IP Library Patent Application 17966799
Patent Application
App. No. 17/966,799

ISOLATING VIRTUAL DESKTOP APPLICATIONS FOR POLICY ENFORCEMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/966,799
Abstract

Some embodiments provide a method of enforcing a set of access policies on traffic exchanged between remote clients and virtual desktop applications. This method receives and stores access policies that define access to different virtual desktop applications by remote clients. To a set of one or more access gateways remote, the method forwards client requests to launch virtual desktop applications. The method analyzes responses provided by the gateway set to virtual desktop requests, and based on this analysis, creates records that identify the virtual applications that will be launched. The method passes the gateway responses back to the remote clients, and upon receiving traffic to the identified virtual applications from the remote clients, (1) uses the created records to identify the virtual applications associated with the received traffic and (2) applies the access policies associated with the identified virtual applications to the received traffic.

Claims (41)

1 . A method of performing load balancing for traffic exchanged between a remote client and a virtual desktop application, the method comprising:

at a load balancer:

performing a load balancing operation to select a gateway to receive a request, from a remote client, to access the virtual desktop application;

receiving from a gateway data specifying (i) a resource that will provide the virtual desktop application and (ii) a first port to use to establish a connection with the resource to receive the virtual desktop application;

forwarding to the remote client the received data after replacing in the received data the first port with a second port;

creating a set of one or more connection tracking records that associates the first and second ports;

using the connection tracking record set subsequently to forward to the gateway data messages received from the remote client that have header that specify the second port as destination ports of the data messages.

2 . The method of claim 1 further comprising replacing the second port with the first port in the data messages forwarded to the gateway from the remote client.

3 . The method of claim 1 further comprising:

storing in the connection tracking record set identity of the virtual desktop application;

applying access policies on traffic exchanged between the remote client and the gateway based on the identity of the virtual desktop application that is retrieved from the connection tracking record set.

4 . The method of claim 3 , wherein the access policies comprise at least one rate limiting policy that specifies a rate associated with traffic exchanged between a remote client and a virtual desktop application associated with the rate limiting policy.

5 . The method of claim 4 , wherein the rate is a maximum rate for the traffic exchanged.

6 . The method of claim 3 , wherein the access policies comprise at least one security policy to block remote access request from a set of network addresses to a virtual desktop application associated with the security policy.

7 . The method of claim 3 , wherein the access policies comprise at least one web access firewall (WAF) policy to apply to a set of network addresses that try to access a virtual desktop application associated with the WAF policy.

8 . The method of claim 3 , wherein the access policies comprise a particular access policy applicable to a particular virtual desktop application.

9 . The method of claim 3 , wherein the access policies comprise a particular access policy applicable to a particular group of two or more virtual desktop applications.

10 . The method of claim 3 , wherein the access policies comprise a particular access policy applicable to a particular virtual desktop that comprises a set of one or more applications.

11 . A non-transitory machine readable medium storing a load-balancing program that performs load balancing for traffic exchanged between a remote client and a virtual desktop application, the program for execution by at least one processing unit, the program comprising sets of instructions for:

performing a load balancing operation to select a gateway to receive a request, from a remote client, to access the virtual desktop application;

receiving from a gateway data specifying (i) a resource that will provide the virtual desktop application and (ii) a first port to use to establish a connection with the resource to receive the virtual desktop application;

forwarding to the remote client the received data after replacing in the received data the first port with a second port;

creating a set of one or more connection tracking records that associates the first and second ports;

using the connection tracking record set subsequently to forward to the gateway data messages received from the remote client that have header that specify the second port as destination ports of the data messages.

12 . The non-transitory machine readable medium of claim 11 , wherein the program further comprises a set of instructions for replacing the second port with the first port in the data messages forwarded to the gateway from the remote client.

13 . The non-transitory machine readable medium of claim 11 , wherein the program further comprises sets of instructions for:

storing in the connection tracking record set identity of the virtual desktop application;

applying access policies on traffic exchanged between the remote client and the gateway based on the identity of the virtual desktop application that is retrieved from the connection tracking record set.

14 . The non-transitory machine readable medium of claim 13 , wherein the access policies comprise at least one rate limiting policy that specifies a rate associated with traffic exchanged between a remote client and a virtual desktop application associated with the rate limiting policy.

15 . The non-transitory machine readable medium of claim 14 , wherein the rate is a maximum rate for the traffic exchanged.

16 . The non-transitory machine readable medium of claim 13 , wherein the access policies comprise at least one security policy to block remote access request from a set of network addresses to a virtual desktop application associated with the security policy.

17 . The non-transitory machine readable medium of claim 13 , wherein the access policies comprise at least one web access firewall (WAF) policy to apply to a set of network addresses that try to access a virtual desktop application associated with the WAF policy.

18 . The non-transitory machine readable medium of claim 13 , wherein the access policies comprise a particular access policy applicable to a particular virtual desktop application.

19 . The non-transitory machine readable medium of claim 13 , wherein the access policies comprise a particular access policy applicable to a particular group of two or more virtual desktop applications.

20 . The non-transitory machine readable medium of claim 13 , wherein the access policies comprise a particular access policy applicable to a particular virtual desktop that comprises a set of one or more applications.

21 . A method of enforcing a set of access policies on traffic exchanged between a remote client and a virtual desktop application, the method comprising:

forwarding to a gateway a request, from a remote client, to access the virtual desktop application;

receiving from a gateway data specifying (i) a resource that will provide the virtual desktop application and (ii) a first port to use to establish a connection with the resource to receive the virtual desktop application;

forwarding to the remote client the received data after replacing in the received data the first port with a second port;

creating a set of one or more connection tracking records that associates the first and second ports and an identifier associated with the virtual desktop application;

using the connection tracking record set subsequently to identify the virtual desktop application for traffic exchanged between the remote client and the resource, and to perform access policy enforcement on the traffic based on the identified virtual desktop application.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2023
From: KAMALAKANNAN, DINESH KUMAR; KANDACHAR SRIDHARA RAO, SUDARSHANA; SHAH, SYED TAYASSAR; CHAWLA, MITTALI; MODI, ABHINAV
To: VMWARE, INC.
Reel/Frame 063081/0012 →