Hierarchical ID Proxy for Scalable Roaming Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network providers face challenges in verifying the identity of devices requesting roaming access, particularly due to diverse and non-scalable infrastructure, competing protocols, and the need to distinguish between authoritative identity providers and their proxies, which can lead to interactions with unauthorized third parties.

Innovation Solution

The system connects to an identity entity using a transport layer security tunnel to receive a certificate that identifies whether the entity is an authoritative identity provider or a proxy, utilizing a hierarchical ID to determine the entity's role and validate the device's identity, thereby ensuring secure and scalable validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity verification infrastructure is used, then identity verification can be performed, but the system is not scalable and is diverse

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a hierarchical ID system as an intermediary layer between identity providers and network access providers. This hierarchical ID acts as a mediator that enables scalable verification by allowing proxy identity providers to represent authoritative identity providers without requiring direct integration with each provider's specific protocol or infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If diverse identity verification infrastructure is used, then multiple identity providers can be supported, but the infrastructure becomes non-scalable and complex

Engineering Contradiction:
Improveidentity provider compatibilityVSAvoidverification infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The hierarchical ID system serves as a universal interface that works across multiple identity providers and network access providers. It provides multi-functionality by enabling both direct identity verification and proxy-based verification through a single standardized mechanism, eliminating the need for separate integration logic for each provider.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If authoritative identity providers are directly contacted, then accurate identity verification is achieved, but the system cannot handle proxy scenarios efficiently

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidproxy handling capability
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The hierarchical ID system introduces a proxy mechanism where intermediary identity providers can represent authoritative identity providers. The system maintains verification accuracy by validating the hierarchical relationship between proxies and authoritative providers, while simplifying operations by allowing networks to contact proxies instead of requiring direct contact with authoritative providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If direct connection to authoritative identity providers is required, then security is maintained, but the system lacks flexibility for roaming access scenarios

Engineering Contradiction:
Improvesecurity assuranceVSAvoidroaming access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the identity verification process into hierarchical levels: authoritative identity providers at the top level and proxy identity providers at intermediate levels. This segmentation allows the system to maintain security by preserving the trust relationship with authoritative providers while gaining flexibility through the introduction of proxy layers that can handle roaming access scenarios.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11445372B2Scalable public key identification model
Publication Date: 2022.09.13 CISCO TECHNOLOGY INC
  • US11445372B2 patent drawing
  • US11445372B2 patent drawing
  • US11445372B2 patent drawing

AI summary

The present technology pertains to a system, method, and non-transitory computer-readable medium for confirming the identities of devices requesting roaming access on a network by authoritative identity providers and proxies for authoritative identity providers. The technology can, in response to a receipt of a request from a device for roaming access, connect to an identity entity at an address by a network access provider, wherein the request for roaming access identifies an authoritative identity provider host name; receive a certificate from the identity entity; and determine, using the certificate, whether the identity entity is an authoritative identity provider or a proxy for an authoritative identity provider.