Trusted Path Authentication for Secure Remote Desktop Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for remote desktop access often compromise user security and efficiency due to lack of awareness about resource execution, limited access to local operating systems, and user confusion from multiple interfaces, while also requiring cumbersome authentication processes.

Innovation Solution

A method and system that authenticate users of desktop appliances to remote machines using a trusted component, processing secure attention sequences to minimize user interaction and maintain familiar local operating system interactions, leveraging existing components without replacing them, and ensuring secure access through a broker service and remote machine authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a desktop appliance provides remote desktop access without user awareness, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted path mechanism as an intermediary between the user and the remote desktop system. This trusted path provides verified information about the remote system's identity and security state, allowing users to make informed decisions about connecting without sacrificing ease of operation. The broker service acts as another intermediary that mediates authentication and connection establishment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple interfaces are provided for accessing local and remote operating systems, then adaptability is improved, but ease of operation is worsened due to user confusion

Engineering Contradiction:
ImproveadaptabilityVSAvoidease of operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges the local and remote desktop interfaces into a unified experience. The remote desktop is presented through the local desktop environment, creating a seamless integration where users interact with a single unified interface rather than switching between multiple separate interfaces. This reduces user confusion while maintaining adaptability.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If a user is prevented from accessing the local operating system while connected to remote desktop, then security is improved, but adaptability is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the level of user access to the local operating system adjusts based on the connection state and security requirements. When connected to remote desktop, certain local functions are restricted for security, but the trusted path mechanism provides dynamic verification and information display. The system can dynamically switch between different access modes based on user actions and security context.

Inventive Principle:
Principle #15Dynamics

4Reliability

If cumbersome authentication processes are implemented, then security is improved, but productivity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication through the broker service before the actual remote desktop connection is established. User credentials are verified in advance, and authentication tokens or tickets are obtained beforehand. This preliminary action streamlines the connection process, allowing users to connect quickly without repeated authentication steps while maintaining strong security through the broker's verification process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2241084B1Systems and methods for secure handling of secure attention sequences
Publication Date: 2021.03.31 CITRIX SYSTEMS INC
  • EP2241084B1 patent drawingFigure 1A
  • EP2241084B1 patent drawingFigure 1B
  • EP2241084B1 patent drawingFigure 1C

AI summary

A method for authenticating, by a trusted component, a user of a desktop appliance to a remote machine includes executing, by a desktop appliance, a user interaction component, responsive to receiving a secure attention sequence from a user. The user interaction component receives authentication credentials associated with the user. The desktop appliance transmits, to a broker service, the received authentication credentials. The broker service authenticates the user, responsive to the received authentication credentials. The broker service transmits, to a remote machine, authentication data associated with the received authentication credentials. The remote machine authenticates the user, responsive to the received authentication data. The remote machine provides, to the desktop appliance, access to a resource requested by the user. In another aspect, a trusted component provides, to a user of a desktop appliance, access to secure desktop functionality provided by a remote machine.