IP Library Granted Patent US 10,417,428
Granted Patent B2
US 10,417,428 · App. 14/997,787 · Granted Sep 17, 2019

Methods and systems for providing and controlling cryptographic secure communications terminal providing a remote desktop accessible in secured and unsecured environments

Inventors: Steven L. Rajcan (Malvern, PA); Matthew Mohr (Malvern, PA); Jim Trocki (Malvern, PA); Mark K. Vallevand (Roseville, MN)
Assignee: Unisys Corporation
G06F21/575G06F9/442G06F9/4406G06F9/4416G06F9/452G06F9/454G06F21/53G06F21/74H04L63/029H04L67/025H04L67/306H04W12/06G06F9/441G06F9/4408G06F21/31G06F2221/034H04L63/0428H04L63/08H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,417,428
App. No.
14/997,787
Granted
Sep 17, 2019
Kind
B2
Abstract

Methods and systems for operating a remote desktop client from a computing system hosting a secure boot device. In some embodiments, a method comprises initiating execution of an operating system from the computing system hosting the secure boot device, the computing system communicatively connected within a secure enterprise network, the computing system being untrusted within the secure enterprise network and based on verification of received authentication credentials, booting an operating system from the secure boot device and establishing a secure communication tunnel with a service appliance. Further, the method comprises receiving, from the service appliance a destination address of a secure gateway device connected to the enterprise network and community of interest keys and filters based on the authenticated credentials; and establishing a cleartext communication channel with the secure gateway device, thereby allowing communication between the computing system and one or more trusted endpoints within the secure enterprise network.

Claims (49)

1. A method for operating a remote desktop client from a computing system hosting a secure boot device, the method comprising:

initiating execution of an operating system from the computing system hosting the secure boot device, the computing system communicatively connected within a secure enterprise network, the computing system being untrusted within the secure enterprise network;

receiving authentication credentials from the user;

based on verification of the received authentication credentials, booting, from the secure boot device, the operating system;

establishing a secure communication tunnel with a service appliance;

receiving, from the service appliance, via the secure communication tunnel, a destination address of a secure gateway device connected to the enterprise network and community of interest keys and filters based on the authenticated credentials; and

establishing a cleartext communication channel with the secure gateway device, thereby allowing communication between the computing system and one or more trusted endpoints within the secure enterprise network.

2. The method of claim 1 , wherein communication between the remote desktop client and the service appliance over the first secure communication tunnel is encrypted.

3. The method of claim 1 , wherein data communicated over the cleartext communication channel is encrypted.

4. The method of claim 1 , further comprising:

communicating, via a second cleartext communication channel, with one or more trusted endpoints within the secure enterprise network.

5. The method of claim 4 , wherein communication with the one or more endpoints is based on a user of the secure boot device being associated with a same community of interest as each of the one or more endpoints.

6. The method of claim 1 , wherein the computing system comprises a mobile computing system.

7. The method of claim 1 , wherein, based on detecting a disconnection of the computing system from the secure enterprise network, the method further comprises:

disconnecting the cleartext communication channel with the secure gateway device; and

establishing a secure communication tunnel with the secure gateway device, thereby allowing communication between the computing system and one or more trusted endpoints within the secure enterprise network.

8. A computing system configured to communicate with trusted endpoints within a secure enterprise network, the computing system being communicatively connected within the secure enterprise network but untrusted within the secure enterprise network, the computing system comprising:

a programmable circuit;

a memory communicatively connected to the programmable circuit, the memory storing computer-executable instructions which, when executed by the programmable circuit, cause the computing system to perform a method comprising:

initiating execution of an operating system from the computing system hosting the secure boot device, the computing system communicatively connected within a secure enterprise network, the computing system being untrusted within the secure enterprise network;

receiving authentication credentials from the user;

based on verification of the received authentication credentials, booting, from the secure boot device, the operating system;

establishing a secure communication tunnel with a service appliance;

receiving, from the service appliance, via the secure communication tunnel, a destination address of a secure gateway device connected to the enterprise network and community of interest keys and filters based on the authenticated credentials; and

establishing a cleartext communication channel with the secure gateway device, thereby allowing communication between the computing system and one or more trusted endpoints within the secure enterprise network.

9. The computing system of claim 8 , wherein the computing system comprises a mobile computing system.

10. The computing system of claim 8 , wherein the memory comprises a secure boot device communicatively connected to the computing system via a wired interface.

11. The computing system of claim 10 , wherein the wired interface comprises a USB interface.

12. The computing system of claim 11 , wherein, based on detecting a disconnection of the computing system from the secure enterprise network, the memory stores instructions to further perform:

disconnecting the cleartext communication channel with the secure gateway device; and

establishing a secure communication tunnel with the secure gateway device, thereby allowing communication between the computing system and one or more trusted endpoints within the secure enterprise network.

13. The computing system of claim 8 , wherein communication between the computing system and the service appliance over the secure communication tunnel is encrypted.

14. The computing system of claim 8 , wherein data communicated over the cleartext communication channel is encrypted.

15. A secure system for operating a remote desktop client from a secure boot device positioned within a secure enterprise network, the method comprising:

a client computer having a secure boot device connected thereto, the client computer communicatively connected within a secure enterprise network, the client computer being untrusted within the secure enterprise network;

a remote server communicatively connected to the client computer via a communications network; and

a trusted set of processing modules stored in the secure boot device that, when executed on the client computer, cause the client computer to:

initiate an operating system from the secure boot device;

receive authentication credentials including a user identification and a password;

based on authentication of the received credentials, boot, from the secure boot device, the operating system;

establish a secure communication tunnel with a service appliance;

receive, from the service appliance, via the secure communication tunnel, a destination address of a secure gateway device connected to the enterprise network and community of interest keys and filters based on the authenticated credentials; and

establish a cleartext communication channel with the secure gateway device, thereby allowing communication between the client computer and one or more trusted endpoints within the secure enterprise network.

16. The method for operating a remote desktop client from a secure boot device positioned within a secure enterprise network of claim 15 , wherein communication between the remote desktop client and the service appliance over the first secure communication tunnel is encrypted.

17. The method for operating a remote desktop client from a secure boot device positioned within a secure enterprise network of claim 15 , wherein data communicated over the cleartext communication channel is encrypted.

18. The method for operating a remote desktop client from a secure boot device positioned within a secure enterprise network of claim 15 , further comprising:

communicating, via a second cleartext communication channel, with one or more endpoints connected to the secure enterprise network.

19. The method for operating a remote desktop client from a secure boot device positioned within a secure enterprise network of claim 18 , wherein communication with the one or more endpoints is based on a user of the secure boot device being associated with a same community of interest as each endpoint.

20. The method for operating a remote desktop client from a secure boot device positioned within a secure enterprise network of claim 15 , wherein the computing system comprises a mobile computing system.

Assignments (10)
AMENDED AND RESTATED PATENT SECURITY AGREEMENT Recorded Jun 27, 2025
From: UNISYS CORPORATION; UNISYS HOLDING CORPORATION; UNISYS NPL, INC.; UNISYS AP INVESTMENT COMPANY I
To: COMPUTERSHARE TRUST COMPANY, N.A., AS COLLATERAL TRUSTEE
Reel/Frame 071759/0527 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 054231/0496 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2020
From: RAJCAN, STEVEN J; MOHR, MATTHEW; TROCKI, JIM; VALLEVAND, MARK K
To: UNISYS CORPORATION
Reel/Frame 054188/0687 →
SECURITY INTEREST Recorded Jan 31, 2020
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 051682/0760 →
SECURITY INTEREST Recorded Nov 21, 2019
From: UNISYS CORPORATION
To: WELLS FARGO NATIONAL ASSOCIATION
Reel/Frame 051075/0721 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2018
From: RAJCAN, STEVEN L; MOHR, MATTHEW; TROCKI, JIM; VALLEVAND, MARK K
To: UNISYS CORPORATION
Reel/Frame 045185/0140 →
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: UNISYS CORPORATION
Reel/Frame 044416/0114 →
SECURITY INTEREST Recorded Oct 6, 2017
From: UNISYS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 044144/0081 →
PATENT SECURITY AGREEMENT Recorded Apr 27, 2017
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL TRUSTEE
Reel/Frame 042354/0001 →
SECURITY INTEREST Recorded Jun 3, 2016
From: UNISYS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 038792/0820 →