Identity Provider Service Streamlines VPN Tunnel Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for establishing Virtual Private Network (VPN) tunnels are complex due to the need for multiple interactions between VPN clients, VPN hosts, and authentication and authorization services, which complicates the signaling and messaging processes.

Innovation Solution

The proposed method involves an identity provider service that inter-operates with VPN clients and hosts to provide both user authorization and VPN policies within a single message, allowing the VPN client to retain the client portion of the policy and the VPN host to retain the host portion, thereby simplifying the tunnel establishment process by reducing the need for additional interactions with policy managers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and authorization services (RADIUS, LDAP, AD, Diameter) are used to handle VPN tunnel establishment, then user authentication and authorization are achieved, but the signaling and messaging processes become complex due to multiple interactions between VPN clients, VPN hosts, and authentication services

Engineering Contradiction:
Improveauthentication and authorizationVSAvoidsignaling and messaging complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines authentication and authorization information into a single SAML response message from the identity provider. This merging eliminates the need for separate authentication and policy retrieval interactions, reducing signaling complexity while maintaining reliable user verification and authorization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SAML response message serves multiple functions simultaneously: it authenticates the user, conveys authorization decisions, and delivers VPN policy information to both the VPN client and host. This multi-functionality reduces the number of separate messages and interactions needed in the tunnel establishment process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate interactions with policy managers are used to retrieve VPN policies, then complete policy information is obtained, but the tunnel establishment process requires additional messaging interactions

Engineering Contradiction:
Improvepolicy information completenessVSAvoidtunnel establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The identity provider performs preliminary action by including all necessary VPN policy information in the SAML response message during the authentication phase. This allows the VPN client and host to receive complete policy information without requiring subsequent separate interactions with policy managers, reducing establishment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges policy information delivery with the authentication response, so that policy retrieval is combined with the authentication process. This eliminates separate policy manager interactions and reduces the overall time required for tunnel establishment while ensuring complete policy information is received.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11425098B2Streamlined authentication and authorization for virtual private network tunnel establishment
Publication Date: 2022.08.23 CISCO TECHNOLOGY INC
  • US11425098B2 patent drawing
  • US11425098B2 patent drawing
  • US11425098B2 patent drawing

AI summary

An identity provider (IdP) service interoperates with a Virtual Private Network (VPN) client. The IdP service receives a login request originating from the VPN client to establish a VPN tunnel between the VPN client and a VPN host, the login request indicating a user of the VPN client. The IdP service provides a response to the login request. The response includes at least both first information including an indication that the user of the VPN client is an authorized user and second information including an indication of a VPN policy for the VPN tunnel, the VPN policy including a VPN client policy to be utilized during the VPN tunnel by the VPN client and a VPN host policy to be utilized during the VPN tunnel by the VPN host.