Systems and methods for accelerating delivery of a computing environment to remote user
Abstract
<B> SYSTEMS AND METHODS FOR ACCELERATING THE DELIVERY OF A COMPUTING ENVIRONMENT TO A REMOTE USER <D> The present invention relates to accelerating the delivery of a computing environment to a remote user of a customer at a remote location, The computing environment can include an application and a data file used or processed by the application. The application and the data file can be stored or provided through a remote server for the client. The user can request a computing environment from the server that provides the application to run by the user through the remote computer. For example, the server can continuously stream the application to a remote client. The client and the server can communicate through a device that speeds up the communications between the client and the server. For example, the system can speed up the continuous transmission of the application to the remote user. In some cases, the system or the remote user may also request a data file from the server, and the system speeds up the delivery of the data file to the remote user. As such, users in remote locations gain accelerated access through any networked device to applications and data files located remotely for the user.

Term
Projected expiry 11 April 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
60 claims: 4 independent, 56 dependent
- 1CLAIMS REIVINDICAÇÕES 1. Method for accelerating the delivery of a computing environment to a remote client, the method comprising the steps of:1. Método para aceleração da entrega de um ambiente de computação para um cliente remoto, o método compreendendo as etapas de: (a) recebimento, pelo servidor, de uma requisição a partir de um cliente remoto para execução de um aplicativo, o cliente remoto e o servidor em comunicação através de uma aparelhagem;(a) receipt, by the server, of a request from a remote client for the execution of an application, the remote client and the server in communication through an apparatus;(b) continuous transmission, by the server, to the remote client of an application for execution;. (b) transmissão contínua, pelo servidor, para o cliente remoto de um aplicativo para execução;. (c) transmission, by the server, of a data file requested by the remote client for access by the continuously transmitted application;and (d) acceleration, by the apparatus, of the transmission of the data file to the remote client. (c) transmissão, pelo servidor, de um arquivo de dados requisitado pelo cliente remoto para acesso pelo aplicativo transmitido continuamente;e (d) aceleração, pela aparelhagem, da transmissão do arquivo de dados para o cliente remoto.
- 20System for accelerating the delivery of a computing environment to a remote client, the system comprising:20. Sistema para a aceleração da entrega de um ambiente de computação para um cliente remoto, o sistema compreendendo: a device for accelerating communications between one or more clients and one or more servers;uma aparelhagem para a aceleração das comunicações entre um ou mais clientes e um ou mais servidores;a server receiving a request from a remote client to run an application, the server continuously transmitting an application to run to the remote client through the appliance in response to the request;um servidor recebendo uma requisição a partir de um cliente remoto para execução de um aplicativo, o servidor transmitindo continuamente para o cliente remoto através da aparelhagem um aplicativo para execução, em resposta à requisição;onde o servidor transmite um arquivo de dados requisitado pelo cliente remoto para acesso pelo aplicativo transmitido continuamente;e a aparelhagem acelera a transmissão do arquivo de dados para o cliente remoto. where the server transmits a data file requested by the remote client for access by the continuously transmitted application;and the system speeds up the transmission of the data file to the remote client.
- 39Method for accelerating the delivery of a computing environment to a remote customer through a customer agent and an apparatus, the method comprising the steps of:39. Método para a aceleração da entrega de um ambiente de computação para um cliente remoto através de um agente de cliente e uma aparelhagem, o método compreendendo as etapas de: (a) continuous transmission, through an apparatus, to a client agent of an application for execution requested by a remote client;(a) transmissão contínua, através de uma aparelhagem, para um agente de cliente de um aplicativo para execução requisitado por um cliente remoto;(b) transmission, through the apparatus, of a data file requested by the remote client, of the data file accessed by the application transmitted continuously;and (c) acceleration, by one of the customer agents or the equipment, of the delivery of the data file to the remote customer. (b) transmissão, através da aparelhagem, de um arquivo de dados requisitado pelo cliente remoto, do arquivo de dados acessado pelo aplicativo transmitido continuamente;e (c) aceleração, por um dentre o agente de cliente ou a aparelhagem, da entrega do arquivo de dados para o cliente remoto.
- 50Method for accelerating the delivery of a computing environment to a remote client through a client agent, the method comprising the steps of:50. Método para aceleração da entrega de um ambiente de computação para um cliente remoto através de um agente de cliente, o método compreendendo as etapas de: (a) recebimento por um agente de cliente de um aplicativo transmitido continuamente requerido para execução a partir de um servidor, o agente de cliente em comunicação com o servidor através do agente de cliente;(a) receipt by a client agent of a continuously transmitted application required to run from a server, the client agent communicating with the server through the client agent;(b) request, by the client agent, from the server for a data file accessed by the application transmitted continuously;and (c) acceleration, by the client agent, of the delivery of the data file to the application continuously transmitted from the remote client. (b) requisição, pelo agente de cliente, a partir do servidor de um arquivo de dados acessado pelo aplicativo transmitido continuamente;e (c) aceleração, pelo agente de cliente, da entrega do arquivo de dados para o aplicativo transmitido continuamente do cliente remoto.
Independent claims4
1,186 paragraphs in 13 sections, as filed
(54) Title: SYSTEMS AND METHODS FOR ACCELERATING THE DELIVERY OF A COMPUTER ENVIRONMENT TO A REMOTE USER (30) Unionist Priority: 12/04/2006 us 60 / 744,720 (73) Holder (s): Citrix Systems, Inc ( 72) Inventor (s): Brad J. Pedersen, Prabakar Sundarrajan, Rajiv Sinha, Terry Treder (74) Attorney (s): Dannemann .Siemsen, Bigler & Ipanema Moreira (86) International Application: pct US2007066433 of 11/04/2007 (87) International Publication: wo 2007/121241 of 10/25/2007 (57) Summary: systems and methods for accelerating the delivery of a computer environment to a remote user The present invention relates to accelerating the delivery of a computing environment to a remote user of a customer at a remote location. The computing environment may include a application and a data file used or processed by the application. The application and the data file can be stored or provided through a remote server for the client. The user can request a computing environment from the server that provides the application to run by the user through the remote computer. For example, the server can continuously stream the application to a remote client. The client and the server can communicate through a device that speeds up the communications between the client and the server. For example, the system can speed up the continuous transmission of the application to the remote user. In some cases, the system or the remote user may also request a data file from the server, and the system speeds up the delivery of the data file to the remote user. As such, users in remote locations gain accelerated access through any networked device to applications and data files located remotely for the user.
<td></td><td></td><td></td><td></td><td colspan="2">| App</td>
<td rowspan="2">; I environment I computation 15!</td><td></td><td></td><td></td><td colspan="2"></td>
<td></td><td rowspan="2">k <sup>1250</sup></td><td></td><td colspan="2">(Data file</td>
<td rowspan="2">; | Application | ;</td><td rowspan="2">-( Network</td><td></td><td></td><td rowspan="2">Delivery system</td>
<td>|; czi · :;) (</td><td>'Network 4 ---</td><td></td>
<td>j | Data file | '</td><td>C * J</td><td>Equipment</td><td>40 \ fS></td><td></td><td>app 500</td>
<td></td><td></td><td></td><td></td><td colspan="2"></td>
Client C1 10
S1 Server 30
<img file="BRPI0709986A2_D0001.tif" />
Coâ
Invention Patent Descriptive Report for SYSTEMS AND METHODS FOR ACCELERATING THE DELIVERY OF A COMPUTER ENVIRONMENT TO A REMOTE USER.
Related Patent Applications
This application claims the benefit of and priority for the
US N Provisional Patent Application<sup>9</sup> 60 / 744,720, entitled Systems and Methods for Accelerating Delivery of a Computing Environment to a Remote User and filed on April 12, 2006, which is incorporated herein by reference.
Field of the Invention
The present invention relates to systems and methods for accelerating the delivery of a computing environment, including an application and a data file, to a remote user of a client at a remote location for the server.
Background of the Invention
The administration and management of company environments consumes time, money and resources. In many cases, this is because the application and data management process is decentralized and labor intensive. For example, a significant portion of an administrator's time can be spent providing more storage or performing backups for corporate data, or updating servers to handle growth in corporate data. Also, an administrator may need to create and provision new servers to handle data growth. In addition, an administrator can spend 25 time updating and provisioning a server for a particular user application. In addition, a significant portion of corporate data may reside outside the corporate data center. For example, corporate documents, files and data can exist or be distributed to multiple remote computers in the data center.
In an effort to reduce the time, money and resources required for the administration and management of corporate data and applications, many companies have consolidated and centralized servers, t <sup>11</sup> í corporate data and applications. While consolidation and centralization have reduced some costs and produced some benefits, centralized data and applications introduce additional challenges in providing access to data and applications. One of these challenges involves a remote user 5 trying to access a file over a wide area network (WAN) connection. For example, a remote user at a branch office who typically has a network connection to the corporate data center that operates much more slowly than a LAN connection may attempt to open a Microsoft Office document stored in a data center over the WAN. corporate. Remote user access over the network to the file may be delayed due to latency, reliability and bandwidth over the WAN. Delays can be longer for larger files. Furthermore, as the distance between the remote user and the corporate data center grows, the frequency and extent of network delays in accessing files 15 may also increase. The addition of virtual private network layers, I know | security and other networking over the WAN can further reduce the bandwidth available to remote users and increase file access delays. The lower speed and bandwidth of the remote office can cause unacceptable delays in accessing remote files. To avoid delays in remote file access, remote users can copy and use files locally, defeating the purpose of centralized operations. In addition, WAN connections may be less reliable than LAN connections, resulting in packet loss and network disconnection. WAN interruptions can occur during a file operation, such as saving or opening a document, causing more delays experienced by the remote user.
Therefore, systems and methods for improving remote users' access to centralized applications and data files are desired, including accelerating the delivery of applications and data files 30 to remote users.
Summary of the Invention
The present invention relates to systems and methods for accelerating the delivery of a computing environment for an application and data file to a remote user. The application and the data file can be stored or provided via a remote server for the client. For example, a user, such as a remote employee, can use a computer at a branch office that does not have the application and / or data file available locally. The user may want to edit a corporate document with a word processing application not available on the remote client. The user can request a computing environment from the server that provides the execution of the desired application by the user through the remote client. For example, the server can continuously stream the application to the remote client. The remote client and the server can communicate through a device that speeds up communications between the remote client and the server. For example, the system can speed up the continuous transmission of the application to the remote user. In some cases, the application or the remote user may also request a data file from the server, and the system speeds up the delivery of the data file to the remote user. As such, the present invention provides users in remote locations with accelerated access through any networked device to applications and data files located remotely from the user.
In one embodiment, the present invention relates to a method for accelerating the delivery of an application computing environment and a data file to a customer user at a remote location. The method includes the receipt by the server of a request from a remote client to run an application. The remote client and the server communicate via a device. The method also includes the continuous transmission, by the server, to the remote client of an application for execution. The client transmits a request to the server for a data file usable by the application, and the system speeds up the transmission of the data file to the remote client.
In one embodiment of the present invention, the method includes acceleration by the apparatus, continuously transmitting the application to the remote client. In another mode, the system speeds up the transmission of the data file or the continuous transmission of applications by performing one of the following acceleration techniques: 1) compression; 2) decompression; 3) grouping of Transmission Control Protocol; 4) Transmission Control Protocol multiplexing; 5) Transmission Control Protocol buffering; and 6) caching. In another mode, the method includes the acceleration by an acceleration program on the remote client, of communications between the remote client and the server. In some methods of the method, the system establishes a virtual private network connection or a Secure Socket Layer (SSL) connection with the remote client. In other modalities, the method includes the acceleration, by the equipment, of the payload of a network packet communicated through a transport layer connection between a remote client and the server.
In an embodiment of the present invention, the method includes the transmission by the apparatus of an acceleration program to the remote client upon a request from the remote client for the establishment of a connection or a session with the server. In some modes, the remote client automatically installs and runs an acceleration program upon receipt from the system. In other modalities, the method includes performing, through an acceleration program on the remote client, one of the following acceleration techniques: 1) compression; 2) decompression; 3) grouping of Transmission Control Protocol; 4) Transmission Control Protocol multiplexing; 5) Transmission Control Protocol buffering; and 6) caching. In some modalities, the remote client executes the acceleration program transparently to the application or the server.
In some embodiments of the present invention, the method includes determining by the apparatus that the application is capable of being accelerated and transmitting in response to the determination of an acceleration program for the remote client. In other modalities, the apparatus caches the data file. In one embodiment, the system intercepts the request for the data file and transmits the data file stored in cache in response to the request to the remote client.
In another aspect, the present invention relates to a system for accelerating delivery to a remote user of an application computing environment and a data file to a customer at a remote location. The system includes a device for accelerating communications between one or more remote clients and one or more servers. The system also includes a server receiving a request from a remote client to run an application. The remote client and the server communicate through the system. The server continuously transmits an application to the remote client for execution. The remote client transmits a request to the server for a data file usable by the application, and the system speeds up the transmission of the disposable absorbent article to the remote client.
In some embodiments of the present invention, the apparatus speeds up the continuous transmission of the application to the remote client. In one embodiment, the system speeds up the transmission of the data file or the continuous transmission of the application by performing one of the following acceleration techniques: 1) compression; 2) decompression; 3) grouping of Transmission Control Protocol; 4) Transmission Control Protocol multiplexing; 5) Transmission Control Protocol buffering; and 6) caching. In another embodiment, the system includes an acceleration program on the remote client to speed up communications between the remote client and the server. In one embodiment, the appliance establishes a virtual private network connection or a Secure Socket Layer (SSL) connection with the remote client.
In some embodiments of the system of the present invention, the apparatus accelerates a payload of a communicated network packet through a transport layer connection between the remote client and the server. In one mode, the system transmits an acceleration program to the remote client upon a request from the client to establish a connection or a session with the server. In other modalities, the remote client automatically installs and executes an acceleration program upon receipt from the apparatus.
The acceleration program on the remote client can perform one or more of the following acceleration techniques: 1) compression; 2) decompression; 3) grouping of Transmission Control Protocol; 4) Transmission Control Protocol multiplexing; 5) buffering of Pro10 Transmission Control module; and 6) caching. In one embodiment, the remote client executes the acceleration program transparently to the application or the server.
In another embodiment of the system of the present invention, the apparatus determines that the application is capable of being accelerated, and transmits an acceleration program to the remote client in response to the determination. In one embodiment, the apparatus comprises a cache for caching the data file. In some modalities, the system intercepts the request for the data file and transmits the data file stored in cache to the remote client, 20 in response to the request.
Brief Description of Drawings
These and other aspects of this invention will be readily apparent from the detailed description below and the accompanying drawings, which are meant to illustrate and not limit the invention, and in which:
Figure 1A is a block diagram depicting a network environment;
Figure 1B is a block diagram depicting a modality of a remote computing environment in a network environment;
figures 1C and 1D are block diagrams describing useful computer modalities in relation to the described modalities;
Figure 1E is a block diagram that describes a suitable environment for delivering a computing environment to a customer;
Figure 1F is a block diagram that describes a modality of a system for providing a plurality of application programs available to the local machine through the publication of GUIs in a web service directory;
figure 2 is a flowchart that describes a modality of the steps followed to select a method for executing an application program;
Figure 3A is a block diagram that describes a modality of a local machine starting a program Neighborhood application execution through the World Wide Web;
figure 3B is a flowchart that describes a modality of the steps followed by a local machine to access an enumerated application program using a web service directory;
Figure 4A is a block diagram of a network modality providing policy-based access to application programs for a local machine;
Figure 4B is a block diagram that describes a more detailed embodiment of a policy officer;
figure 4C is a flowchart that describes a modality of the steps followed by a policy agent to make an access control decision based on information received on a local machine;
Figure 4D is a block diagram depicting a mode of a computer network in which authorized remote access to a plurality of application sessions is provided;
figure 4E is a flowchart that describes a modality of the steps followed by a session server for connecting a local machine to its associated application sessions;
figure 5 is a flowchart that describes a modality of the steps followed by a session server for connecting a client node with its associated application sessions;
figure 6 is a block diagram describing a remote machine modality including a management service providing an application enumeration;
figure 7 is a flowchart that describes a modality of the steps followed to access a plurality of files comprising an application program;
figure 8A is a block diagram depicting a mode of a computer running under the control of an operating system that has reduced application compatibility and application sociability problems;
figure 8B is a block diagram depicting a multiple user program that has reduced application compatibility and application sociability problems;
figure 8C is a flow chart that describes a modality of the steps followed in a method for associating a process with an isolation scope;
figure 9 is a flowchart that describes a modality of steps followed in a method for executing an application program;
figure 10 is a flow chart describing a modality of a plurality of application files residing on a remote machine;
figure 11 is a flowchart that describes a modality of the steps followed in a method to respond locally to requests for file metadata associated with files stored remotely;
figure 12 is a block diagram describing a modality of a system for responding locally to requests for file metadata associated with files stored remotely;
figure 13 is a flowchart that describes a modality of the steps followed in a method for accessing a remote file in a directory structure associated with an application program running locally;
figure 14 is a block diagram that describes a modality of a system for accessing a file in a directory structure associated with an application;
figure 15 is a block diagram of a remote machine modality including a license management subsystem;
figure 16 is a block diagram that describes a modality of components in a management service on a remote machine;
figure 17 is a flowchart that describes a modality of the steps followed to apply for and maintain a license from a remote machine;
figure 18 is a block diagram that describes a modality of states that can be associated with a session monitored by a management service;
figure 19 is a block diagram depicting a package including two targets, each target comprising a plurality of application files comprising an application;
figure 20 is a flowchart that describes a modality of the steps followed in a policy-based method for installing an application program without rebutting an operating system;
figure 21 is a flowchart that describes a modality of the steps followed in a policy-based method for installing an application program without rebutting an operating system;
figure 22 is a screen snapshot that describes a method of enumerating scripts to be executed on the local machine;
Figure 23 is a block diagram depicting a modality of a system that includes a package formation mechanism running an installer program in an isolation environment;
figure 24 is a flow chart that describes a modality of the steps followed in an environment in which an execution of an installer program requires rebutting an operating system;
Figure 25 is a block diagram depicting a remote machine modality on which a packet forming mechanism installs an application program;
figure 26 is a flowchart that describes a modality of the steps followed to install an application in an application isolation environment;
figure 27 is a block diagram illustrating a modality of an architecture of an apparatus that performs an integrated cache storage;
Figure 28A is a flow chart of steps followed in one embodiment of a method for integrating device operations with a package processing and the package processing timer;
figure 28B is a flow chart of steps followed in a modality of a method for the practice of invalidation granularity techniques in view of figure 3A;
Figure 29A is a flowchart of steps followed in one method modality using invalidation commands for invalidating expired objects;
Figure 29B is a flow chart of steps followed in a method modality that incorporates an invalidation of groups of objects;
figure 29C is a flowchart of steps followed in a method modality that incorporates an invalidation of groups of objects using object determinants;
figure 30 is a flow chart of steps followed in a modality of a grouping connection method;
figure 31 is a flow chart of steps followed in a modality of a method for translating client and server requests;
figure 32 illustrates an embodiment of a content length parameter;
Figure 33 illustrates a modality of fragment size fields;
figure 34 is a message flow chart describing a connection grouping mode;
figure 35 is a detailed flowchart that illustrates a modality of the steps followed to use the content length parameter to increase the efficiency of connection grouping between clients and servers;
figure 36 is a flowchart that describes a modality of the steps followed to use the content length parameter to increase the efficiency of connection grouping between clients and servers;
figure 37 is a detailed flowchart that illustrates a modality of the steps followed to use fragment size fields to increase the efficiency of connection between clients and servers;
figure 38 is a flowchart that describes a modality of the steps followed to use fragment size fields to increase the efficiency of connection between clients and servers;
figure 39 is a flow chart of a modality of the steps followed for the provision of an integrated caching functionality;
Figure 40A is a block diagram of an embodiment of a client-side acceleration program;
Figure 40B is a block diagram of a modality of an apparatus for the provision of a client side acceleration program;
Figure 41A is a step diagram of an embodiment of a method for dynamic provisioning and automatic installation and execution of a client side acceleration program;
41B is a step diagram of an embodiment of a method for determining that an application can be accelerated;
Figure 41C is a step diagram of another modality of a method of executing a plurality of architecture techniques for delivering content by the acceleration program for interception in the transport layer and using a kernel level data structure. ;
Fig. 42A is a step diagram of another embodiment of a method for automatic installation and execution of the acceleration program on the client through a first program;
Fig. 42B is a step diagram of an embodiment of a method for a first program and of the acceleration program for the provision of virtual private network connectivity and the execution of one or more acceleration techniques;
Fig. 43 is a step diagram of a modality of a method for redirecting a client computer to a ring to bypass a determined non-usable intermediary for transmitting the communication to the server;
Fig. 44 is a step diagram of an embodiment of a method for carrying out a transport control protocol buffering client-side acceleration technique;
Fig. 45A is a step diagram of an embodiment of a method for carrying out a transport control protocol connection cluster client-side acceleration technique;
Figure 45B is a diagrammatic view of a set of HTTP transactions performed by a plurality of applications across a group of one or more transport layer connections in one embodiment;
Fig. 46 is a step diagram of an embodiment of a method for performing a client-side acceleration technique of transport control protocol multiplexing;
Fig. 47 is a diagrammatic view of an embodiment of a content length identifier for a transport layer package;
Figure 48 is a diagrammatic view of another embodiment of a content length identifier for a message transmitted across multiple fragments;
Fig. 49A is a block diagram depicting an example embodiment of a networked computer system for accelerating the delivery of a computing environment to a remote client; and Figure 49B is a flowchart that describes a step method of a method for accelerating the delivery of a computing environment to a remote client.
Detailed Description of the Invention
For the purposes of reading the description of the various modalities below, the following descriptions of the sections of the specification and their respective contents can be useful:
- Section A describes a network environment and a computing environment which can be useful for practicing the modalities described here;
- Section B describes modalities of systems and methods for the delivery of a computing environment to a remote user;
- Section C describes modalities of systems and methods for accelerating communications between a client and a server; and
- Section D describes an exemplary example of accelerating the delivery of a computing environment to a remote user using the systems and methods described here.
A. NETWORK AND COMPUTER ENVIRONMENT
Before discussing the specifics of the present invention, it may be useful to discuss some of the network environments in which the illustrative embodiment of the present invention can be employed. Referring now to Figure 1A, a network environment 5 is described. In a brief overview, network environment 5 comprises one or more 10-10 ”clients (generally referred to as clients 10 or local machines 10) communicating with one or more 30-30” servers (also commonly referred to as servers 30 or remote machines 30) over one or more 40, 40 ”networks. In some embodiments, a client 10 communicates with a server 30 through an apparatus 1250.
Although figure 1A shows a network 40 and a network 40 'between clients 10-10'-10 ”and servers 30-30”, clients 10-10' and servers 30-30 ”can be on the same network 40 The networks 40 and 40 'can be of the same type of network or of different types of networks. Network 40 and / or network 40 'can be a local area network (LAN), such as a company intranet, a metropolitan area network (MAN) or a wide area network (WAN), such as the Internet or the World Wide Web. In one embodiment, network 40 'can be a private network and network 40 can be a public network. In another embodiment, networks 40 and 40 'can both be private networks. In some modalities, 10-10 ”customers may be located at a branch of a corporate company communicating over a WAN connection over network 40 to servers 30-30” located in a corporate data center.
The 40 and / or 40 'network can be any type and / or form of network, and can include any of the following: a point-to-point network, a broadcast network, a wide area network, a local area network , a telecommunications network, a data communication network, a computer network, an ATM (Asynchronous Transfer Mode) network, a SONET (Synchronous Optical Network) network, an SDH (Synchronous Digital Hierarchy) network, a network wireless and a wired network. The network topology 40 and / or 40 'can be a bus, star or ring network topology. The 40 and / or 40 'network and the network topology can be any one of these networks or network topology, as known to those skilled in the art, capable of supporting the operations described here.
As shown in figure 1 A, the apparatus 1250 (also referred to here as an interface unit 1250) is shown between networks 40 and 40 '. In some embodiments, the 1250 system may be located on network 40. For example, a branch of a corporate company may employ a 1250 system at the branch. In other embodiments, the apparatus 1250 may be located on the network 40 '. For example, a 1250 device can be located in a corporate data center. In yet another embodiment, a plurality of apparatus 1250 may be employed in network 40. In some embodiments, a plurality of apparatus 1250 may be employed in network 40 '. In one embodiment, a first device 1250 communicates with a second device 1250 '. In other modalities, the 1250 equipment could be part of any 10-10 'or 30-30 ”client on the same network or on a different 40, 40' as the 10-10” client. One or more 1250 devices can be located anywhere on the network or in network communication paths between a 10-10 ”client and a 30-30” server.
In one embodiment, the system can include multiple remote machines logically grouped 30, one or more of which is available to run applications on behalf of a local machine 10. In these modalities, the logical group of remote machines can be referred to as a database. servers 38 or a bank 38. In some of these embodiments, remote machines 30 can be geographically dispersed. A bank 38 can be managed as a single entity.
Remote machines 30 within each bank 38 can be heterogeneous. That is, one or more of the remote machines 30 can operate according to a type of operating system platform (for example, WINDOWS NT, manufactured by Microsoft Corp. of Redmond, Washington), while one or more of the other remote machines 30 can operate according to another type of operating system platform (for example, Unix or Linux). Remote machines 30 comprising each bank 38 need not be physically close to each other remote machine 30 in this bank 38. Thus, the group of remote machines 30 logically grouped as bank 38 can be interconnected using a wide area network connection (WAN) or a medium area network (MAN) connection. For example, a bank 38 may include remote machines 30 physically located on different continents or in different regions of a continent, country, state, city, campus or room. Data transmission speeds between remote machines 30 in bank 38 can be increased if remote machines 30 are connected using a local area network (LAN) connection or some form of direct connection.
Remote machines 30 can be referred to as servers, file servers, application servers or remote machines. In some embodiments, remote machines 30 may have the ability to function as application servers or as a master application server. In one embodiment, a remote machine 30 may include an Active Directory. Local machines 10 can also be referred to as client nodes or end points. In some modalities, local machines 10 have the ability to function as client nodes seeking access to applications and as application servers providing access to hosted applications for other local machines 10.
In one embodiment, the local machine 10 communicates directly with one of the remote machines 30 in a bank 38. In another embodiment, the local machine 10 runs a program neighborhood application to communicate with the remote machine 30 in a bank 38. In yet another embodiment, remote machine 30 provides the functionality of a master node. In some embodiments, the local machine 10 communicates with the remote machine 30 in bank 38 over a network 40. Over network 40, local machine 10 can, for example, request an execution of several applications hosted by remote machines 30, 30 ', 30 ”and 30”' in bank 38 and receive an output of application execution results for display. Network 40 can comprise synchronous or asynchronous connections and can be a LAN, a MAN (Medium Area Network) or a WAN. In addition, network magnet 40 may comprise a wireless link, such as an infrared channel or a satellite band. In some embodiments, only the master node provides the functionality required for the identification and provision of address information associated with a remote machine 30 'hosting a requested application.
In some modalities, a local machine 10 communicates with a remote machine 30 '”. In one of these modalities, the remote machine 30 '”provides functionality of a web server. In another of these modalities, remote machine 30 '”receives requests from local machine 10, forwards requests to a remote machine 30 and responds to the request by local machine 10 with a response to the request from remote machine 30. In yet another of these modalities, remote machine 30 acquires an enumeration of applications available to local machine 10 and address information associated with a remote machine 30 'hosting an application identified by the application enumeration. In yet another of these modalities, the remote machine 30 ”'presents the response to the request for the local machine 10 using a web interface. In one embodiment, local machine 10 communicates directly with remote machine 30 'to access the identified application. In another embodiment, local machine 10 receives application output data from remote machine 30 '”, application output data generated by an application run identified on remote machine 30'.
Referring now to Figure 1B, a network environment for delivery and / or operation of a computing environment on a client 10 is described. In a brief overview, a server 30 includes an application delivery system 500 for delivering a computing environment or an application and data file to one or more clients. Client 10 may include a computing environment 15 for running an application that uses or processes a data file. Client 10 in communication with server 30 over networks 40, 40 'and appliance 1250 can request an application and data file from server 30, or appliance 1250 can forward a request from client 10 to the server 30. For example, client 10 may not have the application and data file stored locally or accessible locally. In response to the request, server 30 can deliver the application and data file to client 10. For example, in one embodiment, server 30 can transmit the application as a continuous application stream for operation in the computing environment 15 on client 10.
Figures 1C and 1D are block diagrams that describe modalities of general-purpose computer architecture 135 useful as client computing devices 10 and server computing devices 30. As shown in figures 1C and 1D, each computer 135 includes a processing unit central 102 and a main memory unit 122. Each computer 135 can also include other optional elements, such as one or more input / output devices 130a
130b (generally referred to using reference number 130), and a cache memory 140 in communication with central processing unit 102.
Central processing unit 102 is any logic circuit that responds to and processes instructions fetched from main memory unit 122. In many embodiments, the central processing unit is provided by a microprocessor unit, such as those manufactured by Intel Corporation of Mountain View, California; those manufactured by Motorola Corporation of Schaumburg, Illinois; the Crusoe and Efficeon lines of processors manufactured by Transmeta Corporation, of Santa Clara, California; the processor lines manufactured by International Business Machines of White Plains, New York; or the processor lines manufactured by Advanced Micro Devices of Sunnyvale, California.
The main memory unit 122 can be one or more memory chips capable of storing data and allowing any storage location to be directly accessed by microprocessor 102, such as a Static random access memory (SRAM), a Burst SRAM or a Synchronous Burst SRAM (BSRAM), a Dynamic Random Access Memory (DRAM), a Rapid Radio Call Mode DRAM (FDM DRAM), an Enhanced DRAM (EDRAM), an Extended Data Output RAM (EDO RAM), an Extended Data Output DRAM (EDO DRAM), an Extended Burst Output Data DRAM (BEDO DRAM), an Extended DRAM (EDRAM), a synchronous DRAM (SDRAM ), JEDEC SRAM, PC100 SDRAM, Dual Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Direct Rambus DRAM (DRDRAM) or Ferroelectric RAM (FRAM). In the mode shown in figure 1C, processor 102 communicates with main memory 122 through system bus 120 (described in more detail below). Fig. 1B describes an embodiment of a computer system 135 in which the processor communicates directly with main memory 122 through a memory port. For example, in figure 1C, main memory 122 can be a DRDRAM.
Figures 1C and 1D describe modalities in which the main processor 102 communicates directly with the cache memory 140 through a secondary bus, sometimes referred to as the backside bus. In other embodiments, main processor 102 communicates with cache memory 140 using system bus 120. Cache memory 140 typically has a faster response time than main memory 122 and is typically provided by SRAM, BSRAM or EDRAM .
In the modality shown in figure 1C, processor 102 communicates with several I / O devices 130 via local system bus 120. Several buses can be used to connect central processing unit 102 to I / O devices 130, including a VESA VL bus, an ISA bus, an EISA bus, a Microchannel Architecture (MCA) bus, a PCI bus, a PCI-X bus, a PCI-Express bus, or a NuBus. For modalities in which the L / O device is a video display, processor 102 may use an Advanced Graphics Port (AGP) to communicate with the display. Fig. 1D describes an embodiment of a computer system 135 in which the main processor 102 communicates directly with the I / O device 130b via HyperTransport, Rapid l / O or InfiniBand. Figure 1C also describes a modality in which local buses and direct communication are mixed: processor 102 communicates with I / O device 130a using a local interconnect bus while communicating with I / O device 130b directly .
A wide variety of I / O devices 130 can be present on the computer system 135. Input devices include keyboards, mice, trackpads, trackballs, microphones and drafting tables. Output devices include video displays, speakers, inkjet printers, laser printers, and dye sublimation printers. An I / O device can also provide mass storage for the computer system 135, such as a hard disk drive, a floppy disk drive for receiving floppy disks such as 3,5, 5,25 or ZIP disks, a CD-ROM drive, a CD-R / RW drive, a DVD-ROM drive, tape drives of various formats, and USB storage devices, such as a line of USB Flash Drive devices manufactured by Twintech Industry, Inc. of Los Alamitos, California.
In additional embodiments, an I / O device 130 can be a bridge between the system bus 120 and an external communication bus, such as a USB bus, an Apple Desktop bus, an RS-232 serial connection, a SCSI bus, a FireWire bus, a FireWire 800 bus, an Ethernet bus, an AppIeTalk bus, a Gigabit Ethernet bus, an Asynchronous Transfer Mode bus, a HIPPI bus, a Super HIPPI bus, a SerialPIus bus, a SCI / LAMP bus, a FibreChannel bus, or a small Serial Attached computer system interface bus.
General purpose desktop computers of the type described in Figure 1C and Figure 1D typically operate under the control of operating systems, which control task scheduling and access to system resources. Typical operating systems include: MICROSOFT WINDOWS, manufactured by Microsoft Corp. from Redmond, Washington; MacOS, manufactured by Apple Computer, Inc. Cupertino, California; OS / 2, manufactured by International Business Machines of Armonk, New York; and Linux, an operating system freely available from Caldera Corp. Salt Lake City, Utah, among others.
For modalities in which a client machine 10 or a server 30 comprises a mobile device, the device can be a JAVA enabled cell phone, such as i55sr, i58sr, i85s, or i88s, all of which are manufactured by Motorola Corp. Schaumburg, Illinois; 6035 or 7135 manufactured by Kyocera of Kyoto, Japan; or the i300 or i330 manufactured by Samsung Electronics Co., Ltd., Seoul, Korea. In other modes comprising mobile devices, a mobile device may be a personal digital assistant (PDA) operating under the control of the PalmOS operating system, such as the Tungsten W, ο VII, Vllx, i705, all of which are manufactured by palmOne, Inc. of Milpitas, California. In other modalities, client 113 may be a personal digital assistant (PDA) operating under the control of the PocketPC operating system, such as iPAQ 4155, iPAQ 5555, iPAQ 1945, iPAQ 2215, and iPAQ 4255, all of which are manufactured by Hewlett- Packard Corporation of Paio Alto, California; the ViewSonic V36, manufactured by ViewSonic of Walnut, California; or the Toshiba PocketPC e405, manufactured by Toshiba America, Inc. of New York, New York. In yet other modalities, the mobile device is a PDA / phone device combination, such as the Treo 180, Treo 270, Treo 600, Treo 650, or Treo 700w, all of which are manufactured by palmOne, Inc. of Milpitas , California. In yet other modalities, the mobile device is a cell phone that operates under the control of the PocketPC operating system, such as the MPx200, manufactured by Motorola Corp. A typical mobile device can comprise many of the elements described above in figures 1C and 1D, including processor 102 and main memory 104.
B. SYSTEMS AND METHODS FOR DELIVERY OF A COMPUTER ENVIRONMENT
One modality is directed at systems and methods for delivering a computing environment to a remote user on a client 10 located at a remote location on the server 30. Although the methods and systems in this section generally speak of servers 30, the methods and system below you can use servers 30, network devices 1250, or any combination thereof.
Referring now to figure 1E, an embodiment of a system in which remote machines 30 comprise a bench 38, as described in figure 1A, is shown. Each remote machine 30 includes a network side interface 202 and a bank side interface 204. The network side interface 202 of remote machine 30 can be in communication with one or more local machines 10 or a network 210. The network 210 can be a WAN, a LAN or an international network, such as the Internet or the World Wide Web. Local machines 10 can establish connections to remote machines 30 using network 210.
The bank side interfaces 204 of remote machines 30 are interconnected to each other by communication links 200, so that remote machines 30 can communicate with each other. On each remote machine 30, bank side interface 204 communicates with network side interface 202. Bank side interfaces 204 also communicate (designated by arrows 220) with persistent storage 230 and, in some embodiments , with 240 dynamic storage. The combination of remote machines 30, persistent storage 230 and dynamic storage 240, when provided, is collectively referred to as a bank 38. In some embodiments, a remote machine 30 communicates with persistent storage 230 and the other remote machines 30 ' communicate with remote machine 30 to access information stored in persistent storage.
Persistent storage 230 can be physically implemented on a disk, a disk bank, a redundant array of independent disks (RAID), a writable compact disk, or any other device that allows data to be read and written and that maintains written data, if the power is removed from the storage device. A single physical device can provide storage for a plurality of persistent stores, that is, a single physical device can be used to provide persistent storage 230 for more than one bank 38. Persistent storage 230 maintains static data associated with each remote machine 30 in bank 38 and global data used by all remote machines 30 in bank 38. In one embodiment, persistent storage 230 can maintain remote machine data in a Lightweight Directory Access Protocol (LDAP) data model. In other embodiments, persistent storage 230 stores remote machine data in an ODBC-compliant database. For the purposes of this description, the term static data refers to that which does not change frequently, that is, data that changes only on an hourly, daily or weekly basis, or data that never changes. Each remote machine uses a persistent storage subsystem for reading data and writing data to persistent storage 230.
The data stored in persistent storage 230 can be replicated for reliability purposes physically or logically. For example, physical redundancy can be provided using a set of redundant mirrored disks, each providing a copy of data. In other modalities, the database itself can be replicated using standardized database techniques for the provision of multiple copies of the database. In additional modalities, physical and logical replication can be used concurrently.
Dynamic storage 240 (i.e., the collection of all recording tables) can be realized in several ways. In one embodiment, dynamic storage 240 is centralized; that is, all runtime data is stored in the memory of a remote machine 30 in bank 38. The remote machine operates as a master network node with which all other remote machines 30 in bank 38 communicate, when searching access to that runtime data. In another embodiment, each remote machine 30 in bank 38 maintains a full copy of dynamic storage 240. Here, each remote machine 30 communicates with each other remote machine 30 to keep its copy of dynamic storage 240 up to date.
In another embodiment, each remote machine 30 maintains its own runtime data and communicates with each other remote machine 30 when seeking to obtain processing time data from them. Thus, for example, a remote machine 30 trying to find an application program requested by local machine 10 can communicate directly with each other remote machine 30 in bank 38 to find one or more remote machines hosting the requested application.
For 38 banks having a large number of remote machines
30, the network traffic produced by these modalities can become heavy. One embodiment eliminates heavy network traffic by designating a subset of remote machines 30 in a bank 38, typically two or more, as collector points. Generally, a collector point is a remote machine that collects runtime data. Each collector point stores runtime data collected from certain other remote machines 30 in bank 38. Each remote machine 30 in bank 38 is capable of operating as and, consequently, is capable of being designed as a collector point. In one embodiment, each collector point stores a copy of the entire dynamic storage 240. In another embodiment, each collector point stores a portion of the dynamic storage 240, that is, it maintains runtime data for a particular data type. . The type of data stored by a remote machine 30 can be predetermined according to one or more criteria. For example, remote machines 30 can store different types of data based on their boot order. Alternatively, the type of data stored processing a remote machine 30 can be configured by an administrator using the administration tool 140. In these modalities, dynamic storage 240 is distributed among two or more remote machines 30 in bank 38. In another embodiment, an apparatus 1250 can relieve heavy network traffic by accelerating data passed between remote machines 30, 16240 dynamic storage and persistent storage 230. This acceleration can be provided by any of the techniques discussed further in Section C. For example, the 1250 appliance can be used to relieve heavy network traffic.
Remote machines 30 not designated as collector points know remote machines 30 in a bank 38 that are designated as collector points. A remote machine 180 not designated as a collector point can communicate with a particular collector point when delivering and requesting runtime data. Consequently, the collector points listen to network traffic because each remote machine 30 in bank 38 communicates with a single remote collector point machine 30, instead of with each other remote machine 30, when seeking to access time data. of execution.
Each remote machine 30 can operate as a collector point for more than one type of data. For example, the remote 30 ”machine can operate as a collector point for licensing information and loading information. In these modalities, each collector point can accumulate a different type of runtime data. For example, for illustration of this case, the remote 30 ”machine can collect licensing information, while the remote 30” machine can collect loading information.
In some modalities, each collector point stores data that is shared between all remote machines 30 in a bank 38. In these modalities, each collector point of a particular type of data exchanges the data collected by that collector point with each other. collector point for that type of data in bank 38. Thus, upon completion of the exchange of these data, each remote machine 30 ”and 30 has the same data. Also, in these modalities, each collector point 30 and 30 ”also keeps every other collector point well informed of any updates to the runtime data.
A navigation allows a local machine 10 to see banks 38, remote machines 30 and applications in banks 38 and access available information, such as sessions through bank 38. Each remote machine 30 includes an ICA 260 navigation subsystem for the provision to the local machine 10 of a navigation capability. After the local machine 10 establishes a connection to the ICA 260 browser subsystem of any of the remote machines 30, that browser subsystem supports a variety of local machine requests. These local machine requests include: (1) enumeration of remote machine names in the bank, (2) enumeration of application names published in the bank, (3) resolution of a remote machine name and / or name to a remote machine address that is useful for the local machine 10. The ICA 260 browser subsystem also supports requests made by machines at locations 10 running a program neighborhood application that provides local machine 10, upon request, with a view of those applications in bank 38 to which the user is authorized. The ICA 260 browser subsystem forwards all local machine requests mentioned above to the appropriate subsystem on remote machine 30.
In one embodiment, each remote machine 30 in bank 38 that has a program neighborhood subsystem 270 can provide the user of a local machine 10 with an application view in bank 38. The program neighborhood subsystem 270 can limit the view to those applications which the user of the local machine 10 is authorized to access. Typically, this program neighborhood service presents the user with applications as a list or a group of icons.
The functionality provided by the program neighborhood subsystem 270 is available for two types of local machines, (1) local machines enabled with program neighborhood that can access the functionality directly from a local machine workspace and (2) machines non-enabled locations with a program neighborhood (for example, local legacy machines) that can access the functionality by running an enabled desktop with program neighbors on the remote machine.
Communication between a local machine with program neighborhood enabled and program neighborhood subsystem 270 can take place over a dedicated virtual channel that is established on top of an ICA virtual channel. In other modalities, communication takes place using an XML service. In one of these modalities, the local machine with a program neighborhood enabled communicates with an XML subsystem, such as the XML service 516 described in relation to figure 6 below, providing program neighborhood functionality on a remote machine 30.
In one embodiment, the local machine with program neighborhood enabled does not have a connection to the remote machine with a program neighborhood subsystem 270. For this mode, local machine 10 sends a request to the ICA browser subsystem.
260 for establishing an ICA connection to remote machine 30, in order to identify available applications for local machine 10. Local machine 10 then runs a client side dialog that acquires a user's credentials. The credentials are received by the ICA 260 browser subsystem and sent to the program neighborhood subsystem 270. In one embodiment, the program neighborhood subsystem 270 sends credentials to a user management subsystem for authentication. The user management subsystem can return a set of distinguished names representing a list of accounts to which the user belongs. By means of an authentication, the program neighborhood subsystem 270 establishes the virtual program neighbor channel . This channel remains open until application filtering is complete. In some embodiments, a 6120 acceleration program, as described in Section C, can also be transmitted to local machine 10, in response to a local machine request 10.
The program neighborhood subsystem 270 then requests the program neighborhood information from the common application subsystem 524 associated with those accounts. Common application subsystem 524 obtains program neighborhood information from persistent storage 230. Upon receiving the program neighborhood information, the program neighborhood subsystem 270 formats and returns the program neighborhood information to the local machine via the virtual program neighborhood channel. Then, the partial ICA connection is closed.
For another example where the local machine with program neighborhood enabled establishes a partial ICA connection to a remote machine, consider using local machine 10 that selects a bank 38. Selecting bank 38 sends a request from the machine site 10 for the ICA 260 browser subsystem for establishing an ICA connection with one of the remote machines 30 in the selected bank 38. The ICA 260 browser subsystem sends the request to program neighborhood subsystem 270, which selects a remote machine 30 from bank 38. An address information associated with remote machine 30 is identified and returned to local machine 10 by through the ICA 260 browser subsystem. Local machine 10 can then subsequently connect to remote machine 30 corresponding to the received address information.
In another embodiment, the local machine with program neighborhood enabled 10 has an ICA connection through which the virtual program neighborhood channel is established and remains open for as long as the ICA connection persists. Through this virtual program neighborhood channel, the program neighborhood subsystem 270 pushes the program neighborhood information updates to the local machine 10. In order to obtain updates, the program neighborhood subsystem 270 subscribes to events from the common application subsystem 524 to allow the program neighborhood subsystem 270 to detect changes in published applications.
With reference to figure 1F, a block diagram describes another embodiment of a system architecture for providing a plurality of application programs available to the local machine through the publication of GUIs in a web service directory. The system includes local machine 10 and a plurality of remote machines 30. A remote machine 30 functions as a content server. A remote 30 'machine provides web server functionality. A remote 30 ”machine provides functionality for providing access to application files and acts as an application server or file server. Local machine 10 can download (via download) content from content server 30, web server 30 'and application server 30 ”over network 155. In one embodiment, local machine 10 can transfer content (for example, an application) from the 30 ”application server via the client communication channel - application server 1150.
In one embodiment, the web browser 11 on the local machine 10 uses Secure Socket Layer (SSL) support for communications with the content server 30 and / or the web server 30 '. SSL is a secure protocol developed by Netscape Communication Corporation to
Mountain View, California, and is now a standard enacted by the Internet Engineering Task Force (IETF). Web browser 11 can alternatively connect to content server 30 and / or web server 30 'using other security protocols, such as, but not limited to, a Secure Hypertext Transfer Protocol (SHTTP) developed by Terisa Systems de Los Altos, CA, HTTP over SSL (HTTPS), Private Communication Technology (PCT) developed by Microsoft Corporation of Redmond, Washington, and the Transport Level Security (TLS) standard promulgated by the IETF. In other embodiments, the web browser 11 communicates with the servers 30 using an unencrypted communications protocol, such as the Hypertext Transfer Protocol (HTTP).
Additionally, the local machine 10 includes an application client 13 for establishing and exchanging communications with the application server 30 ”through the client communication channel - application server 1150. In one embodiment, application client 13 is a GUI application. In some embodiments, application client 13 is an Independent Computing Architecture (ICA) client, developed by Citrix Systems, Inc. Fort Lauderdale, Florida, and is also referred to below as the ICA 13 client. Other modalities of the application client 13 include a Remote Display Protocol (RDP) client, developed by Microsoft Corporation of Redmond, Washington, an X client -Windows 13, a client side player, an interpreter or a simulator capable of running multimedia applications, email, Java, or .NET code. Furthermore, in one embodiment, the output of an application running on application server 30 ”can be displayed on local machine 10 via application client 13. In some embodiments, application client 13 is an application client such as the application streaming client 552, described in more detail in relation to figure 5. In some embodiments, application client 13 comprises an acceleration program in accordance with any of the modalities described here 6120, for accelerating communications between client 10 and server 30.
Local machine 10 searches the web service directory 160 for a web service. In one embodiment, the search is a manual search. Alternatively, the search is an automatic search. The web service directory 160 can also provide a service-based view, such as an Internet address book or yellow pages, for searching for web services in the web service directory. In another embodiment, the web service directory 160 supports hierarchical navigation based on a structured service name and service type for GUI applications. In one embodiment, the web service directory 160 is run on a remote machine independent of the content server 30, such as a directory server. In other embodiments, the web service directory 160 runs on multiple servers.
In some embodiments, the content server 30 allows the local machine 10 to select web services based on further analysis or information by providing this information or analysis in the web service directory 160. Examples of service information that web service directory 160 can list include, but are not limited to, the name of the business offering the service, the type of service, a textual description of the service, one or more service access points ( SAPs), the type of network, the path to use (for example, TCP or HTTPS), and the quality of service (QoS) information. Furthermore, the service information can be type or user specific (for example, paper) of the client device. Thus, service selection can be based on one or more of the above attributes.
In one embodiment, the type of service denotes a programming interface that local machine 10 must use to access the web service. For example, the type of service may declare that the service is encoded by an interface description language, such as the Web Service Description Language (WSDL).
The service access point, or SAP, is a unique address for an application. SAPs allow the computer system to support multiple applications on the local machine 10 and on each remote machine 30. For example, the 30 ”application server can support an email application (ie, email), an email application, file transfer and / or a GUI application. In one embodiment, each of these applications would have an SAP that would be unique on the 30 ”application server. In one embodiment, SAP is a web or Internet address name (for example, a Domain Name System (DNS), an IP / port, or a Uniform Resource Locator (URL)). Thus, in one embodiment, SAP identifies the web server address 30 'as part of the address for an application stored on the web server 30'. In some embodiments, SAP identifies the address of a publishing server plug-in 165 as part of the address for an application stored on the web server 30 ', as described below. In one embodiment, SAP is an Access Point (accessPoint) in the UDDI registry.
For preparing an item for publication in the web service directory 160, the content server 30 includes a web publishing tool 170. In one embodiment, the web publishing tool 170 is a software module. Alternatively, the web publishing tool 170 is another server that can be externally located or internally located on the content server 30.
In one embodiment, the web server 30 'delivers web pages to the local machine 10. The web server 30' can be any remote machine 30 capable of providing web pages to the local machine 105. In another embodiment, the 30 'web server is a Company Information Portal (for example, a corporate intranet or a business extranet for secure business). Company portals are company websites that aggregate, personalize and serve applications, data and content to users, while offering tools for organizing and using information more efficiently. In some companies, portals have replaced traditional desktop software with browser-based access to a virtual workplace. In some embodiments, a 1250 appliance accelerates the delivery of the provision of web pages that is accelerated using any of the acceleration techniques used here. In other ways, the 6120 acceleration program accelerates the delivery of web pages.
The 30 'web server also includes a 165 publishing server plug-in to allow publishing of graphical user interface (GUI) applications. More specifically, the publishing server plug-in 165 translates a new web service entry URL into a GUI application service, so that the GUI can be accessed through the web service directory 160. In one embodiment, the publishing server plug-in 165 is a Common Gateway Interface (CGI) script, which is a program designed to accept and return data that conforms to the CGI specification. The program can be written in any programming language, such as C, Perl, Java or Visual Basic. In another embodiment, the publishing server plug-in 165 is a Java Server Page (JSP). Using the publishing server plug-in 165 to facilitate the publication of remote GUI applications, local machine 10 can thus access the web service, not through a programming interface or web page, but through an interface full GUI, such as Citrix's ICA or Microsoft's RDP. In some embodiments, a 1250 device or a 6120 acceleration program speeds up the delivery of that GUI to the customer, which is accelerated using any of the acceleration techniques discussed here in Section C.
The 30 ”application server hosts one or more applications that are available for the local machine 10. Examples of such applications include word processing programs, such as MICROSOFT WORD, and spreadsheet programs, such as MICROSOFT EXCEL, both Microsoft Corporation of Redmond, Washington, financial reporting programs, consumer registration programs, programs providing a technical support information, consumer database applications, or application set managers.
In one embodiment, web publishing tool 170 stores information about an application that web publishing tool 170 is publishing to web service directory 160 in persistent mass storage 225. In one embodiment, information is a URL for the dynamic publishing server plug-in 165. The persistent mass storage 225 can be a magnetic disk or a magneto-optical disk. In one embodiment, the persistent mass storage 225 is a database server, which stores data related to the published application in one or more local service databases. The persistent mass storage 225 can be a component located internally or located externally in relation to any or all remote machines 30.
In other embodiments, the content server 30 or the web server 30 'communicates with a remote machine 30 in bank 38 for retrieving the application list. In one of these modalities, the content server 30 or the web server 30 'communicates with bank 38, instead of with persistent mass storage 225.
Referring now to figure 2, a flowchart describes a modality of the steps followed to select a method for executing an application program. In a brief overview, the credentials associated with the local machine or a user of the local machine are received, with a request for an enumeration of applications available for execution by the local machine (step 202). An enumeration of a plurality of application programs available to the local machine is provided, in response to the credentials received (step 204). A request is received to run the listed application (step 206). One of a predetermined number of methods for running the enumerated application is selected, in response to a policy, the predetermined number of methods including a method for continuous application transmission of the enumerated application (step 208).
Credentials associated with the local machine or a user of the local machine are received, with the request for an enumeration of applications available for execution by the local machine (step 202). In one embodiment, the remote machine receives a request by enumerating applications available from local machine 10 with credentials. In another embodiment, an XML service on the remote machine 30 receives the request and credentials and transmits the request and credentials to a management service on the remote machine 30.
In some embodiments, a remote machine 30 functioning as a web server receives communications from the local machine 10 and forwards the communications to a remote machine 30 '. In one of these modalities, the web server forwards the communications to an XML service on the remote machine 30 '. In another of these modalities, the web server resides on the local machine. In other embodiments in which communications from local machine 10 are routed to a remote machine 30 'by the web server, remote machine 30 can be selected in response to an Internet Protocol (IP) address of the local machine 10.
In some embodiments, a local machine 10 requests access to an application residing on a remote machine 30. In one of these modalities, local machine 10 requests an execution by remote machine 30 of the application residing on remote machine 30. In another of these modalities, the local machine 10 requests a recovery of a plurality of application files that comprise the application.
In some modalities, the user provides credentials for the remote machine 30 through a graphical user interface presented to the local machine 10 by the remote machine 30. In other modalities, a remote machine 30 '”having the functionality of a web server provides the graphical user interface for the local machine 10. In yet other modalities, a collection agent transmitted to the local machine 10 by the remote machine 30 accumulates the credentials from the local machine 10. In one embodiment, a credential refers to a username and password. In another embodiment, a credential is not limited to a username and password, but includes, without limitation, a machine ID of the local machine 10, the type of operating system, the existence of a patch for an operating system, MAC addresses of installed network cards, a digital watermark on the client device, a membership in an Active Directory, the existence of a virus scan, the existence of a personal firewall, an http header, a type of browser , a device type, network connection information, such as an internet protocol address or a range of addresses, a remote machine's machine ID 30, access request date or time including settings for variable time zones , and authorization credentials.
In some embodiments, a credential associated with a local machine is associated with a user of the local machine. In one of these modalities, the credential is information held by the user. In another of these modalities, the credential is a user authentication information. In other modalities, a credential associated with a local machine is associated with a network. In one of these modalities, the credential is information associated with a network to which the local machine can connect. In another of these modalities, the credential is information associated with a network collecting information about the local machine. In still other modalities, a credential associated with a local machine is a characteristic of the local machine.
An enumeration of a plurality of application programs available for the local machine is provided, in response to the credentials received (step 204). In one embodiment, a user of a local machine 10 can learn the availability of application programs hosted by remote machines 30 on network 40, without knowing where to find such applications and without the technical information necessary to connect to those applications. These available application programs comprise the user's program neighborhood. A system for determining a program neighborhood for a local machine includes an application program (hereinafter referred to as the Program Neighborhood application), a memory for storing application program components, and a processor for executing the program app. The Program Neighborhood (PN) application can be installed in the memory of the local machine 10 and / or on a remote machine 30, as described below.
A remote machine 30 operating under the Program Neighborhood application collects application-related information from each of the remote machines 30 in a bank 38. The application related information for each hosted application can be a variety of information including, for example, an address of the remote machine hosting that application, the application name, the users or groups of users who are authorized to use that application, and the minimum required capabilities of the local machine 10, before establishing a connection to run the application. For example, the application can continuously transmit video data and therefore a minimum required capacity may be that the local machine supports video data. Other examples are requirements for the local machine to support audio data or have the ability to process encrypted data. Application-related information can be stored in a database.
When a local machine 10 connects to network 40, the user of local machine 10 provides user credentials. User credentials can include the user name of a user of the local machine 10, the user password, and the domain name for which a user is authorized. Alternatively, user credentials can be obtained from smart cards, time-based tokens, social enrollment numbers, user passwords, personal identification numbers (PIN), digital certificates based on a symmetric key or elliptical curve encryption, biometric characteristics of the user or any other means by which the user identification of the local machine 10 can be obtained and submitted for authentication. Remote machine 30 responding to local machine 10 can authenticate the user based on user credentials. User credentials can be stored anywhere the Program Neighborhood application is running. For modalities in which a remote machine 30 runs the Program Neighborhood, credentials can be stored on that remote machine 30.
From user credentials and application-related information, remote machine 30 can also determine which application programs hosted by remote machines 30 are available for use by the user of local machine 10. Remote machine 30 transmits information representing the application programs available for local machine 10. This process eliminates the need for a user of local machine 10 to establish application connections. Additionally, an administrator of the remote machine 30 can control access to applications among multiple users of a local machine 10.
In some embodiments, user authentication performed by remote machine 30 may be sufficient to authorize the use of each hosted application program presented to local machine 10, although these applications may reside on another remote machine 30 '. Therefore, when local machine 10 opens (that is, starts running) one of the 10 hosted applications, an additional entry of user credentials by local machine 10 may be unnecessary for authenticating the use of that application. Thus, a single entry of user credentials can serve to determine the available applications and to authorize the opening of these applications, without an additional manual login authentication process by the user.
A local machine 10 or a remote machine 30 can open the Program Neighborhood application. The results are displayed on the display screen 12, 22 of the local machine 10. In a graphical window-based implementation, the results can be displayed in a 20 Program Neighborhood graphical window and each authorized application program can be presented by a graphical icon in that window.
In one embodiment, the Program Neighborhood application filters out application programs that local machine 10 is not authorized to run and displays only authorized programs (that is, available). In 25 other modalities, the Program Neighborhood application can display both authorized and unauthorized applications. When unauthorized applications are filtered from the view, a notification can be provided indicating that those applications are not available. Alternatively, the Program Neighborhood application can report all applications hosted 30 by remote machines 30 to the user of a local machine 10, without identifying which applications the local machine 10 is authorized or not authorized to run. An authorization can subsequently be determined when local machine 10 attempts to run one of these applications.
Local machine 10 can request an application enumeration from a remote machine 30. Application enumeration allows a user of local machine 10 to see the names of every published application. In one embodiment, the user of the local machine 10 can see the application names regardless of whether the user is authorized to run the application. In another mode, the user sees only those application names that the user is authorized to run.
Application enumeration requests pass to the ICA 260 browser subsystem, to the program neighborhood subsystem 270, or to a common application subsystem 524, depending on the particular process being run by the local machine 10. For example, when the local machine 10 is running a program neighborhood application, requests for application enumeration are sent to program neighborhood subsystem 270 on a remote machine 30. When local machine 10 submits an enumeration request via a web page, the requests pass to the common access point subsystem 524. For these modalities, the common application subsystem 524 serves as an initial access point for the subsystem program neighborhood 270, the ICA 260 browser subsystem, and the common application subsystems, when local machine 10 wants to enumerate the applications. In some embodiments, when local machine 10 submits the enumeration request via a web page, an intermediate remote machine 30 hosting a web server receives the request and forwards the request to a remote machine 30 '.
Upon receipt of enumeration requests, a common application subsystem 524 queries persistent storage 230 for a list of all applications. For requests received from program neighborhood subsystem 270 and common access point subsystems 645, this list of applications is filtered according to the user credentials of the local machine 10 (that is, the user sees only those applications the user is authorized to).
Local machine 10 can also request a remote machine enumeration. Remote machine enumeration allows a user of local machine 10 to view a list of remote machines in bank 38. In one embodiment, the list of remote machines can be filtered according to the type of remote machine, as determined by the machine subsystem. specialized remote machine on that remote machine.
Requests for remote machine enumeration pass to the ICA 260 browser subsystem or to the common access point subsystem 645, depending on the particular process being run by local machine 120. For example, when local machine 120 submits the request from remote machine enumeration via a web page, requests pass to the common 645 access point subsystem. For these modalities, the common remote machine subsystem 300 serves as an initial access point for the ICA 260 browser subsystem and the common access point subsystem 645. Upon receipt of the remote machine enumeration requests, the common remote machine queries persistent storage 230 for a list of all remote machines. Optionally, the list of remote machines is filtered according to the type of remote machine.
Figure 3A is a block diagram that describes another modality of the process by which a local machine 10 starts executing the Program Neighborhood application, in this example, through the World Wide Web. A local machine 10 runs a web browser application 80, such as NETSCAPE NAVIGATOR, manufactured by Netscape Communications, Inc. Mountain View, California or the MICROSOFT INTERNET EXPLORER, manufactured by Microsoft Corporation of Redmond, Washington, or FIREFOX, manufactured by the Mozilla Foundation of Mountain View, California, or OPERA, manufactured by Opera Software ASA, Oslo, Norway, or SAFARI, manufactured by Apple Computer, Inc., of Cupertino, California.
Local machine 10, via web browser 80, transmits a request 82 for access to a Uniform Resource Locator (URL) address corresponding to an HTML page residing on remote machine 30. In some embodiments, the first HTML page 5 returned 84 to the local machine 10 by the remote machine 30 is an enumeration page that seeks to identify the local machine 10.
Still with reference to figure 3A, once the local machine 10 is authenticated by the remote machine 30, the remote machine 30 prepares and transmits to the local machine 10 an HTML page 88 that includes a Program Neighborhood window 58 in which graphic icons 57, 57 'appear representing application programs to which local machine 10 has access. A local machine user 10 invokes an application run represented by the icon 57 by clicking on that icon 57.
In some embodiments, remote machine 30 executes the Program Neighborhood application on behalf of a user of local machine 10. In one of these embodiments, remote machine 30 is an intermediate remote machine residing between local machine 10 and a remote machine 30 '.
With reference to figure 3B, a flowchart describes a fashion20 of the steps followed to provide a plurality of application programs available to the local machine by publishing GUIs in a web service directory. The web publishing tool 170 receives a web service description and access information for an application (for example, a GUI application) for publication (e25 slap 300). In one embodiment, the web service description includes the service information described above (for example, the name of the office offering the web service, the type of service, the textual description of the service and an SAP). Access information can include, for example, a published application name, a Transmission Control Protocol (TCP) navigation server bank address, and a Metaquadro server IP address. In some embodiments, the access information specifies the address to use and a ticket to use to cross the network or security gateways or bridge devices.
The web publishing tool 170 then constructs a service publishing request to request publication of the web service (that is, a GUI application) (step 305). In one embodiment, the service publication request includes an SAP. In some embodiments, SAP is a URL including a web address of the web server 30 'and the publishing server plug-in 165. In addition, the web address can be a Uniform Resource Identifier (URI), which is the generic term for the types of names and addresses that refer to objects on the web. A URL is a type of URI. An example of the URI is the name of the web server 30 '(for example, web server) and the CGI script name (for example, dynamic component) for the publishing server plug-in 165.
The web publishing tool 170 stores an SAP entry associated with SAP in persistent mass storage 225 (step 310). In some embodiments, the web publishing tool 170 also associates the published application information (for example, ICA-published-app-info) with the GUI application. In additional embodiments, the web publishing tool 170 also includes a key in the service publishing request for identifying the SAP entry that content server 30 stores in persistent mass storage 225. For example, the key may be the value of 123456677. An example of an SAP identifying the web server 30 ', the CGI script name of the publishing server plug-in 165 and the key described above is http: // web-server / dynamic-component /? App = 123456677 .
An example of the SAP entry associated with SAP described above is key = 123456677, value = ICA-published-app-info. The key can be any length (for example, a 56-bit key, a 128-bit key). In one embodiment, the key is an encrypted random number. The key can also provide access to the key maintainer. Although illustrated with a key, any means can be used to provide a form of security at the entrance of SAP stored in persistent mass storage 225.
The web publishing tool 170 provides the service publishing request for the content server 30 for publication in the web service directory 160 (step 315). Furthermore, in one embodiment, the content server 30 transmits the SAP key to the local machine 10 requesting the particular web service for subsequent use in locating the SAP entry. In one embodiment, publishing the service publication request allows users of the local machine 10 to access the service. In one embodiment, the GUI applications are published in the web service directory 160 using NFUSE developed by Citrix Systems, Inc. of Fort Lauderdale, Florida. In some embodiments, a GUI application editor customizes the publication of the GUI application in the web service directory 160 using Application Launching And Embedding (ALE), also developed by Citrix Systems, Inc. ALE allows opening of a GUI application from or inserting the application on an HTML page.
Local machine 10 then queries for a service name from web service directory 160 (step 320). The content server 30 receives the query from the local machine 10 (step 325) and finds the requested service name in the web service directory 160. In another mode, the user of the local machine 10 navigates through the service directory of the web 160 until it finds a particular service name that the user of the local machine 10 was trying to find. Although illustrated with the local machine 10, any web service directory client (for example, a UDDI client or an LDAP browser) can query or browse the web service directory 160 to discover published web services.
By locating the SAP associated with the query received, the content server 30 transmits the SAP to the local machine 10 (step 330). Local machine 10 receives SAP (step 335) and determines the address of the publishing server plug-in 165 from SAP. Local machine 10 subsequently transmits a request to the GUI application to the web server 30 '(step 340). In some embodiments, the request from the local machine 10 is an HTTP request transmitted from the web browser 11 to the web server 30 '. In other embodiments, an application (for example, general directory browser or HTML UI) running on local machine 10 receives SAP from content server 30 and provides SAP as an argument for web browser 11.0 web browser 11 can then automatically transmit an HTTP request (to the GUI application) to the web server 30 '. Following along the lines of the previous examples, a particular example of application request for the web server 30 'is http: // web server / dvnamic-component /? App = 123456677.
The web server 30 'and, more particularly, the publishing server plug-in 165 receive the application request associated with SAP (step 345) and determine the SAP entry associated with the request (step 350). In one embodiment, the publishing server plug-in 165 receives the request from the local machine 10 and retrieves the published application information associated with the request that was stored (as part of the SAP entry) in persistent mass storage 225. In some embodiments, the publishing server plug-in 165 uses SAP (or part of SAP) that local machine 10 received from content server 30 as the key to access the appropriate service entry (for example, the published application information) stored in the 225 persistent mass storage.
The publishing server plug-in 165 then builds a file or document having the published application information (for example, an HTTP address from the application server 30 ”) (step 352) and transmits this document to the local machine 10 ( step 355). The publishing server plug-in 165 builds the file so that the file has a format compatible with the application client 13. In one embodiment, the document is a Purpose Internet Mail Extensions document
Multiple (MIME) or secure MIME (S / MIME). In another embodiment, the document is an HTML document containing an HTML tag of an inserted object from an ICA web client. In yet another modality, the document is an HTML document containing an HTML tag of an inserted application streaming client.
The web browser 11 subsequently receives the document and tries to open the document. In one embodiment, if application client 13 is not installed on local machine 10, local machine 10 will communicate with application server 30 ”to download (download) and install application client 13. Upon installation of application client 13 or, alternatively, if application client 13 has already been installed on local machine 10, local machine 10 will open application client 13 to view the document received from web server 30 ' (step 360).
Once application client 13 is installed and running on local machine 10, application server 30 ”then runs the application and displays the application on application client 13 (step 365). In an alternative embodiment, the 30 ”application server transmits a plurality of application files comprising the application to the application client 13 for execution on the local machine 10, as further described in detail below in relation to figure 7. In another embodiment, the local machine 10 sees the document (even before the application client 13 opens) and uses the information in the document to obtain the GUI application from the 30 ”application server. In this mode, the display of the GUI application includes the installation and execution of the 30 ”application server. Furthermore, the document view can be transparent to the user of the local machine 10. For example, local machine 10 can receive the document from the 30 ”application server and interpret the document before automatically requesting the GUI application from the 30” application server.
Thus, application client 13 provides service-based access to published applications, desktops, desktop documents and any other application that is supported by application client 13. Examples of applications that application client 13 can provide access to include, but are not limited to, WINDOWS workspaces, WINDOWS documents, such as MICROSOFT EXCEL, WORD and POWERPOINT, all of which have been developed by Mi crosoft Corporation from Redmond, Washington, Unix workspaces such as SUN SOLARIS developed by Sun Microsystems of Paio Alto, California, and GNU / Linux distributed by Red Hat, Inc. of Durham, North Carolina, among others.
In some embodiments, the enumeration of a plurality of application programs available to the local machine 10 is provided (step 204) in response to a determination by a policy agent regarding whether and how a local machine can access an application. The policy officer can collect information about the local machine before making the determination. Referring now to Figure 4A, a modality of a computer network constructed in accordance with the invention is described, which includes a local machine 10, a collection agent 404, a policy agent 406, a database of policy 408, a bank 38 and an application server 30 ”. In one embodiment, policy agent 406 is a remote machine 30. In another embodiment, the application server 30 ”is a remote machine 30 '. Although only a local machine 10, a collection agent 404, a policy agent 406, a bank 38 and an application server 30 'are described in the manner shown in Figure 4A, it should be understood that the system can provide multiples of either or each of those components.
In a brief overview, when local machine 10 transmits a request 410 to policy agent 406 for access to an application, collection agent 404 communicates with local machine 10, retrieving information about local machine 10, and transmits local machine information 412 to policy agent 406. Policy agent 406 makes an access control decision by applying a policy from policy database 408 to received information 412.
In more detail, local machine 10 transmits a request 410 for a resource to policy agent 406. In one embodiment, policy agent 406 resides on an application server 30 '. In another embodiment, policy agent 406 is a remote machine 30. In yet another embodiment, an application server 30 'receives the request
410 from local machine 10 and transmits request 410 to policy agent 406. In yet another modality, the local machine transmits request 410 to a resource to a remote machine 30 ”', which transmits request 410 to the policy agent 406.
Upon receipt of the request, policy agent 406 initiates an accumulation of information by collection agent 404. Collection agent 404 accumulates information regarding local machine 10 and transmits information 412 to policy agent 406.
In some embodiments, the collection agent 404 accumulates and transmits information 412 over a network connection. In some embodiments, the collection agent 404 comprises a byte code, such as an application written in the JAVA byte code programming language. In some embodiments, the collection agent 404 comprises at least one script. In those modalities, the collection agent 404 accumulates information when running at least one script on the local machine 10. In some embodiments, the collection agent comprises an Active X control on the local machine 10. An Active X control is a Component Object Model (COM) object that implements a set of interfaces that allow it to look and act as a control .
In one embodiment, policy agent 406 transmits collection agent 404 to local machine 10. In another embodiment, a 1250 appliance can store or cache the collection agent. The 1250 apparatus can then transmit the collection agent to a local machine 10. In other embodiments, a 1250 apparatus can intercept the transmission of a 404 collection agent. In yet another embodiment, a 1250 apparatus can accelerate the delivery of an agent collection. In one embodiment, policy agent 406 requires a second run from collection agent 404 after collection agent 404 has transmitted information 412 to policy agent 406. In this embodiment, policy agent 406 may have insufficient information 412 to determine if the local machine 10 meets a particular condition. In other embodiments, policy officer 406 requires a plurality of executions of collection agent 404 in response to information received 412.
In some embodiments, policy agent 406 transmits instructions to collection agent 404 determining the type of information that collection agent 404 accumulates. In those modalities, a system administrator can configure the instructions transmitted to the collection agent 404 from the policy agent 406. This provides greater control over the type of information collected. This also expands the types of access control decisions that the policy agent 406 can take, due to greater control over the type of information collected. The collection agent 404 accumulates information 412 including, without limitation, a machine ID of the local machine 10, type of operating system, existence of a patch for an operating system, MAC addresses of installed network cards, a d 'mark. digital water on the client device, participation in an Active Directory, the existence of a virus scan, the existence of a personal firewall, an HTTP header, a type of browser, a type of device, a network connection information, such as an internet protocol address or a range of addresses, a remote machine's machine ID 30, access request date or time including settings for varying time zones, and authorization credentials . In some embodiments, a collection agent accumulates information to determine whether an application can be accelerated on the client using a 6120 acceleration program.
In some embodiments, the device type is a personal digital assistant. In other modalities, the type of device is a cell phone. In other modalities, the type of device is a laptop computer. In other modalities, the type of device is a desktop computer. In other modalities, the device type is an Internet kiosk.
In some modalities, the digital watermark includes data entry. In some embodiments, the watermark comprises a data pattern inserted into a file to provide source information about the file. In other modalities, the watermark comprises data verification files for the provision of detection of violations. In other modalities, the watermark provides copyright information about the file.
In some embodiments, the network connection information refers to bandwidth capabilities. In other embodiments, the network connection information refers to an Internet Protocol address. In still other modalities, the network connection information consists of an Internet Protocol address. In one embodiment, the network connection information comprises a network zone identifying the logon agent to which the local machine has provided authentication credentials.
In some embodiments, authentication credentials include various types of authentication information, including, without limitation, user names, customer names, customer addresses, passwords, PINs, voice samples, one-time password codes, biometric data , digital certificates, tickets, etc. and combinations thereof. Upon receipt of accumulated information 412, policy officer 406 makes an access control decision based on information received 412.
Referring now to Figure 4B, a block diagram depicts one embodiment of a policy agent 406, including a first component 420 comprising a condition database 422 and a login agent 424, and including a second component 430 comprising a policy database 432. The first component 420 applies a condition to condition database 422 for information received on local machine 10 and determines whether the information received satisfies the condition.
In some embodiments, a condition may require the local machine 10 to run a particular operating system to satisfy the condition. In some embodiments, a condition may require the local machine 10 to perform a particular operating system patch to satisfy the condition. In still other embodiments, a condition may require the local machine 10 to provide a MAC address for each installed network card to satisfy the condition. In some embodiments, a condition may require the local machine 10 to indicate participation in a particular Active Directory to satisfy the condition. In another embodiment, a condition may require local machine 10 to perform a virus scan to satisfy the condition. In other embodiments, a condition may require local machine 10 to run a personal firewall to satisfy the condition. In some embodiments, a condition may require that the local machine 10 comprises a particular type of device to satisfy the condition. In other embodiments, a condition may require that the local machine 10 establishes a particular type of network connection to satisfy the condition.
If the information received satisfies a condition, the first component 420 will store an identifier for that condition in a data set 426. In one embodiment, the information received satisfies a condition, if the information makes the condition true. For example, a condition may require that a particular operating system be installed. If local machine 10 has an operating system, the condition is true and satisfied. In another mode, the information received satisfies a condition, if the information makes the condition false. For example, a condition can address whether there is spyware on local machine 10. If local machine 10 does not contain spyware, the condition will be false and satisfied.
In some embodiments, the logon agent 424 resides outside of policy agent 406. In other embodiments, logon agent 424 resides in policy agent 406. In one embodiment, the first component 420 includes a logon agent 424, which starts to accumulate information about the local machine 10. In some modalities, data storage includes the conditions under which the collection agent can accumulate information. This data store is distinct from condition database 422.
In some embodiments, the logon agent 424 initiates an accumulation of information by executing the collection agent 404. In other embodiments, the logon agent 424 initiates an information accumulation by transmitting the collection agent 404 to the local machine 10 for execution on the local machine 10. In yet other modalities, the logon agent 424 starts an accumulation of additional information after receiving an information 412. In one embodiment, logon agent 424 also receives information 412. In this embodiment, login agent 424 generates data set 426 based on information received 412. In some embodiments, logon agent 424 generates data set 426 by applying a condition from the database 422 to the information received from the collection agent 404.
In another embodiment, the first component 420 includes a plurality of logon agents 424. In this embodiment, at least one of the plurality of logon agents 424 resides in each network domain from which a local machine 10 can transmit a request for resource. In this mode, local machine 10 transmits the resource request to a particular logon agent 424. In some embodiments, the logon agent 424 transmits to the policy agent 406 the network domain from which the local machine 10 accessed the logon agent 424. In one embodiment, the network domain from which the local machine 10 accessing a logon agent 424 is referred to as the network zone of the local machine 10.
The condition database 422 stores the conditions that the first component 420 applies to the received information. Policy database 432 stores the policies that the second component 430 applies to received data set 426. In some embodiments, condition database 422 and policy database 432 store data in a database at ODBC compliance. For example, condition database 422 and policy database 432 can be provided as an ORACLE database, manufactured by Oracle Corporation of Redwood Shores, Calif. In other embodiments, condition database 422 and policy database 432 can be a Microsoft ACCESS database or a Mi51 crosoft SQL server database, manufactured by Microsoft Corporation of Redmond, Wash.
After the first component 420 applies the information received to each condition in the condition database 422, the first component transmits data set 426 to the second component 430. In one embodiment, the first component 420 transmits only data set 426 for the second component 430. Therefore, in this modality, the second component 430 does not receive information 412, only identifiers for satisfied conditions. The second component 430 receives data set 426 and makes an access control decision by applying a policy from policy database 432, based on the conditions identified in data set 426.
In one embodiment, the policy database 432 stores the policies applied to the received information 412. In one embodiment, the policies stored in the policy database 432 are specified, at least in part, by the system administrator. In another embodiment, a user specifies at least some of the policies stored in the 432 policy database. The policy or specific user policies are stored as preferences. Policy database 432 can be stored in volatile or non-volatile memory, or, for example, distributed across multiple servers.
In one modality, a policy allows access to a resource only if one or more conditions are met. In another modality, a policy allows access to a resource, but prohibits a transmission of the resource to the local machine 10. Another policy could make a connection contingent on the local machine 10 that requires access on a secure network. In some modalities, the resource is an application program and the local machine 10 requested the execution of the application program. In one of these modalities, a policy can allow the application program to run on the local machine 10. In another of these modalities, a policy can allow the local machine 10 to receive a continuous transmission of files comprising the application program. In this mode, the continuous transmission of files can be stored and performed in an isolation environment. In yet another of these modalities, a policy can only allow the application program to run on a remote machine, such as an application server, and require the remote machine to transmit application output data to the local machine 10.
Referring now to Figure 4C, a flowchart describes a modality of the steps followed by policy agent 406 to make an access control decision, based on information received from a local machine 10. Upon receiving the information accumulated on local machine 10 (Step 450), policy agent 406 generates a data set based on the information (Step 452). Dataset 426 contains identifiers for each condition satisfied by received information 412. Policy agent 406 applies a policy to each condition identified in dataset 426. That application produces an enumeration of resources that local machine 10 can access ( Step 454). Policy agent 406 then presents that enumeration to the local machine 10. In some embodiments, policy agent 406 creates a Hypertext Markup Language (HTML) document used to present the enumeration to the local machine.
With reference to figure 4D, a modality of a network constructed in accordance with the invention is described, which includes a local machine 10, a collection agent 404, a policy agent 406, a policy database 408, a bank condition data 410, a local machine 20, a session server 420, a stored application database 422, a remote machine 30 ', a first database 428, a remote machine 30 ”and a second database 432. In a brief overview, when the local machine 10 transmits a request 412 to the access control server 406 for access to an application program, the collection agent 404 communicates with the local machine 10, retrieves information about the local machine 10 and transmits local machine information 414 to policy agent 406. Policy agent 406 makes an access control decision, as discussed above in figure 4A and figure 4B. Local machine 10 receives an enumeration of available applications associated with local machine 10.
In some embodiments, session server 420 establishes a connection between local machine 10 and a plurality of application sessions associated with local machine 10. In other embodiments, policy agent 406 determines that local machine 10 is authorized to retrieve a plurality of application files comprising the application and to run the application program locally. In one of these embodiments, the remote machine 30 'stores application session data and a plurality of application files comprising the application program. In another of these embodiments, the local machine 10 establishes an application streaming session with a remote machine 30 'storing the application session data and the plurality of application files comprising the application program. In some embodiments, policy agent 406 determines whether to accelerate the delivery of the streaming session by transmitting an acceleration program 6120 to the local machine 10. In some embodiments, policy agent 406 determines whether to accelerate delivery delivery of data files by transmitting an acceleration program 6120 to the local machine 10.
Referring now to Figure 4E, a flowchart describes an embodiment of the steps followed by session server 420 for providing access for local machine 10 to its associated application sessions. Session server 420 receives information about local machine 10 from policy agent 406 containing an access control decision that policy agent 406 made (step 480). Session server 420 generates an enumeration of associated applications (step 482). Session server 420 can connect local machine 10 to an associated application (step 484). In one embodiment, the information also includes the local machine information 414. In another embodiment, the information includes an authorization to run the application program locally.
Session server 420 generates an enumeration of associated applications (step 482). In some embodiments, policy agent 406 identifies a plurality of application sessions already associated with local machine 10. In other embodiments, session server 420 identifies stored application sessions associated with local machine 10. In some of these modalities, session server 420 automatically identifies stored application sessions, upon receipt of information from policy agent 406. In one embodiment, stored application database 422 resides on session server 420. In another embodiment, the stored application database 422 resides on policy agent 406.
Stored application database 422 contains data associated with a plurality of remote machines in bank 38 running application sessions or providing access to application session data and application files comprising application programs. In some embodiments, identifying application sessions associated with local machine 10 requires querying stored data associated with one or more remote machines. In some of these embodiments, session storage 420 queries stored data associated with one or more remote machines. In other of these modalities, policy officer 406 queries stored data associated with one or more remote machines. In some embodiments, a first application session runs on a remote 30 'machine and a second application session runs on a remote 30 ”machine. In other modalities, all application sessions run on a single remote machine 30 in bank 38.
Session server 420 includes information related to user-initiated application sessions. The session server can be stored in volatile or non-volatile memory or, for example, distributed across multiple servers. Table 1 shows the data included in a portion of an illustrative session server 420:
<td>Application Session</td><td>Application Session 1</td><td>Application Session captive 2</td><td>Application Session asset 3</td>
<td>User ID</td><td>User 1</td><td>User 2</td><td>User 3</td>
<td>Customer ID</td><td>First customer</td><td></td><td>First customer</td>
<td>Customer address</td><td> 172.16.0.50</td><td></td><td> 172.16.0.50</td>
<td>Status</td><td>Active</td><td>Unplugged</td><td>Active</td>
<td>Applications</td><td>Word processor</td><td>Database</td><td>Spreadsheet</td>
<td>Process number</td><td> 1</td><td> 3</td><td> 2</td>
<td>Server</td><td>Server A</td><td>Server B</td><td>C Server</td>
<td>Server address</td><td> 172.16.2.55</td><td> 172.16.2.55</td><td> 172.16.2.56</td>
Table 1
Illustrative session server 420 in Table 1 includes data associating each application session with the user who initiated the application session, an identification of the client computer 10 or 20, if any, from which the user is currently connected to the remote machine 30 ', and the IP address of that client computer 10 or 20. The illustrative session server 420 also includes the status of each application session. An application session status can be, for example, active (meaning that a user is connected to the application session), or disconnected (meaning that a user is not connected to the application session). In an alternative embodiment, an application session status can be set to running - disconnected (meaning that the user has disconnected from the application session, but the applications in the application session are still running), or stopped - disconnected (meaning that the user is disconnected and the applications in the application session are not running, but their operational state immediately before the disconnection was stored). Session server 420 still stores information indicating applications 116 that are running in each application session and data indicating each application process on the server. In modalities in which remote machine 30 'is part of bank 38, session server 420 is at least a part of dynamic storage, and also includes data in the last two lines of Table 1 that indicate which remote machine 30 in bank 38 each application is / was running, and the IP address of that remote machine 30. Alternatively, session server 420 includes a status indicator for each application in each application session.
For example, in the example in Table 1, there are three application sessions, Application Session 1, Application Session 2 and Application Session 3. Application Session 1 is associated with User 1, who is currently using the terminal 1. The IP address of terminal one is 152.16.2.50. The status of Application Session 1 is active and in Application Session 1, a word processing program is running. The word processing program is running on Server A as process number 1. Server A's IP address is 152.16.2.55. Application Session 2 in Table 1 is an example of a disconnected application session 118. Application Session 2 is associated with User 2, but Application Session 2 is not connected to a local machine 10 or 20. Application Session 2 includes a database program that is running on Server A, at IP address 152.16.2.5 as process number 3. Application Session 3 is an example of how a user can interact with sessions application operating on 30 different remote machines. Application Session 3 is associated with User 1, as is Application Session 1. Application Session 3 includes a spreadsheet program that is running on Server B at IP address 152.16.2.56 as process number 2, while the application session included in Application Session 1 is running on Server A .
In another example, a user can access a first application program through an application session running on a remote machine 30 ', such as Server A, while communicating through an application streaming session with a second machine remote 30 ”, such as Server B, for retrieving a second application program from the second remote 30” machine for local execution. The user of local machine 10 may have acquired an authorization to run the second application program locally, while failing to satisfy the prerequisites for running the first application program.
In one embodiment, session server 420 is configured to receive a disconnect request to disconnect application sessions associated with local machine 10 and disconnect application sessions in response to the request. Session server 420 continues to run an application session after disconnecting local machine 10 from the application session. In this embodiment, session server 420 accesses stored application database 422 and updates a data record associated with each disconnected application session, so that the record indicates that the application session associated with local machine 10 is disconnected.
Upon receipt of authentication information associated with a local machine connecting to the network, session server 420 queries the stored application database 422 for identification of any active application sessions that are associated with a local machine user , but which are connected to a different local machine, such as local machine 10, if the authentication information is associated with local machine 20, for example. In one embodiment, if session server 420 identifies any of these active application sessions, session server 420 will automatically disconnect the application session (sessions) from local machine 10 and connect the session (sessions) from application to the current local machine 20. In some embodiments, the authentication information received will restrict the application sessions to which local machine 10 can reconnect. In other embodiments, the authentication information received authorizes an application program to run on local machine 20, where authorization may have been denied to local machine 10. In one of these modalities, session server 420 can provide the local machine with a access information for retrieving the application program for local execution.
A request is received to run an application and numbered (step 206). In one embodiment, a user of local machine 10 selects an application to run from the list of available applications received. In another mode, the user selects an application to run regardless of the enumeration received. In some embodiments, the user selects an application to run by selecting a graphical representation of the application presented on the local machine 10 by a customer agent. In other modalities, the user selects an application to run by selecting a graphical representation of the application presented to the user on a web server or another remote 30 ”machine. In some embodiments, a 1250 device or a 6120 acceleration program accelerates the delivery of the graphical representation. In some embodiments, a 1250 appliance caches or stores any and all associated applications or portions of the associated applications.
In other modalities, the user requests access to a file. In one of these modalities, the execution of an application is required to provide the user with access to the file. In another of these modalities, the application is automatically selected for execution by selecting the file for access. In yet another of these modalities, before the request for accessing the file, the application is associated with a file type, allowing an automatic selection of the application by identifying a type of file associated with the requested file. In some embodiments, a 1250 system or a 6120 accelerator program can be used to accelerate the delivery of one or more files. In some embodiments, a 1250 system can cache or store part or all of a file.
In one embodiment, the listed application comprises a plurality of application files. In some embodiments, the plurality of application files resides on a separate file server or remote 30 ”machine. In still other modalities, the plurality of application files can be transmitted to a local machine 10. In still other modalities, a file in the plurality of application files can be executed before the transmission of a second file in the plurality of application files to the local machine 10. In some modalities, a 1250 device or a 6120 accelerator program can be used to accelerating the delivery of one or more application files.
In some embodiments, remote machine 30 retrieves information about the listed application from remote machine 30 '. In one of these embodiments, remote machine 30 receives an identification from a remote machine 30 ”hosting a plurality of application files. In another such embodiment, remote machine 30 receives an identification of a location from a plurality of application files, identification in accordance with a Universal Naming Convention (UNC). In yet another of these modalities, the identification includes a network location and a socket for an application streaming protocol.
In one embodiment, remote machine 30 retrieves a file containing information about the listed application. The file can include an identification of a location on a server hosting the enumerated application. The file can include an identification of a plurality of versions of the listed application. The file may include an enumeration of a plurality of application files comprising the listed application. The file may include an identification of a compressed file comprising a plurality of application files comprising the listed application. The file can include an identification of prerequisites to be satisfied by a machine running the listed application. The file can include an enumeration of data files associated with the enumerated application. The file can include an enumeration of scripts to be executed on a machine running the enumerated application. The file can include an enumeration of registration data associated with the listed application. The file may include an enumeration of rules for use in a mode in which the listed application is run in an isolation environment. In one embodiment, the file can be referred to as a manifest file. The information the file can contain is described in more detail in relation to figure 21 below.
In some embodiments, remote machine 30 applies a policy to an identified feature of the local machine 10. In one of these embodiments, remote machine 30 identifies a version of the application listed for execution in response to the identified feature. In another of these modalities, the remote machine 30 makes a determination to execute a version of the listed application compatible with a characteristic of the local machine 10. In yet another of these modalities, the remote machine 30 makes a determination to execute a version of the listed application compatible with an operating system running on the local machine 10. In yet another of these modalities, the remote machine 30 makes a determination to execute of a version of the listed application compatible with an operating system revision level on the local machine 10. In one of these modalities, the remote machine 30 makes a determination to execute a version of the listed application compatible with a language specified by an operating system on the local machine 10.
One of a predetermined number of methods for running the enumerated application is selected, in response to a policy, the predetermined number of methods including a method for continuous application transmission of the enumerated application (step 208). In one embodiment, the selection is made in response to an application of a policy for the received credentials associated with the local machine 10. In some embodiments, the selection is made by a policy officer, such as policy officer 406 described above in figure 4A, figure 4B and figure 4C. In other embodiments, the remote machine 30 receiving the credentials and the request to run the listed application still comprises a policy agent 406.
In one embodiment, the predetermined number of methods includes a method for running the application listed on a remote machine 30 '. In another embodiment, the method enumerated application includes a method for executing the enumerated application on the local machine 10. In yet another embodiment, the predetermined number of methods includes a method for executing the enumerated application on a second remote machine 30 '.
In some embodiments, the predetermined number of methods includes a method for providing the enumerated application to the local machine 10 through an application streaming session. In one of these embodiments, the local machine 10 comprises a streaming service agent capable of initiating a connection with a remote machine 30 'and receiving from the remote machine 30' a continuous transmission of transmitted data packets.
The continuous transmission of data packets may include application files comprising the listed application. In some embodiments, application files include data files associated with an application program. In other modalities, the application files include executable files required for the execution of the application program. In yet other modalities, application files include metadata including information about the files, such as location, compatibility requirements, configuration data, registration data, identification of execution script rules for use in isolation environments, or security requirements. authorization. In one embodiment, the continuous transmission of data packets is transmitted over a transport layer connection, such as a payload of a TCP / IP packet.
In some embodiments, the continuously transmitted application is executed before the transmission of each application file in a plurality of application files comprising the continuously transmitted application. In one of these modalities, the execution of the continuously transmitted application begins upon the receipt by a local machine 10 of an application file in the plurality of applications. In another of these modalities, the execution of the continuously transmitted application begins upon receipt by a local machine 10 of an executable application file in the plurality of application files. In yet another of these modalities, the local machine 10 executes a first application file received in a plurality of application files and the first application file received requires access to a second application file in the plurality of application files.
In one embodiment, the continuously transmitted application runs on local machine 10 without permanently residing on local machine 10. In this mode, the continuously transmitted application can run on local machine 10 and be removed from local machine 10 upon termination of the continuously transmitted application. . In another mode, the continuously transmitted application runs on local machine 10 after a pre-employed copy of each application file is stored on local machine 10. In yet another mode, the continuously transmitted application runs on local machine 10 after a copy of each application file to be stored in an isolation environment on the local machine. In yet another modality, the continuously transmitted application runs on the local machine 10 after a copy of each application file is stored in a cache on the local machine 10.
In one embodiment, the method for continuously transmitting the application to the local machine 10 is selected from the predetermined number of methods in response to a determination that the local machine 10 can receive the application files transmitted continuously. In another embodiment, the method for continuously transmitting the application to the local machine 10 is selected from the predetermined number of methods in response to a determination that the local machine 10 has an authority to run the application files continuously transmitted locally.
In other embodiments, the predetermined number of methods includes a method for providing application output data to the local machine 10, the application output data generated from running an application listed on a remote machine 30. In a of these modalities, remote machine 30 is remote machine 30 that receives the request to run the listed application. In another of these embodiments, remote machine 30 is a second remote machine 30 ', such as a file server or an application server. In some embodiments, the listed application resides on remote machine 30 'running the listed application. In other embodiments, the remote machine 30 'running the enumerated application first receives the enumerated application from a second remote machine 30' through an application streaming session. In one of these embodiments, the remote machine 30 'comprises a streaming service agent capable of initiating a connection with a second remote machine 30' and receiving a continuous transmission of transmitted data from the second remote machine 30 '. In another of these embodiments, the second remote machine 30 'can be identified using a load balancing technique. In yet another of these embodiments, the second remote machine 30 'can be identified based on the proximity to the remote machine 30'. These modalities will be described in more detail in relation to figure 9 below.
In some embodiments, remote machine 30 selects from the predetermined number of methods for running the listed application a method for continuously transmitting the listed application to remote machine 30, running the application listed on remote machine 30 and providing it to the local machine 10 application output data generated by running the enumerated application. In one of these modalities, the remote machine 30 selects the method in response to an evaluation of the local machine 10. In another of these modalities, the determination is made in response to an absorbing article an application of a policy for evaluating the local machine 10. Still in another of these modalities, the determination is made in response to an assessment of the credentials received. In one embodiment, remote machine 30 receives a plurality of application files comprising the listed application. In another embodiment, remote machine 30 provides application output data through a presentation level protocol, such as an ICA presentation level protocol or a Remote Desktop Windows presentation level protocol or a XWindows presentation level protocol.
In some embodiments, the remote machine 30 also provides access information associated with the listed application, the access information generated in response to the selected method. In one of these modalities, the access information provides an indication to the local machine 10 of the method selected for executing the listed application program. In another of these modalities, the access information includes an identification of a location of the listed application, the identification in accordance with a Universal Naming Convention (UNC). In yet another of these modalities, the access information includes an identification of a session management server.
In some embodiments, the access information includes an opening ticket comprising authentication information. In one of these modalities, the local machine 10 can use the opening ticket to authenticate the access information received from the remote machine 30. In another of these modalities, the local machine 10 can use the opening ticket to authenticate itself. to a second remote machine 30 hosting the enumerated application. In yet another such embodiment, remote machine 30 includes an opening ticket in the access information in response to a request from local machine 10 for the opening ticket.
Referring now to Figure 5, a block diagram describes a embodiment of the present invention in which a local machine 10 requests an application program to be executed and a remote machine 30 selects an application program execution method. In one embodiment, remote machine 30 receives credentials from local machine 10. In another embodiment, remote machine 30 receives a request for an enumeration of applications available from local machine 10.
In some embodiments, multiple remote redundant machines 30, 30 ', 30 ”, 30'” and 30 ”” are provided. In one of these modalities, there may be, for example, multiple file servers, multiple session management servers, multiple stage machines, multiple web interfaces, or multiple access suite consoles. In another of these embodiments, if a remote machine fails, a redundant remote machine 30 will be selected to provide the functionality of the failed machine. In other embodiments, although remote machines 30, 30 ', 30 ”, 30”' and 30 ”” and web interface 558 and access suite console 520 are described as separate remote machines 30 having separate functionality from a management server, a session management server, a stage machine, a file server, a web server and an access suite console, a single remote machine 30 can be provided having the functionality of all of these machines. In still other embodiments, a remote machine 30 can provide the functionality and services of one or more of the other remote machines.
Referring now to Figure 5 in greater detail, a block diagram describes a mode of a remote machine 30 providing access to an application program. In addition to the interfaces and subsystems described above in relation to figure 1D, the remote machine 30 can still include a management communication service 514, an XML service 516 and a management service 504. The management service 504 can comprise an application management subsystem 506, a server management subsystem 508, a session management subsystem 510 and a license management subsystem 512. Remote machine 30 may be communicating with a console of access suite 520.
In one embodiment, the management service 504 further comprises a specialized remote procedure call subsystem, the Metaframe Remote Procedure Call subsystem (MRFPC) 522. In some embodiments, the MRFPC 522 subsystem routes communications between the subsystems on the machine remote 30, such as the XML service 516, and the management service 504. In other embodiments, the MRFPC 522 subsystem provides a remote procedure call (RPC) interface for calling management functions, delivers RPC calls to management service 504 and returns the results to the subsystem making the call.
In some embodiments, remote machine 30 is in communication with a protocol agent, such as policy agent 406 described above in figure 4B. In one of these embodiments, remote machine 30 is in communication with a policy agent 406 residing on remote machine 30 '. In other embodiments, the remote machine 30 still comprises a policy agent 406.
Remote machine 30 can be communicating with an access suite 520 console. Access suite console 520 can host management tools for an administrator of a remote machine 30 or a bank 38. In some embodiments, the remote machine 30 communicates with the access suite 520 console using XML. In other embodiments, remote machine 30 communicates with the access suite console 520 using a Simple Object Access Protocol (SOAP).
For modalities such as those described in figure 1D and figure 5, where the remote machine 30 comprises a subset of subsystems, the management service 504 can comprise a plurality of subsystems. In one embodiment, each subsystem is a single line or multiple line subsystem. A line is an execution-independent continuous stream running in a multitasking environment. A single-line subsystem is capable of executing only one line at a time. A multiple line subsystem can support multiple lines running concurrently, that is, a multiple line subsystem can perform multiple tasks simultaneously.
The 506 application management subsystem manages information associated with a plurality of applications capable of being transmitted continuously. In one embodiment, the 506 application management subsystem handles requests from other components, such as requests for storage, deletion, updating, enumeration or resolving applications. In another modality, the 506 application management subsystem handles requests sent by components related to an application capable of being transmitted continuously. These events can be classified into three types of events: application publishing, application enumeration and application opening, each of which is described in greater detail below. In other embodiments, the 506 application management subsystem further comprises support for application resolution, application publishing and application publishing. In other embodiments, the 506 application management subsystem uses a data store for storing application properties and policies.
The 508 server management subsystem handles specific settings for application streaming in server bank configurations. In some embodiments, the server management subsystem 508 also handles events that require information retrieval associated with a bank configuration 38. In other embodiments, the 508 server management subsystem handles events sent by other components related to remote machines by providing access to applications through continuous streams and properties from those remote machines. In one embodiment, the server management subsystem 508 stores remote machine properties and bank properties.
In some embodiments, remote machine 30 still comprises one or more subsystems of common application 524 providing access to one or more subsystems of specialized application. These remote machines 30 may also have one or more common remote machine subsystems providing services for one or more specialized remote machine subsystems. In other embodiments, no common application subsystem 524 is provided, and each specialized application and remote machine subsystem implements all required functionality.
In an embodiment in which remote machine 30 comprises a common application subsystem 524, the common application subsystem 524 manages common properties for published applications. In some embodiments, the common application subsystem 524 handles events that require information retrieval associated with published applications or common properties. In other embodiments, the common application subsystem 524 handles all events sent by other components related to common applications and their properties.
A common application subsystem 524 can publish applications to bank 38, which makes each application available for enumeration and opening by a local machine 10. Generally, an application is installed on each remote machine 30 on which an availability of that application is desired. In one embodiment, to publish an application, an administrator runs an administration tool specifying information, such as remote machines 30 hosting the application, the name of the executable file on each remote machine, the required capabilities of a local machine to run the application. application (for example, audio, video, encryption, etc.) and a list of users who can use the application. This specified information is categorized into application-specific information and common information. Examples of application-specific information are: the path name for accessing the application and the name of the executable file to run the application. Common information (that is, common application data) includes, for example, the user friendly name (for example, Microsoft WORD 2000), a unique identification of the application, and the users of the application.
Application-specific information and common information can be sent to a specialized application subsystem controlling the application on each remote machine 30 hosting the application. The specialized application subsystem can write application-specific information and common information for persistent storage 240.
When provided, a common application subsystem 524 also provides an installation for managing applications published in bank 38. Through a common application subsystem 524, an administrator can manage bank 38 applications using an administration tool, such as the console access suite 520, for configuring application groups and producing an application tree hierarchy for those application groups. Each application group can be represented as a file folder in the application tree hierarchy. Each application folder in the application tree hierarchy can include one or more other application folders and specific instances of remote machines. The common application subsystem 524 provides functions for creating, moving, renaming, deleting and enumerating application folders.
In one embodiment, the common application subsystem 524 supports application management subsystem 506 in handling application enumeration and application resolution requests. In some embodiments, the common application subsystem 524 provides functionality for identifying an application to run in response to a mapping between a data file type and an application for processing the data file type. In other embodiments, a second application subsystem provides functionality for file type association.
In some embodiments, the remote machine 30 may still comprise a policy subsystem. A policy subsystem includes a policy rule to determine whether an application can be transmitted continuously to a local machine 10 upon a request by the local machine 10 to run the application. In some embodiments, the policy subsystem identifies a server access option associated with a continuously streamed application published in the access suite 520 console. In one of these modalities, the policy subsystem uses the server access option as a policy in the place of the policy rule.
The session monitoring subsystem 510 maintains and updates a session status of an application streaming session associated with a local machine 10 and enforces license requirements for application streaming sessions. In one embodiment, the session management subsystem 510 monitors sessions and logs events, such as opening an application or ending an application streaming session. In another embodiment, the session monitoring subsystem 510 receives communications, such as heartbeat messages, transmitted from local machine 10 to remote machine 30. In yet another embodiment, session management subsystem 510 responds to session queries from management tools, such as tools in the 520 access suite console. In some embodiments, the 504 management service still comprises a license management subsystem in communication with the session management subsystem for provisioning and maintaining licenses for local machines for running applications.
In one embodiment, the 504 management service provides functionality for application enumeration and application resolution. In some modalities, the 504 management service also provides functionality for opening an application, monitoring and session monitoring, publishing an application and enforcing a license.
Referring now to Figure 6, a block diagram describes a mode of a remote machine 30 comprising a management service providing an application enumeration. The 504 management service can provide an application enumeration through the use of a web interface interacting with an XML 516 service. In one embodiment, the XML 516 service enumerates applications for a user of a local machine 10. In another embodiment, the XML 516 service implements the functionality of the ICA browser subsystem and the program neighborhood subsystem described above. The XML 516 service can interact with a 514 management communication service. In one embodiment, the XML 516 service generates an application enumeration request using the 514 management communication service. The application enumeration request may include a client type indicating an execution method to be used when executing the search agent. The application enumeration request is sent to a common application subsystem 524. In one embodiment, the common application subsystem 524 returns an enumeration of applications associated with the typically application enumeration request client. In another embodiment, the common application subsystem 524 returns an enumeration of applications available to the user of the local machine 10, the enumeration selected in response to an application of a policy to a credential associated with the local machine 10. In this embodiment, an agent of policy 406 can apply the policy to credentials accumulated by a collection agent 404, as described in relation to figure 4B above. In yet another modality, the application enumeration is returned and an application of a policy to the local machine 10 is deferred until an execution of an enumerated application is requested.
The management service 504 can provide an application resolution service for the identification of a second remote machine 30 'hosting an application. In one embodiment, the second remote machine 30 'is a file server or an application server. In some embodiments, the management service 504 queries a file including identifiers for a plurality of remote machines 30 hosting applications. In one embodiment, the management service 504 provides the application resolution service in response to a request from a local machine 10 to run an application. In another embodiment, the management service 504 identifies a second remote machine 30 'capable of implementing a different method of running the application than a first remote machine 30. In some embodiments, the management service 504 identifies a first remote machine 30 'capable of continuously transmitting an application program to a local machine 10 and a second remote machine 30' capable of running the application program and providing application output data generated in response to running the application program for the local machine 10.
In one embodiment, a web interface transmits an application resolution request to the XML 516 service. In another embodiment, the XML 516 service receives an application resolution request and transmits the request to the MRFPC 522 subsystem.
In one embodiment, the MRFPC 522 subsystem identifies a type of customer included with an application resolution request received. In another modality, the MRFPC subsystem applies a policy to the client type and determines the continuous transmission of the application to the local machine 10. In this modality, the MRFPC 522 subsystem can forward the application resolution request to a management subsystem application code 506. In one embodiment, upon receipt of the application resolution request from the MRFPC 522 subsystem, the application management subsystem 506 can identify a remote machine 30 ”” functioning as a session management server 562 for the local machine 10 In some embodiments, the local machine transmits a heartbeat message to the session management server 562. In another embodiment, the application management subsystem 506 can identify a remote machine 30 'hosting a plurality of application files comprising the application to be transmitted continuously to the local machine 10.
In some embodiments, the application management subsystem 506 uses a file enumerating a plurality of remote machines hosting the plurality of application files for identification of the remote machine 30 '. In other embodiments, the application management subsystem 506 identifies a remote machine 30 'having an IP address similar to an IP address of the local machine 10. In still other embodiments, the application management subsystem 506 identifies a remote machine 30 'having an IP address in a range of IP addresses accessible to the local machine 10.
In yet another modality, the MRFPC 522 subsystem applies a policy to the client type and determines that the application can run on a remote machine 30 ', the remote machine 30' transmitting application output data generated by an application run to the local machine 10. In this modality, the MRFPC subsystem 522 can forward the application resolution request to a common application subsystem 524 for retrieving a host address identifier for a remote 30 'machine. In one embodiment, the identified remote machine 30 'can transmit the application output data to the local machine using a presentation level protocol, such as ICA or RDP or X Windows. In some embodiments, remote machine 30 'receives the application from a second remote machine 30' through an application streaming session.
In one embodiment, upon completion of enumerated application enumeration and application resolution, access information is transmitted to local machine 10 which includes an identification of a method of execution for an enumerated application and an identifier of a remote machine 30 ' hosting the enumerated application. In a mode where the 504 management service determines that the listed application will run on the local machine 10, a web interface creates and
<img file="BRPI0709986A2_D0002.tif" />
transmits to the local machine 10 a file containing name information and a file containing resolved name information about the listed application. In some embodiments, the file can be identified using a .rad extension. Local machine 10 can run the enumerated application in response to the content of the received file. Table 2 describes a modality of information contained in the file:
<td colspan="2">Field</td><td rowspan="2">description Points for a manifest file</td><td rowspan="2">Source</td>
<td></td><td>UNC path</td>
<td> 20</td><td></td><td>container master on the file server.</td><td>XML service</td>
<td></td><td>Initial program</td><td>Program for opening from the container.</td><td>XML service</td>
<td></td><td>Command Line</td><td>For opening documents using FTA.</td><td>XML service</td>
<td></td><td>Web server URL</td><td>For client messages from RADE to Wl.</td><td>Wl config</td>
<td></td><td>Bank id</td><td>The bank to which the application belongs - required</td><td></td>
<td> 25</td><td></td><td>for heartbeat messages.</td><td>Wl config</td>
<td></td><td>Opening ticket</td><td>The application streaming client</td><td></td>
<td></td><td></td><td>uses the opening ticket to purchase a ticket</td><td></td>
<td></td><td></td><td>execution of program license authorization.</td><td>XML / IMA</td>
<td></td><td>Opening information</td><td>ICA file inserted for fallback, if</td><td></td>
<td> 30</td><td>fallback from ICA</td><td>to be allowed a fallback.</td><td>XML service</td>
<td></td><td>Table 2</td><td></td><td></td>
The file can also contain an opening ticket for use by the local machine when running the application, as shown in Table 2. In some embodiments, the opening ticket expires after a predetermined period of time. In one embodiment, the local machine provides the opening ticket to a remote machine hosting the enumerated application to be run. The use of the opening ticket to authorize access to the application listed by a user of the local machine helps prevent the user from reusing the file or generating an unauthorized version of the file to improperly access applications. In one embodiment, the opening ticket comprises a large, randomly generated number.
As described above in relation to figure 2, a method for selecting an application program execution method begins when credentials associated with local machine 10 or a user of local machine 10 are received (step 202) and an enumeration of a plurality application programs available to the local machine is provided in response to the credentials received (step 204). A request is received to run the enumerated application (step 206) and one of a predetermined number of methods for running the enumerated application is selected, in response to a policy, the predetermined number of methods including a method for streaming the application from the application enumerated (step 208).
Referring now to figure 7, a flowchart describes a modality of the steps followed to access a plurality of files comprising an application program. A local machine performs a pre-opening analysis of the local machine (step 210). In one embodiment, the local machine 10 performs a pre-opening analysis of the local machine (step 210). In one embodiment, the local machine 10 performs a pre-opening analysis before retrieving and executing a plurality of application files comprising an application program. In another embodiment, the local machine 10 performs a pre-opening analysis in response to an indication received that the pre-opening analysis is a requirement for authorization to access the plurality of application files comprising an application program.
In some embodiments, the local machine 10 receives, from a remote machine 30, access information associated with the plurality of application files. In one of these embodiments, the access information includes an identification of a location of a remote machine 30 'hosting the plurality of application files. In another of these embodiments, the local machine 10 receives an identification from a plurality of applications comprising one or more versions of the application program. In yet another of these modalities, the local machine 10 receives an identification from a plurality of application files comprising one or more application programs. In other embodiments, local machine 10 receives an enumeration of application programs available to local machine 10 for retrieval and execution. In one of these modalities, the enumeration results from an evaluation of the local machine 10. In still other embodiments, the local machine 10 retrieves at least one feature in response to the retrieved identification of the plurality of application files comprising an application program.
In some embodiments, the access information includes an opening ticket capable of authorizing the local machine to access the plurality of application files. In one of these modalities, the opening ticket is provided for the local machine 10 in response to an evaluation of the local machine 10. In another of these modalities, the opening ticket is provided for the local machine 10 subsequently to a pre-opening analysis of the machine. local machine 10 by local machine 10.
In other embodiments, the local machine 10 retrieves at least one characteristic required to execute the plurality of application files. In one of these modalities, the access information includes at least one feature. In another of these modalities, the access information includes a location of a file for retrieval by the local machine 10, the file listing at least one feature. In yet another of these modalities, the file listing at least one feature still comprises an enumeration of the plurality of application files and the identification of a remote machine 30 hosting the plurality of application files.
Local machine 10 determines that there is at least one characteristic on the local machine. In one embodiment, the local machine 10 makes this determination as part of the pre-opening analysis. In another embodiment, local machine 10 determines whether local machine 10 has at least one feature.
In one embodiment, determining the existence of at least one feature on the local machine 10 includes determining whether a device driver is installed on the local machine. In another embodiment, determining the existence of at least one feature on the local machine 10 includes determining whether an operating system is installed on the local machine 10. In yet another embodiment, determining the existence of at least one feature on the local machine 10 includes determining whether a particular revision level for an operating system is installed on the local machine 10.
In some embodiments, determining the existence of at least one feature on the local machine 10 includes determining whether the local machine 10 has acquired an authorization to run an enumerated application. In one of these modalities, a determination is made by the local machine 10 as to whether the local machine 10 has received a license to run the listed application. In another of these modalities, a determination is made by the local machine 10 as to whether the local machine 10 has received a license to receive through a session of streaming an application a plurality of application files comprising the listed application. In other embodiments, determining the existence of at least one feature on the local machine 10 includes determining whether the local machine 10 has sufficient bandwidth available to retrieve and run an enumerated application.
In some modalities, determining the existence of at least one feature on the local machine 10 includes running a script on the local machine 10. In other modalities, determining the existence of at least one feature on the local machine 10 includes installing a software on the local machine 10. Still in other modalities, determining the existence of at least one feature on the local machine 10 includes modifying a record on the local machine 10. In still other embodiments, determining the existence of at least one feature on the local machine 10 includes the transmission of a collection agent 404 to the local machine 10 for execution on the local machine 10 to accumulate credentials associated with the local machine 10.
The local machine 10 requests from a remote machine 30 an authorization to execute the plurality of application files, the request including an opening ticket (step 212). In some embodiments, the local machine 10 makes the request in response to a determination that at least one feature exists on the local machine 10. In another of these modalities, the local machine 10 determines that the plurality of characteristics exist on the local machine 10, the plurality of characteristics associated with an enumerated application and a response received to a request for execution of the enumerated application. In another of these modalities, if the local machine 10 receives an indication that the authorization to execute the listed application files depends on the existence of at least one characteristic on the local machine 10. In one embodiment, the local machine 10 received an enumeration of application programs, requested an execution of an enumerated application and received an access information including at least one feature and an opening ticket authorizing the execution of the enumerated application when determining the existence of at least one feature on the local machine 10.
In one embodiment, the local machine 10 receives from the remote machine 30 a license authorizing an execution of the plurality of application files. In some embodiments, the license authorizes an execution for a specified period of time. In one of these modalities, the license requires the transmission of a heartbeat message to maintain authorization to execute the plurality of application files.
In another embodiment, the local machine 10 receives from the remote machine 30 the license and an identifier associated with a remote machine 30 monitoring the execution of the plurality of application files. In some embodiments, the remote machine is a session management server 562, as described in figure 5. In one of these modalities, the session management server 562 includes a session management subsystem 510 that monitors the session associated with the local machine 10. In other embodiments, a separate 30 ”remote machine is the 562 session management server.
Local machine 10 receives and executes the plurality of application files (step 214). In one embodiment, the local machine 10 receives the plurality of application files through an application streaming session. In another embodiment, the local machine 10 stores the plurality of application files in an isolation environment on the local machine 10. In yet another embodiment, the local machine 10 executes one of the plurality of application files before receiving a second of the plurality of application files. In some embodiments, a remote machine transmits the plurality of application files to a plurality of local machines, each local machine in the plurality having established a separate application streaming session with the remote machine.
In some embodiments, the local machine 10 stores the plurality of application files in a cache and delays the execution of the application files. In one of these modalities, the local machine 10 receives an authorization to execute the application files for a predefined period of time. In another of these modalities, the local machine 10 receives an authorization to execute the application files during the predefined period of time, when the local machine 10 lacks access to a network. In other embodiments, the local machine stores the plurality of application files in a cache. In one of these modalities, the application streaming client 552 establishes an internal application streaming session to retrieve the plurality of application files from the cache. In another of these modalities, the local machine 10 receives an authorization to execute the application files for a predefined period of time when the local machine 10 lacks access to a network.
Local machine 10 transmits at least one heartbeat message to a remote machine (step 216). In some embodiments, the local machine 10 transmits at least one heartbeat message to retain an authorization to execute the plurality of application files comprising the listed application. In other embodiments, the local machine 10 transmits at least one heartbeat message to retain an authorization for retrieving an application file in the plurality of application files. In still other modalities, the local machine 10 receives a license authorizing the execution of the plurality of application files during the predetermined period of time.
In some modalities, the local machine 10 transmits the heartbeat message to a second remote machine 30 ””. In one of these modalities, the second remote 30 ”machine can comprise a 562 session management server monitoring the recovery and execution of the plurality of application files. In another of these modalities, the second remote machine 30 ”” can renew a license authorizing an execution of the plurality of application files, in response to the transmitted heartbeat message. In yet another of these modalities, the second remote machine 30 ”” can transmit a command to the local machine 10 in response to the transmitted heartbeat message.
Referring back to Figure 5, the local machine 10 can include an application streaming client 552, a streaming service 554 and an isolation environment 556. The application streaming client 552 can be an executable program. In some embodiments, the 552 application streaming client may be able to open another executable program. In other modalities, the application streaming client 552 can start the streaming service 554. In one of these modalities, the application streaming client 552 can provide the streaming service 554 with a parameter associated with the execution of a application program. In another of these modalities, the broadcast client5 of application 552 can start streaming service 554 using a remote procedure call.
In another embodiment, the local machine 10 requests an execution of an application program and receives access information from a remote machine 30 with reference to an execution. In another mode, the application streaming client 552 receives access information. In yet another modality, the application streaming client 552 provides access information to the streaming service 554. In yet another embodiment, the access information includes an identification of a file location associated with a plurality of application files comprising the application program.
In one embodiment, the streaming service 554 retrieves a file associated with a plurality of application files. In some embodiments, the recovered file includes an identification of a location of the plurality of application files. In one of these modalities, the streaming service 554 recovers the plurality of application files. In another of these modalities, the streaming service 554 performs the recovered plurality of application files on the local machine 10. In other modalities, the streaming service 25 transmits the heartbeat messages to a remote machine to maintain authorization for. recovery and execution of the plurality of application files.
In some embodiments, the recovered file includes an identification of the location of more than a plurality of application files, each plurality of application files comprising a different application program. In one of these modalities, the streaming service 554 recovers the plurality of application files including the application program compatible with the local machine 10. In another of these modalities, the streaming service 554 receives an authorization to recover a particular plurality of application files, in response to an evaluation by the local machine 10.
In some embodiments, the plurality of application files is compressed and stored on a file server in a backup storage file, such as CAB, ZIP, SIT, TAR, JAR or other backup storage file. In one embodiment, a plurality of application files stored in a backup storage file comprises an application program. In another embodiment, multiple pluralities of application files stored in a backup storage file each comprise different versions of an application program. In yet another mode, multiple plurality of application files stored in a backup storage file each comprise different application programs. In some embodiments, a backup storage file includes metadata associated with each file in the plurality of application files. In one of these modalities, the streaming service 554 generates a directory structure in response to the included metadata. As will be described in more detail in relation to figure 12 below, metadata can be used to satisfy requests for application programs for directory enumeration.
In one embodiment, the streaming service 554 decompresses a backup storage file to acquire the plurality of application files. In another embodiment, streaming service 554 determines whether a local copy of a file in the plurality of application files exists in a cache on the local machine 10, before retrieving the file from the plurality of application files. In yet another embodiment, the 564 file system filter driver determines whether the local copy exists in the cache. In some embodiments, the streaming service 554 modifies a registry entry before retrieving a file in the plurality of application files.
In some modalities, the continuous transmission service
554 stores a plurality of application files in a cache on the local machine 10. In one of these modalities, the streaming service 554 can provide a functionality for caching 5 a plurality of application files, upon receipt of a request to store in cache the plurality of application files.
In another of these modalities, the streaming service 554 can provide functionality to ensure a cache on the local machine 10. In another of these modalities, the streaming service 10 554 can use a longitudinal to adjust a size and location. from the cache.
v In some modalities, the continuous transmission service
554 creates an isolation environment 556 on the local machine 10. In one of these modalities, the streaming service 554 uses an isolation environment application programming interface 15 to create the isolation environment 556. In another of these modalities, the streaming service 554 stores the plurality of application files in the 556 isolation environment. In yet another of these modalities, the streaming service 554 executes a file in the plurality of 20 application files in the isolation environment. In yet another of these modalities, the streaming service 554 executes the application program in the isolation environment.
For modalities in which authorization is received to run an application on the local machine 10, the application can run 25 in an isolation environment 556. In some embodiments, a plurality of application files comprising the application is stored on the local machine 10 , before the application runs. In other embodiments, a subset of the plurality of application files is stored on the local machine 10, before the application runs. In still other modes, the plurality of application files does not reside in the 556 isolation environment. In other modalities, a subset of the plurality of application files does not reside on the local machine 10. Regardless of a subset of the plurality of application files or each application file in the plurality of application files reside on the local machine 10 or in an isolation environment 556, in some embodiments, an application file in the plurality of application files can be run in an environment insulation 556.
The 556 isolation environment can consist of a core system capable of providing a File System Virtualization, a Registry System Virtualization and a Named Object Virtualization to reduce application compatibility issues, without requiring any source code changes application. The 556 isolation environment can redirect application resource requests using hooking in user mode for registration and in named object virtualization, and in the kernel using a file system filter driver for file system virtualization. What follows is a description of some modalities of a 556 isolation environment.
Referring now to Figure 8A, a mode of a computer running under the control of an operating system 100 that has reduced application compatibility and application sociability issues is shown. Operating system 100 makes several native resources available for application programs 112, 114 through its system layer 108. The view of resources realized by system layer 108 will be called the scope of the system. In order to avoid conflicting access to native resources 102, 104, 106, 107 by application programs 112, 114, an isolation environment 200 is provided. As shown in figure 8A, the isolation environment 200 includes an application isolation layer 220 and a user isolation layer 240. Conceptually, isolation environment 200 provides, through application isolation layer 220, an application program 112, 114 with a unique view of native resources, such as file system 102, registry 104, objects 106 and window names 107. Each isolation layer modifies the view of native resources provided for an application. The modified view of native resources provided by a layer will be referred to as the layer insulation sheet. As shown in Figure 8A, the application isolation layer includes two application isolation scopes 222, 224. Scope 222 represents the view of native resources provided for application 112 and scope 224 represents the view of native resources provided for the application. application 114. Thus, in the modality shown in figure 8A, ο APP1 112 is provided with a specific view of file system 102 ', while ο APP2 114 is provided with another view of file system 102 ”, which is specific to it. In some embodiments, application isolation layer 220 provides a specific view of native resources 102, 104, 106, 107 for each individual application program running on top of operating system 100. In other embodiments, application programs 112, 114 can be grouped into sets, and in these modalities, application isolation layer 220 provides a specific view of native resources for each set of application programs. Conflicting application programs can be placed in separate groups to improve application compatibility and sociability. In other modalities, applications belonging to a set can be configured by an administrator. In some embodiments, a scope of passage insertion can be defined, which corresponds exactly to the scope of the system. In other words, running applications and a passthrough isolation scope operate directly at the scope of the system.
In some embodiments, the application isolation scope is further divided into layered subscopes. The main subscope contains the base opening isolation scope and the additional subscopes contain several modifications to this scope that may be visible to multiple instances running the application. For example, a sub-scope may contain changes to the scope that bring about a change in the parameter's patch level or the installation or removal of additional features. In some embodiments, the set of additional subscopes that is made visible to a running application instance is configurable. In some embodiments, that set of visible sub-spaces is the same for all instances of the application running, regardless of the user on whose behalf the application is running. In others, the set of visible subscopes may vary for different users running the application. In yet other modalities, several sets of subscopes can be defined and the user can have a choice as to which set to use. In some modalities, subscopes can be discarded when they are no longer needed. In some modalities, the modifications contained in a set of subscopes can be merged together to form a single subscope.
Referring now to Figure 8B, a multiple-user computer, having reduced application compatibility and application sociability problems, is described. The multi-user computer includes native resources 102, 104, 106, 107 in system layer 108, as well as the isolation environment 200 discussed immediately above. The application isolation layer 220 works as discussed above, providing an application or group of applications with a modified view of native features. The user isolation layer 240 conceptually provides an application program 112, 114 with a view of native resources that is further altered based on a user identity of the user on whose behalf the application is run. As shown in figure 8B, user insulation layer 240 can be considered to comprise various isolation scopes 242 ', 242 ”, 242'”, 242 ””, 242 '””, 242 ...... (generally 242). A 242 user isolation scope provides a user-specific view of application-specific views of native resources. For example, ο APP1 112 running in a user session 110 on behalf of user a is provided with a file system view 1O2 '(a) which is altered or modified by user isolation scope 242' and the scope of application isolation 222.
In other words, the user isolation layer 240 changes the view of native resources for each individual user by layering a specific user view modification by a user isolation scope 242 'at the top of a user modification. application-specific view provided by an application isolation scope 222, which in turn is layered on top of the pan-systemic view of native resources provided by the system layer. For example, when the first instance of APP1 112 accesses an entry in the registration database 104, the view of the registration database specific to the first user session and the application 1O4 '(a) is consulted. If a requested registry key is found in the specific user view of registry 1O4 '(a), that registry key will be returned to APP1 112. If not, the application-specific registry database view 104' is consulted. If the requested registry key is found in the application-specific view of registry 104 ', that registry key will be returned to ο APP1 112. If not, then the registry key stored in registry database 104 at the system layer 108 (that is, the native registration key) is returned to ο APP1 112.
In some embodiments, user insulation layer 240 provides an isolation scope for each individual user. In other embodiments, the user isolation layer 240 provides an isolation scope for a group of users, which can be defined by roles in the organization or can be predetermined by an administrator. In yet other embodiments, no user insulation layer 240 is provided. In these modalities, the view of native resources seen by an application program is that provided by application isolation layer 220. The isolation environment 200, although described in relation to multiple user computers supporting concurrent execution of application programs by multiple users, can also be used on single user computers to address application compatibility and sociability issues resulting from a run sequential application programs on the same computer system by different users, and those problems resulting from the installation and execution of incompatible programs by the same user.
In some embodiments, the scope of user isolation is further divided into subscopes. Modifications by the user isolation scope for the view presented for an application running in that scope is the aggregate of the modifications contained in each sub-scope in the scope. The subscopes are layered on top of each other, and in the aggregate view, changes to a resource in a higher subscope suppress changes to the same resource in lower layers.
In some of these modalities, one or more of these subscopes may contain changes to the view that are specific to the user in some of these modalities, one or more subscopes may contain changes to the view that are specific to sets of users, which can be defined by system administrators or defined as a user group on the operating system. In some of these modalities, one of these subscopes may contain changes to the view that are specific to the particular login session and, therefore, are discarded when the session ends. In some of these modalities, changes in native resources by application instances associated with the scope of user isolation always affect one of these subscopes, and in the other changes those modalities can affect different subscopes, depending on the particular resource changed.
The conceptual architecture described above allows an application running on behalf of a user to be presented with an aggregated or unified virtualized view of native features, specific to that combination of application and user. This aggregate view can be referred to as virtual scope. The application instance running on behalf of a user is presented with a simple view of native resources reflecting all operating virtualized instances of the native resources. Conceptually, this aggregate view consists primarily of the set of native resources provided by the operating system in the scope of the system, overlaid with the changes made in the scope of application isolation applicable to the parameter being executed, still overlapped with the changes made in the scope of user isolation applicable to the application running on behalf of the user. Native resources in the system scope are characterized by being common to all users and applications on the system, except where operating system permissions deny access to specific users or applications. Modifications to the resource view made in an application isolation scope are characterized as being common to all application instances associated with that application isolation scope. Modifications to the resource view made in the user isolation scope are characterized as being common to all applications associated with the applicable application isolation scope that are running on behalf of the user associated with the user isolation scope.
This concept can be extended to subscopes; modifications to the resource view made in a user subscope are common to all applications associated with the applicable isolation subscope running on behalf of a user, or a group of users, associated with a user isolation subscope. Throughout this description, it should be understood that whenever a general reference is made to the scope, it is intended to also refer to subscopes, when those exist.
When an application requests an enumeration of a native resource, such as a portion of the file system or registration database, a virtualized enumeration is constructed first by enumerating the system scope instance of the native resource, that is, the instance found at the system layer, if any. Then, the application scope instance of the requested resource, that is, the instance found in the appropriate application isolation scope, if any, is enumerated. Any enumerated features found in the application isolation scope are added to the view. If the enumerated resource already exists in the view (because it was presented in the scope of the system as well), it will be replaced by the resource instance found in the application isolation scope. Similarly, the user scope instance of the requested resource, that is, the instance found in the appropriate user isolation scope, if any, is enumerated. Again, any enumerated features found in the scope of user isolation are added to the view. If the native resource already exists in the view (because it was presented in the system scope or the appropriate application isolation scope), it will be replaced with the resource instance found in the user isolation table. In this way, any enumeration of native resources will appropriately reflect a view of the enumerated native resources. Conceptually, the same approach applies to an isolation scope enumeration that comprises multiple subscopes. The individual subscopes are enumerated, with features from the highest sub10 scopes replacing instances of combining the lowest subscopes in the aggregate view.
In other embodiments, an enumeration can be performed from the user isolation scope layer down to the system layer, rather than the reverse. In these modalities, the scope of user isolation is listed. Then, the application isolation scope is enumerated in any resource instances appearing in the application isolation scope that were not enumerated in the user isolation scope are added to the aggregate view that is under construction. A similar process can be repeated for resources appearing only at the system scope.
In yet other modalities, all isolation scopes can be simultaneously enumerated and the respective enumerations combined.
If an application attempts to open an existing instance of a native resource with no intention of modifying that resource, the specific instance that is returned to the application is one that is found in the virtual scope, or, equivalently, the instance that would appear in the virtualized enumeration of the origin of the requested resource. From the standpoint of the isolation environment, the application is said to be requesting the coverage of a virtual resource, and the particular instance of native resource used to satisfy that request is said to be the literal resource corresponding to the requested resource.
If an application running on behalf of a user attempts to open a resource and indicates that it is doing so with the intention of modifying that resource, that application instance is normally given a private copy of that resource for modification, since the resources are in scope application isolation and system scope are common to applications running on behalf of other users. Typically, a user-scoped copy of the resource is made, unless the user-scoped instance already exists. Defining the aggregate view provided by a virtual scope means that the act of copying an application scope or system scope resource to a user isolation scope does not change the aggregate view provided by the virtual scope for the user and the application in question. question, nor to any other user, nor to any other application instance. Subsequent modifications to the resource copied by the application instance running on behalf of the user do not affect the aggregate view of any application instance that does not share the same scope for user isolation. In other words, those modifications do not change the aggregate view of native resources for other users, or for application instances not associated with the same application isolation scope.
Applications can be installed in a particular isolation scope (described in more detail below). Applications that are installed in an isolation scope are always associated with that scope. Alternatively, applications can be opened in a particular isolation scope or in multiple isolation scopes. In effect, an application is opened and associated with one or more isolation scopes. The associated isolation scope or scopes provide access with a particular view of native resources. Applications can also be opened at the scope of the system, that is, they can be associated with no isolation scope. This allows for selective execution of operating system applications, such as Internet Explorer, as well as third-party applications, in an isolated environment.
This ability to open applications in an isolation scope regardless of where the application is installed mitigates application compatibility and sociability issues, without requiring a separate installation of the parameter in the isolation scope. The ability to selectively open applications installed in different isolation scopes 5 provides the ability to have applications which need help applications (such as Word, Notepad, etc.) having those help applications open with the same rule sets.
In addition, the ability to open an application in multiple isolated environments allows for better integration between isolated applications and 10 common applications.
Referring now to Figure 8C, and in a brief overview, a method for associating a process with an isolation scope includes the steps of opening the process in a suspended state (step 882). The rules associated with the desired isolation scope are retrieved15 (step 884) and an identifier for the process and the retrieved rules are stored in a memory element (step 886) and the suspended process is resumed (step 888). Subsequent calls to access native resources made by the process are intercepted or hooked (step 890) and the rules associated with the process identifier, 20 if any, are used to virtualize access to the requested resource (step 892).
Still referring to figure 8C, and in more detail, a process is opened in a suspended state (step 882). In some embodiments, a personalized opening program is used to perform this task. In some of these modalities, the opening program is specifically designed to open a process in a selected isolation scope. In other modalities, the opening program accepts a specification of the desired isolation scope as an input, for example, by a command line option.
The rules associated with the desired isolation scope are retrieved (step 884). In some embodiments, the rules are retrieved from a persistent storage element, such as a hard disk drive or another solid state memory element. Rules can be stored as a relational database, a flat file database, a structured tree database, a binary tree structure, or other persistent data structure. In other modalities, the rules can be stored in a data structure specifically configured to store them.
An identifier for the process, such as a process ID (PID) and the retrieved rules are stored in a memory element (step 886). In some embodiments, a kernel-mode driver is provided, which receives messages from the operating system regarding the new process creation. In these modalities, the PID and the retrieved rules can be stored in the context of the driver. In other embodiments, a file system filter driver or mini filter is provided, which intercepts native resource requests. In these modalities, the PID and the retrieved rules 15 can be stored in the filter. In yet other modalities, all interception is performed by hooking the user mode and no PID is stored in any way. The rules are loaded by the user mode hooking device during the process initialization, and no other component needs to know the rules 20 that apply to the PID, because a rule association is performed entirely in the process.
The suspended process is resumed (step 888) and subsequent calls to access native resources made by the process are intercepted or hooked (step 890) and the rules associated with the process identifier, if any, are used to virtualize access to the resource requested (step 892). In some embodiments, a file system filter driver or a minifilter or file system driver intercepts requests for access to native resources and determines whether the process identifier associated with the intercepted request has been associated with a set of rules. If so, the rules associated with the stored process identifier are used to virtualize the request for access to native resources. If not, the request for access to native resources is passed on unmodified. In other modalities, a dynamically linked library is loaded in the newly created process and the library carries the rules of isolation. In yet other modalities, kernel mode techniques (hooking, filter driver, minifilter) and user mode techniques are used for intercepting calls to access native resources. For modalities in which a file system filter driver stores the rules, the library can load the rules from the file system filter driver.
Processes that are children of processes associated with isolation schools are associated with the isolation scopes of their parent process. In some embodiments, this is accomplished by a kernel-mode driver notifying the file system filter driver that a child process is created. In these modalities, the file system filter driver determines whether the process identifier of the parent process is associated with an isolation scope. If so, the file system filter driver stores an association between the process identifier for the newly created child process and the isolation scope of the parent process. In other embodiments, the file system filter driver can be called directly from the system, without using a ker20 nel mode driver. In other modalities, in the processes that are associated with isolation scopes, the operating system functions that create new processes are hooked or intercepted. When a request to create a new process is received from a process like this, the association between the new child process and the parent's syntactic foams is maintained.
In some embodiments, a scope or sub-scope can be associated with an individual line, rather than an entire process, allowing isolation to be carried out on a per-line basis. In other modalities, one insulation per line can be used for Services and served30 res COM +.
In some embodiments, isolation environments are used to provide additional functionality to the 552 application streaming client. In one of these embodiments, an application program runs in an isolation environment. In another of these modalities, a recovered plurality of application files resides in the isolation environment. In yet another of these modalities, changes to a register on the local machine 10 are made within the isolation environment.
In one embodiment, the application streaming client 552 includes an isolation environment 556. In some embodiments, the application streaming client 552 includes a file system filter driver 564 that intercepts application requests for files. In one of these modalities, the 564 file system filter driver intercepts an application request to open an existing file and determines that the file does not reside in the 556 isolation environment. In another of these modalities, the system filter driver file 564 redirects the chemical reaction to the 554 streaming service in response to a determination that the file does not reside in the 556 isolation environment. The streaming service 554 can extract the file from the plurality of application files and store the file in the 556 isolation environment. The 564 file system filter driver can then respond to the request for the credential with the stored copy of the credential. . In some embodiments, the 564 file system filter driver may redirect the request for the file to a 540 file server, in response to an indication that the streaming service 554 has not retrieved the file or the plurality of application files and a determination that the file does not reside in the 556 isolation environment. In some embodiments, the streaming service 554 may include / comprise a 6120 acceleration program for performing some or all of the acceleration techniques discussed below for accelerating the storage or delivery of files and applications.
In some embodiments, the 564 file system filter driver uses a strict isolation rule to prevent a conflict or inconsistent data from appearing in the 556 isolation environment. In one of these modalities, the 564 file system filter driver intercepts a requesting a resource in an isolation environment can redirect the request to an application isolation environment. In another of these modalities, the 564 file system filter driver does not redirect the request to a system scope.
In one embodiment, the streaming service 554 uses IOCTL commands to communicate with the filter driver. In another mode, communications to the 540 file server are received 10 by the Microsoft SMB streaming protocol.
In some embodiments, the 530 package engine stores in a manifest file a list of file types published as available applications and makes this information available to application publishing software. In one of these modalities, the mechanis, 15 m of package 530 receives this information from the monitoring of an installation of an application program in the isolation environment on the stage machine. In another of these modalities, a user of the 530 packet mechanism provides this information for the 530 packet mechanism. In other modalities, the application publishing software in the access suite 20 console 520 queries the manifest file to present to a 520 access suite console user the possible file types that can be associated with the requested application being published. The user selects a file type to associate with a particular published application. The file type is presented to local machine 10 at the time of application enumeration.
Local machine 10 may include a client agent 560. Client agent 560 provides functionality for associating a file type with an application program and selecting a method for executing the application program in response to the association. In one embodiment, the client agent 560 is a program neighborhood application.
When an application program is selected to run, the local machine 10 makes a determination as to an execution method associated with an application program file type. In one embodiment, the local machine 10 determines that the file type is associated with an execution method requiring an application streaming session to retrieve application files and run in an isolation environment. In this environment, local machine 10 can redirect the request to the 552 application streaming client instead of opening a local version of the application program. In another mode, the customer agent 560 makes the determination. In yet another modality, client agent 560 redirects the request to client 10 for application streaming 552.
In one embodiment, the application streaming client 552 requests access information associated with the application program from the remote machine 30. In some embodiments, the application streaming client 552 receives an executable program containing the access information . In one of these modalities, the 552 application streaming client receives an executable program capable of displaying on the local machine 10 application output data generated from an application program execution on a remote machine. In another of these modalities, the application 552 streaming client receives an executable program capable of retrieving the application program through an application streaming session and running the application program in an isolated environment on the local machine 10. In this mode, the 552 application streaming client can run the received executable program. In yet another of these modalities, remote machine 30 selects an executable program for provisioning to local machine 10 in response to carrying out an application resolution, as described above.
Referring now to Figure 9, a flowchart describes a modality of steps followed in a method for executing an application. As described above in figure 7, with reference to step 214, a local machine 10 receives and executes the plurality of application files. In a brief overview, local machine 10 receives a file that includes a \
\ '
V /
access information for accessing a plurality of application files and for executing a first client capable of receiving a continuous application transmission (step 902). Local machine 10 retrieves an identification from the plurality of application files in response to the file (step 5 904). Local machine 10 retrieves at least one characteristic required to execute the plurality of application files, in response to the file (step 906). Local machine 10 determines whether local machine 10 includes at least one feature (step 908). Local machine 10 executes a second client, the second client requesting an execution of the plurality10 of application files on a remote machine, in response to a determination that local machine 10 lacks at least one feature (step 910).
Referring to figure 9, and in greater detail, the local machine 10 receives a file that includes access information for accessing a plurality of application files and for executing a first client capable of receiving a continuous application transmission (step 902). In one embodiment, the local machine 10 receives an access information that includes an identification of a location from a plurality of application files comprising an application program. In another mode, local machine 10 receives the file in response to a request to execute the application program. In yet another embodiment, the access information includes an indication that the plurality of application files reside on a remote machine 30 ', such as an application server or a file server. In yet another embodiment, the access information 25 indicates that the local machine 10 can retrieve the plurality of application files from the remote machine 30 through an application streaming session.
Local machine 10 retrieves an identification of the plurality of application files in response to the file (step 904). In a modality, local machine 10 identifies a remote machine on which the plurality of application files reside, in response to the file including access information. In another embodiment, the local machine 10 retrieves from the remote machine 30 a file identifying the plurality of application files. In some embodiments, the plurality of application files comprises an application program. In other embodiments, the plurality of application files comprises multiple application programs. In yet other modalities, the plurality of application files comprises multiple versions of a single application program.
Referring to figure 10 ahead, a flowchart describes an embodiment of a plurality of application files residing on a remote machine 30 ', such as the file server 540. In figure 10, 10 a plurality of application files, referred to as a package , includes application files comprising three different versions of one or more \ application programs.
\ In one embodiment, each subset of application files comprising a version of one or more application programs and weapon<sup>x</sup> 15 zen in the pack is referred to as a target. Target 1, for example, includes a version of a word processing application program and spreadsheet program, the version compatible with the English version of the Microsoft Windows 2000 operating system. Target 2 includes a version of a program word processing application and a 20 spreadsheet program, the version compatible with the English language version of the Microsoft XP operating system. Target 3 is a version of a word processing application program and spreadsheet program, the version compatible with the Japanese language version of the Microsoft Windows 2000 operating system with Service Pack 3.
Now returning to figure 9, in some embodiments, the file retrieved from the remote machine 30 hosting the plurality of application files includes a description of the package and the targets included in the plurality of application files. In other embodiments, the file retrieved from the remote machine 30 identifies the plurality of application files comprising an application program requested for execution by the local machine 10.
Local machine 10 retrieves at least one feature required for executing the plurality of application files in response to the file (step 906). In some embodiments, the local machine 10 may not run an application program unless the local machine includes certain characteristics. In one of these embodiments, different application programs 5 require that local machines 10 include characteristics different from those required by other application programs. In another of these modalities, the local machine 10 receives an identification of at least one characteristic required to execute the plurality of application files comprising the requested application program 10 by the local machine 10.
The local machine determines whether the local machine 10 includes at least one feature (step 908). In one embodiment, local machine 10 evaluates an operating system of local machine 10 to determine whether local machine 10 includes at least one feature. In another fashion15, local machine 10 identifies a language used by an operating system on local machine 10 to determine whether local machine 10 includes at least one feature. In yet another embodiment, local machine 10 identifies a revision level of an operating system on local machine 10 to determine whether local machine 10 includes at least 20 a feature. In yet another embodiment, local machine 10 identifies an application version of an application program residing on local machine 10, to determine whether local machine 10 includes at least one feature. In some embodiments, local machine 10 determines whether local machine 10 includes a device driver to determine whether local machine 10 includes at least one feature. In other embodiments, local machine 10 determines whether local machine 10 includes an operating system for determining whether local machine 10 includes at least one feature. In still other embodiments, the local machine 10 determines whether the local machine 10 includes a license to run the plurality of 30 application files to determine whether the local machine 10 includes at least one feature.
Local machine 10 runs a second client, the second client
100 ent requesting the execution of the plurality of application files on a remote machine 30, in response to a determination that the local machine 10 lacks at least one feature (step 910). In one embodiment, when the local machine 10 determines that the local machine 10 lacks at least one feature, the local machine 10 does not run the first client capable of receiving an application continuous stream. In another embodiment, a policy prohibits the local machine 10 from receiving the plurality of application files over a continuous application stream, when the local machine 10 lacks at least one feature. In some embodiments, the local machine 10 determines that the local machine 10 does not include at least one feature. In one of these embodiments, the local machine 10 runs the first client, the first client receiving a continuous application stream comprising the plurality of application files from a remote machine 30 to run on the local machine.
In some embodiments, the local machine 10 executes the second client requesting an execution of the plurality of application files on a remote machine when it determines that the local machine 10 lacks at least one feature. In one of these modalities, the second client transmits the request to a remote machine 30 hosting the plurality of application files. In another of these modalities, the remote machine 30 executes the plurality of application files comprising the application program and generates application output data. In yet another of these modalities, the second client receives application output data generated by executing the plurality of application files on the remote machine. In some embodiments, the second client receives application output data via an Independent Computing Architecture presentation level protocol or a Windows Remote Desktop presentation level protocol or an X presentation level protocol -Windows. In yet another of these modalities, the second client displays the application output on the local machine 10.
In some modalities, the second customer transmits the requisition
101 a remote machine 30 that does not host the plurality of application files. In one of these embodiments, the remote machine 30 can request the plurality of application files from a second remote machine 30 hosting the plurality of application files. In another of these embodiments, the remote machine 30 can receive the plurality of application files from the second remote machine 30 through an application streaming session. In yet another of these modalities, the remote machine 30 stores the received plurality of application files in an isolation environment and executes the application program in the isolation environment. In yet another of these modalities, the remote machine transmits the generated application output data to the second client on the local machine.
Referring back to Figure 5, in one embodiment, the first client, capable of receiving application streaming, is a 552 application streaming client. The application streaming client 552 receives the file, retrieves an identification from a plurality of application files and at least one characteristic required to execute the plurality of application files in response to the file and determines whether local machine 10 includes at least one feature. In another embodiment, the second customer is a 560 customer agent. In some embodiments, the client agent 560 receives the file from the application streaming client 552 in response to a determination by the application streaming client 552 that the local machine 10 lacks at least one feature.
In some embodiments, the 566 application running on the local machine 10 lists the files associated with the 566 application using the Win32 FindFirstFile () and FindNextFile () API calls. In one of these modalities, a plurality of application files comprises application 566. In another of these modalities, not all files in the plurality of application files reside on the local machine 10. In yet another of these modalities, the streaming service 554 recovered the plurality of application files in a
102 backup, but extracted only a subset of the plurality of application files. In yet another of these modalities, the streaming service 554 and the file system filter driver 564 provide functionality to satisfy the enumerated request, even when the requested file does not reside on the local machine 10.
In one mode, functionality is provided by intercepting data enumeration and provisioning requests as if all files in the plurality of application files reside on the local machine 10. In another mode, functionality is provided by interception10 by the driver. 564 file system filter, from an enumeration request transmitted as an IOCTL command, such as IRP_MJ_DIRECTORY_CONTROL IOCTL. When the 564 When the 564 file system filter driver intercepts the call, the 564 file system filter driver redirects the request to the broadcast service15 is continuous 554. In one embodiment, the file system filter driver 564 determines that the requested enumeration resides in an isolation environment on the local machine 10, before the request is redirected to the streaming service 554. In another embodiment, the streaming service 554 fulfills the request using a file in the plurality of application files, the file including an enumeration of a directory structure associated with the plurality of application files. In yet another modality, the streaming service 554 provides the response to the request for the 564 file system filter driver to satisfy the enumeration request.
Referring now to figure 11, a flowchart describes a modality of the steps followed in a method to respond locally to requests for file metadata associated with files stored remotely. In a brief overview, (i) a directory structure representing an application program stored by the remote machine 30 and (ii) metadata associated with each file comprising the stored application program are received from a remote machine (step 1102). The directory structure and metadata are stored (and
103 slap 1104). At least one request for access to metadata associated with a specific file in the directory structure is received (step 1106). At least one request is answered using the stored metadata (step 1108).
Referring to Figure 11 in more detail, a directory structure representing an application program stored by the remote machine and metadata associated with each file comprising the stored application program are received from a remote machine (step 1102). In one embodiment, the streaming service 554 receives the directory structure and metadata. In another embodiment, the streaming service 554 receives the directory structure and metadata when the streaming service 554 retrieves a plurality of application files comprising the stored application program. In yet another modality, the directory structure and metadata are stored in a file in the plurality of application files.
In one embodiment, the metadata associated with each file comprises an alternative name for at least one file. In another embodiment, the metadata associated with each file includes a short name for at least one file, the name being eight characters long, a period and three characters long. In yet another modality, the metadata associated with each file includes a mapping between the alternative name for at least one file and the short name for at least one file. In some embodiments, a file in the plurality of application files has an alternative file name. In one of these modalities, when the file is retrieved by a 554 streaming service to a local machine, the file is associated with a short name, in response to the mapping between the alternate name for the file and the short name for at least one archive.
The directory structure and metadata are stored (step 1104). In one embodiment, the directory structure and metadata are ar
104 stored in a 556 isolation environment. In another embodiment, the directory structure and metadata are stored in a cache memory element. In yet another embodiment, the directory structure representing an application program stored by the remote machine is used to generate an enumeration of a directory structure representing an application program running on the local machine.
At least one request for access to metadata associated with a specific file in the directory structure is received (step 1106). In one embodiment, the request is a request for file enumeration. In another embodiment, the request is a request to determine whether a copy of the file comprising the stored application program resides locally.
In one embodiment, the request is made by a 566 application running in an isolation environment on a local machine. In another mode, the request is made by the 552 application streaming client. In yet another mode, the request is made on behalf of the 566 application.
In one embodiment, the request is intercepted by a 564 file system filter driver. In another embodiment, the request is routed to the 552 application streaming client by the 564 file system filter driver. otherwise, the request is forwarded to the streaming service 554 by the 564 file system filter driver.
In some modalities, the request is hooked by a function that replaces the function or the operating system functions for enumerating a directory. In another embodiment, a dynamically linked hooking library is used to intercept the request. The hooking function can be performed in user mode or kernel mode. For modalities in which the hooking function is executed in user mode, the hooking function can be loaded into the address space of a process when the process is created. For modalities in which the hooking function
105 When executed in kernel mode, the hooking function can be associated with an operating system resource that is used in the dispatch of requests for file operations. For modalities in which a separate operating system function is provided for each type of file operation, each function can be hooked up separately. Alternatively, a unique hooking function can be provided, which intercepts creation or opening calls for various types of file operations.
At least one request is answered using the stored metadata (step 1108). In one embodiment, the 564 file system filter driver responds to the request. In another mode, the 552 application streaming client responds to the request. In yet another modality, the streaming service 554 responds to the request. In one embodiment, the stored metadata is accessed to respond to at least one request. In another mode, the request is answered with a false indication that a remote copy of the file resides locally.
In one embodiment, a Windows Operating System FindFirst operation is satisfied in response to received metadata. In another modality, a Windows Operating System FindNext operation is satisfied in response to received metadata. In yet another modality, an operation to identify a root node in a directory structure is satisfied in response to the received metadata. In some embodiments, an application layer API, such as WIN32_FIND_DATA API, is used to respond to the operation. In other embodiments, a kernel-layer API such as FlLE_BOTH_DIR_INFORMATION is used to respond to the operation.
In one embodiment, metadata satisfies an operation for identifying an access time associated with a node in a directory structure. In another embodiment, metadata satisfies an operation to identify a modification time associated with a node in a directory structure. In yet another modality,
106 metadata satisfies an operation for identifying a modified node in a directory structure.
Referring now to Figure 12, a block diagram describes a modality of a system for locally responding to requests for file metadata associated with files stored remotely, including a streaming service 554, a system filter driver. file 564, a directory structure 570, a plurality of application files 572, metadata 574 and a cache memory element 576. In a brief overview, the directory structure 570 identifies a plurality of files associated with at least one application program. Metadata 574 is associated with at least one of the plurality of files, at least one of the plurality of files residing on a remote machine. In one embodiment, directory structure 570 includes metadata 574. Cache element 576 stores directory structure 570. The 564 file system filter driver intercepts a request to access metadata associated with at least one file stored remotely, accesses the cache element and responds to at least one request using the stored directory structure.
In some embodiments, the streaming service 554 receives directory structure 570 and metadata 574. In one of these embodiments, directory structure 570 represents a plurality of application files 572 associated with an application program, the plurality of application files 572 residing on a remote machine, such as remote machine 30. In another of these modalities, metadata 574 comprises information to respond to a FindFirst request from the Windows Operating System. In yet another of these modalities, metadata 574 comprises information to respond to a FindNext request from the Windows Operating System. In yet another of these modalities, metadata 574 comprises information to answer a request for the identification of a root node in a directory structure. In another of these modali
107 Accordingly, metadata 574 comprises information to respond to a request for the identification of a node in a directory structure. In some embodiments, an application layer API, such as WIN32_FIND<sub>t</sub>_DATA API is used to respond to the operation. In other embodiments, a kernel-layer API such as FlLE_BOTH_DIR_INFORMATION is used to respond to the operation.
In some embodiments, small amounts of metadata 574 over a file can be stored directly in the literal file name, such as by suffixing the virtual name with a metadata indicator, where a metadata indicator is a string uniquely associated with a metadata state in particular. The metadata indicator can indicate or encode one or more bits of metadata. Requests for access to the file by a virtual file name check for possible variations of the literal file name due to the presence of a metadata indicator, and requests for recovery of the file name itself are hooked or intercepted in order to respond with the literal name. In other modalities, one or more alternative names for the file can be formed from the virtual file name and a metadata indicator, and can be created using hard link or flexible link facilities provided by the file system. The existence of these links can be hidden from applications by the isolation environment by indicating that the file is not found, if a request is made to access a file using the name of a link. A presence or absence of a particular link can indicate a metadata bit for each metadata indicator, or there can be a link with a metadata indicator that can take on multiple states to indicate several metadata bits. In yet other modalities, when the file system supports alternate streaming streams, an alternate streaming stream can be created for the realization of metadata, with the size of the streaming indicating several bits of metadata. In yet other modalities, a file system can directly provide the ability to store some meta
108 third-party data for each file in the file system. In yet another modality, a separate sub-scope can be used for recording deleted files, and the existence of a file (not marked with a placeholder symbol) in that sub-scope is taken to mean that the file is deleted.
In one embodiment, data in a user isolation environment, an application isolation environment, and a system scope are combined to form a local enumeration of a directory structure representing an application. In another embodiment, streaming service 554 accesses metadata 574 and directory structure 570 to fill the application isolation environment. In yet another embodiment, the 564 file system filter driver generates the local enumeration of the directory structure. In yet another embodiment, the local enumeration of the directory structure identifies at least one file in the plurality of 572 application files, at least one file residing on a remote machine and not on the local machine. In some embodiments, the local enumeration of the directory structure is stored in cache element 576. In other embodiments, the streaming service 554 generates the application isolation environment and the local enumeration of the directory structure.
In one embodiment, the 564 file system filter driver intercepts a request transmitted to a system scope for access to the local enumeration of the directory structure. In another embodiment, the 564 file system filter driver generates the local enumeration after the request is intercepted. In yet another embodiment, the 564 file system filter driver redirects the request to the local enumeration for the user isolation environment. In yet another embodiment, the 564 file system filter driver redirects the request to the local enumeration for the application isolation environment.
In some embodiments, the 564 file system filter driver intercepts a request for access to a file, identifies the local enumeration in the directory, the file residing on a remote machine.
109
In one of these modalities, the 564 file system filter driver requires a file retrieval by the streaming service 554, as described in greater detail in relation to figure 13 below.
As applications running in an isolation environment make requests for files, a filter driver intercepts these requests. If the request is for opening a file, the filter driver will first redirect the request to an isolation environment, to determine whether the request can be satisfied by the isolation environment. If the call is successful, the filter driver will respond to the request with the instance of the file located in the isolation environment.
However, if the requested file does not reside in the isolation environment, the filter driver will send a request to the streaming service 554 to retrieve the file from the plurality of application files, block it until the request is complete, and then attempt the original opening again. In some embodiments, the functionality of the streaming service 554 for retrieving files from the plurality of application files upon receipt of a filter driver request is referred to as on-demand caching.
Referring now to figure 13, a flowchart describes a modality of the steps followed in a method for accessing a remote file in a directory structure associated with an application program running locally. In a brief overview, a request for an application to access a file is intercepted (step 1302). The request is redirected to a first isolation environment (step 1304). A determination is made that the requested file does not exist in the first isolation environment (step 1306). The request is redirected to a second isolation environment, in response to a determination that the file is identified in a directory structure enumeration associated with a plurality of application files residing on a remote machine (step 1308). The requested file is retrieved from the remote machine, in response to a determination that the second
110 isolation environment does not contain the file and that the file is identified in the enumeration (step 1310).
With reference to figure 13, and in more detail, a request for an application to access a file is intercepted (step 1302). In one embodiment, the request is intercepted by a file system filter driver. In another mode, the file system filter driver intercepts all requests for file access. In yet another mode, a 552 application streaming client intercepts the request. In some modalities, a request by an application to access an executable file is intercepted. In other modalities, a request for an application to access a file, a portion of the application running on a local machine 10, is intercepted.
The request is redirected to a first isolation environment (step 1304). In one embodiment, the application runs in the first isolation environment. In one embodiment, the application is an application program, such as a word processing program or spreadsheet program. In another mode, the application is the 552 application streaming client. In yet another embodiment, the application is a component within the 552 application streaming client trying to open an application program on behalf of a user of the local machine 10. In another embodiment, the file system filter driver redirects the requisition for the first isolation environment.
A determination is made that the requested file does not exist in the first isolation environment (step 1306). In one embodiment, the file system filter driver receives an indication that the requested file does not exist in the first isolation environment.
The request is redirected to a second isolation environment in response to a determination that the file is identified in a directory structure enumeration associated with a plurality of application files residing on a remote machine (step 1308). In
111 a modality, the enumeration of the directory structure is received with access information regarding an execution of the first application. In another embodiment, the enumeration identifies a plurality of application files comprising a second application. In this mode, the first application is a local copy of the second application.
The requested file is retrieved from the remote machine, in response to a determination that the second isolation environment does not contain the file and that the file is identified in the enumeration (step 1310). In one embodiment, the requested file is retrieved from a second remote machine. In another mode, the requested file is retrieved from a file server. In some embodiments, the directory structure enumeration identifies a plurality of application files residing on the local machine. In other embodiments, the enumeration of the directory structure indicates that the plurality of application files resides on the local machine. In one of these modalities, when the application requests access to the file in the plurality of application files, which the enumeration of the directory structure indicated resides on the local machine, the file is acquired from the file server by intercepting the access request. . In another of these modalities, the file server continuously transmits the requested file to the local machine. In yet another of these modalities, when the application requests access to the file in the plurality of application files which the directory structure enumeration indicated resides on the local machine, a copy of the file is provided to the application from a local cache.
In some ways, the requested file is encrypted. In other modalities, the requested file is stored in an encrypted form. In other modalities, the application requesting the file can be prevented from decrypting the requested file, if the application lacks authorization to access the requested file.
In one embodiment, a determination is made that the directory structure enumeration does not identify the file. In this modality, the request to access the file can be redirected to an environment
112 outside the first isolation environment and outside the second isolation environment.
In some modalities, a second request for access to the file is intercepted. In one of these modalities, the request for access to the file is made by a second application. In another of these modalities, the second application runs in a third isolation environment. In yet another of these modalities, the request is redirected to the second isolation environment, in response to a determination that the file is enumerated in the enumeration and that the second isolation environment actually contains the file. The determination is made that the local machine stored the file in the second isolation environment upon receipt of the file from the file server. In yet another mode, the file is stored in the third isolation environment.
Referring now to Figure 14, a block diagram describes a modality of a system for accessing a file in a directory structure associated with an application. In a brief overview, a local machine 10 includes an application streaming client 552, a streaming service 554, an isolation environment 556, a file system filter driver 564, and a first application 566. Local machine 10 can interact with a file server 540, a remote machine 30, a web interface 558 and a second application 566 '.
Local machine 10 initializes application streaming client 552 to run the first 566 application. In one embodiment, application streaming client 552 initializes a streaming service 554 to retrieve and run the first 566 application. modalities, a plurality of application files comprise the first 566 application. In one of these modalities, the streaming service 554 retrieves the plurality of application files and stores them in the isolation environment 566. In another of these modalities, the streaming service 554 identifies a remote machine location in which the plurality of apli files
113 captives resides, but does not recover the plurality of application files. In yet another of these modalities, the streaming service 554 retrieves a subset of files in the plurality of application files. In yet another of these modalities, the streaming service 554 retrieves a backup storage file containing the plurality of application files.
In one embodiment, the first application 566 comprises a local copy of a second application 566 'residing on a remote machine 30. In another embodiment, the plurality of application files resides on the remote machine 30 and comprises the second application 566' residing on a remote machine. remote machine 30. In yet another mode, for the execution of the second application 566 ', the local machine 10 retrieves the plurality of application files, creating the first application 566 on the local machine, and executes the first application 566. In some modalities, the applications 566 and 566 'are user applications, such as word processing applications or spreadsheet applications or presentation applications.
In some embodiments, the plurality of application files includes a file identifying a directory structure associated with the plurality of application files on the remote machine 30. In one of these embodiments, the file includes metadata about each application file in the plurality of application files. In another of these modalities, the streaming service 554 retrieves the metadata from the file to generate an enumeration of the directory structure associated with the plurality of application files, as described in relation to figure 12 above. In yet another of these modalities, the streaming service 554 stores the directory structure enumeration associated with the plurality of application files comprising the second application 566 '. In some embodiments, the streaming service 554 stores the enumeration in a second isolation environment.
In one mode, the streaming service 554 retrieves an initial executable file associated with the first application 566. In another mode, the streaming service 554 performs the
114 first 566 application on local machine 10 by recovering the initial executable file. In yet another modality, the first 566 application requires access to other files in the plurality of application files, since the files are necessary for the continued execution of the first 566 application. In some modalities, the first 566 application runs in the isolation environment 556.
The 564 file system filter driver intercepts requests by the first 566 application running in the 556 isolation environment to access a file in the plurality of application files. The 564 file system filter driver redirects the request to the 556 isolation environment. If the requested file resides in the 556 isolation environment, access to the requested file will be provided for the first 566 application.
If the requested file does not reside in the 556 isolation environment, the 564 file system filter driver redirects the request to a second isolation environment. In one embodiment, the second isolation environment includes the enumeration of the directory structure generated by the streaming service 554 and associated with the plurality of application files comprising the second application 566 '. In another mode, a determination is made that the requested file is identified in the directory structure enumeration.
In some embodiments, the streaming service 554 provides a semaphore for the isolation environment 556. In one of these embodiments, the file system filter driver 564 using the semaphore indicates to the streaming service 554 that access to a file in the plurality of application files is required. In other embodiments, the 564 file system filter driver uses a line to indicate to the streaming service 554 that access to the file is required.
Upon receipt of notification from the 564 file system filter driver, the streaming service 554 retrieves the requested file from the plurality of application files. Still in
115 another of these modalities, the streaming service 554 stores the requested file in the second application isolation environment. In one embodiment, the request for access to the file is satisfied with the instance of the file retrieved from the plurality of application files and stored in the second isolation environment. In another mode, the requested file is also stored in the first isolation environment.
In some embodiments, a determination is made that the second isolation environment does not contain the file and that the file is identified in the enumeration. In one of these embodiments, the file is identified in the enumeration in the directory structure associated with the plurality of application files comprising the second application 566 'and the file is a file in the plurality of application files. In another of these modalities, the streaming service 554 did not retrieve the file from the remote machine. In yet another of these modalities, the streaming service 554 did not recover a plurality of application files including the requested file. In yet another of these modalities, the streaming service 554 recovered the plurality of application files in a backup storage file, but did not recover the requested file from the backup storage file.
In one embodiment, the streaming service 554 includes a transceiver, in communication with the file system filter driver. In another mode, the transceiver receives the redirected request from the file system filter driver. In yet another modality, the transceiver forwards the request for the file to a remote machine hosting the requested file. In one embodiment, the remote machine is a 540 file server. In another mode, the request is forwarded to a remote machine 30, which routes the request to a 540 file server. In some modes, the 540 file server continuously transmits the requested file to the transceiver on the local machine 10. In other modes, the machine
116 remote 30 continuously transmits the requested file to the transceiver on the local machine 10. Still in other modalities, upon receipt of the requested file from the 540 file server, the transceiver stores the received file in the second isolation environment.
In one embodiment, the 564 file system filter driver intercepts a second request for access to the file made by a third 566 ”application running on local machine 10, in a third isolation environment. In another embodiment, the 564 file system filter driver redirects the request for access to the file to the second isolation environment. In yet another modality, the file system filter driver 564 determines that the streaming service 554 stored the received file in the second isolation environment, before the interception of the request for access by the third application 566 ”.
In some modalities, upon initialization, the streaming service 554 can fill a cache in an isolation environment, before the execution of an application program. In one of these modalities, the streaming service 554 installs a log file in the isolation environment. In another of these modalities, the streaming service 554 stores a mapping between a long file name and a short file name.
In one embodiment, to save space on the local machine, the cache size can be limited. In some modalities, when the cache approaches its limit size, the oldest files in the cache will automatically be purged to make room for new files. In one of these modalities, the age of a file is determined by a time stamp maintained by the operating system indicating a 'last access' time stamp time. In addition to the age of a file, the type of file can be taken into account - binary executable files (.EXE, .DLL, etc.) can be kept longer than articles of similar age of other types.
Upon initialization, the streaming service
117
554 can enumerate files currently in a cache, and determine the total cache size. After a file is added to the cache, by an isolation environment 556 or by the streaming service 554, the streaming service 554 calls a function to inform the cache system about the new file, its location and its size. The size of each newly cached file is added to the total running from the current cache size. This new total is then compared against the cache size limit and, if the limit has been exceeded, the code fires a line to age the cache. There can be only one instance of this line running at any given time.
The line generates a list of all files currently in the cache, sorts this list by time stamp last accessed, and then starts walking down the list deleting files until we have freed up enough disk space to meet the line's exit criteria . The exit criterion is based on decreasing the cache size to a level below the limit which is determined as a percentage of the limit (the default value is 10%). Deleting more than is necessary to avoid exceeding the limit prevents the cache from overloading and trying to reallocate resources each time a new file is added.
In some embodiments, the streaming service 554 provides the ability to copy the entire file into a plurality of application files comprising an application program, in a compressed file format, to the local machine 10. This capability can be referred to as pre-cache . In one of these modalities, when the application program is subsequently executed, all packet requests go to the local copy, instead of crossing the network. These modalities allow a user of the local machine 10 to run the application program at a time when the user does not have access to the network.
A remote machine 30 includes functionality for monitoring application usage by a local machine 10. Remote machine 30 can monitor the status of each application used by local machine 10, for example, when an application is running or terminating. In a hand
118 the remote machine 30 requires the local machine 10 to transmit messages about the status of an application run by the local machine 10. In another mode, when a local machine 10 connects to a network on which the remote machine 30 resides, the local machine 10 transmits a message indicating that local machine 10 has connected to the network.
In one embodiment, local machine 10 is said to have a session when local machine 10 interacts with remote machine 30 and runs one or more applications. In another embodiment, the remote machine 30 requires the local machine to maintain, for the duration of a session, a license to run applications received from a remote machine. In yet another modality, sessions have unique session identifiers assigned by the remote machine.
In one embodiment, local machine 10 transmits messages directly to session management server 562. In another embodiment, local machine 10 transmits messages to remote machine 30, remote machine 30 forwarding messages to the management server session 562 with a local machine ID 10.
In some embodiments, the session management server 562 is a remote machine 30 providing session management and license management services. In one of these embodiments, the session management server 562 includes a server management subsystem 508 providing these services.
In one embodiment, local machine 10 transmits messages directly to session management server 562. In another embodiment, client 10 transmits messages to remote machine 30, remote machine 30 forwarding messages to the session management server 562 with a local machine ID 10.
A local machine 10 can transmit a heartbeat message to remote machine 30. In one embodiment, the heartbeat message includes a request for a license. In this mode, local machine 10 can transmit the tapping message
119 after receiving information associated with an application program for which local machine 10 has requested authorization to run. Local machine 10 can transmit the heartbeat message before the application is run. In one embodiment, the local machine 5 includes with the heartbeat message an opening ticket received with the access information. In this embodiment, remote machine 30 can grant local machine 552 a license upon successful verification of the opening ticket.
In another embodiment, heartbeat message 10 includes an indication that the local machine has started running an application. In yet another mode, the heartbeat message includes an indication that the local machine has finished running an application. In yet another modality, the heartbeat message includes an indication of a failure in the execution of an application.
In one embodiment, the heartbeat message includes a request for identification of a second session management server, such as a 562 session management server. In another embodiment, the heartbeat message includes an indication that the machine site 10 has connected to a network on which the machine on remote 30 resides.
In some embodiments, the heartbeat message includes a request to restart an application streaming session. In one of these embodiments, local machine 10 transmits this heartbeat message when an error has occurred and a connection is terminated between a network on which remote machine 30 resides and local machine 10. In another of these modalities, the local machine 10 transmits information associated with the session with the heartbeat message. In yet another of these modalities, the remote machine 30 can transmit 10 data related to the session to the local machine 30, if the session has not expired.
In another of these modalities, if a remote machine 30 disconnects from a network to which it responds, local machine 10 can
120 You will not receive a response to a heartbeat message transmitted to remote machine 30. In one embodiment, local machine 10 can reestablish a session by transmitting a message requesting a session restart to remote machine 30. In another embodiment , local machine 10 can reestablish a session by transmitting a message requesting a session restart to a second remote machine 30. In some embodiments, when remote machine 30 reconnects to the network, it will create a new session for each session restart request received while remote machine 30 was disconnected. In one of these modalities, the new session will be associated with the reconnected and unlicensed state. In another of these modalities, no new license will be acquired for the new session. In yet another of these modalities, when local machine 10 runs an application, a new license will be acquired and all sessions associated with local machine 10 will be associated with an active and licensed state.
In some embodiments, an application streaming client 552 on local machine 10 generates the heartbeat message. In one of these embodiments, the application streaming client 552 forwards the heartbeat message to a web interface 558 for transmission to local machine 10 for transmission to remote machine 30. In other embodiments, a remote machine 30 comprises a collection point 240 (described above in relation to figure 1 D) receives and stores the heartbeat messages.
In some modalities, the application streaming client 552 requires a license from remote machine 30. In one of these modalities, the license authorizes an application program to run on local machine 552. In another of these modalities, the remote machine 30 can access a second remote machine for the provision of the license. In yet another of these modalities, remote machine 30 can provide the license for the local machine. In yet another of these modalities, remote machine 30 can provide an acceptable license for
121 authorization for a second remote machine. In some modalities, the license is revoked upon termination of the execution of an application program.
In some embodiments, a remote machine 30 in bank 38 includes a license management subsystem for configuring and maintaining licenses for those subsystems that require a license to operate and to control the number of connections for those subsystems. In other embodiments, remote machine 30 incorporates functionality from a license management subsystem into other subsystems, such as the application management subsystem and the session management subsystem. In one embodiment, each remote machine 30 includes a license management subsystem or the functionality associated with a license management subsystem. The license management subsystem manages two types of licenses: (1) feature licenses and (2) connection licenses. In a brief overview, the license management subsystem uses feature licenses to control access to features of licensed software products. A feature may be a particular aspect or feature of the software product, or the feature may be the entire product that will not work without a feature license.
Figure 15 shows a mode of remote machine 30 in bank 38 in which remote machine 30 includes a license management subsystem 1510, a group subsystem 1520, a persistent storage system service module 1570, a service module for dynamic storage system 1580, a relationship subsystem 1530, a specialized remote machine subsystem 1540, and a common access point subsystem 524 in communication with an event bus 1570. Those subsystems shown in figure 15 are for purposes of describing the behavior of the license management subsystem 1510. Remote machine 30 can include other types of subsystems.
The license management subsystem 1510 communicates with the group subsystem 1520 via an event bus for
122 mation and maintenance of a logical grouping of licenses (from this point on, license groups) to facilitate license groups, assignments and groups. A license group includes a collection of license strings, described below, and / or other license groups. License groups collect licenses from similar resources and, consequently, allow a grouping of licenses. A bundled license is a license that is available for use by any remote machine 30 in bank 38. Each license group maintains the collective capabilities of the licenses in the license group and other license subgroups (that is, other license groups in a group excuse me). Information regarding license groupings is maintained, in one mode, in dynamic storage 240. In this modality, each license management subsystem 1610 stores locally the total number of licenses and the license number assigned to a remote machine 30 in bank 38. Upon granting a bundled license, the license management subsystem 1510 makes an entry in dynamic storage 240 indicating that a bundled license is in use. Every other 1510 license management subsystem recognizes that this bundled license is unavailable for lease. In a particular embodiment, dynamic storage 240 stores remote machine ID / client ID pairs associated with each license group to identify the pooled licenses that are in use.
The relationship subsystem 1530 maintains associations between licenses and remote machines 30 and between license groups and remote machines 30. Associations define the number of licenses for each license and license group that only the associated remote machine 30 can obtain (that is, local licenses). A local license is a license that is assigned to a remote machine in bank 38 and is not shared by other remote machines 38. The license management subsystem 1510 communicates with the relationship subsystem 1530 to create, delete, query and update such associations. The common access point subsystem 524 provides remote procedure calls (RPCs) for use by software products residing on remote machine 30. These RPC interfaces allow
123 these software products communicate through the common access subsystem 524 to access license information.
Still referring to figure 15, the specialized remote machine subsystem 1540 communicates with the license management subsystem 1510 to obtain a feature license for each capacity of the specialized remote machine subsystem 1540 for which a license is required. This occurs at startup of specialized remote machine subsystem 1540 and after any license event. If unable to obtain the feature license, the specialized remote machine subsystem 1540 restricts the functionality that that subsystem will provide with a license. Also, the specialized remote machine subsystem 1540 uses the license management subsystem 1510 to obtain client connection licenses whenever a client session is started with the remote machine 30.
The license management subsystem 1510 communicates with the persistent storage service module 352 for storing resource and connection licenses in a 1550 license deposit as license strings formed according to a naming convention. The license deposit 1550 resides on persistent storage 230. Cyclic redundancy checks (CRC) prevent a license violation while these licenses are stored in the license deposit 1550. The license management subsystem 1510 also stores information related to license strings in the license deposit 1550. For example, the information can indicate which licenses are assigned to which remote machines 30 in bank 38 and, in some modalities, the status of activation of each license. In one embodiment, a 1560 connection license table stores identifiers for those local machines that have obtained a connection license.
In one embodiment, the license management subsystem 1510 supports events for subsystems requiring the use of a licensed capacity, such as a request for an available pooled license. The event includes the UID of the subsystem requesting the surgical blade and
124 the UID of the remote machine 30 on which that subsystem resides. The event also contains the type of license requested (that is, a feature or connection license) in the form of a license group ID. The actual license group ID stored in persistent storage 230 is arbitrary, but adherence to the naming convention provides flexibility for the future addition of new software products (ie, subsystems) to the remote machine 30.
The event sent by a requesting subsystem seeking a license includes (1) an indication of the type of license group, the identity of the local machine and the remote machine requesting the license, and an indicator (force) of forcing acquisition. A license group type indication can include an identification of a resource license, such as a load management, or a connection type license, such as a software application program. The field identifying the local machine and the remote machine seeking the license can include the unique identifier associated with the remote machine and the local machine. The force acquisition indicator can be used, for example, for the repurchase of connection licenses after a license change event. A license change event indicates that a license information for persistent storage 230 has changed; for example, a license has been deleted, added or assigned. Through a license change event, each remote machine 30 attempts to reacquire all the connection licenses it had before the license change event, because the particular cause of the license change event is unknown to that remote machine. This indicator, if set, indicates that a connection license must be purchased, even if doing so increases the number of connections to the remote machine 30 beyond the maximum predetermined number of allowable connections. No new connection licenses are subsequently granted until the number of connection licenses in use falls below this predetermined maximum number. In this way, a local machine connection will not be terminated in the middle of a session due to a license change event.
Referring now to Figure 16, a block diagram
125 it describes a modality of the components involved in compliance with licensing. A remote machine 30 includes a server management subsystem 508 and a license management subsystem 512. In some embodiments, the server management subsystem 508 and the license management subsystem 512 provide the functionality of the license management subsystem 1510 described above. In other embodiments, an application management subsystem 506 and a session management subsystem 510 provide the functionality of the license management subsystem 1510 described above. In yet other modalities, other subsystems provide the functionality of the 1510 license management subsystem described above.
In one embodiment, the 508 server management subsystem may include a licensing component used for issuing and revoking licenses. In another embodiment, the license management subsystem 512 can apply a policy to a request to issue or revoke a license received from the server management subsystem 508. In yet another embodiment, the license management subsystem 512 can transmit the request to a remote machine 30 providing a license enforcement functionality. In some embodiments, the management service 504 can maintain a connection to a remote machine 30 providing license enforcement functionality. In other embodiments, the remote machine 30 provides license enforcement functionality.
In some embodiments, a license expires and ceases to be valid upon failure of the local machine 10 to transmit a predetermined number of heartbeat messages to the remote machine. In one of these modalities, a license expiration revokes an authorization to execute an application program by the local machine 10.
In other modalities, a session ends after the expiration of a predetermined period of time. In one embodiment, the 504 management service maintains data related to a session after a license expires until a session expires. In some
126 modalities, session related data can include information such as session name, session id, client id, login time, server name (UNC File Server Path), application name (generated unique name per local machine, based on a browser name), pseudonym, session state (active / licensed, active / unlicensed, reconnected / unlicensed). In another embodiment, the local machine 10 stops transmitting heartbeat messages and resumes transmitting heartbeat messages at a later point in time. In yet another modality, the management service 504 can reissue a license and make the session-related data kept available to the local machine 10 if the 10 resumes transmitting heartbeat messages before the session expires.
Referring now to figure 17, a flowchart describes a modality of the steps followed for requesting and maintaining a license from a remote machine 30 for the duration of a session on a local machine 10. In a brief overview, an application streaming client requests a license (step 1702). A remote machine 30 receives the requisition for the license, checks a ticket associated with the requisition, and generates a license (step 1704). Remote machine 30 provides the license and license associated information for local machine 10 (step 1706). Local machine 10 runs the application, as described above, in relation to step 214 in figure 7. The local machine transmits a heartbeat message indicating that the local machine has run an application (step 1708). Remote machine 30 receives the heart beat message and verifies an identification information transmitted with the heart beat message (step 1708). Remote machine 30 creates a session associated with the running application and local machine 10 (step 1710). A result of the session creation is transmitted to the local machine 10 (step 1712). The local machine transmits the heartbeat messages throughout the execution of the application, as described above in relation to step 216 of figure 7. The local machine receives
127 a response to a transmitted heartbeat message (step 1714). The local machine transmits a heartbeat message indicating an end to an application run (step 1716). Remote machine 30 receives the heartbeat message and determines whether to remove session related data and whether to release the license associated with local machine 10 and the terminated application (step 1718). A result of the determination made by the remote machine 30 is transmitted to the local machine 10 (step 1720).
Referring now to Figure 17, and in greater detail, an application streaming client on a local machine 10 requests a license (step 1702). In some modalities, the local machine 10 requests the license when receiving an access information associated with an application program. In one of these modalities, the local machine requests a license from the remote machine 30 granting an authorization to execute the application program by the local machine 10. In some embodiments, the license request includes an opening ticket received from remote machine 30 with access information. In other embodiments, an application streaming client 552 on local machine 10 transmits the request to a web interface 558 and web interface 558 transmits the request to remote machine 30. In still other modalities, a 510 session management subsystem on the remote machine receives and processes the license request.
A remote machine 30 receives the requisition for the license, checks a ticket associated with the requisition, and generates a license (step 1704). In one embodiment, remote machine 30 verifies that local machine 10 is authorized to run the application. In another embodiment, remote machine 30 determines whether local machine 10 is already associated with an existing license. In yet another embodiment, remote machine 30 determines that local machine 10 is associated with an existing license and provides local machine 10 with an identifier for a session management server 562 managing the existing license. In yet another modality, remote machine 30 generates and provides local machine 10 with a new
128 license, a session identifier, and a 562 session management server ID managing the new license.
In some embodiments, remote machine 30 uses a license management subsystem 1510 to respond to a license request in a modality in which the license management subsystem 1510 receives a license request. The request can be for a feature license or a connection license. The license management subsystem 1510 determines whether the license has already been granted, that is, whether the resource has already been started or a connection to a local machine already exists. If the license is already granted, the 1510 license management subsystem will send a granted event to the license requester. If the license has not been previously granted, the license management subsystem 1510 will determine whether a local license, that is, a license that has been permanently assigned to remote machine 30, is available. In some embodiments, the license management subsystem 1510 performs this determination when verifying a local memory. If a local license is available, that is, remote machine 30 has more licenses permanently assigned than currently granted, the license management subsystem 1510 will send an event granted to the license requester.
Remote machine 30 provides the license and license associated information for local machine 10 (step 1706). In one embodiment, upon receipt of the license, session identifier, and session management server 562 identification from remote machine 30, local machine 10 runs the application. Local machine 10 can run the application, as described above in relation to step 214 in figure 7. The local machine transmits a heartbeat message indicating that the local machine has run an application (step 1708). In one embodiment, the local machine transmits the heartbeat message to remote machine 30 for transmission of the heartbeat message to a session management server 562. In another embodiment, the local machine 10 transmits a heartbeat message
129 directly to a session management server 562, in response to a session management server 562 identifier received from remote machine 30.
Remote machine 30 receives the heart beat message and verifies an identification information transmitted with the heart beat message (step 1708). In one embodiment, a remote machine 30 'is session management server 562. In another embodiment, session management server 562 verifies a server identifier provided with a heartbeat message by the local machine 10. In yet another embodiment, the server identifier is the identifier provided for the local machine 10 by a remote machine 30.
Remote machine 30 creates a session associated with the running application and local machine 10 (step 1710). In one embodiment, the session management server 562 creates a new session associated with the running search agent upon receipt of the heartbeat message. In another embodiment, a third remote machine 30 creates the new session. In some embodiments, the session management server 562 stores information related to the session upon creation of the new session.
A session creation result is transmitted to local machine 10 (step 1712). In some modalities, the result confirms the creation of the session. In other modalities, the result identifies the application or applications associated with the session. The local machine transmits heartbeat messages throughout the application's execution, as described above in relation to step 216 of figure 7. In one embodiment, local machine 10 continues to transmit heartbeat messages at regular intervals throughout the execution of the application program. The local machine receives a response to a transmitted heartbeat message (step 1714). In one embodiment, local machine 10 receives an acknowledgment of receipt of heartbeat messages from session management server 562. In another embodiment
130 In fact, local machine 10 receives a command to execute session management server 562 in response to the receipt of a heartbeat message by session management server 562.
The local machine transmits a heartbeat message indicating an end to an application run (step 1716). Remote machine 30 receives the heartbeat message and determines whether to remove session related data and whether to release the license associated with local machine 10 and the terminated application (step 1718). A determination result made by the remote machine 30 is transmitted to the local machine 10 (step 1720).
Referring now to Figure 18, a block diagram describes a modality of states that can be associated with a session monitored by a management service 504. In one embodiment, a session management subsystem 510 in the management service 504 monitors a session from a local machine 10 and assign a state to the session. In another embodiment, the session management subsystem 510 maintains a list of license related data, which may include an identifier associated with the local machine, an identifier associated with the session, a session state and a time stamp indicating the last time when remote machine 30 received a message from local machine 10. In some embodiments, the session management subsystem 510 includes a session monitoring line. In one of these modalities, the session monitoring line is activated at a periodic license expiration interval to scan the list of license related data and update the session status of a session.
A first state a session can be in is an active and licensed state. In one embodiment, when in this state, local machine 10 has maintained a valid license authorizing an application to run. In another embodiment, a 562 session management server maintains session-related data. In some embodiments, the session management server 562 stores the session-related data on a second remote machine. In one mode, when
131 a local machine 10 initially runs an application, the session for the local machine is in the active and licensed state.
A second state that a session can be in is an active, unlicensed state. In one embodiment, a session is in this state when local machine 10 fails to transmit heartbeat messages and a license to local machine 10 has expired. In another mode, if a session is in this state, then, while the license has expired, insufficient time has elapsed for the session to expire, and the session will be considered active. In some embodiments, while the session is in this state, a remote machine 30 or session management server 562 can store session-related data on behalf of local machine 10. In other embodiments, if a local machine 10 transmits a knock message before the session expires, the session related data will be transmitted to the local machine 10 with a new license and the session will return to the active and licensed state. In one embodiment, a remote machine 30 uses session identifiers and identifiers associated with the local machine to verify that the session has not expired and to provide the local machine with appropriate session-related data.
A third state that a session can be in is a disconnected, non-existent state. When a session expires, the data related to the session is erased.
A fourth state that a session can be in is in the reconnected and licensed state. In one embodiment, when a session on a local machine 10 expires, the data related to the session is erased. In another embodiment, when the local machine 10 transmits a new heartbeat message, a new session identifier and a local machine identifier are generated for the local machine 10. In some embodiments, the local machine 10 authenticates the remote machine 30, receives a new license and enters the active and licensed state.
Table 3 summarizes the states that can be associated with a session.
132
<td>Session Status</td><td>description</td>
<td>Active / Licensed</td><td>Normal mode of operation.</td>
<td>Active / Unlicensed</td><td>Duration of missing heartbeat > License expiration AND Duration of missing heartbeat <Session expiration</td>
<td>Reconnected / Unlicensed</td><td>Duration of missing heartbeat > Session expiration OR CPS / RADE hosting the session is inactive and back online</td>
Table 3
In some embodiments, a package formation mechanism allows the creation of a plurality of application files associated with an application program. In one of these modalities, the package formation mechanism allows the identification of a plurality of application files. In another of these modalities, the package formation mechanism allows the grouping of individual application files into a plurality of application files. In yet another of these modalities, the package formation mechanism allows the hosting of a plurality of application files on a remote machine, such as a file server or an application server.
In one embodiment, the packet forming mechanism is performed on a remote machine described as a stage machine. In another embodiment, the package forming mechanism is performed on a clean machine. A clean machine can be a remote machine with only one operating system installed on it, without additional software, drivers, registry entries or other files. In yet another modality, the packet forming machine runs on a remote machine, the remote machine looking like a local machine on which an application program can be run. In some embodiments, the remote machine on which the pacing mechanism
133 te runs includes an isolation environment providing a clean machine environment in which an application can be installed, even when the remote machine is not a clean machine in itself.
In one embodiment, the plurality of application files is referred to as a package. In another embodiment, the package can be a backup storage file storing the plurality of application files. In yet another embodiment, the package can be a backup storage file stored in the plurality of application files and a file including metadata associated with at least one file in the plurality of application files. In some embodiments, a package may include a plurality of application files comprising an application program. In other embodiments, a package includes a plurality of application files comprising a suite of application programs. In yet other modalities, a package includes a plurality of application files comprising an application program and a prerequisite required to execute the application program.
In one embodiment, the package formation mechanism initiates the execution of an installation program in an isolation environment. In another embodiment, the package formation mechanism monitors a change in the isolation environment generated by the installation program. In yet another modality, the package formation mechanism monitors a creation by the program of installing a file in the isolation environment. In yet another modality, the package formation mechanism monitors a modification by the program of installing a file in the isolation environment. In some embodiments, the plurality of application files includes a file created or modified by the installation program. In other embodiments, the packet formation mechanism implements a 564 file system filter driver for monitoring the isolation environment.
In some embodiments, a package-forming mechanism can generate multiple pluralities of application files, each comprising a different version of a configured application program.
134 to run in a different target environment. In one of these modalities, a plurality of application files are configured to run on a local machine having a particular operating system, a revision level, language settings and a master unit (for example, a plurality of application files can be configured to running on a local machine using the Windows XP Professional operating system with revision level SP2 and above, using English and having the master unit C: \). In another of these modalities, more than a plurality of application files can be combined into a single backup storage file. In yet another of these modalities, each plurality of application files can be referred to as a target. In yet another of these modalities, a backup storage file containing one or more pluralities of application files can be referred to as a package.
Referring now to Figure 19, a block diagram describes a package that includes two targets, each target comprising a plurality of application files comprising an application. In figure 19, the application program 'Foo' is packaged in two targets. The difference between the two targets is the 'Target Language'. Specifically, target 1 supports 'English' and target 2 supports 'German'. In one embodiment, an enumeration of available application programs may list the application program 'Foo'. In another mode, the appropriate plurality of files is transmitted to a local machine requesting access to the application program. In yet another modality, a determination is made for the transmission of a particular target to a local machine, in response to an evaluation from the local machine. In yet another modality, a file associated with the package identifies at least one characteristic associated with a target in the package and required to run on a local machine.
In some embodiments, the 530 package engine prepares an application program for continuous transmission by running an installation program associated with the application program. In one of these modalities, the package formation mechanism generates an environment of
135 isolation on remote machine 30 on which the packet forming mechanism is running. In another of these modalities, the package formation mechanism executes the application program in the isolation environment. In yet another of these modalities, the package formation mechanism identifies a plurality of application files generated or modified by the installation program. In yet another of these modalities, the package formation mechanism creates a backup storage file including the plurality of application files. In one of these modalities, the package formation mechanism creates a .CAB file including the plurality of application files. In another of these modalities, the package formation mechanism creates a directory and stores the plurality of application files in the directory. In some embodiments, the package formation mechanism stores the plurality of application files on a file server or on another remote machine 30. In other embodiments, the package formation mechanism stores the plurality of application files on multiple remote machines.
Referring now to figure 20, a flowchart describes a modality of the steps followed in a policy-based method to effectively install an application program, without rebutting an operating system. In a brief overview, a packaging mechanism runs an installer program in an isolation environment, the installer program installing at least one application file associated with a second application in the isolation environment (step 2002). A call by the installer program to at least one application programming interface (API) is intercepted, the call requiring an action to be taken after an operating system reboots (step 2004). The action of at least one intercepted call is performed without rebooting the operating system (step 2006). An identification of a file type of at least one application file is received (step 2008). At least one execution method is associated with at least one installed application file, in response to the identified file type (step 2010). At least one installed application file is stored in at least
136 a server (step 2012). An enumeration is generated from the second application, at least one installed application file, a location of at least one server and at least one execution method (step 2014).
Referring now to figure 20, and in greater detail, a package formation mechanism runs an installer program in an isolation environment, the installer program installing at least one application file associated with a second application in the isolation environment (step 2002). In one embodiment, running the installer program in the isolation environment allows the package-forming mechanism to isolate changes made by the installer program to a file or record on the local machine. In another modality, the package formation mechanism intercepts a change requested by the installer program and redirects the change to the isolation environment to prevent the change from occurring on the local machine. In still other modalities, the package formation mechanism runs a second installer program in the isolation environment, the second application installing at least one application file associated with a third application in the isolation environment.
In some embodiments, the package formation mechanism runs the installation program in the isolation environment, the installation program running at least one executable application associated with an application within the isolation environment. In a mode in which the installer runs an application, running the application allows the installation of a second application.
In another of these modalities, installing an application requires running at least one executable application, in addition to running the installer program. In another of these modalities, installing an application requires running an Internet browser application, in addition to running the installer program. In some embodiments, an installer program is executed to install a program and the execution of the installer program includes the execution of a second program required to install the program. In one of these modalities, the pro
137 gram is a plug-in. In another of these modes, the program is an Active X component. In yet another of these modes, the program is a Flash component. In yet another of these modalities, the program is a personalized toolbar, just like a Yahoo! or Google. In other modalities, the program is a component installed in the second program and is not executable independently of the second program.
A call by the installer program to at least one application programming interface (API) is intercepted, the call requiring an action to be taken after an operating system reboots (step 2004). The action of at least one intercepted call is performed without rebooting the operating system (step 2006). In some embodiments, the execution of the action comprises the execution of an action from a modified registry entry during an installation. Additional details regarding the execution of at least one intercepted call without rebooting the operating system are provided in relation to figure 25 below.
An identification of a file type of at least one application file is received (step 2008). At least one execution method is associated with at least one installed application file, in response to the identified file type (step 2010). In one embodiment, at least one execution method allows a continuous transmission of at least one application file to a client. In another mode, at least one execution method allows the execution of at least one application file installed on a client. In yet another modality, at least one execution method allows the execution of at least one application file installed on a server. In yet another modality, at least one execution method allows the continuous transmission of at least one application file to a server.
At least one installed application file is stored on at least one server (step 2012). In some embodiments, the installed application program runs in the isolation environment before
138 storage of at least one application file installed on at least one server. In one of these modalities, an additional application file is generated in response to the execution of the installed application program. In another of these modalities, a data file is generated. In yet another of these modalities, the installed application program requires information to complete the installation, the information being required after an initial installation process. In yet another of these modalities, information, such as software product identifiers, license identifiers or other credentials, is required.
In some embodiments, an identifier is provided identifying the location of at least one application file installed on at least one server. In one of these modalities, the identifier conforms to a Universal Naming Convention (UNC). In other embodiments, at least one installed application file is placed in a backup storage file, such as a .CAB file. In one of these modalities, a plurality of application files are stored in a backup storage file and the backup storage file is stored on at least one server. In yet another of these modalities, at least one installed application file is stored on multiple servers. In yet other modalities, at least one application file is placed in a directory storing application files.
An enumeration is generated from the second application, at least one installed application file, a location of at least one server and at least one execution method (step 2014). In some embodiments, the enumeration is stored in a file. In other embodiments, the enumeration is stored in a manifest file. In yet other modalities, the enumeration is stored in an XML file.
In one embodiment, an enumeration is generated from multiple applications, a plurality of installed application files associated with each of the multiple applications, and a location of at least one server storing the plurality of installed application files. In a
139 in another embodiment, an enumeration is generated including an association between the second application and a plurality of installed application files. In yet another modality, an enumeration is generated including an association between the second application and a compressed file containing at least one installed application file.
Referring now to Figure 21, a flowchart describes a modality of the steps followed in a policy-based method for installing an application program without rebuting an operating system. In a brief overview, a packaging mechanism runs an installer program in an isolation environment, the installer program installing at least one application file associated with a second application in the isolation environment (step 2102). A call by the installer program to at least one application programming interface (ARI) is intercepted, the call requiring an action to be taken after an operating system reboots (step 2104). The action of at least one intercepted call is performed without rebooting the operating system (step 2106). A feature identification of at least one application file is received (step 2108). At least one execution prerequisite is associated with at least one installed application file, in response to the identified feature (step 2110). At least one installed application file is stored on at least one server (step 2112). An enumeration is generated from the second application, at least one installed application file, a location of at least one server and at least one execution prerequisite (step 2114).
Referring now to figure 21, and in greater detail, a package formation mechanism runs an installer program in an isolation environment, the installer program installing at least one application file associated with a second application in the isolation environment (step 2102). In one embodiment, running the installer program in the isolation environment allows the package-forming mechanism to isolate changes made by the installer program to a file or record on the local machine. In another modality, the force mechanism
140 Package information intercepts a change requested by the installer program and redirects the change to the isolation environment to prevent the change from occurring on the local machine. In still other modalities, the package formation mechanism runs a second installer program in the isolation environment, the second application installing at least one application file associated with a third application in the isolation environment.
In some embodiments, the package formation mechanism runs the installation program in the isolation environment, the installation program running at least one executable application associated with an application within the isolation environment. In a mode in which the installer runs an application, running the application allows the installation of a second application. In another of these modalities, installing an application requires running at least one executable application, in addition to running the installer program. In another of these modalities, installing an application requires running an Internet browser application, in addition to running the installer program.
Referring to Figure 23 ahead, a block diagram depicts a modality of a system including a package engine 530 running an installer program 2350 in an isolation environment 532 and a file system filter driver 534 in communication with the mechanism package 530 and the isolation environment 532.
In one embodiment, the package engine 530 generates a package (as described above in relation to figure 21) by installing an application program in an isolation environment 532. In another embodiment, the package engine 530 installs the application program on isolation environment 532 by running the 2350 installer program. In some embodiments, the 530 package engine includes a graphical user interface. In one of these embodiments, the graphical user interface allows a user of the 530 packet engine to customize the generation of a packet by the 530 packet engine. In another of these embodiments, the 530 packet engine is communicating with an interface.
141 ce graphical user in the access control suite 520, allowing a user of the access control suite 520 to customize the generation of a package by the 530 package engine.
In some embodiments, the 532 file system filter driver allows installation of the application program in a 532 isolation environment. In one of these modalities, the 532 file system filter driver intercepts a request by the 2350 installer program. another of these modalities, the 532 file system filter driver redirects the request by the 2350 installer program to the 532 isolation environment. In yet another of these modalities, the 532 file system filter driver stores a record of the request made by the 2350 installer program. In yet another of these modalities, the 532 file system filter driver stores a copy of a created file or modified by the 2350 installer program. In some embodiments, the stored records generated by the 532 file system filter driver are stored together as a plurality of application files comprising an application program. In other embodiments, the plurality of application files is stored on a 540 file server.
Referring back to figure 21, a call by the installer program to at least one application programming interface (API) is intercepted, the call requiring an action to be performed after an operating system reboot (step 2104). The action of at least one intercepted call is performed without rebooting the operating system (step 2106). In some modalities, the execution of the action includes the installation of a driver configured to start when the computer system boots. In other modalities, the execution of the action comprises the execution of an action of a registry entry modified during an installation.
An identification of a file type of at least one application file is received (step 2108). In some embodiments, an identification of an operating system type is received. In other fashion
142 lities, an identification of a language used by the operating system is received. In still other modalities, an identification of a version of the second application is received.
At least one execution prerequisite is associated with at least one installed application file, in response to the identified feature (step 2110). In one embodiment, at least one execution prerequisite is associated with at least one application file installed in response to an application of a policy to the feature. In another mode, a script is associated with at least one installed application file, the script comprising an executable program determining the existence of at least one prerequisite of execution on a client. With reference to the front of figure 22, a screen snapshot describes a modality of an enumeration of scripts to be executed on the local machine. A script type 2202 indicates when the script should be executed, for example, before the application runs, or after the application has finished running. An isolation indicator 24 indicates whether the script should be run in an isolation environment on the local machine 10. As shown in figure 22, in some embodiments, the script was associated with the application program at the time when the plurality of application files were packaged together and stored on the remote machine 30 'hosting the plurality of application files.
In some embodiments, at least one running prerequisite requires installing a version of an operating system on a system running at least one installed application file. In other embodiments, at least one execution prerequisite requires the installation of a version of the second application on a system running at least one installed application file. In still other modalities, an instruction is associated with at least one installed application file, the instruction indicating a second installed application file for use by a client failing to satisfy at least one execution prerequisite. In still other modalities, an instruction is associated with at least one installed application file, the instruction indicating a second method
143 of execution to execute at least one application file installed on a client failing to satisfy at least one execution prerequisite. In one of these modalities, the execution method is associated with at least one installed application file, the execution method allowing a continuous transmission of a plurality of application files comprising the second application to a local machine for execution on the local machine. In another of these modalities, an evaluation of a local machine identifies at least one characteristic associated with at least one installed application file not included on the local machine. In yet another of these modalities, an authorization to execute the plurality of application files is revoked. In yet another of these modalities, a second execution method is provided for executing the plurality of application files, the second execution method allowing the execution of the plurality of application files on a remote machine and the transmission of application output data from from the remote machine to the local machine.
At least one installed application file is stored on at least one server (step 2112). In some embodiments, the installed application program runs in the isolation environment before storing at least one application file installed on at least one server. In one of these modalities, an additional application file is generated in response to the execution of the installed application program. In another of these modalities, a data file is generated. In yet another of these modalities, the installed application program requires information to complete the installation, the information being required after an initial installation process. In yet another of these modalities, information, such as software product identifiers, license identifiers or other credentials, is required.
In some embodiments, an identifier is provided identifying the location of at least one application file installed on at least one server. In one of these modalities, the identifier conforms to a Universal Naming Convention (UNC). In other modali
144 At least one installed application file is placed in a backup storage file, such as a .CAB file. In one of these modalities, a plurality of application files are stored in a backup storage file and the backup storage file is stored on at least one server. In yet another of these modalities, at least one installed application file is stored on multiple servers. In yet other modalities, at least one application file is placed in a directory storing application files.
An enumeration is generated from the second application, at least one installed application file, a location of at least one server and at least one execution prerequisite (step 2114). In some embodiments, the enumeration is stored in a file. In other embodiments, the enumeration is stored in a manifest file. In yet other modalities, the enumeration is stored in an XML file.
In one embodiment, an enumeration is generated from multiple applications, a plurality of installed application files associated with each of the multiple applications, and a location of at least one server storing the plurality of installed application files. In another embodiment, an enumeration is generated including an association between the second application and a plurality of installed application files. In yet another modality, an enumeration is generated including an association between the second application and a compressed file containing at least one installed application file.
With reference back to step 2106, when an action of at least one intercepted call is performed without an operating system reboot, in some modalities, a virtualized installation and execution environment are provided, which remove the requirement to rebut the system before running an installed application.
Referring now to figure 24, a flowchart describes a mode in which the execution of an installer program requires a reboot of an operating system on a local machine on which the program
145 an installer runs. A conventional application installer copies files to a remote machine where the application is being installed (step 2402). In some embodiments, copying files can cause the remote machine to reboot. The application installer attempts to copy at least one of the files to locked files (step 2404). In one embodiment, a locked file can be written only when an operating system is run (or rebuilt). The MOVE_FILE_DELAY_UNTIL_REBOOT option is regulated in the MoveFileEx () Win32 API (step 2406). And the application installer calls a system stop / reboot function (step 2408). Following a reboot, the files originally locked are then installed using a reboot (step 2410).
Referring now to Fig. 25, a block diagram describes an embodiment of a remote machine 30 on which a packet forming mechanism installs an application program. Remote machine 30 includes system resources 2502, system APIs 2504 and an application installer 2506 used to install an application. Remote machine 30 also includes a 2508 function latching mechanism, a post-installation processor module 2510 and an application isolation environment 2512. In some embodiments, installing an application program in an isolation environment 2512 allows for installation without a reboot of the remote machine 30. In either of these embodiments, a change made to a virtualized system resource 2502 in an isolation environment 2512 does not change a corresponding system resource 2502 on remote machine 30. Since the system resource on remote machine 30 is not changed, a rebooting the machine to protect the system feature from inappropriate changes is not required.
Referring now to Figure 25, and in greater detail, system resources 2502 can include registry entries, system DLLs and other locked files that the operating system prevents from being written while remote machine 30 is running. The 2504 system APIs include APIs used to rebuild the system that are
146 called by application installer 2506 and hooked by function locking mechanism 2508 to prevent remote machine rebooting 30.
The 2512 application isolation environment provides an environment with an operating system resource view for a 2506 application installer. In one embodiment, the 2512 application isolation environment is a 556 isolation environment. In some embodiments, the Application isolation 2512 provides virtualization of operating system resources, such as the file system, registry and named objects. In one embodiment, the application installer 2506 runs in the application isolation environment 2512. In one embodiment, the application installer 2506 installs the application program in the application isolation environment 2512. In yet another mode, the application installer 2506 runs outside the 2512 application isolation environment and installs the application program within the 2512 application isolation environment.
In some embodiments, the isolation environment 2512 circumvents the requirement to rebound the remote machine 30, when application installer 2506 installs an application in application isolation environment 2512. In one embodiment, the application isolation environment 2512 intercepts a request. to copy an application file to a locked file. In another embodiment, the 2512 application isolation environment redirects the request to copy the application file to an un-locked file. In yet another modality, the 2512 application isolation environment redirects the request to copy the application file to a virtualized file. In yet another modality, a redirection of the request to copy the application file allows the installation of application files without requiring a reboot of the remote machine 30. As an example, if an application installer 2506 tries to write to a locked file, such like c: \ windows \ system32 \ mfc40.dll, the application isolation environment 2512 intercepts the request and redirects the file to another location that is not locked. This ability to avoid files
147 locked means that the file can be installed without having to use MoveFileEx () API and the MOVE_FILE_DELAY_UNTIL_REBOOT indicator (flag). This capability removes the need for a remote machine reboot 30.
In one embodiment, the function locking mechanism 2508 is a 564 file system filter driver. In another embodiment, a 564 file system filter driver includes the function hooking mechanism 2508. In yet another embodiment , the function latching mechanism 2508 intercepts requests from the application installer 2506 to restart the remote machine 30. In some embodiments, the 2512 application isolation environment provides a copy of application files in un-locked files. However, application isolation environment 2512 does not address a request by application installer 2506 for a reboot of remote machine 30. Function hook mechanism 2508 intercepts the request for reboot and responds to application installer 2506.
The 2512 application isolation environment allows a copy of application files to non-locked files. However, in some modalities, other actions are required to install an application, and these actions can occur when rebooting. Preventing the reboot does not preclude the need to complete these actions in the installation process. The 2508 function latching mechanism can provide functionality to perform an action associated with an application installation.
For example, when installing an application, registry entries, such as HKLM \ SYSTEM \ CurrentControlSet \ Control \ Session_Manager \ PendingFileRenameOperations, can be written. Other applications may install services or drivers which need to be started when a machine boots. The post-installation processor module 2510 identifies application files that were modified during an installation, and performs the actions associated with the application files.
148
Referring now to Figure 26, a flowchart describes a modality of the steps followed to install an application in a 2512 application isolation environment. The 2512 application isolation environment provides a virtualized view of the server's operating system for the application installer (step 2602). The server APIs for system reboots and stops are hooked (step 2604) to prevent the 2506 application installer from causing a reboot. Application installer 2506 requests file copy operations for locked files, the request being intercepted and redirected to non-conflicting locations (step 2606). When application installer 2506 tries to rebut when calling a system API, the request is intercepted and the reboot is prevented (step 2608). The post-installation processor module 2510 performs actions that commonly occur after a reboot (step 2610) and the application can then be run in the application isolation environment 2512, without a reboot from a remote machine 30 (step 2612).
In some embodiments, following the installation of the application program in the 2512 application isolation environment, a package formation mechanism identifies a plurality of application files created or modified during an application program installation. In one of these modalities, the plurality of application files is stored on a remote machine. In another of these modalities, a local machine retrieving the plurality of application files can execute the application program.
In some embodiments, the 530 packet engine runs on a remote machine including a 532 isolation environment and a 534 file system filter driver and installs an application program in the 532 isolation environment. In one of these modalities, the remote machine it is referred to as a clean machine or a stage machine. In another of these modalities, the 532 isolation environment includes an application isolation scope providing a modifiable virtualized instance of a native resource provided by an operating system on the clean machine. In yet another of these modalities, the environment isolates
149 ment 532 includes a system isolation scope providing a read-only view of the native resource. In yet another of these modalities, the read-only view of the native resource comprises a screen snapshot of a file system and registry resident on the clean machine.
In one embodiment, a redirector intercepts a request for a change to the native resource. In some embodiments, the redirector is a 534 file system filter driver. In another embodiment, an installer program executed by the 530 package engine requests the change. In yet another modality, switching to the native feature is required to install an application program on the clean machine. In yet another modality, the redirector redirects the request to the 532 isolation environment.
In some modalities, a redirection of requests to change native resources to the 532 isolation environment results in an isolation of changes associated with the installation of an application program. In other modalities, requests for changing native resources are recorded and stored in a storage element. In one of these modalities, all changes associated with an installation of an application program reside in the storage element. In another of these modalities, a local machine 552 retrieving the contents of the storage element and implementing the changes to native resources residing in an isolation environment 556 on local machine 552 results in the installation of the application program on local machine 552.
In some embodiments, a pre-opening analysis of the local machine 10 may be required. In one of these modalities, the local machine 10 verifies that at least one characteristic is included in the local machine 10. In another of these modalities, at least one characteristic is added to the local machine 10 after the pre-opening analysis determines that the local machine 10 lacks at least one feature. In yet another of these modalities, at least one feature is included on a remote machine hosting an application program and a
150 local machine in including at least one feature will prevent the application program from running. In yet another mode, the application program requires at least one feature on the local machine to run.
In some embodiments, the package forming mechanism allows the identification of at least one feature for use in a pre-opening analysis on the local machine. In other modalities, the package formation mechanism allows the association of at least one feature with an application program available for execution on the local machine. In still other modalities, the package formation mechanism allows an executable script to be associated with an application program, the local machine executing the executable script to complete the pre-opening analysis. In yet other modalities, at least one feature is required to exist on the local machine, after the application program has been executed.
The package-forming mechanism can provide functionality for flagging a plurality of application files. In one embodiment, signaling the plurality of application files allows a local machine to verify the integrity of the plurality of application files. In another mode, signaling the plurality of application files prevents a local machine from running a corrupted application program. In some embodiments, a cryptographic checksum, such as MD4 hash, MD5 hash, or SHA-1 hash, of a file in the plurality of application files is computed.
In other modalities, a cryptographic checksum of every file in the plurality of application files is computed. In one of these modalities, the cryptographic checksum is stored in a second file. In another of these modalities, the second file is associated with the plurality of application files. In some embodiments, the second file is added to the plurality of application files. In other modalities, the second file is signaled using a certificate, such as an X.509 certificate. In still other modalities, a
151 local machine retrieving the plurality of application files verifies the signature using a public portion of the certificate. In yet other modalities, the local machine receives the public portion of the certificate and an identification from a certificate trust list for verification of the signature. In one of these modalities, the local machine receives a registration key containing the identification of a certificate trust list.
In one embodiment, the package-forming mechanism provides functionality for customizing an isolation environment. In another embodiment, the package formation mechanism provides functionality for generating a file storing a definition of an isolation environment. In yet another modality, the package formation mechanism includes the file with the plurality of application files comprising an application program. In yet another modality, a local machine receives the file with access information from a remote machine.
In some embodiments, a plurality of application files are stored in a backup storage file. In one of these modalities, the backup storage file is in a CAB file format. In another of these modalities, the backup storage file format does not support a specification by an application program for short file names of a file. In yet another of these modalities, an operating system, such as WINDOWS 2000, cannot provide support for a specification by an application program of short filenames of a file. In other embodiments, an operating system, such as WINDOWS XP, provides support for an application program to specify a short filename for a file. In one of these modalities, a request to execute the file must include the correct short file name of the file.
In one embodiment, a mapping can be generated to associate a long file name of a file in the plurality of application files with a short file name of the file. In another
152 mode, the mapping is stored in a file in the plurality of application files. In yet another embodiment, a file has a short file name only if the long file name of the file is longer than twelve characters. In some embodiments, the short file name is a virtual file name associated with the file. In one of these modalities, the file is transmitted to the local machine 10 for execution, where it is stored with a long file name. In another of these modalities, an application file on the local machine 10 requests an execution of the file using the short file name. In yet another of these modalities, the mapping allows the execution of the file although the request to execute the file did not use the file name on the local machine (the long file name).
In some embodiments, the 530 packet engine generates the mapping. In one of these modalities, the 530 package engine selects a short file name for a file having a long file name. In another of these embodiments, an operating system on remote machine 30 'on which packet engine 530 is running selects a short file name for a file having a long file name. In yet another of these modalities, a single short file name is selected, which does not conflict with a second short file name on remote machine 30 '. In yet another of these modalities, the installer program executed by the 530 package engine generates a file including a mapping between a long file name and a short file name. In other modalities, the mapping is transmitted to a local machine 10, retrieving the file. In another of these modalities, local machine 10 refers to the file when executing the file.
The following illustrative examples show how the methods and systems discussed above can be used for the selection, the continuous transmission to a local machine and the execution on the local machine of a plurality of files comprising an application program. These examples are meant to illustrate and not to limit the invention.
153
EXAMPLE 1
In one embodiment, a user of the local machine 10 requests access to an application program, such as a word processing program, a web browser application, or a spreadsheet program, identified in a list of application programs. In an example of this embodiment, the local machine 10 runs a program neighborhood application that receives an enumeration of applications available to the local machine 10 from a remote machine 30. In another example of this modality, local machine 10 communicates with a web server, such as remote machine 30 ”'to receive application enumeration. The user of the local machine 10 can request access to an enumerated application program by selecting a graphical description representing the enumerated application program. The user of the local machine 10 can request access to an application program not previously installed on the local machine 10.
Local machine 10 transmits the request for access to the application program to a remote machine 30. Local machine 10 receives an identification from a remote machine 30 ”providing access to a plurality of application files comprising the application program. Local machine 10 identifies at least one characteristic required to run the application program. In an example of this modality, the local machine 10 receives at least one characteristic with the identification of the remote machine 30 ”transmitted by the absorbent article to the local machine 10 by the remote machine 30. In another example of this modality, the local machine 10 retrieves at least one characteristic from the remote machine 30 ”, after receiving the identification of the remote machine 30”. Local machine 10 may be required to understand at least one feature before being authorized to recover the plurality of application files. Alternatively, the local machine 10 may be required to understand at least one feature before executing the plurality of application files. In an example of this embodiment, the local machine 10 may be required to comprise at least one feature throughout the execution of the plurality of application files.
154
Upon verification by the local machine 10 that the local machine 10 includes at least one feature, the local machine 10 retrieves at least one application file in the plurality of application files and executes the application file retrieved to run the application program.
EXAMPLE 2
A remote machine 30 receives a request to access an application program from a local machine 10. Remote machine 30 authenticates the local machine 10. In an example of this modality, remote machine 30 requests credentials, such as a username and a password, from local machine 10. In another example of this embodiment, remote machine 30 transmits a collection agent 404 to local machine 10. The collection agent 404 accumulates information about the local machine 10 and transmits the information to the remote machine 30 for use in authenticating the local machine 10. Still in another example of this modality, the remote machine 30 provides information about the local machine 10 for a policy agent 406 for authentication of the local machine 10. Remote machine 30 can comprise policy agent 406. Alternatively, remote machine 30 may be in communication with a remote machine 30 'comprising policy agent 406.
Remote machine 30 selects a method of executing the application program. Remote machine 30 can make the selection in response to authentication of local machine 10. In one example of this mode, remote machine 30 applies a policy to accumulated information about local machine 10. In another example of this mode, the remote machine 30 makes a selection in response to a policy applied to the application program. In yet another example of this modality, remote machine 30 makes the selection in response to a policy applied to a type of file associated with the application program. Remote machine 30 can consult a file to make the selection of the execution method of the application program.
Remote machine 30 can select an application program execution method allowing local machine 10 to receive data from
155 application output generated by running the application program on a remote 30 'machine. Remote machine 30 may select a method of executing the application program by allowing local machine 10 to execute the application program locally after retrieving a plurality of application files comprising the application program.
In one embodiment, remote machine 30 selects an application program execution method allowing local machine 10 to execute the application program locally, while retrieving a plurality of application files comprising the application program through an application streaming session. In an example of this modality, local machine 10 establishes an application streaming session with a remote machine hosting a plurality of application files, local machine 10 initiates the recovery of the plurality of application files through the application streaming session, and local machine 10 performs a first application file retrieved in the plurality of application files while retrieving a second application file retrieved in the plurality of application files. In another example of this modality, local machine 10 executes a first application file in the plurality of application files and retrieves a second application file in the plurality of applications upon receipt of a request from the first application file slot accessing the second application file.
For modalities in which the selected method of execution allows the local machine 10 to retrieve at least one application file in a plurality of application files comprising an application program, remote machine 30 identifies a remote machine 30 ”hosting the application program available for access via local machine 10. Remote machine 30 ”hosts a plurality of application files comprising the application program. The remote 30 ”machine can host multiple pluralities of application files comprising various application programs. In an example of this modality, the remote machine 30 ”hosts a plurality of application files for each of
156 several different versions of an application program.
The remote machine 30 ”hosts a file associating a plurality of application files comprising a particular application program with a description of the application program. The file can also identify one or more execution prerequisites to be identified on a machine, before the transmission of the plurality of application files to the machine. The file can also include an identification of a location on a remote machine's 30 ”network. In an example of this modality, remote machine 30 consults the file to identify the location on the network of remote machine 30 ”.
Remote machine 30 selects a remote machine 30 ”. Remote machine 30 can select a remote machine 30 ”having a location on a network accessible to local machine 10. Remote machine 30 can select a remote machine 30” hosting a version of the application program compatible with local machine 10. Remote machine 30 transmits an identification of the selected method of executing the application program and an identification of the remote machine 30 ”to local machine 10, in response to receiving the request for access to the application program. Remote machine 30 can also transmit the file to local machine 10.
EXAMPLE 3
In one embodiment, the local machine 10 receives an identification of a selected execution method of an application program and an identification of a remote machine 30 ”providing access to a plurality of application files comprising the application program. Local machine 10 verifies an authorization for accessing the application program. In an example of this modality, the local machine 10 performs a pre-opening analysis of itself. Local machine 10 identifies at least one feature and checks for the existence of at least one feature on local machine 10. At least one feature can be a prerequisite for maintaining an authorization for access and execution of the application program. The verification of the existence of at least one characteristic in the
157 local machine 10 can guarantee compatibility between characteristics of local machine 10 and the system requirements of the application program, and can additionally guarantee compliance with security policies or licensing agreements.
Upon successful completion of a pre-opening analysis, local machine 10 establishes an application streaming session with remote machine 30 ”providing access to the plurality of application files. The application streaming session can be any connection over which local machine 10 can request and receive a file in the plurality of application files. Establishing the application streaming session may allow local machine 10 to run a first application file on the plurality of application files before retrieving all files on the plurality of application files. Local machine 10 can initiate an application program run while continuing to retrieve additional application files on the plurality of application files. Alternatively, local machine 10 can retrieve the plurality of applications in one backup storage file and execute a first extracted application file while extracting a second application file from the backup storage file.
EXAMPLE 4
In one embodiment, an application streaming client 552 on a local machine 10 retrieves a plurality of application files from remote machine 30. The application streaming client includes a streaming service 554, an isolation environment 556 and a 564 file system filter driver. Streaming service 554 establishes an application streaming session with remote machine 30 to request and retrieve the plurality of application files. The streaming service 554 runs application files in the 556 isolation environment. The 564 file system filter driver allows application files to be run in the 556 isolation environment by intercepting requests from
158 execution application files and redirecting requests to the 556 isolation environment.
In an example of this modality, the streaming service 554 retrieves a file from backup storage including the plurality of application files comprising an application program. The streaming service 554 extracts a first application file from the backup storage file from the plurality of application files. The first application file can be an executable file. The streaming service 554 can run the first application file in the 556 isolation environment. Running the first application file can initiate an execution of the application program.
In another embodiment, a first application file running in the 556 isolation environment requests from the local machine 10 an enumeration of the plurality of application files. The 564 file system filter driver intercepts the request for enumeration and redirects the request to the 554 streaming service. In modalities in which the streaming service 554 has recovered the plurality of application files, the streaming service 554 can generate an enumeration of the plurality of application files. In modalities where the streaming service 554 retrieved a backup storage file including the plurality of application files, the streaming service 554 can generate the enumeration of the plurality of application files in response to an enumeration included in the storage file backup recovered. In other embodiments, the streaming service 554 retrieves only the core of the plurality of application files while at least one application file in the plurality of application files resides on a remote machine 30 and has not yet been retrieved to the local machine 10 by the transmission service continuous 554. In these modalities, the streaming service 554 can generate an enumeration of the plurality of application files in response to the retrieved enumeration. In an example of these modalities, the continuous transmission service 554 indicates for the first file
159 v the application that the plurality of application files resides on the local machine 10, although only the enumeration resides on the local machine 10.
EXAMPLE 5
In one embodiment, a first application file running in the 556 isolation environment requires from the local machine 10 access to a file identified by the enumeration of the plurality of application files. If the requested file resides in a user scope in the 556 isolation environment accessible to the first application file, the first application file will access the requested file.
If the requested file does not reside in the user scope or in the 556 isolation environment, the 564 file system filter driver will intercept the request and redirect the request to the 554 streaming service. If the requested file is a file in the file backup storage containing the plurality of application files, the streaming service 554 will extract the requested file and store the requested file on the local machine 10. The streaming service 554 can store the file in the 556 isolation environment. The request for the file is satisfied when the file is stored in the 556 isolation environment.
If the requested file does not reside in the 556 isolation environment or the backup storage file including the plurality of application files, the streaming service 554 will request the file from remote machine 30. The streaming service 554 can receive the file from remote machine 30 through an application streaming session. The streaming service 554 stores the file received in the 556 isolation environment. The request for the file is satisfied when the file is stored in the 556 isolation environment.
In an example of this modality, a second application file is executed in a second scope in the 556 isolation environment. The second application file requires access to the file originally requested by the first application file. If a copy of the requested file
160 does not reside in the second user scope, the copy of the requested file stored in the 556 isolation environment will be used to satisfy the request by the application file.
EXAMPLE 6
In one embodiment, a local machine 10 receives from an remote machine 30 an identification of a selected method of executing an application program and an identification of a remote machine 30 'providing access to a plurality of application files comprising the application program. Local machine 10 successfully completes an analysis of local machine 10. Local machine 10 receives a license from remote machine 30 authorizing the execution of the application program. In an example of this modality, the license requires the local machine 10 to transmit heartbeat messages to a session management server 562 for maintaining an authorization to run the application program. Heartbeat messages can include messages indicating an initiation of the execution of an application program, an end of execution of an application program, and messages sent on a periodic basis throughout the execution of the application program. Heartbeat messages can also include messages about the status of local machine 10, such as when local machine 10 connects to a network or when local machine 10 terminates a connection to a network. In another example of this modality, the license specifies a predetermined period of time during which the local machine 10 is authorized to run the application program.
Local machine 10 establishes an application streaming session with remote machine 30 'and retrieves at least one of the application files in the plurality of application files. During the execution of at least one application file, in modalities in which the license received requires a transmission of heartbeat messages, the local machine 10 sends the heartbeat messages to the session management server 562 to maintain authorization for execution at least one application file.
161
EXAMPLE 7
In one embodiment, the local machine 10 receives an identification from a selected method of running an application program and an identification from a remote machine 30 'providing access to a plurality of application files comprising the application program. The local machine 10 successfully completes a pre-opening analysis of the local machine 10. Local machine 10 receives a license specifying a predetermined period of time during which local machine 10 is authorized to run the application program.
Local machine 10 establishes an application streaming session with remote machine 30 'and retrieves at least one of the application files in the plurality of application files. In an example of this modality, the local machine 10 retrieves a subset of the plurality of application files, the subset comprising each file necessary for the execution of the application program, when the local machine 10 is not connected to a network. Local machine 10 stores the subset in a cache on local machine 10.
At a point in time within the predetermined period of time, local machine 10 is disconnected from a network and receives a request for access to the application program from a user of local machine 10. In an example of this modality, the local machine 10 is a device, such as a laptop, and the user of the local machine 10 is in an environment that prohibits connection to networks, such as on an airplane. Upon receipt of the user's request, the local machine 10 can retrieve an application file from the cache from the plurality of application files from the cache and execute the application program.
EXAMPLE 8
In another embodiment, the local machine 10 receives an identification of a selected method of running an application program and an identification of a remote machine 30 'providing access to a plurality of application files comprising the application program. Local machine 10 can receive an identification from a first
162 client residing on local machine 10 for execution to recover the plurality of application files, such as an application streaming client.
In an example of this modality, local machine 10 fails to successfully complete a pre-opening analysis of itself. Local machine 10 may lack a feature required for compatibility with a display of the application program, such as a particular device driver or operating system. Local machine 10 may lack a feature required for compliance with a security policy, for example, participation in an Active Directory or authorization to access a private network. Local machine 10 can be a type of machine incompatible with an application program requirement, such as a personal digital assistant trying to access a computationally intensive application program, or a public machine at a kiosk trying to run a secure application hosted by a remote machine on a private network.
The local machine 10 makes a determination not to recover the plurality of application files through the application streaming session, in response to the determination that the local machine 10 lacks at least one feature required to access the application program. Local machine 10 runs a second client agent residing on local machine 10, instead of running the first identified client agent. In an example of this modality, the local machine 10 receives an identification from the second client agent to be executed, in the event of failure to successfully complete a pre-opening analysis. Local machine 10 requests an application program to run on a remote 30 ”machine. The second client agent receives application output data generated by running the application program on the remote 30 ”machine. The second client agent displays the application exit data on the local machine 10.
EXAMPLE 9
In one embodiment, a network administrator provides access to an application program for users of local machines 10. The ad
163 The administrator runs an application on a remote machine 30 'to generate a plurality of application files comprising the application program. The application can include a graphical user interface. The administrator can use the graphical user interface to identify the application program and an installer program associated with the application program, define policies to be applied when authorizing access to the application program, and specify characteristics about the type of access provided including requirements to be satisfied by a local machine 10 trying to access or run the application program. The administrator can identify an installer program by installing an entire application program or a portion of an application program, such as an update or patch.
In an example of this embodiment, a remote machine 30 includes a package mechanism 530. Package mechanism 530 runs the installer program in an isolation environment 532 on remote machine 30. Running the installer program results in installation in the isolation environment 532, of at least one application file associated with the application program. Remote machine 30 may include a file system filter driver 534, which ensures installation of the application file in the isolation environment 532 by intercepting a request by the installer program to install the application file on local machine 10, and redirecting the requisition for the isolation environment 532. The 530 packet engine can use the 534 file system filter driver to maintain a record of each application file installed in the 532 isolation environment.
The installer program can install a plurality of application files in the 532 isolation environment. Package engine 530 generates a file including an enumeration of application files in the plurality of application files. The file may include information associated with the plurality of application files, such as the type of application program that the plurality of application files comprise, the version of the application program, the execution prerequisites associated with the program
164 application and policy requirements, such as a method of execution required for a particular application program. The packet mechanism 530 stores on a remote machine 30 'the plurality of application files and the file.
In one embodiment, the network administrator identifies an application program comprising an updated version of an existing application program or application file in a plurality of application files comprising an application program.
C. SYSTEMS AND METHODS FOR ACCELERATING COMMUNICATION FROM CUSTOMER - SERVER
One embodiment of the present invention is directed to systems and methods for accelerating client - server communications. These systems and methods can be used alone or in concert, and can be used in conjunction with any of the systems and methods for delivering a computing environment discussed above. In particular, four categories of acceleration techniques will be discussed.
1. Caching of Dynamically Generated Objects · in some ways, client - server communications are accelerated by a 1250 appliance performing a caching of dynamically generated objects on a data communication network.
2. Connection Grouping: In some modalities, client - server communications are accelerated by a 1250 device using connection grouping techniques.
3. Integrated Caching: In another mode, client - server communications are accelerated by a 1250 appliance performing integrated caching with a variety of acceleration techniques.
4. Client Side Acceleration: In yet another modality, client - server communications are accelerated by a program running on a client 10 performing one or more acceleration techniques.
165
1. Caching of Dynamically Generated Objects
As will be described in more detail here, in one embodiment, a 1250 appliance can integrate kernel-level caching functionality into the operating system with 5 or more other processing tasks, including, but not limited to, decryption, decompression, or authentication and / or authorization. An example architecture like this is described here according to figure 27, but other architectures can be used in the practice of the operations described here.
Figure 27 illustrates an example 3200 architecture of a 1250 apparatus. As mentioned above, the 3200 architecture is provided by way of illustration only and is not intended to be limiting. As shown in figure 2, the example 3200 architecture consists of a hardware layer 3206 and a software layer divided into a user space 3202 and a kernel space 3204.
The hardware layer 3206 provides the hardware elements on which programs and services in kernel space 3204 and user space 3202 are executed. The hardware layer 3206 also provides the structures and elements which allow programs and services in the kernel space 3204 and user space 3202 to communicate data internally and externally with respect to the 1250 apparatus. As shown in Figure 27, the hardware layer 3206 includes a 3262 processing unit for running software programs and services, a 3264 memory for software and data storage, 3266 network ports for transmitting and receiving data over a network , and a 3260 encryption processor for performing functions related to the Secure Sockets Layer processing of data transmitted and received over the network. In some embodiments, the 3262 central processing unit can perform the functions of the 3260 encryption processor in a single processor. Additionally, the hardware layer
3206 can comprise multiple processors for each of the 3262 processing unit and the 3260 encryption processor.
166 although hardware layer 3206 of apparatus 1250 is generally illustrated with a 3260 encryption processor, the 3260 processor can be a processor for performing functions related to any encryption protocol, such as a Security Socket Layer (SSL) protocol ) or Transport Layer Security (TLS). In some embodiments, the 3260 processor may be a general purpose processor (GPP), and in additional embodiments, it may have executable instructions for carrying out the processing of any security-related protocol.
Although the hardware layer 3206 of apparatus 1250 is illustrated with certain elements in Figure 27, the hardware portions or components of apparatus 1250 may comprise any type and form of elements, hardware or software, of a computing device, such as the device computation 135 illustrated and discussed in conjunction with figures 1C and 1D here. In some embodiments, apparatus 1250 may comprise a server, gateway, router, switch, bridge or other type of computing or network device, and have any hardware and / or software elements associated with it.
The 1250 appliance operating system allocates, manages or otherwise segregates the system memory available in kernel space 3204 and user space 3202. In an example 3200 software architecture, the operating system can be any type and / or form of Unix operating system. As such, the 1250 system can be running any operating system, such as any version of the Microsoft Windows® operating systems, the different versions of the Unix and Linux operating systems, any version of Mac OS® for Macintosh computers, any built-in operating system , any network operating system, any real-time operating system, any open source operating system, any proprietary operating system, any operating systems for mobile computing devices or network devices, or any other operating system capable of running on the 1250 apparatus and performing the operations described here.
167
The 3204 kernel space is reserved to run the 3230 kernel, including any device drivers, kernel extensions or other kernel-related software. As known to those skilled in the art, the 3230 kernel is the core of the operating system, and provides access, control and management of resources and hardware-related elements of the 1250 apparatus. According to one embodiment, the kernel space 3204 also includes several network services or processes working in conjunction with a 3232 cache manager, sometimes also referred to as the integrated cache, the benefits of which are described in more detail below. Additionally, the 3230 kernel mode will depend on the operating system mode installed, configured or otherwise used by the 1250 device.
In one embodiment, device 1250 comprises a network stack 3267, such as a stack based on TCP / IP, for communication with client 10 and / or server 30. In one embodiment, network stack 3267 is used for communication with a first network, such as network 40, and a second network 40. In some embodiments, device 1250 terminates a first transport layer connection, such as a TCP connection from a client 10, and establishes a second transport layer connection with a server 30 for use by client 10, for example, the the second transport layer connection is terminated on apparatus 1250 and server 30. The first and second transport layer connections can be established via a single 3267 network stack. In other embodiments, device 1250 may comprise multiple network cells, for example, 3267 and 3267 ', and the first transport layer connection can be established or terminated in a 3267 network cell, and the second transport layer connection on the second network stack 3267 '. For example, a network stack can be for receiving and transmitting a network packet on a first network, and another network stack for receiving and transmitting network packets on a second network. In one embodiment, the network stack 3267 comprises a buffer 3243 for queuing one or more network packets for transmission by the 1250 apparatus.
168
As shown in Figure 27, kernel space 3204 includes 3232 cache manager, 3240 high-speed layer 27 integrated package agent, 3234 encryption agent, 3236 policy agent, and multiple protocol compression logic 3238. Running these 3232, 3240, 3234, 3236 and 3238 components or processes in kernel space 3204 or in kernel mode instead of in user space 3202 improves the performance of each of these components, alone or in combination. A kernel operation means that these components or processes 3232, 3240, 3234, 3236 and 3238 run in the core address space of the 1250 device's operating system. For example, running the 3234 encryption agent in kernel mode improves encryption performance by moving encryption and decryption operations to the kernel, thereby reducing the number of transitions between memory space or a kernel line in mode kernel and memory space or a line in user mode. For example, data obtained in kernel mode may not need to be passed or copied to a process or a line running in user mode, such as from a kernel-level data structure to a data-level data structure. user. In another aspect, the number of context switches between kernel mode and user mode is also reduced. Additionally, synchronization of and communications between any of the 3232, 3240, 3234, 3236 and 3238 components or processes can be performed more efficiently in the 3204 kernel space.
In some embodiments, any portion of the 3232, 3240, 3234, 3236 and 3238 components can run or operate in the 3204 kernel space, while other portions of these 3232, 3240, 3234, 3236 and 3238 components can run or operate in the 3202 user space . In one embodiment, a kernel-level data structure is used to provide access to any portion of one or more network packets, for example, a network packet comprising a request from a client 10 or a response from a server 30. In some embodiments, the kernel-level data structure can be obtained by the 3240 package agent through
169 a transport layer driver interface or filter for the 3267 network stack. The kernel level data structure can comprise any interface and / or data accessible through the 3204 kernel space related to the 3267 network stack, network traffic or packets received or transmitted by the 3267 network stack. In other embodiments, the kernel level data structure can be used by any of the 3232, 3240, 3234, 3236 and 3238 components or processes to perform the desired operation of the component or process. In one embodiment, a 3232, 3240, 3234, 3236 and 3238 component is running in the 3204 kernel space when using the kernel level data structure, while in another embodiment the 3232, 3240, 3234, 3236 and 3238 component is run in user mode when using the kernel level data structure. In some embodiments, the kernel-level data structure can be copied or passed to a second kernel-level data structure, or any desired user-level data structure.
The 3232 cache manager can comprise software, hardware or any combination of software and hardware for the provision of access, control and management of cache of any type and form of content, such as dynamically generated objects or objects presented by the origin servers 30. The data, objects or content processed and stored by the 3232 cache manager can comprise data in any format, such as a markup language, or communicated through any protocol. In some embodiments, the 3232 cache manager duplicates the original data stored anywhere or previously computed, generated or transmitted data, where the original data may require a longer access time to search, compute or otherwise obtain in relation to reading a cache memory element. Once the data is stored in the cache memory element, future use can be made by accessing the cached copy, instead of fetching it again and recomputing the original data, thereby reducing access time. In some embodiments, the cache memory element NAT comprises
170 a data object in the 3264 memory of device 1250. In other embodiments, the cache memory element may comprise a memory having a faster access time than the 3264 memory. In another embodiment, the cache memory element may comprise any type and shape of the storage element of the device 1250, such as a portion of a hard disk. In some embodiments, the 3262 processing unit may provide a cache memory for use by the 3232 cache manager. In other embodiments, the 3232 cache manager may use any portion or combination of memory, storage, or processing unit for caching. data, objects and other content.
Furthermore, the 3232 cache manager includes any logic, functions, rules or operations for performing any modalities of the techniques described here. For example, the 3232 cache manager includes logic or functionality for object invalidation based on the expiration of an invalidation time period or upon receipt of an invalidation command from a client 10 or server 30. In some embodiments, the 3232 cache manager can operate as a program, service, process or task running in the 3204 kernel space, and in other embodiments, in the 3202 user space. In one embodiment, a first portion of the 3232 cache runs in user space 3202, while a second portion runs in kernel space 3204. In some embodiments, the 3232 cache manager can comprise any type of general purpose processor (GPP), or any other type of integrated circuit, such as a Programmable Field Array (FGPA), a Programmable Logic Device (PLD) or an Application Specific Integrated Circuit (ASIC).
The 3236 policy agent can include, for example, an intelligent statistical agent or programmable application (s). In one embodiment, the 3236 policy agent provides a configuration mechanism to allow a user to identify, specify, define or configure a caching policy. Policy agent 3236, in some
171 but modalities, it also has access to a support for data structures such as query tables or hash tables to allow caching policy decisions selected by user. In other modalities, the policy agent 3236 can provide any logic, rules, functions or operations for determining and providing access, control and management of objects, data or content being cached by the 1250 apparatus, in addition to access, control and security management, network traffic, network access, compression or any other function or operation performed by the 1250 system. In some embodiments, the policy agent 3236 can be integrated with a policy agent 406 feature. In one embodiment, the policy agent 3236 can determine caching policy decisions based on information provided by a collection agent 404. In some embodiments, the 3236 policy agent can determine caching policy decisions based on an application execution type. In one embodiment, the policy agent can determine caching policy decisions based on whether an application is being streamed continuously to a client 10. Additional examples of policies are further described here.
The 3234 encryption agent comprises any logic, business rules, functions or operations for handling the processing of any security-related protocol, such as SSL or TLS, or any related function. For example, the encryption agent 3234 encrypts and decrypts network packets, or any portion thereof, communicated through the 1250 apparatus. The 3234 encryption agent can also configure or establish SSL or TLS connections on behalf of client 10, server 30 or appliance 1250. As such, the 3234 encryption agent provides a load reduction and an acceleration of SSL processing. In one embodiment, the encryption agent 3234 uses a tunneling protocol to provide a virtual private network between a client 10 and a server 30. In some modalities
172 Also, the 3234 encryption agent is in communication with the 3260 encryption processor. In other embodiments, the 3234 encryption agent comprises executable instructions running on the 3260 encryption processor.
The 3238 multi-protocol compression agent comprises any logic, business rules, function or operations for compressing one or more protocols in a network packet, such as any of the protocols used by the 3267 network stack of the 1250 device. In one embodiment, the multi-protocol compression agent 3238 compresses bidirectionally between clients 10 and servers 30 any protocol based on TCP / IP, including a Message Sending Application Programming Interface (MAPI) (email ), a File Transfer Protocol (FTP), a Hypertext Transfer Protocol (HTTP), Common Internet File System (CIFS) protocol (file transfer), an Independent Computing Architecture (ICA) protocol, a Remote Desktop Protocol (RDP), a Wireless Application Protocol (WAP), a mobile IP protocol, and a Voice over IP protocol (VolP). In other embodiments, the multi-protocol compression agent 3238 provides compression of protocols based on Hypertext Markup Language (HTML) and, in some modalities, provides compression of any markup languages, such as the Extensible Markup Language ( XML). In one embodiment, the 3238 multiple protocol compression agent provides for the compression of any high performance protocol, such as any protocol designed for 1250 device communications to 1250 device communications. In another embodiment, the 3238 multiple protocol compression agent compresses any payload of any communication using a modified transport control protocol, such as Transaction TCP (T / TCP), TCP with check acknowledgments (TCP-SACK) , TCP with large windows (TCPLW), a congestion prediction protocol, such as the TCP-Vegas protocol and a deceptive TCP protocol.
As such, the 3238 multiple protocol compression agent
173 accelerates performance for users accessing applications through desktop clients, for example, Microsoft Outlook and non-web lightweight clients, just like any client opened by popular company applications, such as Oracle, SAP and Siebel, and even mobile clients, such as Pocket PC. In some embodiments, the 3238 multiple protocol compression agent by executing in the 3204 kernel space and integration with the 3240 packet processing agent accessing the 3267 network stack is capable of compressing any of the protocols ported by the TCP / IP protocol , just like any application layer protocol.
The 3240 high-speed layer 2-7 integrated packet agent, also commonly referred to as a packet processing agent or a packet agent, is responsible for managing the kernel level processing of packets received and transmitted by the 1250 appliance through network ports 3266. The 3240 high-speed layer 2-7 integrated packet agent may comprise a buffer for queuing one or more network packets during processing, such as for receiving a network packet or transmitting a network packet. Additionally, the 3240 high-speed layer 2-7 integrated packet agent is communicating with one or more 3267 network stacks for sending and receiving network packets through the 3266 network ports. The high-speed layer 2-7 integrated packet agent 3240 works in conjunction with the encryption agent 3234, the cache manager 3232, the policy agent 3236, and the multi-protocol compression logic 3238. In particular, the 3234 encryption agent is configured to perform SSL packet processing, the 3236 policy agent is configured to perform functions related to traffic management, such as request-level content switching and cache redirection request level, and 3238 multiple protocol compression logic is configured to perform functions related to data compression and decompression.
The 3240 high-speed layer 2-7 integrated packet agent includes a 3242 packet processing timer.
174 In this embodiment, the 3242 packet processing timer provides one or more time slots for triggering the processing of network packets arriving, that is, received, or leaving, that is, transmitted. In some embodiments, the 3240 high-speed layer 2-7 integrated packet agent processes network packets in response to timer 3242. The 3242 packet processing timer provides any type and form of signal to the 3240 high-speed layer 2-7 integrated packet agent to notify, trigger or report an event related to time, interval or occurrence. In many embodiments, the 3242 packet processing timer operates on the order of milliseconds, such as, for example, 100 ms, 50 ms or 25 ms. For example, in some embodiments, the 3242 packet processing timer provides time slots or otherwise causes a network packet to be processed by the 3240 high-speed layer 2-7 integrated packet agent in a time slot 10 ms, while in other modes, in a 5 ms time interval, and in additional modes, a time interval as short as 3, 2 or 1 ms. The 3240 high-speed layer 2-7 integrated packet agent can interface, integrate, or communicate with the 3234 encryption agent, the 3232 cache manager, the 3236 policy agent, and the protocol compression agent multiple 3238 during an operation. As such, any of the logic, functions or operations of the 3234 encryption agent, 3232 cache manager, 3236 policy agent, and 3238 multi-protocol compression logic can be performed in response to the 3242 packet processing timer and / or the 3240 package agent. Therefore, any of the logic, functions or operations of the encryption agent 3234, cache manager 3232, policy agent 3236 and multi-protocol compression logic 3238 can be performed at the granularity of time intervals provided through the 3242 packet processing, for example, in a time interval less than or equal to 10 ms. For example, in one embodiment, the 3232 cache manager can perform an invalidation of any obje
175 cached data in response to the 3240 high-speed layer 2-7 integrated packet agent and / or the 3242 packet processing timer. In another embodiment, the expiration or invalidation time of a cached object can be set to be of the same order of granularity as the 3242 packet processing timer time interval, such as every 10 ms.
In contrast to kernel space 3204, user space 3202 is the area of memory or portion of the operating system used by applications or programs in user mode otherwise running in user mode. A user mode application cannot access the 3204 kernel space directly, and it uses service calls in order to access the kernel services. As shown in figure 27, the 1250 appliance space 3202 includes a 3210 graphical user interface (GUI), a 3212 command line interface (CLI), 3214 shell services, 3216 health monitoring program, and services daemon 3218. GUI 210 and CLI 3212 provide a means by which a system administrator or other user can interact with and control the operation of the 1250 appliance, such as through the 1250 appliance operating system and be in the 3202 user space or the user space. kernel 3204. GUI 3210 can be any type and form of graphical user interface, and can be presented through text, graphic items or otherwise, by any type of program or application, such as a browser. CLI 3212 can be any type and form of command line or text based interface, such as a command line provided by the operating system. For example, CLI 3212 can comprise a shell, which is a tool to allow users to interact with the operating system. In some modalities, CLI 3212 can be provided through a bash, csh, tcsh or ksh shell. The 3214 shell services comprise executable programs, services, tasks, processes or instructions to support an interaction with the 1250 system or the operating system by a user through the 3210 GUI and / or the 3212 CLI.
The 3216 health monitoring program is used for
176 monitoring, checking, reporting and ensuring that network systems are functioning properly and that users are receiving the content requested by a network. The 3216 health monitoring program comprises one or more executable programs, services, tasks, processes or instructions for the provision of logic, rules, functions or operations for monitoring any activity of the 1250 apparatus. In some embodiments, the 3216 health monitoring program intercepts and inspects any network traffic passed through the 1250 appliance. In other embodiments, the health monitoring program 3216 has an interface by any appropriate means and / or mechanisms with one or more of the following: the encryption agent 3234, the cache manager 3232, the policy agent 3236, the logic of 3238 multiple protocol compression, 3240 packet agent, 3218 daemon services, and 3214 shell services. As such, the health monitoring program 3216 can call any application programming interface (API) for determining the status, status or health of any portion of the 1250 apparatus. For example, the health monitoring program 3216 can give ping or send a status inquiry on a periodic basis to check if a program, process, service or task is currently active and running. In another example, the 3216 health monitoring program can check any status, error or history records provided by any program, process, service or task to determine any condition, status or error with any portion of the 1250 apparatus.
3218 daemon services are programs that run continuously or in the background and deal with periodic service requests received by the 1250 appliance. In some embodiments, a daemon service can forward requests to other programs or processes, such as another daemon service 3218, as appropriate. As is known to those skilled in the art, a 3218 daemon service can run without assistance to perform extensive continuous or periodic system functions, such as network control, or to perform any desired task. In some modalities, one or more
177 3218 daemon runs in user space 3202, while in other modalities one or more 3218 daemon services run in kernel space.
Dynamic content, such as one or more dynamically generated objects, can be generated by servers, referred to as application or source servers 30 and / or back-end databases that process object requests from one or more clients 10, local or remote, as described in figure 1A. As those applications or databases process data, including data related to entries received from customers, the response objects presented by these databases and applications may change. The previous objects generated by those applications or databases on a source server will no longer be new and therefore should no longer be cached. For example, given the same set of entries, an object dynamically generated from a first instance may be different from an object dynamically generated from a second instance. In another example, the same object can be generated dynamically with a different set of entries, so that a first instance of the object is generated differently than a second instance of the object.
In order to obtain an improved network performance, the 1250 appliance is designed and configured to address the problems that arise when caching dynamically generated content through a variety of methods, as described in detail below. In some of the modalities described here, the 1250 system incorporates a set of one or more techniques to make it more efficient and effective to invalidate dynamically generated content stored in the cache. Furthermore, the apparatus can incorporate techniques for carrying out control and caching for quick fills. Cache memories typically store any response to a request for an object, as long as that response is not marked as non-cacheable. As described here, efficient caching of dynamically generated content requires techniques that allow the timely invalidation of objects in cache memory that have only
178 a change on the origin server. A timely invalidation allows the cache to avoid presenting deteriorated content - a task of particular concern with dynamically generated content, especially when changes to the content go irregularly. Various techniques are set out below to ensure timely invalidation of dynamically generated content.
The. Integrated functionality
In one aspect, caching dynamically generated objects relates to function integration techniques, logic, or the operations of the 3232 cache manager, the 3236 policy agent, the 3234 encryption agent, and / or the compression agent. 3238 multiple protocol with the 3240 high-speed layer 2-7 integrated packet agent packet processing operations in response to the 3242 packet processing timer. For example, 3232 cache manager operations can be performed at the 3242 packet processing timer time intervals used for packet processing operations, such as receiving or transmitting a network packet. In one embodiment, by integrating with packet processing operations and / or using the packet processing timer, the 3232 cache manager can cache objects with low expiration times up to very short time intervals, as will be described in more detail below. In other embodiments, the 3232 cache manager in response to the 3242 packet processing timer can also receive an invalidation command to invalidate an object in a very short period of object caching.
The 3300 method described in figure 28A illustrates one embodiment of a technique for requiring the 3232 cache manager, the 3236 policy agent, the 3234 encryption agent and / or the 3238 multiple protocol compression agent to perform an operation during a processing or in association with the time intervals for processing a network packet by the layer 2-7 integrated packet agent of
179 high speed or 3240 packet processing agent. In a brief overview, in step 3310 of method 3300, device 1250 receives a network packet or is required to transmit a network packet. In step 3315, device 31250 requires the paco5 t and 3240 processing agent to process the network packet in response to packet processing timer 3242. As part of or associated with packet processing operations, at step 3320, packet processing agent 240 requests that cache manager 3232, policy agent 3236, encryption agent 234 and / or compression agent multiple protocol 3238 3238 perform an operation on a cached object. In step 3325, the cache manager 3232, the policy agent 3236, the encryption agent 234 and / or the multi-protocol compression agent 3238 performs the requested operation, which can include any or a combination of the techniques described here . In one embodiment, the cache manager 3232 determines an invalidation of a cached object, and marks the cached object as invalid. In some embodiments, the 3232 cache manager discards the invalid object in response to a request by the 3240 packet processing agent. As the 3232 cache manager is performing these operations in response to the 3242 packet processing timer, object invalidation can occur in time periods of the order of milliseconds and with objects having an expiration in the order of the time intervals provided by the timer 3242 packet processing time, such as 10 ms.
In more detail of method 3300, in step 3310, the apparatus 1250 receives one or more network packets, and / or transmits one or more network packets. In some embodiments, apparatus 1250 requires to transmit one or more network packets over network 40 or network 40 '. In another embodiment, the apparatus 1250 receives a packet of 30 network on a 3266 port and transmits a network packet on the same port 3266 or on a different port 3266 '. In some embodiments, the 3240 packet agent from the 1250 appliance transmits or requests to transmit
180 one or more network packets. In one embodiment, the apparatus 1250 receives or transmits a packet on a first network 40, while in another embodiment the apparatus 1250 receives or transmits a packet on a second network 40 '. In other embodiments, the apparatus 1250 receives and transmits packets on the same network 40. In some embodiments, the apparatus 1250 receives and / or transmits network packets to one or more clients 10. In other embodiments, the apparatus 1250 receives and / or transmits network packets to one or more servers 30.
In step 3315, device 1250 can request or trigger packet processing operations from packet processing agent 3240 upon receipt of a network packet on network port network port 3266 of device 1250 or upon a request to transmit a network packet from device 1250, or by any combination of receiving and / or transmitting one or more network packets. In some embodiments, the packet processing operations of the 3240 packet processing agent are triggered by a signal provided by a 3242 packet processing timer. In one embodiment, the 3242 packet processing timer can provide a timer functionality triggered by interruption or triggered by an event related to the reception and / or transmission of one or more network packets. In some embodiments, the 3242 packet processing timer is triggered by a rate of receiving and / or transmitting network packets through device 1250 or by the rate at which each packet or batch of packets is processed. As such, the 3242 packet processing timer can be triggered and reset after each set of one or more packet processing operations. In another embodiment, the 3242 packet processing timer provides time slots, equal or varying time slots, for triggering, activation or signaling for the 3240 packet processing agent to perform a function or operation, such as handling a received packet or the transmission of a submitted packet. As discussed above with respect to device 1250 of figure 27, the timer
181 packet termination 3242 can operate in the order of milliseconds, such as causing time intervals or triggering packet processing operations at intervals of 10 ms or less. The granular timer functionality of the package processing timer can be provided in a number of ways and used in operations of the package processing operations of the 3240 package processing agent.
In step 3320 of method 3300, the 3240 packet processing agent requests that one or more of the 3232 cache manager, the 3236 policy agent, the 3234 encryption agent, and / or the 3238 multi-protocol compression agent perform a operation. In one embodiment, the 3240 packet processing agent or the 3242 packet processing timer generates a signal or signals for one or more of the 3232 cache manager, the 3236 policy agent, the 3234 encryption agent and / or the 3238 multiple protocol compression agent. The 3240 packet processing agent can request or signal the operation at any point before, during or after a packet processing operation of a network packet, or one or more packets. In one embodiment, the packet processing agent 240 makes the request by firing the 3242 packet processing timer or expiring a time interval provided by the 3242 packet processing timer, and before performing a processing operation. packet in a network packet. In another embodiment, in the course of carrying out one or more package processing operations, the 3240 package processing agent makes the request. For example, during the execution of an operation, such as in a function call, packet processing agent 240 can make an application programming interface (API) call to one of the 3232 cache manager, the policy 3236, encryption agent 3234 and / or multiple protocol compression agent 238. In other embodiments, the 3240 packet processing agent makes the request upon completion of a network packet processing operation.
182
In step 3325, the requested operation is performed by one or more of the 3232 cache manager, the 3236 policy agent, the 3234 encryption agent and / or the 3238 multiple protocol compression agent. In some embodiments, any functionality or operation provided through the 3204 kernel may be required to be performed, such as through a kernel application programming interface (API). As such, any of the functions of the 1250 device can be performed in conjunction with the packet processing sync or sync intervals via the 3242 packet processing timer. In some embodiments, the requested operation is performed synchronously and in together with the package processing operations of the 3240 package processing agent. For example, packet processing operations wait and continue upon completion of or in response to the requested operation. In other modalities, the requested operation is performed asynchronously with the package processing operations. For example, the 3240 packet processing agent sends a request to perform the operation, but does not block or wait to receive a response from the operation. As will be discussed in more detail in conjunction with the 3350 method described in Figure 28B, the 3240 packet processing agent can request that the 3232 cache manager perform any cache management functions, such as checking for expiration or invalidation of observation, marking objects as invalid, or discarding invalid or expired objects.
In some embodiments, the packet processing agent 3240 at step 3320 sends multiple requests, such as a first request to cache manager 232 and a second request to encryption agent 3234. In other embodiments, the packet processing agent 3240, in step 3320, sends a single request comprising multiple requests to be distributed by the 1250 device, such as via the 3230 kernel to the intended component of the 1250 device. In one embodiment, the requests are subsequently communicated
183 each other. In another mode, requests can be dependent on the status, result, success or completion of a previous request. For example, a first request for policy agent 3236 can be used to determine a policy for processing a network packet from another device or a user associated with the network packet. Based on a 3236 policy agent policy, a second request to the cache may or may not be made, depending on a result of the first request. With the 3232 cache manager, the 3236 policy agent, the 3234 encryption agent and / or the 3238 multiple protocol compression agent integrated in the 3204 kernel space of the 1250 device with the 3240 packet processing agent, there are several operations device 1250, as described here, which can be triggered by and integrated with packet processing operations.
B. Invalidation Granularity
In another aspect, caching dynamically generated objects is related to and incorporates the ability to set the expiration time of objects stored by the cache for fine granular time intervals, such as the granularity of time intervals provided by the processing timer of package. This feature is referred to as invalidation granularity. As such, in one embodiment, objects with low expiration times up to very short time intervals can be cached. In one embodiment, the cache manager in response to a packet processing timer can also receive an invalidation command for invalidating an object in a very short period of object caching. By providing this fine granularity at expiration time, the cache can cache and present objects that change frequently, sometimes even many times in a second. One technique is to leverage the packet processing timer used by the device in a mode, which is capable of operating in increments of time on the order of milliseconds, to allow for a
184 invalidation granularity or low expiration of up to 10 ms or less. Traditional caches, in contrast, typically do not regulate expiration or invalidation granularity in less than a second.
Referring now to Figure 28B, an embodiment of a 3350 method is described for invalidating or expiring an object cached in response to the 3242 packet processing timer and / or the 3240 packet processing agent. in some embodiments, cached objects can be invalidated or expired in the order of milliseconds, such as 10 ms or less. In an overview, in step 3355 of method 3350, the cache manager 3232 receives a signal or request to perform an operation through the 3240 packet processing agent, in response to the 3242 packet processing timer. In step 3360 , the 3232 cache manager determines whether a cached object, such as a dynamically generated object, is invalid or expired '. In step 3365, if the object is invalid, the 3232 cache manager will mark the object as invalid, and in step 3370 it will discard the invalid object from the 3232 cache manager.
In more detail from step 3355, in some embodiments, the 3232 cache manager can be flagged or requested to perform a cache-related operation at any point in time during network packet processing. In one embodiment, in step 3355, cache manager 3232 receives an operation request before processing a network packet received or to be transmitted by device 1250. In one embodiment, the 3232 cache manager receives an operation request upon completion of processing a network packet. For example, the 3240 packet processing agent completes the processing of a network packet, and before waiting for the next 3242 timer time interval or before the next packet is processed, it requires the cache to perform an operation. In other embodiments, during a packet processing operation, the 3240 packet processing agent communicates a request for
185 operation for the 3232 cache manager. In another embodiment, the 3232 cache manager receives a signal, such as from the 3240 packet processing agent or the 3242 packet processing timer to fire the 3232 cache manager to the carrying out an operation. In some embodiments, the sign indicates to invalidate a cached object or to expire an expiration of a cached object.
In some embodiments, the 3232 cache manager may receive a request to perform a cache operation from an entity external to the 3232 cache manager, such as a request to invalidate an object communicated by a server 30, and processed by the agent 3240 package processing. In one mode, the 3232 cache manager can receive an invalidation request in 10 ms or less of object caching, while in another mode, as short as 5 ms, 2 ms or 1 ms. In other embodiments, the 3232 cache manager can perform a cache operation in response to the operations or functionality of the 3232 cache manager, such as the expiration of a timer, to cause an object to be invalidated or while processing any cache command. In other embodiments, the 3232 cache manager uses the 3242 packet processing timer on the 1250 device to trigger cache operations. For example, the 3242 timer can trigger or signal the cache to check for an invalidation or expiration of an object stored in the cache in any time interval capable of being set by the 3242 timer. In one mode, the 3242 timer can be set to trigger or signal the cache in 10 ms or less to be regulated, or in another mode, as short as 5 ms, 2 ms or 1 ms to be regulated. In some embodiments, the origin server 30 can regulate the object's expiration time. In other embodiments, device 1250 or client 10 can regulate the object's expiration time.
In step 3360, cache manager 3232 determines the invalidation or expiration of an object stored in the cache. In some fashion
186 lities, a cached object is invalidated based on a timer expiring. In one embodiment, the 3232 cache manager can issue an invalidation command on an object based on the expiration of a timer. In another embodiment, the cached object is automatically invalidated by the 3232 cache manager, in response to the expiration of a timer, such as a timer set with the 3242 packet processing timer. In some embodiments, in response to the 3242 packet processing timer, the 3232 cache manager checks for the expiration of any timers for cached objects. In one embodiment, the 3232 cache manager determines that an object timer has expired, while in another embodiment, the 3232 cache manager determines that the object timer has not expired. In an additional embodiment, the 3232 cache manager in response to a second trigger or second 3242 packet processing timer time interval will check a second time whether a previously cached object timer has expired.
In some embodiments, the 3232 cache manager parses, interprets, accesses, reads or otherwise processes an invalidation command or a request to identify the object for invalidation in the cache. In one embodiment, an entity external to the 3232 cache manager issues an invalidation command to the 3232 cache manager to invalidate the object. In another embodiment, the external entity can issue the invalidation command in response to a 3242 packet processing timer. If the object is valid and / or has not been invalidated, the 3232 cache manager will invalidate the object in response to the request . In some embodiments, the invalidation request processed by the 3232 cache manager is in response to the 3240 package processing agent's package processing operations processing the request, which in turn may be in response to the package 3242.
In step 3365, the 3232 cache manager marks the object
187 as invalid. The 3232 cache manager can mark each object as invalid in any appropriate or desired manner. In one mode, an object is marked as invalid by regulating an indicator (flag), attribute or property of the stored object. For example, an indicator (flag) can be set to any value identifying for the 3232 cache manager that the object is invalid. In another mode, an object can be marked as invalid by moving the object to an area or portion of the cache for storing invalid objects. In other modalities, the 3232 cache manager can identify or track the invalid and / or valid state of an object stored by a database or a linked list or any type and form of data structure. In some embodiments, the 3232 cache manager uses one or more objects to identify or track the validity or invalidity of one or more objects stored in the cache. In another mode, the object is marked as invalid by changing, modifying or altering the stored object, for example, by deleting or removing a portion of the object so that it cannot be used, or by changing or mutilating of the object name.
In step 3370, the cache manager 3232, in some modalities, discards from the cache those objects marked as invalid. In another embodiment, the 3232 cache manager discards the invalid object from the cache upon request of the object, such as by a client 10. In some embodiments, the 3232 cache manager writes a copy or updated version of the above object to the invalid object. object received after an invalidation or expiration of the object. In another embodiment, the 3232 cache manager reuses the cache memory occupied by the invalid object by storing another or the same portion of cache memory. In yet another modality, the 3232 cache manager does not discard the object marked as invalid, but keeps the object stored in memory or in cache storage.
Although method 3350 describes an invalidation and disposal of cached objects in response to a project timer
188 packet termination and / or in conjunction with packet processing operations to provide invalidity granularity, any cache operations and any caching techniques, as well as any other 1250 device operations described here can be performed at intervals fine granular times provided by the packet processing timer. In some modalities, the invalidation or expiration of cached objects can occur in a time interval as short as 100 ms, while in another mode, a time interval as short as 50 ms. In some embodiments, the invalidation or expiration of cached objects can occur in a time interval as short as 25 ms and, in other modalities, in a time interval as short as 10 ms. Meanwhile, in other modalities, the invalidation or expiration of cached objects can occur in a time interval as short as 5 ms, and even in additional modes, in a time interval as short as 3, 2 or 1 ms.
By incorporating the ability to invalidate objects after very small time increments, as described in methods 3300 and 3350, together with figures 28A and 28B above, an enhanced caching of dynamically generated objects is enabled. Some dynamic content is in fact conducive to being stored and presented from a cache for very short periods of time. In order to successfully cache this content, however, an approach according to one modality provides for object caching for very short periods of time, before the object is invalidated and discarded from the cache memory. For example, certain dynamically generated objects can be cached for as long as 1 second, but anything longer is often unacceptable for content that is constantly changing. In one embodiment, 30 the approach included invalidating or expiring cached content after small fractions of a second. As an example, if an application takes 100 milliseconds to generate a dynamic response,
189 then, the cache can store and present that response for a duration less than or equal to the 100 millisecond period, without compromising the freshness of the data. There will be no new object generated during that 100 millisecond period, because it is shorter than the time it takes to generate a new object. The apparatus 1250 can thus be configured to display the previous object for that duration. The ability of the 1250 apparatus to invalidate really very small time increments is often useful for application environments where the database transaction isolation level is regulated to allow Repeatable Readings or Serialized Reads.
ç. Invalidation Commands
Traditional caching technology invalidates stored content based on a predefined expiration time for the content, which is typically configured by the administrator or received from the server that presented the object. Another technique for content invalidation is described below, in order to more efficiently cache dynamically generated content. One technique includes the ability to receive on the 1250 apparatus an invalidation command that identifies one or more of the objects previously stored in the cache as invalid in real time. For example, the invalidation command can be communicated via a network packet transmitted to the client or an application programming interface (API) call made by a server to the system. This differs from the traditional approach in that the server simply regulates a cache expiry time that it includes in the object header at the time the object is presented.
One technique is illustrated more specifically in figures 29A and 29B. 29A is a flow chart illustrating a method for maintaining a cache, such as a computer memory cache. In a brief overview and according to step 3410, the dynamically generated objects previously presented from a source server 30 are stored in the cache. For example, the dynamically generated object can
190 not be identified as cacheable or otherwise include any cache or cache control information. In step 3420, an invalidation command is received in the 3232 cache or cache manager. The invalidation command identifies one or more objects previously presented as invalid. In step 3430, in response to the invalidation command, the 3232 cache or cache manager marks the object identified as invalid.
In more detail, in step 3410, the 3232 cache manager stores a dynamically generated object received, obtained or communicated from any source in a cache element. In some modalities, the dynamically generated object can be generated and presented from a server 30. In other modalities, the dynamically generated object can be generated and communicated by a client 10. In some embodiments, another portion, component or process of the 1250 apparatus generates the object and stores the object in the cache. In additional embodiments, the dynamically generated object can be generated by another 1250 appliance or another computing device on the network and transmitted or communicated to the 1250 appliance. In some embodiments, the dynamically generated object is not identified as cacheable or identified as not cacheable. In other embodiments, the dynamically generated object is identified as cacheable or is under cache control.
In step 3420, the 3232 cache manager receives an invalidation command identifying an object as invalid, such as a dynamically generated object stored in the cache. In one embodiment, the invalidation command can comprise any type of directive or instruction indicating to the cache that an object is invalid or may otherwise be damaged. In some embodiments, the invalidation command identifies the object and can also identify the time when the object is invalid, as well as which portions of the object may be invalid. In one embodiment, the 3232 cache manager provides an application programming interface (API) that can be called up remotely by a server
191 of origin 30. In some embodiments, the 3232 cache manager can provide any type and form of protocol for receiving commands and responding to commands through one or more network packets. In one embodiment, the 3232 cache manager or 1250 device provides an Extensible Markup Language (XML) API interface for receiving and processing invalidation commands. For example, the 3232 cache manager can provide a service interface from web. In some embodiments, the 3232 cache manager responds to the invalidation command by sending an acknowledgment, status, or other response to the origin server 30. In other modalities, the 3232 cache manager does not respond to the invalidation command. In one embodiment, an object is marked as invalid if an application running on a source server 30 performed an action that caused the stored object to deteriorate, such as by a new or updated version of the object. This could happen, for example, when new editors make changes to a rapidly developing story and therefore want to be certain that the latest version of the story is being presented to customers.
Invalidation commands can be issued from a source server by the application that generated the object, by another server 30 or by another 1250 appliance. In one embodiment, source server 30 issues or communicates an invalidation command to the 3232 cache automatically, in response to a change to the dynamically generated object on the source server 30. The invalidation command can also be generated by an administrative control external or external to server 30 and device 1250. For example, administrative control can be any type and form of program or application running on the network and communicating with device 1250, such as an administrator console. Furthermore, a client 10 could issue or communicate an invalidation command to the 1250 appliance or the 3232 cache manager. For example, if the client needed to perform an action that client 10 recognized that would cause a change in the requested objects on the origin server, the client could communicate the invalidation command. Any
192 cached object can be invalidated by passing a user command executed locally in the cache to the cache or invoked remotely using the XML API infrastructure.
According to step 3430, a cached object, for example, a previously generated dynamically generated object, which has been identified as invalid is marked as such in response to the invalidation command. An invalid object will not be provided for a client requesting from the cache, but, instead, it would be presented directly from the origin server. The 3232 cache manager can mark any object as invalid in any appropriate or desired manner. In one mode, an object is marked as invalid by regulating an indicator (flag), attribute or property of the stored object. For example, an indicator (flag) can be set to any value identifying for the 3232 cache manager that the object is invalid. In another mode, an object can be marked as invalid by moving the object to an area or portion of the cache for storing invalid objects. In other modalities, the 3232 cache manager can identify or track the invalid and / or valid state of an object stored by a database or linked list or any type and form of data structure. In some embodiments, the 3232 cache manager uses one or more objects to identify or track the validity or invalidity of one or more objects stored in the cache. In another mode, the object is marked as invalid by changing, modifying or altering the stored object, for example, by deleting or removing a portion of the object so that it cannot be used, or by changing or mutilating of the object name.
In some embodiments, the 1250 apparatus subsequently discards objects marked as invalid from the cache. In another modality, the apparatus 1250 discards the invalid object from the cache upon request of the object, such as by a client 10. In some modalities, the apparatus 1250 writes an updated copy or version of the object onto the invalid object. In another modality, the equipment
193
1250 reuses the cache memory occupied by the invalid object by storing another dynamically generated object for the same portion of the cache memory.
With the 3232 cache manager command invalidation API, any computing device or user in communication with the 1250 appliance can request to invalidate an object, such as a dynamically generated object, stored in the cache. As such, the invalidation of cached objects can be controlled in real time, instead of using expiration times or invalidation of predetermined settings. Thus, using these techniques, the longevity of cached objects can be controlled from external application processing nodes, such as databases or source application servers. For example, the 1250 appliance can be configured to work with a database so that a change in the database automatically triggers an invalidation command from the database (or application) to the 1250 appliance for disposal of an object or objects in particular.
d. Invalidating Groups Using an Invalidation Command
In an additional modality, the 1250 apparatus identifies and invalidates a group of objects stored by the cache at the same time. Objects stored in a traditional cache memory are each treated individually by the cache when determining whether the object is deteriorated. As each object reaches its specified expiration time (usually as regulated by the server and stored by the cache in a table), that item is discarded from the cache memory. This traditional approach is inefficient and ultimately insufficient, however, to successfully deal with the challenges that arise in trying to cache dynamically generated content.
Figure 29B illustrates another modality of a method for maintaining a cache, such as a computer memory cache, where the 1250 apparatus has the ability to create, store and invalidate groups of related objects that were previously presented from
194 from a source server 30. In a brief overview, in step 3410, an object, such as a dynamically generated object presented from a source server 30, is cached. In step 3412, the cache manager 3232 forms a group of previously presented objects stored in the cache. In one embodiment, the group can be associated with or identified by one or more object determinants, as will be described in greater detail below. In step 3414, the 3232 cache manager maintains a record of the object group. In step 3422, the 3232 cache manager receives an invalidation command to invalidate the object group. In step 3432, the 3232 cache manager marks the object group as invalid in response to the invalidation command.
Step 3410 is the same as in figure 29A, where an object is stored in the cache of the device 1250, such as dynamically generated objects previously presented from a source server 30. In some embodiments, one or more objects may not be identified as cacheable, or otherwise may not have any cache or cache control information. For example, server 30 may assume that dynamically generated objects will not be cached.
According to step 3412, the apparatus 1250 forms a group of a set of objects previously presented from the origin server 30 and stored in the cache. Any suitable or desired set of objects can be associated with each other to form a group. For example, any dynamically generated objects generated for or associated with a web page presentation can form a group. In other embodiments, a group of objects can form a subset of other object groups. In some modalities, the group formed of objects can have objects presented from the same server 30, while in other modalities the group formed of objects has objects presented from different servers 30. In additional modalities, the group of objects can comprise objects from a client 10, objects from a server 30, or objects generated by or presents
195 from clients 10 and servers 30. In one embodiment, an object in the group is static, while another object in the group is generated dynamically. In some cases, an object in the group is not identified as cacheable, while another object in the group is identified as cacheable. In other cases, the objects in the group can be logically related, according to a feature or an application provided by a server 30. In another case, the objects in the group can be related to the same client 10 or the same user.
In step 3414, an object group record is maintained. Various techniques for recording and maintaining a record of a group of objects, or associating another form of objects, can be used in the practice of some types of operations described here. In one embodiment, the record can be kept directly, for example, in a lookup table. In other modalities, the records could be represented in a hash table format. In some embodiments, the 3232 cache manager maintains the association of objects in a database, or a data structure or object in memory. In additional modalities, an indicator, a property or an attribute of each object in the group is assigned or set to a value identifying the group, such as a value equal to, identifying or referencing the name or identifier of the group, such as a determinant of group object that will be described in more detail below. In some embodiments, a group of objects is arranged, placed or located in a portion of cache memory identified as maintaining the group.
In step 3422, an invalidation command is received on the device 1250 or on the 3232 cache manager. According to the modality described in figure 29B, the invalidation command identifies that one or more objects are invalid or are otherwise damaged. In some embodiments, the invalidation command references, identifies or specifies a name or identifier for the group of objects. In one embodiment, the invalidation command comprises a single invalidation request to invalidate all objects in the group. In another modality, the
196 invalidation command identifies an object in the group to be invalidated. In other embodiments, the invalidation command comprises a plurality of invalidation requests for invalidating a plurality of objects in the group.
According to step 3432, the previously presented group of objects is marked as invalid if an invalidation command references, identifies or specifies an object in the group as invalid, each object in the group as invalid or the group as invalid. In some embodiments, if the invalidation command identifies an object in the group as invalid, the 3232 cache manager will mark the object as invalid. In other embodiments, if the invalidation command identifies an object in the group as invalid, the 3232 cache manager will mark the object group as invalid or each object in the group as invalid. Still in additional modalities, the 3232 cache manager can only invalidate the object group when a plurality of objects is identified as invalid through one or more invalidation commands. In another mode, the invalidation command can specify a group name or identifier, and the 3232 cache manager marks the group as invalid, or each object in the group as invalid.
In one embodiment, the apparatus 1250 or the cache manager 3232 discards from the cache memory a group of objects that has been marked as invalid. In some embodiments, objects in the group can be discarded from cache memory only when each object in the group is marked as invalid. In other ways, if an object in the group has been marked as invalid, then the entire group will be discarded. In another mode, the group of objects, or any object in the group, marked as invalid can be discarded upon receipt of a requisition for the group of objects, or any object in the group, by a client 10. In other modalities, the group of objects, or any object in the group, marked as invalid, can be discarded upon receipt of a response from a server 30 providing one or more new objects in the group.
197
An example of the modalities described above follows. Consumer resource management (CRM) applications are used by many companies to monitor and evaluate all aspects of resource management. CRM applications are often implemented and accessed over private or public networks, including the Internet. These applications, which provide access to large amounts of data, are frequently being accessed, thereby benefiting from caching the data generated by these applications. For example, sales reports are often generated and presented to users connected remotely. These sales reports are assembled by a relevant application by compiling data from sales information that is posted to such application servers and / or their underlying databases. Since many users request the same document (that is, a given sales report), without caching, the application server must generate the object for each request. If, however, such objects can be stored in the cache, then database application processing will be conserved, including potentially valuable bandwidth, since the cache is placed closer to the requesting clients.
The challenge for caching these objects arises because each time a new sale is posted to the application running on the origin server (or in its underlying database), the information in the sales report needs to be updated. As a result, all sales reports that may have been stored in any caches supporting these application servers must be invalidated and the contents discarded from the cache. The traditional approach to caching, however, has no way of accurately determining when the change in the underlying database or application is about to occur and therefore cannot reasonably assess the freshness of dynamic content. Every time a change occurs in a source database or application or server, the cache must be able to identify which change was made, and which group of
198 be invalidated as a consequence of this change. The generation of invalidation commands that contain object determinants linked to previously presented groups of objects, as described above, can be adapted to this need.
and. Identification of Object Determinants in a Customer Request or Response
One modality also addresses the need to be able to identify all objects affected by a change of state on the originating application server 30 (and / or an underlying database) by generating object clusters and implementing a parameterized invalidation. In this modality, any predefined object or group of objects can be invalidated by an HTTP request intercepted, for example, from a client, which the cache parses in order to identify an object determinant. The term object determiner refers to any information, data, data structure, parameter, value, data standard, request, response or command that references, identifies or specifies an object or a set of objects, in a unique or other way form. In some embodiments, an object determination is a pattern of bytes or characters in a communication that can be associated with an object or used to uniquely identify the communication that is associated with or referencing the object. In one embodiment, an object determiner indicates whether a change has occurred or will occur, on the source server, for a group of previously presented objects stored in the 3232 cache manager with which the object determiner is associated. In some embodiments, the objects in a group of objects are related because they are associated with at least one object determinant. Specific non-limiting examples of object determinants and additional illustrations of their use are described more fully below.
In some modalities, of the present modality, object determinants are certain predefined parameters or data structures included or embedded in a customer request or response. In others
199 modalities, the client 10, the server 30 or the apparatus 1250 incorporates in one communication one or more object determinants, such as predefined strings or character sets representing the object determinant. Object determinants indicate whether this request will have the effect of causing a change in the state of objects stored on the source server 30 or in databases linked to it. In one embodiment, the existence of the object determinant in a request indicates that a change has occurred or will occur in an object. In another mode, the syntax, structure, parameter or value of the object determiner indicates that a change has occurred or will occur in an object. In one embodiment, the cache receives an object request from a client 10. The request may include certain parameters or values (object determinants) that the cache recognizes that will change the state of the origin server or the application server which, as a consequence, will deteriorate certain related objects stored by the 3232 cache manager that had previously generated by such source server or application server 30. Depending on the invalidation policy established by the user, the parameters (object determinants) may require an invalidation of one or more previously presented objects or groups of objects, by the origin server, which have been stored by the cache. The cache is configured to identify the relevant objects that will be affected by the cache. The cache is configured to identify the relevant objects that will be affected by this change of state (that is, those objects or groups of objects linked to the object determinant) and to invalidate these objects through the method, marking each object as invalid and / or discarding such objects from cache memory.
The technique described above is illustrated in figure 29C. As with other modalities described here, step 3410 comprises caching objects, such as dynamically generated objects, previously presented from a source server. The objects could be generated by an application running on the origin server 30, or they could be removed, for example, from a database accessed by
200 source server 30. In some embodiments, dynamically generated objects are identified as non-cacheable or otherwise not identified as cacheable.
According to step 3421, the cache intercepts or otherwise receives communication between the client and the server, such as a request from a client or a response from a server. In some modalities, the request is for a specific object, the object having previously been presented and stored in the cache. In another mode, the communication includes a response from a server having a requested object. In one embodiment, this reception or interception occurs in accordance with an established caching protocol and communications standards. Although the 3232 cache manager or the 1250 appliance can generally be described as receiving a request, response or communication, upon receiving that request, response or communication, the 3232 cache or the 1250 appliance can intercept or obtain by any means and / or mechanisms appropriate to the request, response or communication, although not communicated directly or explicitly to the cache.
In step 3423, an object determinant is identified in the intercepted communication. The 3232 cache manager can extract, interpret, parse, access, read or otherwise process intercepted communication to determine or identify one or more object determinants in communications. Any parameter, value, syntax, data, structure or set of one or more characters of the communication can be used to identify an object determinant. In one embodiment, the 3232 cache manager can identify the name or identifier of an object in a request from client 10 to server 30, where the client requests the object. In another embodiment, the 3232 cache manager can identify the name or identifier of a first object in client request 10 or a response from server 30 that indicates that a change has occurred or will occur in a second object stored in the cache. In other modalities, the 3232 cache manager from
201 ends if any character patterns in the request match any object determinants associated with an object or group of objects in the cache. In some embodiments, an object determinant can be determined for an object not currently cached. In other embodiments, an object determinant can be determined for an object currently marked as invalid. In other embodiments, an object determinant for a requested object is determined to be associated with an object determiner for a cached object. In yet another modality, upon the first reference, request or response of an object in a communication, the cache manager 3232 establishes the object determinant identified as the object determinant for the object.
By receiving and parsing the communication, such as a client request or a server response, to identify an object determinant, the 3232 cache manager or the 1250 appliance can effectively determine whether to mark an object as invalid cached that was associated with the identified object determinant. Thus, according to step 3425, a determination is made as to whether the object determiner indicates a change in the cached object. In some modalities, the determinant of the identified object may be part of a communication that does not alter, modify or generate an object. In other embodiments, the identified object determinant is a part of a communication that indicates that a change has occurred or will occur in the object associated with the object determinant. For example, communication can be obtaining a request for a dynamically generated object or a submission request that will change the data used for one or more dynamically generated objects. In some modalities, the existence of the object determinant in the communication indicates that a change has occurred or will occur in one or more objects. In another mode, the type or name of a command, a directive or an instruction in the communication together with the object determiner indicates that a change has occurred or will occur in one or more objects. Still in an additional modality, the
202 The existence, value or setting of a parameter or variable of a command, directive or instruction indicates that a change has occurred or will occur in one or more objects associated with an object determinant.
In other embodiments, the 3232 cache manager performs a hash function, an algorithm, or an operation on the intercepted communication or on the object determiner to determine whether a change has occurred on the object. In some embodiments, the hash value is compared with a previously stored hash value for the object and, if different, then the 3232 cache manager recognizes that the object has changed. In yet another modality, a hash value for the object can be included in the communication or in the object determinant. In one mode, the communication indicates that the object has changed by the value or the regulation of a parameter, such as a Boolean indicator (flag). In other modalities, an entity tag control and a validation mechanism, as described in greater detail below, can be used to identify an object and to determine whether the object has changed.
If a change is indicated, then, at step 3431, then the object associated with or identified by the object determinant will be marked as invalid. In some modalities, an object requested by the intercepted communication is marked as invalid according to step 3431, and retrieved from the origin server 30, according to step 3440. Otherwise, in other modalities, the requested object is recovered from the cache according to step 3450. In one mode, any object marked as invalid will be dropped from the cache.
f. Invalidation of Object Groups Based on Object Determinants
The above modality describes the case of invalidation of an object previously presented in the 3232 cache manager, based on the identification of an object determinant in the client request. This general concept can also be used, in another mode, for the identification and invalidation of a group of objects with which one or more object determinants have been associated. This modality is illustrated in figure 29D.
203
The method described in figure 29D starts in the same way as the method in figure 29C. Step 3410 comprises storing objects in the cache, such as dynamically generated objects previously presented from a source server. In some embodiments, one or more of the objects are not identified as cacheable. According to step 3412 and similarly to figure 29B, the objects previously presented are formed in groups. In one embodiment and according to the object determinant technique, a group of objects is associated with or identified by at least one object determinant. As more fully described below, in some embodiments, the association of groups with object determinants depends on the nature and details of the user caching policy, such as a policy defined, controlled, or used by the policy agent 3236. In another embodiment, one or more object determinants of the group comprise one or more object determinants of the objects in the group. In another embodiment, the group object determinant comprises a combination of object object determinants in the group.
According to step 3414, a record is kept of the group, along with its associated object determinants, if applicable. This step is similar to step 3414, illustrated in figure 29B. In one embodiment, the record and / or any object determinants in the group are kept in a lookup table. In other embodiments, the record and / or any object determinants in the group can be maintained in a hash table format. The hash table can be designed to efficiently store non-contiguous keys that can have wide spaces in their alphabetic and numeric strings. In another embodiment, an indexing system can be built on top of a hash table. Material thickness Some modalities, the cache manager 232 maintains the association of objects as a group of one or more object determinants in a database, or a data structure or an object in memory. In additional modalities, an indicator (flag), a property or an attribute of each object in the group is assigned or regulated for a va
204 lor identifying the group, such as a value equal to, identifying or referencing the name or identifier of the group, or a determinant of group object. In some embodiments, a group of objects is arranged, placed or located in a portion of cache memory identified as maintaining the group. In another mode, one or more object determinants are stored in association with the object group.
Steps 3421 and 3423 are similar to steps 3421 and 3423, as shown in figure 29C. According to step 3421, cache manager 3232 or apparatus 1250 intercepts or otherwise receives communication between client 10 and server 30, such as a request from a client for an object previously presented and stored in the cache. In one embodiment, the cache manager 3232 intercepts a request from client 10 to server 30. In some modalities, the request is for an object stored in cache. In other modalities, the request is an instruction, a command or a directive to the server 30 that will cause a change to a cached object, just as it will cause an object to be generated dynamically. In another embodiment, cache manager 3232 intercepts a response from a server 30 to client 10 comprising or identifying a cached object.
In step 3423, an object determinant is identified in the intercepted communication. As mentioned above, the object determiner indicates whether a change has occurred or will occur in the requested object, on the origin server 30. However, in the modality of figure 29D, the object determinant can be associated with a group of objects. This allows for efficient invalidation of all objects stored in the cache that may be affected by a particular object determinant. In some embodiments, an object determinant of an object in the group is identified. In other embodiments, an object determinant, for example, a group object determinant, for the object group is identified. In another embodiment, a combination of object determinants of one or more objects in the group is identified.
205
Thus, according to step 3427, a determination is made as to whether the object determinant indicates a change in the group of objects previously presented. In some modalities, the existence of the group object determinant in the intercepted communication indicates that a change has occurred or will occur in one or more or all of the objects in the group. In other modalities, the name and type of a command, a directive or an instruction in the intercepted communication indicates these changes. In yet another modality, the existence, value or regulation of any parameters or variables in the communication can also indicate these changes.
If, in step 3427, the object determinant indicates a change in the group, then the group of objects previously presented will be marked as invalid in the cache, according to step 3435. In some modalities, one or more or all objects in the group are requested and retrieved from the source server 30, according to step 3440. If, in step 3427, the object determiner does not indicate a change in the group, then, in some modalities, any objects requested as part of an intercepted communication and preferably presented and stored in the cache will be retrieved from the 3232 cache manager accordingly with step 3450. In one embodiment, any object or group of objects marked as invalid can be discarded by the cache's 3232 cache manager.
g. Group Designation
The cache administrator can specifically designate which objects are included in a particular group. Whenever an object is cached, the administrator can make that object a member of one of the configured or implicit groups, depending on the configuration. The configured groups can be based on settings that an administrator has previously established or, alternatively, based on application behavior and other data related to an object invalidation. An object can also be part of an implicit group, if its configured group is dynamic. Objects in the implicit group
206 are grouped by the value of the significant invalidation parameters.
By allowing a very flexible grouping of objects, a cache can achieve a level of flexibility and coordination in the invalidation that is required to cache dynamically generated content. The cache can invalidate a very specific group of objects simultaneously, thus making the cache more likely to respond to the frequent need to invalidate dynamically generated content. The moment the cache assigns an object to a group, the group determines several things in relation to that object, including invalidation parameters and hit determinants, in order to associate one or more object determinants with it.
In the consumer resource management (CRM) example, the cache administrator can pre-designate each of the groupings. For example, the administrator configures the cache to group each of the sales departments by name. Thus, the administrator can designate an automobile department, a motorcycle department, etc., and each time an object determinant is recognized in a request coming into the cache, the cache can then invalidate all objects in a designated group linked to an appropriate department via the object determiner.
H. Rule Based Grouping
Alternatively, the cache administrator can establish rules that allow the cache appliance to determine by running which objects to include in a particular group or groups. These rule-based groupings can rely on the designation of groups by virtue of established rules that link the object to the significant object determinants that the cache uses to create the relevant groups. An example of this approach may involve setting up the setting in each group.
Again going back to the CRM example, a rule may state that each Sales Department subdivision that is established in the application must be recognized by the cache as its own grouping. In this way, groupings can be created without the administrator of
207 cache has to specifically identify each cluster, but allows the cache to determine based on the relevant rules. This technique creates a more flexible and often less labor intensive way of designating clusters. The cache administrator could set up a rule that states that any subdivision of the sales department (ie sales \ auto, sales \ motorcycle, etc.) must have generated a new grouping by the cache. As a request from the Auto Sales Department is processed and returned by the application through the cache, the cache can recognize each sales subgroup and automatically create a grouping for it, based on the preconfigured rule.
The rule can be implemented by the cache each time it sees a new request for an object of type report / sales / auto or report / sales / motorcycle, etc. This process can then be repeated when requesting a Motorcycle Sales Department showing that it is a subgroup of the Sales Department, then the Bicycle Sales Department and so on, as the cache recognizes these subgroups and establishes a grouping of object for each of them. When a known invalidation request comes from the cache linked to one of these groupings or, if a relevant object determinant is identified in a customer requisition (for example, posting a sales report for sales / motorcycle from the Motorcycle Sales Department found in the request grammatical analysis), the cache will know how to invalidate all objects stored in cache in the Motorcycle Sales Department Grouping.
Thus, when a cache recognizes that a change has occurred or will occur in the data presented by the application (because the cache recognizes that the content of a request received by the cache will trigger a change in the application or because of the occurrence of some external change), the technique above allows the cache to quickly and simply identify which objects require invalidation through the grouping process. In this way, the cache is able to invalidate large numbers of dynamically generated objects that are no longer new because of
208 changes in the state of the application or database.
The cache's ability to successfully store and display dynamically generated content from its cache memory can also be improved with an intelligent statistical agent that examines the request and response traffic pattern in order to determine, by a time period, the set of objects that would provide the greatest benefit of caching. The agent can be integrated into the cache apparatus itself, or run on a separate computer as a heuristic for selecting some subset of objects for further investigation to determine suitability for dynamic caching.
i. Additional Use of Object Determinants
As described above, object determinants can be from any data structure that indicates whether a change has occurred or will occur on the origin server, for the group of previously presented objects stored in the cache with which the object determiner is associated. Object determinants could be regulated based on predefined string values embedded in the request. For example, when a request comes with a certain USERID, the USERID can be linked to a group of objects in the cache that must be invalidated each time a post or other request comes from that certain USERID. Potential candidates for object determinants could also include using service identifiers from the server that originally presented the object. The service identifier contains a service IP address, a TCP port and a service identifier present in the HTTP request.
Another potential object determinant present in the request is a uniform request resource (URL) locator. In the case of caching of static objects, the request URL is typically sufficient to uniquely identify the object. For requests for dynamically generated content, however, the information in the URL may not be sufficient to identify the stored object
209 cached. The cache, therefore, must inspect other information in the request to find object determinants including HTTP headers, a cookie header or other custom HTTP headers. The cache can additionally search for a subset of relevant parameter information in a variety of other locations in the client request, including, without limitation: the URL query string, the POST corpus, a cookie header, or any other request or response headers.
The problem with parsing a URL for object determinants is that the URL and other headers can contain a lot of information in addition to what is relevant to the cache decision. The cache, therefore, must be able to parse a very large amount of information to be able to identify the appropriate object determinants. In addition, the data in the header is often sorted arbitrarily, meaning that there are no standardized ways for that data to be placed in the HTTP header and, therefore, a simple comparison is often insufficient to locate the relevant object determinants in that string.
If there is no preconfigured policy for combining a particular object determinant with a relevant object or group of objects stored in cache memory, the cache can still, in another mode, make a determination like this. For example, the cache can examine and parse various aspects of the request to find out if any other object determinants can be found in that request and used to link that request to particular objects stored in cache memory that should be invalidated. Alternatively, the cache could also be allowed to examine a request for certain object determinants that the cache determines, based on a certain predefined heuristic, that can be significantly linked to particular objects or groups of objects. For example, when the request comes into the cache from an update to a schedule associated with a particular USERID, a modality could be
210 configured to recognize that all cached objects with USERID equal to the USERID of the calendar update request and that contained the user's calendar for any particular day would need to be invalidated.
The cache can also assume that object determinants are present as a group of name = value or similar pairs in an order not specified in the URL core, in the queries present in the URL, in the POST corpus or in a cookie header. In one embodiment, it is assumed that the query is formatted as a list of name = value pairs. The user can therefore configure which parameter names are significant. Every cached object is keyed using its access URL first. The URL may look like /site/application/special/file.ext?p1=v1 & p2 = v2 & p3 = v3. The /site/application/special/file.ext part is at the heart of the URL. The part p1 = v1 & p2 = v2 & p3 = v3 is the URL query and contains pairs of parameter - value. These parameter - value pairs can also be present in the POST corpus or in the Cookie headers.
In a modality, the user or administrator establishes that p1 and p2 must be the invalidation parameters or object determinants. The cache thereafter will automatically group objects that have matching p1 and p2 values. One way to implement this grouping is to map p1 and p2 to primary keys in database tables, that is, objects identifiable only in the table that the cache will know how to reference in order to determine a validation status. To update something in those database tables, to reflect the fact that the data stored in the cache is no longer valid, the cache will specify new values for p1 and p2, and when the cache recognizes these new values from the next time he presents this content, he will know how to invalidate the linked objects stored in his memory. When the cache finds a request like this, when it sees the update request, it knows that it has to invalidate the group with values of p1 and p2 matching - because the cache understands that the data at the source will change,
211 thereby affecting all objects that are related to those object determinants p1 and p2.
To address the most complex case where the administrator has not pre-configured the specific parameters embedded in the request as object determinants, the cache can employ user-configured policies to extract the relevant object determinants from the request to help identify when to invalidate object groupings. The determinant string is then used to locate the group of objects stored in the cache and invalidate those objects. These object determinants can be used for configuring the cache to generate lists of significant parameter values. If an incoming write request has matching values for significant parameters, then the objects linked to those parameter names must be invalidated. Alternatively, a user could specify the policy architecture action for extracting the object determinant string from the request. The object determinant string is extracted from the write request and all objects with matching determinant strings are invalidated. In this alternative approach, a request reaches the cache, the cache makes a determination as to whether the request string matches an invalidation policy. The invalidation policy specifies objects on which a content group is to be invalidated.
Alternatively, the cache could use any other user information that may be present in the client request. As mentioned above, the integration of authentication and authorization allows the cache to access user information. The USERID or GROUPID could be one of the determinants in the event that a relevant grouping of cached objects is linked to a user or group of users. Although user information is often an important object determinant, user information may often not be present in the HTTP request. In an additional embodiment, the aspects of dynamic caching can be combined with a system and method for integrating the cache with a variety of other elements.
212 networking tools, including the ability to perform certain types of authentication, access control and audit (AAA) infrastructure. Thus, the security level agreed with the data that is generated by the applications is applied to the data that is instead presented from a cache. This technique allows applications to cache sensitive controlled access information that otherwise could not be cached.
This approach allows the cache to identify users who do not include identifiable user information in the HTTP request, but who can be identifiable through the AAA approach described in the Integrated Caching patent. Such an approach allows the cache to identify the user relevant to a particular request by examining authorization status information that can be shared from AAA processing. In an additional modality, integration allows the application of security policies to information stored in the cache, to prevent unauthorized users from accessing information stored in the cache.
This approach also addresses the challenge posed by the fact that a significant portion of dynamically generated data requires that the customer requesting that data is authorized and authenticated before the cache can respond to the relevant request from the customer. The cache must be able to authorize requests made by authenticated users, so that applications can cache controlled access objects and by integrating this dynamic caching technology with authentication and authorization information, this security can be obtained. The USERID or GROUPID will be one of the object determinants if the objects are customized for a user or group of users. Thus, the security level agreed with the data that is generated by the applications is applied to the information stored in the cache as well. This technique allows applications to cache sensitive controlled access information that could not otherwise be cached.
213
Finally, other information, such as time of day, state of the database at source, etc., can be parsed from the request and used as object determinants to determine whether objects stored in the cache are still valid. The cache can take care of this situation by configuring appropriate expiration behavior on groupings of objects that are configured to be sensitive to these external variables.
To address additionally the challenge presented by the fact that requests for dynamic content must be grammatically analyzed and interpreted by the cache, the cache according to a modality can limit which parameters are judged to be relevant object determinants for the cache. In this way, the success rate for presenting objects from the cache instead of forwarding those requests to the applicable application server can be improved. As an example, a request query from a customer can contain a city and a state parameter. However, the cache can be configured to conform to the requirements of the application for which the cache is storing content to recognize that the response can be presented to requests from customers that the query shows come from all customers in a given state, regardless of city value. For this purpose, the city parameter is not relevant, and the cache could recognize this fact. An alternative modality involves configuring the cache so that an answer can be displayed from the cache, if only the city parameter matches, regardless of what is specified for the state parameter.
In summary, the cache implements a generalized parameterized object combination. In this approach, the cache is configured to recognize the subset of information in the request that will be useful as object determinants, and that are linked to a particular object, so that when those object determinants are recognized, the cache can use the presence (or, conversely, the absence of these determinants) when assessing whether the object or group of objects remains new and
214 able to be served from the cache. The cache maintains a table that it queries each time a request arrives to check against the configured parameters, to determine whether the requested data remains new, and which also allows the cache to combine the relevant data with the appropriate stored object in cache memory, j. Incarnation Numbers
In yet another modality, the cache can use incarnation numbers to invalidate a group of objects. When a cache needs to change the state of each of a group of objects at once, because of a change in the state at the origin, the incarnation numbers provide a simple technique to effect this invalidation. While identifying each object and changing the state individually is an inefficient approach to ensuring the freshness of data stored in a cache, the use of incarnation numbers allows for a much simpler and more effective approach to invalidating groups of data. objects. The present modality describes how each object points to a data structure that represents the group and, therefore, the server only needs to send a command that changes the state in the data structure for the group. When a subsequent request for a cached object arrives from a client, the cache must first find out if the state has changed. To do this, he consults the data structure to reference whether the state has changed for the group.
In order to implement the data structure effectively, the cache must be able to determine whether to query for a change of state. Therefore, the cache must be able to determine whether it has already looked at a change of state in the group or not. This is where the incarnation numbers are useful. The cache associates dynamically generated objects with content groups. Each of these content groups can be represented through a hash table query process with a particular index value or incarnation number contained in a data structure. After that, whenever the cache receives a client request that the cache recognizes as causing a change in
215 status, the client parses the client request for relevant parameters, performs the hash query based on the recognized object determinants, and increases the incarnation index or number in the data structure. Each time an object stored in a designated grouping is requested by a client, the cache performs the hashing algorithm on the object, and compares it with the original stored value in the data structure for that content group. If the stored value is the same as the number calculated by the cache for that object, then the cache knows that the content remains new and can be presented to the requesting 10. In the event that the cache detects a discrepancy between the current calculated incarnation number for that object and the number stored for that content group in the data structure, the cache knows that the stored object is no longer fresh. The cache then invalidates the stored object and sends the request to the application server. When the response returns, the cache appliance will store the new response in cache memory and link that response back to the new data structure. After that, each time the cache receives a request for an object in that cluster, the cache can make the comparison and assuming that no further changes have been made to the data structure, 20 the cache can present the newly stored object.
By using an invalidation of a group of objects in this way, the cache is able to invalidate very quickly - and the time spent is constant, regardless of the number of objects invalidated. Through this faster and more efficient invalidation process, the techniques allow the cache to handle dynamically generated objects more effectively. The approach allows cache devices that are in front of applications to store more aggressively and display dynamically generated objects without presenting invalid or deteriorated content, due to rapid changes in that data. Mode 30 allows the cache to display data that changes frequently or in an unpredictable way, thereby improving the performance of the cache. The cache is also capable of invalidating objects and a group of objects stores
216 in memory using user commands and also by examining and grouping various types of web traffic.
2. Connection Grouping
In one embodiment, a network device 1250 (also referred to here as an interface unit 1250) frees servers 30 from much of the processing load caused by repeatedly opening and closing connections to clients by opening one or more connections to each server and maintaining these connections, to allow access to more repeated data by clients over the Internet. This technique is referred to here as a connection grouping.
For completeness, the connection grouping operation is briefly described below, with reference to figure 30. The process starts in figure 30 when a client 10 requests access to one of the servers in the server group housed by the 1250 interface unit. A connection is opened between interface unit 1250 and the requesting client, and interface unit 1250 receives the request from the client for access to the server, as shown in step 4302. The interface unit 1250 determines the identity of the requested server, as shown in step 4304. In one embodiment, this is accomplished by examining the destination network address specified by the client request. In another mode, this is accomplished by examining the network address and the path name specified by the client request.
After determining the identity of the server 30 to which the client request is to be addressed, interface unit 1250 determines whether a free connection (that is, one that is not in use) to the server is already open, as shown in step 4306. If so, processing resumes at step 4310. If not, interface unit 1250 opens a connection to the server, as shown in step 4308. Interface unit 1250 then translates the client request and passes it to the server, as shown in step 4310, and as more fully described with reference to figure 31 below. After server processing, the interface unit receives a response from the server, as
217 shown in step 4312. The server response is translated and passed on to the requesting client, as shown in step 4314 and further described below. Finally, the 1250 interface unit closes the connection to the client, as shown in step 4316. However, the connection between the 1250 interface unit and the server is not disconnected. By maintaining open connections to the servers and opening and closing connections to the client as needed, the 1250 interface unit frees servers 30 from almost all connection loading problems associated with clients presenting over the Internet.
As will be discussed further below, some modalities are related to step 4316, where the interface unit 1250 closes the connection with the client 10. There are several scenarios that result in an interface unit 1250 closing the connection with the client. For example, the customer can initiate a FIN (finish) command or an RST (reset) command. In both of these scenarios, the 1250 interface unit waits until it receives one of these commands, before losing the connection between itself and the client. Inefficiencies with a connection pool occur when the client is not using or has ended the connection, but does not relay this information to the 1250 interface unit for a period of time. Because the 1250 interface unit is waiting for a command from the client, in order to reuse the connection for another client, the connection is unnecessarily stuck.
As will be explained in more detail below, the Hypertext Transfer Protocol (HTTP) 1.1 (by default) and HTTP 1.0 (with the Connection Technique: Keep-Alive - Connection: Keep Active) allows the client and / or the unit interface interface keep the connection open with the server, even after receiving a server response to a request. The customer and / or the 1250 interface unit can then issue other requests via the same connection, either immediately or after considerable time (or time to think). A customer is in time to think when the customer's human operator is deciding the next link in the browser to click, and so on. This can result in
218 the connections are maintained by the server, although the server is not processing any requests over the connections. Here, server administrators may be forced to protect themselves against too many simultaneous connections to the server by setting a KeepAlive time after which the connection which was inactive or in a time to think is closed. One mode allows the connection to the server to be used by client 10 ', while client 10 is thinking. Obviously, if client 10 'makes a request when client 10 is using the server connection, then client 10' must use a different connection to the server. However, the efficiency of the connection cluster of a modality is realized when a very small number of connections is exceeded and moves to the general case. The general case when 'n' client connections can be statistically multiplexed into 'm' server connections, where 'n' is greater than 'm'.
Figure 31 is a flowchart that describes the operation of a translation mode for client and server requests, as shown in steps 4310 and 4314 (figure 30). In one embodiment, message traffic is in the form of TCP / IP packets, a protocol suite that is well known in the art. The TCP / IP protocol suite supports many applications, such as Telnet, File Transfer Protocol (FTP), e-mail and HTTP. The mode is described in terms of the HTTP protocol. However, the concepts apply equally well to other TCP / IP applications, as will be evident to someone skilled in the art, after reading this specification.
Each TCP packet includes a TCP header and an IP header. The IP header includes a 32-bit source IP address and a 32-bit destination IP address. The TCP header includes a 16-bit source port number and a 16-bit destination port number. The source IP address and port number, collectively referred to as the source network address, uniquely identify the source interface of the packet. Likewise, the destination IP address and port number, collectively referred to as the destination network address, iden
219 uniquely identify the destination interface for the package. The source and destination network addresses of the packet uniquely identify a connection. The TCP header also includes a 32-bit sequence number and a 32-bit recognition number.
The TCP portion of the packet is referred to as a TCP segment. A TCP segment includes a TCP header and a body. The body part of the TCP segment includes an HTTP header and the message. There are two mechanisms for determining the length of the message, including one based on fragmented transfer encoding and another based on content length. A content length header file is found in the HTTP header. If a content length header field is present, its value in bytes will represent the length of the message body. Alternatively, if a fragmented transfer encoding header is present in the HTTP header, and indicates that the fragmented transfer encoding has been applied, then the message length will be defined by the fragmented encoding. Fragmented encoding modifies the body of a message in order to transfer the message as a series of fragments, each with its own indicator contained in the fragment size field.
As will be discussed in detail below, a modality uses the content length parameter and / or the fragmented transfer encoding header to increase the efficiency of connection grouping between servers and clients by avoiding the situation where the client is in time to think. Without this mode, the 1250 interface unit waits for a command from the client, before reusing the connection for another client or the connection expires when the connection has been inactive for too long.
The 32-bit sequence number, mentioned above, identifies the byte in the data string from the sending TCP to the receiving TCP that the first data byte in the TCP segment represents. Since every byte that is exchanged is numbered, the recognition number contains the
220 next sequence number that the acknowledgment sender expects to receive. This is, therefore, the sequence number plus one of the last bytes of data received successfully. The checksum covers the TCP segment, that is, the TCP header and response data (or body). This is a mandatory field that must be calculated and stored by the sender and then verified by the receiver.
In order to successfully route a packet arriving from a client to the intended server, or to route a packet leaving a server to a client, interface unit 1250 employs a process known as network address translation. Network address translation is well known in the art, and is specified by the Request for Comments (RFC) 1631, which can be found at the URL http://www.safety.net/RFC1631 .txt.
However, in order to seamlessly split customer and server connections, a new translation technique has been described in detail in the commonly owned US Patent Application N<sup>s</sup> 09 / 188.709, filed on November 10, 1998, entitled Internet Client-Server Multiplexer, referred to here as connection multiplexing. According to this technique, a packet is translated by modifying its sequence number and the acknowledgment number 20 at the TCP protocol level. A significant advantage of this technique is that no application layer interaction is required.
Referring to figure 31, the packet's network address is translated, as shown in step 4402. In the case of a packet entering 25 (that is, a packet received from a client), the packet's source network address it is changed to that of an outgoing port of interface unit 1250, and the destination network address is changed to that of the intended server. In the case of an outgoing packet (that is, one received from a server), the source network address is changed from that of the server to that of an outbound port of interface unit 1250, and the destination address is changed from that of the 1250 interface unit to that of the requesting customer. Sequence numbers and re numbers
221 Package knowledge is also translated, as shown in steps 404 and 406 and described in detail below. Finally, the package checksum is recalculated to account for these translations, as shown in step 4408.
As mentioned above, a modality is specifically related to a device, method and computer program product to efficiently group client - network server connections through the content length parameter and / or the fragmented transfer encoding header for augmentation. the efficiency of connection grouping between servers and clients. The increase in efficiency is the result of avoiding taking up the connection while the customer is in time to think. In one embodiment, the content length parameters are used to determine the message length. In another embodiment, fragmented transfer encoding is used to determine the message length. The two modalities will be described below with reference to figures 32 and 33, respectively.
Figure 32 illustrates the TCP portion of a TCP packet called the TCP 4500 segment. The TCP 4500 segment includes a TCP header 4502 and a body 4504. Body 4504 contains, among other information, an HTTP header and the message. The content length parameter 4506 is found in the HTTP header. How a modality uses the content length parameter 4506 to provide a more efficient connection grouping is described below, with reference to figures 35 and 36.
Figure 33 illustrates the TCP portion of a TCP packet called the TCP 4600 segment. As stated above, if a fragmented transfer encoding header is present in the TCP header and indicates that the fragmented transfer encoding has been applied, then , the message length will be defined by fragmented encoding. Fragmented encoding modifies the body of a message, in order to transfer the message as a series of fragmen
222 each with its own indicator contained in the fragment size field. The TCP 4600 segment includes a TCP header (not shown) and a body. The body contains, among other information, an HTTP header 4602A-4602C and the message. The HTTP header 4602A4602C is comprised of seven fragment size fields 4606A to 4606G; and six fragment message data 4604A to 4604F.
The fragment size fields 4606A to 4606G are linked together, as shown in figure 33. The fragment size field 4606A indicates the length of the message in fragment message data 4604A, the fragment size field 4606C indicates the length of the message in fragment message data 4604C, and so on. The last fragment size field 4606G always contains the value of zero length indicating that there is no further message data to follow. This is an indication that the entire message has been sent to the customer. How a message uses fragment size fields 4606A to 4606G to provide a more efficient connection pool is described below, with reference to figures 37 and 38. It is important to note that the TCP 4600 segment in figure 33 is for the purpose of illustration only.
Before describing the details of how a modality uses the content length parameter to increase the efficiency of connection pooling, the connection pooling, as described in US Patent Application N<sup>s</sup> 09 / 188.709, filed on November 10, 1998, entitled Internet Client-Server Multiplexer, will be described first for completeness. Figure 34 is a message flowchart that illustrates a connection grouping. Fig. 34 shows interface unit 1250 connecting two clients, C1 and C2, to an S server. Both clients C1 and C2 can comprise any of the clients 10 discussed here, and server S can comprise any of the servers 30 discussed here. First, interface unit 1250 opens a connection to client C1 using network address 1 provided by client C1, as shown by flow 4702. Flow line 4702 is shown as a flow
223 two-way, because the TCP / IP protocol employs a multi-stage fulfillment for opening connections.
Once the connection is opened, interface unit 1250 receives a GET request from client C1 specifying a path name of /sales/forecast.html, as shown by flow line 704. Because no free connection is open between the interface unit 1250 and the S server, the interface unit 1250 opens a connection to the S server. Interface unit 1250 maps this request to network address 2, which specifies server S, as shown by flow line 4706. Interface unit 1250 also passes the GET request to that server, as shown by line flow 4708. Server S responds with the requested web page, as shown by flow line 4710. Interface unit 1250 forwards the web page to client C1, as shown by flow line 4712. Finally, the connection between client C1 and interface unit 1250 is closed, as shown by flow line 4714. According to the TCP / IP protocol, closing a network connection may involve a multi-stage process . Therefore, the 4714 flow line is shown as bidirectional. It is important to note that interface unit 1250 does not close the connection to the S server, but instead keeps it open to accommodate additional data streams.
Then, a connection is opened between interface unit 1250 and client C2, using network address 1 provided by client C2, as shown by flow line 4716. Next, the interface unit 2550 receives a GET request. client C2, specifying the /sales/forecast.html web page, as shown by flow line 4718. Due to the fact that a free connection is already open between the interface unit 1250 and the server S, it is unnecessary for the interface unit 1250 to accumulate the server S with the processing load of opening an additional connection. The 1250 interface unit merely uses a free open connection. Interface unit 1250 maps the GET request to the S server, transfers it and forwards it to the S server, as shown
224 flow line 4720. Interface unit 1250 receives the response from server S, as shown by flow line 4722, and forwards it to client C2, as shown by flow line 4724. Finally, the interface 1250 closes the connection to client C2, as shown by flow line 4726. Again, interface unit 1250 does not close the connection to server S. Instead, the 1250 interface unit keeps the connection open to accommodate additional data streams.
As discussed above, there are several scenarios that result in the 1250 interface unit closing the connection to the C2 client, as shown by flow line 4724. For example, the client can initiate a FIN command, which runs a once the customer has recovered all the requested data (or message). The client can also initiate an RST command (reboot). In addition to closing the connection between the 1250 interface unit and the client, the RST command results in several staging operations being performed to keep the server side connection in good order. In particular, the TCP protocol ensures that the RST command has the correct SEQ (string) number, so that the server accepts the TCP segment; however, the RST commander is not guaranteed to have the correct ACK (acknowledgment) number. To deal with this scenario, the interface unit 1250 keeps track of the data bytes sent by the server and the bytes recognized by the client. If the client has not yet recognized all the data by the server, the interface unit 1250 will calculate the unrecognized bytes, and send an ACK to the server. Furthermore, the server-side PCB can be placed in an expiration queue to allow any server data transfers to drain.
Furthermore, although not shown in figure 34, the server can also close a connection between itself and the interface unit 30 1250. The server would send a FIN command to the interface unit
1250. In this case, the connection between the server and the interface unit 1250 and the connection between the interface unit 1250 and the client will be closed.
225
Another aspect is to maximize the offload of connection processing from the server by minimizing the occasions when the server closes the connection. There are three cases:
(1) The HTTP / 1.1 protocol version is used. In this case, no explicit Keep-Alive header is required. By default, the server keeps the connection open; it is the customer's role to close the connection. One mode unloads the server by reusing the server-side connection. Because it is the customer's role to close the connection, inefficiencies with connection grouping occur when the customer terminates the connection, but does not relay this information to the 1250 interface unit for a period of time. Because the 1250 interface unit is waiting for a command from the client, in order to reuse the connection for another client, the connection is unnecessarily stuck.
(2) The HTTP / 1.0 protocol version is used and the Connection: Keep-Alive header is provided by the client. In this case, the server keeps the connection open; it is the customer's role to close the connection. One mode unloads the server by reusing the server-side connection. As with the HTTP / 1.1 protocol version, inefficiencies with connection pooling occur when the client terminates the connection, but does not relay this information to the 1250 interface unit for a period of time.
(3) The HTTP / 1.0 protocol version is used and the Connection: Keep-Alive header is not provided by the client. In this case, the server will normally close the connection after fully satisfying a GET request. If the server closes the connection after each request, this will deny the 1250 interface unit the opportunity to reuse the server side connection. It turns out that a lot of the Internet still uses HTTP / 1.1 without Connection: Keep-Alive. A new technique to allow the reuse of server-side connections in this specific important case has been described in detail in the commonly owned US Patent Application N<sup>5 </sup>09 / 188.709, filed on November 10, 1998, entitled Internet Client-Server Multiplexer. The 1250 interface unit inspects the GET packet to detect this situation. When this case is detected, the unit
226 interface 1250 inserts Connection: Keep-Alive into the GET package. Since this is done invisibly to the client, the 1250 interface unit must keep track of the number of Bytes Added on the server side connection. The Bytes Added does not affect the sequence numbers in the GET packet, since the sequence number is that of the first byte. However, the 1250 interface unit must add Bytes Added to the subsequent packet sequence number from the client to the server. Conversely, the server will recognize the additional bytes, but the 1250 interface unit must subtract them, before sending the acknowledgment to the client - who does not know that these bytes have been added.
As mentioned above, connection multiplexing is achieved by manipulating sequence and recognition numbers. The sequence and segment recognition numbers received by the 1250 interface unit are modified and mapped to values expected by the recipient. To the client, the data appears to be coming from the server and vice versa. For example, if the input stream denotes a segment received by the 1250 interface unit and the output stream denotes the corresponding output segment, the recognition sequence and numbers will be changed as follows:
Outbound flow sequence number = Inbound flow sequence number - Inbound flow start sequence number + Outbound flow sequence number
Outflow recognition number = Incoming flow recognition number - Incoming flow beginning recognition number + Outgoing flow recognition number
To address the addition of the Connection: Keep-Alive header from HTTP / 1.0 packets, the 1250 interface unit keeps track of Bytes Added in the appropriate half of the connection in this case, on the server side. The sequence number and acknowledgment number formulas are changed as follows: Outgoing sequence number = Outgoing sequence number
227 input - input stream start sequence number + output stream start sequence number + added output stream bytes number outflow recognition number = input stream recognition number - start flow recognition number input stream 5 + output stream start recognition number + added bytes of input stream
The specific examples of translations performed using these equations while incorporating the content length parameter technique of a modality for the provision of a more efficient grouping 10 are described below with reference to figures 35 and 36 (with respect to content length parameter) and figures 37 and 38 (with respect to fragment size fields).
Figure 35 is a detailed flow chart that illustrates the translations of recognition and sequence numbers performed by a modality, while incorporating the content length parameter technique. The label for each stream in figure 35 is of the form T: S, A (L), where T represents the type of TCP segment, S is the sequence number, S is the sequence number, A is the recognition number and L is the content length parameter. The content length parameter des20 describes the number of data bytes in the message.
Streams 4802A to 4802C feature a method of opening the connection between client C1 and interface unit 1250. Each stream represents a TCP segment. In the segment of TCP 4802A, the indicator (flag) SYN in the TCP header is regulated, indicating a new connection request 25 from client C1. Client C1 has established a sequence number beginning in 2000 and an acknowledgment number in 2000. The 1250 interface unit responds with a SYN ACK segment specifying a start sequence number of 4000 and increasing the recognition number for 2001, as shown by flow 4802B.
Each entity (for example, client, server, interface unit) on the network regulates its own sequence number and / or unique recognition number, as is well known in the art. Customer C1 responds with a
228 ACK segment specifying a 2001 sequence number and increasing the recognition number to 4001, as shown by stream 4802C. The client C1 then sends a GET segment specifying a length of 49 bytes, as shown by stream 4804.
Assume that interface unit 1250 determines that there is no free open connection to server S, and therefore sends a SYN segment to server S, specifying a sequence number beginning in 1950, as shown in flowchart 4806A. Server S responds with a SYN ACK segment specifying a starting sequence number of 6000 and increasing the acknowledgment number to 1951, as shown in 4806B. Interface unit 1250 responds with an ACK segment, as shown by flow 8060. Interface unit 1250 then routes the GET segment from client C1 to server S, after modifying the sequence and acknowledgment numbers according to translation equations described above, as shown by flow line 4808.
The S server responds with the requested data by specifying a sequence number of 6001, an acknowledgment number of 2000 and a content length parameter of 999, as shown by flow 4810. Interface unit 1250 receives the RESP segment, translates the sequence and recognition numbers and forwards the RESP segment to customer C1, as shown by flow line 4812A.
At this point, interface unit 1250 receives a request from client C1 to open a connection. As above, flows 4816A to 4816C present a method of opening the connection between client C2 and interface unit 1250. Again, each flow represents a segment of TCP. In the TCP 4816A segment, a SYN indicator (flag) in the TCP header is regulated, indicating a new connection request from the C2 client. Client C2 has set a start sequence number of 999 and an acknowledgment number of 999. Interface unit 1250 responds with a SYN ACK segment specifying a start sequence number of 4999 and incrementing the recognition number
229 to 1000, as shown by flow 4816B. The C2 client responds with an ACK segment specifying a sequence number of 1000 and increasing the acknowledgment number to 5000, as shown by flow 4816C. The C2 client then sends a GET segment specifying a length of 50 bytes, as shown by flow 4818.
Assume, at this point, that the 1250 interface unit has no connections available to the S server that was previously used for client C1, if client C1 has finished with the connection or is in time to think. Instead of waiting for the C1 client to initiate a FIN command (terminate) or an RST command (reset) to release the connection, interface unit 1250 uses the content length parameter to confirm that all requested data has been received by the client C1. Here, in flow 4812B, interface unit 1250 receives confirmation from client C1 that client C1 has indeed received all requested data. This indicates to interface unit 1250 that, although client C1 may be paused for some reason, before it sends a FIN or RST command, client C1 has terminated the connection. The interface unit 1250 modifies the recognition and sequence numbers and routes the RESP ACK trigger signal to the S server, as shown by flow 812C.
Using the same connection as the one used with client C1, interface unit 1250 then routes the GET segment from client C2 to the server, after modifying the sequence and recognition numbers according to the translation equations described above, as shown by flow line 4820. Server S responds with the requested data by specifying a sequence number of 7000, an acknowledgment number of 2050 and a content length parameter of 500, as shown by flow 822.
Interface unit 1250 receives the RESP segment, translates the sequence and acknowledgment numbers and forwards the RESP segment to the C2 client, as shown by flow line 4824A. Here, in flow 4824B, interface unit 1250 obtains confirmation from
230 from customer C2 that customer C2 actually received all the requested data. The interface unit 1250 modifies the recognition and sequence numbers and forwards the RESP ACK segment to the S server, as shown by flow 4824C.
The connection between client C2 and interface unit 1250 is then closed or disconnected once interface unit 1250 receives a FIN or RST command from client 02, as shown by flows 4826A to 4826D. Likewise, the connection between client C1 and interface unit 1250 is then closed or disconnected once it receives a FIN or RST command from client C1, as shown by flows 4814A to 4814D. It is important to note, however, that the interface unit 1250 maintains the connection to the S server. It is also important to note that the sequence of events, as they have been described with reference to figure 36, is for illustration purposes only.
Figure 36 is a flowchart that describes the operation of using the content length parameter to increase the efficiency of grouping connections between clients and servers, according to one modality. Interface unit 1250 maintains connections to a plurality of servers, and routes client requests to these servers, based on the path name specified in the client request. First, interface unit 1250 opens connections to servers, as shown in step 4902. Then, in response to a request from client C1, interface unit 1250 opens a connection to client C1 and receives a request from client C1 for data recovery using a path name, as shown in step 4904.
Interface unit 1250 then selects the server hosting the content specified by the path name, as shown in step 4906. Alternatively, interface unit 1250 queries other predefined policies for selecting the appropriate server, such as server load and the state of the servers. The 1250 interface unit manages and maintains a database of servers and ban
231 of the server it houses. Among other things, information in this database includes currently active policies and rules that allow the 1250 interface unit to route packets arriving at the correct server. Depending on the network conditions and the desired services, these policies and rules can change very quickly.
Interface unit 1250 then translates the request and passes the translated request to the selected server, as shown in step 4908. Interface unit 1250 receives the response from server S, as shown in step 4910. Interface unit 1250 then translates the response and passes the translated response to client C1, as shown in step 4912.
Assume for the purposes of illustration that, at this point, the interface unit 1250 receives a request from the C2 client for data recovery. Interface unit 1250, in response to the C2 client's request, opens a connection to the C2 client and receives a request from the C2 client for data retrieval using a path name, as shown in step 4914. Interface unit 1250 then selects the server hosting the content specified by the path name, as shown in step 4916.
In step 4918, interface unit 1250 determines whether client C2 has selected the same server as client C1. If the result of step 4918 is negative, then the interface unit 1250 proceeds in a way necessary to satisfy the customer's request C2 (which is not important for this modality). At this point, the flowchart in figure 36 ends. Alternatively, if the result of step 4918 is positive, then interface unit 1250 determines whether there are any open connections to the selected server, as shown in step 920.
If the result of step 4920 is positive, then the interface unit 1250 proceeds as necessary to satisfy the customer's request C2 (which is not important for this modality). At this point, the flowchart in figure 9 ends. Alternatively, if the result for step 4920 is negative, then interface unit 1250 will use the parameter
232 length of content to confirm that client C1 received all the data that client C1 requested, as shown in step 4922. It is important to note that interface unit 1250 does not expect client C1 to send a FIN or RST command in order to determine that client C1 has finished the connection or is in time to think. This allows for more efficient connection pooling, due to the fact that the 1250 interface unit can use each connection more quickly than if the 1250 interface unit waited for the customer to close the connection before reusing the connection for another customer.
In step 4924, interface unit 1250 then translates the request and passes the translated request to the selected server using the same connection that client C1 used, as shown in step 4924. Interface unit 1250 receives the response from server S, as shown in step 4926. Interface unit 1250 then translates the response and passes the translated response to the C2 client, as shown in step 4928. Interface unit 1250 uses the content length parameter to confirm that client C2 has received all the data that client C2 has requested, as shown in step 4930.
Then interface unit 1250 closes or disconnects connection with client C2 in step 4932. Finally, interface unit 1250 closes or disconnects connection with client C1 in step 4934, and the flowchart in figure 36 ends. As stated above with reference to figure 35, the sequence of events as they have been described with reference to figure 36 is for purposes of illustration only.
Figure 37 is a detailed flow chart that illustrates the translations of recognition and sequence numbers performed by a modality, while incorporating the fragment size field technique. The label for each flow in figure 37 is of the form T: S, A (L), where T represents a type of TCP segment, S is the sequence number, A is the recognition number and L is a size field fragment. The total values of the fragment size fields describe the number of bytes of data in the TCP segment.
233
For simplicity, it was assumed that connections with client C1 and client C2 have already been established. The client C1 then sends a GET command specifying a length of 49 bytes, as shown by flow 4002. Interface unit 1250 determines that there is no free open connection to the S server and therefore opens a connection to the S server ( not shown in figure 37). Interface unit 1250 then routes the GET segment from client C1 to server S, after modifying the sequence and recognition numbers according to the translation equations described above, as shown by flow line 4004.
For the purposes of illustration, assume that the data in the response segment has a total content data length of 999. Also, assume that the data will be transmitted in two data fragments of 300 and a data fragment of 399. Note that this is for illustration purposes only and is not intended for limitation. Therefore, server S first responds with a fragment of the requested data (or a message) specifying a sequence number of 6001, an acknowledgment number of 2000, and a fragment size field of 300, as shown by flow 4008A. Interface unit 1250 receives the RESP segment, translates the sequence and acknowledgment numbers, and forwards the RESP segment to client C1, as shown by flow line 4006A. Client C1 acknowledges receipt of data for interface unit 1250, as shown by flow line 4006B. Interface unit 1250 in response passes this acknowledgment to server S, as shown by flow line 4008B.
The S server then responds with the second fragment of the requested data by specifying a sequence number of 6301, a recognition number of 2001 and a fragment size field of 300, as shown by flow 4012A. Interface unit 1250 receives the RESP segment, translates the sequence and acknowledgment numbers, and forwards the RESP segment to client C1, as shown by flow line 4010A. Customer C1 acknowledges receipt of the
234 data to the 1250 interface unit, as shown by the 401OB flow line. Interface unit 1250 in response passes this acknowledgment to server S, as shown by flow line 4012B.
Server S then responds with the third fragment of the requested data by specifying a sequence number of 6601, a recognition number of 2002 and a fragment size field of 399, as shown by flow 4016A. Interface unit 1250 receives the RESP segment, translates the sequence and acknowledgment numbers, and forwards the RESP segment to client C1, as shown by flow line 4014A. Client C1 acknowledges receipt of data for interface unit 1250, as shown by flow line 4014B. Interface unit 1250 in response passes this acknowledgment to server S, as shown by flow line 4016B.
Finally, server S responds with the final fragment of the data zero (indicated by a fragment size field that equals zero) specifying a sequence number of 7000, a recognition number of 2003 and a fragment size field of 9 , as shown by flow 4020. Interface unit 1250 receives the RESP segment, translates the sequence and acknowledgment numbers and forwards the RESP segment to client C1, as shown by flow line 4018. This indicates to interface unit 1250 and client C1 that all requested data has been transmitted.
At this point, the C2 client then sends a GET segment specifying a length of 50 bytes, as shown by flow 4022. Assume at this point that interface unit 1250 has no connections available with server S. The goal is to reuse the same connection for the S server that was previously used for client C1, if client C1 has finished the connection or is in time to think. Instead of waiting for the C1 client to initiate a FIN command (terminate) or an RST command (reset) to release the connection, the interface unit uses the fragment size field that was zero to confirm that all requested data has been received by customer C1. This indicates for the unit
235 interface 1250 which, although client C1 may be pausing for some reason before sending a FIN or RST command, client C1 has ended the connection. The interface unit 1250 modifies the recognition and sequence numbers and forwards the GET segment to the S server, as shown by flow 4024.
For the purposes of illustration, assume that the data in the response segment has a total content data length of 500. Also, assume that the data will be transmitted in a data fragment of 300 and a data fragment of 200. Note that this is for illustration purposes only and is not intended for limitation. Therefore, server S first responds with a fragment of the requested data by specifying a sequence number of 7000, an acknowledgment number of 2050 and a fragment size field of 300, as shown by flow 1028A. The interface unit 1250 receives the RESP segment, translates the sequence and acknowledgment numbers and forwards the RESP segment to the client C2, as shown by flow line 1026A. Client C2 acknowledges receipt of data for interface unit 1250, as shown by flow line 4026B. Interface unit 1250 in response passes this acknowledgment to server S, as shown by flow line 4028B.
Server S then responds with the second fragment of the requested data by specifying a sequence number of 7300, an acknowledgment number of 2051 and a fragment size field of 200, as shown by flow 4032A. The 1250 interface unit receives the RESP segment, translates the sequence and recognition numbers, and forwards the RESP segment to the C2 client, as shown by flow line 4030A. Client C2 acknowledges receipt of data for interface unit 1250, as shown by flow line 4030B. Interface unit 1250 in response passes this information to server S, as shown by flow line 4032B.
Finally, server S responds with the final fragment of data zero (indicated by a fragment size field that is equivalent to
236 to zero) by specifying a sequence number of 7500, a recognition number of 2052 and a fragment size field of 0, as shown by flow 4036. Interface unit 1250 receives the RESP segment, translates the sequence and recognition and forwards the RESP segment to client C2, as shown by flow line 4034. This indicates to interface unit 1250 and client C2 that all requested data has been transmitted.
The connection between client C2 and interface unit 1250 is then closed or broken, once interface unit 1250 receives a FIN or RST command from client C2, as shown by flow 4038. Likewise, the connection between client C1 and interface unit 1250 then it is closed or undone, once it receives a FIN or RST command from client C1, as shown by flow 4040. It is important to note, however, that the Í250 interface unit maintains the connection to the S server. It is also important to note that the sequence of events, as they have been described with reference to figure 37, is for the purpose of illustration only and not limit.
Figure 38 is a flowchart that describes the operation of using fragment size fields to increase the efficiency of grouping connections between clients and servers, according to one modality. Interface unit 1250 maintains connections to a plurality of servers, and routes client requests to these servers based on the path name specified in the client request. First, interface unit 1250 opens connections to servers, as shown in step 4102. Then, in response to a request from client C1, interface unit 1250 opens a connection to client C1 and receives a request from the client C1 for data recovery using a path name, as shown in step 4104.
Interface unit 1250 then selects the server hosting the content specified by the path name, as shown in step 4106. Interface unit 1250 then translates the request and passes the translated request to the selected server, as shown in
237 step 4108. Interface unit 1250 receives the response from server S, as shown in step 4110. Interface unit 1250 then translates the response and passes the translated response to client C1, until the fragment size field is equal to zero, as shown in step 4112.
Assume, for illustration purposes, that at this point the interface unit 1250 receives a request from the C2 client to open a connection. Interface unit 1250, in response to a C2 client request, opens a connection to the C2 client, and receives a request from the C2 client to retrieve data using a path name, as shown in step 4114. Interface unit 1250 then selects the server hosting the content specified by the path name, as shown in step 4116.
In step 4118, interface unit 1250 determines whether client C2 has selected the same server as client C1. If the result of step 4118 is negative, then the interface unit 1250 proceeds in a way necessary to satisfy the customer request C2. At this point, the flowchart in figure 38 ends. Alternatively, if the result of step 4118 is positive, then interface unit 1250 will determine if there are any open connections to the selected server, as shown in step 4120.
If the result of step 1120 is positive, then the interface unit 1250 proceeds in a way necessary to satisfy the customer request C2. At this point, the flowchart in figure 38 ends. Alternatively, if the result of step 4120 is negative, then interface unit 1250 will use the fact that the fragment size field was equal to zero in step 4112 to confirm that client C1 received all message data that client C1 requested. It is important to note that interface unit 1250 does not wait for client C1 to send a FIN or RST command in order to determine that client C1 has finished the connection or is in time to think.
In step 4122, interface unit 1250 then translates the request and passes the translated request to the selected server using
238 the same connection that the C1 client used. Interface unit 1250 receives the response from server S, as shown in step 4124. Interface unit 1250 then translates the response and passes the translated response to client C2, until the fragment size field equals zero, as shown in step 4126. Interface unit 1250 uses the fragment size field to confirm that client C2 has received all the message data that client C2 has requested.
Then, the interface unit 1250 closes or disconnects the connection with the client C2 in step 4128. Finally, the interface unit 1250 closes or undoes the connection with the client C1 in step 4130, eox in figure 38 ends. As stated above with reference to figure 37, the sequence of events as they have been described with reference to figure 38 is for illustration purposes only and not limit.
The previous modalities are specifically described when implemented in an interface unit, such as the interface unit 1250, which is connected to servers in a bank for the purpose of offloading connection processing time from the servers. However, they can also be applied to other types of devices that are in the network connection path between the client and the servers. As network traffic flows through these devices, they all have the opportunity to offload connection processing. Some examples of these devices are:
- Load balancers which distribute client network connections among a set of servers in a server bank (distributed locally or geographically).
- Bandwidth managers which monitor network traffic and measure packet flow.
- Firewalls monitor packets and allow only authorized packets to flow through.
- Routers and switches are also in the way of network traffic. The industry trend may be to integrate additional functionality (such as load balancing, bandwidth management
239 and firewall functionality) on these devices.
The modalities can also be applied to computer systems which are at the end points of network connections. In this case, addition plates can be used to download the main processing elements to the computer system.
3. Integrated caching
Figure 39 illustrates a flowchart 5300 of a sequence of events that can occur in a device that provides integrated caching functionality according to one modality. However, the modality is not limited to the description provided by flowchart 5300. Instead, it will be evident to people skilled in the relevant technique (s) from the teachings provided here that other functional flows are in scope and in scope. spirit of the sport. These other functional flows could involve different processing, different sequencing and other variations on the integration of caching.
The flowchart 5300 method can be implemented on one or more devices that are communicatively coupled to a data communication network. For example, the flowchart 5300 method can be implemented in an apparatus, such as apparatus 1250 described above with reference to figure 1 A, having a 3200 software architecture as described above with reference to figure 27. The method of flow chart 5300 will be described with continued reference to this example modality.
As shown in figure 39, the flowchart 5300 method starts at step 5302, in which the apparatus 1250 receives an encrypted packet from one of the clients 10. In one embodiment, the apparatus 1250 is configured to act as an SSL endpoint next to servers 30, decrypting encrypted packets received from clients 10, and then sent for further processing as needed, and finally to an appropriate resource based on address information in the encrypted packets. The appropriate resource can
240 be, for example, any of the servers 30 or the cache managed by the appliance 1250. In step 5304, the appliance 1250 performs a decryption processing on the package.
In step 5306, apparatus 1250, which is configured according to a modality for carrying out AAA policies for access control, authenticates and / or authorizes the client from which the encrypted packet was received.
In step 5308, the apparatus 1250, which is configured according to a modality for carrying out certain types of packet processing, performs a packet processing on the decrypted packets to reduce the connection processing time processing requirements generated by the applicable network protocols.
In step 5310, the apparatus 1250, which is configured according to a mode for content compression and decompression, decompresses a request associated with the package. In one embodiment, the request comprises a web object request.
In step 5312, the apparatus 1250 is then able to activate the cache functionality, which receives a clear and / or authorized and / or decompressed and / or packaged request for an object. Because the previous processing described with reference to steps 5302, 5304, 5306, 5308 and 5310, the cache management logic can make a decision as to whether the object has been cached or can be cached based on clear / authorized / uncompressed / processed package request and therefore it is able to process a much wider array of requests than traditional caches and perform caching more efficiently than traditional approaches. Furthermore, due to the fact that the caching logic is working in a kernel space together with other processes, it refers to the relevant object as a data structure with equal status in relation to that data structure as each of the other applications and therefore integration is won in an extremely efficient way.
241
As shown in step 5314, if the object is no longer in cache memory, device 1250 sends a request to one or more servers 30. Before the request is sent, however, several additional processing steps can occur.
For example, in step 5216, appliance 1250 optionally performs connection processing to ensure efficient transit of the request to the server (s) and, in step 5318, appliance 1250 optionally makes a load balancing decision for ensure that the request is sent to the most appropriate server (s). Also, in one embodiment, the request is encrypted before being sent to the server (s) through a back-end encryption process, thereby providing end-to-end network security. In step 5320, the request is transmitted to the server (s).
In step 5322, apparatus 1250 receives a response back from one of servers 30. If back-end encryption is supported, as discussed above, apparatus 1250 will decrypt the response from the server.
In step 5324, apparatus 1250 compresses an object associated with the response from the server. In one embodiment, the object comprises a web object.
In step 5326, the cache management logic on the 1250 appliance stores the object in the cache in a compressed form. The cache management logic is capable of storing objects compressed in this way, due to the processing capabilities - once the object is stored in the cache, future client requests for the object can be presented from the cache, without performing the steps 5316, 5318, 5320, 5322, 5324 and 5326, as described above. This is indicated by the line directly connecting decision step 5314 to step 5328 in flow chart 5300.
In step 5328, after the object has been received from a server or retrieved from the cache, the 1250 appliance performs packet processing on the connection to more efficiently serve the retrieval.
242 original customer request. At step 5330, the response object is then re-encrypted and delivered back to the customer.
Each of the processing steps described above occurs at the kernel / OS level of the 1250 appliance. By implementing the cache in the middle of and integrated with other processing steps in the kernel / OS space, a modality is capable of creating additional functionality and improve cache performance.
This integration allows for a cache implementation according to a modality for carrying out additional functions that traditionally are beyond the functional capabilities of a cache. For example, a modality allows the cache to work with encrypted and / or compressed objects.
Another example of additional functionality that can be achieved by one modality involves caching end-to-end encrypted HTTPS traffic. Typically, caches only store unencrypted HTTP responses from servers. Certain caches may support, in some cases, an SSL encrypted HTTPS delivery from the cache to the clients, but in any case, traditional caches are not able to cache responses that have been encrypted by the server and then , are unable to support end-to-end encryption (that is, server to client). Typically, when a response is encrypted by the server in the form of HTTPS, the cache is unable to decrypt a response like this and is therefore unable to store the response in its cache memory. For this reason, traditional caches fail to provide any benefit in the face of end-to-end encrypted traffic in one mode, the integrated caching appliance serving as a two-way endpoint for SSL encrypted HTTPS traffic.
For example, in one embodiment, the integrated caching appliance acts as a termination point for encrypted traffic between the server and the appliance, and between the appliance and
243 the clients. In this way, the system is capable of decrypting and caching encrypted SSL responses received from servers and, when presenting these responses to a customer, re-encrypt that response and safely deliver it to the requesting customer, thereby allowing a end-to-end encryption and thereby increasing the applicability of caching for a wider variety of web traffic.
In one embodiment, the system can also serve as an end point in a virtual private SSL network (SSL VPN). In particular, the appliance can act as a near-end SSL endpoint for any resource on a private data communication network, decrypting encrypted packets received from a client and then sending them to the destination server resource. appropriate based on address information in the encrypted packets. A data communication session established between the client and a gateway can be encrypted with the gateway serving as an encryption endpoint, as described in the preceding paragraphs of this application. As described, the client can use the Secure Sockets Layer (SSL), IPSec, or some other encryption method to establish the encrypted data communication session by means of which an interception mechanism on the client directs traffic to the gateway , while keeping the client browser thinking that it is communicating directly with the destination servers or the destination networks. In such a modality, the encrypted data communication session can be ended at the gateway, which also includes an integrated cache, as described here. In this way, a caching feature can be integrated with the SSL VPN feature.
The gateway can also perform any AAA policies applicable to the request and, consequently, the gateway will serve cached objects only to properly authenticated clients, as well as allowing requests only to users authorized to access a particular cached object. This is possible by
244 that the cache is integrated in such a way that the access control policies of the gateway are enforced before the cache sees any particular request. Thus, cached objects get the benefit of access control without the cache itself having to perform authentication and authorization. By integrating the cache with these other functions, the cache itself becomes more efficient and more effective in handling the variety of data that passes through today's networks. One modality is also able to improve the efficiency of the overall network performance by introducing the benefits of cache functionality for a wider array of web traffic.
Some other unique results of the integration mode described above according to one modality are as follows. One result is the ability to cache pre-compressed data and present it to customers aware of the compression. Another result is the ability to cache controlled access data. Yet another result is the ability to work with external caches to provide a cache scaling capability. Because the cache is integrated with redirection and traffic management capabilities at the gateway, external caches can be used to provide a second caching link, thereby extending the storage capacity (and benefits) significantly cached. Through this modality, this capacity is created, without the cache module itself having to explicitly implement cache redirection policies.
In terms of performance, by integrating the cache as described above, cache processors are freed from performing the variety of connection processing tasks that traditionally are required for caches, acting as nodes on a network, to perform, and thus are able to perform their caching functions at their highest performance levels. In fact, by allowing compressed data to be cached, the cache is able to work even more efficiently and allow users to perceive a per
245 still higher.
As previously mentioned in this application, efficiency comes as a result of the way in which the cache is integrated with other services and network technologies including load balancing, encryption, AAA, compression and other types of packet acceleration and processing technology. As a result, duplication of processing and other inefficiencies introduced by traditional modes of integration are avoided. These inefficiencies, caused by unnecessary copying and context switching, arise because each object received by the device must be copied to a message and then into a processor memory before processing by the relevant application. The request must then be copied back to the object or package level for processing by the cache, adding additional memory copies. In contrast, a modality performs integration at the OS or kernel level, thereby allowing the cache to operate on the object as a data structure in which the cache has the same status as other applications and / or processes in relation to and processing this data structure, and where the need for these additional memory copies is eliminated, as all processes are working with the same data structure. The result is more efficient integration.
The. Caching with Proactive Validation on a Data Communication Network
Because web objects can change over time, each potentially cacheable object is said to have a shelf life or freshness. The concept of freshness refers to the fact that the application server that originally generated the content also determines the period of time that this object can be presented by a cache, which can store that object. The caches must be able to determine whether the copy of an object stored in its memory is still fresh or not, or whether the cache needs to retrieve a new copy of the object from the source server. One modality implements a new approach to ensure the freshness of the object. Many cache implementations
246 Conventional try to keep the cached content fresh by fetching the content from the source on a predetermined schedule. Fetching content from the source occurs at times set by the cache administrator typically based on one or more of the following approaches: (i) at regular specified intervals or (ii) when the content is about to expire.
There are two problems typically associated with the approaches commonly employed above. First, unnecessary processing loads are imposed on the origin server, because that server is required to provide content to the cache requesting the update (regardless of whether this update occurs at specified intervals or as the content is about to expire), regardless of how much whether that content will finally be presented to customers. Second, the cache incurs an additional processor load based on the extra processing time generated because the cache needs to keep track of the elements that must be updated and the time that they have to be updated.
A cache according to one modality solves the above problems using a new prefetch approach. The prefetching of the content is not carried out according to a predefined schedule or immediately before the content expires. Instead, a modality performs a prefetch only when both of the following conditions have been met: (1) a customer has made a request for the specified content and (2) that content is 'about to expire'.
This approach addresses both problems described above. A proactive revalidation is more likely to generate a request to update content from the source server when that content is being actively accessed. This minimizes the amount of 'unnecessary' load on the source server. As discussed above, when the cache requests an update of objects that are not finally presented to clients (and are only rarely presented, depending on the sensitivity of the cache), the cache is using
247 its own resources as well as the resources of the origin server. One method avoids the inefficient use of the cache and server resources by requesting only that content that is being actively accessed. The approach also reduces, for the same reason, the bandwidth used for prefetching and therefore makes the use of network resources more efficient than traditional approaches.
Furthermore, a modality uses the expiration information included in the cached object itself to determine whether to request an update of the object from the origin server. This expiration information is typically included in the headings of the relevant object. This modality thus avoids the inefficiencies of looking at any additional information for searching, unlike many traditional approaches which require the cache to keep a table following the update schedule. Using a 'demand-based' prefetch technique also improves the benefits that are inherent in a prefetch. This technique reduces the number of cache losses for frequently accessed objects, since these objects are very likely to undergo a proactive revalidation, just before they expire. This technique can also prevent traffic from coming to a source server that can occur when a large response that is in great demand expires. In the traditional approach, all requests for this content lose their cache and are sent to the origin server, because the cache content has expired. In contrast, in one embodiment, the contents of the cache memory will generally be updated immediately before expiration and, therefore, the situation where cache losses occur while the cache is updating is much less likely to arise.
In one embodiment, pre-fetch aggressiveness can be controlled by adjusting the length of the pre-expiration period in which the content is determined to be about to expire and also the number of client requests required to trigger an update via the cache. relevant object.
248
B. Optimization Processing of Large Non-Cacheable Responses Using Negative Cells
According to one modality, the cache recognizes and does not store objects that are over a specified size, in order to improve the object's hit ratio. Caches typically have limited memory space devoted to storing cached objects, and therefore, certain responses that exceed the allocated memory space are ultimately rejected as non-cacheable and not cached. With traditional caches, the cache attempts to store the large response in its cache memory and only aborts the response storage once the cache recognizes that the response size exceeds a predefined maximum size. Traditional caches will repeatedly attempt to cache the large response each time a request for that response is received by the cache from the server. In each case, the cache will need to determine that the object is not cacheable since it exceeds the memory space. So this is clearly an inefficient approach.
According to one modality, the cache employs optimization to avoid spending effort on storing these responses. Whenever the cache detects a response that becomes non-cacheable due to the size of the response, it stores a notation for the corresponding request in a data structure called a negative cell. The notation indicates that the request is not cacheable. In the future, when a customer requests the same object, the request is combined with the notation considered as the first request stored in the data structure. Facilitating the combination, the cache will not attempt to cache the response and, instead, the request will be completely bypassed by the cache.
There is no user configuration required for specifying the duration for which a negative cell should remain in the cache. In fact, users are not even aware that this particular mechanism is being employed. In one embodiment, the cache uses information
249 regular expiration information that he would have used to cache the large response to cache negative information about that response.
4. Client Side Acceleration
In one embodiment, a client-side acceleration program can perform one or more acceleration techniques to accelerate, improve, or otherwise improve a client's communications with and / or access to a server, such as accessing an application provided by a server. Referring now to Figure 40A, a customer 6205 having an acceleration program 6120 is described. In a brief overview, the 6205 client operates on the 6100 computing device that has an operating system with a 6202 kernel mode and a 6202 user mode, and a 6210 network stack with one or more layers 6210a through 6210b. The 6205 customer can understand any and all of the 10 customers discussed previously. Although only one 6205 customer is shown, any number of customers 10 can comprise customer 6205. The 6205 client may have installed and / or run one or more 6220a through 6220n applications. In some embodiments, one or more 6220a through 6220n applications can communicate over the 6210 network stack with a network. One of the 6220N applications can also include a first 6222 program, for example, a program which can be used in some ways to install and / or run the 6120 accelerator program.
The 62010 client 6210 network stack may comprise any type and form of software or hardware, or any combination thereof, for the provision of connectivity to and communications with a network. In one embodiment, the 6210 network stack comprises a software implementation for a network protocol suite. The 6210 network stack may comprise one or more network layers, such as any network layers of the Open Systems Interconnection (OSI) communications model, such as those skilled in the art recognize and appreciate. As such, the 6210 network stack can comprise any type and form of protocols for any of the following layers of the
250
OSI: 1) a physical link layer, 2) a data link layer, 3) a network layer, 4) a transport layer, 5) a session layer, 6) a presentation layer, and 7) an application layer. In one embodiment, the network stack 310 may comprise a transport control protocol (TCP) by the internet protocol (IP) network layer protocol, generally referred to as TCP / IP. In some embodiments, the TCP / IP protocol can be performed using the Ethernet protocol, which can comprise any of the IEEE wide area network (WAN) or local area network (LAN) family protocols, such as those protocols covered by IEEE 802.3. In some embodiments, the 6210 network stack comprises any type and form of wireless protocol, such as IEEE 802.11 and / or a mobile internet protocol.
For a TCP / IP-based network, any TCP / IP-based protocol can be used, including a Message Sending Application Programming Interface (MAPI) (email), File Transfer Protocol (FTP) , Hypertext Transfer Protocol (HTTP), Common Internet File System (CIFS) protocol (file transfer), Independent Computing Architecture Protocol (ICA), Remote Desktop Protocol (RDP), Wireless Application Protocol (WAP), Mobile IP protocol, and Voice over IP (VolP) protocol. In another embodiment, the network stack 210 comprises any type and form of transport control protocol, such as a modified transport control protocol, for example, a Transaction TCP (T / TCP), a TCP with acknowledgments of selection (TCP-SACK), TCP with large windows (TCP-LW), a congestion prediction protocol, such as the TCP-Vegas protocol, and a TCP deception protocol. In other embodiments, any type and form of user datagram protocol (UDP), such as UDP over IP, can be used by the 6210 network stack, such as for voice communications or for real-time data communications.
Furthermore, the 6210 network stack may include one or more network drivers supporting one or more layers, such as a TCP driver or
251 a network layer driver. Network drivers can be included as part of the computing device 100's operating system or as part of any network interface cards or other network access components of the 6100 computing device. In some embodiments, any of the 6210 network stack network drivers can be customized, modified or adapted to provide a customized or modified portion of the 6210 network stack in support of any of the techniques described here. In other embodiments, the 6120 acceleration program is designed and built to operate with or work in conjunction with the 6210 network stack, installed or otherwise provided by the 205 client operating system.
The 6210 network stack comprises any type and form of interfaces for receiving, obtaining, providing or otherwise accessing any information and data relating to the 6205 client's network communications. In one embodiment, an interface with the 6210 network stack comprises an application programming interface (API). The interface can also comprise any functional call, hooking or filtering mechanism, event or callback mechanism, or any type of interface creation technique. The 6210 network stack through the interface can receive or provide any type and form of data structure, such as an object, related to the functionality or operation of the 6210 network stack. For example, the data structure may comprise information and data related to a network packet or one or more network packets. In some embodiments, the data structure comprises a portion of the network packet processed in a protocol layer of the 6210 network stack, such as a transport layer network packet. In some embodiments, data structure 6225 comprises a kernel-level data structure, while in other embodiments, data structure 6225, while in other embodiments, data structure 6225 comprises a user mode data structure. A kernel-level data structure may comprise a data structure obtained from or related to a portion of the 6210 network stack operating
252 in kernel mode 6202, or a network driver or some software running in kernel mode 6202, or any data structure obtained or received by a service, process, task, line or other executable instructions running or operating in kernel mode operational system.
Additionally, some portions of the 6210 network stack can run or operate in the 6202 kernel mode, for example, the data link or network layer camera, while other portions run or operate in the 6203 user mode, such as a layer 6210 network stack application. For example, a first portion 6210a of the network stack may provide user mode access to the network stack 6210 to an application 6220a to 6220n, while a second portion 6210a of the network stack 6210 provides access to a network. In some embodiments, a first portion 6210a of the mesh stack may comprise one or more upper layers of the mesh stack 6210, such as any of layers 5 through 7. In other embodiments, a second portion 6210b of mesh stack 6210 comprises one or more lower layers, such as any of layers 1 to 4. Each of the first portion 6210a and the second portion 6210b of the network stack 6210 may comprise any portion of the network stack 6210, in any one or more network layers, in user mode 6203, in kernel mode 6202, or combinations thereof, or on any portion of a network layer or interface point for a network layer or any portion of or interface point for user mode 6203 and kernel mode 6203.
The 6120 acceleration program herein may comprise software, hardware, or any combination of software and hardware. In some embodiments, the 6120 acceleration program comprises any type and form of executable instructions built and designed to execute or provide functionality and operations as described here. In some modalities, the 6120 acceleration program comprises any type and form of application, program, service, process, task or line. In one embodiment, the 6120 acceleration program comprises a driver, such as a network driver built and designed
253 to have an interface and work with the 6210 network stack. The logic, functions and / or operations of the 6120 acceleration program executable instructions can perform one or more of the following acceleration techniques: 1) 6238 multiple protocol compression, 2) 6224 transport control protocol clustering, 3) 6226 transport control protocol multiplexing, 4) 6228 transport control protocol buffering, and 5) caching through of a 6232 cache manager, which will be described in more detail below. In addition, the 6120 acceleration program can perform 6234 encryption and / or decryption of any communications received and / or transmitted by the 6205 client. In some embodiments, the 6120 acceleration program also performs tunneling between the 6205 client and another device computing device 6100, such as a 30 server. In other embodiments, the 6120 acceleration program provides a virtual private network connection to a server 30.
In some embodiments, the 6120 acceleration program operates on one or more layers of the 6210 network stack, such as the transport layer. In one embodiment, the 6120 acceleration program comprises a filter driver, a hooking mechanism or any form and type of suitable network driver interface that has an interface with the transport layer of the network stack, such as through the interface transport driver (TDI). In some embodiments, the 6120 acceleration program has an interface with a first protocol layer, such as the transport layer or another protocol layer, such as any layer above the transport protocol layer, for example, a transport layer. application protocol. In one embodiment, the 6120 acceleration program may comprise a driver that conforms to the Network Driver Interface Specification (NDIS), or an NDIS driver. In another embodiment, the 6120 acceleration program may comprise a minimum filter or a miniport driver. In one embodiment, the 6120 acceleration program or a portion thereof operates in the 6202 kernel mode. In another embodiment, the 6120 acceleration program or
254 a portion of it operates in 6203 user mode. In some embodiments, a portion of the 6120 accelerator program operates in 6202 kernel mode, while another portion of the 6120 accelerator program operates in 6203 user mode. In other modalities, the 6120 accelerator program operates in 6203 user mode, but has an interface with a kernel-mode driver, process, service, task or portion of the operating system, in order to obtain a data-level data structure. 6225 kernel. In additional modalities, the 6120 accelerator program is a user mode application or program, such as a 6220a to 6220n application.
The 6120 acceleration program can operate on or interface with a protocol layer in a way that is transparent to any other protocol layer of the 6210 network stack. For example, in one embodiment, the 6120 acceleration program operates or interfaces with the transport layer of the 6210 network stack transparently to any protocol layer below the transport layer, such as the network layer, and any protocol layer above the transport layer, such as session, presentation, or application layer protocols. This allows other protocol layers of the 6210 network stack to operate as desired and without modification, for use by the 6120 acceleration program. As such, the 6120 acceleration program can interface with the transport layer to accelerate any communications provided. through any protocol ported by the transport layer, such as any application layer protocol by TCP / IP.
Furthermore, the 6120 accelerator program can operate on or interface with the 6210 network stack in a transparent manner to any 6220a to 6220n application, a 6205 client user, or any other computing device, such as a server, in 6205 customer communications. The 6120 acceleration program can be installed and / or executed on the 6205 client in such a way that the 6120 acceleration program can accelerate any communications from a 6220a to 6220n application, without modifying the 6220a to 6220n application. In some cases, the user of the 6205 client or a computing device in communications with the 6205 client is not aware of the existence, execution or operation of the 6120 acceleration program. As such, in some embodiments, the 6120 acceleration program is installed, executed 5 and / or operated transparently for a 6220a to 6220n application, a 6205 client user, another computing device, such as a server, or any other one of the protocol layers above and / or below the protocol layer with the interface created by the 6120 accelerator program.
In some embodiments, the 6120 acceleration program performs one or more of the 6224, 6226, 6228, 6232 acceleration techniques in an integrated manner or manner. In one embodiment, the 6128 acceleration program comprises any type and form of mechanism for intercepting, hooking, filtering or receiving communications in the transport protocol layer of the 6210 network stack. By intercepting a 6205 client network packet in the transport layer and creating an interface with the 6210 network stack in the transport layer through a data structure, such as a 6225 kernel level data structure, the acceleration program 6120 can perform acceleration techniques 20 related to the transport layer in the network packet, such as transport control protocol (TCP) buffering, a TCP pool and a TCP multiplexing. In addition, the 6120 acceleration program can perform a 6225 compression or any of the protocols, or multiple protocols, ported as the network packet payload of the transport layer protocol.
In one embodiment, the 6120 accelerator program uses a 6225 kernel level data structure providing access to any portion of one or more network packets, for example, a network packet comprising a request from a 6205 client or a response to 30 from a server. In one embodiment, the kernel-level data structure can be used by the 6120 accelerator program to perform the desired acceleration technique. In one embodiment, the training program
256 6120 acceleration is running in 6202 kernel mode, when using the 6225 kernel level data structure, while in another mode the 6120 acceleration program is running in 6203 user mode, when using the level data structure 6225. In some embodiments, the kernel-level data structure can be copied or passed to a second kernel-level data structure, or any desired user-level data structure. Although the 6120 acceleration program is generally described in figure 40A as having a first portion operating in 6203 user mode and a second portion operating in 6202 kernel mode, in some embodiments, any portion of the 6120 acceleration program may run in 6203 user or in 6202 kernel mode. In some embodiments, the 6120 accelerator program can operate only in 6203 user mode, while in other modalities, the 6120 acceleration program can operate only in 6202 kernel mode.
Furthermore, by intercepting the transport layer of the 6210 network stack or obtaining access to the network packet through a 6225 kernel level data structure, the 6120 accelerator program can perform or apply a plurality of acceleration techniques at a single interface point or at a single run point or run time of any executable instructions from the 6120 accelerator program. For example, in a modality, function or instruction set in the 6120 acceleration program, a plurality of acceleration techniques can be performed, such as by calling a set of executable instructions built and designed to perform the technique of acceleration. acceleration. In some embodiments, the 6120 accelerator program at an interface point, place of execution or instruction set calls one or more application programming interfaces (APIs) for any program, service, process, task, line, or instruction executables designed and built to provide: 1) 6238 multiple protocol compression, 2) 6224 transport control protocol cluster, 3) 6226 transport control protocol multiplexing, 4) stores
257 buffering of transport control protocol 6228, and 5) caching through a 6232 cache manager and, in some embodiments, 6234 encryption.
By executing the plurality of acceleration techniques in one location or location in the executable instructions of the 6120 acceleration program or in a 6210 network stack protocol layer, such as the transport layer, the integration of these acceleration techniques is performed more efficient and effective way. In one aspect, the number of context switching between processes can be reduced, as well as reducing the number of data structures used or copies of data structures in memory needed or otherwise used. In addition, a synchronization of communications between any of the acceleration techniques can be performed more efficiently, such as in a tightly coupled manner, in a set of executable instructions from the 6120 acceleration program. As such, any logic, rules, functionality or operations relating to the order of acceleration techniques, which techniques to perform, and data and information to be shared or passed between techniques can be performed more efficiently. The 6120 acceleration program can intercept a TCP packet at the transport layer, obtain the TCP packet payload through a 6225 kernel level data structure, and then perform the desired acceleration techniques in one order desired. For example, the network packet can first be compressed and then cached. In another example, compressed cached data can be communicated via a buffered, grouped and / or multiplexed TCP connection to a server.
In some embodiments, and still with reference to figure 40A, a first program 6222 can be used to install and execute the acceleration program 6120, automatically, silently, transparently or otherwise. In one embodiment, the first 6222 program comprises a plug-in component, such as an ActiveX control or a Java control or a script that is loaded and executed by an application
258
6220a to 6220η. For example, the first program comprises an ActiveX control loaded and run by a 6220 web browser application, such as in the memory space or context of the 6220 application. In another embodiment, the first 6222 program comprises a set of executable instructions loaded in and run by the 6220a to 6220n application, such as a browser. In one embodiment, the first 6222 program comprises a program designed and built to install the 6120 acceleration program. In some modalities, the first 6222 program obtains, transfers (downloads) or receives the 6120 acceleration program over the network from another computing device. In another embodiment, the first 6222 program is an installer program or a plug and play manager for installing programs, such as network drivers or the 6205 client operating system.
In other embodiments, the first 6222 program may comprise any and all of the features described here in Section B. In another embodiment, the first 6222 program may comprise a 404 collector. In another embodiment, the first program may comprise a program for installing a collection agent. In another embodiment, the first 6222 program can also comprise a computing environment 15. In one embodiment, the first 6222 program may also comprise a means for installing a computing environment, such as an execution environment or a virtual execution environment. In one embodiment, the first program 6222 can comprise an application streaming client 442, as discussed previously. In another embodiment, the first 6222 program can comprise an application to be executed on a client 10.
In other embodiments, the first 6222 program may comprise a portion of the functionality, operations and logic of the 6120 acceleration program to facilitate or carry out any other functionality, operations and logic of the 6120 acceleration program described here, such as any of the techniques of acceleration. In some embodiments, the first 6222 program is used to establish a connection,
259 such as a transport layer connection, or a communication session with an appliance or a server, such as a Secure Socket Layer (SSL) communication session. In one embodiment, a first 6222 program is used to establish or facilitate the establishment of a virtual private network connection and a communication session.
The 6232 acceleration program cache manager 6232 or the 6205 client, as described in figure 40A, can comprise software, hardware or any combination of software and hardware for providing cache access, control and management of any kind and form of content, such as dynamically generated objects or objects presented by servers 30. The data, objects or content processed and stored by the 6232 cache manager can comprise data in any format, such as a markup language, or communicated through any protocol. In some embodiments, the 6232 cache manager duplicates the original data stored somewhere or previously computed, generated or transmitted data, where the original data may require a longer access time to be searched, computed or otherwise obtained in relation to a cache memory element. Once the data is stored in the data element and cache memory, future use can be made by accessing the cached copy, rather than retrieving or recomputing the original data, thereby reducing access time. . In some embodiments, the cache memory element may comprise a data object in the 6205 client memory. In other embodiments, the cache memory element may comprise a memory having a faster access time than the memory otherwise used by the 6205 client. In another embodiment, the mechanism element may comprise any type and form of memory element. 6205 client storage, such as a portion of a hard drive. In yet another modality, the 6232 cache manager can use any portion and combination of memory, storage, or drive.
260 cessation for caching data, objects and other content.
Furthermore, the 6232 cache manager can include any logic, functions, rules or operations for performing any modalities of the techniques described here. For example, the 6232 cache manager includes logic or functionality for object invalidation based on the expiration of an invalidation time period or upon receipt of an invalidation command from a 6205a client to 6205n or server 30. In some embodiments, the 6232 cache manager can operate as a program, service, process or task running in the 6202 kernel space and, in other modalities, in the 6203 user space. In one embodiment, a first portion of the cache manager 6232 runs in the 6203 user space, while a second portion runs in the 6202 kernel space. In some modalities; the 6232 cache manager can comprise any type of general purpose processor (GPP), or any other type of integrated circuit, such as a Programmable Field Array (FGPA), a Programmable Logic Device (PLD) or an Integrated Circuit Application Specific (ASIC).
The 6234 encryption agent of the 6120 acceleration program or the 6205 client comprises any logic, business rules, functions or operations for handling the processing of any security-related protocol, such as SSL or TLS, or any related function. For example, encryption agent 6234 encrypts and decrypts network packets, or any portion thereof, communicated by the 6205 client. The 6234 encryption agent can also configure or establish SSL or TLS connections on behalf of the 6205 client. As such, the 6234 encryption agent provides an offload and an acceleration of SSL processing. In one embodiment, encryption agent 6234 uses a tunneling protocol to provide a virtual private network between a 6205 client and another computing device, such as a server.
Still with reference to figure 40A, the compression agent of
261 multiple protocol 6238 of accelerator program 6120 or client 6205 comprises any logic, business rules, function or operations for compressing one or more protocols of a network packet, such as any of the protocols used by the client's 6210 network stack 6205. For example, 6238 multi-protocol compression may include compression and decompression utilities comprising GZip compression and decompression, differential compression and UnCompression, or any other proprietary or publicly available utility for compressing and decompressing data to be transmitted over a network. . In one embodiment, the 6238 multi-protocol compression agent compresses bidirectionally between the 6205 client and another computing device, such as servers, any TCP / IP-based protocol, including a Messaging Application Programming Interface (MAPI) ) (ernail), a File Transfer Protocol (FTP), a Hypertext Transfer Protocol (HTTP), Common Internet File System (CIFS) protocol (file transfer), an Independent Computing Architecture (ICA) protocol, a Remote Desktop Protocol (RDP), a Wireless Application Protocol (WAP), a mobile IP protocol, and a Voice over IP protocol (VolP). In other embodiments, the multiple protocol compression agent 6238 provides a compression of protocols based on Hypertext Markup Language (HTML) and, in some modalities, provides compression of any markup languages, such as the Extensible Markup Language ( XML). As such, the 6238 multi-protocol compression agent accelerates performance for users accessing applications through desktop clients, for example, Microsoft Outlook and lightweight non-web clients, just like any client opened by popular company applications. , such as Oracle, SAP and Siebel, and even mobile customers, such as Pocket PC.
The 6120 acceleration program also performs buffering, clustering and multiplexing transport protocol layer acceleration techniques, as will be described in greater detail below. As such, the 6120 acceleration program comprises any type and form of executable instructions having logic, rules, functions and operations for performing any of these techniques, as described here. The 6120 acceleration program intercepts, controls and manages any transport layer application programming interface (API) calls made by a 6220a through 6220n application through the 6210 network stack in the transport layer of the 6210 network stack. The acceleration program 6120 responds to any requests from client 6205 in a transparent manner, so that client 6205 receives a response as expected from the transport protocol layer of network stack 101010. For example, in one embodiment, the acceleration program 6120 intercepts on the network stack 6210 of client 6205 a request for establishing a transport layer connection with another computing device, such as a server, and can use a group of _____one or more transport layer connections established by the 6120 acceleration program to respond to the request. In another embodiment, the 6120 acceleration program multiplexes a request from a first 6220a application over an established transport layer connection used by a second 6220b application.
In some embodiments, the 6120 acceleration program comprises a mechanism for buffering or maintaining communications from the 6205 client to the 6205 client, prior to transmission over a network. For example, the rate of consumption by the 6205 client of communications received from a network, such as from a server, may be less than the rate of production of communications transmitted by the 6205 client on the network. As such, the 6205 client may be sending more requests to a server 30 at a higher rate than at which the 6205 client can consume and process responses from those requests. The acceleration program 6120 can intercept a communication, and determine whether a consumption rate and / or a production rate of the 6205 client is below a predetermined limit, such as a limit configured by a user, by the 6205 client or by a another computing device. If the rate determined is below the desired limit, the acceleration program
263
6120 will store the intercepted communication in a customer's memory element, until the 6205 customer's performance increases the consumption rate and / or the production to a rate equal to or higher than the predetermined or desired limit. At this point, a client-side mechanism is provided for strangling the 6205 client's communications, based on the consumption performance and / or the production of communications by the 6205 client.
The 6220a to 6220n application described in figure 40A can be any type and / or form of application, such as any type and / or form of web browser, web-based client, client-server application, a client computing client lightweight, an ActiveX control, or a Java applet, or any other type and / or form of executable instructions capable of executing on the 6205 client or communicating over a 6204 network. The 6220a to 6220n application can use any type of protocol and it can be, for example, an HTTP client, an FTP client, an Oscar cylinder or a Telnet client. In some embodiments, the 6220a to 6220n application uses a remote display or presentation level protocol. In one embodiment, the 6220a to 6220n application is an ICA cylinder, developed by Citrix Systems, Inc. of Fort Lauderdale, Florida. In other ways, the 6220a to 6220n application includes a Remote Desktop (RDP) client, developed by Microsoft Corporation of Redmond, Washington. In other modalities, the 6220a to 6220n application comprises any type of software related to VolP communications, such as an IP softphone. In other embodiments, the 6220a to 6220n application comprises any application related to real-time data communications, such as applications for streaming video and / or audio.
Figure 40B illustrates an example architecture for a 1250 appliance similar to the appliance architecture described in figure 27. In a brief overview, appliance 1250 comprises a 6206 hardware layer and a software layer divided into a 6203 user space and a 6202 kernel space. The 6206 hardware layer also
264 provides the structures and elements which allow programs and services in the 6202 kernel space and 6203 user space to communicate data internally and externally with respect to the 1250 apparatus. The software layer comprises programs, services, processes, tasks, 5 lines and other executable instructions for the provision of logic, functions and operations of the 1250 apparatus.
Apparatus 1250 comprises a 6275 application acceleration determination mechanism and a 6120 client-side acceleration program. The 6275 application acceleration determination mechanism comprises software, hardware or any combination of hardware and software. In some embodiments, the 6275 application acceleration determination mechanism comprises any type and form of executable instructions, such as a program, service, process, task or line having logic, function, resets or operations Tara determine whether a 6220a application a 6220n running on a 6205 client and / or server 30 can be accelerated or if access or communications between a 6205 client and a server 30 can be accelerated. In one embodiment, a database is used by the 6275 application acceleration determination engine to determine whether a 6220a to 6220n application can be accelerated. 20 For example, the database can associate a 6220a to 6220n application with one or more acceleration techniques capable of accelerating the 6220a to 6220n application, and it can also be based on user, type, shape, location, processing capacity and other features of the 6205 client and / or server 30. In some embodiments, the 6275 application acceleration determination mechanism uses a lookup table, file, data structure or object in memory comprising information identifying whether an application 6220a to 6220n by name, type or category can be accelerated by an acceleration technique. In other embodiments, the 1250 apparatus and / or the 6275 application acceleration determination mechanism includes a configuration mechanism, such as a user interface, graphics, command line or otherwise, for receiving a user input for identification, specification
265 or configuration as to whether a 6220a to 6220n application or access to a server 30 can be accelerated.
In some modalities, the 6275 application acceleration determination mechanism requests information from server 30 identifying whether an application 6220a to 6220n can be accelerated and, in other modalities, by what acceleration technique (s) and for what type and form of 6205 customers. In yet another modality, the 6275 application acceleration determination mechanism comprises a database of historical information regarding the performance of a 6220a application 10 to 6220n between a 6205 client and a server 30, with and without one or more client-side acceleration, for the provision of a database of comparative and heuristic information about where the 6220a to 6220n application is accelerated or capable of being accelerated, using any client-side acceleration techniques. For example, the device in 1250 po15 captures network-related performance information related to the performance of the 6220a to 6220n application from the 6205 client. As such, the determination as to whether a 6220a to 6220n application is capable of being accelerated can be adapted to be based on or influenced by a change in the operational and performance characteristics of the 6204 network.
In one respect, the 6220a to 6220n application may not be able to be accelerated or may be able to be accelerated, but the acceleration would not be effective or would otherwise be minimal. In one embodiment, the application type and form 6220a to 6220n may not use a protocol or may not communicate in a manner suitable for use with an acceleration technique. In another modality, the protocol or the way in which the 6220a to 6220n application communicates may allow the performance of an acceleration technique, but based on any of the operational or performance characteristics of the 6205 client, the 1250 or of server 30, the acceleration technique would not be effective or otherwise 30 would provide minimal acceleration. As such, the 6275 application acceleration determination engine may determine that the 6220a through 6220n application is not intended to be accelerated, based on whether the 6220a application
266 the 6220η is capable of being accelerated or whether the acceleration would suit a desired predetermined limit of performance improvement.
In another aspect, the apparatus 6250 stores a client side acceleration program 6120 in a storage or memory element of the apparatus 1250, such as a storage or memory provided by the hardware layer 6206 of the apparatus. In one embodiment, the 1250 appliance dynamically determines via the 6275 application acceleration determination mechanism a 6220a to 6220n application to be used or being used by the 6205 client that can be accelerated by the 6120 acceleration program running on the 6205 client and transmits or otherwise it communicates the acceleration program 6120 from the storage or memory of the 1250 appliance to the customer 6205. In another embodiment, apparatus 1250 determines that communications between client 6205 and a server 30 can be accelerated by the acceleration program 6120 running on client 6205 and communicates acceleration program 6120 to client 6205. In some embodiments, the apparatus 1250 receives, transfers (via download) or obtains the acceleration program 6120 from another computing device 6100, such as a server 30.
In some embodiments, the 6120 accelerator program receives, transfers (via download) or obtains policy information from policy agent 3236 on device 1250. In other modalities, the 6120 accelerator program executes or operates a policy agent, independently of or in conjunction with policy agent 3236 of the 1250 apparatus. In other embodiments, the 3240 packet agent or a portion thereof can be operated on the 6205 client, as well as a part of the 6120 acceleration program. As such, the 6120 acceleration program can operate on the 6205 client according to the timing timer. 3242 packet processing, as described above. In one embodiment, the 6120 acceleration program can perform acceleration techniques integrated at a point in execution and in response to granular time intervals provided by the 3242 packet processing timer.
267
In some modalities, the health monitoring program 3216 can check and determine the status, error or history of any 6120 client side acceleration program on any 6205 client in communication with the 1250 appliance or to which the 1250 appliance has transmitted the acceleration program 6120. In some modalities, the health monitoring program 3216 or a portion of it is executed on client 6205.
Referring now to Figure 41A, a modality of a 6300 method for dynamic provisioning by the 1250 apparatus of an acceleration program 6120 and for automatic installation and execution of the acceleration program 6120 by the customer 6205 is described. In a brief overview, in step 6310, apparatus 1250 intercepts a request from a 6205 client to establish a communication session with the server. In step 6315. the 1250 appliance will transmit the 6120 acceleration program for the 6205 client to the 6205 client automatically install and execute. In step 6320, upon receipt of the 6120 acceleration program, the 6205 client automatically executes the 6120 acceleration program on the 6210 network stack to intercept communications between the 6205 client and the server 30. In step 6330, the acceleration program 6120 performs any of the plurality of acceleration techniques and can encrypt and / or decrypt communications.
In more detail, in step 6310, the apparatus 1250 can intercept or otherwise receive, by any suitable means and mechanisms, a request from client 6205 to establish a communication session with server 30. In one embodiment, the agent packet 6240 of the 1250 appliance intercepts communications from the 6205 client. In other embodiments, apparatus 1250 establishes a first transport layer connection with the 6205 client, for example, with the 6120 acceleration program, and a second transport layer connection with the 6205 server on behalf of the 6205 client. , the apparatus 1250 can receive, intercept or otherwise obtain any of the client communications transmitted to the server 30.
268
In some embodiments, the appliance 1250 intercepts a request for the client 6205 to establish a transport layer connection with the server 30. In other embodiments, the appliance 1250 intercepts a request for the establishment of a communication session through any protocol layer above the transport layer connection, such as an HTTP application layer protocol. This method modality can be practiced with a request for the establishment of a communication session in any protocol layer of the 6210 network stack of client 6205.
In step 6315, the device 1250 transmits the acceleration program 6120 to the customer 6205. The device 1250 can transmit the acceleration program 6120 at any point before, during or after the establishment of the communication session requested by the customer 6205. In one mode , the device 1250 transmits the acceleration program 6120 to the customer 6205 in response to the interception of the customer request. In another modality, the device 1250 forwards the request to the server 30 and transmits the acceleration program 6120 to the client 6205. In some modalities, the device 1250 establishes the communication session with the server 30 and, upon the establishment of the session communication device, the 1250 device transmits the 6120 acceleration program. In yet another modality, the 1250 appliance performs the authentication and / or authorization of the 6205 client, or the 6205 client user, and if the authenticated 6205 user or client is authorized in this way, the 1250 appliance transmits the 6120 acceleration program for the 6205. In one embodiment, the apparatus 1250 forwards the client request to server 30 for authentication and / or authorization and, if server 30 authenticates and / or authorizes the client request, apparatus 1250 transmits the 6120 acceleration program to the client 6205.
In some modalities, the apparatus 1250 transmits the acceleration program 6120 from the storage or memory of the apparatus 1250. In other modalities, the apparatus 1250 requests the acceleration program 6120 from the server 30 and forwards the program.
269 acceleration program received 1620 to client 6205. In another mode, server 30 transmits the acceleration program 6120 to client 6205. In one mode, apparatus 1250 transmits a Uniform Resource Locator (URL) to client 6205 to the 6205 customer obtain, download (download) or receive the acceleration program. In some embodiments, the URL identifies a location of the 6120 accelerator program in a storage or a location in the 1250 appliance, while in other embodiments the URL identifies the 6120 accelerator program on a server 30, such as a web server providing the program 6120 accelerator for download (via download). In one embodiment, the 6120 accelerator program is stored on the 6205 client, and the 1250 device transmits a key, such as an encryption or license key, to the 6205 client for the 6205 client to install and make use of the 6120 acceleration program. stored on client 6205. In some embodiments, the 1250 equipment transmits any files, configuration, data or other information to the 6205 client to be used for installation and execution of the 6120 acceleration program on the 6205 client.
In one embodiment, the 6120 accelerator program is designed and built to be automatically installed and executed by the 6205 client. The 6120 accelerator program can include any files, entries, configuration, data or instructions for making the 6120 accelerator program registered or recognized by the 6205 client operating system, according to the type and form of the operating system. In one embodiment, another computing device, such as a server or a switch, transmits the acceleration program to the 6205 client, and the 6205 client automatically installs and executes the 6120 acceleration program. In one mode, the acceleration program 6120 is designed and built to be a plug-and-play (PnP) device to be added to a computing device running 6100. In some embodiments, the 6120 accelerator program is a self-installing executable, just like an executable including an installer program and the 6120 accelerator program. In other embodiments, the 6120 accelerator program
270 may include a plurality of files, for example, an installation package or an installation download (such as download), such as files required for registration and installation of the 6120 accelerator program on the 6205 client operating system. For example, the acceleration 6120 can comprise an .inf file and an .sys file. An .inf file provides a Windows Septup in the Microsoft Windows family of operating systems with the information required to configure a device, such as a list of valid logical settings for the device and the driver file names associated with the device. In some 10 modalities, the .inf file can comprise an autorun .inf file, which is a configuration file that tells or tells the operating system which executable to start and any configuration information related to the start of the executable. In one embodiment, the .sys file is the driver file purchased in the application program R120 in a 15 of the same.
In step 6320, the 6205 client automatically installs the 6120 acceleration program. The 6120 acceleration program can be installed in any suitable manner according to the 6205 client operating system. In one embodiment, the 6205 client installs the 20 acceleration program 6120 upon receipt of the 6120 acceleration program.
In some embodiments, the 6205 client automatically performs or performs a silent installation of the 6120 accelerator program. In one embodiment, the silent installation is performed transparently to a 6205 client user or application. In other modalities, the silent installation 25 of the 6120 acceleration program does not require a 6205 client reboot or restart. In another mode, the silent installation does not require user interaction to begin and / or complete the installation. In other embodiments, the silent installation of the 6120 acceleration program occurs while the 6205 client is running transparently to a network layer, session layer and / or application layer of the 6210 network stack. In some modalities, the 6120 acceleration program is a self-installing executable that is run by customer 271 and 6205. In other modalities, the 6205 client uses a plug-and-play manager to install the 6120 accelerator program. In one embodiment, the 6205 client comprises an installation manager which receives and installs the 6120 accelerator program. in another embodiment, the 6120 acceleration program transmitted by the 1250 apparatus also includes an installation program that installs the 6120 acceleration program.
In another mode, the 6120 acceleration program is automatically installed through a silent installation. In a modality, a silent installation comprises an installation not attended by a user. In another mode, a silent installation comprises an installation that does not require or interact with the user to begin and / or complete the installation. In some modalities, the installation is silent because the installation process does not require information regarding an installation status or progress. In one embodiment, the installation is silent because the installation process does not display information regarding the status or progress of the installation . In one embodiment, the installation is silent because it is transparent to the user. In other modalities, the installation is silent because the installation of the 6120 accelerator program does not require a reboot or a restart of the 6205 client. In another mode, the installation is silent because the installation occurs seamlessly during an operation 6205, without interruption or disruption to the customer's operation. As such, the 6120 accelerator program can be installed in a way that is transparent to the user or a 6205 client application by not requiring a reboot and not displaying any information to the user related to the installation.
In order to prevent or prevent a reboot or restart of the 6205 client, in some modalities, the 6205 client, like the 6205 client's operating system, has a plug and play manager for installing and configuring drivers, such as a network driver in a 6120 acceleration program mode, for Plug and Play devices, en
272 when the operating system is running. In one embodiment, the plug and play manager is not instructed to reboot or restart the 6205 client, based on the configuration of the 6120 accelerator program installation package. In another embodiment, the .inf file does not comprise an instruction to rebound or restart the computer. In one embodiment, the 6120 acceleration program can be implemented as a side-by-side component, instead of replacing shared dynamic link libraries (DLLs) in use. In other specific embodiments, for a 6120 accelerator program network driver, the 6120 accelerator program uses the INetCfgPnpReconfigCalIback network driver API, so that the user is not required to reboot the operating system to cause configuration changes have an effect on the driver. In addition, the 6120 accelerator program may have a notification object that calls the SendPnpReconfig API in its implementation of the ApplyPnpChanges method of INetCfgComponentControl to send configuration information to the network component driver that owns the object. The SendPnpReconfig API provides a notification object with a mechanism for sending data to the driver and, in some ways, is used to avoid requiring a user to reboot the operating system before configuration changes take effect.
In step 6325, upon completion of the installation of the 6120 acceleration program automatically, silently, transparently or otherwise, the 6120 acceleration program is automatically executed on the 6205 client. In some embodiments, the installation program that installs the program 6120 accelerator starts or runs the 6120 accelerator program. In some embodiments, the installer program for the 6120 accelerator program makes a system call to load or execute the 6120 accelerator program in the 6205 customer memory. In one embodiment, the 6120 accelerator program installation comprises an instruction, a command or a directive to start the 6120 acceleration program. In one embodiment, the 6120 acceleration program includes an automatic run configuration, such as an auto file
273 run.inf, which notifies the 6205 client to automatically run the 6120 accelerator program. In other ways, a plug and play manager or the 6205 client's operating system automatically runs the 6120 accelerator program upon installation. In one embodiment, the 6120 acceleration program comprises a service, process, line or task, which is initiated by the 6205 customer. In some embodiments, the 6120 accelerator program is an operating system service that is configured to start automatically. In one embodiment, the 6120 acceleration program comprises a network driver loaded into the network stack memory of the client's operating system.
In another embodiment, the 6120 accelerator program comprises a network driver that is loaded into the 6205 client memory. In some embodiments, the 6120 accelerator program is loaded into memory allocated to the 6210 network stack. In some cases, the 6120 acceleration program is loaded and executed in an area or memory space that allows the 6120 acceleration program to access a protocol layer of the network stack, such as the transport layer. In other cases, the accelerator program is loaded and executed in memory that allows the 6120 accelerator program to access a 6225 kernel level data structure. In other embodiments, the 6120 accelerator program is loaded into an application's memory 6220a to 6220n. In another mode, the 6120 acceleration program runs independently in its own memory space or context. In one embodiment, the 6120 acceleration program runs in the memory space or context of a 6220a to 6220n application. In some embodiments, the 6120 accelerator program is loaded into a user mode memory or a memory allocated to the 6203 user mode, while in other modalities the 6120 accelerator program is loaded into a kernel mode memory or an allocated memory. to 6202 kernel mode.
In some embodiments, the 6120 acceleration program is loaded into memory and / or executed on the 6205 client in a trans way
274 relative to a client user, a 6205 client application, the 1250 appliance or the 30 server. In other modalities, the 6120 acceleration program is executed to interface with the transport layer of the 6210 network stack, and is executed transparently to any protocol layer above the transport layer, such as a session or application layer, and any protocol layer below the transport layer, such as the network layer. In one embodiment, the acceleration program 6120 is executed transparently for any connection of the transport layer of the 6205 client, or the transport layer itself.
At step 6330, the acceleration program 6120 loaded, started, or otherwise running performs any of the plurality of acceleration techniques in the 6120 acceleration program, such as any techniques provided by: 1) 6238 multiple protocol compression, 2) 6224 transport control protocol clustering, 3) 6226 transport control protocol multiplexing, 4) 6228 transport control protocol buffering, and 5) caching through from a 6232 cache manager. The 6120 accelerator program can also perform any encryption and / or decryption of communications between client 6205 and server 30. In one embodiment, the 6120 acceleration program performs multiple protocol compression. In another mode, the 6120 acceleration program performs a transport control protocol grouping and in an additional mode, the 6120 acceleration program performs a multiplexing through the grouped transport layer connection. In one embodiment, the 6120 acceleration program performs transport control protocol buffering. In some embodiments, the 6120 accelerator program performs caching. In other embodiments, the 6120 accelerator program performs caching and compression. In one embodiment, the 6120 accelerator program performs caching with a transport layer cluster and multiplexing. In another modality, the acceleration program
275
6120 performs multiple protocol compression with a transport layer cluster and a multiplexing. In another modality, the acceleration program 6120 performs caching and / or compression with TCP buffering, and in an additional modality, with TCP grouping and multiplexing.
As such, the 6120 acceleration program is dynamically provided by the 1250 apparatus and automatically installed and executed on the 6205 client in a silent or transparent way for the 6205 client user or application to perform one or more client side acceleration techniques. for communications between the 6205 client and a server 30. The 6120 acceleration program can perform these acceleration techniques transparently for any protocol layer of the network stack and transparently for a client user, client application, appliance or server.
In another aspect, the 1250 appliance can determine whether an application requested to be accessed by the 6205 client can be accelerated, and provide the 6120 acceleration program for the 6205 client, if the application can be accelerated. Referring now to Figure 41B, another embodiment of a method is described. The method can be practiced through requests for establishing a connection or a communication session as well as requests for access to an application on a server. In a brief overview of the 6350 method, in step 6355, the 1250 appliance intercepts a request from a 6205 client requesting access to a 6220a to 6220n application on a 30 server. In step 6260, the 1250 appliance determines whether the 6220 application is capable to be accelerated. In step 6265, if application 6220 cannot be accelerated, then the application forwards the request to the server in step 6267. In step 6365, if application 6220 can be accelerated, then appliance 1250 determines whether the acceleration program 6120 is installed on client 6205 or was previously transmitted to client 6205. If the acceleration program 6120 has not yet been provided for client 6205, then method 6250 continues in step 6315 of method 6300 described above
276 for the transmission, installation and execution of the acceleration program. If the 6120 accelerator program has been installed and is running on the 6205 client, then the 1250 device, in step 6375, sends a message to the 6120 accelerator program on the 6205 client to accelerate the 6220 application. In step 6330 of method 6350, the 6120 acceleration program performs a plurality of communications acceleration techniques for the 6220 application, and can encrypt and / or decrypt those communications.
In more detail, in step 6355, the device 1250 can intercept by any means and appropriate mechanisms a request from the client 6205 to access an application provided by the server 30. In one embodiment, the packet agent 6240 of the device 1250 intercepts communications to from customer 6205. In other embodiments, apparatus 1250 establishes a first transport layer connection with the 6205 client, for example, with the 6120 acceleration program, and a second transport layer connection with the 6205 server on behalf of the 6205 client. , the apparatus 1250 can receive, intercept or otherwise obtain any of the client communications transmitted to the server 30. In some modalities, the device 1250 intercepts a request for the client 6205 to access a 6220 application through a transport layer connection established with the server 30. In other modalities, the device 6205 intercepts a request for the establishment of a communication session through any transmission power layer above the transport layer connection, such as an HTTP application layer protocol. In one embodiment, apparatus 6205 intercepts a request from client 205 to display and provide an application 6220 from server 30 through a remote display protocol, such as ICA or RDP.
In step 6360, apparatus 1250 determines whether application 6220 requested by customer 6205 can be accelerated. In some embodiments, the 1250 appliance identifies, extracts or otherwise processes an application identifier from the intercepted customer request that
277 identifies the application by name, type or category. In one embodiment, the 6275 application acceleration determination mechanism is used by the 1250 appliance to determine whether the 6220 application can be accelerated. In some embodiments, the 6275 application acceleration determination engine performs a search or query against a database, query table, or other structured data source in memory or storage, such as a data structure or an object , to determine whether the 6220 application can be accelerated. In another embodiment, apparatus 1250 sends a communication, such as a request, to a server 30 to determine whether the 6220 application can be accelerated.
In other embodiments, the 1250 appliance has a performance record or history to determine whether the 6220 application has been accelerated before and whether the acceleration has improved the performance and operation of the 6220 application. As such, the 1250 appliance can determine that an application 6220 can be accelerated, if that acceleration meets a predetermined limit of improvement in the performance or operations of the 6220 application. In yet another modality, the 1250 appliance provides heuristic rules based on the current operation and the performance of the 6204 network, the 6205 client or the 30 server. In one modality, the 6220 application can be determined to be capable of being accelerated, if the 6205 customer has certain performance and operational characteristics or capabilities, for example, a processor with a certain speed or a minimum amount of memory. In some embodiments, the 6220 application can be determined to be capable of being accelerated based on a configured policy or rule, such as on the policy manager of the 1250 appliance. For example, a 6220 application to be communicated between a remote user with a a certain type of client 6205 accessing a certain type of application 6220 and / or server 30 can be accelerated. In other embodiments, the 6220 application can be determined to be capable of acceleration based on user or customer 6205 authentication and authorization. In yet another embodiment, the 6220 application can be
278 determined as not being desired to be accelerated. For example, the 6220 application is of a type that is not used frequently.
In step 6365, if application 6220 is determined not to be capable of being accelerated or otherwise it is desired not to apply acceleration techniques to application 6220 on client 6205, appliance 1250 forwards the intercepted client request to server 30 in step 6368 and does not transmit or provide the acceleration program 6120 to the customer 6205. In one embodiment, the 1250 apparatus can perform or provide an acceleration based on the 6220 apparatus. In other embodiments, the 1250 appliance does not accelerate the 6220 appliance on the 1250 appliance. In yet another modality, the 1250 appliance can perform some acceleration techniques and not others for the 6220 appliance, if the 1250 appliance determines that the 6220 appliance it is not capable of being or otherwise desired to be accelerated.
In step 6365, if the 6220 application is determined to be capable of being accelerated or otherwise it is desired to apply acceleration techniques to the application on the 6205 client, the 1250 appliance will determine whether the 6120 acceleration program has been provided for the 6205 client. one mode, the 1250 device determines whether the 6120 acceleration program has been installed on the 6205 client or is running on the 6205 client. In some embodiments, the 1250 appliance sends a communication to the 6120 accelerator program on a 6205 client to determine whether the 6120 accelerator program is running on the 6205 client. In other modalities, the 1250 appliance checks a log file or a log file. history to determine whether the 6120 acceleration program has been transmitted to the 6205 client. In another embodiment, the 1250 appliance checks with a 6216 health monitoring program from the 1250 appliance or from the 6205 client, to determine whether the 6120 acceleration program is running on the 6205 client.
If the 1250 device determines that the 6120 acceleration program was not transmitted, installed and / or executed on the 6205 client, the
279 apparatus 1250 will provide the 6120 acceleration program according to the 6300 method steps described together with figure 41 A. For example, the 1250 apparatus transmits the 6120 acceleration program to the 6205 client, which the 6205 client upon receipt install and run. In one embodiment, by performing the appropriate steps of the 6300 method, the 1250 apparatus can communicate in step 6275 a message to the acceleration program to apply one or more of the acceleration techniques to the 6220 application. In other modalities, if the acceleration program 6120 is already installed and running, then, in step 6375, the apparatus 1250 communicates a message to the acceleration program 6120 to apply one or more of the acceleration techniques to the 6220 application.
In some modalities, the 6120 acceleration program performs any of the acceleration techniques available by the 6120 acceleration program for the identified application 6120. In another mode, the 1250 apparatus indicates to the 6120 acceleration program which of the acceleration techniques to perform for the 6220 application. In one embodiment, the 6120 acceleration program can apply the desired acceleration techniques for the 6120 application on a per-session basis. That is, the message from device 1250 to the 6120 acceleration program only informs the 6120 acceleration program to perform acceleration techniques for this instance or session of the 6220 application. In other modalities, once the 6120 acceleration program receives a message from the 1250 device to apply acceleration techniques to the identified application 6220, the 6120 acceleration program applies the acceleration techniques to any 6220 application instances or sessions , or until the 6205 client is rebuilt or restarted, or the 6205 system is rebuilt or restarted.
In one embodiment, the message from device 1250 in step 6375 is not application specific. For example, the message tells the 6120 accelerator program to perform one or more of the acceleration techniques for any 6205 client application.
280 modalities, the message sent to the 6205 client informs the 6120 acceleration program to stop using any or more of the acceleration techniques for the 6220 application, or for all 6220a to 6220n applications. In another embodiment, the 1250 appliance communicates a message to the 6120 acceleration program to ignore certain 6220 applications. In yet another embodiment, apparatus 1250 communicates a message to the 6120 acceleration program to provide configuration data or information for the 6120 acceleration program, such as an update to an acceleration technique or an application of a new acceleration technique. acceleration.
In step 6330, the 6120 acceleration program performs any of the plurality of acceleration techniques from the 6120 acceleration program for the 6220 application, such as any techniques provided by 1) 6238 multiple protocol compression, 2) control protocol grouping transport 6224, 3) transport control protocol multiplexing 6226, 4) transport control protocol buffering 6228, and 5) caching via a 6232 cache manager. The 6120 accelerator program can also perform any encryption and / or decryption of communications between the 6205 client and server 30. In one embodiment, the 6120 accelerator program performs a multiple protocol compression of application-related data. In another modality, the 6120 acceleration program performs a transport control protocol grouping and, in an additional modality, the 6120 acceleration program performs a multiplexing through the grouped transport layer connection. In one embodiment, the 6120 acceleration program performs transport control protocol buffering. In some embodiments, the 6120 accelerator program performs caching. In other embodiments, the 6120 accelerator program performs caching and compression. In one mode, the 6120 acceleration program performs caching with a transport layer cluster and in an additional mode also with multiplexing. In a
281 another modality, the acceleration program 6120 performs a compression of multiple protocol with a buffering of TCP, and in an additional modality with grouping of transport layer and, still in an additional modality also with multiplexing. In another modality, the acceleration program 6120 performs caching with compression and, in an additional modality, with TCP grouping and in an additional modality with multiplexing.
As such, a 1250 appliance dynamically determines whether to accelerate an application or whether the application can be accelerated, and communicates with the 6120 client-side acceleration program to perform on the 6205 client any or more of the acceleration techniques for the 6220 application. Furthermore, in some modalities, a plurality of 6120 acceleration programs can be dynamically delivered to the 6205 customer by the apparatus and automatically installed and executed by the 6205 customer. For example, an acceleration program can be provided according to the techniques and procedures. methods for each connection to a 6205 server, or each communication session with a 6220 application. As such, the 6205 client can automatically install and run a plurality of 6120 accelerator programs for handling and accelerating each 630 server or 6220a through 6220n application.
Referring now to Figure 41C, an embodiment of a 6380 method for carrying out a plurality of acceleration techniques in an integrated manner is described. In a brief overview, in step 6280, the acceleration program 6120 intercepts in the transport layer a network packet of communication between the client 6205 and the server 30 through a transport layer connection. In step 6390, the acceleration program 6120 accesses the network packet in the transport layer through a kernel level data structure, for example, a data structure provided with an API for the 62010 client 6210 network stack. In step 6395, the 6120 acceleration program performs a plurality of acceleration techniques in an integrated manner, using the kernel level data structure at an interface point or at a
282 execution point in the 6120 acceleration program.
In more detail, in step 6385, the acceleration program 6120 intercepts by any suitable means and mechanisms a network packet of communication between client 6205 and server 30 over a transport layer connection. In one embodiment, the 6120 acceleration program intercepts a network packet from or related to a request by the client or a response to it, to establish a transport layer connection between client 6205 and server 30. In another embodiment, the 6120 acceleration program intercepts a network packet from or related to a request or response to it, to access or use a 6220 application through the transport layer connection between the 6205 client and the server 30 . In one embodiment, the acceleration program 6120 intercepts the network packet at the transport protocol layer via a transport driver interface or otherwise a network driver interfaced to a transport protocol layer of the 6210 network stack. In another embodiment, the 6120 acceleration program intercepts the network packet at the transport protocol layer or any other protocol layer of the 6210 network stack via a Network Driver Interface Specification (NDIS) driver, or a driver miniport, or a minifilter driver. In some embodiments, the 6120 acceleration program intercepts the network packet at the transport layer through a hooking or filtering mechanism.
In step 6390, the 6120 accelerator program accesses or otherwise obtains information and data from the network packet intercepted at the transport layer through a 6225 kernel level data structure. Using the 6225 kernel level data structure , the 6120 acceleration program can obtain information and data on the payload (s) or one or more protocols ported or transported by the network packet in the transport layer. In some embodiments, using a kernel-level data structure for representing the network packet at the layers of the network stack at and / or above the transport layer allows the 6120 acceleration program to perform or operate the plurality of techniques.
283 of acceleration in the transport layer and for protocol layers carried by the transport layer network packet. In one embodiment, the use of a single 6225 kernel-level data structure prevents or avoids a copy and allocation of memory along with a context switch using multiple data structures in multiple protocol layers of the 6210 network stack. . In one embodiment, the accelerator program 6120 copies the kernel level data structure 6225 to a second data structure, which can comprise another kernel level data structure or a user level data structure.
In step 6395, the acceleration program 6120 performs, executes or operates the plurality of acceleration techniques at a single interface point or an execution point in the 6210 program or in a set of executable instructions or a 6210 program execution point. The 6120 acceleration program performs any of the plurality of acceleration techniques in the 6120 acceleration program, such as any techniques provided by: 1) 6238 multiple protocol compression, 2) 6224 transport control protocol clustering, 3) multiplexing of transport control protocol 6226, 4) buffering transport control protocol 6228, and 5) caching through a 6232 cache manager. The 6120 acceleration program can also perform any encryption and / or decryption of the 6220 application communications between client 6205 and server 30 at the same point of execution of the acceleration techniques of the 6120 acceleration program.
In one embodiment, the 6120 acceleration program performs in a set of executable instructions, such as a function call or a location or a location, any desired plurality of acceleration techniques subsequently to each other. For example, the 6120 accelerator program obtains the intercepted network packet through a kernel level data structure and then executes the instructions representing the logic, function, rules or operation of the acceleration techniques subsequently. to others: As such, information and data from the network packet can be extracted or obtained once through the structure.
284 6225 kernel-level data and used as input, parameters, arguments and conditions for any of the instructions in the 6120 acceleration program representing acceleration techniques. Although the network packet contains higher-level protocol data and information, the 6120 acceleration program in some embodiments processes the higher-level network data and protocol data and information at one point and at a time during an execution. In addition, the 6120 acceleration program can perform each of a plurality of acceleration techniques in any desired order in an integrated manner, such as compressing data stored in the 6232 cache manager or compressing / decompressing data retrieved from the cache.
In one embodiment, the 6120 acceleration program performs multiple protocol compression and caching subsequent to each other. In another modality, the acceleration program 6120 performs, subsequently to each other, operations related to a transport control protocol grouping and multiplexing through the grouped transport layer connection. In one embodiment, the 6120 acceleration program performs transport control protocol buffering subsequent to compression and caching, or to a TCP grouping and / or multiplexing. In some embodiments, the 6120 accelerator program performs caching. In one embodiment, the 6120 accelerator program performs caching subsequent to a transport layer and multiplexing cluster. In another embodiment, the 6120 acceleration program performs a multiple protocol compression subsequently to a transport layer cluster and a multiplexing. In one embodiment, the 6120 accelerator program performs caching and compression subsequently with TCP buffering and in an additional modality subsequently with TCP pooling and multiplexing.
285
Although the acceleration program is generally described as subsequently performing acceleration techniques, a subsequent execution may also include other logic, functions and operations not related to an acceleration, but integrated and executed between each acceleration technique. The acceleration program still obtains operational and performance efficiency with this integration according to the executable instructions for the acceleration techniques and any other operations or functions are performed at a single interface point or point of execution in the acceleration program. Furthermore, acceleration techniques for protocol layers carried on or above the transport protocol layer are processed at a time and / or at a location on the transport layer. As such, the acceleration techniques for these higher level protocols do not need to be applied again as the network packet traverses and is processed at these higher levels of the 6210 network stack, or at a later point in the 6210 network stack.
In other respects, a first program 6222 and the acceleration program 6120 (or also referred to as the second program in this embodiment) can be used. In one embodiment, the first 6222 program together with the second 6120 program can be used to facilitate and establish a virtual private network connection with a server 30, such as through the 1250 appliance, by which the client-side acceleration techniques can be applied. In another embodiment, the first 6222 program is used to install and execute the second program or the 6120 acceleration program.
Referring now to Fig. 42A, an embodiment of a 6400 method for practicing this aspect is described. In a brief overview, in step 6402, client 6205 logs in and establishes a communication session with the 6205 system. In step 6404, system 1250 sends the first 6222 program to client 6205. In step 6406, the client 6205 installs and runs the first 6222 program, which in turn installs and runs the 6120 acceleration program, that is, the second program. In step 6407, the 6205 client communicates with and accesses resources on
286 a private network through an established encrypted data communication session. In step 6410, client 6205 logs out of the 1250 system and ends the communication session with the 1250 system.
In step 6402 of method 6400, client 6205 performs a login procedure and establishes an encrypted data communication session with device 1250 over the 6204 network. In one embodiment, the encrypted data communication session is used as a tunnel for form a traffic bridge from client 6205 to any of the servers 30, which reside behind the apparatus 1250 on a private data communication network. In one embodiment, the 6205 client logs in and establishes a data communication session with the 1250 appliance using the Secure Sockets Layer (SSL), or other encryption methods, such as IPSec, and Transport Level Security (TLS) ). In another embodiment, a protocol such as Secure Sockets Layer Hypertext Transfer Protocol (HTTPS) can be used to initiate the encrypted data communication session.
In step 6404, in response to a login and the establishment of the encrypted data communication session, the 1250 appliance sends a first program to the 6205 client over the 6204 network. The first program is designed and built, or otherwise configured, to act as a tunnel endpoint for communication through the encrypted data communication session. In one embodiment, the first program comprises a plug-in application that is automatically installed and run by the 6204 client browser. For example, the first program can comprise an ActiveX control that is provided as a plug-in to be run by the browser Microsoft Internet Explorer® web page. In another embodiment, the first program may comprise a Java applet that is provided as a plug-in to be run by a Netscape Navigator® web browser or another control or programming component that works across network environments.
In step 6406, client 6205 installs and executes the first program 6222, where the execution of the first program comprises the installation
287 a second program on client 6205. In one embodiment, the first 6222 program can be automatically installed and executed, such as using any of the techniques discussed in conjunction with method 6300 and figure 41 A. In some embodiments, the first program 6222 obtains, transfers (via download) or receives the second program, or the 6120 acceleration program, from the 1250 system. In another embodiment, the first 6222 program comprises an installer or an installation manager for the second program, such as the 6120 accelerator program to automatically install and run the second program, such as through a silent installation or a transparent installation for a user of the 6205 client, the 62020 client 6220 application, the 1250 appliance or server 30.
In one embodiment, the second program is configured, in part, to intercept communications from 6220 applications running on the 6205 client that are destined for resources on the 6204 network and to provide intercepted communications for the first 6222 program to be sent to the system. 1250 through the encrypted data communication session. The second program can also be configured to provide an intranet network name resolution service and optionally split network traffic. By dividing the traffic, a modality is able to determine which traffic is channeled to an SSL tunnel or an encryption tunnel of the first 6222 program and which traffic is allowed or allows to continue forward for processing by the transport layer of the 6210 network stack under normal, routine or typical customer 6205 operations. In one embodiment, the second program comprises a dynamic interceptor (for example, a filter device driver) that is inserted as a hook into a 6205 client operating system. For example, the second program can comprise a filter device driver which is attached to the transport layer stack of the client operating system, such as the transport layer stack of a Microsoft Windows® operating system.
In step 6408, since the first and second programs
288 have been installed, applications running on the 6205 client can communicate with and access resources, such as applications and data, over a private 6204 data communication network through the established encrypted data communication session. The way in which this communication occurs will be discussed in greater detail below with respect to figure 42B. Note that, in one mode, the functions of the first program and the second program as described above are performed by a single control or programming component that is automatically installed and executed by the 6205 client, such as the 6120 acceleration program. In addition, for the provision of a virtual private network connection and communications, the first 6222 program and / or the second program, such as the 6120 acceleration program, can perform any of the acceleration techniques described here in customer communications through of the virtual private network connection, for example, the encrypted tunnel or bridge to the 1250 system.
In step 6410, the 6205 client performs a logout procedure to disconnect the 6204 network, which ends the encrypted data communication session with the 1250 device. In one mode, when the logout is done, the first 6222 program automatically modifications made to the 6205 client operating system to return the operating system to a state prior to installing the first 6222 program and / or the second program. In one embodiment, the first 6222 program and / or the second program also includes an uninstaller or uninstall instructions for removing the first and second programs from the 6205 client operating system or from an additional operation on the 6205 client in a non-intrusive manner for the 6205 customer's continued operations. In yet another embodiment, the first 6222 program and / or the 6120 accelerator program removes any files, such as temporary files or cookies, used by 6205 client applications during any communication connections or sessions provided.
Fig. 42B describes an embodiment of another method
289
6450 whereby a 6205 client communicates with and accesses resources on a 6204 private data communication network. For example, method 6450 represents a method by which step 6408 of method 6400 can be performed. In a brief overview, in step 6452, client 6205 makes a new connection or resolves a domain name, such as a TCP / IP domain name resolution, through the first program and / or the second program. In step 6454, the second program is executed. In step 6456, the second program intercepts communications from the 6205 client to the private network and redirects or sends communications to the first 6222 program. In step 6458, the first 6222 program terminates or delegates the connection, separates the payload and encapsulates the payload for delivery through the established encrypted communication session. In step 6460, the first program 6222 sends communications intercepted by the public network to the 1250 device on the private network through the pre-established encrypted communication session. In step 6462, the apparatus 1250 decrypts the communications received from the first program and routes the decrypted communications to the appropriate destination resource, such as a server 30. In step 6464, the destination resource processes the decrypted communications, and in step 6464 the destination resource sends a reply communication, if any, to the \ 1250 system. In step 6468, the 1250 system encrypts the response and communication. sends encrypted communications over the public network to the first 6222 client 6205 program through the pre-established encrypted communication session. In step 6470, the first program 6222 de25 encrypts reply communications and routes the decrypted communications to the appropriate client application via the second program.
In step 6452, a 62020 client 6220 application makes a new connection or resolves a domain name through the proto30 transport layer of the 6205 client 6210 network stack. In one embodiment, the 6220 application may request the establishment of a transport layer connection between the 6205 client and a server 30, or between the client
290 te 6205 and the 1250 appliance. In another embodiment, the 6220 application or the 6205 client can request access to a 6220 application provided by server 30. For example, server 30 can provide server-based computing or lightweight client computing. by transmitting an ICA or RDP remote display protocol representing an output from a 6220 application running on server 30. In another embodiment, the 6205 client may request access to resources on a server 30, such as files or directories, or e-mail services. In some embodiments, the client 6205 may be on a public network 40 and the server 30 on a private network 40 '. In other embodiments, client 6205 and server 30 may be on different private networks.
In step 6454, the second program performs one or more functions automatically or otherwise, before any transport layer functions are started. In some embodiments, the second program is or otherwise comprises the 6120 acceleration program. In one embodiment, the second program intercepts or otherwise receives the customer request from step 6452. In some modalities, the 62020 client 6205 application makes API calls to the 6210 network stack, which are intercepted by the second program. Before any PAI calls are processed by the transport layer of the 6210 network stack, the second program is hooked into or otherwise interfaced with the 6210 network stack to execute logic, rules, functions or operations, before communication be transmitted or processed for transmission over a transport layer connection.
In step 6456, the second program intercepts communications from client 205, as with any application 6220a to 6220n on client 6205 that are destined for resources on a 40 'network and redirects them to the first program 6222, which in one mode comprises an ActiveX control plug-in, a Java applet, or another control or programming component that works across network environments. The second program can access, read or otherwise obtain destination information from the packet or network packets
291 providing intercepted communications to determine that the communication is destined for a network, such as a private network 40 'behind the 1250 apparatus. For example, the second program can extract or interpret the destination IP address and / or the port to from the network package. Upon determining that an intercepted communication is destined for the 40 'network, the second program communicates the intercepted communication to the first 6222 program through any suitable interface means and mechanism, such as through any inter-process communication interface or an API call. . In one embodiment, the intercepted communication is sent to the first 6222 program as is, or, in other modalities, the intercepted communication is preprocessed by the second program, before being sent to the first 6222 program. For example, the second program can remove the payload from the intercepted communication and forward the payload to the first 6222 program.
In step 6458, each intercepted communication is terminated or delegated by the first program 6222, and the first program 6222 prepares the intercepted communication for transmission through the established encrypted data communication session. In one embodiment, the first 6222 program separates the payload and encapsulates the payload for delivery through the encrypted data communication session. In another embodiment, the first 6222 program encapsulates the intercepted communication as received by the second program. In some embodiments, the payload is a TCP payload and is encapsulated in a new TCP connection between client 6205 and server 30, as well as through device 1250.
In step 6460, the first program 6222 sends the communications intercepted by the 6204 network to the 1250 apparatus through the pre-established encrypted data communication session. In some embodiments, the first 6222 program encrypts intercepted communications and sends the encrypted intercepted communications to the 1250 device. In one embodiment, encryption is performed according to SSL protocols. In another mode, encryption is based
292 in TLS. Any type and form of encryption and / or decryption can be used by the first 6222 program or by the 6120 accelerator program.
In step 6462, the device 1250 acts as a next terminator to the connection sent by the first program 6222. The device 1250 decrypts the communications received from the first program 6222, and forwards the decrypted communications to the appropriate destination resource on the 40 'network. through a second connection that the apparatus 1250 has established with the destination resource in the 40 'network. In one embodiment, a decryption is performed according to SSL protocols or other applicable encryption and decryption protocols. In some embodiments, the 1250 equipment performs one or more acceleration techniques in the communication forwarded to the destination resource, such as one or more of the following: techniques provided by 1) compression of multiple tocol 6238 ', 2) grouping of transport control protocol 6224', 3) multiplexing of transport control protocol 6226 ', 4) buffering of transport control protocol 6228' , and 5) caching via a 6232 'cache manager.
In step 6464, the destination resource processes the decrypted communications 20. In one mode, decrypted communications are a requirement for establishing a connection or communication session. In another mode, decrypted communications are a requirement to start or access a 6220 application on behalf of the 6205 client. In other embodiments, decrypted communications25 are a request for a web page, such as an HTTP request to receive a web page from a web server 30.
In step 6466, if the decrypted communications include a request for which there is a response, then the destination resource will send response communications to the 1250 appliance. In some 30 modalities, the response includes an acknowledgment of establishing a connection or session communication as requested by customer 6205. In other ways, the response includes an error message. In
293 a modality, the response includes an authentication request or a challenge response mechanism. In other modalities, the response includes a 6120 accelerator program to be used by the 6205 client. In another embodiment, the response includes HTML, such as a web page 5 to be displayed by the 6205 client. In other modalities, the response includes an object, such as a dynamically generated object.
In step 6468, apparatus 1250 sends response communications over network 40 to the first program 6220 on client 6205 through the pre-established encrypted data communication session. In one embodiment, the apparatus 1250 encrypts the reply communications and sends the encrypted reply communications to the first program 6222. In some modalities, encryption is performed according to SSL protocols or other applicable encryption and decryption protocols. Furthermore, the apparatus 1250 can perform any of the communications acceleration techniques for the 6205 client, such as 6238 'multiple protocol compression, 6232' caching or TCP 6228 'buffering.
In step 6470, the first program 6222 decrypts the response communications and forwards the communication to the appropriate application 6222 through the second program. The first 6222 program can use any suitable interface means or mechanism for communicating to the second program, such as through any type and form of inter-process communication mechanism or an API call. The second program provides response communication through the network 6225 stack from client 6205 to application 6220. As such, application 6220 transparently receives response communication without any changes or modifications to application 6220.
According to another modality, the 6205 client performs additional processing of intercepted communications before sending 30 communications over network 40 in step 6458. Due to the fact that a modality provides a VPN solution that acts as a proxy by terminating connections on the client , before encrypting this data, processing
294 additional work can be done more effectively. This processing can include a Domain Name Service (DNS) name resolution of intercepted communications to allow client applications to use whatever IP addresses they choose, as well as dynamically change those addresses at run time. This additional processing allows modalities to be effectively integrated with other technologies, such as global service load balancing to achieve greater availability and greater efficiency among gateways or distributed servers. Additional connection processing may also allow you to maintain detailed records and statistics regarding intercepted communications.
In another embodiment, a 1250 device terminates communications received from the first program on client 6205 and further processes one or more requests included there, instead of forwarding communications to a destination on network 40 ', as shown in step 6462. This additional processing may include back-end encryption in which communications are re-encrypted by the 1250 apparatus, prior to delivery to the appropriate destination on the 40 'network, thereby providing end-to-end network security. The destination will then decrypt the traffic and respond appropriately. In addition, this processing can allow the 1250 appliance to present responses from a cache, instead of requiring additional work by a destination server, performing a local network load balancing, a global service load balancing and / or communications compression to improve network efficiency and responsiveness 40.
According to the methods described above, a VPN based on an encrypted data communication session is established between a client 205 and network 40. For example, in one embodiment, a secure VPN is established over HTTPS. After that, all communications from client 6205 to network 40 are routed through the first program to the 1250 system and vice versa, through this encrypted data communication session. It should be noted that, although the
295 encrypted data communication can be established using HTTPS, the communications that are passed through the encrypted data communication session need not be HTTPS packet data or even HTTP packet data. For example, communications may also comprise a Transmission Control Protocol / User Datagram Protocol (TCP / UDP) or Internet Control Message Protocol (ICMP) packet data, although these examples are not intended to be limiting. Furthermore, although the method described with reference to figure 42B describes a request-response type communication between an application on client 6205 and a resource on network 40, encrypted communications need not be based on request-response. Instead, communications can be of any type. Thus, any client application that can establish a connection or communication session, such as a UDP session, can send and receive encrypted communications.
In another aspect, the acceleration program 6120 can dynamically divert any intermediate device from the client to connect or communicate with a server 30. For example, a 6205 client can have a connection to a server through one or more intermediaries, such as like the 1250 stereo. For one reason or another, an intermediary may no longer be available for use by the 6205 client to communicate with the server 30, for example, the 1250 appliance may be stopped for maintenance or may be in the process of rebooting or restarting. The 6120 acceleration program determines that the intermediary is no longer available 25 and automatically establishes a different connection path or communication session with the server 30. This can occur transparently to the 6205 client user or application, so that the connection and / or communication session does not appear to have changed or was otherwise interrupted.
Referring now to Figure 43, an embodiment of a 6500 method for the automatic diversion of an intermediate is described. In a brief overview, in step 6505, the 6120 acceleration program establishes
296 a transport layer connection between client 6205 and server 30 through an intermediary, such as apparatus 1250. In step 6510, the acceleration program 6120 determines that the intermediary is not usable for communication by the client 6205 to the server 30 through the transport layer connection 5 established. In step 6515, the acceleration program 6120 intercepts on the 6205 client a communication from the 6205 client to the 30 server. In step 6520, acceleration program 6120 establishes a second transport layer connection between client 6205 and server 30, and, as a result, bypasses intermediate 10 determined to be unusable for client communications to server 30 In step 6525, the acceleration program 6120 transmits the intercepted communication from client 6205 to server 30 through the second transport layer connection.
In more detail, in step 6505, the acceleration program
6120 establishes a transport layer connection between client 6205 and server 30 through an intermediary. In one embodiment, the intermediary comprises a 6205 apparatus. In other embodiments, the intermediary comprises one or more of the following: a cache, a server, a gateway, a firewall, a bridge, a router, a switch, a connection center, a neighbor, or any application or software program operating as or providing the functionality and operations of any of these types and forms of intermediaries. In one embodiment, the intermediary can operate on server 30. In some embodiments, the transport layer connection is established through a plurality of intermediates of the same type and shape or of different types and shapes. In another embodiment, the transport layer connection comprises the connection of a transport layer connection group established as the customer 6205 or the apparatus 1250.
In step 6510, the acceleration program 6120 determines that the intermediate 30 is not available or is otherwise not usable for communication by the client 6205 to the server 30 through the established transport layer connection. The 6120 acceleration program can
297 terminate the status or availability of the intermediary by any appropriate means and / or mechanism. In one embodiment, the 6120 acceleration program determines that the intermediary is not available by receiving an error message or a failure response associated with a transmission to the intermediary. For example, the 6120 acceleration program may receive a failed transport layer communication response when transmitting communication from the 6205 client over the established transport layer connection. In another mode, the 6120 acceleration program can transmit a ping command to the intermediary at a predetermined frequency for monitoring the intermediary's status and availability. If the 6120 acceleration program does not receive a response from the intermediary or, in some modalities, receives a delayed response or a response with a longer than desired latency, the 6120 acceleration program may determine that the intermediary is not available or is usable by customer 6205. In other embodiments, a server 30, a device 1250 or the intermediary can send a message to the client 6205 or the acceleration program 6120 providing information identifying that the intermediary is not available or is not otherwise usable by the client 6205. In in some embodiments, the established transport layer connection is disturbed or interrupted or, in other embodiments, it is closed.
In step 6515, the acceleration program 6120 intercepts a communication from client 6205 to server 30 destined through the intermediary through the established transport layer connection. The 6120 acceleration program can intercept communication at any point and at any transmission power layer in the 6210 network stack. In one embodiment, the 6120 acceleration program intercepts communication at the transport protocol layer before transmission at the established transport layer connection. For example, in some embodiments, the 6120 acceleration program comprises a network driver that has a transport driver interface or is otherwise interfaced to the transport protocol layer. Other modalities
298 they may include a first program 6222 and the acceleration program 6120 as a second program, as discussed in conjunction with figures 42A to 42B, where the first program 6222 or the acceleration program 6120 intercepts the communication.
In step 6520, acceleration program 6120 establishes a second transport layer connection for server 6205 to client 6205, in order to bypass the intermediate determined to be unavailable or unusable by the client in step 6510. In one embodiment, the 6120 acceleration program establishes a second transport layer connection directly to server 30, for example, when client 6205 and server are on the same 6205 network or on different routable networks between client 6205 and server 30. In another embodiment, the acceleration program 6120 establishes the second transport layer connection with a second intermediate, such as a second device 1250 '. In some embodiments, the acceleration program 6120 requires that the appliance 1250 establishes another transport layer connection with the server 30. In one embodiment, the appliance 1250 uses a second transport layer connection from a group of layer connections. transport to server 30. In another embodiment, the acceleration program 6120 requires server 30 to establish the second transport layer connection. In some embodiments, the 6120 acceleration program uses a second transport layer connection from a group of transport layer connections established by the 6120 acceleration program with the server 30.
In one embodiment, the acceleration program 6120 establishes the second transport layer connection in step 6520 transparently to a user or application 6220 of the 6205 client or, in some modalities, transparently to any protocol layer above or below the transport layer. In some respects, the second transport layer connection is automatically established for the 6205 customer by determining in step 6510 that the intermediary is not available or should not be used by the 6205 customer.
299 other embodiments, the second transport layer connection is automatically established upon a failure to transmit the intercepted communication to the server 30, for example, the first attempt to transmit the communication. In some embodiments, the second transport layer connection is automatically established upon failure of one or more retryed transmissions of the communication, or upon exhaustion of a predetermined number of retries. In another embodiment, the second transport layer connection is established by determining that the intermediary is delaying the rate of transmission or reception of network packets, causing latency or otherwise affecting the use of the transport layer connection. an unwanted way. In one embodiment, the 6120 acceleration program performs load balancing and establishes a second transport layer connection bypassing the intermediary to offload any processing or operations from the intermediary to the 6205 customer and / or a second intermediary.
In step 6525, the acceleration program 6120 transmits the intercepted communication from client 6205 to server 30 through the second transport layer connection. In one embodiment, the acceleration program 6120 transmits the intercepted communication directly to the server 30. In other embodiments, the acceleration program 6120 transmits the intercepted communication through a second intermediary, such as a second device 1250. By using the second transport layer connection, the 6120 acceleration program bypasses the middleman and continues the operations of a 6220 application from the 6205 client to the 30 server. In one embodiment, a 6220 application from the 6205 client continues with the operations and communications with server 30 as if application 6220 is continuing to use the previous or first established transport layer connection. As such, the 6120 acceleration program prevents, avoids or circumvents any communication interruption, disturbance, latencies, delays or other operational or performance issues that may occur if the intermediary is not diverted by the program.
300 6120 acceleration system. In another aspect, this technique automatically provides the 6205 client with continuous access to a server 30 or remotely accessed application, even if there is a problem or a disturbance in access from an intermediate device.
Furthermore, the redirection and diversion techniques described above can be used to perform load balancing and traffic management on the 6205 client to access one or more servers 30 providing applications 6220a to 6220n, or other content and a 6205 client functionality. For example, in a modality, an intermediary or a device used by the client to access a server may be overloaded with increasing transport layer connections and decreasing a response rate, performance or other operations. By determining a decreasing performance of the intermediary or device, the 6120 acceleration program can redirect the client to another intermediary or device, or server, to bypass any performance bottlenecks in end-to-end connectivity to the client. server.
In other respects, client-side acceleration techniques can be related to or performed on the transport protocol layer of the client's network stack. The 6120 acceleration program can comprise executable instructions for performing any one or more of 1) transport control protocol (TCP) 6228 buffering, 2) TCP 6224 connection pooling and 3) TCP 6226 multiplexing . In some embodiments, such as the 6120 acceleration program transparently processes intercepted communications at the client network stack's transport protocol layer, the 6120 acceleration program can control and manage the client's TCP connections, and the use and transmission over connections through the 6220a to 6220n client 6205 applications. Figure 44 describes a modality of method 6600 of using TCP buffering techniques, while figures 45A to 45B describe a modality of the TCP connection clustering technique and figures 46, 47 and 48 the multiplexing technique of TCP.
301
In a brief overview of a method modality 6600 described in figure 44, in step 6605, the acceleration program 6120 intercepts a communication from client 6205 to server 30, such as a request for access to server 30 by client 6205 . In step 610, the 6120 acceleration program determines whether a difference between a consumption rate of received server responses and a rate of production of requests transmitted by the client falls below a predetermined threshold. If in step 6615 the difference in product and consumption rates does not fall below the predetermined limit, the acceleration program 6120 will forward the communication to server 30 in step 6617. If, in step 6615, the rate difference is below the predetermined limit, then, in step 6620, the acceleration program 6120 will store the communication in the memory of the 6205 customer. In step 6625, the acceleration program 6120 determines whether the difference in the rates has changed above the predetermined limit and, if so, forwards the stored communication to the server 30. Otherwise, the 6120 acceleration program maintains communication in the 6205 customer memory, up to a point in time when the difference in rates changes in step 6625 to above the predetermined limit. For example, if the 6205 client is transmitting requests to the server 30 at a rate higher than the rate at which the 6205 client can consume the generated responses, the 6120 acceleration program will maintain an additional transmission until a future point in time when the difference in rates has changed.
In more detail, in step 6605, the acceleration program intercepts communication from client 6205 to server 30. The acceleration program 6120 can intercept communication at any point and at any protocol layer in the 6210 network stack. one mode, the acceleration program 6120 intercepts communication at the transport protocol layer before transmission at the established transport layer connection. For example, in some embodiments, the 6120 acceleration program comprises a network driver that has a transport driver interface or is otherwise interfaced with the driver.
302 transport protocol. Other embodiments may include a first program 6222 and the acceleration program 6120 as a second program, as discussed in conjunction with figures 42A to 42B, in which the first program 6222 or the acceleration program 6120 intercepts the communication. In one embodiment, the communication comprises a request by the 6205 client to use or otherwise access a resource from the server 30, such as a 6220 application.
In step 6610, the acceleration program 6120 determines whether a difference between a consumption rate and a production rate of the 6205 customer falls below a predetermined threshold. In one mode, the 6120 acceleration program counts and tracks the number of requests transmitted by the 6205 client to server 30, and in another mode, the 6120 acceleration program counts and tracks the number of responses received by the 6205 client from of server 30. In some modalities, the 6205 client tracks the transmitted responses and requests received on a per 6220 application basis. The responses and requests can be tracked at any protocol layer of the 6210 network stack. In one embodiment, the number of requests transmitted by the 6205 client or the 6220 application is counted and tracked from the submission point to the transport layer or to a transport layer connection between the 6205 client and the server 30. Likewise, in another mode, the number of responses received by the client 6205 or application 6220 from server 30 is contacted and tracked from the receiving point to the transport layer or from the transport layer connection between client 6205 and server 30 and / or at the point where the response is provided for a protocol layer, such as an application layer, above the transport layer of the 6210 network stack.
In some embodiments, the 6120 acceleration program accesses inspects or otherwise obtains information and data about the sending and receiving of TCP buffers from the transport layer connection established by the 6120 acceleration program between the 6205 client and the server
303
30. For example, the 6120 accelerator program can determine the default and maximum size of any TCP / IP buffers and the currently used portions of the buffer for determining a difference in rates between sending and receiving network packets from the client. 6205 for server 30. In other embodiments, the 6120 acceleration program uses any type and form of congestion algorithm to determine if there is congestion caused by a difference in consumption and product of network packets from client 6205 to server 30. In another embodiment, the 6120 acceleration program interfaces with or obtains information or data from a congestion algorithm used by the transport layer connection, such as a network driver or a TCP service provider. For example, in one mode, the 6120 acceleration program determines information and data regarding the congestion window used by the connection.
The predetermined limit can be configured, specified, defined or identified by any suitable means and mechanism of the 6120 acceleration program. In one embodiment, the limit can be specified as a percentage, relative, absolute or otherwise, between the production rate and the consumption rate of the 6205 client and / or the 6220 application. The rates for consumption and / or product can be identified by a number of consumed receipts and transmissions produced, respectively, over any period of time at any granularity. In some modalities, the limit can be specified as a difference in quantity between the production rate and consumption of the 6205 customer and / or the 6220 application, and in some modalities, a difference in quantity over a period of time. For example, the threshold can be specified as the point in time when the 6205 client produced 6100 requests more than the 6205 client consumed. In another example, the threshold can be specified as the point in time when the 6205 client is producing 610 requests per period of time for the server 30 more than the requests consumed by the 6205 client during the same period of time.
304
In step 6615, if the difference in product and consumption rate for the 6205 client and / or the 6220 application is below the predetermined threshold, the 6120 acceleration program will forward the communication to the 6260 server in step 6617. In some embodiments, the acceleration 5 performs any acceleration techniques for communication. For example, communication can be routed to the server via a grouped multiplexed transport layer connection and can additionally be compressed. In other embodiments, the 6205 client can forward the communication to a 1250 device providing a connection for the 6205 client to the 30 server.
In step 6615, if the difference in product rate and consumption of the 6205 client and / or the 6220 application is below the predetermined limit, the 6120 acceleration program, in step 6620, will store the communication in the 6205 client memory. In some embodiments, memory 15 can be a 6202 kernel mode memory from client 6205. In one embodiment, the accelerator program 6120 can store communication in the cache through the cache manager 6232. In other embodiments, the 6120 acceleration program may use an object, data structure or other data element accessible by the 6120 acceleration program to buffer, maintain or otherwise store the intercepted communication. In one embodiment, the intercepted communication can be stored in a compressed manner in memory. In another embodiment, the acceleration program 6120 sends the intercepted communication to a first program 6222 for storage or maintenance in memory for transmission at a later point in time.
In step 6625, the acceleration program 6120 determines when to transmit the stored communication to the server 30. In one embodiment, the acceleration program 6120 performs steps 6610 and 6615 to determine whether the difference in customer production and consumption rates 6205 is above the limit, whereby the acceleration program 6120 forwards the stored communication to server 30 in step 6617. In some modalities, the acceleration program 6120 compares the
305 difference in production and consumption rates on a regular or predetermined frequency or on an interrogation or event basis, and when the difference rises above the predetermined limit, the 6120 acceleration program forwards the communication to the server 30. In other modalities , the 6120 acceleration program regulates or sets a timer to determine how long to store the intercepted communication. Upon expiration of the timer, the 6120 acceleration program transmits the stored communication to the server 30. In another mode, the 6120 acceleration program checks the number of server responses consumed by the 6205 client since the storage of the intercepted communication. If the number of responses consumed is greater than a predetermined number, the acceleration program 6120 will release the intercepted communication from the memory buffer or storage and submit the communication for transmission to the server 30.
If, at step 6625, the acceleration program 6120 determines that the production and consumption rates have not changed in an appropriate manner, the acceleration program 6120 will hold or maintain the intercepted communication in memory until an appropriate time point is reached. In one embodiment, the 6120 acceleration program forwards the communication to the server at step 6617, even if the production and / or consumption rates do not change. For example, after a period of time waiting for the production and / or consumption rate to change and the rates not to change, the 6120 acceleration program forwards the communication to the server 30.
Although the TCP buffering technique is generally discussed in relation to an intercepted communication or request, the 6600 method modalities can be practiced sequentially, almost simultaneously or concurrently for multiple intercepted communications from client 6205 to server 30. Additionally , in another modality, the 6600 method can be practiced on the client with respect to communications from the client to multiple servers 30. For example, a first instance of the 6600 method can be practiced among the customer
306 te 6205 and a first server 30 ', and a second instance of method 6600 can be practiced between the 6205 client and a second server 30 ”. Furthermore, in some modalities, the 6600 method can be practiced by a first application 6200a and also by a second application 6200b, using the respective production and consumption rates of each application. In other modalities, the 6600 method can be practiced for a first 6200a application, but not for a second 6200b application.
According to another aspect, the 6120 client side acceleration program reduces the processing load of servers 30 and / or appliance 1250 caused by repeatedly opening and closing client connections by opening one or more connections to each server and maintaining these connections to allow repeated access to data by client 6205 applications to server 30. This technique is generally referred to here as a connection pool. Referring now to figure 45A, in a brief overview of method 6700, in step 6702, acceleration program 6120 intercepts an application request for access to a server and, in step 6704, determines the identity of the server associated with request. In step 6706, the accelerator program 6120 determines whether the accelerator program 6120 has a transport layer connection established with server 30 free for use by the 6220 application. If there is no transport layer connection to server 30 free for use by the 6220 application, the 6220 accelerator program will establish, in step 6708, a transport layer connection with server 30 for use by the 6205 client. In step 6706, if a transport layer connection is available for use by the 6220 application, in step 6710, the 6120 acceleration program will translate the application request for transmission or communication through the available transport layer connection.
In an additional overview, in step 6712, accelerator program 6120 receives the response to the request from server 30 and, in step 6714, translates the response into a response for application 6220. In step 6716, the acceleration program 6120 can maintain or leave the transport layer cone307 open for use by any of the 6205 client 6220a through 6220n applications. By maintaining on the 6205 client open transport layer connections to servers 30 and by opening and closing connections to applications as needed, the 6120 acceleration program frees servers from TCP connection load problems associated with the customer service 6205 over network 40, such as the Internet. In step 6718, the acceleration program 6120 at some point closes the transport layer connection, if the connection is determined to be no longer used by one or more applications 6220 from client 6205 to access server 30.
In more detail, in step 6702, the acceleration program 6120 intercepts a request by any application 6220a to 6220n from client 6205 for access to a server 30. In some modalities, the request is intercepted at the transport protocol layer prior to establishment. or transmission of the request via a transport layer connection. In other modalities, the request is intercepted at any protocol layer above the transport layer or a transport layer connection. In one embodiment, the application request 6220 is a request for opening or establishing a transport layer connection with the server 30. In some embodiments, in response to the request, the 6120 acceleration program establishes a first transport layer connection for a group of transport layer connections for use by client 6205a 6220a to 6220n applications. heating is a request for access to the server via a transport layer connection established by the 6205 client.
In step 6704, the acceleration program 6120 determines the identity of the server 30 from the request by any suitable means and mechanism. In some embodiments, the domain name or internet protocol address 30 of the server 30 is identified or otherwise referenced by the content of the request, for example, a request text string can identify the domain name of a server 30 . In a
308 As such, regardless of server 30 is determined by the header information of a TCP packet, such as the destination internet protocol address and port number. In another embodiment, server 30 is associated with application 6220, and accelerator program 5 6120 searches for or queries the association in a database or other structured information store.
In step 6706, the 6120 acceleration program determines whether there is a transport layer connection available for use or that is otherwise free for use by the 6220 application. In one embodiment, the 6120 acceleration program may not yet have established a transport layer connection to server 30, and as such there is no transport layer connection available for the 6220 application to use. In another embodiment, the 6120 acceleration program may have a transport layer connection previously established with server 30, 15 but determines that another 6220 application is currently actively using the connection. As will be discussed in greater detail below, the 6120 acceleration program determines whether an established transport layer connection is available for use by another application or can be shared by applications 6220a through 6220n, based on the length of a message being received from server 30 to application 6220, such as responding to a request and / or if communications between server 30 and application 6220 are currently inactive.
In step 6708, if the accelerator program 6120 determines that a transport layer connection is not available for use by application 6220, the accelerator program 6120 establishes a transport layer connection with server 30. In some embodiments, the transport layer connection established in step 6708 is the first transport layer connection to the server 30, and in other embodiments, the transport layer connection is a second transport layer connection 30 of a plurality transport layer connections to server 30. In yet another embodiment, the 6120 acceleration program expects an already established transport layer
309 becomes available or free to communicate the application request to server 30. For example, the accelerator program 6120 may determine that a first application 6220a may soon be completing a transaction with server 30 over an established connection.
In step 6710, the 6120 acceleration program translates the application request to be transmitted over the transport layer connection to the 6106 server. In some embodiments, the 6120 acceleration program uses a port number for the layer connection communication transport for all 6220a to 6220n applications from the 6205 client sharing the connection. In some cases, the 6120 accelerator program tracks requests and responses highlighted for requests on an application-by-application basis. As such, the acceleration program 6120 recognizes which application 6220 is transmitting and receiving network packets over the transport layer connection to server 30 at any given point in time. In one embodiment, only one 6220 application at a time is sending and receiving on the transport layer connection, so the 6220 accelerator program understands which 6220 application is using the connection. In some embodiments, the 6120 accelerator program associates a 6220 application process id with the request. In other embodiments, the 6120 accelerator program provides and associates a port number with the 6220 application, and modifies the port number in the TCP network packet to be transmitted to the assigned application port number. In another embodiment, the port number is provided by the 6220 application and the 6120 acceleration program changes or otherwise provides the port number in accordance with the TCP network packet.
In step 6712, the acceleration program 6120 receives a response to the application request from server 30. In one embodiment, server 30 does not respond to the request. In another embodiment, server 30 responds with an error or a failure message. In some embodiments, server 30 responds with multiple responses. In
310 in other embodiments, server 30 responds with a response comprising multiple network packets or multiple TCP segments. In another embodiment, server 30 responds with one or more network packets identifying the source port number associated with or assigned to the 6220 application. In one embodiment, server 30 responds with one or more network packets by identifying a source port number for the transport layer connection and used for multiple 6205 client applications.
In step 6714, the accelerator program 6120 translates or otherwise processes the response from server 30 in a manner in response to application 6220. In one embodiment, the accelerator program 6120 replaces the source port number of the packet or network packets received by the 6220 application port number. In another modality, the acceleration program 6120 determines through a tracking mechanism the 6220 application currently using the transport layer connection and passes the response to the 6220 application through the 6210 network stack. In one modality, the response does not is changed and passed for processing through the protocol layers of the 6210 network stack above the connection transport layer. In some embodiments, the 6120 acceleration program expects multiple portions, such as TCP segments, of the response to be received, before processing and forwarding the response to the 6220 application. In one embodiment, the 6120 acceleration program passes the response for a first 6222 program, which interfaces with and provides the answer for the 6220 application.
In step 6716, the acceleration program 6120 maintains or leaves the transport layer connection open in a group of one or more transport layer connections from client 6205 to server 30. In one embodiment, the 6120 acceleration program or a 6210 network stack transport layer driver includes a keep-in-place mechanism that periodically probes the other end of a connection, when the connection is otherwise inactive, for example, when there is no data to send. The retention mechanism can send this message
311 message in order to receive a response to confirm that the connection is still active, although the connection may be inactive. The keep current message and the corresponding response can include any type and form of format, command, directive or communication. As such, in some modalities, the 6120 acceleration program transmits or causes a message to be maintained through the transport layer driver for the transport layer connection. In some embodiments, the 6120 acceleration program regulates a frequency for messages to remain in effect, and in other modalities, it changes the frequency of messages to remain in effect based on the compartment or activity of the 6220a to 6220n applications using the connection.
In some embodiments, the 6120 acceleration program intercepts any RST and / or FIN commands, that is, TCP / IP commands for resetting and / or terminating the TCP connection, received by the transport layer connection. In one mode, the 6120 acceleration program ignores, takes no action, or otherwise abandons, erases or clears the intercepted RST and / or FIN command. In another mode, the 6120 acceleration program intercepts and receives RST and / or FIN commands, but sends a message to the other end of the connection to leave or keep the connection open. In other embodiments, the 6120 acceleration program establishes a new transport layer connection in response to a closure of an established transport layer connection due to the processing of an RST and / or FIN command.
In other embodiments, the 6120 acceleration program inserts an instruction, a command, or a directive into an intercepted communication from the 6205 client to direct the server 30 to keep the connection open or otherwise not close the connection, unless the 6205 client send a command to do so. For example, in one mode, the 6120 acceleration program intercepts a GET request communication from the HTTP protocol, such as protocol version 1.0, and inserts a keep-in-place header, for example, Connection: Keep-Alive in the
312 communication with the server 30. In other modalities, a GET request or other HTTP command may include the keep in effect header. In these modalities, the acceleration program 6120 can intercept the communication and check for the header to remain in force and then forward the communication to the server 30. In some embodiments, a version 1.1 or later of HTTP is used, whereby the keep in force mechanism is implicit, so that the server 30 keeps the connection open until the 6205 client requests the connection to be closed. In other embodiments, the 6120 acceleration program keeps the transport layer connection open with server 30 until client 6205 is rebuilt or restarted, network 40 becomes unavailable or client 6205 is disconnected from network 40, or server 30 be rebuilt or restarted.
In step 6718, the acceleration program 6120 can close any one or more of the transport layer connections between a 6205 client and a server 30 at any desired point in time. In some embodiments, the 6120 acceleration program closes a transport layer connection by terminating one or more applications 6220a through 6220n on the 6205 client using the connection. In other embodiments, the 6120 acceleration program closes a transport layer connection upon expiration of an expiration period for any 6220a to 6220n application using the connection. For example, the 6120 acceleration program can configure, regulate or provide a timer to expire over a predetermined period of time and, if the connection is or remains inactive during the period of time. The 6120 acceleration program will close the connection. In some embodiments, the server 30 can be rebooted, restarted or the connection broken or interrupted and the accelerator program 6120 closes the connection. In some modalities, the 6120 acceleration program transmits or causes an RST and / or FIN command to be transmitted to close the connection upon the completion of the sending of requests to and the receipt of all response data from the server 30 . In other embodiments, the transport layer connection or group of transport layer connections is closed by
313 a 6205 client restart or reboot, network 40 disconnection or network 40 unavailability, or server 30 restart or reboot.
In some embodiments, a first transport layer connection to the server 30 is kept open, while a second transport layer connection to the server is closed, as the 6120 accelerator program determines that only the first transport layer connection is required to compartmentalize a connection to server 30 by one or more applications 6220a through 6220n from client 6205. In other embodiments, the 6120 acceleration program maintains a group of a transport layer connection with any server 30 and establishes a second or a plurality of connections for a given server 30, based on increased requests, communications, or use of a network connection. transport layer of the 6220a through 6220n applications on the 6205 client.
Although a 6700 method modality is generally discussed in relation to a group of one or more transport layer connections from client 6205 to server 30, accelerator program 6120 can subsequently establish a group, almost simultaneously or concurrently of transport layer connections between the client and each of a plurality of servers 30. As such, a first 6220a application and a second 6220b application can use a first group of one or more transport layer connections to server 30a, and a third 6220c application and a fourth 6220d application using a second group of one or more connections transport layer with server 30b. Furthermore, each of the steps of a 6700 method can be performed in different instances and at different frequencies. In some embodiments, multiple instances of the 6120 acceleration program can be used to handle each group of one or more transport layer connections for each server 30.
Now, with reference to figure 45B, a flowchart is described from an acceleration program 6120 providing a layer connection.
314 transport for use by two applications 6220a and 6220b from a 6205 client, to a server 30 in one mode, or to a 1250 appliance in another mode. The acceleration program 6120 on client 6205 opens a first transport layer connection between client 6205 and server 30, or apparatus 1250, using a network address 1 provided by the 6220 application, as described in step 6752. Step 6752 is shown as a two-way step, because the TCP / IP protocol employs a multi-stage fulfillment for opening connections.
Once the transport layer connection is established, the 6120 accelerator program intercepts a GET request from the 6220a application by specifying a path name of /sales/forecast.html, as shown in step 6754. Because no free transport layer connection is open between the 6120 accelerator program and server 30, or the 6205 appliance, the 6120 accelerator program opens a transport layer connection. In one embodiment, the acceleration program 6120 maps the request from application 6220a to a second network address of network address 2, which specifies server 30, as shown in step 6756. For example, the acceleration program 6120 performs a network address translation for modifying the destination IP address and / or destination port to a 30 'server requested by the 6220a application or another 30 ”server that can also handle or respond to the request. In another modality, the acceleration program 6120 sends the request to the server 30 or the equipment 1250, as received or as generated by the application 6220s.
The 6120 acceleration program also passes the GET request to that server 30 or the 1250 device, as shown in step 6758. In one mode, the 1250 device forwards the request to server 30 and, in an additional mode, the 1250 device forwards the request through transport layer connections grouped or grouped and multiplexed between the equipment 1250 and the server 30. In some embodiments, server 30 responds with the requested web page, as shown by step 6760. The accelerator program 6120 forwards the web page to application 6220a, as shown by step 6762. In one embodiment, the layer connection between the accelerator program 6120 and server 30 or apparatus 1250 is closed, as shown by step 6764. In other modalities, the 6120 acceleration program intercepts the close request and ignores the request, leaving the transport layer connection open. According to the TCP / IP protocol, closing a network connection can involve a multi-stage process. Therefore, the flow line from step 6764 is shown as bidirectional. In other modalities and according to the techniques of the grouping aspect, the transport layer connection established and used by the first 6220 application is kept open or otherwise maintained to accommodate additional data steps for the same 6220a application or a different application, such as the second 6220b application.
In step 6766, the acceleration program 6120 intercepts a request from the second application 6220a to server 30, or appliance 1250. If there is an open transport layer connection open and / or usable by the second application 6220b, such as the connection transport layer established in step 6756 for the first 6220a application, the 6120 acceleration program uses this previously established transport layer connection. As such, a second transport layer connection does not need to be opened in step 6766. Otherwise, the accelerator program 6120 establishes a second transport layer connection with server 30 or apparatus 1250. In step 6768, the transport program Acceleration intercepts a request from the second 6220b application, for example, by requesting the /sales/forecast.html web page, and transmits the request to server 30 or the 1250 apparatus, in step 6770. Due to the fact that a free connection is already open between the 6120 accelerator program and the 6120 server, it is unnecessary for the 6120 accelerator program to overload the 6120 server with the processing load of opening an additional connection. In step 6772, the training program
316 acceleration 6120 intercepts or receives a response from server 30, such as through apparatus 1250 from the transport layer connection, and forwards the response to the second application 6220b. In step 6776, the acceleration program 6120 intercepts a request to close 5 from the second application 6220b, and, in some modalities, closes the connection, while in other modalities it ignores the request, and maintains the connection for accommodating other requests data from the first 6220a application, the second 6220b application, or another 6220c to 6220n application from the 6205 client.
There are several scenarios that result in the acceleration program
6120 closing the connection to server 30 or apparatus 1250, in step 6776. For example, client 6205 or accelerator program 6120 can initiate a FIN command (terminate) upon a determination that client 6205 has retrieved all data requested for the applications 6220a and 6220b, or by terminating, closing or exiting applications 6220a and 6220b. In some embodiments, the 6205 client or the 6120 acceleration program can also initiate an RST command (reset) under similar conditions. In addition to closing the connection between the 6120 accelerator program and server 30 or device 1250, the RST command 20 results in several staging operations being carried out to keep the server side connection in good order. In particular, the TCP protocol ensures that the RST command has the correct SEQ (string) number, so that the server accepts the segment. However, the RST command is not guaranteed to have the correct ACK (acknowledgment) number 25. To deal with this scenario, the acceleration program 6120 keeps track of the data bytes sent by the server 30 or by the 1250 equipment, and the bytes recognized by the 6205 client. If the 6205 client has not yet recognized all data by the server 30, the accelerator program 6120 calculates the unrecognized bytes, and sends an ACK 30 to the server 6205.
Furthermore, although not shown in figure 45B, server 30 or appliance 1250 can also close a connection between itself and
317 client 6205. Ο server 30 or equipment 1250 would send a FIN command to client 6205. In response, in some modalities, the acceleration program 6120 closes the connection and, in an additional mode, reestablishes another connection with server 30 or the 1250 apparatus.
Furthermore, although a method method 6700 of figure 45A and the example flow chart of figure 45B are generally discussed as a grouping of one or more transport layer connections for use by a plurality of applications, grouping techniques can be applied. to a single 6220 application that requests or initiates a plurality of transport layer connections and requests through these connections. For example, in an HTTP protocol mode, a transport layer connection can be established or each HTTP request from an application. Using the techniques, a group of one or more transport layer connections can be used by the 6220 application, without opening and closing transport layer connections for each request.
In another aspect, techniques for multiplexing application requests over the same transport layer connection or a shared one can be used, such as a transport layer connection established using the grouping techniques described in conjunction with figures 45A to 45B. In some embodiments, the availability of an established transport layer connection is determined and requests can be multiplexed from a plurality of applications through the connection by checking whether the content of a response from server 30 for requests from an application was received completely. As will be discussed in more detail below, in one embodiment, the content length parameter of a response is used, and in another embodiment, a fragmented transfer encoding header for a response is used to check that all a reply were received. In one respect, if all data from a response has been received it is checked to determine if a currently connected connection is free for use by an application and / or whether it is pa
318 To establish another transport layer connection for the group of connections to the server, as in steps 6706 and 6708 of method 6700 described in figure 45. In another embodiment, the technique of checking the length of content for a response is used as a technique for multiplexing requests from a plurality of applications over the same transport layer connection.
Referring now to Figure 46, an embodiment of a method 6800 for multiplexing requests through a single transport layer connection from client 6205 to server 30 is described. In a brief overview, in step 6805, accelerator program 6120 establishes a transport layer connection between client 6205 and server 30. In step 6810, accelerator program 6120 intercepts a first request for a first application 6220a to the server 30. In step 6815, the 6120 acceleration program determines whether the transport layer connection is currently being used by another application or is otherwise inactive. In step 6817, if the transport layer connection is available for use by the 6220a application, then, in step 6820, the 6120 acceleration program transmits the request to the server. Otherwise, at step 6817, if the transport layer connection is not available for use by the 6220a application, then the 6120 acceleration program at step 6819 will wait for a period of time and return to step 6815, or establish a second transport layer connection for use by the 6220 application. In step 6825, the 6120 accelerator program receives an application request response from the server. In step 6830, acceleration program 6120 intercepts a second request, for a second application 6220b, and proceeds to step 6815 to determine whether the transport layer connection is available for use by the second application 6220b. In some embodiments, the acceleration program 6120 intercepts the request from the second application 6220b in step 6830, before receiving the response from the first request in step 6825, or before receiving all the response data. As further discussed here, in some modalities
319 However, the 6120 acceleration program uses the content length checking technique to determine when the transport layer connection is down or an application has received all data for a response to a request.
In more detail, in step 6805, the 6120 acceleration program establishes a transport layer connection between the 6205 client and the server 30. In some embodiments, the 6120 acceleration program establishes the transport layer connection with or through the apparatus 1250 or an intermediary. In one embodiment, the acceleration program 6120 establishes the transport layer connection as a group of transport layer connections to server 30. As such, in some embodiments, the transport layer connection may comprise a second or third transport layer connection to the server 30. In other embodiments, the 6120 acceleration program may establish the transport layer connection via a first 6222 program, as previously discussed here. In some embodiments, the 6120 acceleration program established the transport layer connection in response to a request for a first 6220a application from the 6205 client.
In step 6810, the acceleration program 6120 intercepts a first request by a first application 6220a to access the server 30. In some modalities, the request is intercepted at the transport protocol layer before the establishment or transmission of the request through the connection of transport layer. In other modalities, the request is intercepted at any protocol layer above the transport layer or above the transport layer connection. In some embodiments, the request is intercepted by a first program 6222. In one embodiment, the request from application 6220a is a request for opening or establishing a transport layer connection with server 30. In another embodiment, the application request is a request for access to the server through the established transport layer connection or through the 1250 device.
320
In step 6815, the 6120 acceleration program determines whether the transport layer connection is down or available for use by the first 6220a application or communicates the first request from the first 6220a application. In some embodiments, the 6120 5 acceleration program determines from a group of one or more transport layer connections, which transport layer connection in the group is inactive or free for use by the first 6220a application. In one embodiment, the 6120 acceleration program determines that the transport layer connection is inactive because the 6120 acceleration program established the transport layer connection in response to the request, or immediately before the request. In some embodiments, the 6120 accelerator program may not have received any requests from any 6220 application and recognizes this request as the first request to be intercepted and processed by the 6120 accelerator program. In another fashion, the 6120 acceleration program tracks the number of highlighted responses for any requests transmitted on the transport layer connection, and if there are no highlighted responses, the 6120 acceleration program will recognize that the transport layer connection is available. for use by the first 6220a application. In yet another fashion, the 6120 acceleration program recognizes that the transport layer connection is currently inactive. For example, the 6120 acceleration program may be initiating requests to keep the server current to keep the connection open. In some embodiments, the transport layer connection is inactive, since the last transaction has been completed, 25 but server 30 and / or client 6205 has not yet transmitted an RST and / or FIN command.
In some embodiments, the accelerator program 6120 can check the content length of a response to determine whether the response from server 30 for the first request from the first application 6202a is complete or otherwise the accelerator program 6120 has received all the data for the answer. As mentioned above, these techniques in some modalities can also be used for
321 determining the establishment of another connection for the clustering technique. With respect to this technique, figures 47 and 48 will be used to describe the verification of the content length parameter of a response in one modality, or in another modality, a fragmented transfer coding header for a response, to determine whether all data for a response has been received. Fig. 47 describes a TCP portion of a TCP packet referred to as the TCP 6900 segment. The TCP 6900 segment includes a TCP header 6902, and a body 6904. Body 6904 comprises among other data 10 and information a header HTTP and a message in a modality, in which the heat exchanger package carries an HTTP application layer protocol. In some embodiments, a content length parameter 6906 is found, found or referenced by or in the HTTP header. In one embodiment, the acceleration program 6120 15 uses the content length parameter 6906 to determine whether all data for a response is received.
Fig. 48 describes another embodiment of a TCP segment of a TCP packet. In some modalities of using the HTTP protocol over the transport layer connection, a fragmented transfer encoding header 20 may be present and indicating that a fragmented transfer encoding has been applied to the TCP segment or packet. As such, in this mode, the message length is defined by fragmented encoding. Fragmented encoding modifies the message body in order to transfer the message as a series of fragments, each fragment with its own length indicator in a fragment size field. The TCP 7600 segment includes a TCP header (not shown) and a body. The body comprises, among other information, an HTTP header 7602A to 7602C and the message. The HTTP header 7602A to 7602C comprises seven fragment size fields 7606A to 7601C, and six fragment message data 7604A to 7604F.
The fragment size fields 7606A to 7606G are linked together or otherwise referenced or associated, as shown in figure 48. The fragment size field 7606A indicates the message length in fragment message data 7604A, the field fragment size 7606C indicates the message length in fragment message data 7604C and so on. The last fragment size field 7606G comprises the value of zero length indicating that there are no more fragments or anything else from the following message. In another embodiment, the acceleration program 6120 determines through the fragment size fields whether the 6205 client received all the data for a response.
Although figures 47 and 48 generally describe a technique for checking that all data for a response to a request has been received, these techniques are applicable to a server 30 or a device 1250 sending an asynchronous message or communication to the customer 6205. Furthermore, although these techniques are generally described in conjunction with figures 47 and 48 for an HTTP protocol, these techniques can be used for any protocol on any protocol layer that provides an indication of the length of data to be transmitted or received by the client. 6205. As such, in some embodiments, the 6120 acceleration program accesses, extracts, inspects, analyzes or otherwise processes any portion of the network packet, including any protocol layer, to determine whether all data has already been received in association with a request, response or communication between the client and the server or the equipment. In yet another modality, the acceleration program 6120 tracks the number of bytes transmitted, received and acknowledged between client 6205 and server 30 to determine whether any bytes are standing out between client 6205 and server 30. Otherwise, in step 6819, the acceleration program 6120 can wait until all data is received for a request from each application30. For example, the 6120 acceleration program can set a timer, for example, for a short period of time, and proceed to step 6815. In some embodiments, the speed program
323 celeration 6120 checks whether all data was received in response to a packet processing timer from client 6210 network stack 62. In other embodiments, in step 6819, acceleration program 6120 establishes another transport layer connection for the transmission of the first request from the first 6220a application.
At step 6820, the 6120 acceleration program can track which 6220 application currently has a highlighted request or response on the connection or is currently using the connection. For example, only one 6220 application at a time can transmit a request and receive a response on the connection. As such, the 6120 accelerator program understands which 6220 application is using the connection. In some embodiments, the 6120 acceleration program uses a port number for transport layer connection communication for all 6220a to 6220n applications from the 6205 client sharing the connection. In some cases, the 6120 acceleration program tracks requests and responses highlighted for requests on an application-by-application basis. In some embodiments, the 6120 accelerator program associates a 6220 application process id with the request. In yet another modality, the acceleration program 6120 transmits the request from the first 6220a application with a request from the second 6220b application in the same packet or in the same network packets, segment or TCP segments. In other embodiments, the 6120 acceleration program transmits a plurality of application requests 6220a to 6220n over the same transport layer connection as part of a series of TCP segments from one or more TCP segment windows.
In other modalities, the 6120 acceleration program uses a port numbering mechanism and / or scheme to monitor and recognize what response or message received is for the 6220a to 6220n application. In other embodiments, the 6120 accelerator program provides and associates a port number with the 6220 application, and modifies the port number in the TCP network packet to be transmitted to the assigned application port number. In another mode, the port number is pro
324 via the 6220 application and the 6120 acceleration program changes or otherwise provides the port number in accordance with the TCP network packet. As such, in some embodiments, the 6120 acceleration program can interweave requests from a plurality of applications 6220a to 6220n from client 6205, so that applications 6220a to 6220n can use the transport layer connection at the same time.
In step 6825, the acceleration program 6120 receives a response to the first request from the first application 6220a from server 30, such as through the 6205 apparatus, and provides the response to the first application 6220a. In some embodiments, the 6120 acceleration program provides the response for the first 6220a application through the 6210 network stack, such as allowing or starting processing the response through the protocol layers above the connection transport layer. In another embodiment, the first 6222 program provides the answer to the first 6220a application. In other embodiments, the 6120 acceleration program can provide the response for the first 6220a application through an inter-process communication mechanism or an interface, such as an API. In some embodiments, the 6120 acceleration program receives only a portion of the response, such as a first fragment in a multiple fragment message, as described in figure 48.
In step 6830, accelerator program 6120 intercepts a request for a second application 6220b for access to server 30. In some embodiments, acceleration program 6120 intercepts the request for second application 6220b before step 6825. In other modalities, the program Accelerator 6120 intercepts the request for the second application 6220b while receiving the response in step 6825. In another embodiment, the 6120 acceleration program intercepts the request from the second 6220b application before the 6205 client or the 6120 acceleration program receives all data for a response from the first request from the first 6220a application. By intercepting the request for the second 6220b application, the 6120 acceleration program proceeds to
325 step 6815 in one embodiment, to determine whether to multiplex the second request via the transport layer connection or whether to establish another transport layer connection, such as another connection in a group of connections. In other modalities, the acceleration program 6120 transmits the request from the second application 6220b over the same connection as the first application 6220a, while the first application 6220a has an outstanding response or has not received all data from the response of the first request. In another mode, the acceleration program 6120 transmits the request for the second application 6220b after the first application 6220a has received the response and before any generated commands RST and / or FIN are generated in relation to the first application 6220a.
Although the 6120 acceleration program was generally discussed in relation to client-side implementation and the execution of acceleration techniques, the 6120 acceleration program has an interface and works in conjunction with the 1250 apparatus, which also implements and executes techniques equipment side acceleration. In one embodiment, the client side acceleration program 6120 and apparatus 1250 can work together with one another to carry out a plurality of acceleration techniques in communications between 6205 clients and servers 30. In some embodiments, the client side acceleration program 120 and the apparatus 1250 provide TCP grouping and multiplexing, as well as providing a cascading or end-to-end grouping and multiplexing mechanism between clients 6205 and servers 30. For example, the acceleration program 6120 can provide a first grouped transport layer connection for apparatus 1250, which in turn provides a second grouped transport layer connection for server 30. In another example, the 6120 acceleration program can multiplex an application request through a first transport layer connection grouped on the 6205 client, which in turn is multiplexed by the 1250 appliance through the second transport layer connection grouped with O
326 server 30. In some embodiments, the acceleration program 120 provides a throttling mechanism for transmitting requests from the 6205 client, while the 1250 apparatus provides a throttling mechanism for transmitting responses from the 30 servers to the 6205 clients. In another embodiment, the 6120 accelerator program performs client-side caching for the 6205 client, while the 1250 appliance provides caching of objects, such as dynamically generated objects, for the 6205 client together with other clients 6205.
In some modalities, in addition to or in conjunction with the realization of acceleration techniques on the 6205 client and / or on the apparatus, the 6120 acceleration program and the apparatus may provide a virtual private network connection and communications between the 6205 client and an access of network 40 through the 1250 equipment. In another mode, the acceleration program 6120 can compress the data communicated from a 6220 application, and the device 1250 can decompress the compressed data upon receipt. Conversely, apparatus 1250 can compress data communicated from an application 6220 on server 30 into a private data communication network 40 'and the acceleration program 6120 can decompress compressed data upon receipt. Also, the 6120 acceleration program and the 1250 device can act as end points in an encrypted or tunneling data communication session, in which the 6120 acceleration program encrypts data communicated from a 6220 application, and the 1250 device decrypts encrypted data upon receipt. In a similar way, the apparatus 1250 encrypts the data communicated from a 6220 application on the private data communication network and the acceleration program 6120 can decrypt the data upon receipt.
D. Example of Accelerating Delivery of a Computing Environment
In view of the structure, functions and operations described above in Sections B and C, in some modalities, the delivery of an ambi
327 computing power for a customer can be accelerated. For example, the modalities described here can be used for the delivery of a streaming application and a data file processable by the application from a central corporate data center to a remote user location, such as a company branch . The appliance and the acceleration program provide end-to-end acceleration techniques for accelerating any transport layer payload, such as continuously transmitted applications and data files, from a server to a remote client. The application delivery management system provides application delivery techniques for delivering a computing environment to a remote user's desktop based on a plurality of execution methods and based on any authentication and authorization policies enforced through a policy agent. With these techniques, a remote user can obtain a computing environment and access applications and data files stored on the server from any device connected to the network.
Referring now to Figure 49A, a modality for practicing the application acceleration and delivery systems and methods described above is described. In a brief overview, a client 10 is communicating with a server 30 via a network 40, 40 'and the apparatus 1250. For example, client 10 can reside in a corporate data center. Client 10 comprises a client agent 560 and a computing environment 15. The computing environment 15 can run or operate an application that accesses, processes or uses a data file. The computing environment 15, an application and / or data file can be delivered via the device 1250 and / or the server 30. In some embodiments, the client 10 also includes a 4120 accelerator program, a 404 collection agent and a streaming client 562. Server 30 includes an application delivery system 500 and, in some embodiments, a policy agent 406.
In one embodiment, the 500 g application delivery system
328 to reside or run on a 30 server. In another embodiment, the application delivery system 500 can reside or run on a plurality of 30-30 ”servers. In some embodiments, the application delivery system 500 may run on a server bank. In one embodiment, the server 30 running the application delivery system 500 can also store or supply the application and the data file. In another embodiment, a first set of one or more servers 30 can run the application delivery system 500, and a different server 30 'can store or supply the application and the data file. In some embodiments, each of the 500 application delivery systems, the application and the data file may reside or be located on different servers. In one embodiment, the application delivery system 500 also includes policy agent 406. In another embodiment, policy agent 406 runs separately from application delivery system 500. In some embodiments, policy agent 406 is on the same server 30 as application delivery system 500. In other embodiments, agent policy 406 is executed on the 1250 apparatus. In yet another embodiment, any portion of the application delivery system 500 and / or policy agent 406 may reside, be executed or stored in or distributed to the 1250 apparatus, or to a plurality of apparatus.
In some embodiments, the client agent 560 includes any of the streaming client 562, the collection agent 404 and / or the acceleration program 6120, as previously described above. In one embodiment, client agent 560, streaming client 562, collection agent 404 and / or the acceleration program 6120 form or are incorporated into a single program or a set of executable instructions providing functionality, logic and the operations of each. In other embodiments, each of the streaming client 562, the collection agent 404 and the acceleration program 6120 is executed separately from the client agent 560. In one mode, client 10 executes client agent 560. In another mode
329 client 10 executes streaming client 562. In some modalities, client 10 executes collection agent 404. In one embodiment, client 10 executes the 6120 acceleration program. In some modalities, client 10 executes client agent 560 with one or more of the streaming client 562, the collection agent 404 or the acceleration program 6120. In other embodiments, client 10 executes the streaming client 562 and the acceleration program 6120. In one embodiment, client 10 executes the acceleration program 6120 and the collection agent 404.
In some embodiments, client 10 obtains client agent 560, streaming client 562 and / or collection agent 404 from server 30. In other embodiments, client 10 obtains client agent 560, client continuous transmission 562 and / or the collection agent 404 from the apparatus 1250. In one embodiment, any one of the customer agent 560, the continuous transmission client 562 and / or the collection agent 404 can be stored in the apparatus 1250. For example, in some embodiments, the client agent 560, the streaming client 562 and / or the collection agent 404 can be cached on the 1250 appliance. In other embodiments, upon a determination by the 1250 appliance that an application can be accelerated, the apparatus 1250 can transmit the client agent 560, the streaming client 562, the acceleration program 6120 and / or the collection agent 404 to the client 10. In other embodiments, client 10 can automatically install and run any one of client agent 560, streaming client 562, accelerator program 6120 and / or collection agent 404. In yet another modality, any one of the client agent 560, the streaming client 562, the acceleration program 6120 and / or the collection agent 404 can be executed transparently for a user or client application, or for any portion of the customer's network stack.
In some embodiments, the 1250 appliance establishes a VPN or SSL VPN connection for client 10 with server 30 or
330 40 'net. In other modalities, the apparatus 1250 acts as a proxy, an access server or a load balancer for providing access to one or more servers 30. In one embodiment, the apparatus 1250 and / or the acceleration program 6120 accelerate the delivery of the streaming client 562, the collection agent 404 and / or client agent 560 to client 10. In one embodiment, the apparatus 1250 speeds up the delivery of the 6120 acceleration program to client 10. In other modalities, the apparatus 1250 and / or the acceleration program 6120 accelerate the delivery of the computing environment 15, of an application and / or data file to the client 10. In one embodiment, the client 10 has a computing environment 15 and the device 1250 and / or the accelerator program 6120 speed up the delivery of the application and / or the data file. In one embodiment, the 1250 system and / or the 6120 acceleration program speed up application delivery. In another mode, the 1250 equipment and / or the 6120 acceleration program speed up the delivery of the data file. In yet another embodiment, the apparatus 1250 and / or the acceleration program 6120 accelerate the delivery of a computing environment 15, such as an execution environment or a virtualized execution environment previously described here.
In one embodiment, apparatus 1250 uses information collected from collection agent 404 to determine whether a computing environment 15, an application and / or a data file can be accelerated. In some embodiments, the policy agent for application 1250 comprises policy agent 406. In other embodiments, apparatus 1250 communicates with or interfaces with policy agent 406 to determine authentication and / or authorization from a remote user or remote client 10 for access to the computing environment 15, the application and / or to the data file from a server 30. In another embodiment, apparatus 1250 communicates with or interfaces with policy agent 406 to determine authentication and / or authorization from a remote user or remote client 10 to have the application delivery system 500 delivering a or more from am
331 computing environment 15, the application and / or the data file. In yet another modality, the 1250 appliance establishes a VPN or SSL VPN connection based on the authentication and / or authorization of the 404 collection agent of a remote user or a remote client 10. In one embodiment, the 1250 appliance controls the flow of network traffic and communication sessions based on policy agent policies 406. For example, apparatus 1250 can control access to a computing environment 15, an application or data file based on policy agent 406.
Referring now to Figure 49B, a modality of a method for accelerating the delivery of a computing environment to a remote user of a customer and a remote location is described. In a brief overview of method 8000, in step 8005, server 30 receives a request to run an application on client 10. In step 8010, server 30 continuously transmits an application to client 10 for execution. In step 8015, apparatus 1250 and / or the client side acceleration program 6120 accelerate the transmission or delivery of the application to client 10. In step 8020, client 10 or the application requests a data file from the server 30 for use by the application. In step 8025, server 30 and / or apparatus 1250 transmit the data file to client 10. In step 8030, the apparatus 1250 and / or the client side acceleration program 6120 speeds up the transmission or delivery of the data file to the client 10.
In more detail, in step 8005, a server 30 receives a request to run an application on a client 10. In some embodiments, the user of client 10 makes the request. In other modalities, an application, operating system or computing environment 15 transmits the request. In one embodiment, apparatus 1250 intercepts the request from client 10 and forwards the request to server 30. In one embodiment, the apparatus 1250 forwards the request to server 30 based on the authentication and / or authorization of the user or client 10. In another embodiment, the apparatus 1250 forwards the request.
332 request to server 30 based on information provided by the collection agent 404. In one embodiment, the request includes a request for application execution by a method of a plurality of execution methods. For example, client user 10 may request the application to run as an application continuously streamed from the server, as an application installed and run locally, or as a server-based application running on server 30 and viewing remotely for the client 10. In some modalities, the request is based on a file type association. For example, a user 10 can select a file associated with an application that is used for reading or accessing the file.
In step 8010, in response to the request from step 8005, server 30 transmits the application for execution to client 10. In some embodiments, server 30 continuously transmits the application to client 10. For example, by streaming the application in some modalities, the application operates on client 10 without an installation. In other embodiments, the server 30 transmits to the client 10 an application for local installation and execution. For example, using the automatic installation and execution techniques described in conjunction with the ace20 reading program 6120 in Section C, customer 10 can automatically install and run the application upon receipt. In another embodiment, server 30 runs the application on a server on behalf of the client, and transmits the display to client 10 via a remote display protocol or presentation layer. In yet another modality, the a25 pairing 1250 continuously transmits the application to client 10 or transmits the application to client 10 for installation and / or execution. In some embodiments, the apparatus 1250 and / or the server 30 transmit the computing environment 15 comprising the application. In other embodiments, the apparatus 1250 and / or the server 30 transmit the computing environment 15 in response to a request.
In step 8015, the equipment 1250 and / or the acceleration program 6120 accelerate the delivery of the application for execution to the customer
333
10. In one embodiment, apparatus 1250 performs or applies one or more of the plurality of acceleration techniques described in Section C above. In another embodiment, the 6120 acceleration program performs or applies one or more of the plurality of client-side acceleration techniques also described in Section C above. In some embodiments, the acceleration program 1250 and the apparatus 6120 work together or together with each other to carry out a plurality of acceleration techniques on the client 10 and the apparatus 1250. For example, the acceleration program 6120 can execute a first set of one or more acceleration techniques, while apparatus 1250 performs a second set of one or more acceleration techniques. In one embodiment, the 1250 acceleration program and the 6120 apparatus perform the same acceleration techniques. In another mode, the acceleration program 1250 and the device 6120 perform different acceleration techniques.
In one embodiment, the apparatus 1250 and / or the acceleration program 6120 accelerate any payload communicated through a transport layer connection between client 10 and server 30. In some embodiments, server 30 continuously transmits the application as a or more data files over a transport layer connection, such as a payload of a TCP / IP packet. In other embodiments, the server 30 continuously transmits the application via an application layer protocol or a streaming protocol over a transport layer connection. In another embodiment, the server 30 transmits a display output via an ICA or RDP protocol over the transport layer connection. In any of these modes, the apparatus 1250 and / or the acceleration program 6120 accelerate application delivery through payloads of transport layer packages.
In step 8020, client 10 transmits a request for a data file for use by the application or computing environment 15. In some embodiments, the request for the data file is transmitted
334 with the request for running an application in step 8005. In one embodiment, the request for running an application includes the request for the data file. In other modalities, the application or the computing environment requests the data file in the course of carrying out any functionality, operations or logic of the application or computing environment. For example, the application or computing environment 15 can request any macros, scripts, configuration data, profile, models or rules from a server 30. In some ways, the application requests the data file as a background process or task of the application. In one embodiment, the user of the application or computing environment 15 requests the data file to read, access or otherwise process the file for editing through an application, such as opening a document for editing through an application word processing. In some modalities, the user drags and drops a device in an application of the computing environment to request the data file. In other modalities, the user can request the data file through a file and directory interface, for example, a file explorer in the Windows operating system, for storage of a networked or remote storage system, such as a driver network from a central server.
In step 8025, server 30 or device 1250 transmits the requested data file to client 10. In some embodiments, server 30 or device 1250 transmits the data file to client 10 in response to the request in step 8020. In other embodiments, server 30 or apparatus 1250 transmits the data file to client 10 without a request from client 10. For example, server 30 can push an update to a data file for client 10. In one embodiment, server 30 transmits the requested data file to client 10. In another embodiment, appliance 1250 transmits the requested data file to client 10. For example, in one embodiment, appliance 1250 intercepts a request. through the data file, checks the cache of the 1250 system for the data file, and
335 transmits the cached data file to client 10. In yet another mode, the accelerator program 6120 intercepts the data file request on client 10 and provides the data file to client 10 through a program cache acceleration 6120. In some embodiments, the device 1250 or the server 30 transmits the data file via a streaming protocol or a continuous transmission. In other embodiments, apparatus 1250 or server 30 transmits the data file using any type and form of caching protocol.
In step 8030, the apparatus 1250 and / or the acceleration program 6120 speed up the delivery or transmission of the data file to the client 10. In some modalities, the data file can be transmitted using any type and form of protocol, such as an application layer protocol by a transport layer protocol. In one embodiment, the 1250 device speeds up the transmission of the data file. In another mode, the 6120 acceleration program speeds up the transmission of the data file. In some embodiments, the 1250 equipment together with the 1250 acceleration program speeds up the transmission of the data file. As discussed here, the apparatus 1250 and / or the acceleration program 6120 can perform one or more of a plurality of acceleration techniques on the client 10 and the apparatus 30 to accelerate the transmission of the data file. In some embodiments, the appliance 1250 and / or the accelerator program 6120 can cache one or more data files on the client 10 or on the appliance 1250 for use by the application or computing environment 15.
Representative Examples
As an example modality, a user may be located at a branch office working on a local machine 10. The user may wish to use a word processing application, such as MICROSOFT Word to edit a company document, residing on remote machines 30 located in a central office. The user can then navigate through a web browser to a hosted corporate website
336 by the remote machine 30. Once the user is authenticated by the remote machine 30, the remote machine 30 can prepare and transmit to the local machine 10 an HTML page that includes a Program Neighborhood window, as described here in figures 3A and 3B in which graphic icons appear representing application programs to which the local machine 10 has access. The user of the local machine 10 can invoke the ex of an application by clicking on an icon. A policy officer as described in figures 4A through 4D can then determine whether and how local machine 10 can access the word processing application. The application can then be locally installed and executed using the techniques described in figures 20 to 21. The user can then use the application to select a document on the remote machine 30 for editing. An apparatus 1250 can then speed up the delivery of the file to the local machine 10 using any techniques described here, such as TCP multiplexing.
As another example, a second user may be located at a branch office working on a local machine 10. The user may wish to access, via the user's corporate account, an email containing an attached file. The email application and email data files can reside in a central office. Upon a user request to access the email application, a policy agent as described in figures 4A through 4D can determine that it is to continuously transmit the email application to the user using the continuous transmission techniques described here. A policy officer can also determine that it is to install an accelerator program as described here on the local machine 10. Application streaming can be accelerated using techniques described here, such as dynamic caching. A 1250 device can accelerate file delivery by using an acceleration technique, such as TCP clustering, as described here. The system can also cache some or all of the data files delivered to the remote machine, in order to speed up subsequent requests. Caching
337 it can be done on the equipment 1250 or on the local machine 10 together with the acceleration program.
As a third example, a user located in a branch may wish to access a spreadsheet program, such as MICROSOFT Excel, to update a spreadsheet. The user can use a local machine 10 to establish an SSL connection to a remote machine 30 at a central office, and select the spreadsheet application from a program neighborhood, as described in figures 3A and 3B. A collection agent as described in figure 4D can then collect information about the local machine to determine whether the spreadsheet application can be continuously transmitted to local machine 10 over the SSL connection. The SSL connection can be accelerated by a 1250 appliance providing SSL or TCP connection grouping and multiplexing, as described here. The user can then select a file from within the spreadsheet application for editing. Local machine 10 can transmit the request for the file to the remote machine. A 1250 device can then use the compression techniques described here to accelerate the delivery of the file to the user.
Although generally described above as an application delivery system and an application acceleration delivery from a computing environment to a customer, the application delivery system and the appliance can accelerate the delivery of a plurality of computing environments, applications and / or data files for a customer. For example, the application delivery system and the appliance can accelerate the delivery to the customer of a first computing environment associated with one type of operating system and a second computing environment associated with a second type of operating system. In addition, the application delivery system and the appliance can accelerate the delivery of a computing environment, application and / or data file to a plurality of customers. Furthermore, although generally described above as an application delivery system and a device accelerating the delivery of a computing environment to a remote user or customer
338 remote, the application delivery system and the appliance can accelerate the delivery of a computing environment, an application and / or a data file to any customer, local, remote or otherwise, such as a customer on a LAN server.
Furthermore, although generally described above as a device between the client and the application delivery system, a plurality of devices can be used between one or more clients and one or more servers. In some embodiments, a first system resides on the customer's network, and a second system resides on the server's network. In one embodiment, the first device and the second device communicate with each other in carrying out the operations described here. For example, the first device and the second device can communicate using any internal, high-performance or device-to-device communication protocol. In addition, a plurality of application delivery systems can be used in conjunction with an apparatus or a plurality of apparatus. The application delivery system and the appliance can be used in a variety of network environments and infrastructure architectures.
The modalities can be provided as one or more programs that can be read on a computer and are realized in one or more articles of manufacture. The article of manufacture can be a floppy disk, a hard disk, a compact disk, a digital versatile disk, a flash memory card, a PROM, a RAM, a ROM or a magnetic tape. In general, programs that can be read on a computer can be implemented in any programming language. Some examples of languages that can be used include C, C ++, C # or JAVA. Software programs can be stored in one or more articles of manufacture as an object code.
Contents13
73 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73
20 members in 9 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 60744720 | United States of America | – | |
| 74472006 | United States of America | P | |
| 74472006 | United States of America | P | |
| 2007066433 | United States of America | W | |
| 2007066433 | United States of America | W | |
| 2007066433 | – | – | – |
| 60744720 | – | – | – |
| US20060744720P | – | – | – |
| WO2007US66433 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| US2007244987A1 | United States of America | A1 | |
| US2007245409A1 | United States of America | A1 | |
| AU2007238099A1 | Australia | A1 | |
| CA2646414A1 | Canada | A1 | |
| WO2007121241A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2007121241A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20080110894A | Republic of Korea | A | |
| EP2005712A2 | European Patent Office (EPO) | A2 | |
| CN101473628A | China | A | |
| JP2009536377A | Japan | A | |
| US2010023582A1 | United States of America | A1 | |
| US7970923B2 | United States of America | B2 | |
| BRPI0709986A2This record | Brazil | A2 | |
| AU2007238099B2 | Australia | B2 | |
| US8151323B2 | United States of America | B2 | |
| US8886822B2 | United States of America | B2 | |
| CN104767834A | China | A | |
| CN104767834B | China | B | |
| EP2005712B1 | European Patent Office (EPO) | B1 | |
| BRPI0709986B1 | Brazil | B1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapse because of non-payment of annual fees (definitively: art 78 iv lpi, resolution 113/2013 art. 12)LapsedB24J | B24J | |
| Lapse acc. art. 78, item iv - on non-payment of the annual fees in timeLapsedB21F | B21F | |
| Decision: intention to grantB09A | B09A | |
| Objections, documents and/or translations needed after an examination request according art. 34 industrial property lawB06F | B06F |
Numbers
- Publication
- PI0709986
- Publication, DOCDB
- PI0709986
- Publication, EPODOC
- BRPI0709986
- Application
- 9986
- Application, DOCDB
- PI0709986
- Application, EPODOC
- BR2007PI09986
Titles2
- Portuguese
- SISTEMAS E MÉTODOS PARA A ACELERAÇÃO DA ENTREGA DE UM AMBIENTE DE COMPUTAÇÃO PARA UM USUÁRIO REMOTO
- English
- SYSTEMS AND METHODS FOR ACCELERATING THE DELIVERY OF A COMPUTER ENVIRONMENT TO A REMOTE USER
Classification
- CPC, 11
- H04L67/06
- H04L67/34
- H04L69/10
- H04L63/0272
- H04L63/105
- H04L63/166
- H04L67/02
- H04L69/165
- H04L67/568
- H04L69/16
- H04L2012/5603
- IPC, 2
- H04L29 08
- H04L29 06