Secure Desktop Isolation for Web Conference Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional web conferencing software risks exposing presenters' sensitive information and compromising desktop integrity due to attendees' ability to access and control the presenter's working desktop during network meetings.

Innovation Solution

A secure desktop is created on the presenter's device, isolated from the working desktop, allowing only authorized applications and actions, with security policies controlling what can be run and shared, preventing access to sensitive information and reducing data transfer over VPN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the attendee is allowed to remotely control the presenter's working desktop, then the ease of operation for the meeting is improved, but the security of sensitive information on the working desktop deteriorates

Engineering Contradiction:
Improveremote control capabilityVSAvoiddesktop security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the desktop environment into two separate desktops: a working desktop for sensitive operations and a meeting desktop for remote sharing. This segmentation allows the presenter to maintain security on the working desktop while providing full control access on the meeting desktop, resolving the contradiction between remote control capability and desktop security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the attendee is restricted from running certain applications, then the security of the working desktop is improved, but the functionality for the meeting deteriorates

Engineering Contradiction:
Improvedesktop securityVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The meeting desktop acts as an intermediary environment between the attendee's remote control requests and the working desktop's protected resources. Security policies are enforced at the meeting desktop level, allowing restricted applications to be blocked without affecting the presenter's ability to run any application on the working desktop, thus maintaining both security and functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If graphics-heavy applications are allowed on the secure desktop, then the functionality for the meeting is improved, but the bandwidth consumption over VPN deteriorates

Engineering Contradiction:
Improveapplication functionalityVSAvoidbandwidth consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The system changes the parameter of graphics rendering by detecting when graphics-intensive applications are launched on the meeting desktop and switching to a low-graphics mode. This allows the meeting functionality to be maintained while dramatically reducing the bandwidth consumption over the VPN connection, resolving the contradiction between application functionality and bandwidth usage.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8370431B1Secure desktop for a network meeting
Publication Date: 2013.02.05 PULSE SECURE LLC
  • US8370431B1 patent drawing
  • US8370431B1 patent drawing
  • US8370431B1 patent drawing

AI summary

A network meeting application for providing network meetings, such as web conference meetings, runs on a presenter device. In response to a request for a network meeting from an attendee device, the presenter device creates a secure desktop separate from a working desktop. The presenter may use the secure desktop to share documents, presentations, or other applications with the attendee device. The attendee device is blocked from accessing the working desktop of the presenter device. A presenter using the presenter device may switch between the working desktop and the secure desktop. Security policies, downloaded to the presenter device from a server, determine the applications the attendee may run on the secure desktop. The secure desktop thereby protects the integrity of the presenter's working desktop during a web conference meeting, while allowing documents, presentations, or other applications to be shared with attendees via the secure desktop.