Sequence Number Rotation for PEP Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protocols, such as TCP/IP, face limitations in performance and compatibility with legacy equipment, leading to data integrity issues and connectivity problems when using performance-enhancing proxies (PEPs), especially due to routing changes and security/firewall configurations.

Innovation Solution

Sequence number rotation and adjustment of data packet fields to ensure packets are recognized as valid or invalid by downstream devices, allowing for detection of PEP failures and maintaining data integrity through Protected Packet Flow Sessions (PPFS).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If PEPs manipulate protocol or data to enhance performance, then network performance is improved, but data integrity is compromised when PEPs fail or routing changes occur

Engineering Contradiction:
Improvenetwork performanceVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that verifies whether manipulated packets have been properly processed by PEPs. This intermediary layer checks packet integrity through authentication codes or checksums, ensuring that enhanced packets are correctly recognized and processed, thus maintaining data integrity while allowing performance enhancement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where receiving devices verify packet authenticity and provide error feedback when packets are improperly manipulated or routed around PEPs. This feedback loop allows the system to detect and correct integrity issues, maintaining reliable data transmission despite PEP manipulations.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If PEPs are deployed to enhance legacy equipment, then compatibility with old equipment is improved, but new packet behavior is rejected by firewalls and security devices

Engineering Contradiction:
Improvecompatibility with legacy equipmentVSAvoidfirewall rejection
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes packet parameters by adding authentication codes or modifying checksum fields in a standardized way that maintains packet structure. This allows PEP-manipulated packets to retain their original format characteristics while incorporating integrity verification mechanisms, enabling them to pass through firewalls and security devices without rejection.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If PEPs compress data streams to increase bandwidth, then effective bandwidth is doubled, but CPU burden erases performance advantages on fast links

Engineering Contradiction:
Improveeffective bandwidthVSAvoidCPU burden
Core Design Contradiction:
Quantity of substanceVSUse of energy by moving object

Solution Approach 1:

The patent applies compression selectively based on link characteristics. PEPs assess the bandwidth and CPU capacity of connected links, applying compression only where beneficial (low bandwidth links) and leaving fast links uncompressed. This local adaptation optimizes the balance between bandwidth utilization and CPU resource consumption.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7551620B1Protecting data integrity in an enhanced network connection
Publication Date: 2009.06.23 CITRIX SYSTEMS INC
  • US7551620B1 patent drawing
  • US7551620B1 patent drawing
  • US7551620B1 patent drawing

AI summary

The integrity of a data stream transmitted over a network is protected by adjusting the sequence number, the port number, or another field of a data packet field, for a number of data packets so that the data packets will be considered either valid or invalid by a downstream receiving device. Data packets that have such a field adjusted can be thought of as being rotated outside of a valid range or window, as defined for a network connection. This field of a rotated data packet can be further adjusted, through de-rotation or re-rotation, for various applications. Downstream devices can thus respond to the data packets depending on the state of the rotation.