IP Library Granted Patent US 9,106,425
Granted Patent B2
US 9,106,425 · App. 13/683,969 · Granted Aug 11, 2015

Method and system for restricting execution of virtual applications to a managed process environment

Inventors: C. Michael Murphey (Seattle, WA); Kenji C. Obata (Seattle, WA); Mark Jeremy Zeller (Seattle, WA); Stefan I. Larimore (Redmond, WA)
Assignee: CODE SYSTEMS CORPORATION
H04L9/32G06F21/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,106,425
App. No.
13/683,969
Granted
Aug 11, 2015
Kind
B2
Abstract

Methods and systems for restricting the launch of virtual application files. In one embodiment, a launching application is signed with a digital signature. When the launching application launches a runtime engine and instructs it to execute an application file, the runtime engine determines whether an entity identifier associated with the launching application identifies an authorized entity. If the entity identifier identifies an authorized entity and the digital signature is valid, the runtime engine executes the application file. In another embodiment, a ticket is transmitted to the launching application along with an instruction to launch the application file. The ticket includes a digital signature and an expiration date. The launching application communicates the ticket to the runtime engine, which will execute the application file only if the digital signature is valid and a current date is not later than the expiration date.

Claims (29)

1. A computer-implemented method for use with a launching application and a separate runtime engine, the launching application and the runtime engine being configured to access a shared memory location, the method comprising:

at the launching application, receiving a first instruction to execute a virtualized application file and a ticket, the ticket comprising a digital signature and an expiration date;

at the launching application, storing the ticket in the shared memory location and sending a second instruction to the runtime engine instructing the runtime engine to execute the virtualized application file; and

in response to the second instruction received from the launching application, at the runtime engine, reading the ticket from the shared memory location, determining whether the digital signature is valid, determining whether the ticket has expired, and executing the virtualized application file only when the runtime engine determines the ticket is valid and has not yet expired, whether the ticket is valid being determined based on the digital signature, and whether the ticket has expired being determined based on the expiration date.

2. The computer-implemented method of claim 1 for use with the runtime engine comprising a public key, wherein whether the ticket is valid is determined based on the digital signature and the public key.

3. The computer-implemented method of claim 1 for use with the launching application connected to a server computing device via the Internet, wherein the first instruction to execute the virtualized application file and the ticket are both received by the launching application from the server computing device via the Internet.

4. The computer-implemented method of claim 3 , further comprising:

at the launching application, receiving a third instruction to at least partially download the virtualized application file.

5. A computer-implemented method for use with a virtualized application file, and a shared memory location storing a ticket comprising a digital signature and an expiration date, the virtualized application file comprising a digital rights management indicator, the method comprising:

receiving an instruction to execute the virtualized application file from a launching application that stored the ticket in the shared memory location;

in response to the instruction, reading the ticket from the shared memory location and reading the digital rights management indicator from the virtualized application file;

when the digital rights management indicator indicates the ticket is to be validated, determining whether the digital signature is valid, determining whether the ticket has expired, and executing the virtualized application file only when the ticket is determined to be valid and not yet expired, whether the ticket is valid being determined based on the digital signature, and whether the ticket has expired being determined based on the expiration date; and

when the digital rights management indicator indicates the ticket is not to be validated, executing the virtualized application file.

6. The computer-implemented method of claim 5 further comprising:

obtaining a public key, wherein whether the ticket is valid is determined based on the digital signature and the public key.

7. The computer-implemented method of claim 5 , further comprising:

when the ticket is determined to be one of invalid or expired, displaying an error message.

8. A computer-implemented method for use with a remote computing device operated by a user, the remote computing device implementing a launching application and a separate runtime engine, the method comprising:

instructing the remote computing device to display a plurality of selectable options, each option corresponding to an application file, wherein the application file is a virtualized application file;

receiving a selection of one of the plurality of selectable options from the remote computing device;

determining whether the user operating the remote computing device has logged into a user account;

when the user has not logging into a user account, instructing the remote computing device to display a login display, receiving login information from the remote computing device via the login display, and determining whether the login information is valid;

when the login information is valid, creating a login session;

creating a ticket comprising a digital signature and an expiration date, creating the ticket comprising incorporating information related to the login session into the ticket;

instructing the launching application on the remote computing device to launch the application file corresponding to the selected one of the plurality of selectable options; and

transmitting the ticket to the launching application, the launching application being operable to communicate the ticket to the runtime engine, the runtime engine being operable to execute the application file corresponding to the selected one of the plurality of selectable options in response to an instruction to do so only when the digital signature of the ticket is valid and a current date is not later than the expiration date.

9. The computer-implemented method of claim 8 , further comprising:

downloading the application file corresponding to the selected one of the plurality of selectable options to the remote computing device.

10. The computer-implemented method of claim 8 , wherein the application file corresponding to the selected one of the plurality of selectable options was stored on the remote computing device before the remote computing device is instructed to display the plurality of selectable options.

Assignments (3)
ADDRESS CHANGE Recorded Nov 10, 2015
From: CODE SYSTEMS CORPORATION
To: CODE SYSTEMS CORPORATION
Reel/Frame 037084/0283 →
CHANGE OF ADDRESS Recorded May 28, 2015
From: CODE SYSTEMS CORPORTATION
To: CODE SYSTEMS CORPORATION
Reel/Frame 035794/0628 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2012
From: MURPHY, C. MICHAEL; OBATA, KENJI C.; ZELLER, MARK JEREMY; LARIMORE, STEFAN I.
To: CODE SYSTEMS CORPORATION
Reel/Frame 029339/0327 →
Continuity (2)
Division 12916348 · Oct 29, 2010
Related Publication 20130086386A1 · Apr 4, 2013