Cloud Identity Interworking via EAP and OAuth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise businesses transitioning to cloud-based services face challenges in maintaining user credentials and managing authorization servers, as they prefer not to provide identity management services, and existing authentication protocols like OAuth 2.0 are not suitable for basic access authentication at the access layer.

Innovation Solution

Implementing an extensible authentication protocol (EAP) to interwork with cloud-based identity providers supporting OAuth-based authentication and authorization interfaces, allowing user devices to authenticate and authorize access to networks using encrypted credentials without exposing user credentials to the service provider network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If enterprises use cloud-based identity providers for authentication, then device complexity and credential management burden are reduced, but compatibility with traditional EAP-based network access authentication is lost

Engineering Contradiction:
Improvecredential management complexityVSAvoidauthentication protocol compatibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism that translates between OAuth 2.0 token-based authentication (used by cloud identity providers) and EAP-based authentication (required by traditional network access systems). The access point or authentication server acts as a mediator that can validate OAuth tokens and facilitate EAP authentication flows, enabling cloud-based credentials to work with legacy network infrastructure without requiring enterprises to implement full identity management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises implement traditional AAA servers for authentication, then authentication control and security are improved, but operational burden and maintenance complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidserver maintenance burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables cloud-based identity providers to perform authentication services autonomously without requiring enterprise-managed AAA servers. The cloud identity provider independently handles user credential verification, token generation, and authentication decisions, while the network infrastructure simply validates received tokens. This self-service model eliminates the need for enterprises to provision, configure, and maintain authentication servers, significantly reducing operational burden while maintaining security through the cloud provider's established security infrastructure.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If user credentials are transmitted in plaintext for authentication, then authentication process simplicity is improved, but security against credential leakage and replay attacks deteriorates

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidcredential leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the authentication approach by changing the parameter of credential representation from plaintext passwords to encrypted OAuth 2.0 access tokens. Instead of transmitting sensitive credentials directly, the system uses token-based authentication where the credential parameter is replaced with a secure, revocable token that contains authentication information in an encrypted and standardized format. This parameter change maintains authentication simplicity while eliminating plaintext transmission vulnerabilities.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220311626A1Cloud-based identity provider interworking for network access authentication
Publication Date: 2022.09.29 CISCO TECHNOLOGY INC
  • US20220311626A1 patent drawing
  • US20220311626A1 patent drawing
  • US20220311626A1 patent drawing

AI summary

Techniques for utilizing an extensible authentication protocol (EAP) to interwork with a cloud-based identity provider supporting OAuth based authentication and authorization interfaces. An access network may be accessible by a user device interacting with a service provider network configured to securely transmit encrypted credentials from the user device, over EAP, and relay the encrypted credentials to a cloud-based authorization server, using a backchannel over hypertext transfer protocol secure (HTTPS) via OAuth, for authorization and authentication of the user device to access the access network. The network may be configured as a public wireless network, a private wireless network, a public cellular network, a private cellular network, and/or an OpenRoaming Network.