Client Login Certificates for Remote Desktop Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based remote desktop systems require cumbersome authentication processes for users accessing virtual desktops, often necessitating separate login credentials and specialized security protocols, which undermine the single sign-on experience and burden gateway resources.
Innovation Solution
A system and method that enables single sign-on for remote applications using a client-based login certificate, where the client device stores a login certificate securely and communicates it directly with the virtual infrastructure, bypassing the need for specialized security protocols and gateway involvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate authentication process using smart card reader and certificate authority is implemented, then security is improved, but device complexity and ease of operation deteriorate due to additional hardware requirements and cumbersome authentication steps
Solution Approach 1:
The patent extracts the authentication functionality from the gateway server and relocates it to the client device by implementing a local certificate store and authentication module. This allows the client to perform self-authentication using stored certificates, eliminating the need for gateway-based authentication and reducing gateway resource consumption while maintaining security.
Solution Approach 2:
The client device is empowered to authenticate itself independently to multiple virtual desktop infrastructure providers using its own stored certificates. The authentication process becomes a self-service operation where the client presents its certificate directly to the VDI provider without requiring gateway mediation, simplifying the authentication flow and improving ease of operation.
2Reliability
If gateway-based authentication is used, then centralized security control is improved, but gateway resource consumption increases and single sign-on capability deteriorates
Solution Approach 1:
The authentication credentials (certificates) are pre-configured and stored in the client device before connection attempts. This preliminary setup allows the client to perform authentication locally without consuming gateway resources during the authentication process, while centralized security control is maintained through the initial certificate distribution and management.
Solution Approach 2:
The patent introduces a certificate store and authentication module as an intermediary layer between the client and VDI providers. This intermediary handles authentication locally using stored certificates, eliminating the need for gateway involvement in the authentication process while maintaining secure access control.
3Reliability
If multiple authentication protocols are required for remote desktop access, then security is improved, but ease of operation deteriorates due to user burden of managing multiple credentials
Solution Approach 1:
The client device is designed with universal authentication capability using stored certificates that can be presented to multiple different VDI providers. A single certificate store contains credentials that work across different authentication protocols and providers, enabling the client to access various virtual desktop environments without requiring separate authentication mechanisms for each provider.
Solution Approach 2:
The patent merges multiple authentication credentials into a single certificate store on the client device. Instead of requiring separate authentication processes for different VDI providers, the system combines multiple certificates and credentials into one unified storage location, allowing the client to perform single sign-on authentication to multiple providers using the same credential management interface.
Data Source
AI summary
A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.


