Secure Gateway Redirection for Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote connection systems require manual reconfiguration of client devices to switch between different entry points in a secure network, leading to inefficiencies and increased time and effort in establishing secure data connections.

Innovation Solution

A method that automatically redirects client devices from one gateway to another within a secure data network based on determination logic, using redirect messages to instruct clients to reconnect via a more appropriate gateway, thereby eliminating the need for manual reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual reconfiguration is used to switch entry points, then connection accuracy is improved, but time consumption and operational complexity increase

Engineering Contradiction:
Improveconnection accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The client device automatically determines the appropriate entry point using determination logic without requiring manual reconfiguration. The system performs self-service by autonomously selecting the optimal gateway based on client location and network conditions, eliminating the need for user intervention while maintaining connection accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The determination logic pre-evaluates multiple entry points and identifies the most appropriate one before the client attempts connection. By performing this selection in advance based on client device information and gateway characteristics, the system avoids trial-and-error connections and reduces time consumption.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual reconfiguration is used to switch entry points, then connection accuracy is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveconnection accuracyVSAvoidoperational simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system automatically performs entry point selection without requiring user configuration or intervention. The determination logic embedded in the client device autonomously identifies the appropriate gateway, making the operation as simple as initiating a connection request while maintaining high connection accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The determination logic acts as an intermediary between the client device and multiple entry points. It automatically processes the selection based on client information and gateway characteristics, shielding the user from complex configuration tasks while ensuring accurate connection routing.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automatic redirection is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improveconnection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The determination logic pre-evaluates entry point suitability using client device information and gateway characteristics before connection attempts. This preliminary assessment enables automatic redirection to the optimal gateway, improving connection efficiency without requiring complex real-time decision-making mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses varying parameters such as client location, gateway load, and network conditions to dynamically select entry points. By changing selection criteria based on current system state rather than fixed configuration, the system achieves high productivity while keeping the determination logic relatively simple.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2401842B1Redirection of secure data connection requests
Publication Date: 2018.11.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2401842B1 patent drawingFigure 1
  • EP2401842B1 patent drawingFigure 2
  • EP2401842B1 patent drawingFigure 3

AI summary

Methods, systems, and computer-readable media are disclosed for processing a secure data connection request. A particular method receives, at a first gateway, a secure data connection request from a client identifying a server to connect to. The first gateway sends the client device a redirect message instructing the client device to attempt alternate connection via a second gateway. The client sends a secure data connection request to the second gateway and the second gateway facilitates the secure data connection between the client and the server.