Computerized method of managing a computer remote session operation
A computerized method of managing a computer remote session operation, comprising providing a server for hosting application execution; configuring a number of predefined user accounts with low security permissions on said server, where said user accounts are not tied to any specific real user; Whenever a remote user requests to start a remote session, finding an available user account not currently in use on said computer, allocating it for the remote session and marking it as unavailable for subsequent session requests; Generating a one-time password for said user account; Communicating the assigned user account identifier and temporary password to client component on the user's side, either directly or through an intermediate broker; causing the client component to connect to the server using said user account identifier and temporary password; and, upon termination of the remote session, deleting the assigned user account's data and marking it as available again.
1. A computerized method of managing remote sessions, the method comprising:
configuring plural predefined user accounts with low security permissions on a remote server for hosting execution of an application;
whenever a remote user requests to start a remote session, finding an available user account, from among said plural predefined user accounts, which is not currently in use on said computer, allocating the available user account for the remote session and marking the available user account as unavailable;
generating a temporary password for said user account;
communicating the assigned user account identifier and temporary password to a client component on the user's computer, either directly or through an intermediate broker;
causing the client component to connect to the server using said user account identifier and said password; and
upon termination of the remote session, deleting the assigned user account's data,
wherein said remote sessions require no permanent tie between Internet users and individual operating system user accounts and instead, allow plural Internet users to connect to a local application which defines plural OS user accounts by finding an available OS user account for each of the Internet users, and
wherein all traces of a given ending session with a first user are destroyed.
2. The method of claim 1 , wherein at least one program in the remote session that a user has requested to start is controlled using a virtualized storage method comprising:
defining an arbitrary directory path on the user's computer.
3. The method of claim 1 , wherein the user requests a specific virtual application to be used as part of the user's remote session, the method further comprising provisioning the requested specific virtual application to the remote server, before letting the user's remote session start.
4. The method of claim 1 , wherein sessions are started with a user-specified file to open as a parameter.
5. The method of claim 4 , wherein, upon session start, a server component downloads said user-specified file from a remote storage on the user's computer, using previously acquired user storage access tokens.
6. The method of claim 5 , wherein the server component launches an application capable of handling the user's selected file according to the file's type.
7. A system configured for managing a remote session operation of a computer, comprising processing circuitry configured to perform the following:
configuring a number of predefined user accounts with security permissions on a server for hosting application execution, where said user accounts are not tied to any specific real user;
wherein all traces of a given ending session with a first user are destroyed;
whenever a remote user requests to start a remote session, finding an available user account not currently in use on said computer, allocating the available user account for the remote session and marking the available user account as unavailable for subsequent session requests;
generating a temporary password for said user account;
communicating the assigned user account identifier and said temporary password to a client component on the user's computer;
causing the client component to connect to the server using said user account identifier and said temporary password; and
upon termination of the remote session, deleting the assigned user account's data,
wherein said remote sessions require no permanent tie between Internet users and individual operating system user accounts and instead, allow plural Internet users to connect to a local application which finds an available OS user account for each of the Internet users thereby to define plural OS user accounts, and
wherein a remote application session is brokered for each of the Internet users, accordingly.
8. The system of claim 7 , wherein the assigned user account identifier is communicated to the client component on the user's computer through an intermediate broker.
9. The method of claim 2 , wherein a remote application session is brokered for each of the Internet users, accordingly, including
marking those OS user accounts as “in use”, and,
at least once, when a further Internet user requests a remote session, and the local application finds that an individual OS user account from among the plural OS user accounts is available, a remote session is brokered for the further Internet user by allocating the individual OS user account which is now available to the further Internet user.
10. The system of claim 7 , further comprising the server for hosting application execution.
11. The system of claim 7 , wherein the assigned user account identifier and temporary password are communicated directly to the client component on the user's computer.
12. The method of claim 1 , wherein at least one remote session is coupled with its own cloud storage using storage virtualization.
13. The method of claim 12 , wherein at least one Internet user is connected to personal remote storage and can see and work on her or his personal cloud files.
14. The method of claim 13 , wherein at least one given server accommodates N users, without requiring N individual operating system accounts for the N users.
15. The system of claim 7 , wherein the temporary password is communicated to the client component on the user's computer through an intermediate broker.
16. The system of claim 7 , wherein said plural OS user accounts are marked as “in use”.
17. A computer program product, comprising a non-transitory tangible computer readable medium having computer readable program code embodied therein, said computer readable program code adapted to be executed to implement a method of managing a remote session operation of a user's computer, the method comprising:
configuring plural predefined user accounts with low security permissions on a remote server for hosting execution of an application, wherein all traces of a given ending session with a first user are destroyed;
whenever a remote user requests to start a remote session, finding an available user account, from among said plural predefined user accounts, which is not currently in use on said user's computer, allocating the available user account for the remote session and marking the available user account as unavailable;
generating a temporary password for said user account;
communicating the assigned user account identifier and the temporary password to a client component on the user's computer, either directly or through an intermediate broker;
causing the client component to connect to the server using said user account identifier and said temporary password; and
upon termination of the remote session, deleting the assigned user account's data,
wherein said remote sessions require no permanent tie between Internet users and individual operating system user accounts and
instead, allow plural Internet users to connect to a local application which defines plural OS user accounts by finding an available OS user.
18. The system of claim 16 , wherein, at least once, when a further Internet user requests a remote session, the local application brokers a remote session for the further Internet user.
19. The system of claim 18 , wherein the remote session is brokered by allocating an individual OS user account which is now available to the further Internet user.
20. The method of claim 19 , wherein the virtualized storage method also comprises causing file enumeration operation requests sent from at least one controlled program to an operating system of the user's computer to be intercepted.
21. The method of claim 20 , wherein the virtualized storage method also comprises checking, for at least one file enumeration operation request intercepted, whether the file enumeration operation request is targeted at said arbitrary directory path or a subdirectory thereof.
22. The method of claim 21 , wherein the virtualized storage method comprises initiating a file enumeration request on a remote storage when the file enumeration operation request is targeted at said arbitrary directory path or a subdirectory thereof.
23. The method of claim 22 , wherein when the file enumeration operation request is targeted at said arbitrary directory path or a subdirectory thereof, the virtualized storage method also comprises returning the result of the remote enumeration operation to the controlled program.
24. The method of claim 3 , further comprising, upon start of the remote session, launching the requested specific virtual application and causing the requested specific virtual application to be rendered to the user.
25. The method of claim 1 , wherein said user accounts are not tied to any specific real user.