Remote Session Certificate Trust for Secure BYOD Connections
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unmanaged or partially managed user devices face challenges in trusting certificates from secure servers due to lack of installed certificates, leading to potential security risks and user experience issues, especially in BYOD arrangements.
Innovation Solution
User devices establish secure connections through remote user sessions, such as virtualized applications or cloud-based applications, to determine certificate trust using a remote user session's certificate store, eliminating the need for manual installation and local certificate updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional certificates are pushed to unmanaged user devices, then certificate trust is improved, but device complexity and user resistance increase
Solution Approach 1:
A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.
Solution Approach 2:
The system enables self-service by allowing user devices to establish secure connections without manual certificate installation. The gateway automatically manages certificate validation and secure connection establishment, freeing users from complex certificate management tasks.
2Reliability
If manual certificate installation is required, then certificate trust is improved, but ease of operation deteriorates
Solution Approach 1:
The system enables self-service by allowing user devices to establish secure connections without manual certificate installation. The gateway automatically manages certificate validation and secure connection establishment, freeing users from complex certificate management tasks.
Solution Approach 2:
A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.
3Ease of operation
If certificates are not installed on unmanaged devices, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.
Solution Approach 2:
Instead of copying certificates to each unmanaged user device, the system creates a virtual copy of the secure connection environment at the gateway. The gateway maintains the necessary certificates and security credentials, then replicates the secure connection experience for multiple users without distributing sensitive certificate data.
4Ease of operation
If remote user sessions are used to determine certificate trust, then ease of operation is improved, but device complexity increases
Solution Approach 1:
A gateway server acts as an intermediary between the enterprise and unmanaged user devices. The gateway receives certificates from the enterprise, validates them, and then establishes secure connections to remote servers on behalf of user devices. This eliminates the need to install certificates directly on unmanaged devices while maintaining security trust.
Solution Approach 2:
Instead of copying certificates to each unmanaged user device, the system creates a virtual copy of the secure connection environment at the gateway. The gateway maintains the necessary certificates and security credentials, then replicates the secure connection experience for multiple users without distributing sensitive certificate data.
Data Source
AI summary
Methods and systems for establishing trust in certificates based on remote user sessions are described herein. A computing device may establish, via a gateway, one or more remote user sessions of virtualized application, cloud-based applications, and/or remote desktops. The computing device may initiate an establishment process for a secure connection with a secure server. The computing device may, as part of the establishment process, may receive a certificate for the secure server. The computing device may locally determine whether the certificate is trusted. If the certificate is not trusted, the computing device may select a remote user session to perform a remote attempt for determining trust in the certificate. The computing device may send the certificate to the selected remote user session and may receive data indicating a result of the remote attempt. The computing device may determine whether the certificate is trusted by the remote attempt.


