Terminal Server Remote Login via Data Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional remote login methods, such as single sign-on (SSO) and user bind authentication, cannot analyze data flow on terminal servers, making it impossible to implement remote login in these systems.

Innovation Solution

A method and device that analyze and match data flow in the terminal server to allow remote login by recording and saving login information, and using pre-configured rules to determine if the user can access the internal system, with options for automatic or manual input of login information based on SSO authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional SSO authentication or user bind authentication is used, then authentication can be performed in client applications, but remote login cannot be implemented on terminal servers because data flow analysis is not available

Engineering Contradiction:
Improveremote login capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a terminal server as an intermediary component between the client and the internal system. The terminal server captures and analyzes authentication data flow, enabling SSO and user bind authentication methods to work in remote login scenarios where direct client-server authentication would otherwise be impossible.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of direct client authentication with a data flow analysis mechanism. Instead of relying on client-side plugins or manual input, the system uses automated capture and analysis of authentication data packets transmitted through the terminal server, substituting mechanical interaction with automated electronic monitoring.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If manual input of login information is required, then security can be maintained, but user convenience and login efficiency deteriorate

Engineering Contradiction:
Improvelogin convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-configuring authentication rules and capturing login information in advance. The terminal server records and analyzes authentication data flows before actual login attempts, preparing the system to automatically verify credentials without requiring manual user input during the login process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by monitoring authentication data flows and using the analyzed results to automatically control the login process. The terminal server receives authentication information, analyzes it against predefined rules, and provides feedback that automatically approves or denies login attempts, eliminating the need for manual user input while maintaining security.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If data flow analysis is implemented on terminal servers, then remote login can be achieved, but the complexity of the authentication process increases

Engineering Contradiction:
Improveremote login functionalityVSAvoiddata flow analysis complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the authentication process into distinct functional modules: data flow capture, data flow analysis, rule matching, and authentication decision-making. The terminal server is segmented into specific components that handle each aspect of the authentication process independently, making the overall complex system manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9111077B2Method and device for realizing remote login
Publication Date: 2015.08.18 SANGFOR TECH INC
  • US9111077B2 patent drawing
  • US9111077B2 patent drawing
  • US9111077B2 patent drawing

AI summary

The present disclosure provides a method and a device for realizing remote login. The method includes: a terminal server responding to a login request to an internal system from an end user, and recording and saving login information of the end user for logging in to the internal system; and the terminal server judging and analyzing the way the end user logs in to the internal system according to the login information and pre-configured rule, and allowing the end user to log in to and access the internal system if the analyzed result matches the pre-configured rule. The method and device allows for implementations of the SSO authentication and user bind authentication on the aspect of the data flow in the terminal server, simplifies the process of logging in to and accessing the internal system, and improves the information security of the system.