IP Library Granted Patent US 11,616,821
Granted Patent B1
US 11,616,821 · App. 16/574,009 · Granted Mar 28, 2023

System and method for streaming application isolation

Inventor: Allan Havemose (Arroyo Grande, CA)
Assignee: International Business Machines Corporation
H04L65/61H04L63/0823H04L63/20H04L67/01H04W4/60H04L63/145H04L63/166H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,616,821
App. No.
16/574,009
Granted
Mar 28, 2023
Kind
B1
Abstract

Providing streaming of one or more applications from streaming servers onto one or more clients. The computer readable medium includes computer-executable instructions for execution by a processing system. The applications are contained within one or more isolated environments, and the isolated environments are streamed from the servers onto clients. The system may include authentication of the streaming servers and authentication of clients and credentialing of the isolated environments and applications the clients are configured to run. The system may include encrypted communication between the streaming servers and the clients. The system may further include a management interface where administrators may add, remove and configure isolated environments, configure client policies and credentials, and force upgrades. The streamed isolated environments may be isolated from other applications and the host operating system on the clients and applications within the isolated environments may run without performing an application-installation on the client.

Claims (31)

1. A system, comprising:

a host server comprising one or more memory and storage locations configured to store one or more server isolated environments and one or more host server update-caches, wherein the one or more server isolated environments each comprise at least one or more applications and files for the at least one or more applications;

one or more clients, each comprising:

one or more memory and storage locations configured to store one or more client isolated environments,

a client update-cache for each of the one or more client isolated environments, wherein the one or more client isolated environments comprise at least one or more applications and files for the one or more applications, and

wherein each of the one or more host server update-caches are configured to:

compare a corresponding one or more host server update-cache to a client update-cache, of the one or more client update caches, to identify a file in a client isolated environment that has changed since last being streamed to a client of the one or more clients.

2. The system according to claim 1 , wherein a client policy manager stores client account records comprising one or more of:

a client login, an account holder name, a status of account, and a list of credentialed isolated environments.

3. The system according to claim 1 , wherein the one or more clients are authenticated against a client policy manager and access to applications and isolated environments are granted based on the client-authentication, wherein authentication of the client credentials is performed by using at least one of a certificate, a user-id, and a client policy manager.

4. The system according to claim 1 , wherein the host server is authenticated using a certificate and the one or more clients validate the host certificate before accepting streaming applications from the host server, wherein secure socket layer (SSL) encrypted communication is established using the certificate between the one or more clients and the isolated environment of the host server.

5. The system according to claim 1 , wherein the client credentials for the one or more clients are validated for access to the isolated environments.

6. The system according to claim 5 , wherein non-credentialed isolated environments are removed from the one or more clients.

7. The system according to claim 5 , wherein a credentialed isolated environment is updated if the credentialed isolated environment is already installed on the one or more clients.

8. The system according to claim 5 , wherein a credentialed isolated environment is installed on the one or more clients if the credentialed isolated environment is not already installed.

9. The system according to claim 1 , further comprising:

a graphical user interface configured to provide the one or more clients with an option to select which isolated environment to access.

10. The system according to claim 9 , wherein a most recently run isolated environment is automatically selected for access.

11. The system according to claim 1 , wherein the one or more clients access at least one client isolated environment without validating credentials against the isolated environment of the host server.

12. The system according to claim 1 , wherein the one or more clients are validated against the isolated environment of the host server prior to accessing any isolated environments.

13. The system according to claim 12 , wherein the one or more clients access already installed isolated environments without accepting updates from the isolated environment of the host server.

14. The system according to claim 1 , wherein a client policy manager contains a record with credentialed isolated environments, account information, and a cache sub-system for each of the one or more clients.

15. The system according to claim 1 further comprising:

a management interface wherein an administrator configures client configuration settings and isolated environment host server configuration settings.

16. The system according to claim 15 , wherein at least one or more applications are streamed to the one or more clients and the one or more clients can access the one or more applications without performing a local installation.

17. The system according to claim 15 , wherein the client configuration settings comprise one or more of:

adding and removing credentialed isolated environments, adding and removing clients, forcing a rebuild of client update-caches, setting user-names, and setting account status.

18. The system according to claim 15 , wherein the isolated environment host server configuration settings comprise one or more of:

installing and removing isolated environments, updating isolated environments, rebuilding one or more update caches, setting a compression algorithm, and setting a message digest algorithm.

19. The system according to claim 15 , wherein the management interface is provided using a graphical user interface.

20. The system according to claim 15 , wherein the management interface is provided using an application programming interface (API).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2022
From: HAVEMOSE, ALLAN
To: OPEN INVENTION NETWORK LLC
Reel/Frame 061679/0812 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2022
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061365/0571 →