Cloud Virtual Desktop Security Gateway for Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based virtual desktop environments face security threats from unauthorized data leakage and malicious code influx due to the risks associated with remote access and interaction protocols, with existing methods either causing user inconvenience or failing to address unknown malicious code and antivirus incapacitation.

Innovation Solution

A security control apparatus and method that includes a network control unit, policy checking unit, and security solution interaction unit to analyze and block unauthorized data transmission based on compliance with user authority policies, using a security protocol-based packet with a protocol control header and data, and interacting with external security solutions for malicious file identification and data leakage prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external equipment such as USB devices is prohibited from accessing the cloud via virtual desktop configuration, then data leakage risk is fundamentally reduced, but user convenience deteriorates significantly

Engineering Contradiction:
Improvedata leakage preventionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A security gateway is introduced as an intermediary component between the virtual desktop and external equipment. The gateway intercepts and controls all data transmission channels, including USB devices, clipboard, and other interaction protocols, allowing selective permission granting while maintaining security. This resolves the contradiction by enabling controlled access rather than complete prohibition.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security control mechanism is segmented into multiple independent modules: protocol analysis module, policy checking module, and security solution interaction module. Each module handles specific aspects of security control, allowing fine-grained management of different data transmission channels while maintaining overall security posture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If antivirus programs are installed in virtual desktop to prevent malicious code, then known malicious code is blocked, but unknown malicious code and antivirus incapacitation cannot be handled

Engineering Contradiction:
Improvemalicious code blockingVSAvoidcoverage against unknown threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary analysis of data packets before they reach the virtual desktop environment. The protocol analysis module examines packet structures and the policy checking module validates data against predefined policies in advance, preventing malicious code execution before it can compromise the system or antivirus program.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security gateway acts as an intermediary that filters and validates all incoming data before it reaches the virtual desktop. This intermediate security layer provides an additional defense mechanism that can detect and block unknown threats based on behavioral patterns and policy violations, supplementing traditional antivirus capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encrypted channels are used for remote interaction, then data transmission security is improved, but security threats can bypass all security equipment through the encrypted channel

Engineering Contradiction:
Improvedata transmission securityVSAvoidsecurity threat bypass risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security gateway is positioned as an intermediary that terminates encrypted connections and performs security checks on decrypted data. By acting as a trusted intermediary that controls the encrypted channel, the system can inspect data content while maintaining encryption for data in transit, preventing threats from bypassing security equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security validation is performed preliminarily on decrypted packets before they are forwarded to the virtual desktop. The protocol analysis and policy checking occur before data enters the encrypted channel to the remote device, ensuring that only validated data is transmitted even through encrypted channels.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9674143B2Security control apparatus and method for cloud-based virtual desktop
Publication Date: 2017.06.06 ELECTRONICS & TELECOMM RES INST
  • US9674143B2 patent drawing
  • US9674143B2 patent drawing
  • US9674143B2 patent drawing

AI summary

The security control apparatus includes a network control unit for receiving a security protocol-based packet that includes a protocol control header and data and that is transmitted between a cloud-based virtual desktop interaction remote agent unit and a virtual machine of a cloud-based virtual desktop interaction device, and blocking network traffic between cloud-based virtual desktop interaction remote agent unit and the virtual machine, depending on received results of checking. A policy checking unit checks whether information extracted from the security protocol-based packet is compliant with control policies, and transmits results of checking to the network control unit. If the information is not compliant with the control policies, a security solution interaction unit transmits the extracted information to an external security solution, and transmits results of checking by a corresponding security solution to the network control unit.