Connection Chain Identifier for Multi-Hop Transport Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In remote access environments, correlating analytical data from multiple intermediary devices is challenging due to the lack of a common identifier for communications between clients and servers, making it difficult to track and troubleshoot connections across multiple transport layer hops.
Innovation Solution
A method and system that set a globally unique identifier (GUID) for packets traversing between clients and servers, allowing subsequent intermediary devices to associate and increment a hop count, ensuring data correlation and tracking across multiple transport layer connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple intermediary devices are used to provide functional services (firewalls, authentication) between client and server, then security and service functionality are improved, but the ability to correlate analytical data and track connection flows across these devices deteriorates due to lack of common identifiers
Solution Approach 1:
The patent introduces an intermediary device (analyzer) that acts as a mediator between multiple TCP proxies. This analyzer collects analytics data from each proxy and correlates them using a common identifier (connection chain identifier), enabling centralized tracking and analysis of connection flows across multiple intermediary devices without disrupting their individual functional services
Solution Approach 2:
The patent creates a universal identification mechanism (connection chain identifier) that can be used across different types of intermediary devices (TCP proxies, firewalls, authentication gateways). This universal identifier enables any intermediary device in the chain to contribute analytics data that can be correlated by the analyzer, making the system adaptable to various service functions while maintaining correlation capability
2Productivity
If each TCP proxy generates and processes analytics data independently, then local analysis capability is improved, but the ability to correlate analytics data across the entire connection chain deteriorates without a common identifier
Solution Approach 1:
The patent implements a feedback mechanism where each TCP proxy sends its analytics data to a centralized analyzer. The analyzer receives analytics from multiple proxies, correlates them using the connection chain identifier, and provides a comprehensive view of the connection flow. This feedback loop enables both local processing at each proxy and global correlation at the analyzer level
3Adaptability or versatility
If multiple intermediary devices traverse connection flows, then service functionality and security are improved, but determining the order of intermediary devices and tracking connection paths becomes more difficult
Solution Approach 1:
The patent applies preliminary action by establishing the connection chain identifier at the beginning of the connection flow. The first TCP proxy in the chain creates this identifier when receiving the initial connection request from the client, and subsequent proxies inherit and use this identifier. This preliminary establishment of the identifier simplifies tracking and determines the order of intermediary devices throughout the connection lifecycle
Data Source
AI summary
The present disclosure is directed towards systems and methods for associating multiple transport layer hops between a client and a server. A first intermediary device may receive a request for a transport layer connection between the client and the server. The first intermediary device may generate a unique identifier to identify a connection chain between the client and the server across a plurality of transport layer connections via the plurality of devices. The first intermediary device may set a hop count to a number of hops that the first device is between the client and the server. The first intermediary device may forward information about the unique identifier and the hop count to a next device of the plurality of devices.


