VPN Gateway SSO via Tunnel Session Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of web-based resources and applications often face the inconvenience of multiple authentication steps when accessing protected resources through virtual private networks (VPNs) and identity providers, particularly due to the need for re-authentication when accessing SAML-protected resources.

Innovation Solution

A VPN gateway is configured to act as an identity provider, detecting whether a security assertion request is received through an established tunneling session and issuing security assertions without requiring re-authentication, thereby providing single sign-on (SSO) functionality for users with an established tunneling session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN gateway requires re-authentication for SAML-protected resources, then security is maintained, but user convenience and access efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the VPN gateway and identity provider functions into a single entity. The VPN gateway acts as both the tunnel endpoint and the identity provider that issues SAML assertions, eliminating the need for separate authentication to different systems. This consolidation allows the gateway to recognize authenticated users and automatically issue security assertions without requiring re-authentication, thus maintaining security while improving user convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The VPN gateway is designed to perform multiple functions: it serves as both a tunnel endpoint for secure communications and an identity provider for SAML-based authentication. This multi-functionality allows the gateway to handle both VPN tunneling and security assertion issuance, enabling single sign-on capability across different resource types without requiring separate authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication systems are used for VPN and web resources, then security coverage is improved, but authentication complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication systems into a unified gateway that handles both VPN authentication and SAML identity provider functions. This merging reduces authentication complexity by eliminating the need for users to interact with separate authentication systems, while maintaining comprehensive security coverage through the gateway's ability to enforce authentication policies for both tunnel establishment and resource access.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If additional client-side software components are added for SSO detection, then SSO functionality is enabled, but device resource requirements increase

Engineering Contradiction:
ImproveSSO capabilityVSAvoidsoftware resource requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service SSO detection where the VPN gateway itself detects whether it is receiving requests through an established tunnel and automatically determines whether to issue security assertions. This eliminates the need for complex client-side software components to detect tunneling sessions, as the gateway autonomously makes this determination based on the presence of the tunnel, thereby enabling SSO functionality without increasing device resource requirements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8776209B1Tunneling session detection to provide single-sign on (SSO) functionality for a VPN gateway
Publication Date: 2014.07.08 PULSE SECURE LLC
  • US8776209B1 patent drawing
  • US8776209B1 patent drawing
  • US8776209B1 patent drawing

AI summary

A VPN gateway is described that provides single sign-on (SSO) functionality with respect to remote users who have established tunneling sessions with the VPN gateway and who attempt to access a protected resource. The VPN gateway may receive, from a client device, a security assertion request that includes a request for a security assertion to be made by the VPN gateway with respect to a user of a private network associated with the VPN gateway, determine whether the security assertion request was received via a tunneling session established for the user between the client device and the VPN gateway, and issue a security assertion for the user in response to determining that the security assertion request was received via the tunneling session. In this way, a VPN gateway may act as an SSO identity provider for users that have an established tunneling session with the gateway.