Encrypted Clipboard for Secure Remote Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for remote access to applications and desktops face security risks when allowing data transfer between remote computing systems and client devices, leading to user frustration due to disabled copy-and-paste functionality to prevent data storage on the client device.
Innovation Solution
A method where encrypted data is transferred between remote computing systems via a backend system, bypassing the client device, using user session identifiers and encryption protocols to manage and secure data transfer, while enforcing policies and scanning for malicious content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data transfer is allowed between remote computing systems and client devices, then user functionality and convenience are improved, but security risks increase due to potential unauthorized data access
Solution Approach 1:
The patent introduces an encrypted clipboard as an intermediary mechanism between the remote computing system and client device. Data is copied to the encrypted clipboard on the remote system, encrypted during transfer, and only decrypted when pasted on the client device. This intermediary encrypted storage mechanism enables data transfer functionality while maintaining security, as the data remains encrypted during transmission and storage in the clipboard.
Solution Approach 2:
The patent applies encryption parameter changes to the data during the copy-paste process. Data is transformed from plaintext to encrypted text when copied to the clipboard, and only transformed back to plaintext when actually pasted on the client device. This parameter change (encryption state) ensures that data cannot be accessed or read during transmission and storage in the clipboard, resolving the security concern while maintaining transfer functionality.
2Object-affected harmful factors
If copy-and-paste functionality is disabled to prevent data storage on client device, then security is improved, but user experience deteriorates due to frustration
Solution Approach 1:
The encrypted clipboard serves as a secure intermediary that allows data to be temporarily stored during the copy-paste operation without permanently storing it on the client device. The data exists in an encrypted state in the clipboard, enabling the copy functionality to work while preventing unauthorized access or persistent storage, thus resolving the contradiction between security and user experience.
Solution Approach 2:
The patent implements a temporary encrypted clipboard that exists only for the duration of the copy-paste operation. The encrypted data in the clipboard is transient and does not persist on the client device after the paste operation completes. This disposable nature of the encrypted clipboard allows users to perform copy-paste operations freely while ensuring data is not permanently stored, resolving the security versus usability contradiction.
3Object-affected harmful factors
If encryption is applied to data in transit, then security is improved, but data transfer complexity increases
Solution Approach 1:
The patent merges the encryption and decryption operations into the existing clipboard copy-paste mechanism. The encryption is applied automatically when data is copied to the clipboard on the remote system, and decryption occurs automatically when data is pasted on the client device. By combining these security operations with the standard clipboard functionality, the system maintains security without adding significant user-facing complexity.
Solution Approach 2:
The encryption and decryption processes are implemented as automatic self-service operations within the clipboard mechanism. The system automatically encrypts data when it is copied to the clipboard and automatically decrypts it when pasted, without requiring user intervention or complex configuration. This self-service approach handles the encryption complexity in the background while maintaining simple user interaction, resolving the contradiction between security and complexity.
Data Source
AI summary
A backend computing system may receive first data from a first computing system, where the first data may be an encrypted version of second data that has been generated at the first computing system based on a command at the first computing system. The backend computing system may identify a second computing system different than the first computing system based on a status of the second computing system, and may send the first data to the second computing system to enable the second computing system to decrypt the first data and perform a function with respect to the second data. In some embodiments, the first computing system may generate padded data by adding data to the second data, and send the padded data to the backend computing system. In some embodiments, the first computing system may send random data to the backend computing system.


