Zero-Trust RDP Access with MFA and Policy-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote Desktop Protocol (RDP) lacks support for multifactor authentication (MFA) and network level authentication (NLA), limiting security and customization options.

Innovation Solution

Implementing a zero-trust cloud environment to provide MFA for RDP sessions by authenticating user accounts, generating MFA challenges, and initiating RDP sessions only after successful challenge completion, using XRDP containers and policy engines to manage and monitor connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If RDP protocol is used for remote desktop access, then ease of operation is improved, but security is worsened due to lack of MFA support

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication service between the RDP client and server that mediates the authentication process. This service intercepts RDP authentication requests, adds MFA verification steps, and forwards authenticated sessions to the target system. The intermediary layer enables MFA for RDP without modifying the RDP protocol itself, resolving the contradiction between maintaining RDP ease of operation and enhancing security through MFA.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If proprietary RDP protocol is used, then ease of operation is improved, but adaptability is worsened due to limited customization options

Engineering Contradiction:
Improveease of operationVSAvoidadaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication process into separate components: the existing RDP protocol handling remains intact while a separate authentication service handles MFA and policy enforcement. This segmentation allows the RDP protocol to maintain its ease of operation while the separate authentication layer provides adaptability through configurable policies, custom authentication methods, and flexible rule sets that can be adjusted without modifying the core RDP protocol.

Inventive Principle:
Principle #1Segmentation

3Reliability

If MFA is added to RDP through zero trust environment, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication service acts as an intermediary that manages the complexity of MFA integration. It handles MFA challenge generation, verification, and session management, shielding users from the underlying complexity. The service presents a simple interface to users while managing complex security protocols in the background, thus improving security without significantly increasing user-facing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service capabilities where the authentication service automatically manages MFA challenges, verifies responses, and enforces policies without requiring manual configuration by users. The service autonomously handles authentication workflows, session management, and security policy enforcement, reducing the operational complexity burden on users while maintaining enhanced security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12476957B2System and method for providing multi factor authorization to RDP services through a zero trust cloud environment
Publication Date: 2025.11.18 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12476957B2 patent drawing
  • US12476957B2 patent drawing
  • US12476957B2 patent drawing

AI summary

Remote desktop protocol (RDP) is a proprietary protocol for controlling machines over a network. In order to overcome certain deficiencies of the protocol a method is disclosed utilized in a zero trust cloud environment, to provide access to a RDP servers utilizing multifactor authorization services which are not natively supported by RDP. This is performed utilizing an RDP client while simultaneously providing an authenticated and secure policy based experience through a zero trust network.