Connection Chain Identifier for Multi-Hop Transport Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In remote access environments, correlating analytical data from multiple intermediary devices is challenging due to the lack of a common identifier for communications between clients and servers, making it difficult to track and troubleshoot connections across multiple transport layer hops.

Innovation Solution

A method and system that set a globally unique identifier (GUID) for packets traversing between clients and servers, allowing subsequent intermediary devices to associate and increment a hop count, ensuring data correlation and tracking across multiple transport layer connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple intermediary devices are used to provide functional services (firewalls, authentication) between client and server, then security and service functionality are improved, but the ability to correlate analytical data and track connection flows across these devices deteriorates due to lack of common identifiers

Engineering Contradiction:
Improvesecurity and service functionalityVSAvoidconnection flow correlation capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary device (analyzer) that acts as a mediator between multiple TCP proxies. This analyzer collects analytics data from each proxy and correlates them using a common identifier (connection chain identifier), enabling centralized tracking and analysis of connection flows across multiple intermediary devices without disrupting their individual functional services

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal identification mechanism (connection chain identifier) that can be used across different types of intermediary devices (TCP proxies, firewalls, authentication gateways). This universal identifier enables any intermediary device in the chain to contribute analytics data that can be correlated by the analyzer, making the system adaptable to various service functions while maintaining correlation capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If each TCP proxy generates and processes analytics data independently, then local analysis capability is improved, but the ability to correlate analytics data across the entire connection chain deteriorates without a common identifier

Engineering Contradiction:
Improvelocal analytics processingVSAvoidconnection-wide analytics correlation
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where each TCP proxy sends its analytics data to a centralized analyzer. The analyzer receives analytics from multiple proxies, correlates them using the connection chain identifier, and provides a comprehensive view of the connection flow. This feedback loop enables both local processing at each proxy and global correlation at the analyzer level

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple intermediary devices traverse connection flows, then service functionality and security are improved, but determining the order of intermediary devices and tracking connection paths becomes more difficult

Engineering Contradiction:
Improveservice functionalityVSAvoidconnection path tracking
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by establishing the connection chain identifier at the beginning of the connection flow. The first TCP proxy in the chain creates this identifier when receiving the initial connection request from the client, and subsequent proxies inherit and use this identifier. This preliminary establishment of the identifier simplifies tracking and determines the order of intermediary devices throughout the connection lifecycle

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10021018B2Systems and methods for associating multiple transport layer hops between clients and servers
Publication Date: 2018.07.10 CITRIX SYSTEMS INC
  • US10021018B2 patent drawing
  • US10021018B2 patent drawing
  • US10021018B2 patent drawing

AI summary

The present disclosure is directed towards systems and methods for associating multiple transport layer hops between a client and a server. A first intermediary device may receive a request for a transport layer connection between the client and the server. The first intermediary device may generate a unique identifier to identify a connection chain between the client and the server across a plurality of transport layer connections via the plurality of devices. The first intermediary device may set a hop count to a number of hops that the first device is between the client and the server. The first intermediary device may forward information about the unique identifier and the hop count to a next device of the plurality of devices.