QUIC Connection ID Policy Encoding for Secure MASQUE Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network solutions, such as VPN tunneling and proxy-based technologies, face limitations in securely connecting remote users to private enterprise applications, particularly with QUIC protocol, and lack mechanisms for tunneling Layer 2 ethernet packets over MASQUE protocols.
Innovation Solution
The QUIC and MASQUE protocols are extended to provide secure access to private enterprise resources by establishing MASQUE tunnels and handling QUIC connection migrations, while enforcing network policies without decrypting or proxying connections, using metadata-encoded connection IDs and EoMASQUE tunnels to transmit Layer 2 ethernet frames.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If VPN tunneling is used to connect remote users to private enterprise applications, then universal protocol compatibility is achieved, but network security is compromised due to large attack surface
Solution Approach 1:
The patent introduces MASQUE proxy nodes as intermediary components that terminate QUIC connections from remote users and establish separate connections to enterprise applications. This mediator architecture allows the system to maintain protocol compatibility while securing the enterprise network, as the proxy nodes act as controlled entry points rather than allowing direct VPN access to internal resources.
Solution Approach 2:
The patent changes the transport protocol parameter from traditional TCP-based VPN to QUIC over UDP. This parameter change enables modern encryption standards and connection migration capabilities while reducing the attack surface through protocol-specific security features inherent in QUIC design.
2Object-affected harmful factors
If proxy-based solutions are used to improve edge controls and reduce attack surface, then network security is improved, but compatibility with non-TCP protocols deteriorates
Solution Approach 1:
The patent implements a universal MASQUE proxy system that can handle multiple protocols including QUIC, HTTP/2, and other applications over QUIC through a single proxy infrastructure. This multi-functional design allows the proxy to maintain security controls while supporting diverse protocols without requiring separate proxy instances for each protocol type.
3Reliability
If QUIC proxy node replacement is implemented to improve system reliability, then fault tolerance is enhanced, but connection continuity deteriorates due to difficulty in handling failover
Solution Approach 1:
The patent implements connection state pre-synchronization and validation mechanisms that prepare for potential proxy node failures before they occur. The system pre-establishes connection states and validates them across multiple proxy nodes, enabling seamless failover when a proxy node fails without interrupting the QUIC connection between the remote user and enterprise application.
4Reliability
If QUIC protocol is used to enable connection migration and improve user experience, then connection resilience is enhanced, but middle box interoperability deteriorates due to version awareness requirements
Solution Approach 1:
The patent positions the MASQUE proxy as an intermediary that handles QUIC connection migration on behalf of traditional middle boxes. The proxy node maintains awareness of connection state changes and manages migration between different QUIC endpoints, shielding version-unaware middle boxes from the complexity of QUIC connection migration while preserving the resilience benefits.
Data Source
AI summary
Techniques for encoding metadata representing a policy into a QUIC connection ID are described herein. A metadata-aware network including one or more enforcement nodes, a policy engine, and/or a connection datastore may be utilized to enforce a policy and route communications on a QUIC connection. The policy engine may be configured to encode metadata representing one or more network policies into a QUIC source connection ID (SCID) and/or may store a mapping between the SCID and a corresponding destination connection ID (DCID) in the connection datastore. The policy engine may communicate with a QUIC application server and/or one or more QUIC proxy nodes to encode the SCID into a QUIC packet. The enforcement nodes may access the metadata and enforce the policies via a connection ID included in a QUIC header of a QUIC packet or by performing a lookup in the connection datastore using the connection ID.


