Intermediary Device Network Profile IP Address Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data communication networks lack a systematic method to dynamically specify and manage internet protocol addresses for intermediary devices when establishing connections with servers, which can lead to security issues and inefficient traffic management.

Innovation Solution

The implementation of network profiles that allow intermediary devices to select and use specific internet protocol addresses from a pool of subnet IP addresses and mapped IP addresses for connections, enabling dynamic IP address selection based on network profiles bound to load balancing, content switching, or monitoring services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the intermediary device uses its own IP address as the source IP for backend connections, then the device can establish connections with servers, but the server cannot distinguish between regular traffic and monitor probes, reducing security and traffic management efficiency

Engineering Contradiction:
Improveconnection establishmentVSAvoidsecurity issues and traffic management inefficiency
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the IP address pool into different categories (SNIPs and MIPs) and further divides them into multiple IP sets. Each IP set is assigned for specific purposes (e.g., one set for regular traffic, another for monitor probes). This segmentation allows the server to distinguish between different types of traffic based on the source IP address, resolving the contradiction between establishing connections and maintaining security/traffic management efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different qualities or characteristics to different IP addresses within the pool. Specifically, certain IP addresses are designated with the quality of being suitable for monitor probes, while others are designated for regular client traffic. This local quality differentiation enables the server to identify and handle monitor probes separately from regular traffic, improving both security and traffic management without compromising connection establishment.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If the intermediary device uses a single IP address for all backend connections, then the configuration is simple, but the device cannot efficiently manage internal connections or distribute traffic to specific services

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidinternal connection management efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements a dynamic IP address selection mechanism where the intermediary device automatically selects the appropriate IP address from the pool based on the specific service and connection requirements. Instead of using a static single IP address, the system dynamically chooses from multiple IP sets, allowing efficient internal connection management and service-specific traffic distribution while maintaining ease of operation through automated selection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The IP address pool serves multiple functions simultaneously: it provides source IP addresses for regular client traffic, for monitor probes, and for different services. By making the IP address pool universal and multi-functional, the system can efficiently manage diverse internal connections without requiring separate configurations for each function, thus maintaining ease of operation while improving productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the intermediary device dynamically selects IP addresses from a pool, then the device can improve traffic management and security, but the device complexity increases due to the need to manage IP pools and profiles

Engineering Contradiction:
Improvesecurity and traffic managementVSAvoidIP address pool management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs preliminary action by pre-configuring the IP address pool and organizing IP addresses into named sets with specific purposes defined in advance. Network profiles are created beforehand that associate specific IP sets with particular services or functions. This preliminary organization reduces the complexity of dynamic selection during operation, as the device only needs to retrieve and use pre-defined configurations rather than making complex decisions in real-time, thus maintaining security and traffic management capabilities while reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If the server is configured to respond only to requests from specific IP addresses, then server security is improved, but the intermediary device needs a systematic method to manage and specify which IP addresses to use

Engineering Contradiction:
Improveserver securityVSAvoidIP address specification management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary action by pre-defining network profiles that specify which IP sets should be used for different services and scenarios. These profiles are configured in advance and associate specific IP address sets with particular services, monitors, or traffic types. This preliminary specification eliminates the need for complex real-time decision-making about IP address selection, allowing the intermediary device to simply retrieve the appropriate pre-configured IP set from the profile, thus maintaining server security while simplifying IP address management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network profile acts as an intermediary between the server's security requirements and the IP address pool. The profile translates the security requirement (server responds only to specific IPs) into a manageable configuration that the intermediary device can easily implement. By introducing this intermediary layer of abstraction, the system maintains strict security controls while reducing the complexity of IP address specification management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9742857B2Systems and methods for supporting a network profile
Publication Date: 2017.08.22 CITRIX SYSTEMS INC
  • US9742857B2 patent drawing
  • US9742857B2 patent drawing
  • US9742857B2 patent drawing

AI summary

The present solution is directed to a system for specifying a source internet protocol (IP) address used by an intermediary device for a connection to a server. The system includes a device intermediary to a plurality of clients and a server. The device may have a net profile for sending traffic to servers. The net profile specifies one or more internet protocol (IP) addresses to use as a source IP address for a connection between the device and the server. The device receives a request from a client of the plurality of clients via a first transport layer connection between the client and the device, identifies the net profile for the request, and establishes, responsive to the request, a second transport layer connection between the device and the server using an IP address.