IP Library Granted Patent US 8,850,060
Granted Patent B1
US 8,850,060 · App. 12/359,353 · Granted Sep 30, 2014

Network interface within a designated virtual execution environment (VEE)

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,850,060
App. No.
12/359,353
Granted
Sep 30, 2014
Kind
B1
Abstract

A system and method for managing network traffic provided to users includes a computer system and an operating system running on the computer system. A plurality of Virtual Execution Environments (VEEs) are executed on the computer system. Each VEE provides a set of services to remote users. A one or more designated VEE(s) provide network traffic handling services to other VEEs based on the needs of the remote users of the particular VEEs. The network traffic processing services are provided via a virtual network adapter(s) implemented within the designated VEE(s). The network traffic handling services are controlled and administered by each of the VEEs via control means of the designated VEE(s).

Claims (62)

1. A system for handling network traffic comprising:

a computer system having a processor and a memory;

an operating system (OS) running on the computer system;

a plurality of Virtual Execution Environments (VEEs) running under the OS, wherein the VEEs provide services to a plurality of remote users;

at least one designated VEE operationally coupled to other VEEs of the plurality of the VEEs and providing network traffic handling services to the other VEEs, wherein the designated VEE is separate from the OS;

a virtual network adapter running within the designated VEE and processing the network traffic; and

common control means integrated within the designated VEE operationally coupled to control means of each of the other VEEs for providing administration of the network traffic handling services to each of the VEEs using private control data sets of each VEE.

2. The system of claim 1 , wherein the VEE is any of a Virtual Private Server, a Virtual Machine, a Hypervisor-based Virtual Machine, a session of Windows Terminal Server, and a session of Citrix Presentation Server.

3. The system of claim 1 , wherein the virtual network adapter processes network traffic based on pre-set rules and policies.

4. The system of claim 1 , wherein the designated VEE provides network traffic handling services to the plurality of the VEEs that are running on a computer cluster.

5. The system of claim 1 , wherein the virtual network adapter includes any of:

a spam filtering application, and

an anti-virus protection application.

6. The system of claim 1 , wherein the virtual network adapter includes security services comprising:

filtering network traffic based on user-specific parameters only;

filtering network traffic based on VEE-specific parameters only; and

filtering network traffic based on a combination of the user-specific parameters and the VEE-specific parameters.

7. The system of claim 1 , wherein the control means provide a selection of the network traffic handling rules and policies based on the private control data sets of each VEE; and

wherein the private control data sets comprise the traffic handling rules and policies specific to each remote user of each VEE.

8. A method for handling network traffic comprising:

launching a plurality of Virtual Execution Environments (VEEs) on a computer system;

designating one of the VEEs for providing network traffic handling services to the other VEEs, wherein the designated VEE is separate from an operating system of the computer system;

activating a virtual network adapter within the designated VEE for processing the network traffic; and

controlling deployment of the network traffic handling services by the designated VEE using private control data sets specific to each of the VEEs,

wherein the designated VEE is operationally coupled to each of the VEEs through common VEE integrated control means for providing administration of the network traffic handling services to each of the VEEs using private control data sets of each VEE.

9. The method of claim 8 , wherein the VEE is any of a Virtual Private Server, a Virtual Machine, a Hypervisor-based Virtual Machine, a session of Windows Terminal Server, and a session of Citrix Presentation Server.

10. The method of claim 8 , wherein the designated VEE provides network traffic handling services to the plurality of VEEs running on a plurality of computer systems.

11. The method of claim 8 , wherein the virtual network adapter includes any of:

a spam filtering application, and

an anti-virus protection application.

12. The method of claim 8 , wherein the virtual network adapter includes security services comprising:

filtering network traffic based on user-specific parameters only;

filtering network traffic based on VEE-specific parameters only; and

filtering network traffic based on a combination of the user-specific parameters and the VEE-specific parameters.

13. The method of claim 8 , wherein the private control data sets comprise traffic handling rules and policies specific to each remote user of the VEE.

14. A system for handling network traffic comprising:

a computer cluster having a plurality of nodes, wherein each node has a processor and a memory;

an operating system running on each node of the cluster;

a plurality of Virtual Execution Environments (VEEs) running on each node, wherein the VEEs provide services to a plurality of remote users, and wherein the designated VEE is separate from an operating system of the computer system of its node;

at least two designated VEEs running on different computer systems providing network traffic handling services to other VEEs;

virtual network adapters for processing the network traffic running within the designated VEEs; and

common control means within the designated VEEs and operationally coupled to control means of each of the other VEEs for providing administration of the network traffic handling services to each of the VEEs,

wherein each of the designated VEEs provides a different network traffic handling service to the other VEEs; and

wherein the virtual network adapters includes at least one of spam filtering application and anti-virus protection application.

15. The system of claim 14 , wherein the VEEs comprise VPSs.

16. The system of claim 14 , wherein the VEEs comprise VMs.

17. A system for handling user applications comprising:

a computer system having a processor and a memory;

an operating system (OS) running on the computer system;

a plurality of Virtual Execution Environments (VEEs) running under the OS, wherein the VEEs provide services to a plurality of remote users;

at least one VEE designated as an application server for providing services to the other VEEs, wherein the designated VEE is separate from the OS; and

common control means integrated within the designated VEE operationally coupled to control means of each of the other VEEs for providing communication from the application server to each of the VEEs and from the VEEs to the application server;

wherein invocation, inside one of the VEEs, for executing an application is redirected to the designated VEE for starting and running the application inside the designated VEE;

wherein the application runs in a context of the designated VEE; and

the application communicates with the VEE from which it was invoked using a virtual network adapter.

18. The system of claim 17 , wherein the application server is Java application server, .NET Framework, Appserver, Base4 or Zope.

19. The system of claim 17 , wherein the context of the designated VEE comprises any of:

local VEE files;

the VEE settings;

inter process communication means with the local process of the VEE;

the VEE network addresses and ports.

20. The method of claim 1 , wherein the common control means uses common control parameters for administration of the VEEs.

Assignments (12)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: ACRONIS INTERNATIONAL GMBH
To: VIRTUOZZO INTERNATIONAL GMBH
Reel/Frame 066931/0580 →
REAFFIRMATION AGREEMENT Recorded Aug 28, 2022
From: ACRONIS AG; ACRONIS INTERNATIONAL GMBH; ACRONIS SCS, INC.; ACRONIS, INC.; GROUPLOGIC, INC.; NSCALED INC.; ACRONIS MANAGEMENT LLC; 5NINE SOFTWARE, INC.; ACRONIS GERMANY GMBH; ACRONIS NETHERLANDS B.V.; ACRONIS BULGARIA EOOD; DEVICELOCK, INC.; DEVLOCKCORP LTD; ACRONIS INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 061330/0818 →
SECURITY INTEREST Recorded Dec 19, 2019
From: ACRONIS INTERNATIONAL GMBH
To: MIDCAP FINANCIAL TRUST
Reel/Frame 051418/0119 →
RELEASE OF SECURITY INTEREST Recorded Oct 21, 2019
From: OBSIDIAN AGENCY SERVICES, INC.
To: ACRONIS INTERNATIONAL GMBH; GROUPLOGIC, INC.
Reel/Frame 050783/0893 →
SECURITY INTEREST Recorded Jul 26, 2017
From: ACRONIS INTERNATIONAL GMBH; GROUPLOGIC, INC.
To: OBSIDIAN AGENCY SERVICES, INC., AS COLLATERAL AGENT
Reel/Frame 043350/0186 →
RELEASE OF SECURITY INTEREST Recorded Dec 14, 2015
From: SILICON VALLEY BANK
To: PARALLELS HOLDINGS LTD. (F/K/A SWSOFT HOLDINGS LTD.)
Reel/Frame 037289/0685 →
PATENT SECURITY AGREEMENT Recorded Feb 27, 2014
From: ACRONIS INTERNATIONAL GMBH
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 032366/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2012
From: PARALLELS IP HOLDINGS GMBH
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 027989/0898 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2012
From: PARALLELS HOLDINGS, LTD.
To: PARALLELS IP HOLDINGS GMBH
Reel/Frame 027595/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2011
From: SWSOFT HOLDINGS, LTD.
To: PARALLELS HOLDINGS, LTD.
Reel/Frame 027467/0345 →
SECURITY AGREEMENT Recorded Jun 23, 2011
From: PARALLELS HOLDINGS LTD. (F/K/A SWSOFT HOLDINGS LTD.)
To: SILICON VALLEY BANK
Reel/Frame 026480/0957 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2009
From: TORMASOV, ALEXANDER G.; PROTASSOV, STANISLAV S.; BELOUSSOV, SERGUEI M.
To: SWSOFT HOLDINGS, LTD.
Reel/Frame 022152/0590 →