Traffic Management Virtual Server End Point Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for traffic management in data communication networks lack integration and interoperability between authentication, authorization, and auditing (AAA) services and traffic management policies, leading to inefficiencies in managing network traffic and client access.

Innovation Solution

The implementation of a system that integrates AAA services with traffic management by using a traffic management virtual server to redirect clients to an authentication virtual server for credential authentication and policy establishment, allowing dynamic selection of authentication servers based on client attributes and policies, and applying these policies to manage network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If AAA services and traffic management services are implemented separately, then each service can be independently managed and configured, but integration and interoperability between the two services are lacking

Engineering Contradiction:
Improveintegration and interoperabilityVSAvoidservice architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines AAA services and traffic management services into a unified service framework where both services operate within the same system architecture. The traffic management virtual server and authentication virtual server are integrated components that work together, allowing seamless interoperability while maintaining independent service functionality through modular design.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtual server architecture provides multi-functionality by enabling a single system to perform both AAA services (authentication, authorization, accounting) and traffic management functions. The traffic management virtual server can handle both traffic routing and authentication coordination, reducing the need for separate dedicated systems while maintaining service independence.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If static authentication server selection is used, then system configuration is simple, but the system cannot dynamically adapt to different client attributes and policies

Engineering Contradiction:
Improvedynamic authentication server selectionVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamic authentication server selection where the traffic management virtual server evaluates client attributes (such as user role, device type, network location) and policy requirements in real-time to determine the most appropriate authentication virtual server. This dynamic adaptation allows the system to respond to changing conditions while maintaining a standardized interface for authentication requests.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication mechanism incorporates feedback loops where the traffic management virtual server receives information about client characteristics and policy requirements, processes this information through evaluation rules, and selects authentication servers based on the analyzed feedback. This feedback-driven selection optimizes authentication routing while adapting to varying system conditions.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If manual traffic management policies are configured, then policy control is precise, but the system cannot automatically adapt to changing network conditions and client behaviors

Engineering Contradiction:
Improveautomatic policy applicationVSAvoidpolicy control precision
Core Design Contradiction:
Extent of automationVSManufacturing precision

Solution Approach 1:

The system implements self-service automation where the traffic management virtual server automatically evaluates client attributes and applies appropriate policies without manual intervention. The system autonomously determines authentication requirements, selects appropriate authentication servers, and enforces traffic management policies based on real-time client characteristics, reducing reliance on manual configuration while maintaining policy effectiveness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary evaluation of client attributes and policy requirements before authentication occurs. By pre-assessing client characteristics (such as device type, user role, network location) and determining the appropriate authentication server and policies in advance, the system prepares the authentication pathway beforehand, enabling automatic adaptation while maintaining precise policy control through pre-configured evaluation rules.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9264429B2Systems and methods for using end point auditing in connection with traffic management
Publication Date: 2016.02.16 CITRIX SYSTEMS INC
  • US9264429B2 patent drawing
  • US9264429B2 patent drawing
  • US9264429B2 patent drawing

AI summary

The present invention provides a system and method of managing traffic traversing an intermediary based on a result of end point auditing. An authentication virtual server of an intermediary may determine a result of an end point analysis scan of a client. Responsive to the determination, the traffic management virtual server can obtain the result from the authentication virtual server. Further, the traffic management virtual server may apply the result in one or more traffic management policies to manage network traffic of a connection of the client traversing the intermediary. In some embodiments, the authentication virtual server may receive one or more expressions evaluated by the client. The one or more expressions identifies one or more attributes of the client. The traffic management virtual server can also determine a type of compression or encryption for the connection based on applying the one or more traffic management policies using the result.