Network Access Control Session Detection for Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control systems require users to re-authenticate when accessing web-based resources managed by third-party service providers, leading to increased time consumption, password fatigue, and higher IT infrastructure costs due to multiple authentication sessions.

Innovation Solution

Implementing network access session detection to enable a Network Access Control (NAC) device to provide single sign-on (SSO) functionality by verifying the identity of users with established network access sessions, allowing seamless access to protected resources without re-authentication through security assertions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users access web-based resources managed by third-party service providers through existing network access control systems, then authentication security is maintained, but users must re-authenticate multiple times leading to increased time consumption and password fatigue

Engineering Contradiction:
Improveauthentication securityVSAvoidtime consumption for re-authentication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication through the NAC device before users need to access web-based resources. The NAC device establishes authentication credentials in advance, and these credentials are then reused for accessing third-party web resources without requiring re-authentication. This preliminary action eliminates the need for multiple authentication attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The NAC device acts as an intermediary between the user and third-party web resources. It establishes a trust relationship where the NAC device's authentication credentials are used to access web-based resources on behalf of the user. This intermediary approach allows single sign-on functionality where one authentication at the NAC device grants access to multiple web resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users access multiple web-based resources through third-party service providers, then service versatility is improved, but multiple authentication sessions increase IT infrastructure costs

Engineering Contradiction:
Improveaccess to web-based resourcesVSAvoidIT infrastructure for multiple authentication sessions
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The NAC device provides universal authentication credentials that work across multiple web-based resources from different third-party service providers. Instead of maintaining separate authentication sessions for each resource, the NAC device's credentials serve multiple functions, allowing users to access various web resources with a single authentication. This multi-functionality reduces the need for multiple authentication infrastructure components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10116644B1Network access session detection to provide single-sign on (SSO) functionality for a network access control device
Publication Date: 2018.10.30 PULSE SECURE LLC
  • US10116644B1 patent drawing
  • US10116644B1 patent drawing
  • US10116644B1 patent drawing

AI summary

This disclosure describes techniques for verifying the identity of a user with a network access control (NAC) device in response to receiving a security assertion request for the user. To verify the identity of a user, an NAC device may, in response to receiving a security assertion request from a user agent executing on a client device, cause the user agent to redirect a session verification request to an NAC client executing on the client device. The NAC client may detect the session verification request, and provide information indicative of a valid network access session for the user to the NAC device. The NAC device may verify the identity of the user based on the information indicative of the valid network access session. In this way, an NAC device may verify the identity of a user without requiring the user to re-authenticate with the NAC device.