Trusted Application Delivery Without Duplicate Entitlement Databases
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualization environments, managing user entitlements for applications across multiple systems leads to technical challenges and inefficiencies due to duplicated user entitlement data, requiring separate databases for connection servers and application managers.
Innovation Solution
Establishing trust between a connection server and an application manager by sharing a public certificate and administrative credentials, allowing the connection server to manage user entitlements for both server-managed and on-demand applications without duplicating data across databases.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user entitlements are managed separately in multiple systems (connection server and application manager), then each system can independently control access to its applications, but user entitlement data is duplicated across multiple databases, increasing storage space requirements and computational complexity
Solution Approach 1:
The patent merges the user entitlement management functionality into a single centralized location (the connection server) while maintaining the ability for the application manager to independently control application delivery. The connection server stores user entitlement data and communicates with the application manager through standardized interfaces, eliminating the need for separate entitlement databases in each system.
Solution Approach 2:
The connection server is designed to perform multiple functions: it manages user entitlements for both virtualized applications and on-demand applications, authenticates users, and coordinates with different application delivery systems. This multi-functional approach consolidates what would otherwise require separate specialized systems.
2Adaptability or versatility
If user entitlement data is duplicated in multiple databases, then each system has full control over its application access, but storage space is wasted and computational complexity increases
Solution Approach 1:
The patent consolidates user entitlement data into a single database at the connection server, eliminating redundant storage across multiple systems. The application manager receives necessary entitlement information through standardized communication protocols, maintaining system autonomy without requiring duplicate data storage.
3Adaptability or versatility
If separate databases are used for connection server and application manager, then each system can independently manage its applications, but computational complexity increases due to data synchronization and verification
Solution Approach 1:
The patent extracts the user entitlement management function from the application manager and places it exclusively in the connection server. The application manager focuses solely on application delivery and execution, while entitlement verification is handled by the connection server, reducing computational overhead for both systems.
Solution Approach 2:
The connection server acts as an intermediary between users and the application manager, handling all entitlement verification and user authentication. This mediator approach allows the application manager to operate independently without direct involvement in complex entitlement management computations.
Data Source
AI summary
A computerized method of delivering applications includes transmitting, by a connection server, a registration request to an application manager server, the registration request including administration credentials for the application manager server and a public certificate of the connection server, the administration credentials causing the application manager server to trust the connection server regarding application requests; receiving, by the connection server, a user application launch request from a user device, the user application launch request identifying an application; generating a proxy application launch request for the received user application launch request, the proxy application launch request identifying the application and including a signed message created with a private key associated with the public certificate; and transmitting the proxy application launch request for delivery to the application manager server, causing the application manager server to make the application available to the user device after authenticating the signed message.


