Dynamic UDN Group Onboarding via Credential-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared network environments like hotel rooms or classrooms, users face challenges with secure onboarding of devices and limited control over access, leading to security concerns and poor user experience due to the lack of easy device discovery and access management.

Innovation Solution

The implementation of user-defined networks (UDNs) allows for dynamic addition and removal of user devices to private groups based on authentication, enabling secure and controlled access to specific services and devices within a physical space without manual operations, using a system that automatically assigns devices to UDN groups based on credentials and co-location with access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all devices are connected to a shared network environment, then network coverage and accessibility are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the shared network into multiple isolated User Defined Networks (UDNs), where each user's devices form a separate logical network. This segmentation allows broad network coverage while preventing cross-user access, as each UDN is confined to its own namespace and can only communicate with authorized devices within that specific network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network broker as an intermediary component that manages device discovery, authentication, and UDN formation. The broker mediates all communication between users and the network infrastructure, enabling secure onboarding by verifying credentials and automatically creating appropriate UDN boundaries without requiring manual configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual device onboarding is implemented, then access control security is improved, but user experience and operational efficiency deteriorate

Engineering Contradiction:
Improveaccess controlVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service onboarding where user devices automatically discover available UDNs, authenticate using provided credentials, and join the appropriate network without manual intervention. The system autonomously handles device registration, UDN creation, and authorization, maintaining strict access control while providing a seamless user experience similar to automatic Wi-Fi connection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-configuring UDN policies, authentication mechanisms, and device authorization rules before users arrive. The network broker is pre-programmed with security policies that automatically apply during onboarding, eliminating the need for manual security configuration while ensuring reliable access control from the moment devices connect.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If users can discover all devices on the network, then device visibility is improved, but security and user control worsen

Engineering Contradiction:
Improvedevice visibilityVSAvoidunauthorized control
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by allowing each user to discover and access only devices within their own UDN, while devices in other users' networks remain invisible. This localized visibility ensures users have complete awareness of authorized devices without exposing them to unauthorized devices, maintaining both device visibility and security by restricting discovery scope to the user's specific network context.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240195812A1Onboarding Auto Creation of UDN Groups and Dynamic Binding
Publication Date: 2024.06.13 CISCO TECHNOLOGY INC
  • US20240195812A1 patent drawing
  • US20240195812A1 patent drawing
  • US20240195812A1 patent drawing

AI summary

Disclosed herein are systems, methods, and computer-readable media for dynamic user device access to a user defined network (UDN) group. A request from a user device to access an end device is received from an application on the user device, where the request includes a credential and the end device is associated with multiple end devices within a private group with access to a set of services. A user device identity of the user device is dynamically added to the private group (e.g., UDN group) based on authenticating the user device based on the credential being associated with the private group. A change of authorization is sent to a controller to include the user device within the private group, and the user device is granted access to the set of services.