Virtual Machine Deployment for Enterprise Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users may not be able to access enterprise applications on their devices if the applications are incompatible with the host operating system, and enrollment in an Enterprise Mobility Management (EMM) system is required, which can be a barrier due to compliance rules and security requirements.

Innovation Solution

A management service creates and manages virtual machines on client devices to emulate the execution of applications, using a hypervisor and guest management components to ensure compliance with enterprise policies, allowing the application to appear as if it is natively installed and executed by the host operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a user enrolls a device through an EMM system to access enterprise applications, then the user can access applications that require compliance rules and security policies, but the device enrollment process becomes complex and restrictive due to compliance rules and security requirements

Engineering Contradiction:
Improveapplication accessibilityVSAvoidenrollment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual machine as an intermediary layer between the user device and enterprise applications. This virtual machine handles the complex EMM enrollment and compliance requirements, while the user interacts with a simplified interface. The virtual machine acts as a mediator that isolates the complexity of device enrollment from the end user, allowing application access without requiring users to directly manage compliance rules and security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the device enrollment process by separating the virtual machine environment from the host device. The virtual machine can be enrolled independently with specific compliance rules, while the host device maintains its own security profile. This segmentation allows targeted application of EMM policies only where needed, reducing overall enrollment complexity for users.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If enterprise applications are made browser-based with authentication, then users can access applications without device enrollment, but applications with complex compliance requirements cannot be properly secured

Engineering Contradiction:
Improveapplication access easeVSAvoidsecurity compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The virtual machine serves as an intermediary that provides both ease of access and security compliance. Users can access applications through a simplified interface similar to browser-based access, while the virtual machine backend enforces comprehensive EMM compliance rules and security policies. This intermediary layer maintains security reliability without sacrificing user accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the operational parameters of application delivery by transitioning from direct host execution or simple browser-based access to virtualized execution with configurable compliance parameters. The virtual machine allows dynamic adjustment of security parameters, compliance rules, and access controls, enabling both easy user access and robust security enforcement simultaneously.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If the virtual machine console is hidden and user interfaces are generated by the hypervisor, then the application appears to execute natively improving user experience, but the system complexity increases

Engineering Contradiction:
Improveuser experienceVSAvoidvirtualization layer complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The hypervisor creates a copy or representation of the native application interface that users can interact with. Instead of showing the actual virtual machine console, the system generates replicated user interface elements that mimic native application behavior. This copying approach provides an improved user experience with native-like interaction while the underlying virtualization complexity remains hidden from users.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The hypervisor acts as an intermediary that translates between the virtual machine environment and the user interface layer. It generates user interfaces that appear native while routing interactions to the appropriate virtualized applications. This intermediary layer manages the complexity of virtualization transparently, providing simplified native-like interactions to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10255092B2Managed virtual machine deployment
Publication Date: 2019.04.09 OMNISSA LLC
  • US10255092B2 patent drawing
  • US10255092B2 patent drawing
  • US10255092B2 patent drawing

AI summary

A system can include computer instructions that can cause a computing device to obtain a request to access an application on behalf of a user. The request can be obtained from a client device associated with the user. The computer instructions can further cause the computing device to determine whether the client device is required to execute a virtual machine that executes the application. The computer instructions can further cause the computing device to identify whether the virtual machine is installed in the client device. The computer instructions can further cause the computing device to cause the virtual machine to be installed in the client device.