Roaming Consortium Identifier Automates Credential Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networks face challenges in handling diverse identity requirements across different locations and service providers, where the need for location-specific identity validation and privacy protection is not adequately addressed, leading to incompatibilities and manual credential selection burdens.

Innovation Solution

The implementation of Roaming Consortium Identifiers (RCOIs) that advertise and manage multiple identity types, allowing seamless onboarding and automated credential selection based on location-specific requirements, ensuring compliance with local access provider policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual credential selection is used for network association, then users can control identity disclosure, but the process becomes complex and time-consuming

Engineering Contradiction:
Improveidentity validation complianceVSAvoidcredential selection process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables user devices to automatically select and use appropriate credentials for network association without manual intervention. The automated credential selection process analyzes location-specific requirements and autonomously chooses the most suitable identity type, eliminating the need for users to manually evaluate and select credentials while ensuring compliance with local access provider policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary mechanism (automated credential selection system) that mediates between the user device and the wireless network. This intermediary automatically handles the credential selection process by receiving location-specific requirements, determining the appropriate identity type, and selecting credentials that satisfy both user privacy preferences and network access policies, thereby resolving the contradiction between automation and compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-specific identity validation is implemented, then network security and policy compliance improve, but device compatibility and accessibility decrease

Engineering Contradiction:
Improvepolicy complianceVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements a universal credential management approach where user devices store multiple identity types (work, personal, guest credentials) and can automatically select the appropriate one based on location-specific requirements. This multi-functional credential system enables a single device to adapt to various network environments and policy requirements, maintaining both security compliance and broad device compatibility across diverse locations and service providers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs dynamic credential selection where the system adapts its behavior based on real-time location-specific requirements. The automated selection process dynamically determines which identity type to use by analyzing the current network environment, access provider policies, and user preferences, allowing the system to flexibly adjust to different locations while maintaining policy compliance and device compatibility.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple identity types are managed manually, then privacy control is improved, but system complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoididentity management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service automation where the user device autonomously manages multiple identity types. The automated credential selection process privately evaluates location-specific requirements and automatically selects the most appropriate credential without requiring user intervention. This self-managing system maintains strong privacy control by keeping credential evaluation local and automatic, while reducing the perceived complexity for users who no longer need to manually manage multiple identities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring multiple identity types (work, personal, guest credentials) in the user device before network association is needed. The system prepares these credentials in advance and automatically selects the appropriate one based on location-specific requirements at the time of association. This preliminary preparation eliminates the need for real-time manual credential management, reducing system complexity while maintaining privacy control through pre-established identity options.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3884713B1Roaming consortium identifier (RCOI)-based system for handling identity requirements
Publication Date: 2025.06.25 CISCO TECHNOLOGY INC
  • EP3884713B1 patent drawingFigure 1
  • EP3884713B1 patent drawingFigure 2
  • EP3884713B1 patent drawingFigure 3

AI summary

Roaming Consortium Identifier (RCOI)-based handling of identity requirements may be provided. First, an access device may advertise an identifier. The identifier may identify a roaming federation and an identity type used by a service provider in order to provide service by the access device. Next, a request to associate with the access device may be received from a user device. The request may be compliant with the identity type advertised in the identifier. The user device may then be associated with the access device in response to receiving the request.