Virtual Desktop Secure Browser Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in network computing environments lack robust security measures, particularly for remote users and devices, which can lead to vulnerabilities in sensitive data transmission and increased risks of malware transmission and unauthorized access.

Innovation Solution

The implementation of a secure authentication system using two-factor authentication, biometrics, and virtual desktop infrastructure, where client devices connect to a secure computing environment through access points and desktop virtualization systems, with firewalls and authentication services to protect sensitive data and prevent malware transmission, and a secure browser application for secure data access and wire transfers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then system simplicity is maintained, but security reliability deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into multiple independent components: authentication services, firewalls, virtual desktop infrastructure, and secure browsers. Each component performs a specific security function, allowing the system to achieve high reliability through segmented security controls rather than relying on a single complex authentication mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary security layers including authentication services that mediate between client devices and network resources, and firewalls that act as intermediaries to filter and monitor traffic. These intermediaries enhance authentication security by adding verification steps without requiring fundamental changes to the core system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote access is enabled for users, then accessibility is improved, but malware transmission risk increases

Engineering Contradiction:
Improveuser accessibilityVSAvoidmalware transmission risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Firewalls are deployed as intermediary security barriers between remote client devices and the network. These firewalls inspect incoming and outgoing traffic, filter malicious content, and monitor communication protocols, thereby enabling remote access while mitigating malware transmission risks through layered security inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts sensitive data processing from client devices and relocates it to secure server environments. By taking out data handling operations from potentially compromised remote devices and performing them in isolated, secure virtual desktops, the system maintains user accessibility while eliminating malware transmission vectors that could exploit local device vulnerabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If data protection measures are enhanced, then information security is improved, but transmission speed decreases

Engineering Contradiction:
Improvedata protectionVSAvoiddata transmission speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Security functions are segmented and distributed across multiple components including authentication services, firewalls, and secure browsers. Each component handles specific security tasks efficiently, avoiding the need for excessive data processing at a single point. This segmentation allows data protection measures to be applied at optimal points in the transmission path with minimal impact on overall speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts security parameter levels based on the nature of data being transmitted and the current network environment. Encryption strength, authentication requirements, and firewall inspection depth are modified according to risk assessments, allowing enhanced data protection for sensitive information while maintaining faster transmission speeds for less critical data.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240098082A1Online Authentication Systems and Methods
Publication Date: 2024.03.21 AXOS BANK
  • US20240098082A1 patent drawing
  • US20240098082A1 patent drawing
  • US20240098082A1 patent drawing

AI summary

A server may include at least one server processor configured to execute an application. A desktop virtualization system may include at least one desktop virtualization processor. The desktop virtualization processor may be configured to instantiate a virtual desktop; authenticate a user of a client device; in response to authenticating the user of the client device, place the client device in communication with the virtual desktop through at least one network; launch a secure browser in the virtual desktop; and using the secure browser, place the client device in communication with the server through the at least one network. The application may be configured to perform processing in response to at least one command from the client device. The processing may include generating a one-time passcode, establishing a code word not communicated through the at least one network, and sending a message including the one-time passcode to a sender client device.