EP1515229A2

System for executing application sets within application containers

Abstract

A system is disclosed having servers with operating systems that may differ, operating in disparate computing environments, wherein each server includes a processor and an operating system including a kernel a set of associated local system files compatible with the processor. This invention discloses a method of providing at least some of the servers in the system with secure, executable, applications related to a service, wherein the applications may be executed in a secure environment, wherein the applications each include an object executable by at least some of the different operating systems for performing a task related to the service. The method of this invention requires storing in memory accessible to at least some of the servers a plurality of secure containers of application software. Each container includes one or more of the executable applications and a set of associated system files required to execute the one or more applications, for use with a local kernel residing permanently on one of the servers. The set of associated system files are compatible with a local kernel of at least some of the plurality of different operating systems. The containers of application software exclude a kernel; and some or all of the associated system files within a container stored in memory are utilized in place of the associated local system files resident on the server.

EP1515229A2, drawing sheet 1
Sheet 1 of 18

Term

Term ended

Projected expiry passed 15 September 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 15 independent, 2 dependent

  1. 1
    In a system having a plurality of servers with operating systems that differ, operating in disparate computing environments, wherein each server includes a processor and an operating system including a kernel a set of associated local system files compatible with the processor, a method of providing at least some of the servers in the system with secure, executable, applications related to a service, wherein the applications may be executed in a secure environment, wherein the applications each include an object executable by at least some of the different operating systems for performing a task related to the service, the method comprising the steps of:storing in memory accessible to at least some of the servers a plurality of secure containers of application software, each container comprising one or more of the executable applications and a set of associated system files required to execute the one or more applications, for use with a local kernel residing permanently on one of the servers;wherein the set of associated system files are compatible with a local kernel of at least some of the plurality of different operating systems, the containers of application software excluding a kernel, and wherein some or all of the associated system files within a container stored in memory are utilized in place of the associated local system files resident on the server prior to said storing step.
  2. 2
    A method as defined in claim 1, wherein each container has an execution file associated therewith for starting the one or more applications, and wherein the execution file includes instructions related to an order in which executable applications within will be executed, and wherein in operation when applications are executed, applications within a container have no access to system files or applications in other containers or system files within the operating system during execution thereof if those applications or system files are read/write files.
  3. 4
    A method as defined in any one of claims 1, 2, or 3 comprising the step of assigning a unique associated identity to each of a plurality of the containers, wherein the identity includes at least one of IP address, host name, and MAC address.
  4. 5
    A method as defined in any one of claims 1 through 4, wherein the one or more applications and associated system files are retrieved from a computer system having a plurality of secure containers.
  5. 6
    A method as defined in any one of claims 2 through 5 wherein server information related to hardware resource usage including at least one of CPU memory, network bandwidth and disk allocation is associated with at least some of the containers prior to the applications within the containers being executed.
  6. 7
    A method as defined in any of claims 2 through 6, wherein containers include files stored in network file storage, and parameters forming descriptors of containers stored in a separate location.
  7. 8
    A method as defined in any of claims 1 through 7 comprising the step of creating containers prior to said step of storing containers in memory, wherein the step of creating containers comprises the steps of:a) running an instance of a service on a server,    determining which files are being used, and,    copying applications and associated system files to memory;or, (b) using a skeleton set of system files as a container starting point and installing applications into that set of files.
  8. 9
    A method as defined in any of claims 1 to 8 further comprising the step of installing a service on a target server selected from one of the plurality of servers, wherein the step of installing the service includes the steps of:using a graphical user interface, associating a unique icon representing a service with an unique icon representing a server for hosting applications related to the service and for executing the service, so as to cause the applications to be distributed to, and installed on the target server.
  9. 10
    A method as defined in claim 9 wherein the target server and the graphical user interface are at remote locations, or wherein the graphical user interface is installed on a computing platform, and wherein the computing platform is a different computing platform than the target server.
  10. 11
    A method as defined in any of claims 9 or 10, wherein the step of associating includes the step of relatively moving the unique icon representing the service to the unique icon representing a server.
  11. 12
    A method as defined in any of claims 9 through 11 further comprising the step of:de-installing a service from a server, comprising the steps of: displaying the unique icon representing the service;displaying the unique server icon representing the server on which the service is installed;and utilizing the icon representing the service and the icon representing the server to initiating the de-installation of the selected software application from the selected server.
  12. 13
    A method according to any of claims 9 through 12 further comprising the step of separating the icon representing the service from the icon representing the server.
  13. 15
    A computing system for performing a plurality of tasks each comprising a plurality of processes comprising:a plurality of secure stored containers of associated files accessible to, and for execution on, one or more servers, each container being mutually exclusive of the other, such that read/write files within a container cannot be shared with other containers, each container of files having its own unique identity associated therewith, said identity comprising at least one of an IP address, a host name, and a Mac_address;wherein, the plurality of files within each of the plurality of containers comprise one or more application programs including one or more processes, and associated system files for use in executing the one or more processes, each container having its own execution file associated therewith for starting one or more applications, in operation, each container utilizing a kernel resident on the server and wherein each container exclusively uses a kernel in an underlying operation system in which it is running and is absent its own kernel;and, a run time module for monitoring system calls from applications associated with one or more containers and for providing control of the one or more applications.
  14. 16
    A computing system as defined in claim 15, further comprising a scheduler comprising values related to an allotted time in which processes within a container may utilize predetermined resources and, wherein the run time module includes an intercepting module associated with the plurality of containers for intercepting system calls from any of the plurality of containers and for providing values alternate to values the kernel would have assigned in response to the system calls, so that the containers can run independently of one another without contention, in a secure manner, the values corresponding to at least one of the IP address, the host name and the Mac_Address.
  15. 17
    A computing system as defined in claim 16, wherein the run time module performs:monitoring resource usage of applications executing;intercepting system calls to kernel mode, made by the at least one respective application within a container, from user mode to kernel mode;comparing the monitored resource usage of the at least one respective application with the resource limits;and, forwarding the system calls to a kernel on the basis of the comparison between the monitored resource usage and the resource limits.