Terminal Services Gateway Two-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing server resources outside a firewall, such as VPN technology, are difficult to set up and maintain, and do not provide a secure solution for corporate intranets, as they expose the server to potential attacks when directly connected to the Internet.

Innovation Solution

Implementing a Terminal Services Gateway (TSG) with two-factor authentication using an independent authentication server and a token-based mechanism, where a client device receives a one-time password token from the authentication server, which is then verified before accessing the terminal services or gateway server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VPN technology is used to access server resources outside the firewall, then remote access capability is improved, but device complexity and difficulty of setup/maintenance worsen

Engineering Contradiction:
Improveremote access capabilityVSAvoidsetup and maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Terminal Services Gateway (TSG) as an intermediary component that mediates between remote clients and terminal services servers. The TSG handles authentication, protocol conversion, and connection management, allowing clients to access terminal services through a standardized interface without requiring complex VPN configurations. This intermediary simplifies the overall system architecture by centralizing the complexity in a manageable gateway component rather than requiring complex client-side VPN setups.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If server is directly connected to the Internet for remote access, then accessibility is improved, but security worsens due to exposure to attacks

Engineering Contradiction:
ImproveaccessibilityVSAvoidserver exposure to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The TSG acts as a security intermediary that sits between the Internet and the terminal services server. It handles all external connections and authentication requests, preventing direct Internet access to the server. The gateway validates credentials, manages security policies, and controls what resources external users can access, thereby maintaining server security while enabling remote accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network architecture into distinct zones: the public Internet zone, the gateway zone (TSG), and the private server zone. This segmentation isolates the server from direct Internet exposure while allowing controlled access through the gateway. The firewall further segments network traffic, creating layered security that protects the server while maintaining accessibility.

Inventive Principle:
Principle #1Segmentation

3Reliability

If two-factor authentication with token-based mechanism is implemented, then security is improved, but device complexity worsens

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The TSG serves as an intermediary that manages the two-factor authentication process. It handles token issuance, validation, and integration with the terminal services authentication system. By centralizing authentication management in the gateway, the system achieves enhanced security without requiring complex authentication logic in each client or server component. The gateway absorbs the complexity of implementing secure two-factor authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8756660B2Enabling two-factor authentication for terminal services
Publication Date: 2014.06.17 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8756660B2 patent drawing
  • US8756660B2 patent drawing
  • US8756660B2 patent drawing

AI summary

Techniques for enabling two-factor authentication for terminal services are described. A client receives an authentication token from an authentication server. The authentication token is used as a factor for authenticating the client to a terminal services device. Native authentication of the client is also performed.