WLAN Identity Federation Trust Architecture for IDP Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wi-Fi identity federations face challenges in efficiently and reliably onboarding lesser-known or non-traditional identity providers (IDPs) with different credential sets, limiting the acceptance of IDPs by access points.

Innovation Solution

A wireless LAN (WLAN) public identity federation trust architecture that evaluates the credential strength of user devices by calculating the strength of the associated identity provider based on its authentication methods, allowing access if the credential strength meets a predetermined threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access providers onboard multiple lesser-known or non-traditional IDPs with different credential sets, then the versatility and acceptance of IDPs increases, but the complexity of evaluating and managing credentials for each IDP increases significantly

Engineering Contradiction:
ImproveIDP acceptanceVSAvoidcredential evaluation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential evaluation framework that can assess credentials from any IDP type (traditional or non-traditional) through a common set of evaluation criteria. The access point uses standardized parameters such as credential strength, IDP reputation, and authentication method reliability to evaluate diverse credential sets uniformly, eliminating the need for IDP-specific evaluation logic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts evaluation parameters based on IDP characteristics and credential types. Instead of using fixed evaluation rules, the access point modifies weighting factors and thresholds according to the specific IDP being evaluated, allowing flexible adaptation to different credential schemes while maintaining a consistent evaluation process.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If access providers manually evaluate credentials for each user from each IDP, then the reliability of authentication increases, but the time and resources required for authentication increase significantly

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary evaluation of IDP credentials and establishes trust relationships in advance. Access points pre-assess IDP credibility and credential strength before actual user authentication occurs, creating a foundation of pre-validated trust that speeds up subsequent user authentication while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where authentication outcomes and credential validation results are continuously monitored and used to refine evaluation models. The system learns from past authentication decisions and adjusts its evaluation criteria accordingly, improving both reliability and efficiency over time through data-driven optimization.

Inventive Principle:
Principle #23Feedback

3Quantity of substance

If access providers accept credentials from non-traditional IDPs, then the quantity of accepted IDPs increases, but the difficulty of assessing credential strength and authenticity increases

Engineering Contradiction:
Improvenumber of IDPsVSAvoidcredential strength assessment
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces intermediary evaluation layers that mediate between diverse IDP credential systems and the access control decision. These intermediaries translate different credential types into a common assessment framework, making it easier to evaluate non-traditional IDPs by converting their unique credential schemes into standardized metrics that can be uniformly assessed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250097209A1Wireless LAN (WLAN) public identity federation trust architecture
Publication Date: 2025.03.20 CISCO TECHNOLOGY INC
  • US20250097209A1 patent drawing
  • US20250097209A1 patent drawing
  • US20250097209A1 patent drawing

AI summary

The disclosed technology relates to a process of evaluating any number of different identity providers (IDPs) and their respective set of credentials that are used to authenticate corresponding users to assist with the onboarding of the different IDPs in connection with Wi-Fi identity federations. In particular, the process allows a person's electronic identity and attributes (stored across one or more IDPs) to be determined once using a standard. Once trust has been established for the user, that trust can then be utilized across a number of different systems (e.g., Single-sign on). The same trust determination can be used without the need for the authenticity of the user identity to be re-evaluated with each new access request.