Identity Mapping for Interoperable Packet-Based Communication Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users of instant messaging and voice over internet protocol (VoIP) services need to maintain separate contact lists and register separately with different software providers, leading to inconvenience and potential security issues due to the lack of interoperability between these communication networks.
Innovation Solution
A method and system that allow a user to access a second packet-based communication network by creating a derived user identity from their first network identity using a predetermined rule, enabling seamless communication across both networks with a single authentication process, thus allowing interoperability between instant messaging and VoIP networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users register separately with different software providers for instant messaging and VoIP services, then each network can maintain its own security and authentication mechanisms, but users must maintain separate contact lists and perform multiple authentication processes
Solution Approach 1:
The patent implements a universal authentication mechanism where a single user identity can be used across multiple packet-based communication networks. The system allows a user to authenticate once with their home network, and that authentication is recognized by visited networks through identity mapping, enabling the same identity to function universally across different networks without requiring separate registrations.
Solution Approach 2:
The patent introduces network elements that act as intermediaries to map user identities between different networks. When a user roams between networks, the home network element and visited network element work together to translate and recognize the user's identity, allowing seamless authentication without the user needing to know about the underlying complex inter-network authentication mechanisms.
2Adaptability or versatility
If separate client software is required for each communication service, then each service can be optimized independently, but users must download and maintain multiple clients with separate contact lists
Solution Approach 1:
The patent enables a single client application to access multiple packet-based communication networks by implementing a universal identity mapping mechanism. The client uses a single identity that is recognized across different networks, allowing one client to provide multiple communication services (instant messaging, VoIP, etc.) without requiring separate applications for each service.
Solution Approach 2:
The patent merges multiple network access functions into a single authentication process. Instead of requiring separate authentication and contact list management for each network, the system combines these functions by allowing a single authenticated identity to access multiple networks, effectively merging what would otherwise require separate client applications.
3Reliability
If digital certificates are exchanged between users in peer-to-peer systems, then user identities can be verified and trust can be established, but the authentication process becomes more complex and requires additional security infrastructure
Solution Approach 1:
The patent uses network elements as intermediaries to handle the complex certificate exchange and identity verification processes. Instead of requiring direct peer-to-peer certificate exchange between users, the network elements mediate the authentication by mapping identities and verifying credentials, simplifying the process for end users while maintaining strong security.
Solution Approach 2:
The patent implements automatic identity mapping and authentication where the system performs the complex security operations without requiring user intervention. When a user accesses a visited network, the authentication process is automatically handled by the network elements through identity mapping, eliminating the need for users to manually manage certificates or understand the underlying security infrastructure.
Data Source
AI summary
A user of a first packet-based communication network is authorized to access a second packet-based communication network. In at least some embodiments, an authorization request is received from a user terminal of the user at a first network element of the first packet-based communication network, the authorization request comprising a first user identity. Responsive to the authorization request, a request is transmitted to create a second user identity from the first network element to a second network element of the second packet-based communication network. The second network element creates the second user identity for use in the second packet-based communication network, the second user identity being derivable from the first user identity according to a predetermined rule. The second user identity in the second packet-based communication network is stored for use with subsequent communication events over the second packet-based communication network.


