Virtual Machine Deployment for Enterprise Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users may not be able to access enterprise applications on their devices if the applications are incompatible with the host operating system, and enrollment in an Enterprise Mobility Management (EMM) system is required, which can be a barrier due to compliance rules and security requirements.
Innovation Solution
A management service creates and manages virtual machines on client devices to emulate the execution of applications, using a hypervisor and guest management components to ensure compliance with enterprise policies, allowing the application to appear as if it is natively installed and executed by the host operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a user enrolls a device through an EMM system to access enterprise applications, then the user can access applications that require compliance rules and security policies, but the device enrollment process becomes complex and restrictive due to compliance rules and security requirements
Solution Approach 1:
The patent introduces a virtual machine as an intermediary layer between the user device and enterprise applications. This virtual machine handles the complex EMM enrollment and compliance requirements, while the user interacts with a simplified interface. The virtual machine acts as a mediator that isolates the complexity of device enrollment from the end user, allowing application access without requiring users to directly manage compliance rules and security policies.
Solution Approach 2:
The system segments the device enrollment process by separating the virtual machine environment from the host device. The virtual machine can be enrolled independently with specific compliance rules, while the host device maintains its own security profile. This segmentation allows targeted application of EMM policies only where needed, reducing overall enrollment complexity for users.
2Ease of operation
If enterprise applications are made browser-based with authentication, then users can access applications without device enrollment, but applications with complex compliance requirements cannot be properly secured
Solution Approach 1:
The virtual machine serves as an intermediary that provides both ease of access and security compliance. Users can access applications through a simplified interface similar to browser-based access, while the virtual machine backend enforces comprehensive EMM compliance rules and security policies. This intermediary layer maintains security reliability without sacrificing user accessibility.
Solution Approach 2:
The system changes the operational parameters of application delivery by transitioning from direct host execution or simple browser-based access to virtualized execution with configurable compliance parameters. The virtual machine allows dynamic adjustment of security parameters, compliance rules, and access controls, enabling both easy user access and robust security enforcement simultaneously.
3Ease of operation
If the virtual machine console is hidden and user interfaces are generated by the hypervisor, then the application appears to execute natively improving user experience, but the system complexity increases
Solution Approach 1:
The hypervisor creates a copy or representation of the native application interface that users can interact with. Instead of showing the actual virtual machine console, the system generates replicated user interface elements that mimic native application behavior. This copying approach provides an improved user experience with native-like interaction while the underlying virtualization complexity remains hidden from users.
Solution Approach 2:
The hypervisor acts as an intermediary that translates between the virtual machine environment and the user interface layer. It generates user interfaces that appear native while routing interactions to the appropriate virtualized applications. This intermediary layer manages the complexity of virtualization transparently, providing simplified native-like interactions to users.
Data Source
AI summary
A system can include computer instructions that can cause a computing device to obtain a request to access an application on behalf of a user. The request can be obtained from a client device associated with the user. The computer instructions can further cause the computing device to determine whether the client device is required to execute a virtual machine that executes the application. The computer instructions can further cause the computing device to identify whether the virtual machine is installed in the client device. The computer instructions can further cause the computing device to cause the virtual machine to be installed in the client device.


