiments described. Rather, any combination of the described features and elements is considered for implementing and practicing the considered embodiments, regardless of whether different embodiments are involved. Furthermore, when elements of an embodiment are described in the form of "at least one of A and B," it should be understood that embodiments including only element A, only element B, and including both elements A and B are all considered. Moreover, while the embodiments disclosed herein may achieve advantages over other possible solutions or over the prior art, whether a particular advantage is achieved by a given embodiment does not limit the scope of this disclosure. Therefore, the aspects, features, embodiments, and advantages disclosed herein are merely illustrative and should not be considered elements or limitations of the appended claims unless expressly recited in the claims. Similarly, references to "the invention" should not be construed as a generalization of any inventive subject matter disclosed herein and should not be considered elements or limitations of the appended claims unless expressly recited in the claims.
[0079] As will be apparent to those skilled in the art, the embodiments disclosed herein can be embodied as systems, methods, or computer program products. Therefore, the embodiments may take the form of entirely hardware embodiments, entirely software embodiments (including firmware, resident software, microcode, etc.), or embodiments combining software and hardware aspects, all of which are generally referred to herein as “circuit,” “module,” or “system.” Furthermore, the embodiments may take the form of computer program products embodied in one or more computer-readable media having computer-readable program code embodied thereon.
[0080] Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, fiber optic cable, RF, or any suitable combination of the foregoing.
[0081] Computer program code used to perform the operations of the various embodiments of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages (e.g., Java, Smalltalk, C++, etc.) and conventional procedural programming languages (e.g., the "C" programming language or similar programming languages). This program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)), or can be connected to an external computer (e.g., via the Internet through an Internet service provider).
[0082] Aspects of this disclosure have been described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments presented in this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in the blocks of the flowchart illustrations and / or block diagrams.
[0083] These computer program instructions may also be stored in a computer-readable medium that can direct a computer, other programmable data processing apparatus or other device to operate in a particular manner such that the instructions stored in the computer-readable medium produce an article of manufacture, including instructions that implement the functions / actions specified in the boxes of flowcharts and / or block diagrams.
[0084] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus or other equipment to cause a series of operational steps to be performed on the computer, other programmable apparatus or other equipment to produce a computer-implemented process. Thus, the instructions that execute on the computer, other programmable data processing apparatus or other equipment provide a process for implementing the function / action specified in the boxes of the flowchart and / or block diagram.
[0085] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments. In this regard, each box in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing one or more specific logical functions. It should also be noted that in some alternative implementations, the functions mentioned in the boxes may appear in a different order than that shown in the drawings. For example, depending on the functions involved, two boxes shown consecutively may actually be executed substantially simultaneously, or the boxes may sometimes be executed in reverse order. It should also be noted that each box in the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs a specific function or action, or by a combination of dedicated hardware and computer instructions.
[0086] In view of the foregoing, the scope of this disclosure is defined by the appended claims.
Claims
1. A method for communication, comprising: The user equipment (UE) receives a sharing query from the access point (AP), where the AP indicates that the relevant wireless network supports federated identity for data sharing; The UE is associated with the AP by authenticating its identity using a federated identity provider; After being associated with the AP, the UE determines whether the sharing query is within the UE's sharing preferences; Perform the following operations before transmitting a positive response: The UE transmits a negotiation response to the AP, the negotiation response requesting additional details about a sharing policy, wherein the sharing policy includes guidelines for sharing at least one of the following with one or more partner entities after the association: (i) the identity of the UE, or (ii) supplemental data of the UE, wherein the one or more partner entities are associated with the AP and are different from the federated identity provider that authenticated the identity of the UE; The UE receives a policy update from the AP, the policy update including additional details about the sharing policy; as well as The UE determines whether the shared query is within the UE's shared preferences based on the additional details; In response to determining that the sharing query is within the sharing preference, the UE transmits an affirmative response to the AP for identity sharing, the affirmative response authorizing the collection of at least one of the following after the association and sharing at least one of the following with the one or more partner entities identified in the sharing policy: (i) the UE's identity or (ii) supplementary data of the UE; and After sending the affirmative response, perform the following operations: The UE receives a second shared query from the AP; Receive shared incentives from the AP; as well as In response to determining that the second sharing query is within the UE's sharing preferences based on the sharing incentive, a second positive response to the second sharing query is sent.
2. The method of claim 1, wherein the sharing policy is received in at least one of the following: a beacon frame of the associated wireless network, an authentication response of the associated wireless network, and an association response for associating with the AP in the associated wireless network.
3. The method according to claim 1, wherein, The policy update includes incentive details for providing various levels of incentives when authorized sharing of at least one of the following: (i) the identity of the UE, or (ii) supplementary data of the UE.
4. The method according to claim 1, wherein, Determining whether the shared query is within shared preferences is based on at least one of the following: User input, whereby the user inputs either authorizes or denies the requested shared data; A list of user-defined settings that indicate authorized shared data; or Historical user choices regarding authorizing or denying the sharing of specific data.
5. The method according to claim 1, wherein, The shared query selects from a group consisting of the following items: A general shared query request uses at least one of the following: (i) the identity of the UE, or (ii) supplementary data of the UE; or A specific shared query requests specific data other than at least one of the following: (i) the identity of the UE, or (ii) supplementary data of the UE.
6. A method for communication, comprising: A support notification is transmitted via the access point (AP), indicating support for federated identity to share data within the wireless network associated with the access point; The AP is associated with the UE by authenticating the identity of the user equipment (UE) using a federated identity provider. After being associated with the UE, the AP receives a first identification sharing preference from the UE and transmits the sharing policy of the wireless network to the UE. The first identification sharing preference indicates that negotiation is preferred. The sharing policy includes guidelines for sharing at least one of the following with one or more partner entities after the association: (i) the identity of the UE, or (ii) supplemental data of the UE, wherein the one or more partner entities are associated with the AP and are different from the federated identity provider that authenticated the identity of the UE. In response to determining that the UE currently does not meet the access incentive, the access incentive is notified to the UE; as well as In response to receiving an instruction from the UE to share an authorized second identity sharing preference, after the association, at least one of the following is shared with the one or more partner entities indicated in the sharing policy: (i) the identity of the UE, or (ii) supplementary data of the UE.
7. The method according to claim 6, further comprising: In response to receiving from the UE a third-party sharing preference indicating that sharing is unauthorized: Based on the authorization of the UE's identity by the federated identity provider, access to the wireless network is granted; Collect supplementary data from the UE; as well as Maintain the identity of the UE and the privacy of the UE's supplementary data.
8. The method according to claim 6 or 7, further comprising: In response to determining that the access incentive is currently satisfied by the UE, the access incentive is implemented for the UE.
9. A device for communication, configured to: Receive a first sharing query from an access point (AP), wherein the AP indicates that the relevant wireless network supports federated identity for data sharing; The device is associated with the AP by authenticating its identity using a federated identity provider; After being associated with the AP, the device determines whether the first sharing query is within the device's sharing preferences; as well as In response to determining that the first sharing query is within the sharing preferences of the device, an affirmative response for identity sharing is transmitted to the AP, the affirmative response authorizing the collection of at least one of the following after the association and sharing at least one of the following with one or more partner entities identified in the sharing policy: (i) the identity of the device or (ii) supplementary data of the device, wherein the sharing policy includes guidelines for sharing at least one of the following with the one or more partner entities: (i) the identity of the device or (ii) supplementary data of the device, wherein the one or more partner entities are associated with the AP and are different from the federated identity provider that authenticated the identity of the device; as well as After sending the affirmative response, perform the following operations: The device receives a second shared query from the AP; as well as In response to determining that the second sharing query is not within the sharing preferences of the device, the second sharing query is responded to with a negative response.
10. The device of claim 9, wherein the sharing policy is received in at least one of the following: a beacon frame of the associated wireless network, an authentication response of the associated wireless network, and an association response for associating with the AP in the associated wireless network.
11. The device according to any one of claims 9 to 10, further configured to perform the following operation before transmitting the affirmative response: A negotiation response is sent to the AP, the negotiation response requesting additional details about the sharing policy; Receive policy updates from the AP, the policy updates including additional details of the shared policy; and Based on the additional details, it is determined whether the first shared query is within the shared preferences.
12. The device according to claim 11, wherein, The policy update includes incentive details for providing various levels of incentives when authorized sharing of at least one of the following: (i) the identity of the device, or (ii) supplementary data of the device.
13. The device according to claim 9, further configured to: Receive shared incentives from the AP; and In response to determining whether the second shared query is within the shared preference based on the shared incentive, a second positive response to the second shared query is sent.
14. The device according to any one of claims 9 to 10, wherein, The first shared query and the second shared query are selected from the group consisting of the following: A general shared query request uses at least one of the following: (i) the identity of the device, or (ii) supplementary data of the device; or A specific shared query requests specific data other than at least one of the following: (i) the identity of the device, or (ii) supplementary data of the device.
15. The device according to any one of claims 9 to 10, wherein, Determining whether the first shared query or the second shared query is within the shared preferences is based on at least one of the following: User input, whereby the user inputs either authorizes or denies the requested shared data; A list of user-defined settings that indicate authorized shared data; or Historical user choices regarding authorizing or denying the sharing of specific data.
16. An apparatus for communication, configured to perform the method according to any one of claims 6 to 8.
17. A computer-readable medium comprising computer program instructions that, when executed by a device, cause the device to perform the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Virtual identity apparatus and method for using same
US20030172090A1
Roaming consortium identifier (RCOI)-based system for handling identity requirements
US20200163013A1