Implementing service level agreements in an identity federation

US12010559B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12010559-B2
Application numberUS-202318187549-A
CountryUS
Kind codeB2
Filing dateMar 21, 2023
Priority dateOct 29, 2020
Publication dateJun 11, 2024
Grant dateJun 11, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for dynamically negotiating a service legal agreement (SLA) between a roaming device and a visited network (VN) in an identity federation. An identity profile provided to a user device by an identity provider (IDP) is accessed by the user device. The identity profile includes a first SLA criteria. An advertisement from the VN indicating one or more SLAs supported by the VN is received at the user device. The advertisement is received before the user device has associated with the VN. The IDP and the VN are part of a same identity federation. It is determined that the SLA supported by the VN satisfies the first SLA criteria. Upon that determination, an acceptance is transmitted by the user device to the VN, and the user device is associated with the VN.

First claim

Opening claim text (preview).

We claim: 1. A method, comprising: accessing, by a user device, an identity profile provided to the user device by an identity provider (IDP), wherein the identity profile includes a service level agreement (SLA) criterion; receiving, at the user device, an advertisement from a visited network (VN) indicating one or more SLAs supported by the VN, wherein the advertisement is received before the user device has associated with the VN, and wherein the IDP and the VN are part of a same identity federation; and upon determining one of the one or more SLAs supported by the VN satisfies the SLA criterion, associating, by the user device, with the VN. 2. The method of claim 1 , wherein the SLA criterion comprises a minimum bandwidth. 3. The method of claim 2 , wherein the SLA criterion is stored in an identity profile in the user device that was received from the IDP, the identity profile further comprising identity information used by the VN to authenticate the user device with the IDP. 4. The method of claim 3 , wherein the user device associates to the VN only after the VN has authenticated the user device with the IDP based on the identity information. 5. The method of claim 1 , wherein the SLA criterion comprises a maximum latency. 6. The method of claim 1 , further comprising, before associating with the VN: receiving, at the user device, the SLA criterion from the IDP. 7. The method of claim 1 , wherein the VN comprises a Wi-Fi network and the user device is a wireless device. 8. The method of claim 1 , further comprising: upon determining the one or more SLAs supported by the VN does not satisfy the SLA criterion, outputting at least one of a graphical user interface (GUI) or audio message to a user of the user device, the GUI or audio message indicating differences between the SLA criterion and the one or more SLAs supported by the VN; and receiving, after outputting the GUI or audio message, input from the user whether to agree to one of the one or more SLAs supported by the VN in order to associate the user device to the VN. 9. The method of claim 1 , further comprising monitoring, by the user device, compliance of the VN with the SLA criterion. 10. The method of claim 1 , wherein the identity profile further comprises identity information; the method further comprising providing, by the user device, the identity information to the VN for authentication. 11. A non-transitory computer readable medium having program instructions embodied therewith, the program instructions executable by a processor of a user device to perform an operation, the operation comprising: accessing, by the user device, an identity profile provided to the user device by an identity provider (IDP), wherein the identity profile includes a service level agreement (SLA) criterion; receiving, at the user device, an advertisement from a visited network (VN) indicating one or more SLAs supported by the VN, wherein the advertisement is received before the user device has associated with the VN, and wherein the IDP and the VN are part of a same identity federation; and upon determining one of the one or more SLAs supported by the VN satisfies the SLA criterion, associating, by the user device, with the VN. 12. The non-transitory computer readable medium of claim 11 , wherein the SLA criterion comprises a minimum bandwidth. 13. The non-transitory computer readable medium of claim 11 , wherein the SLA criterion comprises a maximum latency. 14. The non-transitory computer readable medium of claim 11 , wherein the operations further comprise, before associating with the VN: receiving, at the user device, the SLA criterion from the IDP. 15. The non-transitory computer readable medium of claim 14 , wherein the SLA criterion is stored in an identity profile in the user device that was received from the IDP, the identity profile further comprising identity information used by the VN to authenticate the user device with the IDP. 16. The non-transitory computer readable medium of claim 15 , wherein the user device associates to the VN only after the VN has authenticated the user device with the IDP based on the identity information. 17. The non-transitory computer readable medium of claim 11 , wherein the VN comprises a Wi-Fi network and the user device is a wireless device. 18. The non-transitory computer readable medium of claim 11 , wherein the operations further comprise: upon determining the one or more SLAs supported by the VN does not satisfy the SLA criterion, outputting at least one of a graphical user interface (GUI) or audio message to a user of the user device, the GUI or audio message indicating differences between the SLA criterion and the one or more SLAs supported by the VN; and receiving, after outputting the GUI or audio message, input from the user whether to agree to one of the one or more SLAs supported by the VN in order to associate the user device to the VN. 19. The non-transitory computer readable medium of claim 11 , wherein the operations further comprise monitoring, by the user device, compliance of the VN with the SLA criterion. 20. The non-transitory computer readable medium of claim 11 , wherein the identity profile further comprises identity information; and wherein the operations further comprise providing, by the user device, the identity information to the VN for authentication.

Assignees

Inventors

Classifications

  • WLAN [Wireless Local Area Networks] · CPC title

  • Authentication · CPC title

  • Processing or transfer of terminal data, e.g. status or physical capabilities · CPC title

  • Identity-dependent · CPC title

  • between location registers or mobility servers · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12010559B2 cover?
Techniques for dynamically negotiating a service legal agreement (SLA) between a roaming device and a visited network (VN) in an identity federation. An identity profile provided to a user device by an identity provider (IDP) is accessed by the user device. The identity profile includes a first SLA criteria. An advertisement from the VN indicating one or more SLAs supported by the VN is receive…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04W28/24. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 11 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).