Overlay Tunnel Formation via Automatic Peer Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Clients with limited network capabilities, such as single-board computers or tablets, face difficulties in accessing resources through networks due to lack of specialized hardware or software configuration, and are exposed to security risks without additional configuration, leading to potential malicious interceptions and inadequate data transfer capacity.

Innovation Solution

The establishment of an overlay tunnel between a client and a server using intermediary devices with symmetric bandwidth and data rate capabilities, where the client-side device intercepts connection requests, generates security hash information, and communicates with the server-side device to authenticate and set up a secure virtual IP address-based connection without requiring additional hardware or software configuration on the client.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If clients with limited network capabilities directly access the network without intermediary devices, then hardware and software complexity is reduced, but security risks increase and communication capabilities are limited

Engineering Contradiction:
Improveclient configurationVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces intermediary devices (overlay network endpoints) that act as mediators between clients and the network. These intermediaries provide security services, capability enhancement, and transparent mediation without requiring client configuration changes. The intermediary devices establish overlay tunnels that protect client communications while maintaining simplicity at the client end.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If clients directly access network resources without intermediary devices, then communication path is direct and simple, but clients lack capability to handle complex network communications

Engineering Contradiction:
Improvecommunication capabilityVSAvoidnetwork architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Intermediary devices are deployed in the network path to provide enhanced communication capabilities. These devices handle complex networking tasks such as protocol translation, capability matching, and communication management, allowing clients with limited capabilities to access network resources effectively without modifying client hardware or software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented into overlay and underlay networks. The overlay network provides enhanced capabilities and security services through intermediary devices, while the underlay network handles basic transport. This segmentation allows clients to remain simple while benefiting from complex services provided by the overlay layer.

Inventive Principle:
Principle #1Segmentation

3Reliability

If intermediary devices are deployed to provide overlay tunnels, then security and communication capability are improved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvesecure communicationVSAvoidintermediary device configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediary devices automatically discover each other and establish overlay tunnels without manual configuration. The system employs automatic discovery mechanisms where intermediaries advertise their presence and capabilities, and automatically form peer relationships based on symmetric capability matching. This self-service approach eliminates the need for complex manual configuration while maintaining security and reliability.

Inventive Principle:
Principle #25Self-service

4Device complexity

If automatic discovery mechanism is implemented between intermediary devices, then configuration complexity is reduced, but discovery time and initial setup duration increase

Engineering Contradiction:
ImproveconfigurationVSAvoiddiscovery time
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The intermediary devices use standardized, universal discovery protocols that allow them to automatically identify and establish connections with compatible peers. By employing universal discovery mechanisms, the system reduces configuration complexity while optimizing discovery time through efficient peer matching based on symmetric capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11804984B2Intelligent and dynamic overlay tunnel formation via automatic discovery of citrivity/SDWAN peer in the datapath in a pure plug and play environment with zero networking configuration
Publication Date: 2023.10.31 CITRIX SYSTEMS INC
  • US11804984B2 patent drawing
  • US11804984B2 patent drawing
  • US11804984B2 patent drawing

AI summary

Described embodiments provide systems and methods of forming overlay tunnels for delivery of data between networked devices. A first intermediary device may transmit, responsive to a connection request from a client, a request having a source IP address corresponding to a first virtual IP address of the first device and a first payload including first security hash information to be processed by a second intermediary device. The first device may receive, from the second intermediary device, a response. The response may have a source IP address corresponding to the IP address of the server and a second payload including a virtual IP address of the second device, responsive to second security hash information corresponding to the first security hash information. The first device may establish an overlay tunnel using the first virtual IP address and the second virtual IP address for communicating data between the client and the server.