WLAN Identity Federation Trust Architecture for IDP Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wi-Fi identity federations face challenges in efficiently and reliably onboarding lesser-known or non-traditional identity providers (IDPs) with different credential sets, limiting the acceptance of IDPs by access points.
Innovation Solution
A wireless LAN (WLAN) public identity federation trust architecture that evaluates the credential strength of user devices by calculating the strength of the associated identity provider based on its authentication methods, allowing access if the credential strength meets a predetermined threshold.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access providers onboard multiple lesser-known or non-traditional IDPs with different credential sets, then the versatility and acceptance of IDPs increases, but the complexity of evaluating and managing credentials for each IDP increases significantly
Solution Approach 1:
The patent implements a universal credential evaluation framework that can assess credentials from any IDP type (traditional or non-traditional) through a common set of evaluation criteria. The access point uses standardized parameters such as credential strength, IDP reputation, and authentication method reliability to evaluate diverse credential sets uniformly, eliminating the need for IDP-specific evaluation logic.
Solution Approach 2:
The system dynamically adjusts evaluation parameters based on IDP characteristics and credential types. Instead of using fixed evaluation rules, the access point modifies weighting factors and thresholds according to the specific IDP being evaluated, allowing flexible adaptation to different credential schemes while maintaining a consistent evaluation process.
2Reliability
If access providers manually evaluate credentials for each user from each IDP, then the reliability of authentication increases, but the time and resources required for authentication increase significantly
Solution Approach 1:
The system performs preliminary evaluation of IDP credentials and establishes trust relationships in advance. Access points pre-assess IDP credibility and credential strength before actual user authentication occurs, creating a foundation of pre-validated trust that speeds up subsequent user authentication while maintaining reliability.
Solution Approach 2:
The patent implements feedback mechanisms where authentication outcomes and credential validation results are continuously monitored and used to refine evaluation models. The system learns from past authentication decisions and adjusts its evaluation criteria accordingly, improving both reliability and efficiency over time through data-driven optimization.
3Quantity of substance
If access providers accept credentials from non-traditional IDPs, then the quantity of accepted IDPs increases, but the difficulty of assessing credential strength and authenticity increases
Solution Approach 1:
The patent introduces intermediary evaluation layers that mediate between diverse IDP credential systems and the access control decision. These intermediaries translate different credential types into a common assessment framework, making it easier to evaluate non-traditional IDPs by converting their unique credential schemes into standardized metrics that can be uniformly assessed.
Data Source
AI summary
The disclosed technology relates to a process of evaluating any number of different identity providers (IDPs) and their respective set of credentials that are used to authenticate corresponding users to assist with the onboarding of the different IDPs in connection with Wi-Fi identity federations. In particular, the process allows a person's electronic identity and attributes (stored across one or more IDPs) to be determined once using a standard. Once trust has been established for the user, that trust can then be utilized across a number of different systems (e.g., Single-sign on). The same trust determination can be used without the need for the authenticity of the user identity to be re-evaluated with each new access request.


