Provisioning Domain Identifier for Identity Provider Policy Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The OpenRoaming system lacks the ability to influence devices to use more advanced internet protocol (IP) configuration options provided by identity providers (IDPs).

Innovation Solution

The implementation of Roaming Consortium Organization Identifier (RCOI) specific provisioning domains (PVDs) allows IDPs to deliver configuration and policy information to wireless stations (STAs), enabling the use of advanced IP configuration options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the OpenRoaming system uses existing RCOI-based policies, then basic federation interworking is achieved, but the system cannot deliver advanced IP configuration options to devices

Engineering Contradiction:
Improveconfiguration options deliveryVSAvoidIP configuration information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the configuration information delivery by introducing a separate provisioning domain (PVD) structure alongside the existing RCOI-based federation. The PVD identifier is generated by associating RCOI with specific provisioning domains, allowing configuration information to be divided into basic federation policies (handled by existing RCOI) and advanced IP configurations (handled by new PVD structure). This segmentation enables delivery of advanced IP configuration options without disrupting existing federation interworking.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces provisioning domains as an intermediary layer between the identity federation system and devices. The PVD acts as a mediator that receives configuration information from the system and delivers it to devices in a format they can understand and apply. This intermediary structure enables the OpenRoaming system to influence device configuration by providing a dedicated channel (PVD) for transmitting advanced IP configuration options that were previously unavailable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system introduces new provisioning domain structures, then advanced IP configuration delivery is enabled, but system complexity increases

Engineering Contradiction:
Improveconfiguration delivery capabilityVSAvoidprovisioning domain structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent designs the provisioning domain structure to be multi-functional, serving both existing federation purposes and new configuration delivery needs. The PVD identifier is generated by combining existing RCOI with provisioning domain information, allowing the same structure to handle both basic federation interworking and advanced IP configuration delivery. This universality reduces complexity by reusing existing components (RCOI) rather than creating entirely new systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by pre-generating PVD identifiers and associating them with RCOI before actual configuration delivery. The provisioning domain structure is established in advance, with PVD configuration information prepared and linked to specific identity providers. This preliminary setup enables the system to seamlessly deliver advanced IP configuration options without requiring complex real-time processing or device-side complexity during actual configuration application.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250039662A1Delivering identity provider specific configurations and policies
Publication Date: 2025.01.30 CISCO TECHNOLOGY INC
  • US20250039662A1 patent drawing
  • US20250039662A1 patent drawing
  • US20250039662A1 patent drawing

AI summary

Techniques for wireless communications are disclosed. The techniques include generating a provisioning domain (PVD) identifier by associating a roaming consortium organization identifier (RCOI), relating to an identity federation comprising an identity provider (IDP), with the PVD. The techniques further include providing PVD configuration information from the IDP to a wireless station (STA) associated with the IDP, using the PVD identifier. The techniques further include applying one or more configuration policies at the STA based on the PVD configuration information.