RDP Key Sharing via Time-Limited Encrypted Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for secure exchange of private keys for authenticating users to remote desktop protocol (RDP) services to ensure secure remote access while minimizing user input and preventing unauthorized access through time-limited password validity.
Innovation Solution
A method for securely exchanging private keys using a single sign-on system, where a portal environment system retrieves and encrypts usernames and passwords with a time-limited validity, allowing automatic login to RDP services without additional user input, and automatically updates passwords and software versions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication methods requiring repeated login credentials are used, then security can be maintained, but user convenience and productivity deteriorate due to repeated manual input
Solution Approach 1:
The system performs preliminary actions by pre-establishing and storing encrypted credential information in a secure database before the user needs access. When authentication is required, the system retrieves and uses these pre-stored credentials automatically, eliminating the need for repeated manual input while maintaining security through encryption and time-limited validity.
Solution Approach 2:
The patent introduces an intermediary authentication system that acts as a mediator between the user and the RDP service. This intermediary handles the credential management, encryption, and validation processes automatically, allowing seamless authentication without requiring users to manually enter credentials for each service access.
2Ease of operation
If permanent passwords are used for RDP access, then ease of operation improves, but security deteriorates due to increased risk of unauthorized access and password reuse attacks
Solution Approach 1:
The system transitions from static permanent passwords to dynamic time-limited credentials. Each password is assigned a specific validity period that automatically expires, preventing permanent reuse. The system dynamically generates and manages credentials with different validity periods based on user roles and access requirements, maintaining ease of login while eliminating permanent password risks.
Solution Approach 2:
The system applies beforehand cushioning by implementing time-limited validity and automatic expiration mechanisms that prevent prolonged exposure of credentials. The encryption layers and validity constraints are built into the system architecture in advance, cushioning against potential security breaches and unauthorized long-term access.
3Reliability
If manual password updates are required, then security can be maintained, but productivity deteriorates due to additional user input requirements
Solution Approach 1:
The authentication system performs self-service by automatically managing password expiration and updates without requiring user intervention. When a password approaches its validity limit or when software updates are deployed, the system automatically generates new credentials, updates the database, and maintains continuity of access, thereby maintaining security while eliminating manual update requirements.
Solution Approach 2:
The system ensures continuity of useful action by maintaining automatic authentication functionality throughout the entire credential lifecycle. From initial login through periodic updates to final expiration, the system continuously manages credentials without interruption or manual intervention, ensuring uninterrupted access while maintaining security standards.
Data Source
AI summary
Various methods for the secure exchange of private keys for authenticating a user to an RDP service are provided. One example method may comprise receiving a request comprising a session token to provide a user with access to an RDP service, and retrieving a username and password associated with the user using the session token. The method may further comprise assigning a time period of validity to the password. Furthermore, the method may comprise generating a first secret key based on user information, generating a second secret key based on the first secret key and a salt, and encrypting a packet comprising the password and the time period using the second secret key. Additionally, the method may comprise transmitting the username and encrypted packet to the device for authenticating the user with the requested RDP service. Similar and related example methods, apparatuses, systems, and computer program products are also provided.


