Federated Onboarding Service for Scalable OpenRoaming Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mechanisms for onboarding user devices to the OpenRoaming™ framework are complex and lack a scalable, reliable solution for global provisioning, with many device vendors and operators unable to implement or maintain existing systems like Passpoint Online Signup and captive portals.

Innovation Solution

A federated onboarding service leveraging the existing PKI trust model of the OpenRoaming™ framework, allowing devices to automatically identify and authenticate with networks using user credentials, enabling seamless global onboarding through a unified service that eliminates the need for proprietary solutions at the operator level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If proprietary onboarding solutions (Passpoint Online Signup, captive portals) are implemented at operator level, then onboarding functionality is provided, but device complexity and difficulty of maintenance increase significantly

Engineering Contradiction:
Improveonboarding functionalityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a federated onboarding service as an intermediary component that mediates between the device and the OpenRoaming framework. This service handles the complex authentication and onboarding procedures centrally, allowing devices to onboard through a simplified process while maintaining full functionality. The federated service acts as a mediator that translates simple device requests into complex framework operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The federated onboarding service provides universal onboarding capabilities that work across multiple operators and networks within the OpenRoaming framework. Instead of each operator implementing separate proprietary solutions, a single universal service handles onboarding for all participants, reducing device complexity while maintaining broad compatibility and functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If operators deploy separate proprietary onboarding systems, then onboarding is supported, but scalability and reliability across global networks decrease

Engineering Contradiction:
Improveonboarding supportVSAvoidglobal provisioning reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges separate operator-specific onboarding systems into a unified federated onboarding service within the OpenRoaming framework. By combining multiple independent onboarding implementations into a single coordinated service, the system achieves both operator adaptability and global reliability. The merged service ensures consistent behavior across all networks while maintaining support for operator-specific requirements.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If manual onboarding processes are used, then security can be maintained, but onboarding time and user convenience increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The federated onboarding service performs preliminary authentication and credential verification actions before the actual network connection is established. By pre-processing security checks and preparing authentication credentials in advance, the system maintains strong security validation while significantly reducing the time users experience during the onboarding process. The preliminary actions include certificate verification, credential validation, and session preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12418593B2Mechanism to enable a federated onboarding service in an openroaming framework
Publication Date: 2025.09.16 INTEL CORP
  • US12418593B2 patent drawing
  • US12418593B2 patent drawing
  • US12418593B2 patent drawing

AI summary

This disclosure describes systems, methods, and devices related to a mechanism to enable a federated onboarding service in an OpenRoaming™ framework. A device may receive a prompt to initiate onboarding of the device to a framework. The device may the initiate a federated onboarding service process at an access network provider (ANP) that is connected to the device, wherein the federated onboarding service process is configured to onboard the device to the framework. The device may further receive a list of available identity providers (IdPs) configured for the framework and receive a selection of an IdP of the list of available IdPs. The device may then establish a connection between the IdP and the device. The device may receive an IdP-generated user-specific profile, and the device may connect to the framework using the user-specific profile.