Virtual Desktop Access Device Group-Based Privilege Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in securely managing user authorization and privilege levels within virtual desktop environments, particularly when access devices lack native directory service support, leading to restricted functionality and security vulnerabilities.

Innovation Solution

Implementing a directory service system with group-based privilege logic in virtual desktop environments, where access devices are authenticated and authorized based on user groups, enabling or restricting functions accordingly, and using a user privilege module to enforce tiered access levels without relying on robust authentication systems or native directory services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If access devices lack native directory service support, then device complexity is reduced, but user authorization security and functionality are compromised

Engineering Contradiction:
Improveaccess device complexityVSAvoiduser authorization security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a virtual desktop infrastructure (VDI) directory service as an intermediary between access devices and user authentication. The VDI directory service handles directory service operations for access devices that lack native support, mediating authentication and authorization requests. This allows simple access devices to gain secure directory service capabilities through the intermediary VDI system, resolving the contradiction between device simplicity and authorization security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access devices have restricted functionality due to lack of authentication system, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal privilege level system that can be applied across multiple access devices with different capabilities. The VDI directory service provides a unified authorization framework that works with various device types (thin clients, thick clients, mobile devices), enabling each device to operate at appropriate privilege levels without requiring native directory service support. This universal approach maintains security while enabling broad device functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts device functionality based on authenticated privilege levels. After successful authentication through the VDI directory service, access devices receive appropriate privilege levels that enable or disable specific functions. This dynamic adjustment allows devices to start with restricted functionality for security, then gain appropriate operational capabilities based on user credentials and authorization policies.

Inventive Principle:
Principle #15Dynamics

3Reliability

If group-based privilege logic is implemented, then user authorization control is improved, but device complexity increases

Engineering Contradiction:
Improveuser authorization controlVSAvoidprivilege logic complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex group-based privilege logic from individual access devices and centralizes it in the VDI directory service. Access devices only need to communicate authentication requests and receive privilege level assignments, without implementing complex group management or privilege logic locally. This extraction maintains strong authorization control through centralized group policies while keeping access devices relatively simple.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10652247B2System and method for user authorization in a virtual desktop access device using authentication and authorization subsystems of a virtual desktop environment
Publication Date: 2020.05.12 DELL PROD LP
  • US10652247B2 patent drawing
  • US10652247B2 patent drawing
  • US10652247B2 patent drawing

AI summary

A virtual desktop system includes a directory service system and an access device. The directory service system include a group list, each group including a list of authorized users and an associated privilege level. The access device includes privilege logic to implement privilege levels, each privilege level being associated with one of the groups. The access device is only permitted to log on to the directory service to the exclusion of other functions of the access device until the access device receives an indication of a particular group from the directory service. The directory service receives a log on from a user of the access device, authenticates the user as being associated with the particular group, and sends the indication to the access device. The privilege logic enables the other functions of the access device in accordance with the privilege level associated with the particular group.