Gateway Appliance Direct Routing for DaaS Private Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Desktop as a Service (DaaS) systems face challenges in securely accessing private enterprise network data hosted in a cloud environment without requiring costly tenant cloud accounts or complex network configurations, often necessitating separate network pipes and complicated routing setups.

Innovation Solution

A method involving a gateway appliance that establishes direct routes between session clients and a virtual session connector within a private enterprise computing network, allowing for secure relay of private enterprise network data using Transmission Control Protocol (TCP) and token-based authentication, thereby bypassing the need for additional VPN hardware and costly infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network configurations are used for DaaS sessions to access private enterprise network data, then secure access is achieved, but device complexity and infrastructure costs increase due to requiring separate network pipes and complex routing setups

Engineering Contradiction:
Improvesecure accessVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway appliance as an intermediary component that mediates between DaaS session clients and the private enterprise network. This gateway appliance consolidates multiple routing functions and network pipe configurations into a single device, thereby maintaining secure access while reducing overall network configuration complexity. The gateway appliance acts as a centralized point of control that simplifies the network architecture by eliminating the need for multiple separate network pipes and complex routing setups.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate network pipes are deployed for each private enterprise network, then secure connectivity is maintained, but device complexity and infrastructure costs increase

Engineering Contradiction:
Improvesecure connectivityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate network pipe configurations and routing functions into a single gateway appliance. Instead of deploying independent network infrastructure for each private enterprise network connection, the gateway appliance consolidates these functions, maintaining secure connectivity while significantly reducing infrastructure complexity. This merging approach allows multiple DaaS session clients to access different private enterprise networks through a unified gateway, eliminating redundant infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If complex routing setups are implemented for DaaS sessions, then access to private enterprise network data is enabled, but ease of operation deteriorates due to complicated configuration requirements

Engineering Contradiction:
Improveaccess capabilityVSAvoidconfiguration simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The gateway appliance implements self-service capabilities by automatically managing routing configurations and network pipe setups. Instead of requiring manual configuration of complex routing parameters for each DaaS session client, the gateway appliance autonomously handles these configurations, thereby maintaining full access capability to private enterprise network data while dramatically improving ease of operation. The system performs self-configuration and adaptive routing without requiring deep network knowledge from users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20200389526A1COMPUTING SYSTEM PROVIDING DIRECT ROUTING FOR DESKTOP AS A SERVICE (DaaS) SESSIONS TO A PRIVATE NETWORK AND RELATED METHODS
Publication Date: 2020.12.10 CITRIX SYSTEMS INC
  • US20200389526A1 patent drawing
  • US20200389526A1 patent drawing
  • US20200389526A1 patent drawing

AI summary

A method may include establishing a first direct route to a gateway appliance from session clients each associated with a respective Desktop as a Service (DaaS) session run by a virtual session controller within a computing network, and establishing a second direct route from the gateway appliance to a virtual session connector within at least one private enterprise computing network. The method may also include relaying private enterprise network data between the session clients and the virtual session connector through the gateway appliance via the first direct route to each session client and the second direct route to the virtual session connector.