Proxy Auth Binding for Unified QUIC Session Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing proxy protocols, such as QUIC, often require separate authentication and authorization for each application instance, leading to a fragmented user experience and increased security vulnerabilities due to the lack of seamless session handling and interoperability with middle boxes.
Innovation Solution
A method to combine independent sessions from a single device into a single logical session using a proxy service, sharing a single authentication/authorization token through cryptographic binding, enabling unified access across multiple applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication is required for each application instance, then security control is improved, but user experience and system efficiency deteriorate due to repeated authentication
Solution Approach 1:
The patent combines multiple independent application sessions from a single device into a unified logical session at the proxy server. The proxy server aggregates session identifiers from different applications and binds them to a single authentication token, allowing users to authenticate once and access multiple applications without repeated authentication prompts.
Solution Approach 2:
The patent creates a universal authentication mechanism that works across multiple applications and protocols. The proxy server establishes a single logical session that can handle various inner protocols (QUIC, TCP, UDP) while maintaining a unified authentication approach, making the system multi-functional rather than application-specific.
2Reliability
If separate authentication is required for each application instance, then security granularity is improved, but system productivity deteriorates due to increased authentication overhead
Solution Approach 1:
The patent merges the authentication processing for multiple applications into a single operation at the proxy server. By combining session identifiers and creating one logical session, the system eliminates redundant authentication requests and token validations, significantly reducing processing overhead and improving system productivity.
Solution Approach 2:
The patent performs preliminary authentication at the proxy server level before traffic is routed to individual applications. The single logical session is established upfront, and subsequent application requests within the same device context automatically inherit the authenticated state, eliminating the need for repeated authentication actions.
3Speed
If QUIC protocol is used for better performance, then speed is improved, but compatibility with middle boxes deteriorates due to version awareness requirements
Solution Approach 1:
The patent introduces a proxy server as an intermediary between QUIC clients and backend services. The proxy server acts as a version-aware middle box that understands QUIC protocol semantics while providing translation and adaptation layers for backend systems. This mediator approach enables QUIC performance benefits while maintaining compatibility with traditional TCP/UDP-based backend infrastructure.
Solution Approach 2:
The patent creates a universal proxy architecture that can handle multiple protocols (QUIC, TCP, UDP) through a single interface. The proxy server is designed to be protocol-agnostic at the backend interface while supporting protocol-specific optimizations at the client interface, making the system adaptable to different protocol requirements without sacrificing performance.
4Ease of operation
If proxy nodes terminate connections and open new connections, then edge control is improved, but session continuity deteriorates due to connection breaking
Solution Approach 1:
The patent merges multiple connection sessions into a single logical session at the proxy server. By aggregating session identifiers from different connections and binding them to a unified authentication context, the system maintains session continuity even when individual connections are terminated and restarted, as the logical session persists across connection boundaries.
Solution Approach 2:
The patent establishes a buffer layer at the proxy server that decouples client connections from backend sessions. The proxy server maintains a mapping between client connection identifiers and backend session identifiers, allowing it to handle connection terminations and restarts without disrupting the logical session state, thus cushioning against session continuity issues.
Data Source
AI summary
Techniques for combining independent sessions between application(s) and a VPN, proxy service, or similar system, including inner protocol sessions (e.g., such as QUIC, etc.), coming from a single device to form a single logical session, where the single logical session could share a single authentication/authorization token are described. The techniques include receiving, from a device within a network, a request for a first application to access a service associated with the proxy service or the VPN, sending, to the device, a first authentication request, and receiving, from the device, a message including a token. The techniques may further include authenticating, by the proxy service or the VPN, the token using a unique identifier associated with the device and enabling, by the proxy service or the VPN, the device to access the service via a first session flow.


