Systems and methods providing connection lease anti-theft features for virtual computing sessions
Abstract
A computing device may include a memory and a processor cooperating with the memory and configured to receive requests from a client device to connect with the computing device. The client device may be shared by multiple authenticated users and have a public/private encryption key pair associated therewith, and the requests may be based upon connection leases and the public key for the client device. The connection leases may also be generated for respective authenticated users and include an authenticated version of the public key for the client device so that the connection leases are specific to the client device and respective users. The processor may also provide the client device with access to computing sessions for respective authenticated users based upon the connection leases and verification of the public key, and prevent the use of the connection leases for authorizing connections for other authenticated users.
Claims
exact text as granted — not AI-modified1 . A computing device comprising:
a memory and a processor cooperating with the memory and configured to
receive requests from a client device to connect with the computing device, the client device being shared by multiple authenticated users and having a public/private encryption key pair associated therewith, the requests based upon connection leases and the public key for the client device, and the connection leases being generated for respective authenticated users and including an authenticated version of the public key for the client device so that the connection leases are specific to the client device and respective users; and
provide the client device with access to computing sessions for respective authenticated users based upon the connection leases and verification of the public key, and prevents the use of the connection leases for authorizing connections for other authenticated users.
2 . The computing device of claim 1 wherein the processor is further configured to, prior to authorizing connections with the client device:
initiate a challenge to be signed by the client device with the private key associated with the client device; and
validate the signed response with the public key for the client device.
3 . The computing device of claim 2 wherein the processor initiates the challenge and validates the signed response prior to verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
4 . The computing device of claim 2 wherein, prior to the challenge and response, the processor is further configured to validate a signature and date associated with the connection lease, and validate that the public key is valid.
5 . The computing device of claim 2 wherein the processor initiates the challenge and validates the signed response after verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
6 . The computing device of claim 1 wherein the connection lease includes a hash of the authenticated version of the public key for the client device.
7 . The computing device of claim 1 wherein the public/private key pair is generated at the client device using a hardware-backed key store.
8 . The computing device of claim 1 wherein the processor is further configured to drop the connection with the client device based on a failure to verify that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
9 . A method comprising:
at a virtual delivery appliance,
receiving requests from a client device to connect with the virtual delivery appliance, the client device being shared by multiple authenticated users, the client device having a public/private encryption key pair associated therewith, the requests based upon connection leases and the public key for the client device, and the connection leases being generated for respective authenticated users and including an authenticated version of the public key for the client device so that the connection leases are specific to the client device and respective users; and
providing the client device with access to computing sessions for respective authenticated users based upon the connection leases and verification of the public key, and preventing the use of the connection leases for authorizing connections for other authenticated users.
10 . The method of claim 9 further comprising, prior to authorizing the connection with the client device:
initiating a challenge from the virtual delivery appliance to be signed by the client device with the private key associated with the client device; and
validating at the virtual delivery appliance the signed response with the public key for the client device.
11 . The method of claim 10 wherein initiating and validating comprise initiating the challenge and validating the signed response prior to verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
12 . The method of claim 10 wherein initiating and validating comprise initiating the challenge and validating the signed response after verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
13 . The method of claim 9 wherein the public key for the client device is registered with a broker; and further comprising validating, at the virtual delivery appliance, that the public key for the client device is registered with the broker prior to verification of the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
14 . The method of claim 9 wherein the connection lease includes a hash of the authenticated version of the public key for the client device.
15 . A method comprising:
receiving a request at a computing device from a client device, the client device having a public/private encryption key pair associated therewith, the request being based upon a connection lease and the public key for the client device, and the connection lease including an authenticated version of the public key for the client device so that the connection lease is specific to the client device; verifying at the computing device that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device; and providing the client device with access to a computing session responsive to verification of the authenticated version of the public key.
16 . The method of claim 15 further comprising, prior to providing the client device with access to the computing session:
initiating a challenge from the computing device to be signed by the client device with the private key associated with the client device; and
validating at the computing device the signed response with the public key for the client device.
17 . The method of claim 16 wherein initiating and validating comprise initiating the challenge and validating the signed response prior to verifying that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
18 . The method of claim 16 wherein initiating and validating comprise initiating the challenge and validating the signed response after verifying that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
19 . The method of claim 15 wherein the public key for the client device is registered with a broker; and further comprising validating, at the computing device, that the public key for the client device is registered with the broker prior to verifying that the authenticated version of the public key upon which the connection lease was generated matches the public key for the client device.
20 . The method of claim 15 wherein the connection lease includes a hash of the authenticated version of the public key for the client device.Join the waitlist — get patent alerts
Track US2022086012A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.