Incident Area Network Credential Issuer for Disconnected Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Incident area networks, deployed during public safety incidents, face challenges in authenticating and authorizing users and devices without access to backend infrastructure, due to operational constraints such as disconnected modes and resource limitations.
Innovation Solution
An identity server is configured to receive agency-issued credentials, map attributes to relevant incident-specific attributes, and generate incident-issued credentials, enabling authentication and authorization within the incident area network without relying on external infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the incident area network operates in disconnected mode without access to backend infrastructure, then the network can be deployed rapidly during public safety incidents, but the ability to authenticate and authorize users and devices is compromised
Solution Approach 1:
The patent introduces a credential issuer as an intermediary component deployed within the incident area network. This credential issuer can issue credentials locally without requiring connection to external backend infrastructure, thereby maintaining authentication capability in disconnected mode while enabling rapid deployment
Solution Approach 2:
The system performs preliminary actions by pre-deploying the credential issuer and necessary authentication components within the incident area network before disconnection occurs. This allows the network to self-authenticate users and devices without requiring real-time connection to backend infrastructure
2Reliability
If backend infrastructure is duplicated at the incident area network, then authentication and authorization can be performed locally, but time, resource, and security constraints make this approach infeasible
Solution Approach 1:
The patent extracts only the essential credential issuance functionality from the backend infrastructure and deploys it as a lightweight credential issuer within the incident area network. This avoids duplicating the entire backend infrastructure while maintaining the core authentication capability
Solution Approach 2:
Instead of duplicating the full backend infrastructure, the system creates a simplified copy or representation of the authentication functionality through the credential issuer, which can operate independently with reduced resource requirements
3Adaptability or versatility
If the number of users and devices accessing the incident area network changes rapidly, then the network can adapt to dynamic incident requirements, but authentication and authorization become increasingly challenging without backend infrastructure
Solution Approach 1:
The credential issuer is designed to dynamically issue credentials to users and devices as they join or leave the incident area network. The system can rapidly adapt to changing user populations without requiring backend infrastructure, maintaining authorization capability through local credential management
Data Source
AI summary
A method and apparatus for issuing an incident-issued credential for an incident area network. One embodiment provides an identity server including an electronic processor configured to receive an agency-issued credential and retrieve a first set of attributes from the agency-issued credential. The electronic processor is also configured to map the first set of attributes to a scope of a service available through an incident area network. The electronic processor is further configured to generate the incident-issued credential for the incident area network including the scope and issue the incident-issued credential to a user device.


