IP Library Granted Patent US 12,495,025
Granted Patent B2
US 12,495,025 · App. 18/349,370 · Granted Dec 9, 2025

Zero-trust virtual desktop infrastructure authentication

Inventors: Ramanandan Nambannor Kunnath (Bangalore, IN); Rohit Pradeep Shetty (Bangalore, IN)
Assignee: Omnissa, LLC
H04L63/08G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,025
App. No.
18/349,370
Granted
Dec 9, 2025
Kind
B2
Abstract

Various examples are disclosed for a zero-trust authentication model for virtual desktop infrastructure (VDI) sessions. Upon user authentication of a VDI session, security posture assessments can be performed that analyze an ongoing or continuous state of the user, client device, or network conditions. Remedial measures or mitigation procedures can be performed to address potential non-compliance of the VDI session.

Claims (37)

1 . A system, comprising:

at least one computing device;

program instructions stored in memory and executable in the at least one computing device that, when executed by the at least one computing device, cause the at least one computing device to:

authenticate a virtual desktop infrastructure (VDI) session associated with a user based upon at least one authentication mechanism;

obtain a first security posture of a user account associated with the VDI session;

obtain a second security posture of at least one of a network or a client device from which the user account is connecting to the VDI session;

perform an evaluation of the first security posture and the second security posture;

determine that a mitigation procedure is required based upon identifying a non-compliant state by the evaluation of the first security posture and the second security posture;

identify a mitigation based upon the evaluation; and

perform the mitigation to at least one of the VDI session, the user account, or the client device, wherein the mitigation comprises terminating the VDI session after a timeout period and wherein the timeout period is extended or eliminated in response to the user correcting the non-compliant state identified by the evaluation.

2 . The system of claim 1 , wherein the mitigation comprises performing another user authentication of the user based upon the at least one authentication mechanism.

3 . The system of claim 1 , wherein the evaluation of the first security posture and the second security posture comprises a continuous evaluation of the VDI session after an initial startup of the VDI session.

4 . The system of claim 1 , wherein the mitigation comprises pausing the VDI session until the non-compliant state identified by the evaluation is corrected.

5 . The system of claim 1 , wherein the mitigation comprises generating a notification within the VDI session containing information about the non-compliant state identified by the evaluation.

6 . A non-transitory computer-readable medium embodying program code executable in at least one computing device that, when executed by the at least one computing device, causes the at least one computing device to:

authenticate a virtual desktop infrastructure (VDI) session associated with a user based upon at least one authentication mechanism;

obtain a first security posture of a user account associated with the VDI session;

obtain a second security posture of at least one of a network or a client device from which the user account is connecting to the VDI session;

perform an evaluation of the first security posture and the second security posture;

determine that a mitigation procedure is required based upon identifying a non-compliant state by the evaluation of the first security posture and the second security posture;

identify a mitigation based upon the evaluation; and

perform the mitigation to at least one of the VDI session, the user account, or the client device, wherein the mitigation comprises terminating the VDI session after a timeout period and wherein the timeout period is extended or eliminated in response to the user correcting the non-compliant state identified by the evaluation.

7 . The non-transitory computer-readable medium of claim 6 , wherein the mitigation comprises performing another user authentication of the user based upon the at least one authentication mechanism.

8 . The non-transitory computer-readable medium of claim 6 , wherein the evaluation of the first security posture and the second security posture comprises a continuous evaluation of the VDI session after an initial startup of the VDI session.

9 . The non-transitory computer-readable medium of claim 6 , wherein the mitigation comprises pausing the VDI session until the non-compliant state identified by the evaluation is corrected.

10 . The non-transitory computer-readable medium of claim 6 , wherein the mitigation comprises generating a notification within the VDI session containing information about the non-compliant state identified by the evaluation.

11 . A method, comprising:

authenticating a virtual desktop infrastructure (VDI) session associated with a user based upon at least one authentication mechanism;

obtaining a first security posture of a user account associated with the VDI session;

obtaining a second security posture of at least one of a network or a client device from which the user account is connecting to the VDI session;

performing an evaluation of the first security posture and the second security posture;

determining that a mitigation procedure is required based upon identifying a non-compliant state by the evaluation of the first security posture and the second security posture;

identifying a mitigation based upon the evaluation; and

performing the mitigation to at least one of the VDI session, the user account, or the client device, wherein the mitigation comprises terminating the VDI session after a timeout period and wherein the timeout period is extended or eliminated in response to the user correcting the non-compliant state identified by the evaluation.

12 . The method of claim 11 , wherein the mitigation comprises performing another user authentication of the user based upon the at least one authentication mechanism.

13 . The method of claim 11 , wherein the evaluation of the first security posture and the second security posture comprises a continuous evaluation of the VDI session after an initial startup of the VDI session.

14 . The method of claim 11 , wherein the mitigation comprises pausing the VDI session until a non-compliant state identified by the evaluation is corrected.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 25, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067239/0402 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2023
From: NAMBANNOR KUNNATH, RAMANANDAN; SHETTY, ROHIT PRADEEP
To: VMWARE, INC.
Reel/Frame 064198/0379 →
Continuity (1)
Related Publication 20250023853A1 · Jan 16, 2025
References Cited (6)
US 20130091585A1 · Dumais · 2013 [cited by examiner]
US 20130326072A1 · Smyth · 2013 [cited by examiner]
US 20160065690A1 · Hanyu · 2016 [cited by examiner]
US 20220232004A1 · Soman · 2022 [cited by examiner]
US 20220417319A1 · Kelly · 2022 [cited by examiner]
US 20230418947A1 · Vajravel · 2023 [cited by examiner]