RDP Key Sharing via Time-Limited Encrypted Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure exchange of private keys for authenticating users to remote desktop protocol (RDP) services to ensure secure remote access while minimizing user input and preventing unauthorized access through time-limited password validity.

Innovation Solution

A method for securely exchanging private keys using a single sign-on system, where a portal environment system retrieves and encrypts usernames and passwords with a time-limited validity, allowing automatic login to RDP services without additional user input, and automatically updates passwords and software versions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods requiring repeated login credentials are used, then security can be maintained, but user convenience and productivity deteriorate due to repeated manual input

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-establishing and storing encrypted credential information in a secure database before the user needs access. When authentication is required, the system retrieves and uses these pre-stored credentials automatically, eliminating the need for repeated manual input while maintaining security through encryption and time-limited validity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication system that acts as a mediator between the user and the RDP service. This intermediary handles the credential management, encryption, and validation processes automatically, allowing seamless authentication without requiring users to manually enter credentials for each service access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If permanent passwords are used for RDP access, then ease of operation improves, but security deteriorates due to increased risk of unauthorized access and password reuse attacks

Engineering Contradiction:
Improveease of loginVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system transitions from static permanent passwords to dynamic time-limited credentials. Each password is assigned a specific validity period that automatically expires, preventing permanent reuse. The system dynamically generates and manages credentials with different validity periods based on user roles and access requirements, maintaining ease of login while eliminating permanent password risks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies beforehand cushioning by implementing time-limited validity and automatic expiration mechanisms that prevent prolonged exposure of credentials. The encryption layers and validity constraints are built into the system architecture in advance, cushioning against potential security breaches and unauthorized long-term access.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If manual password updates are required, then security can be maintained, but productivity deteriorates due to additional user input requirements

Engineering Contradiction:
ImprovesecurityVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication system performs self-service by automatically managing password expiration and updates without requiring user intervention. When a password approaches its validity limit or when software updates are deployed, the system automatically generates new credentials, updates the database, and maintains continuity of access, thereby maintaining security while eliminating manual update requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system ensures continuity of useful action by maintaining automatic authentication functionality throughout the entire credential lifecycle. From initial login through periodic updates to final expiration, the system continuously manages credentials without interruption or manual intervention, ensuring uninterrupted access while maintaining security standards.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8959349B2Method and apparatus for key sharing over remote desktop protocol
Publication Date: 2015.02.17 STONEWARE INC
  • US8959349B2 patent drawing
  • US8959349B2 patent drawing
  • US8959349B2 patent drawing

AI summary

Various methods for the secure exchange of private keys for authenticating a user to an RDP service are provided. One example method may comprise receiving a request comprising a session token to provide a user with access to an RDP service, and retrieving a username and password associated with the user using the session token. The method may further comprise assigning a time period of validity to the password. Furthermore, the method may comprise generating a first secret key based on user information, generating a second secret key based on the first secret key and a salt, and encrypting a packet comprising the password and the time period using the second secret key. Additionally, the method may comprise transmitting the username and encrypted packet to the device for authenticating the user with the requested RDP service. Similar and related example methods, apparatuses, systems, and computer program products are also provided.