Remote Session Certificate Trust for Secure BYOD Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unmanaged or partially managed user devices face challenges in trusting certificates from secure servers due to lack of installed certificates, leading to potential security risks and user experience issues, especially in BYOD arrangements.

Innovation Solution

User devices establish secure connections through remote user sessions, such as virtualized applications or cloud-based applications, to determine certificate trust using a remote user session's certificate store, eliminating the need for manual installation and local certificate updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional certificates are pushed to unmanaged user devices, then certificate trust is improved, but device complexity and user resistance increase

Engineering Contradiction:
Improvecertificate trustVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing user devices to establish secure connections without manual certificate installation. The gateway automatically manages certificate validation and secure connection establishment, freeing users from complex certificate management tasks.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual certificate installation is required, then certificate trust is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvecertificate trustVSAvoidcertificate installation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service by allowing user devices to establish secure connections without manual certificate installation. The gateway automatically manages certificate validation and secure connection establishment, freeing users from complex certificate management tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If certificates are not installed on unmanaged devices, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improvecertificate installationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of copying certificates to each unmanaged user device, the system creates a virtual copy of the secure connection environment at the gateway. The gateway maintains the necessary certificates and security credentials, then replicates the secure connection experience for multiple users without distributing sensitive certificate data.

Inventive Principle:
Principle #26Copying

4Ease of operation

If remote user sessions are used to determine certificate trust, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvecertificate installationVSAvoidconnection establishment
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of copying certificates to each unmanaged user device, the system creates a virtual copy of the secure connection environment at the gateway. The gateway maintains the necessary certificates and security credentials, then replicates the secure connection experience for multiple users without distributing sensitive certificate data.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12531846B2Trusting a certificate for a secure connection based on a remote user session
Publication Date: 2026.01.20 CITRIX SYSTEMS INC
  • US12531846B2 patent drawing
  • US12531846B2 patent drawing
  • US12531846B2 patent drawing

AI summary

Methods and systems for establishing trust in certificates based on remote user sessions are described herein. A computing device may establish, via a gateway, one or more remote user sessions of virtualized application, cloud-based applications, and/or remote desktops. The computing device may initiate an establishment process for a secure connection with a secure server. The computing device may, as part of the establishment process, may receive a certificate for the secure server. The computing device may locally determine whether the certificate is trusted. If the certificate is not trusted, the computing device may select a remote user session to perform a remote attempt for determining trust in the certificate. The computing device may send the certificate to the selected remote user session and may receive data indicating a result of the remote attempt. The computing device may determine whether the certificate is trusted by the remote attempt.