Automatic restore for a failed virtual computing session
Abstract
A computer system includes a client device, and a server configured to monitor a status of a virtual computing session for failure, with the virtual computing session being accessed by the client device. The server redirects the client device to a backup virtual computing session based on failure of the virtual computing session, and updates a state of the backup virtual computing session to match a previous state of the virtual computing session prior to failure.

Term
Projected expiry 17 June 2040.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 3 independent, 12 dependent
- 1A computer system comprising:a client device;and a server configured to monitor a virtual computing session for failure, with the virtual computing session being accessed by said client device, redirect said client device to a backup virtual computing session based on failure of the virtual computing session, and update a state of the backup virtual computing session to match a previous state of the virtual computing session prior to failure.
- 4A server comprising:a memory and a processor cooperating with said memory and configured to monitor a virtual computing session for failure, with the virtual computing session being accessed by a client device, redirect the client device to a backup virtual computing session based on failure of the virtual computing session, and update a state of the backup virtual computing session to match a previous state of the virtual computing session prior to failure.
- 11A method comprising:monitoring a virtual computing session for failure, with the virtual computing session being accessed by a client device;redirecting the client device to a backup virtual computing session based on failure of the virtual computing session;and updating a state of the backup virtual computing session to match a previous state of the virtual computing session prior to failure.
Independent claims3
94 paragraphs, as filed
<u>Technical Field</u>
The present disclosure relates to cloud service providers, and more particularly, to providing backup virtual desktops to users.
<u>Background</u>
There are several different types of desktop virtualization systems. As an example, Virtual Desktop Infrastructure (VDI) refers to the process of running a user desktop inside a virtual machine that resides on a server, with the virtual machine providing a virtual computing session. Servers in such systems may include storage for virtual desktop images and system configuration information, as well as software components to provide the virtual desktops and allow users to interconnect to them. For example, a VDI server may include one or more hypervisors (i.e., virtual machine managers) to create and maintain multiple virtual machines, software to manage the hypervisors, a connection broker, and software to provision and manage the virtual desktops.
Desktop virtualization systems may be implemented using a single virtualization server or a combination of servers interconnected as a server grid. For example, a cloud computing environment, or cloud system, may include a pool of computing resources (e.g., desktop virtualization servers), storage disks, networking hardware, and other physical resources that may be used to provision virtual desktops, along with additional computing devices to provide management and customer portals for the cloud system.
<u>Summary</u>
A computer system comprises a client device, and a server configured to monitor a virtual computing session for failure, with the virtual computing session being accessed by the client device. The client device is redirected to a backup virtual computing session based on failure of the virtual computing session, and a state of the backup virtual computing session is updated to match a previous state of the virtual computing session prior to failure.
Failure of the virtual computing session corresponds to when the virtual computing session becomes unavailable while in use by the client device. This may be due to a virtual server providing the computing session being taken offline for maintenance without any warning, or due to failure of the virtual server. Loss of productivity is minimized by redirecting the client device to a backup virtual computing session that corresponds to a most recent state update on applications running in the assigned virtual computing session.
The computer system may further include at least one virtual delivery appliance connecting the client device to the virtual computing session, with the server being further configured to receive state updates on the virtual computing session from the at least one virtual delivery appliance. The server may update the state of the backup virtual computing session with a most recent state update received.
The server may update the state of the backup virtual computing session before failure of the virtual computing session. Alternatively, the server may update the state of the backup virtual computing session after failure of the virtual computing session.
The at least one virtual delivery appliance may comprise a plurality of virtual delivery appliances, and the server may redirect the client device to a different virtual delivery appliance to access the backup virtual computing session.
The virtual computing session may be hosted in a data center, and the backup virtual computing session may be hosted in a different data center. The at least one virtual delivery appliance may monitor a status of the virtual computing session, and provide the status to the server.
Another aspect is directed to a server comprising a memory and a processor cooperating with the memory and configured to monitor a virtual computing session for failure, with the virtual computing session being accessed by a client device. The client device is redirected to a backup virtual computing session based on failure of the virtual computing session, and a state of the backup virtual computing session is updated to match a previous state of the virtual computing session prior to failure.
Yet another aspect is directed to a method comprising monitoring a virtual computing session for failure, with the virtual computing session being accessed by a client device. The client device is redirected to a backup virtual computing session based on failure of the virtual computing session, and a state of the backup virtual computing session is updated to match a previous state of the virtual computing session prior to failure.
<u>Brief Description of the Drawings</u>
<ul id="ul0001" list-style="none" compact="compact"><li><figref idref="f0001">FIG. 1</figref> is a schematic block diagram of a network environment of computing devices in which various aspects of the disclosure may be implemented.</li><li><figref idref="f0002">FIG. 2</figref> is a schematic block diagram of a computing device useful for practicing an embodiment of the client machines or the remote machines illustrated in <figref idref="f0001">FIG. 1</figref>.</li><li><figref idref="f0003">FIG. 3</figref> is a schematic block diagram of a cloud computing environment in which various aspects of the disclosure may be implemented.</li><li><figref idref="f0004">FIG. 4</figref> is a schematic block diagram of desktop, mobile and web based devices operating a workspace app in which various aspects of the disclosure may be implemented.</li><li><figref idref="f0005">FIG. 5</figref> is a schematic block diagram of a workspace network environment of computing devices in which various aspects of the disclosure may be implemented.</li><li><figref idref="f0006">FIG. 6</figref> is a schematic block diagram of a computer system providing backup virtual computing sessions in which various aspects of the disclosure may be implemented.</li><li><figref idref="f0007">FIG. 7</figref> is a more detailed schematic block diagram of the computer system illustrated in <figref idref="f0006">FIG. 6</figref>.</li><li><figref idref="f0008">FIG. 8</figref> is a flowchart illustrating a method for operating the computer system illustrated in <figref idref="f0006">FIG. 6</figref>.</li><li><figref idref="f0009">FIG. 9</figref> is a flowchart illustrating a method for operating the broker service illustrated in <figref idref="f0006">FIG. 6</figref>.</li></ul>
<u>Detailed Description</u>
The present description is made with reference to the accompanying drawings, in which exemplary embodiments are shown. However, many different embodiments may be used, and thus the description should not be construed as limited to the particular embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete. Like numbers refer to like elements throughout.
As will be discussed below, organizations or enterprises turn to cloud service providers to provide desktop virtualization systems for their users. Since these organizations do not manage maintenance of the virtual servers, there is typically a service level agreement (SLA) between the cloud service providers and the organizations to ensure a minimum level of service is maintained.
Each cloud service provider typically manages tens of thousands of virtual servers to provide the virtual desktops. Even with a SLA of 99.9999%, there is still a possibility of a considerable number of virtual desktops being shut down due to maintenance of a virtual server without any warning to the users. Consequently, user productivity is significantly impacted when their virtual computing session is no longer available. Thus, existing technologies provide an overall user experience that is inconsistent and frustrating at times which can lead to less user adaption of such services.
To solve the problems with existing virtualization technologies described above, the present disclosure describes systems, devices and methods in which a state of the applications running on each virtual desktop is periodically saved. This allows each user with a virtual computing session that is no longer available to be redirected to a backup virtual computing session configured with a most recent state update received prior to the virtual computing session becoming unavailable.
The present description is made with reference to the accompanying drawings, in which example embodiments are shown. However, many different embodiments may be used, and thus the description should not be construed as limited to the particular embodiments set forth herein. Like numbers refer to like elements throughout.
As will be appreciated by one of skill in the art upon reading the following disclosure, various aspects described herein may be embodied as a device, a method or a computer program product (e.g., a non-transitory computer-readable medium having computer executable instruction for performing the noted operations or steps). Accordingly, those aspects may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects.
Furthermore, such aspects may take the form of a computer program product stored by one or more computer-readable storage media having computer-readable program code, or instructions, embodied in or on the storage media. Any suitable computer readable storage media may be utilized, including hard disks, CD-ROMs, optical storage devices, magnetic storage devices, and/or any combination thereof.
Referring initially to <figref idref="f0001">FIG. 1</figref>, a non-limiting network environment 10 in which various aspects of the disclosure may be implemented includes one or more client machines <b>12A-12N,</b> one or more remote machines <b>16A-16N,</b> one or more networks <b>14, 14',</b> and one or more appliances <b>18</b> installed within the computing environment <b>10.</b> The client machines <b>12A-12N</b> communicate with the remote machines <b>16A-16N</b> via the networks <b>14, 14'.</b>
In some embodiments, the client machines <b>12A-12N</b> communicate with the remote machines <b>16A-16N</b> via an intermediary appliance <b>18.</b> The illustrated appliance <b>18</b> is positioned between the networks <b>14, 14'</b> and may also be referred to as a network interface or gateway. In some embodiments, the appliance <b>108</b> may operate as an application delivery controller (ADC) to provide clients with access to business applications and other data deployed in a datacenter, the cloud, or delivered as Software as a Service (SaaS) across a range of client devices, and/or provide other functionality such as load balancing, etc. In some embodiments, multiple appliances <b>18</b> may be used, and the appliance(s) <b>18</b> may be deployed as part of the network <b>14</b> and/or <b>14'</b>.
The client machines <b>12A-12N</b> may be generally referred to as client machines <b>12,</b> local machines <b>12,</b> clients <b>12,</b> client nodes <b>12,</b> client computers <b>12,</b> client devices <b>12,</b> computing devices <b>12,</b> endpoints <b>12,</b> or endpoint nodes <b>12.</b> The remote machines <b>16A-16N</b> may be generally referred to as servers <b>16</b> or a server farm <b>16.</b> In some embodiments, a client device <b>12</b> may have the capacity to function as both a client node seeking access to resources provided by a server <b>16</b> and as a server <b>16</b> providing access to hosted resources for other client devices <b>12A-12N.</b> The networks <b>14, 14'</b> may be generally referred to as a network <b>14.</b> The networks <b>14</b> may be configured in any combination of wired and wireless networks.
A server <b>16</b> may be any server type such as, for example: a file server; an application server; a web server; a proxy server; an appliance; a network appliance; a gateway; an application gateway; a gateway server; a virtualization server; a deployment server; a Secure Sockets Layer Virtual Private Network (SSL VPN) server; a firewall; a web server; a server executing an active directory; a cloud server; or a server executing an application acceleration program that provides firewall functionality, application functionality, or load balancing functionality.
A server <b>16</b> may execute, operate or otherwise provide an application that may be any one of the following: software; a program; executable instructions; a virtual machine; a hypervisor; a web browser; a web-based client; a client-server application; a thin-client computing client; an ActiveX control; a Java applet; software related to voice over internet protocol (VoIP) communications like a soft IP telephone; an application for streaming video and/or audio; an application for facilitating real-time-data communications; a HTTP client; a FTP client; an Oscar client; a Telnet client; or any other set of executable instructions.
In some embodiments, a server <b>16</b> may execute a remote presentation services program or other program that uses a thin-client or a remote-display protocol to capture display output generated by an application executing on a server <b>16</b> and transmit the application display output to a client device <b>12.</b>
In yet other embodiments, a server <b>16</b> may execute a virtual machine providing, to a user of a client device <b>12,</b> access to a computing environment. The client device <b>12</b> may be a virtual machine. The virtual machine may be managed by, for example, a hypervisor, a virtual machine manager (VMM), or any other hardware virtualization technique within the server <b>16.</b>
In some embodiments, the network <b>14</b> may be: a local-area network (LAN); a metropolitan area network (MAN); a wide area network (WAN); a primary public network <b>14;</b> and a primary private network <b>14.</b> Additional embodiments may include a network <b>14</b> of mobile telephone networks that use various protocols to communicate among mobile devices. For short range communications within a wireless local-area network (WLAN), the protocols may include 802.11, Bluetooth, and Near Field Communication (NFC).
<figref idref="f0002">FIG. 2</figref> depicts a block diagram of a computing device <b>20</b> useful for practicing an embodiment of client devices <b>12,</b> appliances <b>18</b> and/or servers <b>16.</b> The computing device <b>20</b> includes one or more processors <b>22,</b> volatile memory <b>24</b> (e.g., random access memory (RAM)), non-volatile memory <b>30,</b> user interface (UI) <b>38,</b> one or more communications interfaces <b>26,</b> and a communications bus <b>48.</b>
The non-volatile memory <b>30</b> may include: one or more hard disk drives (HDDs) or other magnetic or optical storage media; one or more solid state drives (SSDs), such as a flash drive or other solid-state storage media; one or more hybrid magnetic and solid-state drives; and/or one or more virtual storage volumes, such as a cloud storage, or a combination of such physical storage volumes and virtual storage volumes or arrays thereof.
The user interface <b>38</b> may include a graphical user interface (GUI) <b>40</b> (e.g., a touchscreen, a display, etc.) and one or more input/output (I/O) devices <b>42</b> (e.g., a mouse, a keyboard, a microphone, one or more speakers, one or more cameras, one or more biometric scanners, one or more environmental sensors, and one or more accelerometers, etc.).
The non-volatile memory <b>30</b> stores an operating system <b>32,</b> one or more applications <b>34,</b> and data <b>36</b> such that, for example, computer instructions of the operating system <b>32</b> and/or the applications <b>34</b> are executed by processor(s) <b>22</b> out of the volatile memory <b>24.</b> In some embodiments, the volatile memory <b>24</b> may include one or more types of RAM and/or a cache memory that may offer a faster response time than a main memory. Data may be entered using an input device of the GUI <b>40</b> or received from the I/O device(s) <b>42.</b> Various elements of the computer <b>20</b> may communicate via the communications bus <b>48.</b>
The illustrated computing device <b>20</b> is shown merely as an example client device or server, and may be implemented by any computing or processing environment with any type of machine or set of machines that may have suitable hardware and/or software capable of operating as described herein.
The processor(s) <b>22</b> may be implemented by one or more programmable processors to execute one or more executable instructions, such as a computer program, to perform the functions of the system. As used herein, the term "processor" describes circuitry that performs a function, an operation, or a sequence of operations. The function, operation, or sequence of operations may be hard coded into the circuitry or soft coded by way of instructions held in a memory device and executed by the circuitry. A processor may perform the function, operation, or sequence of operations using digital values and/or using analog signals.
In some embodiments, the processor can be embodied in one or more application specific integrated circuits (ASICs), microprocessors, digital signal processors (DSPs), graphics processing units (GPUs), microcontrollers, field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), multicore processors, or general-purpose computers with associated memory.
The processor <b>22</b> may be analog, digital or mixed-signal. In some embodiments, the processor <b>22</b> may be one or more physical processors, or one or more virtual (e.g., remotely located or cloud) processors. A processor including multiple processor cores and/or multiple processors may provide functionality for parallel, simultaneous execution of instructions or for parallel, simultaneous execution of one instruction on more than one piece of data.
The communications interfaces <b>26</b> may include one or more interfaces to enable the computing device <b>20</b> to access a computer network such as a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or the Internet through a variety of wired and/or wireless connections, including cellular connections.
In described embodiments, the computing device <b>20</b> may execute an application on behalf of a user of a client device. For example, the computing device <b>20</b> may execute one or more virtual machines managed by a hypervisor. Each virtual machine may provide an execution session within which applications execute on behalf of a user or a client device, such as a hosted desktop session. The computing device <b>20</b> may also execute a terminal services session to provide a hosted desktop environment. The computing device <b>20</b> may provide access to a remote computing environment including one or more applications, one or more desktop applications, and one or more desktop sessions in which one or more applications may execute.
An example virtualization server <b>16</b> may be implemented using Citrix Hypervisor provided by Citrix Systems, Inc., of Fort Lauderdale, Florida ("Citrix Systems"). Virtual app and desktop sessions may further be provided by Citrix Virtual Apps and Desktops (CVAD), also from Citrix Systems. Citrix Virtual Apps and Desktops is an application virtualization solution that enhances productivity with universal access to virtual sessions including virtual app, desktop, and data sessions from any device, plus the option to implement a scalable VDI solution. Virtual sessions may further include Software as a Service (SaaS) and Desktop as a Service (DaaS) sessions, for example.
Referring to <figref idref="f0003">FIG. 3</figref>, a cloud computing environment <b>50</b> is depicted, which may also be referred to as a cloud environment, cloud computing or cloud network. The cloud computing environment <b>50</b> can provide the delivery of shared computing services and/or resources to multiple users or tenants. For example, the shared resources and services can include, but are not limited to, networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, databases, software, hardware, analytics, and intelligence.
In the cloud computing environment <b>50,</b> one or more clients <b>52A-52C</b> (such as those described above) are in communication with a cloud network <b>54.</b> The cloud network <b>54</b> may include backend platforms, e.g., servers, storage, server farms or data centers. The users or clients <b>52A-52C</b> can correspond to a single organization/tenant or multiple organizations/tenants. More particularly, in one example implementation the cloud computing environment <b>50</b> may provide a private cloud serving a single organization (e.g., enterprise cloud). In another example, the cloud computing environment <b>50</b> may provide a community or public cloud serving multiple organizations/ tenants. In still further embodiments, the cloud computing environment <b>50</b> may provide a hybrid cloud that is a combination of a public cloud and a private cloud. Public clouds may include public servers that are maintained by third parties to the clients <b>52A-52C</b> or the enterprise/tenant. The servers may be located off-site in remote geographical locations or otherwise.
The cloud computing environment <b>50</b> can provide resource pooling to serve multiple users via clients <b>52A-52C</b> through a multi-tenant environment or multi-tenant model with different physical and virtual resources dynamically assigned and reassigned responsive to different demands within the respective environment. The multi-tenant environment can include a system or architecture that can provide a single instance of software, an application or a software application to serve multiple users. In some embodiments, the cloud computing environment <b>50</b> can provide on-demand self-service to unilaterally provision computing capabilities (e.g., server time, network storage) across a network for multiple clients <b>52A-52C.</b> The cloud computing environment <b>50</b> can provide an elasticity to dynamically scale out or scale in responsive to different demands from one or more clients <b>52.</b> In some embodiments, the computing environment <b>50</b> can include or provide monitoring services to monitor, control and/or generate reports corresponding to the provided shared services and resources.
In some embodiments, the cloud computing environment <b>50</b> may provide cloud-based delivery of different types of cloud computing services, such as Software as a service (SaaS) <b>56,</b> Platform as a Service (PaaS) <b>58,</b> Infrastructure as a Service (IaaS) <b>60,</b> and Desktop as a Service (DaaS) <b>62,</b> for example. IaaS may refer to a user renting the use of infrastructure resources that are needed during a specified time period. IaaS providers may offer storage, networking, servers or virtualization resources from large pools, allowing the users to quickly scale up by accessing more resources as needed. Examples of IaaS include AMAZON WEB SERVICES provided by Amazon.com, Inc., of Seattle, Washington, RACKSPACE CLOUD provided by Rackspace US, Inc., of San Antonio, Texas, Google Compute Engine provided by Google Inc. of Mountain View, California, or RIGHTSCALE provided by RightScale, Inc., of Santa Barbara, California.
PaaS providers may offer functionality provided by IaaS, including, e.g., storage, networking, servers or virtualization, as well as additional resources such as, e.g., the operating system, middleware, or runtime resources. Examples of PaaS include WINDOWS AZURE provided by Microsoft Corporation of Redmond, Washington, Google App Engine provided by Google Inc., and HEROKU provided by Heroku, Inc. of San Francisco, California.
SaaS providers may offer the resources that PaaS provides, including storage, networking, servers, virtualization, operating system, middleware, or runtime resources. In some embodiments, SaaS providers may offer additional resources including, e.g., data and application resources. Examples of SaaS include GOOGLE APPS provided by Google Inc., SALESFORCE provided by Salesforce.com Inc. of San Francisco, California, or OFFICE 365 provided by Microsoft Corporation. Examples of SaaS may also include data storage providers, e.g. DROPBOX provided by Dropbox, Inc. of San Francisco, California, Microsoft SKYDRIVE provided by Microsoft Corporation, Google Drive provided by Google Inc., or Apple ICLOUD provided by Apple Inc. of Cupertino, California.
Similar to SaaS, DaaS (which is also known as hosted desktop services) is a form of virtual desktop infrastructure (VDI) in which virtual desktop sessions are typically delivered as a cloud service along with the apps used on the virtual desktop. CITRIX CLOUD is one example of a DaaS delivery platform. DaaS delivery platforms may be hosted on a public cloud computing infrastructure such as AZURE CLOUD from Microsoft Corporation of Redmond, Washington (herein "Azure"), or AMAZON WEB SERVICES provided by Amazon.com, Inc., of Seattle, Washington (herein "AWS"), for example. In the case of Citrix Cloud, Citrix Workspace app may be used as a single-entry point for bringing apps, files and desktops together (whether on-premises or in the cloud) to deliver a unified experience.
The unified experience provided by the Citrix Workspace app will now be discussed in greater detail with reference to <figref idref="f0004">FIG. 4</figref>. The Citrix Workspace app will be generally referred to herein as the workspace app <b>70.</b> The workspace app <b>70</b> is how a user gets access to their workspace resources, one category of which is applications. These applications can be SaaS apps, web apps or virtual apps. The workspace app <b>70</b> also gives users access to their desktops, which may be a local desktop or a virtual desktop. Further, the workspace app <b>70</b> gives users access to their files and data, which may be stored in numerous repositories. The files and data may be hosted on Citrix ShareFile, hosted on an on-premises network file server, or hosted in some other cloud storage provider, such as Microsoft OneDrive or Google Drive Box, for example.
To provide a unified experience, the resources a user requires may be located and accessible from the workspace app <b>70.</b> The workspace app <b>70</b> is provided in different versions. One version of the workspace app <b>70</b> is an installed application for desktops <b>72,</b> which may be based on Windows, Mac or Linux platforms. A second version of the workspace app <b>70</b> is an installed application for mobile devices <b>74,</b> which may be based on iOS or Android platforms. A third version of the workspace app <b>70</b> uses a hypertext markup language (HTML) browser to provide users access to their workspace environment. The web version of the workspace app <b>70</b> is used when a user does not want to install the workspace app or does not have the rights to install the workspace app, such as when operating a public kiosk <b>76.</b>
Each of these different versions of the workspace app <b>70</b> may provide the same user experience. This allows a user to move from client device <b>72</b> to client device <b>74</b> to client device <b>76</b> in different platforms and still receive the same user experience for their workspace. The client devices <b>72, 74</b> and <b>76</b> are referred to as endpoints.
As noted above, the workspace app <b>70</b> supports Windows, Mac, Linux, iOS, and Android platforms as well as platforms with an HTML browser (HTML5). The workspace app <b>70</b> incorporates multiple engines <b>80-90</b> allowing users access to numerous types of app and data resources. Engines <b>80-90</b> optimize the user experience for a particular resource, and also provide an organization or enterprise with insights into user activities and potential security threats.
An embedded browser engine <b>80</b> keeps SaaS and web apps contained within the workspace app <b>70</b> instead of launching them on a locally installed and unmanaged browser. With the embedded browser, the workspace app <b>70</b> is able to intercept user-selected hyperlinks in SaaS and web apps and request a risk analysis before approving, denying, or isolating access.
A high definition experience (HDX) engine <b>82</b> establishes connections to virtual browsers, virtual apps and desktop sessions running on either Windows or Linux operating systems. With the HDX engine <b>82,</b> Windows and Linux resources run remotely, while the display remains local, on the endpoint. To provide the best possible user experience, the HDX engine <b>82</b> utilizes different virtual channels to adapt to changing network conditions and application requirements. To overcome high-latency or high-packet loss networks, the HDX engine <b>82</b> automatically implements optimized transport protocols and greater compression techniques. Such techniques can be optimized for a certain type of display, such as video, images, or text. The HDX engine <b>82</b> identifies these types of resources in an application and applies the most appropriate algorithm to that section of the screen.
For many users, a workspace centers on data. A content collaboration engine <b>84</b> allows users to integrate all data into the workspace, whether that data lives on-premises or in the cloud. The content collaboration engine <b>84</b> allows administrators and users to create a set of connectors to corporate and user-specific data storage locations. This can include OneDrive, Dropbox, and on-premises network file shares, for example. Users can maintain files in multiple repositories and allow the workspace app <b>70</b> to consolidate them into a single, personalized library.
A networking engine <b>86</b> identifies whether or not an endpoint or an app on the endpoint requires network connectivity to a secured backend resource. The networking engine <b>86</b> can automatically establish a VPN tunnel for the entire endpoint device, or it can create an app-specific µ-VPN connection. A µ-VPN defines what backend resources an application and an endpoint device can access, thus protecting the backend infrastructure. In many instances, certain user activities benefit from unique network-based optimizations. If the user requests a file copy, the workspace app <b>70</b> can automatically utilize multiple network connections simultaneously to complete the activity faster. If the user initiates a VoIP call, the workspace app <b>70</b> improves its quality by duplicating the call across multiple network connections. The networking engine <b>86</b> uses only the packets that arrive first.
An analytics engine <b>88</b> reports on the user's device, location and behavior, where cloud-based services identify any potential anomalies that might be the result of a stolen device, a hacked identity or a user who is preparing to leave the company. The information gathered by the analytics engine <b>88</b> protects company assets by automatically implementing countermeasures.
A management engine <b>90</b> keeps the workspace app <b>70</b> current in terms of performance and policies. This not only provides users with the latest capabilities, but also includes extra security enhancements. The workspace app <b>70</b> includes an auto-update service that routinely checks and automatically deploys updates based on customizable policies.
Referring now to <figref idref="f0005">FIG. 5</figref>, a workspace network environment <b>100</b> providing a unified experience to a user based on the workspace app <b>70</b> will be discussed. The desktop, mobile and web versions of the workspace app <b>70</b> all communicate with the workspace experience service <b>102</b> running within the Citrix Cloud <b>104.</b> The workspace experience service <b>102</b> then pulls in all the different resource feeds <b>16</b> via a resource feed micro-service <b>108.</b> That is, all the different resources from other services running in the Citrix Cloud <b>104</b> are pulled in by the resource feed micro-service <b>108.</b> The different services may include a virtual apps and desktop service <b>110,</b> a secure browser service <b>112,</b> an endpoint management service <b>114,</b> a content collaboration service <b>116,</b> and an access control service <b>118.</b> Any service that an organization or enterprise subscribes to are automatically pulled into the workspace experience service <b>102</b> and delivered to the user's workspace app <b>70.</b>
In addition to cloud feeds <b>120,</b> the resource feed micro-service <b>108</b> can pull in on-premises feeds <b>122.</b> A cloud connector <b>124</b> is used to provide virtual apps and desktop deployments that are running in an on-premises data center. Desktop virtualization may be provided by Citrix virtual apps and desktops <b>126,</b> VMware Horizon <b>128</b> or Microsoft RDS <b>130,</b> for example. In addition to cloud feeds <b>120</b> and on-premises feeds <b>122,</b> device feeds <b>132</b> from Internet of Thing (IoT) devices <b>134,</b> for example, may be pulled in by the resource feed micro-service <b>108.</b> Site aggregation is used to tie the different resources into the user's overall workspace experience.
The cloud feeds <b>120,</b> on-premises feeds <b>122</b> and device feeds <b>132</b> each provides the user's workspace experience with a different and unique type of application. The workspace experience can support local apps, SaaS apps, virtual apps, and desktops browser apps, as well as storage apps. As the feeds continue to increase and expand, the workspace experience is able to include additional resources in the user's overall workspace. This means a user will be able to get to every single application that they need access to.
Still referring to the workspace network environment <b>20,</b> a series of events will be described on how a unified experience is provided to a user. The unified experience starts with the user using the workspace app <b>70</b> to connect to the workspace experience service <b>102</b> running within the Citrix Cloud <b>104,</b> and presenting their identity (event 1). The identity includes a user name and password, for example.
The workspace experience service <b>102</b> forwards the user's identity to an identity micro-service <b>140</b> within the Citrix Cloud <b>104</b> (event 2). The identity micro-service <b>140</b> authenticates the user to the correct identity provider <b>142</b> (event 3) based on the organization's workspace configuration. Authentication may be based on an on-premises active directory <b>144</b> that requires the deployment of a cloud connector <b>146.</b> Authentication may also be based on Azure Active Directory <b>148</b> or even a third party identity provider <b>150,</b> such as Citrix ADC or Okta, for example.
Once authorized, the workspace experience service <b>102</b> requests a list of authorized resources (event 4) from the resource feed micro-service <b>108.</b> For each configured resource feed <b>106,</b> the resource feed micro-service <b>108</b> requests an identity token (event 5) from the single-sign micro-service <b>152.</b>
The resource feed specific identity token is passed to each resource's point of authentication (event 6). On-premises resources <b>122</b> are contacted through the Citrix Cloud Connector <b>124.</b> Each resource feed <b>106</b> replies with a list of resources authorized for the respective identity (event 7).
The resource feed micro-service <b>108</b> aggregates all items from the different resource feeds <b>106</b> and forwards (event 8) to the workspace experience service <b>102.</b> The workspace experience service <b>102</b> is a component of the Citrix Cloud <b>104</b> that enumerates and delivers workspace resources to the Citrix workspace user experience. The user selects a resource from the workspace experience service <b>102</b> (event 9).
The workspace experience service <b>102</b> forwards the request to the resource feed micro-service <b>108</b> (event 10). The resource feed micro-service <b>108</b> requests an identity token from the single sign-on micro-service <b>152</b> (event 11). The user's identity token is sent to the workspace experience service <b>102</b> (event 12) where a launch ticket is generated and sent to the user.
The user initiates a secure session to a gateway service <b>160</b> and presents the launch ticket (event 13). The gateway service <b>160</b> initiates a secure session to the appropriate resource feed <b>106</b> and presents the identity token to seamlessly authenticate the user (event 14). Once the session initializes, the user is able to utilize the resource via the gateway service <b>160</b> (event 15). Having an entire workspace delivered through a single access point or application advantageously improves productivity and streamlines common workflows for the user.
Referring now to <figref idref="f0006">FIG. 6</figref>, the illustrated computer system <b>200</b> advantageously redirects a client device <b>210</b> from a virtual computing session <b>230</b> to another virtual computing session <b>240</b> based on failure of the virtual computing session <b>230.</b> The other virtual computing session <b>240</b> will also be referred to as a backup virtual computing session <b>240.</b> The client device <b>210</b> may be a smartphone, a tablet computer, a laptop computer, a desktop computer, for example.
Failure of the virtual computing session <b>230</b> corresponds to when the virtual computing session <b>230</b> becomes unavailable while in use by the client device <b>210.</b> A user is no longer able to view a virtual app or virtual desktop when the virtual computing session <b>230</b> fails. This may be due to a virtual server providing the virtual computing sessions <b>230</b> being taken offline for maintenance without any warning, or due to failure of the virtual server. Loss of productivity is minimized by redirecting the client device <b>210</b> to a backup virtual computing session <b>240</b> that corresponds to a recent or previous state update on applications running in the assigned virtual computing session <b>230.</b> The updates are at particular points in time, with the most recent update being the last update prior to the client device <b>210</b> being redirected to the backup virtual computing session <b>240.</b> Redirecting the client device <b>210</b> to the backup virtual computing session <b>240</b> may take a few seconds. Without the redirection, it would take several minutes or more for a user to access another virtual computing session, during which time the user is unable to work.
At least one virtual delivery appliance <b>220A</b> is configured to connect the client device <b>210</b> to the virtual computing session <b>230.</b> A virtual delivery appliance <b>220A</b> is software installed on a virtual machine running in a host computing device (i.e., virtual server). The virtual machine provides the virtual computing session <b>230,</b> and the virtual delivery appliance <b>220A</b> makes the virtual computing session <b>230</b> remotely available to a client device <b>210.</b> The at least one virtual delivery appliance <b>220A</b> may be a Citrix Virtual Delivery Agent (VDA), for example.
A broker service <b>250</b> is configured to interface with the at least one virtual delivery appliance <b>220A.</b> The broker service <b>250</b> may also be referred to as a broker server or server. The broker service <b>250</b> monitors the virtual computing session <b>230</b> for failure, redirects the client device <b>210</b> to the backup virtual computing session <b>240</b> based on a failure of the virtual computing session <b>230,</b> and updates a state of the backup virtual computing session <b>240</b> to match a previous state of the virtual computing session <b>230</b> prior to failure.
While only one client device <b>210,</b> one virtual computing session <b>230,</b> and one backup virtual computing session <b>240</b> are shown in the illustrated example, it will be appreciated that the computer system <b>200</b> may include a plurality of client devices <b>210,</b> a plurality of virtual computing sessions <b>230</b> and a plurality of backup virtual computing sessions <b>240.</b> Even though only two virtual delivery appliances <b>220A, 220B</b> are shown, additional virtual delivery appliances are provided as necessary based on how many client devices <b>210</b> are requesting virtual computing sessions <b>230.</b>
One example architecture for providing access to virtual computing sessions <b>230</b> is Citrix Virtual Apps and Desktops (CVAD) provided by Citrix Systems, Inc. Citrix Virtual Apps is an application virtualization platform that helps optimize productivity with universal access to virtual apps and server-based desktops from different client devices <b>210.</b> CVAD carries all the same functionality as Citrix Virtual Apps, plus the option to implement a scalable Virtual Desktop Infrastructure (VDI). Citrix Virtual Apps/CVAD are available as a cloud service or an on-prem configuration.
Such computer virtualization infrastructures may utilize Independent Computing Architecture (ICA) files for authenticating client devices <b>210</b> to access respective virtual computing sessions <b>230</b> and computing resources. ICA is a protocol designed for transmitting Windows graphical display data as well as keyboard and mouse input over a network. ICA files contain short-lived Secure Ticket Authority (STA) and logon tickets. The STA ticket may be used to authorize a connection to a virtual delivery appliance <b>220A</b> (e.g., Citrix Virtual Delivery Agent (VDA)) via a Gateway (e.g., Citrix Gateway).
The logon ticket may single-sign-on (SSOn) a user of the client device <b>210</b> into the virtual computing session <b>230.</b> In the case of CVAD, this is done through a "high-definition" experience (HDX) session, which may be available to users of centralized applications and desktops, on different client devices and over different networks.
In the illustrated example, functions of the broker service <b>250</b> are performed within a cloud computing service <b>260</b> (e.g., Citrix Cloud). The broker service <b>250</b> includes a processor and memory to determines which desktops and applications a user is allowed to access, as well as determining which virtual delivery appliance <b>220A</b> is to host the specific applications or desktop.
Additional functions of the broker service <b>250</b> include monitoring a status of the virtual computing session <b>230.</b> The status is provided by the virtual delivery appliance <b>220A</b> to the broker service <b>250.</b> In addition, the broker service <b>250</b> also periodically receives state updates <b>254</b> on applications running in the assigned virtual computing session <b>230.</b> The state updates <b>254</b> are stored in a database <b>252</b> within the cloud computing service <b>260.</b> When the virtual computing session <b>230</b> is no longer available (i.e., referred to as a failure), the broker service <b>250</b> redirects the client device <b>210</b> to the backup virtual computing session <b>240</b> and updates a state of the backup virtual computing session <b>240</b> with a most recent state update <b>254</b> received prior to the virtual computing session <b>230</b> becoming unavailable.
The cloud computing service <b>260</b> illustratively includes a cloud interface <b>256.</b> The cloud interface <b>256</b> is configured to interface with the client device <b>210</b> for enrollment of the client device <b>210</b> in the cloud computing service <b>260.</b> In an example implementation, the cloud interface <b>256</b> may be implemented with Citrix Workspace, and the client device <b>210</b> may be running Citrix Workspace App, although other suitable platforms may be used in different embodiments.
The at least one virtual delivery appliance <b>220A</b> may communicate with the broker service <b>250</b> via a cloud connector <b>258.</b> In an example embodiment, the cloud connector <b>258</b> may be implemented with Citrix Cloud Connector, although other suitable platforms may also be used in different embodiments. Citrix Cloud Connector is a component that serves as a channel for communication between Citrix Cloud and customer resource locations, enabling cloud management without requiring complex networking or infrastructure configuration. However, other suitable cloud connection infrastructure may also be used in different embodiments.
The illustrated computer system <b>200</b> will now be discussed in greater detail with reference to <figref idref="f0007">FIG. 7</figref>. A host computing device <b>228</b> providing the virtual computing session <b>230</b> is in a data center <b>226,</b> and a host computing device <b>238</b> providing the backup virtual computing session <b>230</b> may be in a different data center <b>236.</b> In other embodiments, the host computing devices <b>228, 238</b> may be in the same data center.
Host computing devices <b>228, 238</b> include a virtual machine <b>222A, 222B</b> managed by a hypervisor, respectively. The virtual machine <b>222A</b> provides the virtual computing session <b>230</b> and the virtual machine <b>222B</b> provides the backup virtual computing session <b>230</b> within which applications execute on behalf of the client device <b>210.</b> The virtual delivery appliance <b>220A</b> is associated with virtual machine <b>222A,</b> and the virtual delivery appliance <b>220B</b> is associated with virtual machine <b>222B.</b>
The status of the virtual computing session <b>230</b> correlates with a status of the virtual machine <b>222A.</b> Status refers to an operating condition or operational capabilities at a particular point in time. The operating condition or operational capabilities of the virtual computing session <b>230</b> correlates with the operating condition or capabilities of the virtual machine <b>222A.</b> When the virtual machine <b>222A</b> is available, then the virtual computing session <b>230</b> likewise is available. This corresponds to a normal operating status at a particular time. When the virtual machine <b>222A</b> is no longer available, then the virtual computing session <b>230</b> likewise is no longer available. This corresponds to a failed operating status at a particular time.
The virtual delivery appliance <b>220A</b> provides status updates about the virtual machine <b>222A</b> to the broker service <b>250.</b> The status updates may be referred to as a heartbeat or health signal that allows the broker service <b>250</b> to determine if the virtual machine <b>222A</b> providing the virtual computing session <b>230</b> has a normal operating status or a failed operating status. The heartbeat or health signal may be periodic pings from the virtual delivery appliance <b>220A</b> to the broker service <b>250.</b> The status updates thus let the broker service <b>250</b> know if the virtual machine <b>222A</b> is providing the virtual computing session <b>230</b> to the client device <b>210.</b>
The virtual delivery appliance <b>220A</b> also periodically provides state updates <b>254</b> to the broker service <b>250</b> on applications running in the virtual computing session <b>230.</b> A most recent state update <b>254</b> is to be used by the broker service <b>250</b> on the backup virtual session <b>240</b> when the virtual computing session <b>230</b> has a failed operating status.
One approach to synchronizing the backup virtual computing session <b>240</b> with the virtual computing session <b>230</b> is to do so after failure of the virtual computing session <b>230.</b> In other words, the broker service <b>250</b> updates a state of the backup virtual computing session <b>240</b> for a first time after failure of the virtual computing session <b>230.</b>
An advantage of this approach is to reduce the number of host computing devices <b>238</b> that are reserved or set aside for backup virtual computing sessions <b>240.</b> For example, there may be tens of thousands of host computing devices <b>228</b> providing virtual computing sessions <b>230</b> in the data center <b>226,</b> but only a small percentage may fail at any one time. Consequently, the number of host computing devices <b>238</b> needed for providing the backup virtual computing sessions <b>240</b> in the data center <b>238</b> is much lower. For example, 10 to 20 host computing devices <b>238</b> in the data center <b>236</b> may be set aside for providing backup virtual computing sessions <b>240.</b> The broker server <b>250</b> still periodically stores state updates <b>254</b> of each virtual computing sessions <b>230</b> in a database <b>252.</b>
Another approach to synchronizing the backup virtual computing session <b>240</b> with the virtual computing session <b>230</b> is to do a mapping (e.g., a one-to-one mapping) with the virtual computing session <b>230</b> while the virtual computing session <b>230</b> is available to the client device <b>210.</b> This requires the number of host computing devices <b>238</b> providing the backup virtual computing sessions <b>240</b> to equal the number of host computing devices <b>228</b> providing the virtual computing sessions <b>240.</b> For example, tens of thousands of host computing devices <b>238</b> in the data center <b>236</b> would be set aside for providing backup virtual computing sessions <b>240.</b> Each time the broker service <b>250</b> receives a state update <b>254</b> of a virtual computing session <b>230,</b> that state update <b>254</b> is provided to the corresponding backup virtual computing session <b>240.</b>
As noted above, the host computing device <b>228</b> may be taken offline for maintenance without any warning resulting in the client device <b>210</b> momentarily losing the virtual computing session <b>230</b> until redirected to the backup virtual computing session <b>240.</b> However, in other embodiments, warning may be provided from the virtual delivery appliance <b>220A</b> to the broker service <b>250.</b> This allows the broker service <b>250</b> to go ahead and redirect the client device <b>210</b> from the virtual computing session <b>230</b> to the backup virtual computing session <b>240</b> without having the virtual delivery appliance <b>220A</b> reporting a failed operating status. Alternatively, the virtual delivery appliance <b>220A</b> may delay shutdown of the virtual machine <b>222A</b> providing the virtual computing session <b>230</b> to allow time for the client device <b>210</b> to be redirected to the backup virtual computing session <b>240</b> without having the virtual delivery appliance <b>220A</b> reporting a failed operating status.
Referring now to <figref idref="f0008">FIG. 8</figref>, a flowchart <b>300</b> illustrating a method for operating the computer system <b>200</b> will be discussed. From the start (Block <b>302</b>), the method includes connecting a client device <b>210</b> to a virtual computing session <b>230</b> at Block <b>304.</b> The broker service <b>250</b> monitors a status of the virtual computing session <b>230</b> at Block <b>306,</b> as previously described above. The broker service <b>250</b> determines at Block <b>308</b> if there is a failure of the virtual computing session <b>230,</b> as also previously described above. If the client device <b>210</b> is still accessing the virtual computing session <b>230,</b> then the virtual delivery appliance <b>220A</b> provides periodic state updates on the virtual computing session <b>230</b> at Block <b>310.</b> If the client device <b>210</b> is no longer able to access the virtual computing session <b>230,</b> then the broker service <b>250</b> redirects the client device <b>210</b> to a backup virtual computing session <b>240</b> based on a failure of the virtual computing session at Block <b>312,</b> and updates a state of the backup virtual computing session <b>240</b> to match a previous state of the virtual computing session <b>230</b> prior to failure at Block <b>314.</b> The method ends at Block <b>316.</b>
Referring now to <figref idref="f0009">FIG. 9</figref>, a flowchart <b>350</b> illustrating a method for operating the broker service <b>250</b> within the computer system <b>200</b> will be discussed. From the start (Block <b>352</b>), the method includes directing or assigning a client device <b>210</b> to a virtual delivery appliance <b>220A</b> at Block <b>354.</b> The broker service <b>250</b> receives a status of the virtual computing session <b>230</b> at Block <b>356.</b> The broker service <b>250</b> monitors a status of the virtual computing session <b>230</b> at Block <b>358</b> to determine if there is a failure of the virtual computing session <b>230,</b> as previously described above. If the client device <b>210</b> is still accessing the virtual computing session <b>230,</b> then the virtual delivery appliance <b>220A</b> provides periodic state updates on the virtual computing session <b>230</b> at Block <b>360.</b> If the client device <b>210</b> is no longer able to access the virtual computing session <b>230,</b> then the broker service <b>250</b> redirects the client device <b>210</b> to a backup virtual computing session <b>240</b> based on a failure of the virtual computing session at Block <b>362,</b> and updates a state of the backup virtual computing session <b>240</b> to match a previous state of the virtual computing session <b>230</b> prior to failure at Block <b>364.</b> The method ends at Block <b>366.</b>
Many modifications and other embodiments will come to the mind of one skilled in the art having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is understood that the foregoing is not to be limited to the example embodiments, and that modifications and other embodiments are intended to be included within the scope of the appended claims.
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN116010139A | Cited by | China | Search report |
| US10133619B1 | Cites | United States of America | Examiner |
| US2014149695A1 | Cites | United States of America | Search report |
| US2015019704A1 | Cites | United States of America | Search report |
| US2016055045A1 | Cites | United States of America | Examiner |
| US2016328260A1 | Cites | United States of America | Examiner |
| US2017083354A1 | Cites | United States of America | Search report |
| US2018060572A1 | Cites | United States of America | Examiner |
| US2018095845A1 | Cites | United States of America | Search report |
| US2018373554A1 | Cites | United States of America | Examiner |
| US2019317780A1 | Cites | United States of America | Examiner |
| US2019317781A1 | Cites | United States of America | Examiner |
| US9047238B2 | Cites | United States of America | Examiner |
3 members in 2 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 201916532733 | United States of America | A | |
| 201916532733 | United States of America | A | |
| 201916532733 | United States of America | – | |
| 201916532733 | – | – | – |
| US201916532733 | – | – | – |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| EP3772686A1This record | European Patent Office (EPO) | A1 | |
| US2021042197A1 | United States of America | A1 | |
| US11449393B2 | United States of America | B2 |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | |
| Request for examination filed17P | 17P | |
| Designated contracting states (corrected)RBV | RBV | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN PUBLISHEDSTAA | STAA |
Numbers
- Publication
- 3772686
- Publication, DOCDB
- 3772686
- Publication, EPODOC
- EP3772686
- Application
- 201806163
- Application, DOCDB
- 20180616
- Application, EPODOC
- EP20200180616
Titles3
- German
- AUTOMATISCHE WIEDERHERSTELLUNG EINER FEHLERHAFTEN VIRTUELLEN COMPUTING-SITZUNG
- English
- AUTOMATIC RESTORE FOR A FAILED VIRTUAL COMPUTING SESSION
- French
- RESTAURATION AUTOMATIQUE D'UNE SESSION INFORMATIQUE VIRTUELLE DÉFAILLANTE
Classification
- CPC, 13
- G06F11/301
- G06F11/1464
- G06F9/452
- G06F9/45558
- G06F2009/4557
- G06F2009/45575
- G06F2201/815
- G06F2201/86
- G06F11/2038
- G06F11/2097
- G06F11/1658
- G06F11/1484
- G06F2009/45595
- IPC, 4
- G06F9 451
- G06F11 07
- G06F11 14
- G06F9 455
Designated states3
- Contracting states, 1
- Türkiye
- Extension states, 1
- Montenegro
- Validation states, 1
- Tunisia