VDI Client Access Filters for Per-Resource VM Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtual desktop infrastructure (VDI) clients grant or restrict access to resources on a per-user basis, leading to security issues by providing full access to unnecessary files or devices, as access is either completely allowed or denied, rather than being tailored to specific needs.

Innovation Solution

Implementing access filters at the client device to enforce customized access rules, allowing only necessary resources to be accessed by a remote virtual machine (VM) based on user input or automatic generation from user actions, thereby granting or denying access on a per-file or per-device basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the VDI client grants access to resources on a per-user basis, then ease of operation is improved, but security is worsened because full access is provided to unnecessary files or devices

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments access control from user-level to resource-level granularity. Instead of granting or denying access to entire folders or devices based on user identity, the system divides control into individual file or device-level permissions. The VDI client evaluates each resource access request independently against a policy, allowing precise control over which specific files or devices are accessible while blocking others at the same level. This segmentation resolves the contradiction by maintaining ease of operation through automated per-resource evaluation while improving security by preventing unnecessary broad access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing differentiated access policies for different resources within the same user session. Rather than applying a uniform access rule across all resources for a given user, the system assigns specific access permissions to individual files or devices based on local characteristics and policies. Each resource can have its own access criteria evaluated independently, allowing the system to grant access to necessary resources while denying access to unnecessary ones, thus resolving the security issue without compromising operational ease.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If the VDI client restricts access to resources, then security is improved, but ease of operation is worsened because access is completely denied rather than tailored to specific needs

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments the access control decision-making process into individual resource evaluations. Instead of applying a blanket restriction that completely denies access to all resources for a user, the system divides control into discrete file or device-level decisions. Each resource access request is evaluated independently against the policy, allowing the system to maintain security through restrictive policies while improving ease of operation by automatically granting access to specific necessary resources without requiring manual configuration for each case.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service by enabling the VDI client to automatically evaluate and make access control decisions based on predefined policies without requiring manual intervention. The system autonomously determines whether to grant or deny access to each resource by evaluating the access request against the policy criteria, thereby maintaining security through restrictive policies while improving ease of operation by eliminating the need for manual access management and enabling seamless resource access when permissions are satisfied.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the VDI client grants access to more files or devices than necessary, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments access control to the individual file or device level, allowing the VDI client to evaluate each resource access request independently against the policy. This granular segmentation enables the system to grant access to only the specific files or devices necessary to fulfill the request, rather than granting broad access to entire folders or device types. By dividing control into discrete resource-level decisions, the system maintains ease of operation through automated evaluation while preventing unnecessary access that would compromise security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by granting access to only the specific subset of files or devices necessary to fulfill the access request, rather than granting complete access to all resources of a certain type. The VDI client evaluates each resource individually and grants access only where the policy permits, providing the minimum necessary access rather than excessive access. This approach maintains ease of operation by enabling necessary resource access while improving security by limiting access to only what is required.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10986215B2Access control in the remote device of network redirector
Publication Date: 2021.04.20 OMNISSA LLC
  • US10986215B2 patent drawing
  • US10986215B2 patent drawing
  • US10986215B2 patent drawing

AI summary

An approach for accessing one or more resources at a virtualized desktop infrastructure (VDI) client running on a client device by a remote virtual machine (VM) is provided. The method includes intercepting, via a VDI agent, a request to access one or more resources at the client device, transferring the request from the remote VM to the client device via a network redirector protocol, and filtering the request to determine if the request complies with one or more rules. For a first resource of the one or more resources, if the request does not comply with any one of one or more first rules of the one or more rules, access to the first resource is denied. If the request complies with the one or more first rules, access to the first resource is granted and a response is sent to the VDI agent via the network redirector protocol.