Terminal Services Gateway Reverse RDP Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote assistance is challenging when users behind NAT firewalls or corporate networks need help, as existing solutions are insecure and impose scalability limitations or risk network security by requiring port openings.

Innovation Solution

A terminal services gateway enables a reverse RDP connection, allowing a helpdesk server to act as the terminal services client and tunnel RDP data through NAT firewalls using a TS gateway protocol, reversing roles to enable secure remote assistance sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an intermediary node on the Internet is used to connect helper and helpee, then remote assistance can be established, but security is compromised and scalability is limited

Engineering Contradiction:
Improveremote assistance connectionVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses a Terminal Services Gateway as a secure intermediary that mediates connections between RDP clients and terminal servers. The gateway maintains security by requiring authentication and using secure protocols (RPC/HTTPS with SSL), while still enabling remote assistance connections. This resolves the contradiction by providing a controlled intermediary that ensures security while facilitating connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If port opening or mapping is configured on firewalls to enable remote assistance, then connectivity is achieved, but network security is compromised

Engineering Contradiction:
Improveremote assistance connectivityVSAvoidnetwork security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of opening firewall ports to allow incoming connections to terminal servers, the patent inverts the approach by having terminal servers initiate outbound connections through the firewall to RDP clients. The TS gateway accepts incoming connections on a single port, then establishes outbound RDP connections to clients. This inversion maintains firewall security while enabling remote assistance functionality.

Inventive Principle:
Principle #13The other way round (Inversion)

3Extent of automation

If traditional terminal services architecture is used with terminal servers inside corporate networks, then centralized management is achieved, but accessibility from external networks is limited

Engineering Contradiction:
Improvecentralized terminal services managementVSAvoidexternal network accessibility
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The Terminal Services Gateway serves multiple functions: it acts as an authentication server, a connection broker, and a protocol translator between RPC/HTTPS and RDP protocols. This multi-functionality allows the gateway to maintain centralized terminal services management while simultaneously providing external network accessibility through secure web-based connections.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9438662B2Enabling secure remote assistance using a terminal services gateway
Publication Date: 2016.09.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9438662B2 patent drawing
  • US9438662B2 patent drawing
  • US9438662B2 patent drawing

AI summary

A secure remote assistance session between computers that are behind firewalls and/or NAT devices is provided by an arrangement that uses a terminal services (“TS”) gateway to enable utilization of a remote desktop protocol (“RDP”) connection by a terminal services client in a reverse direction to that used in a conventional terminal services session. The connection is made via a regular TS gateway protocol mechanism by which the TS client behind a firewall establishes a connection to the remote server that is typically behind a firewall that protects a corporate network. The server then functions as the terminal services client to tunnel RDP data through the established TS gateway connection through the NAT firewall to a client. Thus, the server and client reverse roles after the TS gateway connection is made to thereby enable remote viewing of the graphical user interface that is displayed by the client in support of the remote assistance session.