IP Library › Granted Patent US 11,412,375
Granted Patent B2
US 11,412,375 · App. 16/654,514 · Granted Aug 9, 2022

Establishing untrusted non-3GPP sessions without compromising security

Inventors: Anthony Fajri (Pleasanton, CA); Gautam Mohanlal Borkar (Redmond, WA); Solomon Ayyankulankara Kunjan (Milton, CA); Tariq Habibullah (Allen, TX)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/037H04L12/66H04L61/1511H04L61/203H04W12/04H04W76/11
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,412,375
App. No.
16/654,514
Granted
Aug 9, 2022
Kind
B2
Abstract

Systems, methods, and devices are disclosed for establishing sessions over a network. A query can be sent, from a mobile device to an authoritative DNS server, requesting a session over a network. In response to the query, a list of available communication protocol options can be received from the authoritative DNS server. A specific communication protocol can be selected from the list of available communication protocol options, where the specific communication protocol is selected based on one or more performance metrics. A connection with a gateway device can then be initiated using the selected specific communication protocol.

Claims (55)

1. A method for establishing sessions over a network comprising:

sending a query, from a mobile device to an authoritative Domain Name System (DNS) server, requesting a session over a network;

receiving, in response to the query, a list of available communication protocol options from the authoritative DNS server, the list including Quick User Datagram Protocol Internet Connection (QUIC);

selecting QUIC as a specific communication protocol from the list of available communication protocol options, wherein the specific communication protocol is selected based on one or more performance metrics;

based on receiving an IP address of a gateway device from the DNS server, establishing a plurality of multiplexed connections between the mobile device and the gateway device, wherein multiple streams of data reach the mobile device and the gateway device independently; and

sending a message over the plurality of multiplexed connections during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption; and

initiating a connection with the gateway device using the selected specific communication protocol.

2. The method of claim 1 , the method further comprising:

sending the selected specific communication protocol to the authoritative DNS server; and

receiving an IP address of the gateway device in order to initiate the session.

3. The method of claim 1 , further comprising:

based on the connection being initiated, establishing a same session identifier between the gateway device and the mobile device.

4. The method of claim 1 , the method further comprising:

establishing the connection under a first access point, wherein the session associated with the connection is associated with a session identifier; and

when the mobile device migrates from the first access point to a second access point, sending a client hello message that includes the session identifier so that the session remains unbroken independent of a change in IP address of the mobile device.

5. The method of claim 1 , wherein the performance metrics are based on one or more of latency, throughput, number of handshake requests, or reducing overhead during connection setup.

6. The method of claim 1 , further comprising:

sending a message during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption.

7. A system comprising:

one or more processors; and

at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to:

send a query, from a mobile device to an authoritative Domain Name System (DNS) server, requesting a session over a network;

receive, in response to the query, a list of available communication protocol options from the authoritative DNS server, the list including Quick User Datagram Protocol Internet Connection (QUIC);

select QUIC as a specific communication protocol from the list of available communication protocol options, wherein the specific communication protocol is selected based on one or more performance metrics;

based on receiving an IP address of a gateway device from the DNS server, establish a plurality of multiplexed connections between the mobile device and the gateway device, wherein multiple streams of data reach the mobile device and the gateway device independently; and

send a message over the plurality of multiplexed connections during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption; and

initiate a connection with the gateway device using the selected specific communication protocol.

8. The system of claim 7 , the one or more processors further caused to:

send the selected specific communication protocol to the authoritative DNS server; and

receive an IP address of the gateway device in order to initiate the session.

9. The system of claim 7 , the one or more processors further caused to:

based on the connection being initiated, establish a same session identifier between the gateway device and the mobile device.

10. The system of claim 7 , the one or more processors further caused to:

establish the connection under a first access point, wherein the session associated with the connection is associated with a session identifier; and

when the mobile device migrates from the first access point to a second access point, send a client hello message that includes the session identifier so that the session remains unbroken independent of a change in IP address of the mobile device.

11. The system of claim 7 , wherein the performance metrics are based on one or more of latency, throughput, number of handshake requests, or reducing overhead during connection setup.

12. The system of claim 7 , the one or more processors further caused to:

send a message during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption.

13. A non-transitory computer-readable storage medium having stored therein instructions which, when executed by a processor, cause the processor to perform operations comprising:

sending a query, from a mobile device to an authoritative Domain Name System (DNS) server, requesting a session over a network;

receiving, in response to the query, a list of available communication protocol options from the authoritative DNS server, the list including Quick User Datagram Protocol Internet Connection (QUIC);

selecting QUIC as a specific communication protocol from the list of available communication protocol options, wherein the specific communication protocol is selected based on one or more performance metrics;

based on receiving an IP address of a gateway device from the DNS server, establishing a plurality of multiplexed connections between the mobile device and the gateway device, wherein multiple streams of data reach the mobile device and the gateway device independently; and

sending a message over the plurality of multiplexed connections during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption; and

initiating a connection with the gateway device using the selected specific communication protocol.

14. The non-transitory computer-readable storage medium of claim 13 , the processor further caused to perform the operations comprising:

sending the selected specific communication protocol to the authoritative DNS server; and

receiving an IP address of the gateway device in order to initiate the session.

15. The non-transitory computer-readable storage medium of claim 13 , the processor further caused to perform the operations comprising:

based on the connection being initiated, establishing a same session identifier between the gateway device and the mobile device.

16. The non-transitory computer-readable storage medium of claim 13 , the processor further caused to perform the operations comprising:

establishing the connection under a first access point, wherein the session associated with the connection is associated with a session identifier; and

when the mobile device migrates from the first access point to a second access point, sending a client hello message that includes the session identifier so that the session remains unbroken independent of a change in IP address of the mobile device.

17. The non-transitory computer-readable storage medium of claim 13 , the processor further caused to perform the operations comprising:

sending a message during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2019
From: FAJRI, ANTHONY; BORKAR, GAUTAM MOHANLAL; KUNJAN, SOLOMON AYYANKULANKARA; HABIBULLAH, TARIQ
To: CISCO TECHNOLOGY, INC.
Reel/Frame 050735/0230 →
Continuity (1)
Related Publication 20210120403A1 · Apr 22, 2021