Delivering identity provider specific configurations and policies
Techniques for wireless communications are disclosed. The techniques include generating a provisioning domain (PVD) identifier by associating a roaming consortium organization identifier (RCOI), relating to an identity federation comprising an identity provider (IDP), with the PVD. The techniques further include providing PVD configuration information from the IDP to a wireless station (STA) associated with the IDP, using the PVD identifier. The techniques further include applying one or more configuration policies at the STA based on the PVD configuration information.
1 . A method, comprising:
generating a provisioning domain (PVD) identifier by adding a roaming consortium organization identifier (RCOI), relating to an identity federation comprising an identity provider (IDP), to a domain name of the IDP;
providing PVD configuration information from the IDP to a wireless station (STA) associated with the IDP, using the PVD identifier; and
applying one or more configuration policies at the STA based on the PVD configuration information.
2 . The method of claim 1 , wherein the identity federation comprises an OpenRoaming federation.
3 . The method of claim 1 , wherein the PVD identifier comprises a uniform resource identifier (URI) comprising at least a portion of the RCOI.
4 . The method of claim 3 , wherein providing the PVD configuration information from the IDP to the STA associated with the IDP, using the PVD identifier comprises:
retrieving the one or more configuration policies at the STA by transmitting a query to the URI.
5 . The method of claim 4 , further comprising:
determining, based on a value provided by the IDP to the STA, to transmit the query to the URI.
6 . The method of claim 1 , wherein providing PVD configuration information from the IDP to the STA associated with the IDP, using the PVD identifier, comprises:
transmitting a network message comprising the PVD identifier from the IDP to an intermediate network device between the IDP and STA.
7 . The method of claim 6 , wherein the network message comprises a remote authentication dial-in user service (RADIUS) access accept message.
8 . The method of claim 6 , wherein the intermediate network device inserts the PVD identifier into a second network message and transmits the second network message to the STA.
9 . The method of claim 8 , wherein the second network message comprises a router advertisement (RA).
10 . The method of claim 6 , wherein the intermediate network device comprises at least one of: (i) a wireless local area network (WLAN) controller (WLC) or (ii) a wireless access point (AP).
11 . A system, comprising:
a processor; and
a memory having instructions stored thereon which, when executed on the processor, performs operations comprising:
generating a provisioning domain (PVD) identifier by adding a roaming consortium organization identifier (RCOI), relating to an identity federation comprising an identity provider (IDP), to a domain name of the IDP;
providing PVD configuration information from the IDP to a wireless station (STA) associated with the IDP, using the PVD identifier; and
applying one or more configuration policies at the STA based on the PVD configuration information.
12 . The system of claim 11 , wherein the PVD identifier comprises a uniform resource identifier (URI) comprising at least a portion of the RCOI.
13 . The system of claim 12 , wherein providing the PVD configuration information from the IDP to the STA associated with the IDP, using the PVD identifier comprises:
retrieving the one or more configuration policies at the STA by transmitting a query to the URI.
14 . The system of claim 11 , wherein providing PVD configuration information from the IDP to the STA associated with the IDP, using the PVD identifier, comprises:
transmitting a network message comprising the PVD identifier from the IDP to an intermediate network device between the IDP and STA.
15 . The system of claim 14 , wherein the intermediate network device inserts the PVD identifier into a second network message and transmits the second network message to the STA.
16 . A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processor, performs operations comprising:
generating a provisioning domain (PVD) identifier by adding a roaming consortium organization identifier (RCOI), relating to an identity federation comprising an identity provider (IDP), to a domain name of the IDP;
providing PVD configuration information from the IDP to a wireless station (STA) associated with the IDP, using the PVD identifier; and
applying one or more configuration policies at the STA based on the PVD configuration information.
17 . The non-transitory computer-readable medium of claim 16 , wherein the PVD identifier comprises a uniform resource identifier (URI) comprising at least a portion of the RCOI.
18 . The non-transitory computer-readable medium of claim 17 , wherein providing the PVD configuration information from the IDP to the STA associated with the IDP, using the PVD identifier comprises:
retrieving the one or more configuration policies at the STA by transmitting a query to the URI.
19 . The non-transitory computer-readable medium of claim 16 , wherein providing PVD configuration information from the IDP to the STA associated with the IDP using the PVD identifier, comprises:
transmitting a network message comprising the PVD identifier from the IDP to an intermediate network device between the IDP and STA.
20 . The non-transitory computer-readable medium of claim 19 , wherein the intermediate network device inserts the PVD identifier into a second network message and transmits the second network message to the STA.