SSO Server Plain Text Session for TLS Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transport Layer Security (TLS) encryption makes it difficult for network elements to determine flow characteristics of user sessions, hindering the application of policy decisions such as access control and priority management.
Innovation Solution
A Single Sign On (SSO) server, like an Identity Provider (IdP) server, validates user and device credentials, determines user attributes, and provides network controls like Quality of Service (QoS) and path selection, enabling network access devices to enforce policies on encrypted TLS sessions by redirecting the session to a plain text format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TLS encryption is applied to secure communication between client endpoint and application provider server, then security and privacy of communication are improved, but network elements cannot determine flow characteristics to apply policy decisions
Solution Approach 1:
The patent applies preliminary action by establishing a plain text user session before the TLS encrypted session. Network controls including flow characteristics, quality of service parameters, and policy decisions are determined and injected into the plain text session in advance. This allows network elements to inspect and control traffic characteristics before encryption occurs, resolving the contradiction between security and flow detection capability.
2Reliability
If TLS encryption is applied to secure communication, then communication privacy is improved, but network controls cannot be enforced on the encrypted traffic
Solution Approach 1:
The system performs preliminary authentication and policy enforcement actions before TLS encryption is established. User credentials are validated, user attributes are determined, and network controls are established in the plain text session phase. This preliminary action enables policy enforcement while maintaining encryption for the actual data transmission.
Solution Approach 2:
The patent introduces an intermediary plain text user session between the client endpoint and application provider server. This intermediary session allows network elements to inject network controls and enforce policies without interfering with the encrypted communication channels. The plain text session acts as a mediator that enables control while preserving the security of the encrypted sessions.
3Ease of operation
If plain text user session is established to enable network controls, then policy enforcement capability is improved, but session security may be reduced compared to fully encrypted TLS session
Solution Approach 1:
The patent segments the communication session into two distinct parts: a plain text user session for control plane operations and policy enforcement, and TLS encrypted sessions for data plane communication. This segmentation allows each part to serve its specific function optimally - the plain text session enables easy policy enforcement while the encrypted sessions maintain security for actual data transmission.
Solution Approach 2:
The system applies different security qualities to different parts of the communication flow. The control plane (plain text user session) uses lower security requirements to enable easy policy enforcement, while the data plane (TLS encrypted sessions) uses high security requirements. This local quality differentiation resolves the contradiction by allowing plain text where needed for control while maintaining encryption where needed for security.
Data Source
AI summary
Network controls for application access secured by transport layer security (TLS) using single sign on (SSO) flow may be provided. An application access request for authenticating a user may be received in response to the user requesting an access to an application. User credentials associated with the user may be validated. In response to validating the user credentials, user attributes associated with the user may be determined. Network controls for a user session associated with the application access request may be determined based on the user attributes. The application access request may be redirected to a plain text user session. The plain text user session may comprise the network controls for the user session.


