Virtual Session Validation Against Dynamic Entitlements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In desktop virtualization, static connection leases can lead to resiliency and performance issues due to dynamic user entitlements and resource location changes, causing users to lose access to sessions, experience clock drifting, or encounter security key issues.
Innovation Solution
Implement a method where virtual delivery appliances validate connection leases in real-time against updated published resource entitlements, allowing secure partial operation during brokering service unavailability and redirecting clients to alternative appliances based on usage levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static connection leases are used for virtual desktop access, then users can connect to virtual sessions, but resiliency and performance issues occur due to dynamic user entitlements and resource location changes
Solution Approach 1:
The system transitions from static connection leases to dynamic validation by having virtual delivery appliances continuously validate connection leases against updated published resource entitlements at the computing device. This dynamic validation process allows the system to adapt to changing user entitlements and resource locations while maintaining reliable session access.
Solution Approach 2:
The system implements a feedback mechanism where virtual delivery appliances validate connection leases by comparing them against current published resource entitlements stored at the computing device. This continuous validation loop ensures that session access remains reliable while adapting to dynamic changes in user permissions and resource availability.
2Reliability
If real-time validation of connection leases is implemented, then security and resilience are maintained, but additional validation steps are required
Solution Approach 1:
The computing device stores published resource entitlements locally, enabling virtual delivery appliances to perform self-validation of connection leases without requiring continuous communication with the broker service. This self-service validation mechanism maintains security and resilience while reducing system complexity during broker unavailability.
Solution Approach 2:
The system performs preliminary action by having the computing device store published resource entitlements in advance before broker service unavailability occurs. This pre-stored information enables rapid validation of connection leases without requiring real-time broker communication, maintaining security while simplifying the validation process during outages.
3Productivity
If connection leases are validated against updated published resource entitlements, then faster access to virtual resources is achieved, but real-time validation infrastructure is required
Solution Approach 1:
The system creates a local copy of published resource entitlements at the computing device, which virtual delivery appliances can validate against without requiring real-time communication with the broker service. This copying mechanism enables faster access to virtual resources while reducing the complexity of the validation infrastructure during broker unavailability.
4Reliability
If virtual delivery appliances are arranged in a pool with pre-authorized validation, then continued session access is possible during broker outages, but appliance management complexity increases
Solution Approach 1:
Virtual delivery appliances in the pool use pre-authorized validation stored locally to independently validate connection leases without requiring broker service communication. This self-service capability enables session continuity during broker outages while simplifying appliance pool management by reducing inter-dependencies between appliances and the broker.
Data Source
AI summary
A method may include storing and updating published resource entitlements for a plurality of client devices at a computing device. The method may also include using a plurality of virtual delivery appliances to receive connection requests from the client devices, with the connection requests including connection leases having associated resource entitlements the client devices are respectively permitted to access, and request validation of the connection leases from the computing device. At the computing device, responsive to validation requests from the virtual delivery appliances, the connection leases may be compared to the updated published resource entitlements and validated based thereon. At the virtual delivery appliances, the client devices may be provided with access to virtual sessions corresponding to the published resource entitlements responsive to the virtual session request validations from the computing device.


