Thin Client Session Credential Encryption and Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems often require users to enter their logon credentials multiple times when establishing a terminal services session, leading to user irritation and increased session establishment delays.

Innovation Solution

A mechanism that allows users to authenticate their credentials once, using a session allocation manager and trust authority system to securely redirect and validate credentials, eliminating the need for multiple prompts by encrypting and decrypting credentials within a predetermined time frame.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems are used to establish terminal services sessions, then security validation is ensured, but users are prompted multiple times for credentials causing delays and irritation

Engineering Contradiction:
Improveauthentication securityVSAvoidsession establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by capturing user credentials at the client terminal before the actual terminal services session establishment. The Session Allocation Manager validates credentials in advance and establishes a trusted relationship, so that when the terminal connects to the server, authentication has already been completed preliminarily, avoiding repeated credential prompts during session setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a Session Allocation Manager as an intermediary component that mediates between the client terminal and the terminal server. This intermediary captures credentials from the client, validates them against the server, and establishes a trusted session allocation. The intermediary enables single credential entry by bridging the authentication gap between client and server without requiring multiple credential prompts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple credential prompts are used during terminal services session establishment, then authentication security is maintained, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by capturing user credentials at the client terminal before the actual terminal services session establishment. The Session Allocation Manager validates credentials in advance and establishes a trusted relationship, so that when the terminal connects to the server, authentication has already been completed preliminarily, avoiding repeated credential prompts during session setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a Session Allocation Manager as an intermediary component that mediates between the client terminal and the terminal server. This intermediary captures credentials from the client, validates them against the server, and establishes a trusted session allocation. The intermediary enables single credential entry by bridging the authentication gap between client and server without requiring multiple credential prompts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8161154B2Establishing a thin client terminal services session
Publication Date: 2012.04.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8161154B2 patent drawing
  • US8161154B2 patent drawing
  • US8161154B2 patent drawing

AI summary

An encrypted credential is received from a client terminal, where the encrypted credential is based on encryption of an authentication credential input by a user at the client terminal for allocating resources from a central server, the resources to provide a thin client terminal services session. A thin client terminal services session is established between the client terminal and the central server using the allocated resources, where establishing the thin client terminal services session include receiving a decryption key from a remote system, and decrypting the encrypted credential using the decryption key.