Privacy Layer for Secure Virtualized Desktop Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtualized desktop environments face challenges with latency and privacy concerns when using thin client devices with limited hardware, as data processing and storage on network devices can lead to increased latency and risks of unauthorized access.
Innovation Solution
Implementing a privacy layer using tamper-resistant hardware components and a blockchain-controlled permissions system to securely store and process user data on network devices, with a trusted execution environment and hardware security modules to ensure data isolation and encryption, while maintaining low-latency response times through edge computing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data processing and storage are moved to network devices in a virtualized desktop environment, then computing resources on client devices are conserved and data availability is improved, but latency increases and privacy/security concerns arise
Solution Approach 1:
The patent segments the virtualized desktop environment into multiple isolated instances running on network devices, with each instance dedicated to a specific user session. This segmentation allows data to be stored and processed on the network (improving availability) while maintaining low latency through direct network device-to-client communication channels for each segmented session.
Solution Approach 2:
The patent introduces a privacy layer as an intermediary component between the virtualized desktop environment and the network. This privacy layer includes encryption modules and secure communication protocols that mediate data transmission, ensuring low-latency access while protecting against unauthorized access and improving overall system reliability.
2Ease of operation
If data is stored and processed on network devices, then client device hardware requirements are reduced, but unauthorized access risks increase
Solution Approach 1:
The patent implements preliminary security measures by establishing encrypted communication channels and authentication mechanisms before data transmission occurs. The privacy layer pre-configures security protocols and validates user credentials in advance, allowing thin client devices to access network-stored data portably while preventing unauthorized access through pre-established security barriers.
Solution Approach 2:
The patent creates an inert security environment through encryption and isolated virtual machine instances. Data stored on network devices is protected by cryptographic protocols that create a secure, inert atmosphere, making the data inaccessible to unauthorized parties even though it resides on network infrastructure, thereby enabling portable thin client operation without increased security risk.
3Use of energy by moving object
If virtualization technology is used to host desktop environments on network devices, then local processing power is conserved, but network dependency and latency are increased
Solution Approach 1:
The patent merges the virtualized desktop environment directly with edge computing resources on network devices, combining low-power thin client hardware with high-performance network-based processing. This merging allows minimal energy consumption on the client device while maintaining fast response times through the integrated nature of the virtualized environment running on the network infrastructure.
Solution Approach 2:
The patent shifts the processing dimension from local client devices to network edge infrastructure. By moving the computational workload to another dimension (the network layer), the system achieves both low client device energy consumption and fast response times, as the network dimension provides both power and speed that individual client devices lack.
4Reliability
If cryptographic keys are stored securely on client devices, then data encryption is enabled, but key management complexity and device security requirements increase
Solution Approach 1:
The patent extracts cryptographic key management from the thin client devices and relocates it to the network-based privacy layer. This extraction allows strong encryption security to be maintained while reducing device complexity on client endpoints, as the key management infrastructure is removed from the portable devices and centralized in the network infrastructure.
Data Source
AI summary
A device may receive a request to establish a virtualized environment to support a session for a client device in communication with the computing device over a network. The device may instantiate the virtualized environment in a trusted execution environment of the device, wherein the trusted execution environment may include one or more hardware resources that isolate the virtualized environment from a rich execution environment associated with the device. The device may cause a hardware security module associated with the device to obtain one or more cryptographic keys by communicating with a secure element of the client device, and the device may secure communication between a local operating system executing on the client device and the virtualized environment instantiated in the trusted execution environment using the one or more cryptographic keys.


