Open Roaming Security Data Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current Open Roaming (OR) system lacks the capability to inform user devices about a network's security posture or reputation before establishing a connection, leading to potential security risks as devices may inadvertently connect to insecure networks.

Innovation Solution

The proposed solution integrates the evaluation of a network's security posture and reputation into the OR federation system by retrieving, evaluating, and transmitting security data to user devices before connection establishment. This involves the Identity Provider (IdP) querying the Security Data Provider (SDP) for security data, which may include reputation scores and security profiles, and then transmitting this information to user devices for evaluation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the Open Roaming system allows seamless access across networks without repeated authentication, then ease of operation is improved, but security reliability deteriorates because devices may connect to insecure networks without prior knowledge

Engineering Contradiction:
Improveseamless accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security evaluation by retrieving and assessing security data from the SDP before allowing connection establishment. This advance action enables the device to know the security posture of a network prior to connecting, thus maintaining ease of operation while improving security reliability through pre-connection verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The Identity Provider acts as an intermediary between the user device and the access network. It retrieves security data from the Security Data Provider and uses this information to mediate the connection decision, balancing the ease of roaming access with security requirements by filtering connections based on evaluated security criteria

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security data retrieval and evaluation is integrated into the authentication process, then security reliability is improved, but device complexity increases due to additional system components and processes

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Identity Provider is enhanced to perform multiple functions: traditional authentication verification plus new security data retrieval and evaluation. By making the IdP multi-functional, the system improves security without requiring separate dedicated security evaluation devices, thus limiting the increase in overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses existing federation infrastructure and protocols where the IdP automatically retrieves security data from the SDP using established communication mechanisms. This self-service approach allows security evaluation to be integrated without requiring manual configuration or additional complex infrastructure setup

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250168633A1Open roaming security enhancements
Publication Date: 2025.05.22 CISCO TECHNOLOGY INC
  • US20250168633A1 patent drawing
  • US20250168633A1 patent drawing
  • US20250168633A1 patent drawing

AI summary

Techniques for enhancing the security of network access within an open roaming framework are provided. A first network device receives a request to authenticate connection of a user device to a network. The first network device retrieves security data associated with the network. Based on analyzing the security data associated with the network, the first network device determines that one or more security criteria are satisfied. The first network device transmits a response to the user device, where the response instructs the user device to establish a connection with the network and does not disclose the security data.