Virtual Desktop Server Protocol Interception for VDI Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual desktop infrastructure (VDI) faces challenges with multimedia traffic latency and bandwidth consumption due to 'hair-pinning' over networks, where multimedia is delivered in display protocol-specific formats, and hypervisors are not designed for real-time tasks like voice processing, limiting traffic prioritization and security policy application.

Innovation Solution

A network device, referred to as a virtual desktop server (VDS), intercepts control sessions between clients and connection brokers, initiates new sessions, and relays data between clients and hosts, terminating encryption and offloading multimedia processing to improve network efficiency and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multimedia traffic is delivered through the display protocol in VDI, then the client can receive multimedia content, but bandwidth consumption increases and latency is introduced due to hair-pinning over the network

Engineering Contradiction:
Improvemultimedia delivery reliabilityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts multimedia traffic from the display protocol tunnel by implementing protocol interception at the network device. The network device intercepts display protocol packets, identifies multimedia content within them, and extracts this content for separate handling through dedicated multimedia protocols, thereby reducing the bandwidth burden on the display protocol channel.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network device acts as an intermediary between the host and client, intercepting display protocol traffic and facilitating the extraction and redirection of multimedia content. This intermediary function allows the system to separate multimedia delivery from the encrypted display protocol tunnel, enabling optimized routing and reduced latency for multimedia traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the hypervisor scheduler handles voice traffic, then compute resources are utilized, but latency and jitter are introduced because hypervisors are not designed for real-time tasks

Engineering Contradiction:
Improvecompute resource utilizationVSAvoidvoice traffic latency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent extracts real-time voice and multimedia traffic from the hypervisor scheduler by implementing protocol interception. The network device identifies real-time traffic within display protocol packets and extracts it for separate processing through dedicated real-time communication protocols, bypassing the hypervisor scheduler that is not optimized for time-sensitive operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network device serves as an intermediary that separates real-time voice traffic from the general-purpose hypervisor scheduling system. By intercepting and re-routing real-time traffic through specialized protocols, the system achieves low-latency voice communication while maintaining efficient compute resource utilization through the hypervisor for non-real-time tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to the display protocol session, then security is improved, but the ability to prioritize traffic and apply security policies is limited

Engineering Contradiction:
Improvesession securityVSAvoidtraffic prioritization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network device acts as a trusted intermediary that intercepts encrypted display protocol traffic and applies deep packet inspection to identify traffic types. This intermediary function enables the system to maintain encryption for security while simultaneously applying quality of service policies, traffic prioritization, and differentiated security policies based on the identified traffic content without requiring decryption of the entire session.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by implementing selective traffic handling within the encrypted session. The network device applies different processing rules to different types of traffic (multimedia, voice, data) identified within the encrypted display protocol stream, enabling localized quality of service and security policy application without compromising overall session encryption.

Inventive Principle:
Principle #3Local quality

4Stability of the object's composition

If a single reliable session is used for display protocol communication, then connection stability is maintained, but network device ability to prioritize different traffic types is limited

Engineering Contradiction:
Improvesession stabilityVSAvoidtraffic prioritization flexibility
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent segments the single display protocol session into multiple logical channels by implementing protocol interception and analysis. The network device identifies different traffic types (multimedia, voice, data) within the unified session and separates them for differential handling, enabling traffic prioritization and quality of service policies while maintaining the stability of the underlying encrypted connection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9485292B2Display protocol interception in the network for services and network-based multimedia support for VDI
Publication Date: 2016.11.01 CISCO TECHNOLOGY INC
  • US9485292B2 patent drawing
  • US9485292B2 patent drawing
  • US9485292B2 patent drawing

AI summary

An apparatus and related method are provided for improving the performance of virtual desktop services. A network device is deployed in a network to intercept packets of a control session initiated by a client with a connection broker to obtain data from a host. The network device initiates a new control session to the connection broker on behalf of the client. The network device receives host information from the connection broker, replaces address information of the network device for the host information in a control session message and sends the control session message to the client. The network device establishes a data session with the client, initiates a data session with the host on behalf of the client and relays data between the data session with the host and the data session with the client such that the network device is transparent to the client and the host.