Federated Authentication Service for OpenRoaming IDP Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication roaming frameworks, such as the WBA OpenRoaming framework, face limitations in allowing non-Wi-Fi network operators or providers to join the federation due to the requirement of supporting the 802.1X/EAP authentication mechanism, thereby excluding a significant number of potential identity providers.

Innovation Solution

Implementing a Federated Authentication Service (FAS) that abstracts the 802.1x/EAP authentication within the OpenRoaming framework, enabling user authentication through alternative protocols like oAuth or SAML, allowing IDPs without 802.1X/EAP support to integrate with the framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the 802.1X/EAP authentication mechanism is required for joining the federation, then security and authentication reliability are improved, but the adaptability and inclusivity of the framework deteriorate by excluding non-Wi-Fi network operators

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidframework adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component that translates between 802.1X/EAP authentication (required by the Wi-Fi federation) and alternative authentication protocols (used by non-Wi-Fi identity providers). This mediator enables non-Wi-Fi operators to join the federation without implementing 802.1X/EAP, thus resolving the contradiction between maintaining authentication reliability and improving framework adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into separate components: the Wi-Fi federation layer that requires 802.1X/EAP, and the identity provider layer that can use alternative protocols. This segmentation allows each layer to operate with its preferred authentication method while maintaining overall system functionality and inclusivity

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If alternative authentication protocols like oAuth or SAML are implemented, then the inclusivity and scale of the federation are improved, but the complexity of the authentication system increases

Engineering Contradiction:
Improvefederation inclusivityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The intermediary component provides a unified interface that abstracts the complexity of multiple authentication protocols. Non-Wi-Fi identity providers interact with a standardized interface while the intermediary handles the protocol translation and coordination, thus improving federation inclusivity without significantly increasing the apparent complexity for participating entities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is designed with universal compatibility through the intermediary that can handle multiple authentication protocols (802.1X/EAP, oAuth, SAML, etc.). This multi-functionality allows a single system architecture to support diverse identity providers without requiring separate complex implementations for each protocol

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12507067B2Apparatus, system, and method of federated authentication service (FAS) for wireless communication roaming
Publication Date: 2025.12.23 INTEL CORP
  • US12507067B2 patent drawing
  • US12507067B2 patent drawing
  • US12507067B2 patent drawing

AI summary

For example, a Federated Authentication Service (FAS) server may be configured to register the FAS server with a wireless communication roaming federation service; to authenticate a user of a mobile device according to a network authentication protocol of the wireless communication roaming federation service, e.g., over a Remote Authentication Dial-In User Service (RADIUS) over Transport Layer Security (RADSec) tunnel between the FAS server and an Access Network Provider (ANP); to identify an Identity Provider (IDP) for the user based on user information for the user received from the ANP via the RADSec tunnel; to trigger user authentication of the user with the IDP for the user via an authentication interface between the FAS server and the IDP for the user; and based on a determination that the user is successfully authenticated with the IDP for the user, to send an authentication success message to the ANP via the RADSec tunnel.