Virtual Desktop Infrastructure VNIC Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Server-based computing systems using remote desktop protocols are vulnerable to misuse due to all applications running in the user space of the virtual machine having access to the same virtual network interface card (VNIC), allowing unauthorized access to network destinations.
Innovation Solution
Implementing two separate virtual network interface cards (VNICs) on a virtual machine, where one is exclusively accessible by the remote desktop application for management network connections and the other by other applications for product network connections, with the remote desktop application's VNIC being isolated and only accessible in the user space, enhancing security and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all applications running in the user space of the virtual machine are allowed to access the same VNIC, then the system is easier to operate and more versatile, but the system becomes vulnerable to misuse and security breaches
Solution Approach 1:
The patent divides the single VNIC into two separate VNICs: a first VNIC exclusively for the remote desktop application and a second VNIC for other applications. This segmentation isolates the remote desktop application's network traffic from other applications, preventing unauthorized access while maintaining individual network access capabilities for each application type.
Solution Approach 2:
The patent assigns different access permissions and network characteristics to different VNICs based on their specific functions. The first VNIC is configured with exclusive access for the remote desktop application with specific network policies, while the second VNIC is configured for other applications with different access rules, providing localized security qualities tailored to each application's needs.
2Reliability
If separate VNICs are implemented for different applications, then security and reliability are enhanced, but device complexity increases
Solution Approach 1:
The patent implements a universal virtualization layer that manages multiple VNICs through a standardized interface. The virtual machine monitor and virtual switch provide multi-functional capabilities to handle network traffic routing, security policies, and resource allocation across multiple VNICs uniformly, reducing the operational complexity despite the increased number of network interfaces.
Data Source
AI summary
Disclosed are methods and apparatus for isolating a connection between a client machine and a remote desktop application running on a virtual machine (VM), the remote desktop application providing a virtual desktop to the client machine. The VM is configured to execute the remote desktop application and one or more other applications. The connection between the client machine and the remote desktop application, for exchanging remote desktop protocol data, is provided by using a first virtual network interface card (VNIC) on the VM, where the first VNIC is exclusively accessible by the remote desktop application and inaccessible to the one or more other applications. Another connection between a remote server and one of the one or more other applications is provided using a second VNIC on the VM, in response to the remote desktop application receiving an indication from the virtual desktop to execute the one application.


