Virtualized Enterprise Apps in Managed VMs for Clean Removal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The management of personal devices used for accessing enterprise resources in BYOD scenarios faces challenges such as incomplete uninstallation of applications, residual artifacts, and improper configuration changes, leading to unacceptable issues for both enterprises and users.
Innovation Solution
A networked environment utilizing managed virtual machines (VMs) and virtualized applications, managed by a management service, ensures proper installation, configuration, and removal of enterprise applications, with features like virtualized application delivery and encryption, ensuring compliance and data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional application installation methods are used on personal devices, then application functionality is provided, but incomplete uninstallation and residual artifacts occur
Solution Approach 1:
The patent segments the application delivery system into virtualized application packages that are self-contained and isolated from the host operating system. Each application runs in a virtualized environment, allowing complete removal of the virtualization layer and all associated artifacts without affecting the host system or leaving residual files.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the application and the host operating system. This intermediary layer manages all application files, registry entries, and system resources, enabling clean uninstallation by simply removing the virtualization layer while leaving the host system untouched.
2Adaptability or versatility
If enterprise applications are installed directly on personal devices, then access to enterprise resources is enabled, but device management and compliance enforcement become difficult
Solution Approach 1:
The patent segments enterprise applications into isolated virtualized packages that run independently on personal devices. This segmentation allows the enterprise to manage and control specific application behaviors without needing to manage the entire device, simplifying compliance enforcement while maintaining resource access.
Solution Approach 2:
The patent applies local quality by implementing management controls specifically within the virtualized application environment rather than at the device level. Each virtualized application can have its own policies, restrictions, and configurations applied locally, enabling fine-grained control without affecting the overall device management complexity.
3Ease of operation
If applications are delivered traditionally to personal devices, then installation is straightforward, but improper configuration changes and service removal issues occur
Solution Approach 1:
The patent uses copying by delivering virtualized application packages that contain complete, pre-configured copies of the application and all its dependencies. These packages are self-contained and can be copied to multiple devices without requiring complex installation processes, ensuring consistent and accurate configuration across all deployments.
Solution Approach 2:
The patent applies preliminary action by pre-configuring all application settings, dependencies, and system integrations within the virtualized package before delivery. This preliminary configuration ensures that when the application is installed on a personal device, it automatically has the correct configuration without requiring manual setup or risking improper system changes.
4Adaptability or versatility
If BYOD devices are used for enterprise access, then user flexibility is improved, but offline usage causes management service communication issues
Solution Approach 1:
The patent implements self-service by embedding management service communication capabilities directly within the virtualized application package. The virtualized application can autonomously manage its own compliance status, update its configuration, and maintain security policies even when offline, eliminating the need for continuous connection to the enterprise management service.
Data Source
AI summary
Examples of enterprise management using managed virtual machines for virtualized applications are described. In some examples, a managed virtual machine is executed on a host device and enrolled with a management service. A virtualized application drive is stored in the managed virtual machine. A launch agent executed within the managed virtual machine detects an application access request corresponding to user interaction with a host operating system of the host device. The application volumes launch agent accesses the virtualized application drive and launches the virtualized application corresponding to the application access request.


