Virtual Desktop Sensitive Application Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual desktop infrastructure environments, collaborative sessions pose a challenge as sensitive information from applications like email and instant messaging can unintentionally be exposed to secondary users, leading to security and privacy issues.

Innovation Solution

Implement a mechanism to monitor sensitive applications during collaborative sessions, allowing the primary user to choose how to handle such applications, including hiding, minimizing, closing, or popping out the sensitive applications from the shared desktop.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the primary user shares their entire desktop with secondary users during a collaborative session, then collaboration efficiency and convenience are improved, but sensitive information from applications may be unintentionally exposed to secondary users

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidsensitive information exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The desktop environment is segmented into shared regions and private regions. The system identifies sensitive applications (such as email clients, instant messaging applications, and document editors) and creates separate display channels for these applications versus other desktop content. This segmentation allows collaborators to view general desktop content while sensitive application content is routed to a private channel visible only to the primary user.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer between the desktop applications and the collaborative session. This intermediary component monitors application windows, identifies sensitive applications based on predefined criteria or user configuration, and selectively routes their display output. The intermediary enables the primary user to control which applications are shared and which remain private, resolving the contradiction between full desktop sharing and sensitive information protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system monitors and controls sensitive applications during collaborative sessions, then information security is improved, but system complexity and user configuration requirements increase

Engineering Contradiction:
Improveinformation securityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system provides self-service capabilities by automatically detecting and categorizing applications based on their window titles, process names, or known application signatures. Users can configure sensitive application types through a simplified interface that presents common categories (email, messaging, documents) with optional custom entries. The system maintains a default configuration that works for most users without requiring complex setup, while still providing advanced customization options for those who need them.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250028550A1Hiding sensitive information in collaborative virtual desktop sessions
Publication Date: 2025.01.23 OMNISSA LLC
  • US20250028550A1 patent drawing
  • US20250028550A1 patent drawing
  • US20250028550A1 patent drawing

AI summary

Systems and methods are described for hiding a primary user's sensitive information in collaborative virtual desktop sessions where multiple secondary users access the primary user's virtual desktop. In particular, embodiments described herein leverage a mechanism for monitoring when designated sensitive applications are opened in the virtual desktop. After the primary user sets up a collaborative session on their virtual desktop, if a sensitive application opens in the virtual desktop during the collaborative session, the sharing of the desktop graphical user interface (GUI) can be stopped and the user can be prompted (e.g., via a warning dialog that pops up) to choose how to proceed. For example, the user can choose to hide the entire desktop, to minimize or close the sensitive application, or to continue sharing the desktop but pop-out the sensitive application from the remote desktop in a separate window that is not shared with the collaborators.