Certificate-Based Authentication for Roaming Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network processing services face challenges in providing secure and transparent access to managed network services for roaming users, particularly when they have dynamically assigned IP addresses, leading to security vulnerabilities and cumbersome access methods.

Innovation Solution

A system that uses certificate-based client authentication and automated location-dependent service routing to establish secure connections between roaming computers and managed network services over shared public networks, eliminating the need for traditional VPNs and ensuring secure, transparent access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP lockdown authentication is used for managed network services, then security is improved and transparency is maintained for users with static IP addresses, but roaming users with dynamically assigned IP addresses cannot access the service

Engineering Contradiction:
Improveauthentication securityVSAvoidaccessibility for roaming users
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the authentication parameter from static IP address to dynamic parameters including certificate-based authentication, user credentials, and location information. This allows the system to authenticate users regardless of their IP address, enabling both static and dynamic IP users including roaming users to access the managed network service securely

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic authentication mechanisms that adapt to different user scenarios. The system dynamically adjusts authentication requirements based on user identity, location, and device information, allowing seamless access for roaming users while maintaining security through certificate-based authentication and automated routing

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If VPN is used to provide access to managed network services for roaming users, then accessibility is improved, but system complexity increases and security vulnerabilities arise

Engineering Contradiction:
Improveaccessibility for roaming usersVSAvoidVPN infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and secure connection functionality from the VPN infrastructure and integrates it directly into the managed network service architecture. By using certificate-based authentication and establishing direct secure connections between client agents and service providers, the system eliminates the need for complex VPN setups while maintaining security and accessibility for roaming users

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces client agents as intermediaries that facilitate secure connections between roaming users and managed network services. These agents handle authentication, establish secure channels, and manage communication without requiring full VPN infrastructure, thereby reducing system complexity while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If simple username and password authentication is used, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple authentication factors including certificate-based authentication, user credentials, device information, and location data into a unified authentication mechanism. This combination maintains security through cryptographic certificates while improving ease of operation by automating the authentication process and transparently verifying user identity across multiple parameters

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If managed network services are hosted locally within corporate network, then security and control are improved, but installation and maintenance costs increase

Engineering Contradiction:
Improveservice controlVSAvoidinstallation and maintenance cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal managed network service architecture that can be deployed remotely while serving multiple functions including authentication, secure communication, and service delivery. The service provider infrastructure can serve multiple clients through the public network, reducing per-client installation and maintenance costs while maintaining security through centralized certificate-based authentication and controlled access

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8898315B2Remote access to resources
Publication Date: 2014.11.25 CISCO TECHNOLOGY INC
  • US8898315B2 patent drawing
  • US8898315B2 patent drawing
  • US8898315B2 patent drawing

AI summary

The invention provides systems and for securely transmitting data between a roaming computer and a managed network service over a shared public network. A secure connection is created between the roaming computer and a server computer that hosts or acts as a secure gateway to the managed network service. The connection is set up and established by a client agent installed on the roaming computer and a connection component of the managed service on the server computer. The client agent and the connection component of the managed service operate, on an initial request from the roaming computer to the managed service to negotiate the secure connection using certificate-based client authentication. The client certificate preferably includes user-specific attributes that can be extracted by the connection component and made available to the managed service to apply processing rules specific to the user.