IP Library Granted Patent US 12705315
Granted Patent B2
US 12705315 · App. 18/194,978 · Granted Aug 11, 2026

Utilizing video and input pipelines to protect virtual desktop infrastructure sessions

Inventors: Orr Srour (Ramat-Hasharon, IL); Ori Laslo (Rehovot, IL); Ashish Gupta (Fremont, CA); Vadim Makhervaks (Bellevue, WA); Andrew Lee Jenks (Woodinville, WA); Samuel John Wenker (Kirkland, WA)
Assignee: Microsoft Technology Licensing, LLC
G06F21/1085G06F9/45533G06F9/452G06F2009/45583G06F2009/45587G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705315
App. No.
18/194,978
Granted
Aug 11, 2026
Kind
B2
Abstract

Methods and systems are described which facilitate protecting a virtual desktop infrastructure (VDI) session. A first communication channel is established between a first cryptographic element and a VDI service. The first cryptographic element decrypts a video stream from the VDI service and overlays the decrypted video stream on a user's display. A second communication channel is established between a second cryptographic element and the VDI service. The second cryptographic element encrypts input received at a user's input device and sends the encrypted input to the cloud VDI service.

Claims (38)

1 . A method, implemented at a computer system that includes a processor system, for protecting a virtual desktop infrastructure (VDI) session, comprising:

establishing a first communication channel between an enclaved portion of the processor system and a cloud VDI service that provides remote access to a virtual service, the enclaved portion of the processor system being inaccessible by an operating system (OS) that executes at the computer system;

at the enclaved portion of the processor system,

decrypting a video stream that is received from the cloud VDI service over the first communication channel and that corresponds to a first display output of the virtual service into a decrypted video stream;

overlaying the decrypted video stream over a second display output of the OS, wherein the decrypted video stream is inaccessible to the OS; and

initiating display of a user interface indicator that the decrypted video stream is secure;

establishing a second communication channel between a microcontroller unit and the cloud VDI service, the microcontroller unit being inaccessible by the OS; and

at the microcontroller unit,

encrypting an input received from an input device associated with the computer system to generate an encrypted input; and

sending the encrypted input to the cloud VDI service via the second communication channel as an input to the virtual service,

wherein the first communication channel and the second communication channel are associated with a common cryptographic credential, and the cloud VDI service verifies that the first communication channel and the second communication channel are associated with the common cryptographic credential.

2 . The method of claim 1 , wherein the enclaved portion of the processor system is a digital rights management (DRM) processor.

3 . The method of claim 1 , wherein the processor system is a central processing unit (CPU).

4 . The method of claim 1 , wherein the processor system is a graphics processing unit (GPU).

5 . The method of claim 1 , wherein the processor system and the microcontroller unit are located on a docking station that is connected to user input/output devices.

6 . The method of claim 1 , wherein sending the encrypted input to the cloud VDI service via the second communication channel comprises the microcontroller unit passing the encrypted input to the processor system.

7 . The method of claim 1 , the common cryptographic credential being stored at the enclaved portion of the processor system and the microcontroller unit at provisioning of the enclaved portion of the processor system and the microcontroller unit.

8 . The method of claim 1 , wherein the cloud VDI service verifies that the first communication channel and the second communication channel are associated with the common cryptographic credential prior to sending the video stream over the first communication channel.

9 . The method of claim 1 , further comprising, at the enclaved portion of the processor system, decrypting an audio stream that is received from the cloud VDI service.

10 . A computer system comprising:

a hardware processor comprising an enclaved portion, wherein the enclaved portion:

establishes a first communication channel with a cloud VDI service that provides remote access to a virtual service, the enclaved portion being inaccessible by an operating system (OS) that executes at the computer system;

decrypts a video stream that is received from the cloud VDI service over the first communication channel and that corresponds to a first display output of the virtual service into a decrypted video stream, wherein the decrypted video stream is inaccessible to the OS;

overlays the decrypted video stream over a second display output of the OS; and

initiates display of a physical indicator that the decrypted video stream is secure; and

a microcontroller unit that:

establishes a second communication channel with the cloud VDI service, the microcontroller unit being inaccessible by the OS;

encrypts an input received from an input device associated with the computer system to generate an encrypted input; and

sends the encrypted input to the cloud VDI service via the second communication channel as an input to the virtual service,

wherein the first communication channel and the second communication channel are associated with a common cryptographic credential, and the cloud VDI service verifies that the first communication channel and the second communication channel are associated with the common cryptographic credential.

11 . The computer system of claim 10 , wherein the enclaved portion also decrypts an audio stream that is received from the cloud VDI service.

12 . The computer system of claim 10 , wherein the enclaved portion is a digital rights management (DRM) processor.

13 . The computer system of claim 10 , wherein the processor is a central processing unit (CPU).

14 . The computer system of claim 10 , wherein the processor is a graphics processing unit (GPU).

15 . The computer system of claim 10 , wherein the processor and the microcontroller unit are located on a docking station that is connected to user input/output devices.

16 . The computer system of claim 10 , wherein sending the encrypted input to the cloud VDI service via the second communication channel comprises the microcontroller unit passing the encrypted input to the processor.

17 . The computer system of claim 10 , the common cryptographic credential being stored at the enclaved portion and the microcontroller unit at provisioning of the enclaved portion and the microcontroller unit.

18 . The computer system of claim 10 , wherein the cloud VDI service verifies that the first communication channel and the second communication channel are associated with the common cryptographic credential prior to sending the video stream over the first communication channel.