VDI Authentication Interworking Gateway for Single-Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a virtual desktop infrastructure (VDI) environment, users face inconvenience due to the need for a two-step login process when accessing a virtual desktop and a target system, as conventional SSO technologies are hindered by the inability to exchange necessary information between the local terminal and the virtual desktop.

Innovation Solution

A system and method that employs a VDI authentication interworking gateway to receive VDI environment information, generate user authentication information, encrypt it, and transmit it to the target system for delegated authentication, enabling single-sign-on by using VDI account information, IP addresses, host names, and hardware details, and ensuring authentication validity through generation time checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional SSO technology is used in VDI environment, then single login should enable access to multiple systems, but information exchange between local terminal and virtual desktop is blocked preventing SSO functionality

Engineering Contradiction:
Improvelogin convenienceVSAvoidauthentication information exchange
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that mediates between the VDI service server and the target system. The authentication server receives authentication information from the VDI service server, validates it, and then uses it to authenticate the user at the target system. This intermediary enables information exchange across the isolation barrier by centralizing authentication logic in a trusted third-party service that can access both systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into distinct functional components: the VDI service server handles virtual desktop authentication, the authentication server handles cross-system authentication coordination, and the target system handles application-level authentication. This segmentation allows each component to operate independently within its security boundary while still enabling coordinated single-sign-on functionality through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

2Reliability

If two-step login process is implemented for VDI service system and target system, then security is maintained through separate authentication, but user convenience deteriorates due to multiple logins required

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the authentication processes of the VDI service system and the target system into a unified authentication flow. By having the authentication server coordinate both authentication events and reuse the initial VDI authentication credentials for the target system login, the system combines multiple security checks into a single user action, achieving both security and convenience.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If information exchange is enabled between local terminal and virtual desktop for SSO, then single-sign-on functionality is achieved, but security isolation between components is compromised

Engineering Contradiction:
Improvesingle-sign-on capabilityVSAvoidsecurity isolation breach
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authentication server acts as a security intermediary that receives authentication information from the VDI service server through secure interfaces, validates the credentials, and then initiates authentication with the target system. This mediator approach enables SSO functionality while maintaining security isolation because each component only communicates with the authenticated intermediary rather than directly with each other, preserving the security boundary while enabling information exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9374360B2System and method for single-sign-on in virtual desktop infrastructure environment
Publication Date: 2016.06.21 SAMSUNG SDS CO LTD
  • US9374360B2 patent drawing
  • US9374360B2 patent drawing
  • US9374360B2 patent drawing

AI summary

A system and a method for single-sign-on (SSO) in a virtual desktop infrastructure (VDI) environment are disclosed. The system includes a VDI service server configured to provide a virtual desktop environment to a user terminal according to a request from the user terminal, and a VDI authentication interworking gateway configured to receive VDI environment information of the user terminal from the VDI service server and carry out delegated user authentication for a target system in the virtual desktop environment using the VDI environment information.