Clientless RDP Gateway Translating HTTP for Zero-Trust Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote desktop protocol (RDP) solutions are proprietary and lack customization options, leading to inefficiencies and limitations in user access to secure network environments.
Innovation Solution
A system and method for providing remote desktop access through a zero trust cloud environment using a clientless gateway to translate RDP over HTTP, enabling access via a web browser and utilizing Apache Guacamole to facilitate RDP sessions, with features like XRDP containers for credential capture and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If proprietary RDP protocol is used, then remote desktop access functionality is provided, but customization options are limited and user needs cannot be easily met
Solution Approach 1:
The patent introduces a gateway as an intermediary component that sits between the client device and the RDP server. This gateway translates web-based HTTP/HTTPS traffic into RDP protocol communications, enabling customized web interface functionality while maintaining compatibility with standard RDP servers. The gateway acts as a mediator that allows customization at the web interface layer without modifying the core RDP protocol.
Solution Approach 2:
The system segments the remote desktop access functionality into distinct layers: a customizable web interface layer, a translation/gateway layer, and the core RDP protocol layer. This segmentation allows each layer to be independently customized or modified without affecting the others, particularly enabling web-based customization while preserving RDP functionality.
2Ease of operation
If RDP client software is installed on client devices, then full RDP functionality is available, but deployment complexity increases and clientless access is not achieved
Solution Approach 1:
The gateway serves as a clientless intermediary that performs protocol translation on the server side. Instead of requiring RDP clients on user devices, the gateway receives standard web traffic and translates it into RDP protocol communications with the backend server. This eliminates the need for client software installation while maintaining full RDP functionality through server-side translation.
Solution Approach 2:
The patent replaces the mechanical requirement of installing RDP client software on client devices with a web-based HTTP/HTTPS interface. The complex RDP protocol stack that would normally need to be present on the client device is instead implemented in the gateway server, substituting the client-side mechanical requirement with a server-side software solution accessible through standard web browsers.
3Adaptability or versatility
If web-based access is implemented, then clientless gateway access is achieved, but direct RDP protocol transfer is not possible
Solution Approach 1:
The gateway acts as a bidirectional intermediary that translates in both directions: converting web-based HTTP/HTTPS requests into RDP protocol communications toward the backend server, and converting RDP protocol responses into web-compatible formats for the client device. This dual translation capability enables web browser compatibility while maintaining direct RDP protocol transfer to the backend server.
4Reliability
If zero trust architecture is implemented, then enhanced security is provided, but authentication and access control complexity increases
Solution Approach 1:
The zero trust architecture implements preliminary authentication and verification actions before establishing any RDP session. The gateway performs identity verification, device validation, and access policy checks in advance of the actual desktop session. This preliminary security enforcement simplifies the overall authentication process by handling verification upfront rather than requiring complex continuous authentication during the session.
Data Source
AI summary
Remote desktop protocol (RDP) is a proprietary protocol for controlling machines over a network. In order to overcome certain deficiencies of the protocol a method is disclosed utilized in a zero trust cloud environment, to provide access to a pool of RDP servers, via an RDP client or via a web based interface while simultaneously providing an authenticated and secure policy based experience.


