Virtual Desktop Shadowing via Centralized Management Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtual desktop infrastructure environments, running a separate software process on each virtual machine to enable desktop shadowing consumes significant resources, which is inefficient and resource-intensive.
Innovation Solution
A virtual desktop management server receives the virtual desktop transmission from a virtual machine and, based on policy settings, grants limited management access to an administrator device, allowing it to access the virtual desktop's display data only after obtaining permission from the client device, thus eliminating the need for an additional application on the virtual machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a separate software process is run on each virtual machine to enable desktop shadowing, then desktop shadowing functionality is achieved, but significant computing resources are consumed
Solution Approach 1:
A shadowing service is introduced as an intermediary component that runs on the VDM server rather than on each virtual machine. This service receives display data from virtual machines and makes it available to administrator devices, eliminating the need for shadowing software to run on each VM while enabling the functionality.
Solution Approach 2:
The shadowing service on the VDM server serves multiple virtual machines simultaneously, providing a universal solution that replaces the need for individual shadowing software instances on each VM. This multi-functional approach consolidates resource consumption at the server level rather than distributing it across many VMs.
2Ease of operation
If display data is made accessible to administrator devices without permission checks, then management access is simplified, but user privacy and security are compromised
Solution Approach 1:
The system implements a permission checking mechanism where the shadowing service receives display data and checks whether the requesting administrator device is authorized to access it. This feedback loop ensures that access is granted only to authenticated administrators while maintaining user privacy, balancing ease of operation with security.
Data Source
AI summary
Exemplary methods, apparatuses, and systems include a virtual desktop management (VDM) server receiving selection of a virtual desktop from an administrator device and receiving transmission of the virtual desktop from a virtual machine. The virtual desktop is generated by the virtual machine and transmitted concurrently to a remote client device and to the VDM server. The VDM server determines that the received transmission of the virtual desktop includes a policy state and, in response, provides the administrator device with limited management access to the selected virtual machine. The limited management access prevents the administrator device from accessing display data for the virtual desktop. The VDM facilitates sending a request to and receiving permission from the client device to enable the administrator device to access the display data.


