Virtual Delivery Appliance Biometric Authentication Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems in virtual environments, such as virtual desktops, face challenges due to the absence of Trusted Platform Modules (TPM) and biometric devices, leading to security issues with password-based authentication, including phishing attacks and user convenience problems, as they are not scalable and prone to privacy concerns.
Innovation Solution
A biometric authentication framework that leverages the crypto-processor at client devices to provide FIDO2-based passwordless authentication services, securely redirecting authentication flows and utilizing endpoint device capabilities, even in environments without native FIDO2 capabilities, by pairing with FIDO2-capable mobile devices for secure authentication operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used in virtual environments, then authentication can be performed, but security is compromised due to phishing attacks and server breaches
Solution Approach 1:
The patent introduces a biometric authentication intermediary system that mediates between the user and the virtual environment. The biometric data is processed locally on the client device through a biometric processor, creating a secure intermediary layer that prevents direct exposure of authentication credentials to potential phishing attacks or server breaches. The biometric processor generates authentication responses without exposing the actual biometric data or private keys.
Solution Approach 2:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of relying on users to remember and input passwords (mechanical process), the system uses biometric characteristics (fingerprint, face, iris) processed through cryptographic operations to generate authentication responses, fundamentally changing the authentication mechanism from something users know to something users are.
2Reliability
If biometric devices are integrated into virtual desktops, then authentication security is improved, but device complexity increases due to absence of native FIDO2 capabilities
Solution Approach 1:
The patent segments the authentication system into distinct functional components: the biometric data collection module on the client device, the biometric processor that performs cryptographic operations, and the virtualization system that provides the authentication interface. This segmentation allows each component to be optimized independently and reduces overall system complexity by distributing functionality across multiple specialized modules.
Solution Approach 2:
The patent creates a universal biometric authentication framework that can operate across different virtualization environments and client devices. The biometric processor implements standard cryptographic operations that can handle various biometric modalities (fingerprint, face, iris) and work with different virtual desktop infrastructure systems, making the solution multi-functional and reducing the need for device-specific implementations.
3Ease of operation
If passwords are eliminated in favor of biometric authentication, then user convenience is improved, but system compatibility challenges arise in virtual environments
Solution Approach 1:
The patent changes the fundamental parameter of authentication from password-based (something users know) to biometric-based (something users are). This parameter change improves user convenience by eliminating the need to remember and input passwords, while the underlying cryptographic operations maintain compatibility with existing authentication protocols and systems.
Solution Approach 2:
The patent creates a virtual copy of the biometric authentication process that runs within the virtualized environment. The biometric processor on the client device generates authentication responses that are copied and transmitted to the virtual desktop system, allowing the virtual environment to use biometric authentication without requiring native FIDO2 hardware integration in the virtualized components.
Data Source
AI summary
A virtual delivery appliance may communicate with a client device over a network to provide the client device with a virtualized session for a user. A processor may be configured to communicate with the client device over the network to perform a registration operation with a relying party. An application within the virtualized session may perform an authentication operation with the relying party to access a resource. The processor may be configured to forward an authentication challenge message to the client device in response to the application receiving the authentication challenge message from the relying party for the user to access the resource, and receive an authentication answer message in response to the authentication challenge message from the client device.


