Intermediary Device Single Sign-On for Remote Desktop Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional remote desktop access methods require custom VPN or RDP clients, which may not be available on all devices, and necessitate multiple authentications for each remote desktop host, complicating secure and seamless access.

Innovation Solution

An intermediary device provides single sign-on (SSO) for remote desktop sessions without the need for custom VPN or RDP clients, using a security token for authentication and encryption, allowing access to remote desktop hosts through a standard Microsoft Remote Desktop Client, while supporting advanced authentication methods like multi-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If custom VPN or RDP clients are installed on user devices, then secure remote desktop access is enabled, but device compatibility is limited and installation complexity increases

Engineering Contradiction:
Improvesecure remote desktop accessVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary device positioned between the client device and remote desktop host. This intermediary receives RDP requests from standard clients, performs authentication and security validation, then establishes secure connections to remote hosts. This mediator approach allows standard RDP clients to work across all devices without requiring custom client installations, while still enforcing security requirements through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication methods are required for each remote desktop host, then security is enhanced, but authentication complexity and user time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication at the intermediary device before the client connects to remote desktop hosts. The intermediary performs multi-factor authentication and credential validation in advance, storing authenticated session information. When users subsequently access remote hosts, the intermediary uses pre-established trust relationships to enable single sign-on, eliminating repeated authentication requirements while maintaining security through the initial comprehensive authentication.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If standard Microsoft Remote Desktop Client is used, then ease of operation is improved, but access control and security validation capabilities are reduced

Engineering Contradiction:
Improveclient usabilityVSAvoidsecurity control complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent employs an intermediary device that acts as a security gateway between standard RDP clients and remote desktop hosts. The intermediary handles all complex security validation, authentication, and access control operations, while the standard Microsoft Remote Desktop Client maintains its simple, user-friendly interface. This separation allows standard clients to provide ease of operation while the intermediary layer implements comprehensive security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3202114B1Systems and methods for performing single sign-on by an intermediary device for a remote desktop session of a client
Publication Date: 2021.05.12 CITRIX SYSTEMS INC
  • EP3202114B1 patent drawingFigure 1A
  • EP3202114B1 patent drawingFigure 1B
  • EP3202114B1 patent drawingFigure 1C

AI summary

The present disclosure is directed to systems and methods for performing single sign on by an intermediary device for a remote desktop session of a client. A first device intermediary to a plurality of clients and a plurality of servers authenticates a user and establishes a connection to the users client device. The device provides a homepage including links to one or more remote desktop hosts associated with the user. The device receives a request to launch an RDP session with a remote desktop host via the homepage and generates RDP content, including a security token, for the user. The device receives a second request that includes the security token to launch the RDP session. The device validates the user using the security token and establishes a connection to the remote desktop host. The device signs into the desktop host using session credentials.