Location Data Federation for Roaming Asset Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a scalable and secure method for sharing location data between asset owners and visited networks across different domains, especially in scenarios where pre-existing agreements are not established, leading to issues with trust and privacy, particularly when devices roam between outdoor and indoor locations or across multiple networks.

Innovation Solution

An identity federation system that registers multiple identity providers with a location, aggregation, and insights service, allowing asset owners to select and bind IDPs to their applications, enabling visited networks to dynamically share location data with asset owners through a trusted and consented mechanism, using digital certificates and a trusted service to establish secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ad hoc solutions are used to share location data between visited networks and asset owners, then location data can be shared, but scalability and trust issues arise due to the large number and diversity of asset owners

Engineering Contradiction:
Improvelocation data sharing capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a location data service as an intermediary component that mediates between visited networks and asset owners. This service receives location data from visited networks, validates it against privacy policies, and distributes it to authorized asset owners. The intermediary abstracts the complexity of direct peer-to-peer interactions, enabling scalable location data sharing without requiring each network to establish individual agreements with every asset owner.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-existing agreements are required between visited networks and asset owners for location data sharing, then privacy and security are maintained, but the system cannot scale to accommodate new asset owners and networks

Engineering Contradiction:
Improveprivacy and securityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by establishing privacy policies and data sharing agreements in advance at the asset owner level. Asset owners define their privacy preferences and authorized data recipients before any location data sharing occurs. When a device roams to a visited network, the location data service automatically applies these pre-established policies without requiring real-time negotiation or new agreements, enabling both privacy protection and rapid scalability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If identity federation and digital certificates are used to establish secure connections, then trust and privacy are ensured, but the setup and configuration become more complex

Engineering Contradiction:
Improvetrust and privacyVSAvoidsystem setup ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements self-service mechanisms where asset owners independently configure their privacy policies and authorized recipients through the location data service. The system automatically handles certificate validation, policy matching, and data routing without requiring manual configuration of secure connections between each visited network and asset owner. This self-service approach maintains strong security through identity federation while dramatically simplifying system setup and ongoing operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4260577B1Controlled access to geolocation data in open roaming federations
Publication Date: 2024.09.18 CISCO TECHNOLOGY INC
  • EP4260577B1 patent drawingFigure 1
  • EP4260577B1 patent drawingFigure 2
  • EP4260577B1 patent drawingFigure 3~4

AI summary

Embodiments herein registers Asset Owners (AOs) and AO applications to a location, aggregation, and insight (LAI) service that are part of the same identity federation. When registering the AO with the LAI service, the AO selects which of a plurality of Identity Providers (IDPs) it has a relationship with, and the LAI service can then bind those IDPs to the AO application. This binding associates respective realms (e.g., domains) corresponding to the selected IDPs to the AO application. Later, when a device owned by the AO roams to a visited network (VN), the LAI service can then use a realm identified from a device ID provided by the device to identify the ID of the AO application. The LAI service then enables the VN to transmit a location of the device to the AO application. In one embodiment, the VN obtains consent from the AO before sharing location data.