IP Library › Granted Patent US 11,743,716
Granted Patent B2
US 11,743,716 · App. 17/817,891 · Granted Aug 29, 2023

Establishing untrusted non-3GPP sessions without compromising security

Inventors: Anthony Fajri (Pleasanton, CA); Gautam Mohanlal Borkar (Redmond, WA); Solomon Ayyankulankara Kunjan (Milton, CA); Tariq Habibullah (Allen, TX)
Assignee: Cisco Technology, Inc.
H04W12/037H04L12/66H04L61/4511H04L61/503H04W12/04H04W76/11
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,716
App. No.
17/817,891
Granted
Aug 29, 2023
Kind
B2
Abstract

Systems, methods, and devices are disclosed for establishing sessions over a network. A query can be sent, from a mobile device to an authoritative DNS server, requesting a session over a network. In response to the query, a list of available communication protocol options can be received from the authoritative DNS server. A specific communication protocol can be selected from the list of available communication protocol options, where the specific communication protocol is selected based on one or more performance metrics. A connection with a gateway device can then be initiated using the selected specific communication protocol.

Claims (61)

1. A method for establishing sessions over a network comprising:

sending a query, from a mobile device to an authoritative Domain Name System (DNS) server, requesting a session over a network;

receiving, in response to the query, a list of available communication protocol options from the authoritative DNS server;

selecting a specific communication protocol from the list of available communication protocol options, wherein the specific communication protocol is selected based on one or more performance metrics;

based on receiving an IP address of a gateway device from the DNS server, establishing a plurality of multiplexed connections between the mobile device and the gateway device, wherein multiple streams of data reach the mobile device and the gateway device independently;

sending a message over the plurality of multiplexed connections during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption; and

initiating a connection with the gateway device using the selected specific communication protocol.

2. The method of claim 1 , the method further comprising:

sending the selected specific communication protocol to the authoritative DNS server; and

receiving an IP address of the gateway device in order to initiate the session.

3. The method of claim 1 , further comprising:

the selecting comprises selecting Quick User Datagram Protocol Internet Communication as the specific communication protocol.

4. The method of claim 1 , further comprising:

based on the connection being initiated, establishing a same session identifier between the gateway device and the mobile device.

5. The method of claim 1 , the method further comprising:

establishing the connection under a first access point, wherein the session associated with the connection is associated with a session identifier; and

when the mobile device migrates from the first access point to a second access point, sending a client hello message that includes the session identifier so that the session remains unbroken independent of a change in IP address of the mobile device.

6. The method of claim 1 , wherein the performance metrics are based on one or more of latency, throughput, number of handshake requests, or reducing overhead during connection setup.

7. The method of claim 1 , further comprising:

sending a message during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption.

8. A system comprising:

one or more processors; and

at least one non-transitory computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

send a query, from a mobile device to an authoritative Domain Name System (DNS) server, requesting a session over a network;

receive, in response to the query, a list of available communication protocol options from the authoritative DNS;

select a specific communication protocol from the list of available communication protocol options, wherein the specific communication protocol is selected based on one or more performance metrics;

based on receiving an IP address of a gateway device from the DNS server, establish a plurality of multiplexed connections between the mobile device and the gateway device, wherein multiple streams of data reach the mobile device and the gateway device independently;

send a message over the plurality of multiplexed connections during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption; and

initiate a connection with the gateway device using the selected specific communication protocol.

9. The system of claim 8 , the operations further comprising:

send the selected specific communication protocol to the authoritative DNS server; and

receive an IP address of the gateway device in order to initiate the session.

10. The system of claim 8 , the operations further comprising:

select Quick User Datagram Protocol Internet Communication as the specific communication protocol.

11. The system of claim 8 , the operations further comprising:

based on the connection being initiated, establish a same session identifier between the gateway device and the mobile device.

12. The system of claim 8 , the operations further comprising:

establish the connection under a first access point, wherein the session associated with the connection is associated with a session identifier; and

when the mobile device migrates from the first access point to a second access point, send a client hello message that includes the session identifier so that the session remains unbroken independent of a change in IP address of the mobile device.

13. The system of claim 8 , wherein the performance metrics are based on one or more of latency, throughput, number of handshake requests, or reducing overhead during connection setup.

14. The system of claim 8 , the operations further comprising:

send a message during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption.

15. A non-transitory computer-readable storage medium having stored therein instructions which, when executed by a processor, cause the processor to perform operations comprising:

sending a query, from a mobile device to an authoritative Domain Name System (DNS) server, requesting a session over a network;

receiving, in response to the query, a list of available communication protocol options from the authoritative DNS server;

selecting a specific communication protocol from the list of available communication protocol options, wherein the specific communication protocol is selected based on one or more performance metrics;

based on receiving an IP address of a gateway device from the DNS server, establishing a plurality of multiplexed connections between the mobile device and the gateway device, wherein multiple streams of data reach the mobile device and the gateway device independently;

sending a message over the plurality of multiplexed connections during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption; and

initiating a connection with the gateway device using the selected specific communication protocol.

16. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

sending the selected specific communication protocol to the authoritative DNS server; and

receiving an IP address of the gateway device in order to initiate the session.

17. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

select Quick User Datagram Protocol Internet Communication as the specific communication protocol.

18. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

based on the connection being initiated, establishing a same session identifier between the gateway device and the mobile device.

19. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

establishing the connection under a first access point, wherein the session associated with the connection is associated with a session identifier; and

when the mobile device migrates from the first access point to a second access point, sending a client hello message that includes the session identifier so that the session remains unbroken independent of a change in IP address of the mobile device.

20. The non-transitory computer-readable storage medium of claim 15 , the operations further comprising:

sending a message during an initial handshake process that includes an exchange of setup keys and supported protocols that enable future packets to use encryption.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2022
From: FAJRI, ANTHONY; BORKAR, GAUTAM MOHANLAL; KUNJAN, SOLOMON AYYANKULANKARA; HABIBULLAH, TARIQ
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060737/0384 →
Continuity (2)
Continuation 16654514 · Oct 16, 2019
Related Publication 20220386114A1 · Dec 1, 2022