VDI Authentication Interworking Gateway for Single-Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a virtual desktop infrastructure (VDI) environment, users face inconvenience due to the need for a two-step login process when accessing a virtual desktop and a target system, as conventional SSO technologies are hindered by the inability to exchange necessary information between the local terminal and the virtual desktop.
Innovation Solution
A system and method that employs a VDI authentication interworking gateway to receive VDI environment information, generate user authentication information, encrypt it, and transmit it to the target system for delegated authentication, enabling single-sign-on by using VDI account information, IP addresses, host names, and hardware details, and ensuring authentication validity through generation time checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional SSO technology is used in VDI environment, then single login should enable access to multiple systems, but information exchange between local terminal and virtual desktop is blocked preventing SSO functionality
Solution Approach 1:
The patent introduces an authentication server as an intermediary component that mediates between the VDI service server and the target system. The authentication server receives authentication information from the VDI service server, validates it, and then uses it to authenticate the user at the target system. This intermediary enables information exchange across the isolation barrier by centralizing authentication logic in a trusted third-party service that can access both systems.
Solution Approach 2:
The patent segments the authentication process into distinct functional components: the VDI service server handles virtual desktop authentication, the authentication server handles cross-system authentication coordination, and the target system handles application-level authentication. This segmentation allows each component to operate independently within its security boundary while still enabling coordinated single-sign-on functionality through standardized interfaces.
2Reliability
If two-step login process is implemented for VDI service system and target system, then security is maintained through separate authentication, but user convenience deteriorates due to multiple logins required
Solution Approach 1:
The patent merges the authentication processes of the VDI service system and the target system into a unified authentication flow. By having the authentication server coordinate both authentication events and reuse the initial VDI authentication credentials for the target system login, the system combines multiple security checks into a single user action, achieving both security and convenience.
3Ease of operation
If information exchange is enabled between local terminal and virtual desktop for SSO, then single-sign-on functionality is achieved, but security isolation between components is compromised
Solution Approach 1:
The authentication server acts as a security intermediary that receives authentication information from the VDI service server through secure interfaces, validates the credentials, and then initiates authentication with the target system. This mediator approach enables SSO functionality while maintaining security isolation because each component only communicates with the authenticated intermediary rather than directly with each other, preserving the security boundary while enabling information exchange.
Data Source
AI summary
A system and a method for single-sign-on (SSO) in a virtual desktop infrastructure (VDI) environment are disclosed. The system includes a VDI service server configured to provide a virtual desktop environment to a user terminal according to a request from the user terminal, and a VDI authentication interworking gateway configured to receive VDI environment information of the user terminal from the VDI service server and carry out delegated user authentication for a target system in the virtual desktop environment using the VDI environment information.


