Unique Network Identifier Assignment for Multi-User Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication systems assign a single IP address to a computer, making it difficult to distinguish between multiple users or programs sharing the same address, leading to issues in unique identification, security, and network monitoring, especially in multi-user environments and server farms.

Innovation Solution

A system and method that assign unique network identifiers and loopback addresses to each program or user session on a computer, allowing multiple users to communicate independently and concurrently, using an interface mechanism to select and associate unique IP addresses and host names from a plurality of identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a single IP address is assigned to a computer for network communications, then the computer can communicate over the network, but multiple users or programs on the computer cannot be uniquely identified

Engineering Contradiction:
Improveuser identification precisionVSAvoidnetwork identifier assignment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network identifier assignment by introducing port numbers as a subdivision of the IP address space. Each user session or program is assigned a unique combination of IP address and port number, effectively segmenting the single IP address into multiple identifiable communication channels. This resolves the contradiction by enabling precise user identification while maintaining the simplicity of a single IP address assignment at the device level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to network identification by introducing port numbers as a secondary identifier alongside the IP address. This dimensional expansion transforms the single-dimensional IP address into a two-dimensional identifier system (IP address + port number), enabling unique identification of multiple users or programs on the same computer without increasing the complexity of the base IP address assignment.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Object-affected harmful factors

If the loopback interface is shared by all users on a multi-user system, then network resources are conserved, but security protection for controlling multiple user access is lacking

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidinterface management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the shared loopback interface by assigning unique port numbers to each user or program accessing it. This segmentation creates isolated communication channels that maintain security boundaries while allowing multiple users to access the loopback interface concurrently. The segmentation prevents unauthorized access and interference between users while conserving the underlying network resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces port numbers as an intermediary layer between the loopback interface and user applications. This intermediary mechanism provides security control and access management without requiring direct modification of the loopback interface itself, thereby enhancing security while maintaining interface simplicity and resource efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a computer has multiple network cards and multiple IP addresses, then more network communications are supported, but the IP addresses are still associated with the computer and not with users or programs

Engineering Contradiction:
Improvenetwork communication versatilityVSAvoiduser identification precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies segmentation by combining the existing multiple IP addresses with port numbers to create a hierarchical identification system. Each user or program is assigned a specific IP address and port number combination, segmenting the network communication capabilities further. This maintains the versatility of multiple network cards while achieving precise user identification through the additional port number dimension.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension (port numbers) to the existing IP address system, transforming it from a one-dimensional identifier to a two-dimensional identifier system. This dimensional enhancement enables precise user identification while preserving the adaptability and versatility provided by multiple IP addresses across different network cards.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7984192B2System and method for assigning unique identifiers to each remote display protocol session established via an intermediary device
Publication Date: 2011.07.19 CITRIX SYSTEMS INC
  • US7984192B2 patent drawing
  • US7984192B2 patent drawing
  • US7984192B2 patent drawing

AI summary

The invention relates to systems and methods for assigning a unique network identifier to one or more programs invoked on a computer. The computer obtains a plurality of network identifiers and associates a first network identifier to a first program invoked on the computer and associates a second network identifier, different from the first network identifier, to a second program invoked on the computer. The program may be a user session hosted by the computer, an application or an application isolation environment. The computer through a network communication interface transmits the first network identifier with the network communication of the first program and transmits the second network identifier with network communication of the second program.