Unified VPN Identity Authentication for Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies face challenges in securely authenticating users to cloud-based services, especially when access is requested from devices not connected to a VPN, as they lack a mechanism to leverage VPN security for user identity establishment across non-VPN devices.

Innovation Solution

The solution involves using VPN-based authentication mechanisms, such as SAML or OAuth, to authenticate users by redirecting access requests through a security proxy, where a certificate-based connection is established, and an identity provider generates an assertion to authenticate the user, even if the device is not connected to the VPN, using techniques like push notifications or inline authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN-based authentication is used to secure access to cloud services, then security and trust are improved, but devices not connected to VPN cannot access cloud services

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess from non-VPN devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an identity provider as an intermediary component that bridges VPN-based authentication and cloud service access. The identity provider receives authentication requests from non-VPN devices, verifies user identity through VPN-based credentials, and issues identity indicators that enable access to cloud services. This mediator allows secure authentication to be extended beyond the VPN network boundary without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the authentication system universal by enabling the same VPN-based authentication mechanism to serve both VPN-connected and non-VPN devices. The identity provider acts as a universal authentication endpoint that handles requests from any device, regardless of VPN connection status, while maintaining the security guarantees of VPN-based authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual password authentication is required for each cloud service, then service-specific security control is improved, but user convenience and productivity deteriorate

Engineering Contradiction:
Improveservice-specific securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authentication operations into a single unified authentication process. Instead of requiring separate password entries for each cloud service, the system combines authentication across multiple services through the identity provider, which issues a single identity indicator that grants access to multiple cloud services. This reduces the number of authentication interactions from multiple to one.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity indicator issued by the identity provider serves multiple functions: it authenticates the user to the cloud service, provides service-specific security control, and enables access across multiple cloud services simultaneously. This universal credential replaces the need for service-specific passwords while maintaining security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If VPN connection is required for cloud service access, then network security is improved, but accessibility and mobility are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The identity provider serves as an intermediary that decouples cloud service access from direct VPN connection requirements. It maintains network security by validating user identity through VPN-based credentials, then enables access from non-VPN devices by issuing identity indicators. This mediator layer preserves security while extending accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process from the network connection requirement. Instead of requiring the entire access path to be within the VPN network, the system separates identity verification (performed through VPN-based credentials) from service access (enabled from any device). This segmentation allows security and accessibility to be independently optimized.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3455762B1Unified VPN and identity based authentication to cloud-based services
Publication Date: 2022.04.06 MOBILEIRON INC
  • EP3455762B1 patent drawingFigure 1
  • EP3455762B1 patent drawingFigure 2
  • EP3455762B1 patent drawingFigure 3

AI summary

Techniques are disclosed to provide VPN and identity based authentication to cloud-based services. In various embodiments, a request to authenticate a user to a service is received. A user identity associated with one or both of the user and the request is determined based at least in part on data comprising the request. An identity assertion is generated based at least in part on the user identity. The identity assertion is provided to a requesting node with which the request to authenticate is associated.