Password-less Wireless Authentication via Identity Broker
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network authentication methods rely on passwords, which are insecure and inconvenient, especially when multiple devices and services are involved, and do not efficiently leverage identity provider services for seamless access.
Innovation Solution
A system that uses access tokens from identity provider services, stored in a user profile with associated policies, to provide password-less authentication by generating a device token for seamless access to wireless networks, ensuring secure and convenient connectivity without exposing Personally Identifiable Information (PII).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used for wireless networks, then authentication can be performed, but security is compromised and user convenience deteriorates
Solution Approach 1:
The patent introduces an identity provider service as an intermediary between the wireless network and the user device. This service issues access tokens that mediate the authentication process, replacing direct password transmission with a secure token-based system that enhances both security and convenience
Solution Approach 2:
The system creates a digital copy of user identity credentials in the form of access tokens issued by the identity provider. These tokens are cryptographic representations that replicate authentication authority without exposing actual password credentials, enabling secure authentication without password transmission
2Adaptability or versatility
If multiple devices need to access the wireless network, then network coverage is improved, but password management complexity increases
Solution Approach 1:
The access token system provides universal authentication credentials that work across multiple devices and services. A single token issued by the identity provider can authenticate the user to various wireless networks and services, eliminating the need for device-specific password management
Solution Approach 2:
The authentication system is segmented into distinct functional components: the identity provider service that manages credentials, the access tokens that carry authentication information, and the wireless network that validates tokens. This segmentation allows each component to handle specific tasks independently, simplifying overall system management
3Ease of operation
If traditional authentication methods are used, then compatibility with existing systems is maintained, but seamless access across services is not achieved
Solution Approach 1:
The identity provider service performs preliminary authentication and issues access tokens before the user attempts to connect to wireless networks. This advance preparation eliminates the need for repeated authentication actions during actual network access, enabling seamless connectivity
Solution Approach 2:
The system changes the authentication parameter from password-based verification to token-based verification. This parameter change enables automated authentication flows where devices can present tokens without user interaction, achieving seamless access while the identity provider manages the increased system complexity
Data Source
AI summary
First, a plurality of access tokens may be received from a respective plurality of identity provider services. Each of the plurality of access tokens may be associated with a user. Then, the plurality of access tokens may be stored in a profile associated with the user. Next, user polices associated with the use of the plurality of access tokens may be assigned. A device token may then be provided to a user device associated with the user. The device token may be associated with the profile. The device token and network policies may be received and then it may be determined that the user polices and the network policies are congruent. In response to determining that the user polices and the network policies are congruent, authentication to at least one of the plurality identity provider services may be made.


