RDP Session Control via Gateway Agent for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote desktop applications face security issues due to open ports and firewall penetrations, limited management device visibility, and increased time and bandwidth usage as the number of participants grows, necessitating an improved system for secure and efficient remote desktop connections.

Innovation Solution

Implementing an endpoint management agent with high privilege on client devices to coordinate remote desktop protocol (RDP) sessions, providing security credentials, and enabling secure remote-control interfaces that transmit visual data and relay commands, while managing network resources effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional remote desktop applications are used to enable remote access, then flexibility in office locations and optimization of computing resources are improved, but security issues arise due to open ports and firewall penetrations

Engineering Contradiction:
Improveflexibility in office locationsVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a remote desktop gateway server as an intermediary component that mediates all remote desktop connections. Instead of direct peer-to-peer connections that require open ports, the gateway server acts as a secure intermediary that authenticates users, establishes encrypted tunnels, and relays traffic. This eliminates the need for firewall penetrations while maintaining remote access flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of opening network ports and creating direct connections with a software-based secure tunneling mechanism. The gateway server establishes encrypted communication channels that substitute for physical port openings, providing security while maintaining connectivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If management devices attempt to gain visibility and control into remote desktop connections, then security and management capabilities are improved, but additional security and privacy issues arise that limit involvement

Engineering Contradiction:
Improvemanagement visibilityVSAvoidsecurity and privacy issues
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The gateway server serves as a trusted intermediary that management devices can securely interact with. Instead of management devices directly penetrating into remote desktop sessions (which creates security issues), they communicate through the gateway's management interface. The gateway mediates between management requirements and session privacy, allowing visibility without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the gateway server provides management devices with information about active sessions, user authentication status, and connection metrics. This feedback loop enables management visibility and control without requiring direct access into the private communication channels between remote desktop participants.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the number of participants in remote desktop applications increases, then collaboration capabilities are improved, but time and bandwidth usage increase

Engineering Contradiction:
Improvenumber of participantsVSAvoidbandwidth usage
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent segments the remote desktop traffic into different communication channels: data traffic flows through encrypted tunnels between clients and the gateway, while visual data is optimized and compressed. The gateway segments management traffic from user traffic, allowing efficient resource allocation and reducing overall bandwidth consumption as participant numbers increase.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway server implements efficient copying and caching mechanisms where visual data from the host system is selectively transmitted to multiple clients. Instead of each client receiving complete duplicate streams, the gateway intelligently copies and distributes only necessary visual updates, reducing total bandwidth usage while supporting multiple participants.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250007976A1Agent-based remote desktop protocol session control
Publication Date: 2025.01.02 IVANTI INC
  • US20250007976A1 patent drawing
  • US20250007976A1 patent drawing
  • US20250007976A1 patent drawing

AI summary

A method of remote desktop protocol (RDP) operating system (OS) session remote-control includes providing security credentials to a client device. The method includes requesting OS sessions currently operating on the client device. The method includes receiving from an agent on the client device, an indication of OS sessions currently operating on the client device. The OS sessions include one or more RDP OS sessions and a console OS session. The method includes selecting a first RDP OS session of the one or more RDP OS sessions. Responsive to the selection of the first RDP OS session, the method includes communicating with an agent an instruction to initiate a remote-control interface with the client device. The remote-control interface is configured such that the agent transmits visual data of the RDP OS session to the service device and relays commands from the service device.