Virtual Delivery Appliance Biometric Authentication Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems in virtual environments, such as virtual desktops, face challenges due to the absence of Trusted Platform Modules (TPM) and biometric devices, leading to security issues with password-based authentication, including phishing attacks and user convenience problems, as they are not scalable and prone to privacy concerns.

Innovation Solution

A biometric authentication framework that leverages the crypto-processor at client devices to provide FIDO2-based passwordless authentication services, securely redirecting authentication flows and utilizing endpoint device capabilities, even in environments without native FIDO2 capabilities, by pairing with FIDO2-capable mobile devices for secure authentication operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication is used in virtual environments, then authentication can be performed, but security is compromised due to phishing attacks and server breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidphishing attacks and server breach vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a biometric authentication intermediary system that mediates between the user and the virtual environment. The biometric data is processed locally on the client device through a biometric processor, creating a secure intermediary layer that prevents direct exposure of authentication credentials to potential phishing attacks or server breaches. The biometric processor generates authentication responses without exposing the actual biometric data or private keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of relying on users to remember and input passwords (mechanical process), the system uses biometric characteristics (fingerprint, face, iris) processed through cryptographic operations to generate authentication responses, fundamentally changing the authentication mechanism from something users know to something users are.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If biometric devices are integrated into virtual desktops, then authentication security is improved, but device complexity increases due to absence of native FIDO2 capabilities

Engineering Contradiction:
Improveauthentication securityVSAvoidvirtualization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: the biometric data collection module on the client device, the biometric processor that performs cryptographic operations, and the virtualization system that provides the authentication interface. This segmentation allows each component to be optimized independently and reduces overall system complexity by distributing functionality across multiple specialized modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal biometric authentication framework that can operate across different virtualization environments and client devices. The biometric processor implements standard cryptographic operations that can handle various biometric modalities (fingerprint, face, iris) and work with different virtual desktop infrastructure systems, making the solution multi-functional and reducing the need for device-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If passwords are eliminated in favor of biometric authentication, then user convenience is improved, but system compatibility challenges arise in virtual environments

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent changes the fundamental parameter of authentication from password-based (something users know) to biometric-based (something users are). This parameter change improves user convenience by eliminating the need to remember and input passwords, while the underlying cryptographic operations maintain compatibility with existing authentication protocols and systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a virtual copy of the biometric authentication process that runs within the virtualized environment. The biometric processor on the client device generates authentication responses that are copied and transmitted to the virtual desktop system, allowing the virtual environment to use biometric authentication without requiring native FIDO2 hardware integration in the virtualized components.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11876798B2Virtual delivery appliance and system with remote authentication and related methods
Publication Date: 2024.01.16 CITRIX SYSTEMS INC
  • US11876798B2 patent drawing
  • US11876798B2 patent drawing
  • US11876798B2 patent drawing

AI summary

A virtual delivery appliance may communicate with a client device over a network to provide the client device with a virtualized session for a user. A processor may be configured to communicate with the client device over the network to perform a registration operation with a relying party. An application within the virtualized session may perform an authentication operation with the relying party to access a resource. The processor may be configured to forward an authentication challenge message to the client device in response to the application receiving the authentication challenge message from the relying party for the user to access the resource, and receive an authentication answer message in response to the authentication challenge message from the client device.