WO2008106295A1

Strategies for securely applying connection policies via a gateway

Abstract

A strategy is described for securely applying connection policies in a system that includes a first entity (e.g., a TS client) connected to a second entity (e.g., a TS server) via a gateway using a remote-operating protocol (e.g., RDP). The strategy involves establishing a first secure channel between the gateway and the TS server and transmitting policy information from the gateway to the TS server. The strategy then involves deactivating the first secure channel and setting up a second secure channel between the TS client and the TS server. The strategy uses the second secure channel to transmit RDP data from the TS client to the TS server. The TS server uses the previously-transmitted policy information to determine whether to enable or disable a feature that affects the TS client, such as device redirection.

WO2008106295A1, drawing sheet 1
Sheet 1 of 7

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

19 claims: 3 independent, 16 dependent

  1. 1
    CLAIMS What is claimed is:1. A method for securely transmitting data from a first entity to a second entity via a gateway using a remote-operating protocol, comprising: establishing a first secure channel between the gateway and the second entity (406);receiving policy information from the gateway at the second entity via the first secure channel, the policy information identifying a manner in which the second entity is to interact with first entity (406);establishing a second secure channel between the first entity and the second entity (408);receiving data at the second entity from the first entity via the second secure channel (412);and taking action on the data at the second entity based on the policy information which was previously transmitted from the gateway to the second entity (412).
  2. 13
    A method for securely transmitting data from a terminal service (TS) client to a TS server via a gateway using a remote-operating protocol, comprising:establishing a first secure channel between the gateway and the TS server (406);sending policy information from the gateway to the TS server via the first secure channel, the policy information identifying a manner in which the TS server is to interact with the TS client (406);deactivating the first secure channel (408);and sending data to the TS server via a second secure channel (410).
  3. 18
    A system (300) for securely transmitting data using a remote- operating protocol, comprising:a terminal service (TS) server (304);and a gateway (312) for proxying the data between at least one TS client (302) and the TS server (304), wherein the system (300) is configured to establish a first secure channel (326) between the gateway (312) and the TS server (304) to transmit policy information (328) from the gateway (312) to the TS server (304), wherein the system (300) is configured to establish a second secure channel (314) between said at least one TS client (302) and the TS server (304) to receive data from said at least one client (302), wherein the TS server (304) is configured to take action on the received data based on the policy information (328) which was previously transmitted from the gateway (312).