MASQUE Proxy Access for QUIC Migration and Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network solutions, such as VPN tunneling and proxy-based technologies, face limitations in handling QUIC protocol connections, particularly in managing secure access to private enterprise applications, enforcing network policies, and tunneling Layer 2 ethernet frames, while maintaining a seamless user experience and secure connection migration.

Innovation Solution

The use of QUIC and Multiplexed Application Substrate over QUIC Encryption (MASQUE) protocols to establish secure connections, encode metadata into QUIC connection IDs for policy enforcement, and extend MASQUE to tunnel Layer 2 ethernet frames, enabling seamless connection migration and network policy enforcement without decryption or proxying.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VPN tunneling is used to provide remote access to private applications, then any application and protocol can be supported, but a large attack surface is opened within the network

Engineering Contradiction:
Improveapplication and protocol compatibilityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a reverse proxy as an intermediary component that sits between external users and internal applications. The reverse proxy terminates external connections and opens new internal connections, acting as a mediator that prevents direct access to internal resources. This resolves the contradiction by maintaining application compatibility through protocol support while reducing the attack surface by blocking direct penetration into the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If proxy-based solutions are used to reduce attack surface, then edge controls are improved, but they don't work well with non-TCP protocols and require additional conversion solutions

Engineering Contradiction:
Improveattack surfaceVSAvoidprotocol support
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements a reverse proxy with multi-protocol support that can handle TCP, UDP, and other non-TCP protocols directly. By making the proxy universal in its protocol capabilities, the system maintains reduced attack surface benefits while eliminating the need for additional conversion solutions for different protocol types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of repair

If QUIC proxy node replacement is implemented, then system maintenance is improved, but seamless connection migration becomes difficult due to UDP-based transport

Engineering Contradiction:
Improveproxy node replacementVSAvoidconnection migration seamlessness
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The patent implements connection state pre-synchronization and validation mechanisms before proxy node replacement. The system performs preliminary checks and prepares migration paths in advance, allowing proxy nodes to be replaced while maintaining seamless user experience through pre-established connection continuity protocols.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If QUIC protocol is used to avoid middle box interoperability issues, then connection security is improved, but reliable and predictable middle box processing becomes unavailable

Engineering Contradiction:
Improveconnection securityVSAvoidmiddle box processing reliability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces controlled middle boxes that are specifically designed to work with QUIC protocol. These intermediary components act as QUIC-aware proxies that maintain the security benefits of QUIC while providing reliable and predictable processing capabilities through dedicated middle box implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250350667A1Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)
Publication Date: 2025.11.13 CISCO TECHNOLOGY INC
  • US20250350667A1 patent drawing
  • US20250350667A1 patent drawing
  • US20250350667A1 patent drawing

AI summary

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise/private application resource executing on an application node and hosted in an enterprise/application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.