Anonymous Remote Access to Shared Computing Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current desktop virtualization systems lack a flexible and secure method to provide differentiated access to shared application sessions for various user groups, with inadequate control over feature sets and data security policies.
Innovation Solution
A computing system and method that allows for credentialed and non-credentialed access to shared application sessions through a secure interface, with distinct access policies for different groups of client devices, enabling centralized management and tracking of application session licenses, and implementation of appropriate security and permission levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If desktop virtualization systems provide centralized access to shared applications, then resource management and security are improved, but flexibility in providing differentiated access to different user groups deteriorates
Solution Approach 1:
The patent segments access to shared applications by dividing client computing devices into different groups (e.g., employees, contractors, customers) and applying distinct access policies to each group. This allows centralized security management while maintaining flexibility in differentiated access through policy-based segmentation rather than uniform treatment of all users.
Solution Approach 2:
The patent implements local quality by tailoring access policies, feature sets, and permission levels to specific groups of client devices. Each group receives customized access rights appropriate to their role (e.g., employees get full access, contractors get limited access), allowing differentiated service while maintaining overall system security.
2Reliability
If access policies are implemented for different user groups, then security and permission control are improved, but system complexity increases
Solution Approach 1:
The patent employs a universal access control framework that handles multiple user groups and access scenarios through a single integrated system. The access control server and policy management mechanisms serve multiple functions (authentication, authorization, telemetry collection, feature control) within one unified architecture, reducing overall system complexity compared to separate systems for each function.
Solution Approach 2:
The patent manages complexity by parameterizing access control through configurable policies that can be adjusted without changing system architecture. Access policies are defined by parameters such as user group identifiers, permission levels, and feature sets, allowing flexible control through parameter modification rather than system reconfiguration.
3Ease of operation
If anonymous access is provided to shared applications, then ease of access for certain user groups is improved, but ability to enforce strict security policies deteriorates
Solution Approach 1:
The patent introduces an intermediary access control server that mediates between anonymous client devices and shared applications. This intermediary layer enables anonymous access for certain user groups (improving ease of access) while simultaneously enforcing security policies by filtering and monitoring traffic, thus resolving the contradiction between accessibility and security enforcement.
Data Source
AI summary
A computing system may include a server configured to provide access to shared application sessions, a first group of client computing devices configured to remotely access shared application sessions from the server through a secure interface using a client security credential, and a second group of client computing devices configured to remotely access shared application sessions from the server through a secure interface anonymously without a client security credential. The server may further provide access to the shared application sessions for the first group of client computing devices based upon a first access policy, and provide access to the shared application sessions for the second group of client computing devices based upon a second access policy different than the first access policy.


