Virtual Session Access via Facial Recognition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods to mitigate internal threats of unauthorized access to sensitive data are either overly restrictive and burdensome or insufficient, failing to prevent security breaches from unauthorized individuals sharing the same physical space as authorized users.

Innovation Solution

A system and method for managing access to a virtual session using a user device that sends a request to a VDI server, which verifies user credentials and sends information to a management server. The management server retrieves an ML model trained to identify the user's face, which is then applied to a video stream from a webcam to verify the user's presence and detect unauthorized objects or individuals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If restrictive physical access control methods are used (e.g., Security Control Room with surveillance cameras), then security against internal threats is improved, but ease of operation and scalability deteriorate

Engineering Contradiction:
Improvesecurity against internal threatsVSAvoidease of access for authorized users
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces mechanical/physical security systems (surveillance cameras, restricted physical access, smartphone surrender requirements) with an optical-based facial recognition system. The VDI client uses a camera to capture facial images and applies machine learning models to verify user identity, eliminating the need for physical security rooms and manual device surrender procedures while maintaining security against internal threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a facial recognition verification system as an intermediary between the user and the virtual session access. The VDI client acts as a mediator that captures facial data, processes it through ML models, and verifies identity before granting access, replacing the need for restrictive physical access controls while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If print screen functionality is prevented, then security against data capture is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity against data captureVSAvoidusability of virtual session
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces software-based restrictions (print screen prevention) with an optical monitoring system. The VDI client uses a camera to detect unauthorized devices (smartphones, cameras) in the user's field of view and applies ML models to identify potential data capture threats, allowing normal software operation while maintaining security through physical space monitoring.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If unauthorized devices are prohibited in viewing area, then security against picture taking is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity against unauthorized viewingVSAvoidconvenience of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an optical monitoring intermediary that continuously scans the user's environment for unauthorized devices. The VDI client uses a camera to detect smartphones, cameras, or other recording devices in the viewing area and applies ML models to identify potential security threats, enabling convenient access while maintaining security through automated environmental monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12301564B2Virtual session access management
Publication Date: 2025.05.13 OMNISSA LLC
  • US12301564B2 patent drawing
  • US12301564B2 patent drawing
  • US12301564B2 patent drawing

AI summary

Methods and systems are described for managing access to a virtual session. A user device can send a request for a virtual session to a virtual desktop interface (“VDI”) server. The VDI server can send details of a user's account to a management server. The management server can send a machine learning (“ML”) model trained to identify the user's face to the user device. The user device can apply the ML model to a video feed of the viewing area of the user device to verify the user's face. The VDI server can initialize the virtual session if the user's face is verified. The user device can monitor the video feed during the virtual session to detect unauthorized objects. If an unauthorized object is detected, the user device can terminate or minimize the session.