Thin Client Profile-Specific Remote Virtual Machines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of personal devices in enterprise environments poses security risks due to the storage of sensitive enterprise data and credentials, and compatibility issues arise from the variety of operating systems and device characteristics, making it challenging to ensure secure and uniform access to managed applications.

Innovation Solution

Implementing a system with profile-specific remote virtual machines, where a thin client on the user device accesses guest applications running on a remote server, keeping sensitive information off the device and allowing access to enterprise applications through a virtual machine environment configured based on user or device profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprise data is stored locally on personal user devices, then data access and productivity are improved, but security risks increase due to exposure of sensitive credentials and enterprise files

Engineering Contradiction:
Improvedata accessVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive enterprise data and credentials from the personal user device by implementing a thin client architecture where enterprise applications run in isolated containers on the user's personal device, while actual data storage and processing occur on secure enterprise servers. This separation removes the harmful element (sensitive data) from the vulnerable location (personal device) while maintaining productive access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer - a thin client with containerized enterprise applications - that mediates between the personal user device and enterprise data resources. This intermediary enables secure data access by acting as a controlled interface that prevents direct exposure of sensitive credentials while maintaining productivity through seamless application access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If managed applications are separately developed for each operating system, then compatibility with specific devices is improved, but device complexity and development costs increase

Engineering Contradiction:
Improveoperating system compatibilityVSAvoiddevelopment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a thin client architecture with containerized enterprise applications that can run on any personal user device regardless of operating system. The containerization technology creates a standardized execution environment that abstracts away OS-specific differences, allowing the same enterprise applications to function universally across iOS, Android, and other mobile platforms without separate development for each OS.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10324745B2Thin client with managed profile-specific remote virtual machines
Publication Date: 2019.06.18 OMNISSA LLC
  • US10324745B2 patent drawing
  • US10324745B2 patent drawing
  • US10324745B2 patent drawing

AI summary

Systems herein include thin clients that operate with managed profile-based virtual machines. This can allow users to utilize personal user devices in an enterprise environment without subjecting sensitive enterprise credentials to the user device. A management server can determine a profile associated with the user device. Based on the profile, a virtual machine can be instantiated at a thin server, remotely from the thin client. The profile-specific virtual machine can include a particular guest operating system, guest applications, security features, or functionality. The instance of the virtual machine can communicate graphics information from a guest application to the thin client, and the thin client can communicate user interface events to the instance for controlling the guest application.