Remote Application Streaming Service Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Administrators of modern enterprise environments face challenges in delivering and maintaining applications across diverse execution environments with varying access to corporate networks, and ensuring applications execute without interfering with other programs, especially in multi-user operating systems where single-user applications may not be designed to run in isolation.

Innovation Solution

A method for selecting execution methods for application programs based on credentials, involving enumeration of available applications, policy-driven selection of execution methods, including application streaming, and providing isolation environments for services to operate independently, allowing applications to execute on remote machines and output data to be streamed back to local machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are executed locally on diverse machines, then application execution capability is maintained, but compatibility and reliability deteriorate due to varying execution environments

Engineering Contradiction:
Improveapplication execution capabilityVSAvoidapplication compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a remote application execution service as an intermediary between the user and the application execution environment. Instead of executing applications directly on diverse local machines, the system mediates execution through a centralized service that provides a consistent execution environment, thereby ensuring compatibility while maintaining execution capability across different client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual copies of the application execution environment through remote virtual machines or containers. These copied environments provide a standardized platform for application execution, allowing applications to run reliably regardless of the underlying hardware or operating system differences of the local machines.

Inventive Principle:
Principle #26Copying

2Productivity

If multiple applications run on the same machine, then resource utilization is improved, but interference and instability increase due to conflicting requirements

Engineering Contradiction:
Improveresource utilizationVSAvoidapplication stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the application execution environment into isolated virtual machines or containers, where each application runs in its own dedicated space. This segmentation allows multiple applications to utilize system resources simultaneously without interfering with each other, as each isolated environment has its own process space, file system, and system libraries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides customized execution environments tailored to each application's specific requirements. Each isolated environment can be configured with the appropriate software versions, dependencies, and system settings needed by that particular application, ensuring optimal performance and stability while allowing diverse applications to coexist on the same physical machine.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If single-user applications run in multi-user operating systems, then application accessibility is improved, but isolation and security deteriorate

Engineering Contradiction:
Improveapplication accessibilityVSAvoidapplication isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The remote application execution service acts as an intermediary that enables single-user applications to run in multi-user environments through virtualization. The virtual machine or container provides a isolated execution context that maintains the application's original design assumptions while allowing it to access system resources through controlled interfaces, thus preserving both accessibility and isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses virtual machine images or container configurations as flexible shells that encapsulate the application and its dependencies. These thin film-like virtualized environments provide a protective layer between the application and the underlying multi-user operating system, enabling seamless execution while maintaining strong isolation boundaries.

Inventive Principle:
Principle #30Flexible shells and thin films

Data Source

PatentUS9965622B2Systems and methods for RADE service isolation
Publication Date: 2018.05.08 CITRIX SYSTEMS INC
  • US9965622B2 patent drawing
  • US9965622B2 patent drawing
  • US9965622B2 patent drawing

AI summary

The present invention is directed towards systems and methods of streaming an application from a remote location to a local machine system, and using local machine system resources in executing that application. In various embodiments, services needed by a streamed application may be started with high local system privileges in their own isolation environment. These service may be started, stopped, and otherwise managed by a Service Control Manager. In order for an application to both access services that operate at high local system privileges and the network so that it can access remotely stored, streaming, information; a streaming application may rely on privileges of the user when accessing network information rather than the higher privileges of the services running in isolation.