Trusted Application Delivery Without Duplicate Entitlement Databases

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualization environments, managing user entitlements for applications across multiple systems leads to technical challenges and inefficiencies due to duplicated user entitlement data, requiring separate databases for connection servers and application managers.

Innovation Solution

Establishing trust between a connection server and an application manager by sharing a public certificate and administrative credentials, allowing the connection server to manage user entitlements for both server-managed and on-demand applications without duplicating data across databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user entitlements are managed separately in multiple systems (connection server and application manager), then each system can independently control access to its applications, but user entitlement data is duplicated across multiple databases, increasing storage space requirements and computational complexity

Engineering Contradiction:
Improveindependent access controlVSAvoiddata management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the user entitlement management functionality into a single centralized location (the connection server) while maintaining the ability for the application manager to independently control application delivery. The connection server stores user entitlement data and communicates with the application manager through standardized interfaces, eliminating the need for separate entitlement databases in each system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The connection server is designed to perform multiple functions: it manages user entitlements for both virtualized applications and on-demand applications, authenticates users, and coordinates with different application delivery systems. This multi-functional approach consolidates what would otherwise require separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If user entitlement data is duplicated in multiple databases, then each system has full control over its application access, but storage space is wasted and computational complexity increases

Engineering Contradiction:
Improvesystem autonomyVSAvoidstorage space
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent consolidates user entitlement data into a single database at the connection server, eliminating redundant storage across multiple systems. The application manager receives necessary entitlement information through standardized communication protocols, maintaining system autonomy without requiring duplicate data storage.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate databases are used for connection server and application manager, then each system can independently manage its applications, but computational complexity increases due to data synchronization and verification

Engineering Contradiction:
Improveindependent application managementVSAvoidcomputational efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the user entitlement management function from the application manager and places it exclusively in the connection server. The application manager focuses solely on application delivery and execution, while entitlement verification is handled by the connection server, reducing computational overhead for both systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The connection server acts as an intermediary between users and the application manager, handling all entitlement verification and user authentication. This mediator approach allows the application manager to operate independently without direct involvement in complex entitlement management computations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12567980B2Delivering applications on demand based on trust between systems
Publication Date: 2026.03.03 OMNISSA LLC
  • US12567980B2 patent drawing
  • US12567980B2 patent drawing
  • US12567980B2 patent drawing

AI summary

A computerized method of delivering applications includes transmitting, by a connection server, a registration request to an application manager server, the registration request including administration credentials for the application manager server and a public certificate of the connection server, the administration credentials causing the application manager server to trust the connection server regarding application requests; receiving, by the connection server, a user application launch request from a user device, the user application launch request identifying an application; generating a proxy application launch request for the received user application launch request, the proxy application launch request identifying the application and including a signed message created with a private key associated with the public certificate; and transmitting the proxy application launch request for delivery to the application manager server, causing the application manager server to make the application available to the user device after authenticating the signed message.