Peer-to-Peer Device Location Sharing with IdP Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless networks face challenges in securely managing peer-to-peer device onboarding and location sharing, particularly in enterprise environments, where conventional methods relying on manufacturer-specific IoT segmentation and PSKs are inefficient and brittle, especially for devices not connected to the infrastructure network.
Innovation Solution
A manufacturer-managed authentication framework enables local policy-based location sharing and service provision for peer-to-peer devices by using Pre-Association Security Negotiation (PASN) and Automated Frequency Coordination (AFC) with an Identity Provider (IdP) to authenticate and authorize devices, ensuring secure location sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manufacturer-specific IoT segmentation and PSKs are used for device authentication, then device onboarding is simplified, but security and reliability deteriorate
Solution Approach 1:
The patent introduces an Identity Provider (IdP) as an intermediary between peer-to-peer devices and the network infrastructure. The IdP issues digital certificates that enable mutual authentication between devices, replacing the direct PSK-based authentication. This mediator provides a trusted third-party mechanism that enhances security while maintaining ease of device onboarding through automated certificate validation.
Solution Approach 2:
The patent replaces the mechanical PSK sharing mechanism with a cryptographic certificate-based authentication system. Instead of manually configuring pre-shared keys between devices, the system uses public key infrastructure (PKI) with digital certificates issued by the IdP. This substitution provides stronger security guarantees while automating the authentication process.
2Adaptability or versatility
If peer-to-peer devices are authenticated without infrastructure connection, then device connectivity is improved, but authentication reliability deteriorates
Solution Approach 1:
The patent implements preliminary authentication action by requiring peer-to-peer devices to obtain digital certificates from the IdP before establishing direct connections. This pre-authentication step ensures that devices are validated by a trusted authority before they engage in infrastructure-independent communication, maintaining authentication reliability while enabling flexible connectivity.
Solution Approach 2:
The patent enables peer-to-peer devices to perform self-authentication using their own digital certificates without requiring continuous connection to the network infrastructure. Devices can independently validate each other's credentials, providing self-service authentication that maintains reliability while enabling connectivity without infrastructure dependency.
3Adaptability or versatility
If location sharing is enabled for peer-to-peer devices, then service functionality is improved, but security risks increase
Solution Approach 1:
The patent implements feedback-based location sharing where the IdP receives location information from peer-to-peer devices and validates it against authentication credentials. The system provides feedback by granting or denying location sharing permissions based on the strength of authentication and policy rules. This controlled feedback mechanism enables location-based services while mitigating security risks through authorized access only.
Data Source
AI summary
Secure device location sharing may be provided. Over a secured link, an indication that a peer-to-peer device desires Automated Frequency Coordination (AFC) based location sharing may be received. Then, from the peer-to-peer device over the secured link, an identity provider (IdP) may be received for the peer-to-peer device. Next, validation of the peer-to-peer device may be requested from the IdP. From the IdP in response to requesting validation of the peer-to-peer device from the IdP, authentication for the peer-to-peer device and an indication that the peer-to-peer device needs AFC based location sharing may be received. An indication that the peer-to-peer device is approved for AFC based location sharing may then be sent to the peer-to-peer device over the secured link.


