Wireless Access Point Identity Token Insertion for Location Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cellular network technologies do not effectively utilize immutable identity credentials for providing location-based and user-based services during data sessions, as IP networking was designed independently of cellular networking, and sensitive identity information is not propagated to the application layer, limiting the resolution of location-based services and user personalization.

Innovation Solution

A cellular basestation is configured to insert identity tokens associated with mobile devices and access points into data traffic, allowing remote services to infer location and user identity, thereby providing location-based and user-based services without requiring users to manually input credentials on mobile devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity credentials are not propagated to the application layer, then network security and privacy are maintained, but location-based services and user personalization cannot be provided

Engineering Contradiction:
Improvenetwork securityVSAvoidlocation-based service capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism where the access point acts as a mediator between the cellular network and the application layer. The access point receives identity credentials from the cellular network and automatically inserts derived location and user information into data traffic without requiring direct propagation of sensitive credentials to the application layer, thus maintaining security while enabling services

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates copies of identity information in a derived form. Instead of propagating the original sensitive identity credentials, the system creates copied representations (location tags and user identifiers) that can be used for service provision without exposing the original credentials, allowing application-layer services to function with sanitized identity data

Inventive Principle:
Principle #26Copying

2Measurement precision

If IP address is used for location inference, then basic location services can be provided, but location resolution is limited due to IP pooling and reassignment

Engineering Contradiction:
Improvelocation resolutionVSAvoidlocation service implementation
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The access point serves as an intermediary that bridges IP networking and cellular networking. It receives the mobile device's identity credential from the cellular network and automatically inserts a location tag into the data traffic, providing precise location information without requiring complex IP-based location resolution systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by pre-establishing the relationship between access points and location information. The access point is pre-configured with its location data, and when a mobile device connects, the access point automatically inserts the appropriate location tag without requiring real-time location calculation or complex processing, simplifying the implementation

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If users manually input credentials for service personalization, then user identity can be established, but user interface complexity and operation time increase

Engineering Contradiction:
Improveuser personalization capabilityVSAvoiduser interface simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements self-service by having the access point automatically insert user identity information into data traffic without requiring any manual input from the user. The mobile device's identity credential, already established during network attachment, is automatically utilized to provide personalized services, eliminating the need for users to manually enter credentials or perform identification actions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The user identification action is performed preliminarily during the network attachment process. The access point captures and stores the mobile device's identity credential at the time of connection, and this pre-captured information is automatically inserted into subsequent data traffic, eliminating the need for users to provide identification information when accessing services

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9686370B2Wireless access point
Publication Date: 2017.06.20 CISCO TECHNOLOGY INC
  • US9686370B2 patent drawing
  • US9686370B2 patent drawing
  • US9686370B2 patent drawing

AI summary

A wireless access point may be in the form of a femtocell basestation in a cellular network. In order to establish a connection into the cellular network, an identity token is required for authorization. A remote service, accessible over a Wide Area Network such as the internet, can register with the access point. When a connected user attempts to connect to the remote service, information derived from the identity token is inserted into the data traffic. Where the identity token identifies the access point, the remote service can return location-specific information. Where the identity token identifies the connected user, the remote service can return subscriber-specific information. The access point can insert information derived directly from the identity token, or it can use the identity token to access a service identity registry, and can then insert the service identity into the data traffic.