SPA Key Unification for Multi-Link Cloud Network Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based networks, existing systems struggle to securely connect client devices to cloud networks when they are connected via two different network links with distinct IP addresses, as the Software Defined Perimeter (SDP) controller is unaware of the operational parameters of the second network link, leading to difficulties in instructing the gateway to open the necessary connections.

Innovation Solution

A system that generates a one-time Single Packet Authentication (SPA) key with a predefined expiration time, which is transmitted to the client device and then used to authenticate and open a connection with the gateway via the second network link, using port knocking protocols to unify the data flows and ensure secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a client device connects to the SDP controller and gateway via two different network links with different IP addresses, then network connectivity and flexibility are improved, but the SDP controller becomes unaware of the operational parameters of the second network link, making it difficult to instruct the gateway to open necessary connections

Engineering Contradiction:
Improvenetwork connectivityVSAvoidconnection management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a SPA key as an intermediary authentication mechanism that bridges the SDP controller and gateway. The SDP controller generates the SPA key and transmits it to the gateway, which then uses this key to authenticate and open connections for the client device. This intermediary key system allows the gateway to independently manage connections without requiring the SDP controller to be aware of all network link parameters, thus resolving the contradiction between multi-link connectivity and connection management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication and connection management processes into distinct components: the SDP controller handles authentication by generating SPA keys, while the gateway handles connection establishment using these keys. This segmentation allows each component to operate independently with its own operational parameters, enabling multi-network-link connectivity without requiring the SDP controller to manage all connection details, thereby reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If security measures such as firewalls and anti-malware tools are deployed to monitor and control network traffic, then network security is improved, but the complexity of network infrastructure and traffic management increases

Engineering Contradiction:
Improvenetwork securityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication action by generating and distributing SPA keys before actual network connections are established. The SDP controller generates these authentication keys in advance and transmits them to the gateway, which then uses them to pre-authorize connection requests. This preliminary authentication mechanism allows firewalls and security tools to operate with predefined authorization rules, reducing the need for complex real-time decision-making and simplifying traffic management while maintaining high security standards

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11777718B2Unification of data flows over network links with different internet protocol (IP) addresses
Publication Date: 2023.10.03 CHECK POINT SOFTWARE TECH LTD
  • US11777718B2 patent drawing
  • US11777718B2 patent drawing
  • US11777718B2 patent drawing

AI summary

Provided herein are systems, devices and methods for opening a connection in a gateway of a cloud based network for a client device connected via two different network links to the gateway and to a Software Defined Perimeter (SDP) controller of a cloud based network. The SDP controller may receive a request from a client device to connect to a gateway of the cloud based network, generate a one-time SPA key for the client device (after authenticated), transmit the SPA key to the gateway, and transmit, via the first network link, the SPA key to the client device. The client device may transmit the SPA key to the gateway via the second network link and the gateway may be configured to open a connection for the client device via the second network link in case the SPA key is valid.