IP Library Granted Patent US 9,055,080
Granted Patent B2
US 9,055,080 · App. 12/967,020 · Granted Jun 9, 2015

Systems and methods for service isolation

Inventors: Vikramjeet Sandhu (Bangalore, IN); Joseph Nord (Lighthouse, FL)
Assignee: Citrix Systems, Inc.
H04L63/102G06F8/61G06F9/455G06F21/105G06F21/53G06F2009/45587G06F2221/2145H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,055,080
App. No.
12/967,020
Filed
Dec 13, 2010
Granted
Jun 9, 2015
Kind
B2
Art Unit
2451
USPC
709/217
Abstract

The present invention is directed towards systems and methods of streaming an application from a remote location to a local machine system, and using local machine system resources in executing that application. In various embodiments, services needed by a streamed application may be started with high local system privileges in their own isolation environment. These service may be started, stopped, and otherwise managed by a Service Control Manager. In order for an application to both access services that operate at high local system privileges and the network so that it can access remotely stored, streaming, information; a streaming application may rely on privileges of the user when accessing network information rather than the higher privileges of the services running in isolation.

Claims (36)

1. A method, comprising:

sending, by a local machine, a request to stream an application;

receiving, by the local machine, an access information file including access information for accessing a plurality of application files and for executing a first client;

retrieving an identification of the plurality of application files, responsive to the access information file;

receiving, by the local machine, information identifying whether the application requires the use of a service with greater security privilege levels than those available to the user of the local machine;

determining that the application requires use of the service and that the service needs to be isolated;

creating, by the local machine responsive to the determination, an isolation environment with security privilege levels greater than those available to the application; and

starting the service as an isolated service in the isolation environment with security privilege levels greater than those available to the application.

2. The method of claim 1 , further comprising the step of using credentials or a token with a different security privilege level than that of the isolation environment for isolated services to access information unavailable to services running with security privilege levels of the isolation environment for isolated services.

3. The method of claim 1 , wherein receiving information identifying whether the application requires the use of services with greater security privilege levels than those available to the user of the local machine includes receiving at least one of mapping information, profiling information, or information identifying services as isolated services.

4. The method of claim 1 , where the starting of isolated services occurs after an application is launched and the application requests a service that is determined to be an isolated service.

5. The method of claim 1 , further comprising the step of deleting all the isolated services.

6. The method of claim 1 , wherein starting an isolated service occurs upon startup or reboot of the local machine.

7. The method of claim 1 , wherein an isolated service is started in its own sandbox.

8. The method of claim 1 , where creating an isolation environment is accomplished through the use of a Service Control Manager.

9. The method of claim 8 , wherein the Service Control Manager initiates, manages, starts, stops, pauses, or deletes an isolated service.

10. The method of claim 8 , wherein the Service Control Manager determines whether a particular service should be isolated.

11. A system comprising:

a local machine communicatively connected to a network;

an environment on the local machine configured to run a streamed application from the network; and

a Service Control Manager (SCM) configured to determine that the streamed application requires use of a service that requires greater security privilege levels than those available and needs to be isolated, wherein the SCM creates, responsive to the determination, an isolation environment on the local machine with security privilege levels greater than those available to the environment running the streamed application and starts the service as an isolated service in the isolation environment.

12. The system of claim 11 , further comprising storage on the network for information identifying whether an application requires the use of services with greater security privilege levels than those available to the user of a local machine.

13. The system of claim 11 , wherein the isolation environment further comprises sandboxes for each isolated service.

14. The system of claim 11 , wherein the local machine comprises storage for isolated services information.

15. A system comprising:

means for sending, by a local machine, a request to stream an application;

means for receiving, by the local machine, an access information file including access information for accessing a plurality of application files and for executing a first client;

means for retrieving an identification of the plurality of application files, responsive to the access information file;

means for receiving, by the local machine, information identifying whether the application requires the use of a service with greater security privilege levels than those available to the user of the local machine;

means for determining that the application requires use of the service and that the service needs to be isolated;

means for creating, by the local machine responsive to the determination, an isolation environment with security privilege levels greater than those available to the application; and

means for starting the service as an isolated service in the isolation environment with security privilege levels greater than those available to the application.

16. The system of claim 15 , further comprising means for using credentials or a token with a different security privilege level than that of the isolation environment for isolated services to access information unavailable to services running with security privilege levels of the isolation environment for isolated services.

17. The system of claim 15 , further comprising means for receiving information identifying whether the application requires the use of services with greater security privilege levels than those available to the user of the local machine where said information includes receiving at least one of mapping information, profiling information, or information identifying services as isolated services.

18. The system of claim 15 , further comprising means for starting isolated services after an application has launched and the application requests a service that is determined to be an isolated service.

19. The system of claim 15 , further comprising means for deleting all the isolated services.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2011
From: SANDHU, VIKRAMJEET; NORD, JOSEPH
To: CITRIX SYSTEMS, INC.
Reel/Frame 026017/0784 →
Continuity (2)
Provisional Application 61286334 · Dec 14, 2009
Related Publication 20110173251A1 · Jul 14, 2011