Dynamic UDN Group Onboarding via Credential-Based Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In shared network environments like hotel rooms or classrooms, users face challenges with secure onboarding of devices and limited control over access, leading to security concerns and poor user experience due to the lack of easy device discovery and access management.
Innovation Solution
The implementation of user-defined networks (UDNs) allows for dynamic addition and removal of user devices to private groups based on authentication, enabling secure and controlled access to specific services and devices within a physical space without manual operations, using a system that automatically assigns devices to UDN groups based on credentials and co-location with access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all devices are connected to a shared network environment, then network coverage and accessibility are improved, but security risks and unauthorized access increase
Solution Approach 1:
The patent segments the shared network into multiple isolated User Defined Networks (UDNs), where each user's devices form a separate logical network. This segmentation allows broad network coverage while preventing cross-user access, as each UDN is confined to its own namespace and can only communicate with authorized devices within that specific network.
Solution Approach 2:
The patent introduces a network broker as an intermediary component that manages device discovery, authentication, and UDN formation. The broker mediates all communication between users and the network infrastructure, enabling secure onboarding by verifying credentials and automatically creating appropriate UDN boundaries without requiring manual configuration.
2Reliability
If manual device onboarding is implemented, then access control security is improved, but user experience and operational efficiency deteriorate
Solution Approach 1:
The patent enables self-service onboarding where user devices automatically discover available UDNs, authenticate using provided credentials, and join the appropriate network without manual intervention. The system autonomously handles device registration, UDN creation, and authorization, maintaining strict access control while providing a seamless user experience similar to automatic Wi-Fi connection.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring UDN policies, authentication mechanisms, and device authorization rules before users arrive. The network broker is pre-programmed with security policies that automatically apply during onboarding, eliminating the need for manual security configuration while ensuring reliable access control from the moment devices connect.
3Loss of information
If users can discover all devices on the network, then device visibility is improved, but security and user control worsen
Solution Approach 1:
The patent implements local quality by allowing each user to discover and access only devices within their own UDN, while devices in other users' networks remain invisible. This localized visibility ensures users have complete awareness of authorized devices without exposing them to unauthorized devices, maintaining both device visibility and security by restricting discovery scope to the user's specific network context.
Data Source
AI summary
Disclosed herein are systems, methods, and computer-readable media for dynamic user device access to a user defined network (UDN) group. A request from a user device to access an end device is received from an application on the user device, where the request includes a credential and the end device is associated with multiple end devices within a private group with access to a set of services. A user device identity of the user device is dynamically added to the private group (e.g., UDN group) based on authenticating the user device based on the credential being associated with the private group. A change of authorization is sent to a controller to include the user device within the private group, and the user device is granted access to the set of services.


