Identity Provider Service Streamlines VPN Tunnel Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for establishing Virtual Private Network (VPN) tunnels are complex due to the need for multiple interactions between VPN clients, VPN hosts, and authentication and authorization services, which complicates the signaling and messaging processes.
Innovation Solution
The proposed method involves an identity provider service that inter-operates with VPN clients and hosts to provide both user authorization and VPN policies within a single message, allowing the VPN client to retain the client portion of the policy and the VPN host to retain the host portion, thereby simplifying the tunnel establishment process by reducing the need for additional interactions with policy managers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication and authorization services (RADIUS, LDAP, AD, Diameter) are used to handle VPN tunnel establishment, then user authentication and authorization are achieved, but the signaling and messaging processes become complex due to multiple interactions between VPN clients, VPN hosts, and authentication services
Solution Approach 1:
The patent combines authentication and authorization information into a single SAML response message from the identity provider. This merging eliminates the need for separate authentication and policy retrieval interactions, reducing signaling complexity while maintaining reliable user verification and authorization.
Solution Approach 2:
The SAML response message serves multiple functions simultaneously: it authenticates the user, conveys authorization decisions, and delivers VPN policy information to both the VPN client and host. This multi-functionality reduces the number of separate messages and interactions needed in the tunnel establishment process.
2Reliability
If separate interactions with policy managers are used to retrieve VPN policies, then complete policy information is obtained, but the tunnel establishment process requires additional messaging interactions
Solution Approach 1:
The identity provider performs preliminary action by including all necessary VPN policy information in the SAML response message during the authentication phase. This allows the VPN client and host to receive complete policy information without requiring subsequent separate interactions with policy managers, reducing establishment time.
Solution Approach 2:
The patent merges policy information delivery with the authentication response, so that policy retrieval is combined with the authentication process. This eliminates separate policy manager interactions and reduces the overall time required for tunnel establishment while ensuring complete policy information is received.
Data Source
AI summary
An identity provider (IdP) service interoperates with a Virtual Private Network (VPN) client. The IdP service receives a login request originating from the VPN client to establish a VPN tunnel between the VPN client and a VPN host, the login request indicating a user of the VPN client. The IdP service provides a response to the login request. The response includes at least both first information including an indication that the user of the VPN client is an authorized user and second information including an indication of a VPN policy for the VPN tunnel, the VPN policy including a VPN client policy to be utilized during the VPN tunnel by the VPN client and a VPN host policy to be utilized during the VPN tunnel by the VPN host.


