Virtual Desktop Secure Browser Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods in network computing environments lack robust security measures, particularly for remote users and devices, which can lead to vulnerabilities in sensitive data transmission and increased risks of malware transmission and unauthorized access.
Innovation Solution
The implementation of a secure authentication system using two-factor authentication, biometrics, and virtual desktop infrastructure, where client devices connect to a secure computing environment through access points and desktop virtualization systems, with firewalls and authentication services to protect sensitive data and prevent malware transmission, and a secure browser application for secure data access and wire transfers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then system simplicity is maintained, but security reliability deteriorates
Solution Approach 1:
The authentication system is divided into multiple independent components: authentication services, firewalls, virtual desktop infrastructure, and secure browsers. Each component performs a specific security function, allowing the system to achieve high reliability through segmented security controls rather than relying on a single complex authentication mechanism.
Solution Approach 2:
The patent introduces intermediary security layers including authentication services that mediate between client devices and network resources, and firewalls that act as intermediaries to filter and monitor traffic. These intermediaries enhance authentication security by adding verification steps without requiring fundamental changes to the core system architecture.
2Ease of operation
If remote access is enabled for users, then accessibility is improved, but malware transmission risk increases
Solution Approach 1:
Firewalls are deployed as intermediary security barriers between remote client devices and the network. These firewalls inspect incoming and outgoing traffic, filter malicious content, and monitor communication protocols, thereby enabling remote access while mitigating malware transmission risks through layered security inspection.
Solution Approach 2:
The patent extracts sensitive data processing from client devices and relocates it to secure server environments. By taking out data handling operations from potentially compromised remote devices and performing them in isolated, secure virtual desktops, the system maintains user accessibility while eliminating malware transmission vectors that could exploit local device vulnerabilities.
3Reliability
If data protection measures are enhanced, then information security is improved, but transmission speed decreases
Solution Approach 1:
Security functions are segmented and distributed across multiple components including authentication services, firewalls, and secure browsers. Each component handles specific security tasks efficiently, avoiding the need for excessive data processing at a single point. This segmentation allows data protection measures to be applied at optimal points in the transmission path with minimal impact on overall speed.
Solution Approach 2:
The system dynamically adjusts security parameter levels based on the nature of data being transmitted and the current network environment. Encryption strength, authentication requirements, and firewall inspection depth are modified according to risk assessments, allowing enhanced data protection for sensitive information while maintaining faster transmission speeds for less critical data.
Data Source
AI summary
A server may include at least one server processor configured to execute an application. A desktop virtualization system may include at least one desktop virtualization processor. The desktop virtualization processor may be configured to instantiate a virtual desktop; authenticate a user of a client device; in response to authenticating the user of the client device, place the client device in communication with the virtual desktop through at least one network; launch a secure browser in the virtual desktop; and using the secure browser, place the client device in communication with the server through the at least one network. The application may be configured to perform processing in response to at least one command from the client device. The processing may include generating a one-time passcode, establishing a code word not communicated through the at least one network, and sending a message including the one-time passcode to a sender client device.


