IP Library Patent Application 18404305
Patent Application
App. No. 18/404,305

LOCATION BASED FIREWALL POLICY FOR VIRTUAL DESKTOP INFRASTRUCTURE (VDI) SYSTEMS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/404,305
Filed
Jan 4, 2024
Art Unit
2437
USPC
726/11
Abstract

A method for implementing a firewall policy for a virtual desktop infrastructure (VDI) system comprising a data center hosting a pool of virtual desktops includes: assigning, a client device to a first virtual desktop included in the pool of virtual desktops hosted by the data center; obtaining data from the client device when the client device logs into the first virtual desktop; determining a location of the client device based, at least in part, on the data obtained from the client device, the location corresponding to a first network environment or a second network environment that is less secure than the first network environment; determining one or more firewall rules based, at least in part, on the firewall policy and the location of the client device; and generating a firewall for the data center based, at least in part, on the one or more firewall rules.

Claims (52)

1 . A method for implementing a firewall policy for a virtual desktop infrastructure (VDI) system comprising a data center hosting a pool of virtual desktops, the method comprising:

assigning, by the data center, a client device to a first virtual desktop included in the pool of virtual desktops hosted by the data center;

obtaining, by the data center, data from the client device when the client device logs into the first virtual desktop;

determining, by the data center, a location of the client device based, at least in part, on the data obtained from the client device, the location corresponding to a first network environment or a second network environment that is less secure than the first network environment;

determining, by the data center, one or more firewall rules based, at least in part, on the firewall policy and the location of the client device, wherein the firewall policy specifies which of a plurality of software applications associated with the first virtual desktop are accessible from the location of the client device; and

generating, by the data center, a firewall for the data center based, at least in part, on the one or more firewall rules.

2 . The method of claim 1 , wherein when the location of the client device corresponds to the second network environment, the determining the one or more firewall rules comprises:

determining, by the data center, the firewall policy prohibits the client device from accessing a first software application of the plurality of software applications from the second network environment; and

generating, by the data center, a first firewall rule prohibiting the client device from accessing the first software application.

3 . The method of claim 2 , wherein the first software application has access to proprietary information.

4 . The method of claim 1 , further comprising:

determining, by the data center, the client device has disconnected from the data center; and

removing, by the data center, the firewall from the data center.

5 . The method of claim 4 , wherein the determining the client device has disconnected from the data center comprises determining, by the data center, that the client device has logged off of the first virtual desktop included in the pool of virtual desktops hosted by the data center.

6 . The method of claim 1 , wherein:

the client device is assigned to an individual of an entity;

the first network environment comprises a first location associated with the entity; and

the second network environment comprises a second location that is not associated with the entity.

7 . The method of claim 1 , wherein generating the firewall comprises applying, by the data center, the firewall to a virtual machine of the data center, wherein the first virtual desktop is running on the virtual machine.

8 . The method of claim 1 , wherein obtaining the data from the client device comprises obtaining, via a VDI agent of the first virtual desktop, the data from the client device.

9 . The method of claim 8 , wherein the data from the client device comprises an internet protocol (IP) address of the client device.

10 . A system for implementing a firewall policy for a virtual desktop infrastructure (VDI) system comprising a data center hosting a pool of virtual desktops, the system comprising:

at least one memory; and

at least one processor coupled to the at least one memory, the at least one processor and the at least one memory configured to:

assign a client device to a first virtual desktop included in the pool of virtual desktops hosted by the data center;

obtain data from the client device when the client device logs into the first virtual desktop;

determine a location of the client device based, at least in part, on the data obtained from the client device, the location corresponding to a first network environment or a second network environment that is less secure than the first network environment;

determine one or more firewall rules based, at least in part, on the firewall policy and the location of the client device, wherein the firewall policy specifies which of a plurality of software applications associated with the first virtual desktop are accessible from the location of the client device; and

generate a firewall for the data center based, at least in part, on the one or more firewall rules.

11 . The system of claim 10 , wherein when the location of the client device corresponds to the second network environment, to determine the one or more firewall rules the at least one memory and the at least one processor are configured to:

determine the firewall policy prohibits the client device from accessing a first software application of the plurality of software applications from the second network environment; and

generate a first firewall rule prohibiting the client device from accessing the first software application.

12 . The system of claim 11 , wherein the first software application has access to proprietary information.

13 . The system of claim 10 , wherein the at least one memory and the at least one processor are further configured to:

determine the client device has disconnected from the data center; and

remove the firewall from the data center.

14 . The system of claim 13 , wherein the determining the client device has disconnected from the data center comprises determining, by the data center, that the client device has logged off of the first virtual desktop.

15 . The system of claim 10 , wherein:

the client device is assigned to an individual of an entity;

the first network environment comprises a first location associated with the entity; and

the second network environment comprises a second location that is not associated with the entity.

16 . The system of claim 15 , wherein the second location comprises an airport, a personal residence, or a hotel.

17 . The system of claim 10 , wherein to obtain the data from the client device, the at least one memory and the at least one processor are configured to obtain, via a VDI agent of the first virtual desktop, the data from the client device.

18 . The system of claim 17 , wherein the data from the client device comprises an internet protocol (IP) address of the client device.

19 . The system of claim 10 , wherein to generate the firewall for the data center, the at least one memory and the at least one processor are configured to apply the firewall to a virtual machine of the data center, and wherein the first virtual desktop is running on the virtual machine.

20 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

assign, by a data center hosting a pool of virtual desktops, a client device to a first virtual desktop included in the pool of virtual desktops hosted by the data center;

obtain, by the data center, data from the client device when the client device logs into the first virtual desktop;

determine, by the data center, a location of the client device based, at least in part, on the data obtained from the client device, the location corresponding to a first network environment or a second network environment that is less secure than the first network environment;

determine, by the data center, one or more firewall rules based, at least in part, on a firewall policy and the location of the client device, wherein the firewall policy specifies which of a plurality of software applications associated with the first virtual desktop are accessible from the location of the client device;

generate, by the data center, a firewall for the data center based, at least in part, on the one or more firewall rules; and

apply, by the data center, the firewall to the data center.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2024
From: XIE, JAMES; ZHAO, YISAN
To: VMWARE LLC
Reel/Frame 067445/0840 →