IP Library Granted Patent US 12,231,421
Granted Patent B2
US 12,231,421 · App. 18/446,337 · Granted Feb 18, 2025

Wireless LAN (WLAN) public identity federation trust architecture

Inventors: Malcolm Muir Smith (Richardson, TX); Bart Brinckman (Nevele, BE); Mark Grayson (Berkshire, GB); Jerome Henry (Pittsboro, NC); Matthew Stephen MacPherson (Cary, NC)
Assignee: Cisco Technology, Inc.
H04L63/0815H04L63/0807H04L63/102H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,421
App. No.
18/446,337
Granted
Feb 18, 2025
Kind
B2
Abstract

The disclosed technology relates to a process of evaluating any number of different identity providers (IDPs) and their respective set of credentials that are used to authenticate corresponding users to assist with the onboarding of the different IDPs in connection with Wi-Fi identity federations. In particular, the process allows a person's electronic identity and attributes (stored across one or more IDPs) to be determined once using a standard. Once trust has been established for the user, that trust can then be utilized across a number of different systems (e.g., Single-sign on). The same trust determination can be used without the need for the authenticity of the user identity to be re-evaluated with each new access request.

Claims (46)

1. A method for automatically authenticating a user device on a network, the method comprising:

receiving a request from the user device to access the network via an access point;

determining an identity provider associated with the user device;

retrieving, from the identity provider, respective strength ratings of a plurality of authentication methods accepted by the access point and each authentication method of the plurality of authentication methods have respective strength ratings;

evaluating a credential strength of the user device based on a strength rating of one or more authentication methods of the plurality of authentication methods used by the user device; and

providing the user device access to the network based on the credential strength of the user device satisfying a pre-determined threshold.

2. The method of claim 1 , wherein the evaluating of the credential strength of the user device further comprising:

identifying a plurality of alternative authentication methods, wherein each alternative authentication method is assigned a pre-determined weight;

requesting additional information relating to one or more of the plurality of alternative authentication methods when an initial evaluation does not satisfy the pre-determined threshold; and

evaluating the credential strength of the user device based on the requested additional information across two or more different identity providers associated with the user device.

3. The method of claim 1 , wherein the credential strength assigned to the user device is used by the user device to access the network via different access points without the need to re-evaluate the credential strength of the user device.

4. The method of claim 1 , wherein the identity provider uses one or more of user name/password, authorization token, device certificate, or SIM to authenticate the user device.

5. The method of claim 1 , wherein the identity provider uses one or more of email, mobile phone, government identification, physical identification, local verification, or biometrics to authenticate the user device.

6. The method of claim 1 , wherein the credential strength of the user device decays after a pre-determined period of time based on decay weights.

7. The method of claim 1 , wherein an identity federation generates the respective strength ratings associated with each of the plurality of authentication methods.

8. A non-transitory computer-readable medium comprising instructions for automatically authenticating a user device on a network, the instructions, when executed by a computing system, cause the computing system to:

receive a request from the user device to access the network via an access point;

determine an identity provider associated with the user device;

retrieve, from the identity provider, respective strength ratings of a plurality of authentication methods accepted by the access point and each authentication method of the plurality of authentication methods have respective strength ratings;

evaluate a credential strength of the user device based on a strength rating of one or more authentication methods of the plurality of authentication methods used by the user device; and

provide the user device access to the network based on the credential strength of the user device satisfying a pre-determined threshold.

9. The non-transitory computer-readable medium of claim 8 , wherein the evaluating of the credential strength of the user device further comprising instructions, which when executed by the computing system, cause the computing system to:

identify a plurality of alternative authentication methods, wherein each alternative authentication method is assigned a pre-determined weight;

request additional information relating to one or more of the plurality of alternative authentication methods when an initial evaluation does not satisfy the pre-determined threshold; and

evaluate the credential strength of the user device based on the requested additional information across two or more different identity providers associated with the user device.

10. The non-transitory computer-readable medium of claim 8 , wherein the credential strength assigned to the user device is used by the user device to access the network via different access points without the need to re-evaluate the credential strength of the user device.

11. The non-transitory computer-readable medium of claim 8 , wherein the identity provider uses one or more of user name/password, authorization token, device certificate, or SIM to authenticate the user device.

12. The non-transitory computer-readable medium of claim 8 , wherein the identity provider uses one or more of email, mobile phone, government identification, physical identification, local verification, or biometrics to authenticate the user device.

13. The non-transitory computer-readable medium of claim 8 , wherein the credential strength of the user device decays after a pre-determined period of time based on decay weights.

14. A system for automatically authenticating a user device on a network, the system comprising:

at least one processor; and

a non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the system to:

receive a request from the user device to access the network via an access point;

determine an identity provider associated with the user device;

retrieve, from the identity provider, respective strength ratings of a plurality of authentication methods accepted by the access point and each authentication method of the plurality of authentication methods have respective strength ratings;

evaluate a credential strength of the user device based on a strength rating of one or more authentication methods of the plurality of authentication methods used by the user device; and

provide the user device access to the network based on the credential strength of the user device satisfying a pre-determined threshold.

15. The system of claim 14 , wherein the evaluating of the credential strength of the user device further comprising instructions, which when executed by the at least one processor, causes the system to:

identify a plurality of alternative authentication methods, wherein each alternative authentication method is assigned a pre-determined weight;

request additional information relating to one or more of the plurality of alternative authentication methods when an initial evaluation does not satisfy the pre-determined threshold; and

evaluate the credential strength of the user device based on the requested additional information across two or more different identity providers associated with the user device.

16. The system of claim 14 , wherein the credential strength assigned to the user device is used by the user device to access the network via different access points without the need to re-evaluate the credential strength of the user device.

17. The system of claim 14 , wherein the identity provider uses one or more of user name/password, authorization token, device certificate, or SIM to authenticate the user device.

18. The system of claim 14 , wherein the identity provider uses one or more of email, mobile phone, government identification, physical identification, local verification, or biometrics to authenticate the user device.

19. The system of claim 14 , wherein the credential strength of the user device decays after a pre-determined period of time based on decay weights.

20. The system of claim 14 , wherein an identity federation generates the respective strength ratings associated with each of the plurality of authentication methods.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2023
From: SMITH, MALCOLM MUIR; BRINCKMAN, BART; GRAYSON, MARK; HENRY, JEROME; MACPHERSON, MATTHEW STEPHEN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064528/0241 →
Continuity (3)
Continuation 17571297 · Jan 7, 2022
Continuation 16742576 · Jan 14, 2020
Related Publication 20230388288A1 · Nov 30, 2023
References Cited (35)
US 8412931B2 · Vedula et al. · 2013 [cited by applicant]
US 8761051B2 · Brisebois et al. · 2014 [cited by applicant]
US 9485248B2 · Schmoyer et al. · 2016 [cited by applicant]
US 9836595B1 · Goldberg et al. · 2017 [cited by applicant]
US 9923927B1 · McClintock et al. · 2018 [cited by applicant]
US 10038692B2 · Choyi et al. · 2018 [cited by applicant]
US 10057247B2 · Jakobsson · 2018 [cited by applicant]
US 10091188B2 · Xiao et al. · 2018 [cited by applicant]
US 11258779B2 · Smith · 2022 [cited by examiner]
US 11765153B2 · Smith · 2023 [cited by examiner]
US 20060053296A1 · Busboom · 2006 [cited by examiner]
US 20070174454A1 · Mitchell et al. · 2007 [cited by applicant]
US 20120179905A1 · Ackerly · 2012 [cited by examiner]
US 20130007868A1 · Hoggan · 2013 [cited by examiner]
US 20130125226A1 · Shah · 2013 [cited by examiner]
US 20130311771A1 · Hoggan · 2013 [cited by examiner]
US 20150264020A1 · Ackerly · 2015 [cited by examiner]
US 20150264051A1 · Hoggan · 2015 [cited by applicant]
US 20160087957A1 · Shah et al. · 2016 [cited by applicant]
US 20170324750A1 · Khan · 2017 [cited by examiner]
US 20170366970A1 · Yu · 2017 [cited by applicant]
US 20180060562A1 · Waltermann et al. · 2018 [cited by applicant]
US 20190007406A1 · Choyi · 2019 [cited by examiner]
US 20190074982A1 · Hughes · 2019 [cited by applicant]
US 20190132326A1 · Spradlin · 2019 [cited by applicant]
US 20190228178A1 · Sharma · 2019 [cited by examiner]
US 20200021440A1 · Maniyar · 2020 [cited by applicant]
US 20200163013A1 · Grayson · 2020 [cited by examiner]
US 20200195436A1 · Khan · 2020 [cited by applicant]
US 20200380115A1 · Knight et al. · 2020 [cited by applicant]
US 20210194883A1 · Badhwar · 2021 [cited by examiner]
EP 2194482A1 · 2010 [cited by applicant]
WO 2014011997A1 · 2014 [cited by applicant]
WO 2014176539A1 · 2014 [cited by applicant]
International Search Report and Written Opinion from the International Searching Authority, dated Apr. 20, 2021, 10 pages, for corresponding International Patent Application No. PCT/US2021/013040. [cited by applicant]