Gateway Authentication Proxy for Channel Latency Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual workspace systems face inefficiencies in establishing communication channels between client and server devices due to separate phases for authentication and capability negotiation, leading to potential performance issues and delays in channel establishment.
Innovation Solution
A method where a computing device receives a connection message from a client device, extracts and authenticates the connection request and authentication information, and facilitates the establishment of a connection between the client and server devices, acting as a proxy for subsequent data exchange, allowing early negotiation of communication capabilities and enabling a transparent view of the virtualization agent.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate phases are used for authentication and capability negotiation, then security is maintained through structured verification, but channel establishment latency increases due to multiple sequential steps
Solution Approach 1:
The patent combines authentication and capability negotiation into a single integrated handshake message exchanged between client and server. The handshake message includes both authentication credentials and capability negotiation data, allowing both functions to be performed in one communication phase rather than separate sequential phases, thereby reducing channel establishment latency while maintaining security verification.
2Reliability
If the gateway acts as a proxy for all communication, then security and control are improved, but communication efficiency decreases due to additional routing steps
Solution Approach 1:
The patent segments the communication process into two distinct phases: an initial proxy phase where the gateway mediates the handshake message exchange for security verification, and a direct phase where the client and server communicate directly after authentication and capability negotiation are complete. This segmentation allows the gateway to provide security control only when necessary, improving overall communication efficiency while maintaining security requirements.
Data Source
AI summary
A computer system to establish a connection between a client device and a server device is provided. The computer system includes a gateway device that receives a message from the client device. The message includes a connection request and authentication information. The gateway device extracts the authentication information and the connection request from the message. The gateway device authenticates the client device, based on the authentication information. Subsequently, the gateway device transmits the connection request to the server device. Thereafter, the gateway device acts as a transparent proxy between the client and server devices, while the client and server devices engage in a handshake process to establish the connection between the client and server devices.


