Token-Based Session Establishment Without Virtual Appliance Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing desktop virtualization systems face issues such as increased latency, resource consumption, complexity, and management burdens due to the use of agents for connecting client devices to virtual delivery appliances, which also introduce additional security and scalability challenges.

Innovation Solution

Establish a persistent connection between a cloud service gateway and a virtual delivery appliance using a token-based mechanism, eliminating the need for agents and simplifying the connection process while ensuring security through a lightweight PKI approach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If agents are used to connect client devices to virtual delivery appliances, then connection management is simplified, but latency increases and resource consumption increases

Engineering Contradiction:
Improveconnection managementVSAvoidlatency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent extracts and removes the agent component from the connection architecture. Instead of using agents on virtual delivery appliances to manage connections, the system uses direct token-based authentication between client devices and gateway devices, eliminating the intermediary agent that caused latency and resource consumption issues.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a gateway device as a new intermediary that replaces the traditional agent-based approach. The gateway device handles connection management, authentication, and session establishment directly, reducing the complexity and performance overhead associated with agent-based connection management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If agents are deployed on virtual delivery appliances, then connection establishment is automated, but device complexity increases

Engineering Contradiction:
Improveconnection establishmentVSAvoidappliance complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent removes the agent software from virtual delivery appliances, thereby reducing appliance complexity. Connection establishment automation is achieved through the gateway device's token-based authentication mechanism rather than through agents running on each appliance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service authentication where client devices automatically obtain tokens and establish connections without requiring agent-based mediation. The gateway device autonomously manages authentication and session establishment, eliminating the need for complex agent deployment and management on appliances.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional connection methods are used, then compatibility with existing systems is maintained, but security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the authentication parameter from traditional agent-based credentials to token-based authentication. Tokens are generated and validated by the gateway device, providing enhanced security through cryptographic token verification while maintaining a relatively simple implementation architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12537854B2Token-based session establishment for client computing devices
Publication Date: 2026.01.27 CITRIX SYSTEMS INC
  • US12537854B2 patent drawing
  • US12537854B2 patent drawing
  • US12537854B2 patent drawing

AI summary

A method may include, at a computing device, receiving a token from an appliance operating as a gateway between a client computing device and the computing device, the token being generated based upon a key of the computing device, and establishing a first connection with the appliance based upon the token, with the first connection being persistent. The method may further include, at the computing device, receiving a request from the appliance via the first connection, the request being for a remote session, and responsive to receipt of the request, establishing a second connection with the appliance that enables the client computing device to access the session.