Cloud Identity Interworking via EAP and OAuth
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise businesses transitioning to cloud-based services face challenges in maintaining user credentials and managing authorization servers, as they prefer not to provide identity management services, and existing authentication protocols like OAuth 2.0 are not suitable for basic access authentication at the access layer.
Innovation Solution
Implementing an extensible authentication protocol (EAP) to interwork with cloud-based identity providers supporting OAuth-based authentication and authorization interfaces, allowing user devices to authenticate and authorize access to networks using encrypted credentials without exposing user credentials to the service provider network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If enterprises use cloud-based identity providers for authentication, then device complexity and credential management burden are reduced, but compatibility with traditional EAP-based network access authentication is lost
Solution Approach 1:
The patent introduces an intermediary mechanism that translates between OAuth 2.0 token-based authentication (used by cloud identity providers) and EAP-based authentication (required by traditional network access systems). The access point or authentication server acts as a mediator that can validate OAuth tokens and facilitate EAP authentication flows, enabling cloud-based credentials to work with legacy network infrastructure without requiring enterprises to implement full identity management systems.
2Reliability
If enterprises implement traditional AAA servers for authentication, then authentication control and security are improved, but operational burden and maintenance complexity increase
Solution Approach 1:
The patent enables cloud-based identity providers to perform authentication services autonomously without requiring enterprise-managed AAA servers. The cloud identity provider independently handles user credential verification, token generation, and authentication decisions, while the network infrastructure simply validates received tokens. This self-service model eliminates the need for enterprises to provision, configure, and maintain authentication servers, significantly reducing operational burden while maintaining security through the cloud provider's established security infrastructure.
3Ease of operation
If user credentials are transmitted in plaintext for authentication, then authentication process simplicity is improved, but security against credential leakage and replay attacks deteriorates
Solution Approach 1:
The patent transforms the authentication approach by changing the parameter of credential representation from plaintext passwords to encrypted OAuth 2.0 access tokens. Instead of transmitting sensitive credentials directly, the system uses token-based authentication where the credential parameter is replaced with a secure, revocable token that contains authentication information in an encrypted and standardized format. This parameter change maintains authentication simplicity while eliminating plaintext transmission vulnerabilities.
Data Source
AI summary
Techniques for utilizing an extensible authentication protocol (EAP) to interwork with a cloud-based identity provider supporting OAuth based authentication and authorization interfaces. An access network may be accessible by a user device interacting with a service provider network configured to securely transmit encrypted credentials from the user device, over EAP, and relay the encrypted credentials to a cloud-based authorization server, using a backchannel over hypertext transfer protocol secure (HTTPS) via OAuth, for authorization and authentication of the user device to access the access network. The network may be configured as a public wireless network, a private wireless network, a public cellular network, a private cellular network, and/or an OpenRoaming Network.


