Password-less Wireless Authentication via Identity Broker

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network authentication methods rely on passwords, which are insecure and inconvenient, especially when multiple devices and services are involved, and do not efficiently leverage identity provider services for seamless access.

Innovation Solution

A system that uses access tokens from identity provider services, stored in a user profile with associated policies, to provide password-less authentication by generating a device token for seamless access to wireless networks, ensuring secure and convenient connectivity without exposing Personally Identifiable Information (PII).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication is used for wireless networks, then authentication can be performed, but security is compromised and user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an identity provider service as an intermediary between the wireless network and the user device. This service issues access tokens that mediate the authentication process, replacing direct password transmission with a secure token-based system that enhances both security and convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a digital copy of user identity credentials in the form of access tokens issued by the identity provider. These tokens are cryptographic representations that replicate authentication authority without exposing actual password credentials, enabling secure authentication without password transmission

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If multiple devices need to access the wireless network, then network coverage is improved, but password management complexity increases

Engineering Contradiction:
Improvemulti-device accessVSAvoidpassword management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access token system provides universal authentication credentials that work across multiple devices and services. A single token issued by the identity provider can authenticate the user to various wireless networks and services, eliminating the need for device-specific password management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system is segmented into distinct functional components: the identity provider service that manages credentials, the access tokens that carry authentication information, and the wireless network that validates tokens. This segmentation allows each component to handle specific tasks independently, simplifying overall system management

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If traditional authentication methods are used, then compatibility with existing systems is maintained, but seamless access across services is not achieved

Engineering Contradiction:
Improveseamless accessVSAvoidauthentication system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The identity provider service performs preliminary authentication and issues access tokens before the user attempts to connect to wireless networks. This advance preparation eliminates the need for repeated authentication actions during actual network access, enabling seamless connectivity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the authentication parameter from password-based verification to token-based verification. This parameter change enables automated authentication flows where devices can present tokens without user interaction, achieving seamless access while the identity provider manages the increased system complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12074859B2Password-less wireless authentication
Publication Date: 2024.08.27 CISCO TECHNOLOGY INC
  • US12074859B2 patent drawing
  • US12074859B2 patent drawing
  • US12074859B2 patent drawing

AI summary

First, a plurality of access tokens may be received from a respective plurality of identity provider services. Each of the plurality of access tokens may be associated with a user. Then, the plurality of access tokens may be stored in a profile associated with the user. Next, user polices associated with the use of the plurality of access tokens may be assigned. A device token may then be provided to a user device associated with the user. The device token may be associated with the profile. The device token and network policies may be received and then it may be determined that the user polices and the network policies are congruent. In response to determining that the user polices and the network policies are congruent, authentication to at least one of the plurality identity provider services may be made.