Virtual Desktop Session Ongoing Authentication Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for accessing protected resources, such as online banking websites, are vulnerable to malware and cyber threats due to lack of ongoing authentication in virtual desktop sessions, allowing potential hijacking and unauthorized access.
Innovation Solution
Implementing a method that performs a series of authentication operations between an end user device and an authentication engine during a virtual desktop session, ensuring ongoing successful authentication to maintain access and terminating the session upon unsuccessful authentication to prevent further access and protect against advanced cyber threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a virtual desktop session is established without ongoing authentication, then ease of operation is improved, but security against advanced cyber threats deteriorates
Solution Approach 1:
The patent implements continuous authentication during the virtual desktop session by periodically requesting authentication tokens from the authentication engine. This ensures that the authentication process does not stop during the session, maintaining security without requiring repeated manual intervention from the user, thus resolving the contradiction between ease of operation and security.
Solution Approach 2:
The system establishes a feedback loop where the authentication engine continuously monitors authentication status and provides feedback to control the virtual desktop session. When authentication fails, the session is terminated; when authentication succeeds, the session continues. This feedback mechanism ensures security while maintaining smooth operation.
2Reliability
If ongoing authentication operations are performed during virtual desktop session, then security against advanced persistent threats is improved, but device complexity increases
Solution Approach 1:
The patent introduces an authentication engine as an intermediary component that handles all authentication operations between the user device and the virtual desktop session. This intermediary manages the complexity of continuous authentication by centralizing the authentication logic, reducing the burden on the user device and simplifying the overall system architecture.
3Reliability
If virtual desktop session is terminated upon authentication failure, then protection against unauthorized access is improved, but loss of time increases
Solution Approach 1:
The continuous authentication mechanism operates in the background during the virtual desktop session, allowing legitimate users to access resources without interruption. The system only terminates the session when authentication fails, minimizing unnecessary time loss while maintaining strong protection against unauthorized access.
Data Source
AI summary
A technique controls access to a protected resource. The technique involves performing a series of authentication operations between an end user device and an authentication engine, and providing, while the series of authentication operations results in ongoing successful authentication, a virtual desktop session from a virtual desktop server to the end user device to enable a user at the end user device to access the protected resource using the virtual desktop session. The technique further involves closing the virtual desktop session when the series of authentication operations results in unsuccessful authentication (e.g., receipt of an incorrect authentication factor, loss of communications between the end user device and the authentication engine, etc.) to prevent further access to the protected resource using the virtual desktop session. Such operation provides additional security beyond that offered by a virtual desktop session without ongoing authentication, and thus protects against more advanced types of cyber threats.


