SPA Key Unification for Multi-Link Cloud Network Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud-based networks, existing systems struggle to securely connect client devices to cloud networks when they are connected via two different network links with distinct IP addresses, as the Software Defined Perimeter (SDP) controller is unaware of the operational parameters of the second network link, leading to difficulties in instructing the gateway to open the necessary connections.
Innovation Solution
A system that generates a one-time Single Packet Authentication (SPA) key with a predefined expiration time, which is transmitted to the client device and then used to authenticate and open a connection with the gateway via the second network link, using port knocking protocols to unify the data flows and ensure secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a client device connects to the SDP controller and gateway via two different network links with different IP addresses, then network connectivity and flexibility are improved, but the SDP controller becomes unaware of the operational parameters of the second network link, making it difficult to instruct the gateway to open necessary connections
Solution Approach 1:
The patent introduces a SPA key as an intermediary authentication mechanism that bridges the SDP controller and gateway. The SDP controller generates the SPA key and transmits it to the gateway, which then uses this key to authenticate and open connections for the client device. This intermediary key system allows the gateway to independently manage connections without requiring the SDP controller to be aware of all network link parameters, thus resolving the contradiction between multi-link connectivity and connection management complexity
Solution Approach 2:
The patent segments the authentication and connection management processes into distinct components: the SDP controller handles authentication by generating SPA keys, while the gateway handles connection establishment using these keys. This segmentation allows each component to operate independently with its own operational parameters, enabling multi-network-link connectivity without requiring the SDP controller to manage all connection details, thereby reducing overall system complexity
2Reliability
If security measures such as firewalls and anti-malware tools are deployed to monitor and control network traffic, then network security is improved, but the complexity of network infrastructure and traffic management increases
Solution Approach 1:
The patent implements preliminary authentication action by generating and distributing SPA keys before actual network connections are established. The SDP controller generates these authentication keys in advance and transmits them to the gateway, which then uses them to pre-authorize connection requests. This preliminary authentication mechanism allows firewalls and security tools to operate with predefined authorization rules, reducing the need for complex real-time decision-making and simplifying traffic management while maintaining high security standards
Data Source
AI summary
Provided herein are systems, devices and methods for opening a connection in a gateway of a cloud based network for a client device connected via two different network links to the gateway and to a Software Defined Perimeter (SDP) controller of a cloud based network. The SDP controller may receive a request from a client device to connect to a gateway of the cloud based network, generate a one-time SPA key for the client device (after authenticated), transmit the SPA key to the gateway, and transmit, via the first network link, the SPA key to the client device. The client device may transmit the SPA key to the gateway via the second network link and the gateway may be configured to open a connection for the client device via the second network link in case the SPA key is valid.


