IP Library Granted Patent US 10,891,398
Granted Patent B2
US 10,891,398 · App. 15/387,442 · Granted Jan 12, 2021

Electronic apparatus and method for operating a virtual desktop environment from nonvolatile memory

Inventors: Kouetsu Wada (Tokyo, JP); Kyohei Matsuda (Tokyo, JP); Tsukasa Nunami (Tokyo, JP); Kohei Momosaki (Tokyo, JP)
Assignee: Toshiba Client Solutions CO., LTD.
G06F21/80G06F9/4416G06F21/53G06F21/34H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,891,398
App. No.
15/387,442
Granted
Jan 12, 2021
Kind
B2
Abstract

According to one embodiment, an electronic apparatus includes a nonvolatile memory and a hardware processor. The nonvolatile memory is configured not to permit a user using the electronic apparatus to access the nonvolatile memory. The hardware processor is configured to download a client program for connection to a first server apparatus configured to provide a virtual desktop environment, from a second server apparatus different from the first server apparatus, make the downloaded client program stored in the nonvolatile memory, and launch the client program stored in the nonvolatile memory in order for the electronic apparatus to receive the virtual desktop environment, in a case where the client program is stored in the nonvolatile memory.

Claims (49)

1. An electronic apparatus configured to operate with a virtual desktop environment without a built-in storage, the electronic apparatus comprising:

an external storage which is a nonvolatile memory configured not to permit a user to access external storage; and

a hardware processor configured to execute firmware, upon powering on the electronic apparatus, the firmware including a network communication function for communicating with a first server apparatus configured to provide the virtual desktop environment and further communicating with a second server apparatus configured to manage connection to the first server apparatus,

wherein the hardware processor is configured to:

based on an internal policy, determine whether a caching function exists on the electronic apparatus;

wherein when a caching function exists on the electronic apparatus, perform a mounting of the external storage and further determine whether the mounting is successful;

when the mounting is successful, the hardware processor is further configured to:

download, from the second server, connection software configured to enable the electronic apparatus to connect to the virtual desktop environment of the first server apparatus when authentication of the electronic apparatus with the second server apparatus has succeeded;

encrypt the downloaded connection software by a device-dependent key that is generated, based at least in part on inherent information of the electronic apparatus;

attempt to cache the encrypted connection software in the external storage by the device-dependent key;

determine if the external storage has caching capabilities by checking 1) if the connection software can be written to the external storage and 2) if the connection software is readable from the storage;

if the connection software is successfully cacheable, decrypt the connection software, by using the device-dependent key; and

launch the connection software downloaded from the second server in the volatile memory using the device-dependent key, when it is determined that mounting of the external storage has succeeded and that the authentication of the electronic apparatus with the second server has succeeded, wherein launching involves logging in to the first server apparatus with credentials;

wherein when a caching function does not exist on the electronic apparatus, mounting of the external storage is unsuccessful, caching capabilities on the electronic apparatus are disabled, or reading of the downloaded connection software is unsuccessful, the hardware processor is further configured to:

download the connection software configured to be decrypted using a common key, the connection software enabling the electronic apparatus to connect to the virtual desktop environment of the first server apparatus, when authentication of the electronic apparatus with the second server apparatus has succeeded;

develop, by the executing firmware, the connection software on the volatile memory included in the electronic apparatus; and

launch the connection software downloaded from the second server apparatus on the volatile memory, using the common key, when it is determined that the electronic apparatus is powered on; and

when the electronic apparatus is disconnected from the first server apparatus after connection between the electronic apparatus and the first server apparatus is established, the firmware erases data in the volatile memory.

2. The electronic apparatus of claim 1 , wherein the hardware processor is configured to:

perform a process for causing the external storage to be in a mounted state for enabling the electronic apparatus to recognize the external storage, when the electronic apparatus is powered on;

decrypt the connection software by using the device-dependent key to launch the connection software, when it is determined that mounting of the external storage has succeeded and it is determined that the connection software is cached in the external storage; and

release the external storage from the mounted state to enable the external storage to be unrecognized when the decryption of the connection software has been succeeded.

3. The electronic apparatus of claim 1 , wherein the hardware processor is configured to:

download, when the connection software is cached in the external storage and the connection software is updated in the second server apparatus, the updated connection software from the second server apparatus; and

overwrite the updated connection software on the connection software cached in the external storage.

4. The electronic apparatus of claim 1 , wherein when the connection software downloaded from the second server apparatus is encrypted by a common key, the hardware processor is configured to:

decrypt the encrypted connection software by a common key distributed to the electronic apparatus;

encrypt the decrypted connection software again by the device-dependent key and store the connection software to be cached in the external storage; and

decrypt the connection software cached in the external storage by the device-dependent key; and

develop the connection software; and

launch the connection software on the volatile memory.

5. A method to be executed by an electronic apparatus configured to operate with a virtual desktop environment without comprising a built-in storage, the electronic apparatus comprising:

an external storage which is a nonvolatile memory configured not to permit a user to access the external storage; and

a hardware processor configured to execute firmware, upon powering on the electronic apparatus, the firmware including a network communication function for communicating with a first server apparatus configured to provide the virtual desktop environment and further communicating with a second server apparatus configured to manage connection to the first server apparatus,

the method comprising:

based on an internal policy, determining whether a caching function exists on the electronic apparatus;

wherein when a caching function exists on the electronic apparatus, performing a mounting of the external storage and further determine whether the mounting is successful;

when the mounting is successful, the method performing further steps comprising:

downloading, from the second server, connection software configured to enable the electronic apparatus to connect to the virtual desktop environment of the first server apparatus when authentication of the electronic apparatus with the second server apparatus has succeeded;

encrypting the downloaded connection software by a device-dependent key that is generated, based at least in part on inherent information of the electronic apparatus;

attempting to cache the encrypted connection software in the external storage by the device-dependent key;

determining if the external storage has caching capabilities by checking 1) if the connection software can be written to the external storage and 2) if the connection software is readable from the storage;

if the connection software is successfully cacheable, decrypting the connection software, by using the device-dependent key; and

launching the connection software downloaded from the second server in the volatile memory using the device-dependent key, when it is determined that mounting of the external storage has succeeded and that the authentication of the electronic apparatus with the second server has succeeded, wherein launching involves logging in to the first server apparatus with credentials;

wherein when a caching function does not exist on the electronic apparatus, mounting of the external storage is unsuccessful, caching capabilities on the electronic apparatus are disabled, or reading of the downloaded connection software is unsuccessful, the hardware processor is further configured to:

downloading the connection software configured to be decrypted using a common key, the connection software enabling the electronic apparatus to connect to the virtual desktop environment of the first server apparatus, when authentication of the electronic apparatus with the second server apparatus has succeeded;

developing, by the executing firmware, the connection software on the volatile memory included in the electronic apparatus; and

launching the connection software downloaded from the second server apparatus on the volatile memory, using the common key, when it is determined that the electronic apparatus is powered on; and

erasing data in the volatile memory, when the electronic apparatus is disconnected from the first server apparatus after connection between the electronic apparatus and the first server apparatus is established.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2019
From: KABUSHIKI KAISHA TOSHIBA
To: TOSHIBA CLIENT SOLUTIONS CO., LTD.
Reel/Frame 048720/0635 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TWO PARTS OF THE ENGLISH TRANSLATION OF THE EMPLOYMENT AGREEMENT PREVIOUSLY RECORDED ON REEL 047772 FRAME 0715. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 21, 2018
From: WADA, KOUETSU; MATSUDA, KYOHEI
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 047984/0325 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2018
From: NUNAMI, TSUKASA; MOMOSAKI, KOHEI
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 047772/0702 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2018
From: WADA, KOUETSU; MATSUDA, KYOHEI
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 047772/0715 →
Priority Claims (1)
JP 2015-253855 · Dec 25, 2015 · national
Continuity (1)
Related Publication 20170185530A1 · Jun 29, 2017