IP Library › Granted Patent US 12,341,756
Granted Patent B2
US 12,341,756 · App. 17/972,560 · Granted Jun 24, 2025

Methods and systems for providing virtual desktop infrastructure via secure classified remote access as a service

Inventors: Marty Spain (Indian Head, MD); Peter Joseph Dunn (Crestview, FL)
Assignee: CDW LLC
H04L63/029G06F9/45558H04L63/1433G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,756
App. No.
17/972,560
Granted
Jun 24, 2025
Kind
B2
Abstract

An internet end-user device includes a processor, a network interface controller; and a memory including instructions that, when executed by the one or more processors cause the end-user device to configure the end-user device to use a red network and perform dependency verification of the end-user device. A method includes configuring an end-user device to use a red network; and performing dependency verification of the end-user device. A non-transitory computer readable medium includes program instructions that when executed, cause an internet end-user device for use by end users to configure the end-user device to use a red network and perform dependency verification of the end-user device.

Claims (45)

1. An internet end-user device for use by end users, the end-user device including:

one or more processors,

one or more network interface controllers; and

a memory including instructions that, when executed by the one or more processors cause the end-user device to:

configure, via the one or more processors, the end-user device to connect to one or more remote services via an offline red network;

perform, via the one or more processors, dependency verification with respect to the configuration of the end-user device;

push, when the end-user device does not have an active internet connection, user data into a staging area; and

synchronize, when an active internet connection is detected, the user data to an online red network.

2. The end-user device of claim 1 , the memory including further instructions that, when executed by the one or more processors cause the end-user device to:

initialize the end-user device in response to a waking up of the end-user device.

3. The end-user device of claim 1 , the memory including further instructions that, when executed by the one or more processors cause the end-user device to:

determine whether a current configuration of the end-user device includes at least one of an active directory configuration, a recursive DNS configuration, a port forwarding configuration, or a public-key infrastructure server configuration.

4. The end-user device of claim 1 , the memory including further instructions that, when executed by the one or more processors cause the end-user device to:

remove access to a network tunnel between the end-user device and one or more red networks in response to a condition.

5. The end-user device of claim 1 , the memory including further instructions that, when executed by the one or more processors cause the end-user device to:

renew one or more cryptographic certificates in the end-user device.

6. The end-user device of claim 1 , the memory including further instructions that, when executed by the one or more processors cause the end-user device to:

access one or more virtual desktop images.

7. A computer-implemented method for providing a virtual desktop infrastructure to an internet end-user device for use by end users via secure classified remote access as a service, comprising:

configuring, via one or more processors, the end-user device to connect to one or more remote services via an offline red network;

perform, via the one or more processors, dependency verification with respect to the configuration of the end-user device;

pushing, when the end-user device does not have an active internet connection, user data into a staging area; and

synchronizing, when an active internet connection is detected, the user data via an online red network path.

8. The computer-implemented method of claim 7 , further comprising:

initializing the end-user device in response to a waking up of the end-user device.

9. The computer-implemented method of claim 7 , further comprising:

establishing one or more network tunnels between the end-user device and one or more remote computer networks by establishing tunnel links from the end-user device to one or more black networks, one or more gray networks, and one or more red networks.

10. The computer-implemented method of claim 7 , wherein performing the dependency verification includes determining whether a current configuration of the end-user device includes at least one of an active directory configuration, a recursive DNS configuration, a port forwarding configuration, or a public-key infrastructure server configuration.

11. The computer-implemented method of claim 9 , further comprising:

enforcing one or more policy rules with respect to the configuration of the end-user device by removing access to one or more network tunnels between the end-user device and the one or more remote computer networks in response to a condition.

12. The computer-implemented method of claim 7 , further comprising:

causing the end-user device to access the virtual desktop infrastructure via one or more network tunnels by accessing one or more virtual desktop images via the end-user device.

13. A non-transitory computer readable medium containing program instructions that when executed, cause an internet end-user device for use by end users to:

configure, via one or more processors, the end-user device to connect to one or more remote services via an offline red network;

perform, via one or more processors, dependency verification with respect to the configuration of the end-user device;

push, when the end-user device does not have an active internet connection, user data into a staging area; and

synchronize, when an active internet connection is detected, the user data to an online red network.

14. The non-transitory computer readable medium of claim 13 , containing further program instructions that when executed, cause the end-user device to:

determine whether a current configuration of the end-user device includes at least one of an active directory configuration, a recursive DNS configuration, a port forwarding configuration, or a public-key infrastructure server configuration.

15. The non-transitory computer readable medium of claim 13 , containing further program instructions that when executed, cause the end-user device to:

renew one or more cryptographic certificates in the end-user device.

16. The non-transitory computer readable medium of claim 13 , containing further program instructions that when executed, cause the end-user device to:

remove access to one or more network tunnels between the end-user device and a second red network in response to a condition.

17. The non-transitory computer readable medium of claim 13 , containing further program instructions that when executed, cause the end-user device to:

access one or more virtual desktop images via the end-user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2023
From: SPAIN, MARTY; DUNN, PETER JOSEPH
To: CDW LLC
Reel/Frame 062455/0496 →
Continuity (2)
Continuation 17340687 · Jun 7, 2021
Related Publication 20230048251A1 · Feb 16, 2023
References Cited (29)
US 8291488B2 · Faraboschi et al. · 2012 [cited by applicant]
US 9191377B2 · Charan et al. · 2015 [cited by applicant]
US 10382401B1 · Lee et al. · 2019 [cited by applicant]
US 10742649B1 · Hook, Jr. et al. · 2020 [cited by applicant]
US 10904350B1 · Kudrin et al. · 2021 [cited by applicant]
US 10979402B1 · Hartley et al. · 2021 [cited by applicant]
US 11870866B1 · Kudrin · 2024 [cited by examiner]
US 20080133964A1 · Rogers et al. · 2008 [cited by applicant]
US 20090187763A1 · Freericks et al. · 2009 [cited by applicant]
US 20140082719A1 · Persson · 2014 [cited by examiner]
US 20150358392A1 · Ramalingam · 2015 [cited by examiner]
US 20160056975A1 · Marin · 2016 [cited by examiner]
US 20170048278A1 · Tomasso · 2017 [cited by examiner]
US 20170214577A1 · Kanojia · 2017 [cited by examiner]
US 20170324566A1 · Kawasaki et al. · 2017 [cited by applicant]
US 20180198760A1 · Murray · 2018 [cited by examiner]
US 20180262346A1 · Levy et al. · 2018 [cited by applicant]
US 20190087204A1 · Babol · 2019 [cited by examiner]
US 20200089573A1 · Baggerman · 2020 [cited by examiner]
US 20200186532A1 · Dynkin et al. · 2020 [cited by applicant]
US 20200403864A1 · Saenger et al. · 2020 [cited by applicant]
NSA Central Security Service, “Commercial Solutions for Classified Program (CSfC)”. Retrieved from the Internet at: <https://www.nsa.gov/resources/everyone/csfc/> (2021). [cited by applicant]
NSA Central Security Service, “Commercial Solutions for Classified (CSfC)”. Retrieved from the Internet at: https://apps.nsa.gov/iaarchive/programs/iad-initiatives/commercial-solutions-for-classified.cfm <https://protec… [cited by applicant]
C4ISRNET, “The Army will soon allow users to access classified info from home”. Retrieved from the Internet at: https://www.c4isrnet.com/2020/06/22/the-army-will-soon-allow-users-to-access-classified-info-from-home/ <ht… [cited by applicant]
Forcepoint, “A secure access solution with support for one or many globally dispersed sites”. Retrieved from the Internet at: <https://www.forcepoint.com/product/cross-domain-security/forcepoint-trusted-thin-client> (20… [cited by applicant]
“Oracle VM VirtualBox®”, User Manual, Version 4.1.10, 298 pp,, retrieved from the Internet at: <https://www.virtualbox.org/wiki/Documentation (Jan. 2012). [cited by applicant]
International Application No. PCT/US2022/027274, International Search Report and Written Opinion, mailed Aug. 4, 2022. [cited by applicant]
U.S. Appl. No. 17/468,719, “Out-Of-Band Management Continuous Monitoring for Secure Classified Remote Access as a Service,” filed on Sep. 8, 2021. [cited by applicant]
U.S. Appl. No. 17/466,928, “Operations and Maintenance Techniques Subsystem for Secure Classified Remote Access as a Service,” filed on Sep. 3, 2021. [cited by applicant]