IP Library Granted Patent US 8,560,593
Granted Patent B2
US 8,560,593 · App. 12/078,174 · Granted Oct 15, 2013

System for provisioning, allocating, and managing virtual and physical desktop computers in a network computing environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,560,593
App. No.
12/078,174
Granted
Oct 15, 2013
Kind
B2
Abstract

A system for provisioning, allocating, and managing virtual and physical desktop computers in an enterprise network computing environment allows for these physical and desktop computers to be grouped logically based on personnel, organizational, or networking efficiencies without regard to the hardware or server that will ultimately run the virtual machine terminal once it is accessed. A connection broker connects incoming connections to one desktop in a desktop group, based on information relating to that incoming connection.

Claims (54)

1. A system for managing user access to a computer system over a network, comprising:

a server computer configured to receive a connection request from at least one client device over a network, wherein said connection request comprises connection information about said at least one user client device;

a desktop group comprising a cluster of a plurality of virtual desktops and a plurality of physical desktops, the plurality of virtual desktops comprising a plurality of virtual machines executing on at least one physical computing device, each of the plurality of physical desktops executing on at least one physical computing device, wherein each of the virtual desktops and each of the physical desktops are configured to operate a single-user operating system that is configured to run a first shell application that initializes initialize a desktop associated with the single-user operating system, wherein the desktop group of the virtual and physical desktops act substantially equivalent to a Terminal Server and each virtual desktop and each physical desktop is substantially equivalent to a Terminal Server user session, and wherein each of the virtual machines encapsulates:

an operating system environment of the single-user operating system;

applications configured to run natively on the operating system;

memory; and

storage resources;

a second shell program configured to provide multi-user Terminal Server functionality of allowing a user to start a desired application without starting a full desktop in an operating system configuration that is not capable of running as a multi-user Terminal Server, wherein the second shell program modifies the registry of the operating system and prevent the first shell application from starting, and wherein the second shell program is configured to receive, from the client device, an instruction to start a desired application rather than the desktop;

a broker service running on said server computer, the broker service configured to:

receive said connection request from a terminal device operated by a user:

determine the user's authorized access to the virtual desktops and the physical desktops in the desktop group based on an access control list;

determine the user's authorized access to one or more applications available in the virtual and physical desktops based on the access control list;

display on the terminal device operated by the user, the virtual desktops, the physical desktops and the one or more applications authorized to be accessed by the user;

select either a first virtual desktop from the plurality of virtual desktops or a first physical desktop from the plurality of physical desktops in response to user input;

route said connection request to either the first virtual desktop or the first physical desktop based at least partly on said connection information;

receive status information of the virtual and physical desktops and notification of events occurring on the virtual and physical desktops and record the events within a management database; and

issue commands to cause the virtual and physical desktops in the desktop group to terminate a process, log off a user, shut down, or reboot;

and

an agent service running in said first virtual desktop, the agent service configured to:

collect information about event information comprising user logon, logoff and disconnect events associated with the user client device; and

send said event information to the broker service, wherein the broker service is configured to notify a user of the at least one client device to proceed with a connection to the first virtual desktop.

2. The system of claim 1 , further comprising a plurality of application resources, wherein said application resources are published to the first virtual desktop to which the connection request has been routed.

3. The system of claim 2 , wherein said application resources are published to the first virtual desktop based on an access control list (ACL) for each published resource.

4. The system of claim 1 , wherein the plurality of physical desktops comprise blade computing devices.

5. The system of claim 1 , wherein at least one of the virtual desktops in the desktop group inherits application access rights associated with the desktop group.

6. The system of claim 1 , wherein the desktop group inherits a user-level policy.

7. The system of claim 1 , further comprising a plurality of application resources, wherein at least a portion of the plurality of application resources is published to the first virtual desktop.

8. The system of claim 7 , wherein each of the published application resources further comprises an access control list (ACL), and wherein user access to the published application resources is controlled based on the ACL.

9. A system for managing user access to a computer system over a network, the system comprising:

at least one server computer configured to receive a connection request from at least one client device over a network, wherein the connection request comprises connection information about the at least one client device;

a broker module executing on the at least one server computer, the broker module being configured to route the connection request, based on said connection information, to at least one of a cluster of a plurality of virtual desktops and a plurality of physical desktops, the plurality of virtual desktops comprising a plurality of virtual machines executing on at least one physical computing device, wherein each of the virtual desktops and the physical desktops are configured to operate a single-user operating system that is configured to run a first shell application that initializes a desktop associated with the single-user operating system in response to the connection request, wherein the cluster of virtual desktops and physical desktops form is a desktop group that is substantially equivalent to a Terminal Server and each virtual desktop and each physical desktop is substantially equivalent to a Terminal Server user session, and wherein each of the virtual machines encapsulates:

an operating system environment of the single-user operating system;

applications configured to run natively on the operating system;

memory; and

storage resources;

wherein the broker module is further configured to:

receive said connection request from a terminal device operated by a user;

determine the user's authorized access to the virtual desktops and the physical desktops in the desktop group based on an access control list;

determine the user's authorized access to one or more applications available in the virtual and physical desktops based on the access control list;

display on the terminal device operated by the user, the virtual desktops, the physical desktops and the one or more applications authorized to be accessed by the user;

select either a first virtual desktop from the cluster plurality of virtual desktops or a first physical desktop from the plurality of physical desktops in response to user input;

route said connection request to either the first virtual desktop or the first physical desktop based at least partly on said connection information;

receive status information of the virtual and physical desktops and notification of events occurring on the virtual and physical desktops and record the events within a management database; and

issue commands to cause the virtual and physical desktops in the desktop group to terminate a process, log off a user, shut down, or reboot;

a second shell program configured to provide multi-user Terminal Server functionality of allowing a user to start a desired application without starting a full desktop in an operating system configuration that is not capable of running as a multi-user Terminal Server, wherein the second shell program modifies the registry of the operating system and prevents the first shell application from starting, and wherein the second shell program is configured to receive from the client device, an instruction to start a desired application rather than the desktop; and

a plurality of data collector modules, each of the data collector modules configured to:

obtain event information regarding a selected one of the cluster of virtual and physical desktops, and wherein the plurality of data collector modules is configured to transmit the event information to the broker module, the event information comprising information regarding one or more of user log on, log off, and disconnect events, and

send heartbeat information to the broker module, the heartbeat information reflecting status of the selected virtual desktop or physical desktop, such that the broker module is further configured to mark the selected virtual or physical desktop offline in response to not receiving the heartbeat information.

10. The system of Claim 9 , wherein the plurality of physical desktops comprises blade computing devices.

11. The system of Claim 9 , further comprising a plurality of application resources, wherein at least a portion of the plurality of application resources is published to at least one of the virtual desktops.

12. The system of claim 11 , wherein each of the published application resources further comprises an access control list (ACL), and wherein user access to the published application resources is controlled based on the ACL.

13. The system of claim 11 , wherein the desktop group comprises a predetermined number of virtual desktops corresponding to a predetermined number of users that are authorized to access the plurality of application resources.

14. The system of claim 9 , wherein the desktop group comprises at least a second desktop group, wherein the desktop group and the second desktop group comprise policy settings determining application access rights, and wherein the desktop group inherits the policy settings of the second desktop group.

15. The system of claim 9 , wherein the desktop group comprises at least a second desktop group, wherein the desktop group and the second desktop group have policy settings determining application access rights, and wherein the desktop group overrides the policy settings of the second desktop group.

Assignments (28)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2016
From: DELL SOFTWARE INC.
To: DELL PRODUCTS L.P.
Reel/Frame 040100/0620 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
CHANGE OF NAME Recorded Aug 19, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031035/0914 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Sep 28, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC (FORMERLY KNOWN AS WELLS FARGO FOOTHILL, LLC)
To: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
Reel/Frame 029050/0679 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CITIZENSHIP OF QUEST SOFTWARE, INC. FROM A CALIFORNIA CORPORATION TO A DELAWARE CORPORATION PREVIOUSLY RECORDED ON REEL 023094 FRAME 0353. ASSIGNOR(S) HEREBY CONFIRMS THE GRANT, ASSIGNMENT, TRANSFER, AND COVEYANCE TO AGENT OF A CONTINUING SECURITY INTEREST IN THE ADDITIONAL PATENTS. Recorded Jun 30, 2010
From: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
To: WELLS FARGO FOOTHILL, LLC, AS AGENT
Reel/Frame 024611/0504 →
AMENDMENT NUMBER TWO TO PATENT SECURITY AGREEMENT Recorded Aug 13, 2009
From: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
To: WELLS FARGO FOOTHILL, LLC, AS AGENT
Reel/Frame 023094/0353 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2008
From: GHOSTINE, PETER E.
To: QUEST SOFTWARE, INC.
Reel/Frame 020836/0273 →