Identity Mapping for Interoperable Packet-Based Communication Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of instant messaging and voice over internet protocol (VoIP) services need to maintain separate contact lists and register separately with different software providers, leading to inconvenience and potential security issues due to the lack of interoperability between these communication networks.

Innovation Solution

A method and system that allow a user to access a second packet-based communication network by creating a derived user identity from their first network identity using a predetermined rule, enabling seamless communication across both networks with a single authentication process, thus allowing interoperability between instant messaging and VoIP networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users register separately with different software providers for instant messaging and VoIP services, then each network can maintain its own security and authentication mechanisms, but users must maintain separate contact lists and perform multiple authentication processes

Engineering Contradiction:
Improvenetwork securityVSAvoiduser authentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication mechanism where a single user identity can be used across multiple packet-based communication networks. The system allows a user to authenticate once with their home network, and that authentication is recognized by visited networks through identity mapping, enabling the same identity to function universally across different networks without requiring separate registrations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces network elements that act as intermediaries to map user identities between different networks. When a user roams between networks, the home network element and visited network element work together to translate and recognize the user's identity, allowing seamless authentication without the user needing to know about the underlying complex inter-network authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate client software is required for each communication service, then each service can be optimized independently, but users must download and maintain multiple clients with separate contact lists

Engineering Contradiction:
Improveservice optimizationVSAvoidnumber of clients
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent enables a single client application to access multiple packet-based communication networks by implementing a universal identity mapping mechanism. The client uses a single identity that is recognized across different networks, allowing one client to provide multiple communication services (instant messaging, VoIP, etc.) without requiring separate applications for each service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple network access functions into a single authentication process. Instead of requiring separate authentication and contact list management for each network, the system combines these functions by allowing a single authenticated identity to access multiple networks, effectively merging what would otherwise require separate client applications.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If digital certificates are exchanged between users in peer-to-peer systems, then user identities can be verified and trust can be established, but the authentication process becomes more complex and requires additional security infrastructure

Engineering Contradiction:
Improveidentity verificationVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses network elements as intermediaries to handle the complex certificate exchange and identity verification processes. Instead of requiring direct peer-to-peer certificate exchange between users, the network elements mediate the authentication by mapping identities and verifying credentials, simplifying the process for end users while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements automatic identity mapping and authentication where the system performs the complex security operations without requiring user intervention. When a user accesses a visited network, the authentication process is automatically handled by the network elements through identity mapping, eliminating the need for users to manually manage certificates or understand the underlying security infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8422650B2Authentication in communication systems
Publication Date: 2013.04.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8422650B2 patent drawing
  • US8422650B2 patent drawing
  • US8422650B2 patent drawing

AI summary

A user of a first packet-based communication network is authorized to access a second packet-based communication network. In at least some embodiments, an authorization request is received from a user terminal of the user at a first network element of the first packet-based communication network, the authorization request comprising a first user identity. Responsive to the authorization request, a request is transmitted to create a second user identity from the first network element to a second network element of the second packet-based communication network. The second network element creates the second user identity for use in the second packet-based communication network, the second user identity being derivable from the first user identity according to a predetermined rule. The second user identity in the second packet-based communication network is stored for use with subsequent communication events over the second packet-based communication network.