Remote Desktop Session Controller Access Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote desktop session host servers face security threats due to non-administrative users' access to non-core functionalities, which can lead to reconnaissance and data breaches.
Innovation Solution
A system that restricts users' access to non-core functionalities by identifying and disabling executable files, shared object library files, and registration keys necessary for these functionalities, using a remote desktop experience controller to enforce access limitations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users are granted access to all functionalities of an application on a remote desktop server, then ease of operation is improved, but security deteriorates due to potential reconnaissance and data breaches
Solution Approach 1:
The patent segments application functionalities into core and non-core categories. The remote desktop experience controller identifies and separates essential core functionalities from optional non-core functionalities, allowing selective access control. This segmentation enables the system to grant users access only to core functionalities by default, while maintaining the ability to provide non-core functionalities to authorized users with elevated permissions, thus resolving the contradiction between ease of operation and security.
Solution Approach 2:
The patent applies local quality by customizing access permissions at different levels within the application structure. Core functionalities are accessible to all authenticated users, while non-core functionalities are restricted to users with specific roles or permissions. This localized differentiation of access rights allows the system to maintain broad accessibility for essential functions while securing sensitive non-core functions, balancing ease of operation with security requirements.
2Productivity
If the system provides comprehensive access to applications on remote desktop sessions, then productivity is improved, but reliability deteriorates due to increased security vulnerabilities
Solution Approach 1:
The patent implements preliminary action by pre-identifying and classifying functionalities as core or non-core before users access the application. The remote desktop experience controller proactively determines which functionalities are essential and which are optional, establishing access control rules in advance. This preliminary classification allows the system to maintain high productivity by enabling comprehensive access when needed while ensuring reliability through pre-established security boundaries that prevent unauthorized access to critical components.
Solution Approach 2:
The patent incorporates feedback mechanisms where the remote desktop experience controller continuously monitors user access patterns and authentication credentials. Based on this feedback, the system dynamically adjusts access permissions to non-core functionalities. Users who demonstrate trusted behavior patterns may be granted access to additional functionalities, enhancing productivity, while users showing suspicious behavior have access restricted, maintaining reliability and security stability.
3Object-affected harmful factors
If the system disables access to non-core functionalities, then security is improved, but ease of operation deteriorates due to limited functionality
Solution Approach 1:
The patent applies dynamics by making access permissions flexible and adaptable rather than static. The remote desktop experience controller dynamically determines which users should access core versus non-core functionalities based on their authentication status, role, and behavior patterns. This dynamic access control allows the system to maintain strong security by restricting non-core functionalities to authenticated users with appropriate permissions, while still providing full functionality to trusted users, thus balancing security protection with ease of operation.
Solution Approach 2:
The patent introduces the remote desktop experience controller as an intermediary between users and the application functionalities. This intermediary component manages the complexity of access control by automatically determining which functionalities should be accessible based on user credentials and security policies. The controller acts as a mediator that translates security requirements into practical access decisions, allowing users to access full functionality when authorized while maintaining security boundaries, thus resolving the contradiction between security protection and ease of operation.
Data Source
AI summary
A system discloses providing secure remote desktop session host experience to a user for a selected application while controlling the user's access to non-core functionalities of the selected application. An implementation of the system disclosed herein identifies a non-core functionality of an application running on a server, flags the executable files, shared object library files, and the registration keys necessary for the non-core functionality of the application, and disables the application's access to the identified executable files, the identified shared object library files, and the identified registration keys.


