Clientless RDP Gateway Translating HTTP for Zero-Trust Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote desktop protocol (RDP) solutions are proprietary and lack customization options, leading to inefficiencies and limitations in user access to secure network environments.

Innovation Solution

A system and method for providing remote desktop access through a zero trust cloud environment using a clientless gateway to translate RDP over HTTP, enabling access via a web browser and utilizing Apache Guacamole to facilitate RDP sessions, with features like XRDP containers for credential capture and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If proprietary RDP protocol is used, then remote desktop access functionality is provided, but customization options are limited and user needs cannot be easily met

Engineering Contradiction:
Improvecustomization optionsVSAvoidprotocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component that sits between the client device and the RDP server. This gateway translates web-based HTTP/HTTPS traffic into RDP protocol communications, enabling customized web interface functionality while maintaining compatibility with standard RDP servers. The gateway acts as a mediator that allows customization at the web interface layer without modifying the core RDP protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the remote desktop access functionality into distinct layers: a customizable web interface layer, a translation/gateway layer, and the core RDP protocol layer. This segmentation allows each layer to be independently customized or modified without affecting the others, particularly enabling web-based customization while preserving RDP functionality.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If RDP client software is installed on client devices, then full RDP functionality is available, but deployment complexity increases and clientless access is not achieved

Engineering Contradiction:
Improveaccess simplicityVSAvoidclient deployment complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway serves as a clientless intermediary that performs protocol translation on the server side. Instead of requiring RDP clients on user devices, the gateway receives standard web traffic and translates it into RDP protocol communications with the backend server. This eliminates the need for client software installation while maintaining full RDP functionality through server-side translation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical requirement of installing RDP client software on client devices with a web-based HTTP/HTTPS interface. The complex RDP protocol stack that would normally need to be present on the client device is instead implemented in the gateway server, substituting the client-side mechanical requirement with a server-side software solution accessible through standard web browsers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If web-based access is implemented, then clientless gateway access is achieved, but direct RDP protocol transfer is not possible

Engineering Contradiction:
Improveweb browser compatibilityVSAvoidprotocol translation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway acts as a bidirectional intermediary that translates in both directions: converting web-based HTTP/HTTPS requests into RDP protocol communications toward the backend server, and converting RDP protocol responses into web-compatible formats for the client device. This dual translation capability enables web browser compatibility while maintaining direct RDP protocol transfer to the backend server.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If zero trust architecture is implemented, then enhanced security is provided, but authentication and access control complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The zero trust architecture implements preliminary authentication and verification actions before establishing any RDP session. The gateway performs identity verification, device validation, and access policy checks in advance of the actual desktop session. This preliminary security enforcement simplifies the overall authentication process by handling verification upfront rather than requiring complex continuous authentication during the session.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12445432B2System and method for providing a web based RDP service through a zero trust cloud environment
Publication Date: 2025.10.14 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12445432B2 patent drawing
  • US12445432B2 patent drawing
  • US12445432B2 patent drawing

AI summary

Remote desktop protocol (RDP) is a proprietary protocol for controlling machines over a network. In order to overcome certain deficiencies of the protocol a method is disclosed utilized in a zero trust cloud environment, to provide access to a pool of RDP servers, via an RDP client or via a web based interface while simultaneously providing an authenticated and secure policy based experience.