RDP Client Access Through Zero Trust Cloud Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote Desktop Protocol (RDP) does not natively support zero trust network architectures, lacking the ability to monitor and authenticate user accounts accessing secure networks, necessitating workarounds or waiting for proprietary protocol updates.

Innovation Solution

Implementing a zero trust cloud environment that includes a frontend RDP server to manage connections, capture and authenticate login credentials, and monitor communications between client devices and target servers, using XRDP containers and clientless gateways to facilitate secure RDP sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If RDP protocol is used for remote desktop access, then connection capability is provided, but zero trust network architecture support is lacking

Engineering Contradiction:
Improvezero trust network securityVSAvoidprotocol functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a zero trust cloud environment as an intermediary between the RDP client and target server. This intermediary captures login credentials, performs authentication, and monitors communications, thereby adding zero trust security capabilities to the existing RDP protocol without requiring changes to the protocol itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the RDP connection into multiple components: the original RDP protocol for basic connectivity, and separate zero trust functions (credential capture, authentication, monitoring) implemented through virtual workloads and clientless gateways. This allows each component to be optimized independently.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If proprietary protocol customization is attempted, then user needs may be met, but implementation complexity increases

Engineering Contradiction:
Improveprotocol customizationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Rather than customizing the proprietary RDP protocol, the patent uses a clientless gateway as an intermediary that handles customization needs. The gateway captures credentials, authenticates users, and manages connections, keeping the original protocol unchanged and reducing implementation complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If zero trust authentication is implemented, then security is improved, but additional authentication steps are required

Engineering Contradiction:
Improveuser access securityVSAvoidconnection process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The zero trust cloud environment performs authentication automatically without requiring user intervention. The clientless gateway captures credentials and handles authentication steps autonomously, making the enhanced security transparent to the user while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12445431B2System and method for providing RDP client based RDP services through a zero trust cloud environment
Publication Date: 2025.10.14 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12445431B2 patent drawing
  • US12445431B2 patent drawing
  • US12445431B2 patent drawing

AI summary

Remote desktop protocol (RDP) is a proprietary protocol for controlling machines over a network. In order to overcome certain deficiencies of the protocol a method is disclosed utilized in a zero trust cloud environment, to provide access to a pool of RDP servers, via an RDP client or via a web based interface while simultaneously providing an authenticated and secure policy based experience.