IP Library Granted Patent US 10,459,752
Granted Patent B2
US 10,459,752 · App. 15/648,433 · Granted Oct 29, 2019

Hybrid remote desktop logon

Inventor: Per Olov Larsson (London, GB)
Assignee: VMware, Inc.
G06F9/45558G06F9/452G06F21/31G06F21/335G06F21/34G06F21/41H04L63/0807H04L63/0815H04L63/083H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,459,752
App. No.
15/648,433
Granted
Oct 29, 2019
Kind
B2
Abstract

A hybrid account logon is disclosed for logging into remote desktops. In one embodiment, the hybrid logon combines local and domain accounts by building a local primary access token which provides credentials for local and domain-based accounts. In one embodiment, a credentials provider creates a serialized structure including both local account information and domain credentials and sends the serialized structure to a logon user interface (UI) process. The logon UI process calls a user authentication service that itself calls a hybrid authentication package which performs a domain logon, discards any identity associated with the domain logon session, and builds a local identity for the local account. The user authentication service then generates a primary access token including the local identity and the domain logon session data, thereby supporting interactive logon based on the local user identity which is also linked to network credentials for use in accessing network resources.

Claims (44)

1. A computer-implemented method of logging on to a system using domain credentials and local user account information, comprising:

initiating a domain logon session using the domain credentials;

generating a local user identity based on at least the local user account information, wherein the local user account information includes (i) a username associated with an available unauthenticated account, or (ii) a username associated with an available unauthenticated account and password combination;

generating a token which includes the generated local user identity and data associated with the initiated domain logon session; and

logging on to the system using the generated token.

2. The method of claim 1 , further comprising, discarding a domain user identity generated as part of initiating the domain logon session.

3. The method of claim 1 , further comprising, applying one or more properties associated with a domain user account during the logging on to the system.

4. The method of claim 1 , wherein:

the domain credentials include one of a username and password or a virtual smartcard.

5. The method of claim 4 , wherein:

the local user account information further includes a password generated by an account manager; and

the method further includes verifying the generated password with the account manager.

6. The method of claim 1 , wherein a user is not required to enter authentication credentials.

7. The method of claim 6 , wherein:

an alias selected by the user is mapped to a domain user account; and

the domain user account is mapped to the local user account.

8. The method of claim 1 , wherein the data associated with the domain logon session includes a session identifier (ID) linked to a kerberos ticket-granting ticket.

9. The method of claim 1 , wherein initiating the domain logon session includes calling a kerberos authentication service without calling a user authentication service which the kerberos authentication service is an extension for.

10. The method of claim 1 , further comprising, launching an application which uses the token to access network resources.

11. A non-transitory computer-readable medium comprising instructions executable by a computer, the computer having one or more physical central processing units (CPUs), wherein the instructions, when executed, cause the computer to perform operations for logging on to a system using domain credentials and local user account information, the operations comprising:

initiating a domain logon session using the domain credentials;

generating a local user identity based on at least the local user account information, wherein the local user account information includes (i) a username associated with an available unauthenticated account, or (ii) a username associated with an available unauthenticated account and password combination;

generating a token which includes the generated local user identity and data associated with the initiated domain logon session; and

logging on to the system using the generated token.

12. The computer-readable medium of claim 11 , the operations further comprising, discarding a domain user identity generated as part of initiating the domain logon session.

13. The computer-readable medium of claim 11 , the operations further comprising, applying one or more properties associated with a domain user account during the logging on to the system.

14. The computer-readable medium of claim 11 , wherein:

the domain credentials include one of a username and password or a virtual smartcard.

15. The computer-readable medium of claim 14 , wherein:

the local user account information further includes a password generated by an account manager; and

the operations further comprise verifying the generated password with the account manager.

16. The computer-readable medium of claim 11 , wherein a user is not required to enter authentication credentials.

17. The computer-readable medium of claim 16 , wherein:

an alias selected by the user is mapped to a domain user account; and

the domain user account is mapped to the local user account.

18. The computer-readable medium of claim 11 , wherein initiating the domain logon session includes calling a kerberos authentication service without calling a user authentication service which the kerberos authentication service is an extension for.

19. The computer-readable medium of claim 11 , the operations further comprising, launching an application which uses the token to access network resources.

20. A system, comprising:

a processor; and

a memory, wherein the memory includes a program for logging on to a system using domain credentials and local user account information, the program being configured to perform operations comprising:

initiating a domain logon session using the domain credentials,

generating a local user identity based on at least the local user account information, wherein the local user account information includes (i) a username associated with an available unauthenticated account, or (ii) a username associated with an available unauthenticated account and password combination,

generating a token which includes the generated local user identity and data associated with the initiated domain logon session, and

logging on to the system using the generated token.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2017
From: LARSSON, PER OLOV
To: VMWARE, INC.
Reel/Frame 042991/0563 →
Continuity (1)
Related Publication 20190018697A1 · Jan 17, 2019
Cited By (1)
US 12,483,885