IP Library Granted Patent US 9,672,078
Granted Patent B2
US 9,672,078 · App. 13/743,191 · Granted Jun 6, 2017

Deployment and management of virtual containers

Inventors: Martin Kacin (Los Altos Hills, CA); Mark Wright (Austin, TX); Michael Gray (Dublin, OH)
Assignee: Dell Products L.P.
G06F9/54G06F9/45537G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,672,078
App. No.
13/743,191
Filed
Jan 16, 2013
Granted
Jun 6, 2017
Kind
B2
Art Unit
2199
USPC
719/328
Abstract

A system virtualizes applications on a managed endpoint using containers. A managed endpoint receives a virtualized container from an IT automation appliance. The virtualized container includes an application and a virtualization module. The virtualization module includes computer program instructions for virtualizing the application. An operating system API call made by the application during execution is intercepted, and a portion of the computer program instructions are executed based on the operating system API call. The computer program instructions modify the behavior of the application to effect the file and data virtualization of the application. A virtualized container can be deployed and updated from an IT automation appliance along with an agent to support the deployment and updating of the virtualized container.

Claims (59)

1. A method for virtualizing applications on a computer using virtual containers, the method comprising:

receiving, at a managed endpoint, a virtual container from a remote computer, the virtual container including an application and computer program instructions for virtualizing the application;

storing the virtual container at the managed endpoint;

determining that the application has started executing at the managed endpoint;

creating a user environment for a user of the application;

monitoring, by the computer program instructions for virtualizing the application, the application for an operating system application program interface (API) call to write a file to a file system of the managed endpoint, the file system located outside of the virtual container;

determining whether to allow the operating system API call to write the file to the file system to proceed, and in response to the determination:

blocking, by the computer program instructions for virtualizing the application, the operating system API call to write the file to the file system;

modifying a filename parameter of the operating system API call to redirect the file to the virtual container;

modifying the user environment to reflect redirection of the file to the virtual container;

writing the file to a location within the virtual container; and

executing the computer program instructions for virtualizing the application that are configured to modify a behavior of the application including:

isolating the application from other applications executing at the managed endpoint; and

isolating data associated with the application from other data stored at the managed endpoint.

2. The method of claim 1 , wherein the computer program instructions for virtualizing the application are further configured to prevent the application from accessing malware.

3. The method of claim 1 , further comprising re-flashing the virtual container to return the virtual container to its initial state.

4. The method of claim 1 , further comprising:

determining whether the application executing at the managed endpoint is part of the virtual container; and

hooking the computer program instructions for virtualizing the application into an appropriate operating system API call in response to determining that the application is part of the virtual container.

5. A system for virtualizing applications on a computer using virtual containers, the system comprising:

a processor;

a non-transitory, computer-readable medium communicatively coupled to the processor; and

computer program instructions stored on the computer-readable medium, the computer program instructions configured to, when executed by the processor, cause the processor to:

receive a virtual container at a managed endpoint from a remote computer and store the virtual container at the managed endpoint, the virtual container including an application and computer program instructions configured for virtualizing the application;

determine that the application has started executing at the managed endpoint;

create a user environment for a user of the application;

monitor the application for an operating system application program interface (API) call to write a file to a file system of the managed endpoint, the file system located outside of the virtual container;

determine whether to allow the operating system API call to write the file to the file system to proceed, and in response to the determination:

block the operating system API call to write the file to the file system;

modify a filename parameter of the operating system API call to redirect the file to the virtual container;

modify the user environment to reflect redirection of the file to the virtual container;

write the file to a location within the virtual container; and

execute the computer program instructions for virtualizing the application that are configured to modify a behavior of the application including:

isolating the application from other applications executing at the managed endpoint; and

isolating data associated with the application from other data stored at the managed endpoint.

6. The system of claim 5 , wherein the computer program instructions for virtualizing the application are further configured to, when executed by the processor, prevent the application from accessing malware.

7. The system of claim 5 , wherein the computer program instructions are further configured to, when executed by the processor, cause the processor to re-flash the virtual container to return the virtual container to its initial state.

8. The system of claim 5 , wherein the computer program instructions are further configured to, when executed by the processor, cause the processor to:

determine whether the application is part of the virtual container; and

hook the computer program instructions for virtualizing the application into appropriate operating system API calls in response to determining that the application is part of the virtual container.

9. A non-transitory, computer-readable medium storing computer program instructions that, when executed by a processor, cause the processor to:

receive, at a managed endpoint, a virtual container from a remote computer, the virtual container including an application and computer program instructions for virtualizing the application;

store the virtual container at the managed endpoint;

determine that the application has started executing at the managed endpoint;

create a user environment for a user of the application;

monitor the application for an operating system application program interface (API) call to write a file to a file system of the managed endpoint, the file system located outside of the virtual container;

determine whether to allow the operating system API call to write the file to the file system to proceed, and in response to the determination:

block the operating system API call to write the file to the file system;

modify a filename parameter of the operating system API call to redirect the file to the virtual container;

modify the user environment to reflect redirection of the file to the virtual container;

write the file to a location within the virtual container; and

execute the computer program instructions for virtualizing the application that are configured to modify a behavior of the application including:

isolating the application from other applications executing at the managed endpoint; and

isolating data associated with the application from other data stored at the managed endpoint.

10. The computer-readable medium of claim 9 , wherein the computer program instructions for virtualizing the application are further configured to, when executed by the processor, cause the processor to prevent the application from accessing malware.

11. The computer-readable medium of claim 9 , wherein the computer program instructions are further configured to, when executed by the processor, cause the processor to re-flash the virtual container to return the virtual container to its initial state.

12. The computer-readable medium of claim 9 , wherein the computer program instructions are further configured to, when executed by the processor, cause the processor to:

determine that the application is part of a virtual container; and

hook the computer program instructions for virtualizing the application into an appropriate operating system API call in response to determining that the application is part of the virtual container.

Assignments (28)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
CHANGE OF NAME Recorded Nov 2, 2016
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 040551/0885 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2016
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE INC.
Reel/Frame 040520/0220 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
MERGER Recorded Jun 2, 2015
From: KACE NETWORKS, INC.
To: DELL PRODUCTS L.P.
Reel/Frame 035766/0326 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2015
From: KACIN, MARTIN; GRAY, MICHAEL R.; WRIGHT, MARK
To: KACE NETWORKS, INC.
Reel/Frame 035766/0268 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
Continuity (3)
Continuation 12556525 · Sep 9, 2009
Provisional Application 61095538 · Sep 9, 2008
Related Publication 20130198764A1 · Aug 1, 2013