AU2006333118B2

System and method for secure remote desktop access

Abstract

A secure remote access system includes client software (114) installed on a portable computer (110) that establishes a remote session with a counterpart server software (120) installed on a server in a DMZ of the company's internal network through a secure tunnel. The DMZ server is connected to a router (130) behind an enterprise second level firewall (127). The router (130) routes the session to the appropriate desktop computer (150) if the desktop is permitted remote access. A bandwidth limiter (140) may be provided to balance the load through the router (130).

AU2006333118B2, drawing sheet 1
Sheet 1 of 3

Term

Projected expiry 14 December 2026.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

12 claims: 6 independent, 6 dependent

  1. 1
    The claims defining the present invention are as follows:1, A system including: a second client computer connected to a first network;5 a server connected to the first network, the server including a first communication means, wherein the first network further includes a first firewall between the server and a first client computer, the first client computer including a second communication means, and a second firewall between the seiver and the second client computer;and 10 a communication tunnel established between the first communication means and the second communication means to connect the second client computer to the first client computer through the server, wherein the first network includes a bandwidth limiter to monitor and regulate data flowing between the first client computer and the second client computer, and 15 the bandwidth limiter limits data flowing between the first client computer and the second client computer if the data flowing is above a threshold for a predetermined period of time.
  2. 5
    5 establishing a connection between a first client computer and a first network;establishing a connection between the first client computer and a server on the first network;and establishing a connection between the first client computer and a second client computer on the first network through the server, 10 wherein the step of establishing the connection between the first client computer and the first network includes obtaining access through a first firewall between the first client computer and the server, wherein the step of establishing the connection between the first client computer and the second client computer includes obtaining access through a second firewall 15 between the server and the second client computer, wherein the first network includes the first firewall and the second firewall, and wherein the first network includes a bandwidth limiter to monitor and regulate data flowing between the first client computer and the second client computer, and wherein the bandwidth limiter limits data flowing between the first client computer 20 and the second client computer if the data flowing is above a threshold for a predetermined period of time.
  3. 6
    7, The method of claim 6, wherein the connection between the first client computer and the first network is established through a second network.
  4. 8
    10. The method of claim 8, wherein the secure policy handler includes a variable timeout condition to terminate the connection between the first client computer and the second client computer, the timeout condition including a first idle period for a trusted client and a second idle period for an untrusted client, the first idle period being longer than the 5 second idle period.
  5. 9
    11, A computer program product including a computer readable medium having stored thereon computer executable instructions that, when executed on a computer, configure the computer to execute the method of any one of claims 6 to 10.
  6. 10
    12. A system substantially as herein described with reference to the accompanying figures.
  7. 11
    13. A method substantially as herein described with reference to the accompanying 15 figures.
  8. 12
    14. A computer program product substantially as herein described with reference to the accompanying figures. COMS ID No:ARCS-319340 Received by IP Australia: Time (H:m) 16:49 Date (Y-M-d) 2011-05-02 WO 2007/078789 PCT/US2006/047602 1/1