Service guarantees via alliance-based networks during roaming
By using a consortium-based network architecture and employing identity provider authentication and guarantee value mechanisms, the problem of seamless roaming and service verification for user devices in areas with insufficient cellular service coverage is solved, ensuring the reliability and security of network-based services.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-10
- Publication Date
- 2026-04-03
AI Technical Summary
In areas with insufficient or blocked cellular service coverage, existing technologies make it difficult for user devices to seamlessly roam to Wi-Fi networks and verify whether network-based services are being provided, leading to issues such as network provider deception and secure connection termination.
By using a consortium-based network architecture, user identities are authenticated by identity providers, secure connections are established, and a guaranteed value mechanism is used to verify whether service providers actually provide network-based services. This includes using credentials and information to establish secure connections between access network providers and service providers, ensuring service reliability.
This technology enables user devices to verify whether network-based services are actually being provided during roaming, solving the problems of network provider deception and secure connection termination, and ensuring service reliability and user experience.
Smart Images

Figure CN116569520B_ABST
Abstract
Description
[0001] Cross-referencing related applications
[0002] This application relates to U.S. Patent No. 17 / 249,644, filed March 8, 2021, entitled "Providing Secure Services During Roaming via Alliance-Based Networks". The foregoing related patent application is incorporated herein by reference in its entirety. Technical Field
[0003] The embodiments presented in this disclosure generally relate to wireless networking, and more specifically, to techniques for providing guarantees of network-based services to client devices while roaming. Background Technology
[0004] Consumers increasingly expect their computing devices to remain connected to network-based services regardless of their location. However, cellular services such as 4G LTE and 5G may be less than ideal for connectivity in certain locations, such as indoors, far from cell towers, and / or otherwise obstructed. Open Roaming, as offered by the Wireless Broadband Alliance (WBA), is another option. TM Technologies like these use a federation-based framework to allow consumers to roam seamlessly onto Wi-Fi networks. Attached Figure Description
[0005] To enable a detailed understanding of the features described above, the present disclosure, which has been briefly summarized above, can be described in more detail by referring to embodiments, some of which are shown in the accompanying drawings. However, it should be noted that the accompanying drawings illustrate typical embodiments and should not be considered limiting; other equivalent embodiments are contemplated.
[0006] Figure 1 This is an illustration showing a connection between a client device and an alliance-based network during roaming, according to one or more embodiments.
[0007] Figure 2 This is a diagram illustrating the sequence of connections from a client device to an alliance-based network according to one or more embodiments.
[0008] Figure 3 This is an illustration showing access to a network-based security service according to one or more embodiments.
[0009] Figure 4 It is a method for providing network-based services to a client device according to one or more embodiments.
[0010] Figure 5It is a method for providing network-based services to a client device according to one or more embodiments.
[0011] Figure 6 It is a method for determining whether a network-based service is being provided to a client device.
[0012] Figure 7 It is a method for determining whether a network-based service is being provided to a client device.
[0013] For ease of understanding, the same reference numerals are used wherever possible to denote the same common elements in the figures. It is foreseeable that elements disclosed in one embodiment may be advantageously used in other embodiments without specific description. Detailed Implementation
[0014] Overview
[0015] The embodiments presented in this disclosure are a method that includes authenticating the identity of a user of a client device after the client device has been associated with an access network provider. Authenticating the user's identity includes receiving credentials associated with the identity from an identity provider, and receiving information from the identity provider identifying a network-based service to be applied to network traffic to the client device. The method also includes establishing a secure connection between the access network provider and a service provider, which is capable of providing the network-based service, using the credentials and the received information. The method further includes receiving network traffic from the service provider. Packets of network traffic include a guarantee value that enables the client device to determine that the network-based service is being provided by the service provider.
[0016] Another embodiment presented in this disclosure is a network device including one or more computer processors configured to perform operations including authenticating the identity of a user of the client device after a client device is associated with an access network provider. Authenticating the user's identity includes receiving credentials associated with the identity from an identity provider, and receiving information from the identity provider identifying a network-based service to be applied to network traffic to the client device. The operation also includes establishing a secure connection between the access network provider and a service provider, which is capable of providing the network-based service, using the credentials and the received information. The operation further includes receiving network traffic from the service provider. Packets of network traffic include a guarantee value that enables the client device to determine that the network-based service is being provided by the service provider.
[0017] Another embodiment presented in this disclosure is a method including associating a client device with an access network provider. Associating the client device includes transmitting the identity of the user of the client device to the access network provider. This identity enables the access network provider to receive (i) credentials associated with the identity and (ii) information identifying a web-based service to be applied to the network traffic of the client device from an identity provider. The method also includes receiving network traffic from a service provider capable of providing web-based services via a secure connection between the service provider and the access network provider. The credentials and the received information are used to establish a secure connection. The method also includes determining, based on the network traffic, whether a web-based service is being provided by the service provider.
[0018] Example Implementation
[0019] Such as OpenRoaming TM Technologies like these allow client devices to roam to different access network providers without requiring repeated logins or authentication. Identity providers can then seek to offer additional services beyond roaming, such as providing web-based (e.g., cloud-based) services to client devices.
[0020] In some embodiments described herein, a method includes authenticating the identity of a user of the client device after the client device has been associated with an access network provider. Authenticating the user's identity includes receiving credentials associated with the identity and information identifying a web-based service to be applied to network traffic using the client device from an identity provider. The method also includes establishing a secure connection between the access network provider and a service provider capable of providing the web-based service using the credentials and the received information. The method further includes receiving network traffic from the service provider. Packets of network traffic include assurance values that enable the client device to determine that a web-based service (e.g., a security service) is being provided by the service provider.
[0021] In other embodiments, the client device determines whether a network-based service is being provided by a service provider by establishing a separate channel from the client device to the service provider (via an access network provider) and transmitting characterization information of network traffic via that separate channel. The client device receives a response from the service provider based on characterization information indicating whether a network-based service is being provided by the service provider.
[0022] Beneficially, this method enables users to verify that network traffic to their client devices is being proactively provided by the service provider to one or more web-based services. This method addresses various challenges, such as access network providers failing to successfully establish secure connections using credentials from identity providers, secure connections being terminated during use, and access network providers deceiving customers by offering false support for one or more web-based services.
[0023] Figure 1 Figure 100 illustrates a connection from client device 105 to alliance-based network 115 during roaming, according to one or more embodiments. Figure 100 shows an example sequence of user use of client device 105. For example, this sequence could represent a user's work schedule.
[0024] Client device 105 can be implemented in any form suitable for wireless networking. In some embodiments, client device 105 is implemented as a mobile computing device, such as a laptop, tablet, smartphone, or smart wearable device. In other embodiments, client device 105 can be a computing device integrated into a vehicle.
[0025] At the start of this sequence, the user is at home 110-1, and client device 105 wirelessly connects to a home network (e.g., a Wi-Fi network), such as a local area network or local access network (LAN), general wide area network (WAN), and / or public network (e.g., the Internet), which provides access to external networks. When the user is driving a car 110-2, client device 105 wirelessly connects to a cellular network (e.g., a 4G LTE or 5G cellular network). When the user arrives at the company office 110-3, client device 105 roams from the cellular network to the Wi-Fi network operated by company office 110-3. The user returns to the car to make a customer call 110-4, and when out of range of the Wi-Fi network, client device 105 reconnects to the cellular network. When the user visits an office branch 110-5, a coffee shop 110-6, and a hotel 110-7, client device 105 later roams to different Wi-Fi networks.
[0026] When roaming to different Wi-Fi networks (e.g., at company office 110-3, branch office 110-5, coffee shop 110-6, and hotel 110-7), client device 105 uses alliance-based network 115 to access the external network. Alliance-based network 115 can be implemented using any standardized and / or proprietary technologies and protocols. For example, alliance-based network 115 can be compatible with OpenRoaming. TM .
[0027] The alliance-based network 115 includes multiple access providers 120 (also referred to as "access network providers") that provide wireless connectivity to client devices 105 using, for example, access points, wireless LAN controllers, etc. Some non-limiting examples of access providers 120 include enterprise access providers 122 (e.g., employers, manufacturing facilities), consumer access providers 124 (e.g., hotels, retail stores), public access providers 126 (e.g., airports, universities, stadiums), etc.
[0028] The alliance-based network 115 includes multiple identity providers 130 that operate to create, maintain, and / or manage user identity information and provide authentication services within the alliance-based network 115. Some non-limiting examples of identity providers 130 include cloud providers 132 (e.g., providers of scalable computing resources), service providers 134 (e.g., telecommunications companies, utility organizations), and equipment manufacturers 136. By authenticating users using identity providers 130, client devices 105 can roam to different access providers 120 without requiring repeated logins or authentication from the user.
[0029] Figure 2 This is a diagram 200 illustrating the sequence of connections from client device 105 to an alliance-based network according to one or more embodiments. The features shown in diagram 200 may be combined with other embodiments (e.g., showing client device 105 with...). Figure 1 Access provider 120 can be used at any of the following locations shown: company office 110-3, office branch 110-5, coffee shop 110-6, or hotel 110-7.
[0030] In Figure 200, access provider 205 ( Figure 1 (An example of an access provider 120) transmits a beacon 220 that announces one or more requirements for connecting client device 105 to access provider 205. Beacon 220 can be implemented in any suitable form, such as an IEEE 802.11u beacon. In some embodiments, beacon 220 instructs client device 105 to provide a user-specific identifier. In other embodiments, beacon 220 instructs client device 105 to provide only a public identifier.
[0031] In response to beacon 220, client device 105 attaches (225) to access provider 205 (i.e., client device 105 establishes a connection with access provider 205), and access provider 205 initiates authentication of the user, for example via an Extensible Authentication Protocol (EAP) process, by transmitting one or more acceptable authentication types 230 to client device 105. Client device 105 may search a list of profiles stored thereon and may automatically select an identity 235 that corresponds to an acceptable credential type 230 (e.g., token, certificate, username / password, SIM, etc.) and best matches one or more requirements specified by access provider 205 (e.g., via beacon 220). In some embodiments, identity 235 includes elements of a Uniform Resource Locator (URL), such as a domain name. Client device 105 may use any suitable technology to select the best match.
[0032] Client device 105 provides the selected identity 235 to access provider 205, and access provider 205 uses identity 235 to contact Domain Name Service (DNS) server 210. As shown in Figure 200, the identity 235 selected by client device 105 is "bob@newco.com", which can be a public or private identity in response to beacon 220 transmitted by access provider 205. Access provider 205 looks up 240 "newco.com" to DNS server 210. Using the result from DNS server 210, access provider 205 establishes a connection to identity provider 215 ( Figure 1 An encrypted and authenticated Transport Layer Security (TLS) tunnel 245 (an example of an identity provider 130) corresponds to an identity 215 and a selected identity 235. Identity provider 215 provides EAP authorization 250 to access provider 205 using the Remote Authentication Dial In User Service (RADIUS) attribute, and access provider 205 provides EAP authorization 255 to client device 105 using EAP over LAN (EAPoL).
[0033] Figure 3 Figure 300 illustrates access to a network-based service according to one or more embodiments. The features shown in Figure 300 can be used in conjunction with other embodiments. For example, Figure 3The client device 305, access provider 325, and identity provider 360 can be Figure 1 Examples of client device 105, access provider 120, and identity provider 130.
[0034] In Figure 300, client device 305 is connected to access provider 325 via a wireless communication link. Access provider 325, identity provider 360, and service provider 345 are interconnected using any suitable type of communication link(s). Each of client device 305, access provider 325, identity provider 360, and service provider 345 can be implemented as one or more computing devices in any suitable form(s). For example, client device 305 can be implemented as a user's mobile computing device, while access provider 325, identity provider 360, and service provider 345 can be implemented as server computers.
[0035] Each of the client device 305, access provider 325, identity provider 360, and security service provider 345 includes one or more corresponding computer processors 310, 330, 365, 350, and corresponding memories 315, 335, 370, 355. The one or more computer processors 310, 330, 365, 350 can be implemented in any suitable form, such as a general-purpose microprocessor, controller, application-specific integrated circuit (ASIC), etc. The memories 315, 335, 370, 355 can include various computer-readable media selected for their size, relative performance, or other capabilities (volatile and / or non-volatile media, removable and / or non-removable media, etc.).
[0036] The interconnection of access provider 325, identity provider 360, and service provider 345 can represent Figure 1 This is an example of a federation-based network 115, and can represent one or more networks of any suitable type, such as the Internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network. The various communication links between the access provider 325, the identity provider 360, and the service provider 345 can have any suitable implementation, such as one or more copper transmission cables, one or more optical fiber transmissions, wireless transmissions, one or more routers, one or more firewalls, one or more switches, one or more gateway computers, and / or one or more edge servers.
[0037] Memory 315, 335, 355, 370 may include one or more modules for performing the various functions described herein. In one embodiment, each module includes program code executable by one or more corresponding computer processors 310, 330, 350, 365. In another embodiment, each module is partially or wholly implemented in the hardware (i.e., circuitry) or firmware of the client device 305, access provider 325, identity provider 360, and / or service provider 345 (e.g., as circuitry within one or more computer processors 310, 330, 365, 350). However, other embodiments of Figure 300 may include modules partially or wholly implemented in other hardware or firmware, such as hardware or firmware included in one or more other computing devices connected to access provider 320. In other words, the overall functionality of one or more modules may be distributed across other devices of Figure 300.
[0038] As shown in the figure, the memory 335 of the access provider 325 includes a guarantee module 340, the memory 355 of the service provider 345 includes a service module 356, and the memory 370 of the identity provider 360 includes an identity service module 372.
[0039] The assurance module 340 typically communicates with the client device 305, the identity provider 360, and the service provider 345 to establish a secure connection with the service provider 345 to provide one or more network-based services to the network traffic of the client device 305. The service module 356 typically provides these one or more network-based services to the network traffic. In some embodiments, the service module 356 uses distributed and / or scalable computing resources that can be provided on demand and / or distributed to provide one or more cloud-based services.
[0040] The one or more network-based services can be provided in any suitable form. In some embodiments, the one or more network-based services include any one or more suitable types of security services, such as firewalls, content filters, anti-malware, protection against known malicious sites, etc. In some embodiments, service module 356 can be implemented as a secure internet or web gateway.
[0041] Identity service module 372 typically operates to create, maintain, and / or manage identity information for different users. Identity service module 372 may also provide authentication services for different users. In some embodiments, identity service module 372 issues credentials 375 for authenticating users. Credentials 375 may be implemented in any suitable form, such as a security token unique to a specific session with the user. In some embodiments, the security token includes (i) a value provided by identity provider 360, (ii) an identifier of identity provider 360, and / or (iii) a value provided by service provider 345. For example, the security token may be implemented as a concatenation of (i), (ii), and (iii).
[0042] Each user is associated with one or more identities 316. Each identity 316 generally includes the information mentioned above. Figure 2 The characteristics of identity 235 are described. In some embodiments, the user configures one or more policies 380 (e.g., corresponding to one or more identities 316) stored by identity provider 360. Therefore, one or more policies 380 can be predefined regarding when client device 305 roams to access provider 325. Each policy 380 specifies one or more network-based services (or capabilities or characteristics) to apply when the corresponding identity 316 is selected. The above describes... Figure 2 Some example techniques for selecting identity 316 are discussed. In some embodiments, policy 380 may specify a particular service provider 345 to use, and may specify a priority (e.g., order) for selecting service provider 345 from multiple service providers. Each policy 380 may be stored by identity provider 360 in any suitable format (e.g., YAML, XML, etc.).
[0043] Therefore, when a user roams to a capable access provider 325, the identity provider 360 can propose cloud-based services (e.g., indicate which cloud-based services are available). For example, the identity provider 360 may have a revenue-sharing agreement with one or more service providers 345. In some embodiments, the cloud-based services proposed by the identity provider 360 may include multiple security levels or tiers selectable by the user. This allows the user to customize one or more security services applied to the connection between the client device and the access network provider, and to verify that those customized security services are actually being provided by one or more service providers 345.
[0044] Each identity 316 associated with a user may be associated with a set of one or more cloud-based services. The identities 316 associated with a user may be categorized or prioritized based on user priority. Furthermore, cloud-based security services may be directly selected and / or purchased by the user, or may be directly proposed by the access provider 325.
[0045] According to the various embodiments described herein, the assurance module 340 operates independently or in conjunction with the service module 356 to communicate with the client device 305, thereby enabling the client device 305 to determine whether one or more network-based services are actually being provided by the service provider 345. In some embodiments, when the client device 305 determines that one or more network-based services are not being provided by the provider 345, the client device 305 may ignore or discard received network traffic.
[0046] In some embodiments, packets of network traffic transmitted from service provider 345 include a guarantee value 390. The guarantee value 390 may be based on one or more tokens assigned to and / or generated by the various components of illustration 300.
[0047] In some embodiments, the guaranteed value 390 is a first token generated by the identity provider 360 and transmitted to both the service provider 345 and the client device 305. The service provider 345 may embed the first token in the header of a packet, and the client device 305 may check whether the first token is present in a received packet.
[0048] In some embodiments, the guaranteed value 390 is based on a first token, and also on a second token generated (and / or assigned to service provider 345) and a third token generated (and / or assigned to client device 305). For example, client device 305 may include the third token in packets transmitted to service provider 345, allowing service provider 345 to learn the third token. In some embodiments, client device 305 stores multiple values of the guaranteed value 390, and may also store multiple indices corresponding to the multiple values.
[0049] In some embodiments, service module 356 includes a predefined function, and applies a first token, a second token, and a third token to the predefined function to generate a result. The predefined function may include any suitable logical and / or arithmetic function. In a non-limiting example, the predefined function is a linear function, represented as:
[0050] f(x) = mx + c, (1)
[0051] Where m represents the first token, x represents the second token, and c represents the third token. Other functions are also considered, which may provide greater robustness and / or other benefits for real-time reverse engineering. In some embodiments, the result of a predefined function calculated by service module 356 is a guaranteed value 390 transmitted from service provider 345 to client device 305. In some embodiments, client device 305 receives and learns the second token and also includes a predefined function. Client device 305 may apply the first, second, and third tokens to the predefined function to generate a result and compare the result with the guaranteed value 390 to determine whether one or more network-based services are actually being provided by service provider 345.
[0052] In some embodiments, packets of network traffic from client device 305 include a value used by service provider 345 to generate guarantee value 390. In some embodiments, this value is included in any one of the packet's in-band (in-situ) Operation, Administration and Maintenance (OAM) header, in-band network telemetry (INT), cookie, or other metadata header.
[0053] In some embodiments, service module 356 stores multiple values (and indices) of the guaranteed value 390, and the value received from client device 305 is used by service module 356 to look up and return the index value of the corresponding guaranteed value 390. In other embodiments, the value received from client device 305 is a third token, and service module 356 applies the third token (along with the first and second tokens) to a predefined function to generate and return the guaranteed value 390. In some embodiments, service module 356 processes the value received from client device 305 to determine whether the value is an index (lookup) value or a third token. Client device 305 can use the guaranteed value 390 received from service module 356 to determine whether one or more network-based services are actually being provided by service provider 345.
[0054] In some embodiments, client device 305 establishes a separate channel 385 (via access provider 325) to service provider 345, which may in some cases be a dedicated guaranteed channel. The separate channel 385 may have any suitable form, such as a Transmission Control Protocol (TCP) connection, User Datagram Protocol (UDP) connection, Fast UDP Internet Connection (QUIC), Internet Control Message Protocol (ICMP) connection, etc.
[0055] Client device 305 receives network traffic from service provider 345 via the original connection and transmits network traffic characterization information 395 via a separate channel 385. Characterization information 395 can have any suitable format. For example, characterization information 395 may include net traffic statistics or other traffic monitoring statistics. In some embodiments, access provider 325 generates characterization information 395 and transmits it to client device 305. Client device 305 may transmit characterization information 395 to service provider 345 via separate channel 385.
[0056] Client device 305 may receive a response from service provider 345 based on representation information 395. In some embodiments, service module 356 determines whether the stream indicated by representation information 395 exists in a local cache table of service provider 345, which can be cached for at least a predetermined time. If the stream exists in the local cache table, the response from service provider 345 is affirmative. However, if the stream does not exist, the response from service provider 345 is an error message, which may specify information about one or more missing streams.
[0057] Figure 4 This is a method 400 for providing network-based services to a client device according to one or more embodiments. Method 400 can be implemented in conjunction with other embodiments. For example, when providing... Figure 3 When client device 305 provides network-based services, method 400 can be... Figure 3 Access provider 325 executes.
[0058] Method 400 begins at box 405, where the access network provider transmits a notification for one or more requested beacons used to connect to the access network provider. For example, the beacon may specify the type of identification (public or private) to be provided by the user.
[0059] At box 415, the access network provider receives a query from the client device. In some embodiments, the query conforms to the Access Network Query Protocol (ANQP). At box 425, the access network provider transmits information indicating that it supports network-based services. In some embodiments, the access network provider uses new ANQP elements to announce support for confederation-based networks, automatic packetization of user-defined networks (UDNs), network-based services, etc.
[0060] At box 435, the access network provider authenticates the identity of the user on the client device. The access network provider and the identity provider (e.g., Figure 3Identity providers (360) communicate with each other. Identity providers can be cloud providers, service providers, device manufacturers, etc. Identity providers can use any appropriate authentication protocol, such as OAuth, Remote Authentication Dial-In User Service (RADIUS), Security Assertion Markup Language (SAML), etc.
[0061] In some embodiments, authenticating a user's identity includes, at box 445, the access network provider receiving credentials associated with the identity from an identity provider. These credentials can be implemented in any suitable form, such as a security token unique to a specific session with the user. In some embodiments, the security token includes a value provided by the identity provider, an identifier of the identity provider, and / or a value provided by the provider of the network-based service. In some embodiments, authenticating a user's identity also includes, at box 455, the access network provider receiving information from the identity provider identifying the network-based service to be applied to network traffic to the client device. In some embodiments, the access network provider receives a RADIUS Access-Accept response from the identity provider.
[0062] At box 465, the access network provider uses credentials and received information to establish a secure connection between the access network provider and a service provider capable of providing network-based services. In some embodiments, this secure connection includes a Virtual Private Network (VPN). In some embodiments, establishing a secure connection includes transmitting (i) information identifying the identity provider and (ii) credentials to the service provider. The access network provider uses information identifying the network-based service (e.g., RADIUS attributes) to establish a secure connection to the service provider.
[0063] At box 475, the access network provider receives network traffic from the client device. Packets of network traffic include values such as index values or tokens generated by the client device, which are transmitted to the service provider to determine a guarantee value. At box 485, the access network provider receives network traffic from the service provider. Packets of network traffic include a guarantee value that enables the client device to determine that a network-based service is being provided by the service provider. Method 400 ends after completing box 485.
[0064] Figure 5 This is a method 500 for providing network-based services to a client device according to one or more embodiments. Method 500 can be implemented in conjunction with other embodiments. For example, method 500 can be... Figure 3 The client device 305 executes to determine whether the network-based service is being provided by [the service provider]. Figure 3 Service provider 345 provides this service.
[0065] Method 500 begins at box 505, where the client device receives a beacon that advertises one or more requests for connection to an access network provider. Box 505 roughly corresponds to... Figure 4 This corresponds to box 405. At box 515, the client device is associated with an access network provider. In some embodiments, associating with an access network provider includes transmitting a query to the access network provider at box 525. Box 525 generally corresponds to... Figure 4 The corresponding frame is 415.
[0066] At box 535, the client device receives information indicating that the access network provider supports network-based services. Box 535 roughly corresponds to... Figure 4 This corresponds to box 425. At box 545, the client device transmits the user's identity to the access network provider. The user's identity can be used by the access network provider to authenticate that identity using an identity provider (e.g., in...). Figure 4 (at frame 435).
[0067] At box 555, the client device receives network traffic from a service provider capable of providing network-based services via a secure connection. At box 565, the client device determines, based on the network traffic, whether a network-based service is being provided by the service provider. Method 500 ends after completing box 565.
[0068] Figure 6 This is a method 600 for determining whether a network-based service is being provided to a client device. In some embodiments, method 600 serves as... Figure 5 It is part of box 565 that is executed.
[0069] Method 600 begins at box 605, where the client device transmits network traffic including values that enable the service provider to determine a guarantee value (e.g., an index value or a token generated by the client device). At box 615, the client device receives a guarantee value based on a first token generated by the identity provider. At box 625, the client device receives a second token generated by the service provider and generates a third token.
[0070] At box 645, the client device applies the first, second, and third tokens to a predefined function, and at box 655 compares the result of the predefined function with the guaranteed value. Method 600 ends after completing box 655.
[0071] Figure 7 This is a method 700 for determining whether a network-based service is being provided to a client device. In some embodiments, method 700 serves as... Figure 5 It is part of box 565 that is executed.
[0072] Method 700 begins at block 705, where the client device establishes a separate channel to the service provider via the access network provider. In some embodiments, this separate channel may operate as a dedicated guaranteed channel. At block 715, network traffic characterization information is transmitted to the service provider via the separate channel. In some embodiments, the characterization information includes net traffic statistics or other traffic monitoring statistics.
[0073] At box 725, the client device receives a response from the service provider based on the representation information. In some embodiments, the service provider determines whether the flow indicated by the representation information exists in the service provider's local cache table. If the flow exists, the response from the service provider is affirmative, acknowledging that the network-based service is utilizing the network traffic provided to the client device. If the flow does not exist, the response from the service provider may be an error message, which may specify information about one or more missing flows. Method 700 ends after completing box 725.
[0074] Various embodiments have been referenced in this disclosure. However, the scope of this disclosure is not limited to the specific embodiments described. Rather, any combination of the described features and elements is considered for implementing and practicing the considered embodiments, regardless of whether different embodiments are involved. Furthermore, when elements of an embodiment are described in the form of "at least one of A and B," it should be understood that embodiments including only element A, only element B, and including both elements A and B are all considered. Moreover, while the embodiments disclosed herein may achieve advantages over other possible solutions or over the prior art, whether a particular advantage is achieved by a given embodiment does not limit the scope of this disclosure. Therefore, the aspects, features, embodiments, and advantages disclosed herein are merely illustrative and should not be considered elements or limitations of the appended claims unless expressly recited in the claims. Similarly, references to "the invention" should not be construed as a generalization of any inventive subject matter disclosed herein and should not be considered elements or limitations of the appended claims unless expressly recited in the claims.
[0075] As will be apparent to those skilled in the art, the embodiments disclosed herein can be embodied as systems, methods, or computer program products. Therefore, the embodiments may take the form of entirely hardware embodiments, entirely software embodiments (including firmware, resident software, microcode, etc.), or embodiments combining software and hardware aspects, all of which are generally referred to herein as “circuit,” “module,” or “system.” Furthermore, the embodiments may take the form of computer program products embodied in one or more computer-readable media having computer-readable / executable program code embodied thereon. As an example, the computer-readable medium may carry computer-executable program code arranged to cause any of the methods described herein to be performed when executed by one or more processors.
[0076] Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, fiber optic cable, RF, or any suitable combination of the foregoing.
[0077] Computer program code used to perform the operations of the various embodiments of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages (e.g., Java, Smalltalk, C++, etc.) and conventional procedural programming languages (e.g., the "C" programming language or similar programming languages). This program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)) or can connect to an external computer (e.g., via the Internet provided by an Internet service provider).
[0078] Aspects of this disclosure have been described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments presented in this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in the blocks of the flowchart illustrations and / or block diagrams.
[0079] These computer program instructions may also be stored in a computer-readable medium that can direct a computer, other programmable data processing apparatus or other device to operate in a particular manner such that the instructions stored in the computer-readable medium produce an article of manufacture, including instructions that implement the functions / actions specified in the boxes of flowcharts and / or block diagrams.
[0080] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus or other equipment to cause a series of operational steps to be performed on the computer, other programmable apparatus or other equipment to produce a computer-implemented process. Thus, the instructions that execute on the computer, other programmable data processing apparatus or other equipment provide a process for implementing the function / action specified in the boxes of the flowchart and / or block diagram.
[0081] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments. In this regard, each box in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing one or more specific logical functions. It should also be noted that in some alternative implementations, the functions mentioned in the boxes may appear in a different order than that shown in the drawings. For example, depending on the functions involved, two boxes shown consecutively may actually be executed substantially simultaneously, or the boxes may sometimes be executed in reverse order. It should also be noted that each box in the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs a specific function or action, or by a combination of dedicated hardware and computer instructions.
[0082] In view of the foregoing, the scope of this disclosure is defined by the appended claims.
Claims
1. A method for providing network-based services to client devices, comprising: After the client device is associated with the access network provider, the identity of the user of the client device is authenticated, wherein authenticating the identity of the user includes: Receive credentials associated with the identity from the identity provider; Receive information from the identity provider that identifies the application of a network-based service to the network traffic of the client device; Using the credentials and the received information, a secure connection is established between the access network provider and the service provider, enabling the service provider to provide the network-based service. Receiving network traffic from the service provider, wherein packets of the network traffic include a guarantee value that enables the client device to determine that the network-based service is being provided by the service provider; and Determining whether the network-based service is being provided by the service provider includes: Establish a separate channel from the client device to the service provider; The network traffic characterization information is transmitted via the separate channel; and Receive a response from the service provider based on the representation information.
2. The method according to claim 1, wherein, The network-based service includes security services specified in a security policy for the identity, wherein the security policy is stored by the identity provider.
3. The method according to claim 1 or 2, wherein, The guarantee value is based on a first token, which (i) is generated by the identity provider, (ii) is transmitted to the service provider, and (iii) is transmitted to the client device via the access network provider.
4. The method according to claim 3, wherein, The guaranteed value is the first token.
5. The method according to claim 3, wherein, The guaranteed value is also based on: The second token generated by the service provider; and A third token generated by the client device.
6. The method according to claim 5, wherein, The guaranteed value is the result of applying the first token, the second token, and the third token to a predefined function.
7. The method according to any of the preceding claims, further comprising: Network traffic is received from the client device, wherein the packets of network traffic include a second value. The guaranteed value is based on the second value.
8. A network device, comprising: One or more computer processors are configured to perform operations, said operations including: After a client device is associated with an access network provider, the identity of the user of the client device is authenticated, wherein authenticating the user's identity includes: Receive credentials associated with the identity from the identity provider; and Receive information from the identity provider that identifies a network-based service to be applied to the network traffic of the client device. Using the credentials and the received information, a secure connection is established between the access network provider and the service provider, enabling the service provider to provide the network-based service. Receiving network traffic from the service provider, wherein packets of the network traffic include a guarantee value that enables the client device to determine that the network-based service is being provided by the service provider; and Determining whether the network-based service is being provided by the service provider includes: Establish a separate channel from the client device to the service provider; The network traffic characterization information is transmitted via the separate channel; and Receive a response from the service provider based on the representation information.
9. The network device according to claim 8, wherein, The network-based service includes security services specified in a security policy for the identity, wherein the security policy is stored by the identity provider.
10. The network device according to claim 8 or 9, wherein, The guarantee value is based on a first token, which (i) is generated by the identity provider, (ii) is transmitted to the service provider, and (iii) is transmitted to the client device via the access network provider.
11. The network device according to claim 10, wherein, The guaranteed value is the first token.
12. The network device according to claim 10, wherein, The guaranteed value is also based on: The second token generated by the service provider; as well as A third token generated by the client device.
13. The network device according to claim 12, wherein, The guaranteed value is the result of applying the first token, the second token, and the third token to a predefined function.
14. The network device according to any one of claims 8 to 13, wherein the operation further comprises: Network traffic is received from the client device, wherein the packets of network traffic include a second value. The guaranteed value is based on the second value.
15. A method for providing network-based services to client devices, comprising: Associating the client device with an access network provider, wherein associating the client device includes transmitting the identity of the user of the client device to the access network provider, wherein the identity enables the access network provider to receive (i) credentials associated with the identity and (ii) information identifying the network-based service to be applied to the network traffic of the client device from the identity provider; Network traffic is received from the service provider via a secure connection between the service provider capable of providing the network-based service and the access network provider, wherein the secure connection is established using the credentials and the received information; and Determining whether the network-based service is being provided by the service provider based on the network traffic. Determining whether the network-based service is being provided by the service provider includes: Establish a separate channel from the client device to the service provider; The network traffic characterization information is transmitted via the separate channel; and Receive a response from the service provider based on the representation information.
16. The method according to claim 15, wherein, The network traffic packets include a guarantee value based on a first token, which (i) is generated by the identity provider, (ii) is transmitted to the service provider, and (iii) is transmitted to the client device via the access network provider.
17. The method according to claim 16, wherein, The guarantee value is the first token, and wherein determining whether the network-based service is being provided by the service provider includes: The guaranteed value received in the network traffic is compared with the first token received by the client device.
18. The method of claim 16, further comprising: Receive the second token generated by the service provider; Generate a third token; Apply the first token, the second token generated by the service provider, and the third token generated by the client device to a predefined function; as well as The result of the predefined function is compared with the guaranteed value.
19. The method according to any one of claims 16 to 18, further comprising: Network traffic including the second value is transmitted from the client device. The guaranteed value is generated based on the second value.
20. An apparatus comprising means for performing the method according to any one of claims 15 to 19.
21. A computer-readable medium carrying computer-executable program code, which, when executed by one or more processors, is arranged such that the method according to any one of claims 1 to 7 and / or 15 to 19 is performed.
Citation Information
Patent Citations
Providing security services via federation-based network during roaming
US20220286447A1
Secure access for B2B applications
US20210136041A1