Federated Identity On-boarding for Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for providing access to wireless networks in enterprise environments are inefficient, as they require manual password entry and agreement to terms by visitors, lacking automation and flexibility in policy enforcement, especially for guest users and devices without pre-existing relationships with access providers.

Innovation Solution

A method involving a federated identity and access services engine that automates the on-boarding of access and identity providers, enabling dynamic policy-based access by establishing secure connections and negotiating identity and access policies, allowing guest users to connect to wireless networks without prior relationships through automated authentication and authorization processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual password entry and terms agreement process is used for wireless network access, then security control is maintained, but access efficiency and user convenience deteriorate

Engineering Contradiction:
Improveaccess efficiencyVSAvoiduser convenience
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-establishing policy frameworks, authentication mechanisms, and access rules before users attempt to connect. The federated identity system pre-configures trust relationships between enterprises and service providers, so that when a user connects, the authentication and policy enforcement are already in place, eliminating the need for manual password entry and terms agreement during the connection process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a federated identity system as an intermediary between users, enterprises, and service providers. This intermediary automatically handles authentication, authorization, and policy enforcement, replacing the manual interaction model. The system mediates the access request by automatically verifying user identity, checking policies, and granting or denying access without requiring users to manually enter passwords or agree to terms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If automated authentication systems are implemented, then access efficiency improves, but system complexity and security management difficulty increase

Engineering Contradiction:
Improveauthentication automationVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The federated identity system is designed as a universal platform that handles multiple functions including authentication, authorization, account management, and policy enforcement across different enterprises and service providers. By consolidating these functions into a single multi-functional system, the patent reduces the need for separate automated systems at each enterprise, thereby managing complexity while maintaining high automation levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The federated identity system acts as an intermediary layer that simplifies complexity for individual enterprises. Instead of each enterprise implementing its own complex automated authentication system, the federated system provides a standardized interface and handles the complex security management centrally, allowing enterprises to benefit from automation without bearing the full complexity burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If federated identity system with dynamic policy negotiation is deployed, then policy compliance and security are enhanced, but implementation complexity and deployment time increase

Engineering Contradiction:
Improvepolicy complianceVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system performs preliminary configuration of policy frameworks, trust relationships, and authentication mechanisms before deployment. The federated identity system is pre-established with defined policies and rules, so that when enterprises and service providers join the federation, the policy compliance framework is already in place, reducing the complexity of real-time policy negotiation and enforcement during operation.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If manual access control processes are used, then system simplicity is maintained, but IT security and policy compliance effectiveness deteriorate

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The federated identity system serves as an intermediary that enhances security effectiveness by providing centralized authentication, authorization, and policy enforcement. It mediates between users and enterprises, ensuring that security policies are consistently applied across the federation. This intermediary approach improves security without requiring each enterprise to independently implement complex security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts security parameters such as authentication methods, authorization levels, and policy enforcement strictness based on the specific context of each access request. This allows the system to maintain high security effectiveness while adapting to different scenarios, reducing the need for uniformly complex security configurations across all access points.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11736944B2Dynamic policy-based on-boarding of devices in enterprise environments
Publication Date: 2023.08.22 CISCO TECHNOLOGY INC
  • US11736944B2 patent drawing
  • US11736944B2 patent drawing
  • US11736944B2 patent drawing

AI summary

In one embodiment, a method for providing access to wireless networks may include receiving, by a wireless network access provider from a user device, a request to access a wireless network. The method may include obtaining data representing a policy applicable to the access request, sending the access request, augmented with the policy, to an identity provider associated with the user and having no pre-existing relationship with the access provider, and receiving, from the identity provider, an access request response indicating whether or not the policy is met. The method may include communicating, to the wireless device, an indication that the access request has been accepted, if the policy is met, or an indication that the access request has been rejected, if the policy is not met. The access provider and identity provider may be members of an identity and access federation that communicate over a dynamically established secure connection.