Incident Area Network Credential Issuer for Disconnected Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Incident area networks, deployed during public safety incidents, face challenges in authenticating and authorizing users and devices without access to backend infrastructure, due to operational constraints such as disconnected modes and resource limitations.

Innovation Solution

An identity server is configured to receive agency-issued credentials, map attributes to relevant incident-specific attributes, and generate incident-issued credentials, enabling authentication and authorization within the incident area network without relying on external infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the incident area network operates in disconnected mode without access to backend infrastructure, then the network can be deployed rapidly during public safety incidents, but the ability to authenticate and authorize users and devices is compromised

Engineering Contradiction:
Improvedeployment speedVSAvoidauthentication capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a credential issuer as an intermediary component deployed within the incident area network. This credential issuer can issue credentials locally without requiring connection to external backend infrastructure, thereby maintaining authentication capability in disconnected mode while enabling rapid deployment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-deploying the credential issuer and necessary authentication components within the incident area network before disconnection occurs. This allows the network to self-authenticate users and devices without requiring real-time connection to backend infrastructure

Inventive Principle:
Principle #10Preliminary action

2Reliability

If backend infrastructure is duplicated at the incident area network, then authentication and authorization can be performed locally, but time, resource, and security constraints make this approach infeasible

Engineering Contradiction:
Improveauthentication capabilityVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential credential issuance functionality from the backend infrastructure and deploys it as a lightweight credential issuer within the incident area network. This avoids duplicating the entire backend infrastructure while maintaining the core authentication capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of duplicating the full backend infrastructure, the system creates a simplified copy or representation of the authentication functionality through the credential issuer, which can operate independently with reduced resource requirements

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If the number of users and devices accessing the incident area network changes rapidly, then the network can adapt to dynamic incident requirements, but authentication and authorization become increasingly challenging without backend infrastructure

Engineering Contradiction:
Improveuser scalabilityVSAvoidauthorization capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The credential issuer is designed to dynamically issue credentials to users and devices as they join or leave the incident area network. The system can rapidly adapt to changing user populations without requiring backend infrastructure, maintaining authorization capability through local credential management

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10104526B2Method and apparatus for issuing a credential for an incident area network
Publication Date: 2018.10.16 MOTOROLA SOLUTIONS INC
  • US10104526B2 patent drawing
  • US10104526B2 patent drawing
  • US10104526B2 patent drawing

AI summary

A method and apparatus for issuing an incident-issued credential for an incident area network. One embodiment provides an identity server including an electronic processor configured to receive an agency-issued credential and retrieve a first set of attributes from the agency-issued credential. The electronic processor is also configured to map the first set of attributes to a scope of a service available through an incident area network. The electronic processor is further configured to generate the incident-issued credential for the incident area network including the scope and issue the incident-issued credential to a user device.