Access Node Metadata Exchange for Identity Federation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identity federations, such as OpenRoaming, do not provide local networks with sufficient information about connected devices to offer enhanced services, limiting the ability to better serve devices as they move between locations.
Innovation Solution
An access node exchanges metadata with an identity provider after device authentication, receiving information about the device or container, such as item, owner, or digital keys, to provide additional services like linking devices to items or owners, unlocking containers, and managing device connections and container movements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If devices authenticate through identity federation, then device mobility and network access are improved, but local networks receive little to no additional information about devices
Solution Approach 1:
The patent implements a feedback mechanism where the access node queries the identity provider for additional device information after authentication. The identity provider responds with metadata about the device, creating a feedback loop that enriches the local network's understanding of connected devices while maintaining mobility benefits.
Solution Approach 2:
The system performs preliminary authentication through the identity federation, establishing device identity and basic access rights before the access node requests additional metadata. This preliminary action ensures security is established first, then additional information is retrieved to enhance service capabilities.
2Adaptability or versatility
If access node requests additional device information from identity provider, then service enhancement capability is improved, but communication complexity increases
Solution Approach 1:
The communication process is segmented into distinct phases: authentication phase (where device identity is established), information retrieval phase (where access node queries identity provider for additional metadata), and service delivery phase. This segmentation allows each phase to be optimized independently, managing overall communication complexity.
Solution Approach 2:
The identity provider acts as an intermediary between the access node and the device. Instead of the access node directly collecting all device information, it queries the identity provider which already holds authenticated device data, simplifying the communication architecture while enabling service enhancement.
3Device complexity
If local network provides basic access only, then network simplicity is maintained, but ability to serve device needs is limited
Solution Approach 1:
The access node is designed with multi-functionality, serving both as a basic network access point and as an information hub that queries the identity provider for enhanced device metadata. This universal design allows the same infrastructure to provide both simple access and enhanced services without requiring separate dedicated systems.
Solution Approach 2:
The network service dynamic adapts based on the device type and authentication result. For simple devices, basic access is provided; for devices with additional metadata (e.g., vehicles, containers), the access node retrieves and utilizes this information to provide enhanced services, making the network behavior dynamic rather than static.
Data Source
AI summary
A method includes receiving, at an access node, a connection request from a device and in response to the connection request, establishing a connection with an identity provider. The device, the access node, the local network, and the identity provider are members of an identity federation. The method also includes, after the device is authenticated with the identity provider, sending or receiving, to or from the identity provider and by the access node, data linking the device to an item and an owner of the device.


