Cloud Delivered Access via Pre-Authentication Virtual Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network technologies face challenges in providing dynamic and seamless cloud-delivered access, particularly in managing client device authentication and network configuration, which leads to static configurations and inefficient traffic management.

Innovation Solution

The implementation of a system that provides a client device with a pre-authentication virtual network and address, followed by authentication-based movement to a post-authentication virtual network, with traffic translation and dynamic IP address management, utilizing a fabric network architecture with components like Edge Devices, Border Devices, and a Map Server for efficient network management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a client device is provided with a pre-authentication virtual network and pre-authentication address, then the device can immediately connect to the network, but the network configuration remains static and insecure until authentication occurs

Engineering Contradiction:
ImproveNetwork connection speedVSAvoidNetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by providing the client device with a pre-authentication virtual network and pre-authentication address before actual authentication occurs. This allows the device to immediately connect to the network infrastructure while authentication is being processed in the background, resolving the contradiction between immediate connectivity and security verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The pre-authentication virtual network acts as an intermediary environment between the unauthenticated client device and the secure post-authentication network. This intermediary allows traffic flow while maintaining security boundaries, enabling both immediate connection and secure authentication processes to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the client device is moved to a post-authentication virtual network after authentication, then network security is improved, but the network configuration requires dynamic changes

Engineering Contradiction:
ImproveNetwork securityVSAvoidNetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic network configuration by automatically moving the client device from the pre-authentication virtual network to the post-authentication virtual network based on authentication status. This dynamic approach allows the network configuration to adapt to security requirements without manual intervention, improving security while managing complexity through automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system provides feedback about the client device's authentication status to the network configuration system. This feedback mechanism triggers automatic configuration changes, moving the device between virtual networks based on authentication outcomes, thereby improving security through automated responses to authentication events.

Inventive Principle:
Principle #23Feedback

3Reliability

If traffic translation is implemented to translate to a post-authentication address, then network security and control are improved, but the traffic management system becomes more complex

Engineering Contradiction:
ImproveNetwork controlVSAvoidTraffic management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The traffic translation system acts as an intermediary that translates between pre-authentication addresses and post-authentication addresses. This intermediary layer provides network control and security by mediating all traffic flow, while the translation complexity is managed centrally rather than at individual device levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a translated copy of the traffic flow through address translation rather than physically modifying the original traffic path. This copying approach maintains control and security while simplifying the implementation, as the translation can be performed through address mapping tables rather than complex traffic manipulation logic.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If dynamic IP address management is implemented for post-authentication addresses, then network flexibility is improved, but the address management system becomes more complex

Engineering Contradiction:
ImproveNetwork flexibilityVSAvoidAddress management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamic IP address management by automatically assigning and managing post-authentication addresses based on client device authentication and network conditions. This dynamic approach improves network flexibility and adaptability while centralizing the complexity of address management in the network infrastructure rather than requiring complex local device logic.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12095765B2Cloud delivered access
Publication Date: 2024.09.17 CISCO TECHNOLOGY INC
  • US12095765B2 patent drawing
  • US12095765B2 patent drawing
  • US12095765B2 patent drawing

AI summary

Cloud delivered access may be provided. A network device may provide a client device with a pre-authentication virtual network and a pre-authentication address. Next, a policy may be received in response to the client device authenticating. The client device may then be moved to a post-authentication virtual network based on the policy. A post-authentication address may then be obtained for the client device in response to moving the client device to a post-authentication virtual network. Traffic for the client device may then be translated to the post-authentication address.