RDP Session Control via Gateway Agent for Secure Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional remote desktop applications face security issues due to open ports and firewall penetrations, limited management device visibility, and increased time and bandwidth usage as the number of participants grows, necessitating an improved system for secure and efficient remote desktop connections.
Innovation Solution
Implementing an endpoint management agent with high privilege on client devices to coordinate remote desktop protocol (RDP) sessions, providing security credentials, and enabling secure remote-control interfaces that transmit visual data and relay commands, while managing network resources effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional remote desktop applications are used to enable remote access, then flexibility in office locations and optimization of computing resources are improved, but security issues arise due to open ports and firewall penetrations
Solution Approach 1:
The patent introduces a remote desktop gateway server as an intermediary component that mediates all remote desktop connections. Instead of direct peer-to-peer connections that require open ports, the gateway server acts as a secure intermediary that authenticates users, establishes encrypted tunnels, and relays traffic. This eliminates the need for firewall penetrations while maintaining remote access flexibility.
Solution Approach 2:
The patent replaces the traditional mechanical approach of opening network ports and creating direct connections with a software-based secure tunneling mechanism. The gateway server establishes encrypted communication channels that substitute for physical port openings, providing security while maintaining connectivity.
2Reliability
If management devices attempt to gain visibility and control into remote desktop connections, then security and management capabilities are improved, but additional security and privacy issues arise that limit involvement
Solution Approach 1:
The gateway server serves as a trusted intermediary that management devices can securely interact with. Instead of management devices directly penetrating into remote desktop sessions (which creates security issues), they communicate through the gateway's management interface. The gateway mediates between management requirements and session privacy, allowing visibility without compromising security.
Solution Approach 2:
The patent implements feedback mechanisms where the gateway server provides management devices with information about active sessions, user authentication status, and connection metrics. This feedback loop enables management visibility and control without requiring direct access into the private communication channels between remote desktop participants.
3Adaptability or versatility
If the number of participants in remote desktop applications increases, then collaboration capabilities are improved, but time and bandwidth usage increase
Solution Approach 1:
The patent segments the remote desktop traffic into different communication channels: data traffic flows through encrypted tunnels between clients and the gateway, while visual data is optimized and compressed. The gateway segments management traffic from user traffic, allowing efficient resource allocation and reducing overall bandwidth consumption as participant numbers increase.
Solution Approach 2:
The gateway server implements efficient copying and caching mechanisms where visual data from the host system is selectively transmitted to multiple clients. Instead of each client receiving complete duplicate streams, the gateway intelligently copies and distributes only necessary visual updates, reducing total bandwidth usage while supporting multiple participants.
Data Source
AI summary
A method of remote desktop protocol (RDP) operating system (OS) session remote-control includes providing security credentials to a client device. The method includes requesting OS sessions currently operating on the client device. The method includes receiving from an agent on the client device, an indication of OS sessions currently operating on the client device. The OS sessions include one or more RDP OS sessions and a console OS session. The method includes selecting a first RDP OS session of the one or more RDP OS sessions. Responsive to the selection of the first RDP OS session, the method includes communicating with an agent an instruction to initiate a remote-control interface with the client device. The remote-control interface is configured such that the agent transmits visual data of the RDP OS session to the service device and relays commands from the service device.


