Anonymous Remote Access to Shared Computing Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current desktop virtualization systems lack a flexible and secure method to provide differentiated access to shared application sessions for various user groups, with inadequate control over feature sets and data security policies.

Innovation Solution

A computing system and method that allows for credentialed and non-credentialed access to shared application sessions through a secure interface, with distinct access policies for different groups of client devices, enabling centralized management and tracking of application session licenses, and implementation of appropriate security and permission levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If desktop virtualization systems provide centralized access to shared applications, then resource management and security are improved, but flexibility in providing differentiated access to different user groups deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility in differentiated access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access to shared applications by dividing client computing devices into different groups (e.g., employees, contractors, customers) and applying distinct access policies to each group. This allows centralized security management while maintaining flexibility in differentiated access through policy-based segmentation rather than uniform treatment of all users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by tailoring access policies, feature sets, and permission levels to specific groups of client devices. Each group receives customized access rights appropriate to their role (e.g., employees get full access, contractors get limited access), allowing differentiated service while maintaining overall system security.

Inventive Principle:
Principle #3Local quality

2Reliability

If access policies are implemented for different user groups, then security and permission control are improved, but system complexity increases

Engineering Contradiction:
Improvepermission controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs a universal access control framework that handles multiple user groups and access scenarios through a single integrated system. The access control server and policy management mechanisms serve multiple functions (authentication, authorization, telemetry collection, feature control) within one unified architecture, reducing overall system complexity compared to separate systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent manages complexity by parameterizing access control through configurable policies that can be adjusted without changing system architecture. Access policies are defined by parameters such as user group identifiers, permission levels, and feature sets, allowing flexible control through parameter modification rather than system reconfiguration.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If anonymous access is provided to shared applications, then ease of access for certain user groups is improved, but ability to enforce strict security policies deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidsecurity policy enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary access control server that mediates between anonymous client devices and shared applications. This intermediary layer enables anonymous access for certain user groups (improving ease of access) while simultaneously enforcing security policies by filtering and monitoring traffic, thus resolving the contradiction between accessibility and security enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11159531B2Computer system providing anonymous remote access to shared computing sessions and related methods
Publication Date: 2021.10.26 CITRIX SYSTEMS INC
  • US11159531B2 patent drawing
  • US11159531B2 patent drawing
  • US11159531B2 patent drawing

AI summary

A computing system may include a server configured to provide access to shared application sessions, a first group of client computing devices configured to remotely access shared application sessions from the server through a secure interface using a client security credential, and a second group of client computing devices configured to remotely access shared application sessions from the server through a secure interface anonymously without a client security credential. The server may further provide access to the shared application sessions for the first group of client computing devices based upon a first access policy, and provide access to the shared application sessions for the second group of client computing devices based upon a second access policy different than the first access policy.