Secure Session Steering With Decoupled Authentication Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication session technologies lack dynamicity in initiation, termination, and session management, particularly in combining location detection and enterprise-directed flow detection, and do not support session memory capabilities or multiple authentication methods, leading to inefficient resource usage and limited user experience.

Innovation Solution

Implementing trusted network detection with IP and DNS flow detection, decoupling authentication from session establishment, and using session-memory capabilities to dynamically manage secure communication sessions based on device location and enterprise-directed flows, allowing for seamless transitions between active and standby states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure communication sessions are continuously maintained to ensure availability, then service reliability is improved, but resource consumption increases

Engineering Contradiction:
Improveservice availabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic session management where secure communication sessions are automatically established, paused, or terminated based on real-time detection of user authentication events and network traffic patterns. This dynamic approach allows the system to maintain service availability when needed while conserving resources during periods of inactivity, resolving the contradiction between reliability and resource consumption.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication and session preparation in advance based on detected authentication events (such as user login). By pre-establishing authentication tokens and session parameters before actual data transmission begins, the system ensures rapid session activation when needed while avoiding continuous resource consumption, thus balancing reliability with resource efficiency.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If authentication is tightly coupled with session establishment to simplify management, then device complexity is reduced, but adaptability decreases

Engineering Contradiction:
Improvesession management complexityVSAvoidauthentication method flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication process from session establishment by introducing independent authentication event detection and session management components. This segmentation allows the system to support multiple authentication methods (various principles) while maintaining simplified session management through standardized session establishment procedures, thus reducing device complexity while increasing adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication token mechanism that decouples authentication from session establishment. The authentication token serves as an intermediary that validates user credentials independently, then enables session establishment without tight coupling. This intermediary approach allows flexible authentication methods while maintaining simple session management logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If session memory capabilities are added to track user authentication and traffic patterns, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvesession management flexibilityVSAvoidsession tracking complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service session management where the system automatically detects authentication events, tracks network traffic patterns, and makes decisions about session establishment and termination without complex external control. This self-service approach provides adaptive session management based on observed patterns while avoiding the complexity of manual configuration and management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs feedback mechanisms by continuously monitoring authentication events and network traffic patterns, then using this information to dynamically adjust session management decisions. This feedback-driven approach enables adaptive session tracking and management while keeping the system relatively simple through rule-based automated responses to observed patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250392586A1Dynamic user authentication and traffic steering
Publication Date: 2025.12.25 CISCO TECHNOLOGY INC
  • US20250392586A1 patent drawing
  • US20250392586A1 patent drawing
  • US20250392586A1 patent drawing

AI summary

Techniques for dynamically establishing, pausing, and/or terminating secure communication sessions. The techniques may include, detecting an occurrence of an authentication trigger event on a computing device and causing a user of the computing device to be authenticated for access to a resource that is to be accessed via a secure communication session. Based at least in part on authenticating the user for access to the resource, a token may be stored in a location that is accessible to a headend appliance associated with the secure communication session. The token may indicate that the user of the computing device is authenticated for access to the resource. In this way, at least partially responsive to detecting an occurrence of a networking trigger event, the secure communication session may be established between the computing device and the headend appliance to provide the computing device with access to the resource.