Virtual Desktop Session Ongoing Authentication Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for accessing protected resources, such as online banking websites, are vulnerable to malware and cyber threats due to lack of ongoing authentication in virtual desktop sessions, allowing potential hijacking and unauthorized access.

Innovation Solution

Implementing a method that performs a series of authentication operations between an end user device and an authentication engine during a virtual desktop session, ensuring ongoing successful authentication to maintain access and terminating the session upon unsuccessful authentication to prevent further access and protect against advanced cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a virtual desktop session is established without ongoing authentication, then ease of operation is improved, but security against advanced cyber threats deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements continuous authentication during the virtual desktop session by periodically requesting authentication tokens from the authentication engine. This ensures that the authentication process does not stop during the session, maintaining security without requiring repeated manual intervention from the user, thus resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system establishes a feedback loop where the authentication engine continuously monitors authentication status and provides feedback to control the virtual desktop session. When authentication fails, the session is terminated; when authentication succeeds, the session continues. This feedback mechanism ensures security while maintaining smooth operation.

Inventive Principle:
Principle #23Feedback

2Reliability

If ongoing authentication operations are performed during virtual desktop session, then security against advanced persistent threats is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication engine as an intermediary component that handles all authentication operations between the user device and the virtual desktop session. This intermediary manages the complexity of continuous authentication by centralizing the authentication logic, reducing the burden on the user device and simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If virtual desktop session is terminated upon authentication failure, then protection against unauthorized access is improved, but loss of time increases

Engineering Contradiction:
ImproveprotectionVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The continuous authentication mechanism operates in the background during the virtual desktop session, allowing legitimate users to access resources without interruption. The system only terminates the session when authentication fails, minimizing unnecessary time loss while maintaining strong protection against unauthorized access.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8701174B1Controlling access to a protected resource using a virtual desktop and ongoing authentication
Publication Date: 2014.04.15 EMC IP HLDG CO LLC
  • US8701174B1 patent drawing
  • US8701174B1 patent drawing
  • US8701174B1 patent drawing

AI summary

A technique controls access to a protected resource. The technique involves performing a series of authentication operations between an end user device and an authentication engine, and providing, while the series of authentication operations results in ongoing successful authentication, a virtual desktop session from a virtual desktop server to the end user device to enable a user at the end user device to access the protected resource using the virtual desktop session. The technique further involves closing the virtual desktop session when the series of authentication operations results in unsuccessful authentication (e.g., receipt of an incorrect authentication factor, loss of communications between the end user device and the authentication engine, etc.) to prevent further access to the protected resource using the virtual desktop session. Such operation provides additional security beyond that offered by a virtual desktop session without ongoing authentication, and thus protects against more advanced types of cyber threats.