Virtual Desktop Access Device Group-Based Privilege Logic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in securely managing user authorization and privilege levels within virtual desktop environments, particularly when access devices lack native directory service support, leading to restricted functionality and security vulnerabilities.
Innovation Solution
Implementing a directory service system with group-based privilege logic in virtual desktop environments, where access devices are authenticated and authorized based on user groups, enabling or restricting functions accordingly, and using a user privilege module to enforce tiered access levels without relying on robust authentication systems or native directory services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If access devices lack native directory service support, then device complexity is reduced, but user authorization security and functionality are compromised
Solution Approach 1:
The patent introduces a virtual desktop infrastructure (VDI) directory service as an intermediary between access devices and user authentication. The VDI directory service handles directory service operations for access devices that lack native support, mediating authentication and authorization requests. This allows simple access devices to gain secure directory service capabilities through the intermediary VDI system, resolving the contradiction between device simplicity and authorization security.
2Reliability
If access devices have restricted functionality due to lack of authentication system, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements a universal privilege level system that can be applied across multiple access devices with different capabilities. The VDI directory service provides a unified authorization framework that works with various device types (thin clients, thick clients, mobile devices), enabling each device to operate at appropriate privilege levels without requiring native directory service support. This universal approach maintains security while enabling broad device functionality.
Solution Approach 2:
The system dynamically adjusts device functionality based on authenticated privilege levels. After successful authentication through the VDI directory service, access devices receive appropriate privilege levels that enable or disable specific functions. This dynamic adjustment allows devices to start with restricted functionality for security, then gain appropriate operational capabilities based on user credentials and authorization policies.
3Reliability
If group-based privilege logic is implemented, then user authorization control is improved, but device complexity increases
Solution Approach 1:
The patent extracts complex group-based privilege logic from individual access devices and centralizes it in the VDI directory service. Access devices only need to communicate authentication requests and receive privilege level assignments, without implementing complex group management or privilege logic locally. This extraction maintains strong authorization control through centralized group policies while keeping access devices relatively simple.
Data Source
AI summary
A virtual desktop system includes a directory service system and an access device. The directory service system include a group list, each group including a list of authorized users and an associated privilege level. The access device includes privilege logic to implement privilege levels, each privilege level being associated with one of the groups. The access device is only permitted to log on to the directory service to the exclusion of other functions of the access device until the access device receives an indication of a particular group from the directory service. The directory service receives a log on from a user of the access device, authenticates the user as being associated with the particular group, and sends the indication to the access device. The privilege logic enables the other functions of the access device in accordance with the privilege level associated with the particular group.


