VMware AlwaysOn Point of Care Desktop with Indigo Identityware software for with Roaming Desktops
Indigo Identityware provides clinical users fast and secure access to their VMware desktop through a fluid, easy and consistent user interface anywhere within the enterprise. Indigo meets all VMware s High Availability user experience requirements: Desktops are always on (VMware View) and enable fast logon Desktop follows user Failover support Access allowed from any endpoint device Familiar (transparent) interface to sustain same application workflow Quick provisioning (Indigo idna included in VMware golden image) Easy Management (Indigo Central Admin snap-in to the MMC) Maintained security (full two factor authentication, desktop locking, encrypted credentials) Low cost High Availability (distributed file caching system & automatic synchronization of user credentials) Fast Access & Strong Authetnication 2
Reference Architecture Desktops (Thick Clients) - Windows XP, 7, & 8 Thin Clients - Windows Embedded Secure Audit - Windows 2003, 2008, 2008R2 Failover Indigo Secure Audit Primary Indigo Secure Audit Microsoft AD Thin Clients (Windows Embedded) running VMware View & Indigo idna Windows Kiosks (thick or thin) for shared access in clinical areas generic local desktop allows Group Unlock of Windows vs. having each user logon to Windows Fast Access, and each user s credentials are authenticated on the VM desktop Windows Desktops VMware View & Indigo idna Legend Fast Access & Strong Authentication SSO & Workflow mgmt (optional) Indigo Secure Audit 3
Reference Architecture Zero Clients - no additional software View Desktop sessions - Windows 7 or 8 Secure Audit - Windows 2003, 2008, 2008R2 Failover Indigo Secure Audit Primary Indigo Secure Audit Microsoft AD Indigo Secure Virtual Kiosk connects user session to VM & provides fast user switching Zero Clients with USB redirection & supported proximity card or biometric readers Legend Fast Access & Strong Authentication SSO & Workflow mgmt (optional) Indigo Secure Audit 4
Test Validation VMware Labs on 9/25/2012 Indigo Identityware installed in VMware Labs on September 25, 2012 and performed a successful demonstration and validation test of its architecture and products. Installed & Configured idna on both a Win 7 and a Win XP client-side machines idna configured for Kiosk Workflow for Fast Access to VMware View Desktop sessions and for other workflows defined by employee role Demonstrated authentication with both proximity card/reader and biometric reader The user logged into the Windows 7 client by tapping his proximity card & upon entering a 4-digit PIN, the local desktop opened was a generic Windows desktop, and the idna Agent immediately launched the VMware View client, providing View with the user s credentials. The user was presented with his VMware View desktop session with no additional authentication or intervention by the user needed. The user tapped his proximity card a second time and the local Windows desktop was immediately locked. User moved to the other local client-side machine (Win XP), authenticated via his proximity card & PIN, the local generic Windows desktop opened while idna automatically launched the VMware View client, and since the user s individual credentials were used in launching View, his VMware View desktop session was automatically roamed to his new location. Same functionality was demonstrated using biometric fingerprint readers. 5
Field Validation Indigo installed its products at a regional medical center in central Minnesota that had already deployed VMware View across the enterprise. Given their need to provide clinical staff: Fast Access to their VMware View desktop sessions, mobility to move from one area to another and easily roam their View session, and to ensure use of strong authentication to meet HIPAA compliance, they chose Indigo Identityware idna and InSession for SSO Workflow Management. 500 Indigo licenses purchased Standard installation of idna on client-side machines; local machines configured with proximity card readers. Shared workstations for clinical staff were configured with the kiosk workflow, where upon authentication, the user was presented with a generic local Windows desktop while idna automatically launched the VMware View session, providing the individual s credentials to VMware to access that user s View desktop session. Other workstations (e.g., executives, admin/finance, etc ) were also installed with idna, but their local desktops were not setup as shared kiosk workstations. Four different workflows were defined based on staff roles and Indigo InSession was installed and configured on the VMware View desktop images to provide SSO to six different enterprise-wide applications (EMR, imaging, prescriptions, etc ). Results The medical center has significantly reduced the time for staff to login to their VMware View desktop sessions, provided easier and simpler access (SSO) to applications based on an employee s role, and is confident that in conjunction with its adoption of VMware View, is both maximizing employee productivity and achieving HIPAA compliance. 6
The Indigo Identityware software components that are installed with the VMware AlwaysOn solution (along with VMware View Client, Agent, Manager, Centralized Desktops, et. al.) are as follows: Indigo idna (client agent for fast access & authentication) idna provides the user with One Touch Access (prox. card tap or finger touch) for clientside computers, automatically launches the VMware View Desktop and provides VMware View with the user s credentials. Indigo Secure Audit Secure Audit (SAS) software is used for user credential replication, disaster recovery and distributed record caching across the network. The SAS application can be easily installed on a virtual machine running Microsoft Windows (e.g., Win 7 or Windows 2008R2). Indigo recommends a minimum of two Secure Audit s per enterprise deployment for failover and credential record data duplication. Indigo Configuration Wizard The Configuration Wizard provides an easy-to-use interface to define the VDI access and workflow for end users and creates a.xml file that is called by idna when the user first authenticates to access the desktop. The customer can customize the launch script on a role by role basis or utilize a single launch script across the enterprise and distribute the script(s) to all client-side machines. Indigo snap-ins for idna local computer management and Central Management for machine groups Indigo InSession (optional) Indigo InSession provides password-free SSO & Workflow Management based on roles for enterprise applications (such as EHR) and can be customized on a enterpriseby-enterprise basis. InSession also provides Secondary Strong Authentication inside of applications to facilitate one-touch authentication for electronically signing charts or prescriptions. 7
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com Copyright 2012 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc., in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Item No: VMW-HG-SECUWKSPDELIVERY- PLAYBK-20120427-WEB 8