Session Manager Locking Remote Computing via Authentication Signals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional session managers for remote computing devices, particularly thin clients, are inefficient in maintaining secure sessions due to reliance on shared local passwords and lack of effective session locking mechanisms, leading to potential unauthorized access when users fail to log off or share passwords.
Innovation Solution
A session manager that establishes a secured session between a local computing device and a remote computing device by transmitting a lock session signal from the remote device, prompting for and authenticating identification information, and locking the session using a Citrix ICA Virtual Channel, ensuring only authorized users can access and maintain the session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional session managers use shared local passwords for authentication, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent extracts the authentication mechanism from the local computing device and relocates it to the remote computing device. The session manager on the remote device handles password verification and session management, eliminating the security vulnerability of shared local passwords while maintaining ease of operation through centralized authentication management.
Solution Approach 2:
The session manager acts as an intermediary between the local computing device and the remote computing device. It mediates authentication by verifying passwords on the remote device and managing session states, thereby securing the authentication process without complicating user interaction.
2Ease of operation
If session locking mechanisms are not implemented, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The session manager implements preliminary session locking when the remote computing device detects inactivity or when a screen saver activates. This preliminary action secures the session before potential unauthorized access can occur, while automatically unlocking when the user returns, maintaining ease of operation.
Solution Approach 2:
The system implements feedback mechanisms where the session manager continuously monitors session state and user activity. When inactivity is detected, it triggers locking; when activity resumes, it triggers unlocking. This automated feedback loop secures sessions without requiring manual user intervention.
3Reliability
If manual log off procedures are required, then security is improved, but productivity deteriorates
Solution Approach 1:
The session manager implements self-service security by automatically locking sessions based on inactivity detection and automatically unlocking them when users return. This eliminates the need for manual log off procedures while maintaining security, thereby preserving productivity without compromising safety.
4Ease of operation
If screen savers are used for security, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent merges the screen saver functionality with session locking functionality. When the screen saver activates on the remote computing device, the session manager simultaneously locks the session. This combination maintains the ease of operation of screen savers while adding the security benefit of session locking, preventing unauthorized access even if the screen saver password is compromised.
Data Source
AI summary
A method for managing a session between a local computing device and a remote computing device, in which a session is established between a local computing device and a remote computing device, a lock session signal is transmitted from the remote computing device to the local computing device, a lock session signal is received at the local computing device, and the session is locked, at the local computing device. Furthermore, the user is prompted for identification information at the remote computing device, and the identification information is transmitted from the remote computing device to the local computing device. Moreover, the identification information is received at the local computing device, the identification information is authenticated at the local computing device, and the session is unlocked, at the local computing device.


