Virtual Desktop Infrastructure VNIC Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server-based computing systems using remote desktop protocols are vulnerable to misuse due to all applications running in the user space of the virtual machine having access to the same virtual network interface card (VNIC), allowing unauthorized access to network destinations.

Innovation Solution

Implementing two separate virtual network interface cards (VNICs) on a virtual machine, where one is exclusively accessible by the remote desktop application for management network connections and the other by other applications for product network connections, with the remote desktop application's VNIC being isolated and only accessible in the user space, enhancing security and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all applications running in the user space of the virtual machine are allowed to access the same VNIC, then the system is easier to operate and more versatile, but the system becomes vulnerable to misuse and security breaches

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the single VNIC into two separate VNICs: a first VNIC exclusively for the remote desktop application and a second VNIC for other applications. This segmentation isolates the remote desktop application's network traffic from other applications, preventing unauthorized access while maintaining individual network access capabilities for each application type.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent assigns different access permissions and network characteristics to different VNICs based on their specific functions. The first VNIC is configured with exclusive access for the remote desktop application with specific network policies, while the second VNIC is configured for other applications with different access rules, providing localized security qualities tailored to each application's needs.

Inventive Principle:
Principle #3Local quality

2Reliability

If separate VNICs are implemented for different applications, then security and reliability are enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal virtualization layer that manages multiple VNICs through a standardized interface. The virtual machine monitor and virtual switch provide multi-functional capabilities to handle network traffic routing, security policies, and resource allocation across multiple VNICs uniformly, reducing the operational complexity despite the increased number of network interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10459743B2Network isolation in virtual desktop infrastructure
Publication Date: 2019.10.29 OMNISSA LLC
  • US10459743B2 patent drawing
  • US10459743B2 patent drawing
  • US10459743B2 patent drawing

AI summary

Disclosed are methods and apparatus for isolating a connection between a client machine and a remote desktop application running on a virtual machine (VM), the remote desktop application providing a virtual desktop to the client machine. The VM is configured to execute the remote desktop application and one or more other applications. The connection between the client machine and the remote desktop application, for exchanging remote desktop protocol data, is provided by using a first virtual network interface card (VNIC) on the VM, where the first VNIC is exclusively accessible by the remote desktop application and inaccessible to the one or more other applications. Another connection between a remote server and one of the one or more other applications is provided using a second VNIC on the VM, in response to the remote desktop application receiving an indication from the virtual desktop to execute the one application.