Dynamic User Authentication for Location-Aware Traffic Steering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication session technologies lack dynamicity in initiation, termination, and session management, particularly in combining location detection and enterprise-directed flow detection, and do not support session memory capabilities or multiple authentication methods, leading to inefficient resource usage and limited user experience.

Innovation Solution

Implementing techniques that combine trusted network detection with IP and DNS flow detection, decouple authentication from session establishment, and utilize session-memory capabilities to dynamically manage secure communication sessions based on device location and enterprise-directed flows, allowing for seamless and efficient session management through token-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If secure communication sessions are initiated based on pre-defined rules, then session initiation automation is improved, but session dynamicity and adaptability deteriorate

Engineering Contradiction:
Improvesession initiation automationVSAvoidsession dynamicity
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic session management by transitioning from static pre-defined rules to real-time condition-based decision making. The system continuously monitors device location, network conditions, and user activity to dynamically initiate, pause, or terminate secure sessions. This allows the session state to adapt flexibly to changing conditions while maintaining automated operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs feedback mechanisms by continuously monitoring session conditions (location, network state, user activity) and using this information to adjust session behavior in real-time. The monitoring component provides ongoing feedback about session validity and appropriateness, enabling the system to respond dynamically to changing conditions while maintaining automated control.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple authentication methods are implemented, then user experience and flexibility are improved, but system complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that supports multiple authentication methods (biometric, token-based, certificate-based) through a single unified system architecture. This multi-functional approach allows the same authentication component to handle various authentication types, reducing overall system complexity while maintaining flexibility and user choice.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages authentication method complexity by dynamically selecting and switching between different authentication parameters based on session context, user preferences, and security requirements. This allows the system to present only the relevant authentication options for each situation, reducing perceived complexity while maintaining versatile authentication capabilities.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If session memory capabilities are added, then session resumption efficiency is improved, but resource consumption increases

Engineering Contradiction:
Improvesession resumption efficiencyVSAvoidresource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent implements selective session memory storage by maintaining detailed session state information only for actively used or recently accessed sessions, while using summarized or cached information for less critical sessions. This local quality approach ensures high resumption efficiency for important sessions while minimizing overall memory resource consumption across the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system manages session memory resources by implementing automatic session state expiration and cleanup mechanisms. Session memory is retained and recovered only when needed for resumption, while expired or inactive session data is automatically discarded. This allows efficient session resumption when required while preventing unbounded resource consumption over time.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS12407677B2Dynamic user authentication and traffic steering
Publication Date: 2025.09.02 CISCO TECHNOLOGY INC
  • US12407677B2 patent drawing
  • US12407677B2 patent drawing
  • US12407677B2 patent drawing

AI summary

Techniques for dynamically establishing, pausing, and/or terminating secure communication sessions. The techniques may include, detecting an occurrence of an authentication trigger event on a computing device and causing a user of the computing device to be authenticated for access to a resource that is to be accessed via a secure communication session. Based at least in part on authenticating the user for access to the resource, a token may be stored in a location that is accessible to a headend appliance associated with the secure communication session. The token may indicate that the user of the computing device is authenticated for access to the resource. In this way, at least partially responsive to detecting an occurrence of a networking trigger event, the secure communication session may be established between the computing device and the headend appliance to provide the computing device with access to the resource.