Virtual Desktop Server Protocol Interception for VDI Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual desktop infrastructure (VDI) faces challenges with multimedia traffic latency and bandwidth consumption due to 'hair-pinning' over networks, where multimedia is delivered in display protocol-specific formats, and hypervisors are not designed for real-time tasks like voice processing, limiting traffic prioritization and security policy application.
Innovation Solution
A network device, referred to as a virtual desktop server (VDS), intercepts control sessions between clients and connection brokers, initiates new sessions, and relays data between clients and hosts, terminating encryption and offloading multimedia processing to improve network efficiency and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multimedia traffic is delivered through the display protocol in VDI, then the client can receive multimedia content, but bandwidth consumption increases and latency is introduced due to hair-pinning over the network
Solution Approach 1:
The patent extracts multimedia traffic from the display protocol tunnel by implementing protocol interception at the network device. The network device intercepts display protocol packets, identifies multimedia content within them, and extracts this content for separate handling through dedicated multimedia protocols, thereby reducing the bandwidth burden on the display protocol channel.
Solution Approach 2:
The network device acts as an intermediary between the host and client, intercepting display protocol traffic and facilitating the extraction and redirection of multimedia content. This intermediary function allows the system to separate multimedia delivery from the encrypted display protocol tunnel, enabling optimized routing and reduced latency for multimedia traffic.
2Productivity
If the hypervisor scheduler handles voice traffic, then compute resources are utilized, but latency and jitter are introduced because hypervisors are not designed for real-time tasks
Solution Approach 1:
The patent extracts real-time voice and multimedia traffic from the hypervisor scheduler by implementing protocol interception. The network device identifies real-time traffic within display protocol packets and extracts it for separate processing through dedicated real-time communication protocols, bypassing the hypervisor scheduler that is not optimized for time-sensitive operations.
Solution Approach 2:
The network device serves as an intermediary that separates real-time voice traffic from the general-purpose hypervisor scheduling system. By intercepting and re-routing real-time traffic through specialized protocols, the system achieves low-latency voice communication while maintaining efficient compute resource utilization through the hypervisor for non-real-time tasks.
3Reliability
If encryption is applied to the display protocol session, then security is improved, but the ability to prioritize traffic and apply security policies is limited
Solution Approach 1:
The network device acts as a trusted intermediary that intercepts encrypted display protocol traffic and applies deep packet inspection to identify traffic types. This intermediary function enables the system to maintain encryption for security while simultaneously applying quality of service policies, traffic prioritization, and differentiated security policies based on the identified traffic content without requiring decryption of the entire session.
Solution Approach 2:
The patent applies local quality by implementing selective traffic handling within the encrypted session. The network device applies different processing rules to different types of traffic (multimedia, voice, data) identified within the encrypted display protocol stream, enabling localized quality of service and security policy application without compromising overall session encryption.
4Stability of the object's composition
If a single reliable session is used for display protocol communication, then connection stability is maintained, but network device ability to prioritize different traffic types is limited
Solution Approach 1:
The patent segments the single display protocol session into multiple logical channels by implementing protocol interception and analysis. The network device identifies different traffic types (multimedia, voice, data) within the unified session and separates them for differential handling, enabling traffic prioritization and quality of service policies while maintaining the stability of the underlying encrypted connection.
Data Source
AI summary
An apparatus and related method are provided for improving the performance of virtual desktop services. A network device is deployed in a network to intercept packets of a control session initiated by a client with a connection broker to obtain data from a host. The network device initiates a new control session to the connection broker on behalf of the client. The network device receives host information from the connection broker, replaces address information of the network device for the host information in a control session message and sends the control session message to the client. The network device establishes a data session with the client, initiates a data session with the host on behalf of the client and relays data between the data session with the host and the data session with the client such that the network device is transparent to the client and the host.


