Details

Izboljšava varnosti in zmogljivosti oddaljenega dostopa z implementacijo prehoda MS-TSGU
ID Mikelj, Nejc (Author), ID Lotrič, Uroš (Mentor) More about this mentor... This link opens in a new window

.pdfPDF - Presentation file, Download (786,71 KB)
MD5: 9F00666CF003A53750579EB1A1F19E48

Abstract
Za omogočanje oddaljenega dostopa se pogosto uporablja Remote Desktop Protocol (RDP). Težava pri tradicionalni uporabi RDP je neposredna izpostavitev javnemu internetu, ki predstavlja resno varnostno tveganje, obstoječe rešitve pa so bodisi lastniške in zaprtokodne, bodisi slabše zmogljive ali neskladne s paradigmo ničelnega zaupanja. To diplomsko delo predstavi zasnovo in implementacijo odprtokodnega aplikacijskega prehoda, skladnega s specifikacijo MS-TSGU (Microsoft Terminal Services Gateway Server Protocol), ki podpira glavni kanal TCP in zmogljiv stranski kanal UDP. Pri implementaciji smo se omejili na sodoben, prečiščen nabor funkcionalnosti specifikacije ter jo nadgradili z avtentikacijo OpenID Connect. Sistem je implementiran v jeziku Rust z ogrodjem Tokio, varnost sej pa zagotavljajo enkratne povezovalne vstopnice, shranjene v podatkovni zbirki Redis. Evalvacija je pokazala, da uporaba prehoda ne povzroči drastičnega poslabšanja odzivnosti v primerjavi z neposrednim dostopom in da uporaba protokola UDP dosledno prispeva k boljši zmogljivosti povezave.

Language:Slovenian
Keywords:oddaljeni dostop, RDP, MS-TSGU, aplikacijski prehod, ničelno zaupanje, Rust
Work type:Bachelor thesis/paper
Organization:FRI - Faculty of Computer and Information Science
Year:2026
PID:20.500.12556/RUL-187052 This link opens in a new window
Publication date in RUL:08.09.2026
Views:63
Downloads:7
Metadata:XML DC-XML DC-RDF
:
Copy citation
Share:Bookmark and Share

Secondary language

Language:English
Title:Improving the Security and Performance of Remote Access through Implementation of the MS-TSGU Gateway
Abstract:
Remote Desktop Protocol (RDP) is a commonly used protocol for enabling remote access. A problem with the traditional use of RDP is its direct exposure to the public internet, which poses a serious security risk, while existing solutions are either proprietary and closed-source, offer limited performance, or fail to meet zero-trust requirements. This thesis presents the design and implementation of an open-source application gateway compliant with the MS-TSGU specification, supporting both a TCP-based main channel and a high-performance UDP-based side channel. The implementation targets a modern, streamlined subset of the specification, extended with OpenID Connect authentication. The system is implemented in Rust using the Tokio runtime, with session security ensured though single-use connection tickets stored in Redis. Evaluation showed that using the gateway does not cause a meaningful degradation in latency compared to direct access and that using UDP protocol consistently improves connection performance.

Keywords:remote access, RDP, MS-TSGU, application gateway, zero trust, Rust

Similar documents

Similar works from RUL:
Similar works from other Slovenian collections:

Back