Access Node Metadata Exchange for Identity Federation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identity federations, such as OpenRoaming, do not provide local networks with sufficient information about connected devices to offer enhanced services, limiting the ability to better serve devices as they move between locations.

Innovation Solution

An access node exchanges metadata with an identity provider after device authentication, receiving information about the device or container, such as item, owner, or digital keys, to provide additional services like linking devices to items or owners, unlocking containers, and managing device connections and container movements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices authenticate through identity federation, then device mobility and network access are improved, but local networks receive little to no additional information about devices

Engineering Contradiction:
Improvedevice mobilityVSAvoiddevice information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the access node queries the identity provider for additional device information after authentication. The identity provider responds with metadata about the device, creating a feedback loop that enriches the local network's understanding of connected devices while maintaining mobility benefits.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary authentication through the identity federation, establishing device identity and basic access rights before the access node requests additional metadata. This preliminary action ensures security is established first, then additional information is retrieved to enhance service capabilities.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If access node requests additional device information from identity provider, then service enhancement capability is improved, but communication complexity increases

Engineering Contradiction:
Improveservice enhancement capabilityVSAvoidcommunication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The communication process is segmented into distinct phases: authentication phase (where device identity is established), information retrieval phase (where access node queries identity provider for additional metadata), and service delivery phase. This segmentation allows each phase to be optimized independently, managing overall communication complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The identity provider acts as an intermediary between the access node and the device. Instead of the access node directly collecting all device information, it queries the identity provider which already holds authenticated device data, simplifying the communication architecture while enabling service enhancement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If local network provides basic access only, then network simplicity is maintained, but ability to serve device needs is limited

Engineering Contradiction:
Improvenetwork simplicityVSAvoidability to serve device needs
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The access node is designed with multi-functionality, serving both as a basic network access point and as an information hub that queries the identity provider for enhanced device metadata. This universal design allows the same infrastructure to provide both simple access and enhanced services without requiring separate dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network service dynamic adapts based on the device type and authentication result. For simple devices, basic access is provided; for devices with additional metadata (e.g., vehicles, containers), the access node retrieves and utilizes this information to provide enhanced services, making the network behavior dynamic rather than static.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11689919B2Dynamic exchange of metadata
Publication Date: 2023.06.27 CISCO TECHNOLOGY INC
  • US11689919B2 patent drawing
  • US11689919B2 patent drawing
  • US11689919B2 patent drawing

AI summary

A method includes receiving, at an access node, a connection request from a device and in response to the connection request, establishing a connection with an identity provider. The device, the access node, the local network, and the identity provider are members of an identity federation. The method also includes, after the device is authenticated with the identity provider, sending or receiving, to or from the identity provider and by the access node, data linking the device to an item and an owner of the device.