Multi tenant access to applications
Abstract
A method of distributing a software application to multiple users in a virtualized computing environment, the procedure comprising: creating an instance of a virtualized computing infrastructure that makes available, through a remote network connection, one or more desktop operating environments remote user to a plurality of users through a web-based user interface; provide access, by means of the one or more user remote desktop operating environments, to an indication of an application that is capable of accepting inputs from a single user; receive, through the one or more user remote desktop operating environments, requests to access the application from a single user; and for each request, create a single user application instance in each of the one or more user remote desktop operating environments and allow each of the plurality of users to access, substantially simultaneously, one of single user applications from which instances have been created.
Term
6 yearsto projected expiry
Projected expiry 11 September 2032, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
10 claims: 3 independent, 7 dependent
- 1ES 2 709 275 T3 REIVINDICACIONES 1. Un procedimiento de distribución de una aplicación de software a múltiples usuarios en un entorno Informático vlrtuallzado, comprendiendo el procedimiento:crear una instancia de una infraestructura informática virtualizada que hace disponible, por medio de una conexión de red remota, uno o más entornos operativos de escritorio remoto de usuario a una pluralidad de usuarios por medio de una interfaz de usuario basada en web;proporcionar acceso, por medio de los uno o más entornos operativos de escritorio remoto de usuario, a una indicación de una aplicación que es capaz de aceptar entradas procedentes de un único usuario;recibir, por medio de los uno o más entornos operativos de escritorio remoto de usuario, solicitudes para acceder a la aplicación de un único usuario;y para cada solicitud, crear una instancia de la aplicación de un único usuario en cada uno de los uno o más entornos operativos de escritorio remoto de usuario y permitir que cada uno de la pluralidad de usuarios acceda, de manera sustancialmente simultánea, a una de las aplicaciones de un único usuario de las que se han creado instancias.
- 2El procedimiento de la reivindicación 1, que comprende adicionalmente mantener datos de estado para las aplicaciones de un único usuario de las que se han creado instancias de tal modo que las aplicaciones de un único usuario de las que se han creado instancias se pueden reanudar en una sesión posterior.
- 3El procedimiento de la reivindicación 1, que comprende adicionalmente presentar y mantener datos de estado para múltiples instancias de la aplicación de un único usuario para múltiples usuarios.
- 4El procedimiento de la reivindicación 1, en el que se crean instancias en máquinas virtuales de las aplicaciones de un único usuario de las que se han creado instancias.
- 5El procedimiento de la reivindicación 1, en el que dicha creación de instancias comprende crear una instancia de porciones de una única copia de la aplicación de un único usuario.
- 6El procedimiento de la reivindicación 1, en el que dicho mantenimiento es llevado a cabo por un gestor de aplicaciones multi-inquilino configurado para gestionar el acceso a las aplicaciones de un único usuario de las que se han creado instancias.
- 7El procedimiento de la reivindicación 5, en el que dicho mantenimiento es llevado a cabo por un gestor de aplicaciones multi-inquilino configurado para gestionar el acceso a las porciones de las que se han creado instancias de la copia única.
- 8Un sistema informático que comprende:un dispositivo informático que comprende al menos un procesador;una memoria acoplada de forma comunicativa con dicho procesador cuando dicho sistema se encuentra operativo;teniendo almacenada dicha memoria en la misma instrucciones de ordenador que, tras su ejecución por el al menos un procesador, dan lugar a: crear una instancia de una infraestructura informática virtualizada que hace disponible, por medio de una conexión de red remota, uno o más entornos operativos de escritorio remoto de usuario a una pluralidad de usuarios por medio de una interfaz de usuario basada en web;proporcionar acceso, por medio de los uno o más entornos operativos de escritorio remoto de usuario, a una indicación de una aplicación que es capaz de aceptar entradas procedentes de un único usuario;recibir, por medio de los uno o más entornos operativos de escritorio remoto de usuario, solicitudes para acceder a la aplicación de un único usuario;para cada solicitud, crear una instancia de la aplicación de un único usuario en cada uno de los uno o más entornos operativos de escritorio remoto de usuario y permitir que cada uno de la pluralidad de usuarios acceda, de manera sustancialmente simultánea, a una de las aplicaciones de un único usuario de las que se han creado instancias;y mantener datos de estado para las aplicaciones de un único usuario de las que se han creado instancias de tal modo que las aplicaciones de un único usuario de las que se han creado instancias se pueden reanudar en una sesión posterior.
- 9El sistema informático de la reivindicación 8, que comprende adicionalmente presentar y mantener datos de estado para múltiples instancias de la aplicación de un único usuario para múltiples usuarios.
- 10Un medio de almacenamiento legible por ordenador que almacena en el mismo instrucciones ejecutables por ordenador para distribuir una aplicación de software a múltiples usuarios en un entorno informático virtualizado, comprendiendo el medio de almacenamiento legible por ordenador, comprendiendo el procedimiento:instrucciones para crear una instancia de una infraestructura informática virtualizada que hace disponible, por ES 2 709 275 T3 medio de una conexión de red remota, uno o más entornos operativos de escritorio remoto de usuario a una pluralidad de usuarios por medio de una interfaz de usuario basada en web;instrucciones para proporcionar acceso, por medio de los uno o más entornos operativos de escritorio remoto de usuario, a una indicación de una aplicación que es capaz de aceptar entradas procedentes de un único usuario;instrucciones para recibir, por medio de los uno o más entornos operativos de escritorio remoto de usuario, solicitudes para acceder a la aplicación de un único usuario;para cada solicitud, crear una instancia de la aplicación de un único usuario en cada uno de los uno o más entornos operativos de escritorio remoto de usuario y permitir que cada uno de la pluralidad de usuarios acceda, de manera sustancialmente simultánea, a una de las aplicaciones de un único usuario de las que se han creado instancias;y mantener datos de estado para las aplicaciones de un único usuario de las que se han creado instancias de tal modo que las aplicaciones de un único usuario de las que se han creado instancias se pueden reanudar en una sesión posterior.
Independent claims10
117 paragraphs in 6 sections, as filed
ES 2 709 275 T3
DESCRIPTION
Multi-tenant access to applications
Background
In general, an increasingly popular form of networking can be referred to as remote presentation systems, which can use protocols such as Remote Desktop Protocol (RDP) and Independent Computing Architecture (ICA). Architecture) to share a desktop and other applications that are running on a server with a remote client. Cloud computing refers to a computing environment to enable on-demand network access to a shared pool of computing resources. Many cloud computing services involve virtualized resources such as those described above and can take the form of web-based applications or tools that users can access and use through a web browser such as if they were programs that are installed locally on their own computers. US 2007/0260702 A1 discloses a web browser architecture for virtual machine access.
Many applications are designed for use by a single user. For example, the AutoCAD program was designed as a single-tenant application and was intended for use by a single user and not by multiple users simultaneously. In contrast, a web-based multi-tenant application such as Bing aims for millions of users to access it simultaneously.
Summary
In a cloud computing system, it is often desirable to provide access to software applications that were not designed to run in such an environment. Procedures and systems are disclosed for presenting a software application to a plurality of users in a cloud computing environment. For example, an application that was designed for use by a single user is provided on a cloud-based platform without re-architecture of the application. Using a web-based interface, multiple cloud users can launch and run the application. The various instances of the application are presented to users in the cloud as if the application were designed as a multi-user application.
Brief description of the drawings
Computer-readable systems, procedures, and media for distributing a software application to multiple users in a virtualized computing environment in accordance with the present specification are further described with reference to the accompanying drawings, in which:
Figure 1 illustrates an exemplary computing environment in which some aspects of the present disclosure can be practiced.
Figure 2 illustrates an exemplary computing environment in which some aspects of the present disclosure can be practiced.
Figure 3 illustrates an exemplary computing environment that includes data centers.
Figure 4 illustrates a data center operating environment.
Figure 5 illustrates an operating environment for practicing some aspects of the present disclosure.
Figure 6 illustrates an exemplary architecture for implementing some of the procedures disclosed herein.
Figure 7 illustrates an exemplary block diagram illustrating some of the procedures disclosed herein.
Figure 8 illustrates an exemplary block diagram illustrating the compute component of a cloud data service.
Figure 9 illustrates an exemplary block diagram illustrating the storage component of a cloud data service.
Figure 10 illustrates an exemplary block diagram illustrating the fabric control component of a cloud data service.
Figure 11 illustrates an exemplary block diagram illustrating the CDN component of a cloud data service.
Figure 12 illustrates an exemplary block diagram illustrating the connection component of a cloud data service.
Figure 13 illustrates an exemplary embodiment of the procedures disclosed herein.
Figure 14 illustrates an exemplary embodiment of the methods disclosed herein.
Figure 15 illustrates an example of an operating procedure to practice some aspects of the present disclosure.
Figure 16 illustrates an exemplary system for practicing some aspects of the present disclosure.
ES 2 709 275 T3
Figure 17 illustrates an exemplary embodiment of a user data montage scenario. Figure 18 illustrates an exemplary embodiment of the procedures disclosed herein.
Detailed description
Certain specific details are set forth in the following description and in the figures to provide a thorough understanding of various embodiments of the disclosure. Certain well-known details that are often associated with computer and software technology are not set forth in the following disclosure to avoid making the various embodiments of the disclosure unnecessarily confusing. Furthermore, those skilled in the relevant art will understand that they themselves can implement other embodiments of the disclosure without one or more of the details described hereinafter. Finally, although various procedures are described with reference to steps and sequences in the following disclosure, the description is, in that sense, to provide a clear implementation of some embodiments of the disclosure, and should not be construed that steps and sequences of steps are required to practice the present disclosure.
It should be understood that the various techniques described herein can be implemented in connection with hardware or software or, where appropriate, with a combination of both. Therefore, the procedures and apparatus of the disclosure, or certain aspects or portions thereof, may take the form of program code (i.e. instructions) that is embodied on tangible media, such as floppy disks, CD-ROMs. , hard drives, or any other machine-readable storage medium in which, when program code is loaded into and executed by means of a machine, such as a computer, the machine becomes an apparatus for practicing the disclosure. In the case of the execution of a program code in programmable computers, in general the computing device includes a processor, a storage medium that is readable by the processor (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device. One or more programs that may implement or use the processes described in connection with the disclosure, for example, through the use of an application programming interface (API), reusable controls, or the like. Preferably, such programs are implemented in an object-oriented, high-level, procedural programming language to communicate with a computer system. However, the program or programs can be implemented in assembly or machine language, if desired. In either case, the language can be a compiled or interpreted language, and combined with hardware implementations.
A remote desktop system is a computer system that maintains applications that can be run remotely through client computer systems. An entry is entered into a client computer system and transferred over a network (for example, using protocols based on the International Telecommunication Union (ITU) T.120 family of protocols such as Remote Desktop Protocol (RDP) , See Desktop Protocol)) to an application on a terminal server. The application processes the input as if the input was entered at the terminal server. The application generates an output in response to the input received and the output is transferred to the client over the network.
Some embodiments can be run on one or more computers. Figure 1 and the following discussion are intended to provide a brief overview of a suitable computing environment in which disclosure can be implemented. One skilled in the art can appreciate that computer systems 200, 300 may have some or all of the components that are described with respect to computer 100 of FIG. 1.
The term circuitry used throughout the disclosure may include hardware components such as hardware interrupt controllers, hard drives, network adapters, graphics processors, hardware-based video / audio codecs, and the firmware / software that is used to operate such hardware. The term circuitry can also include microprocessors that are configured to carry out a function or functions by means of firmware or by means of switches that are established in a certain way or one or more logical processors, for example, one or more cores. of a general multi-core processing unit. The logic processor or processors in the present example can be configured by means of software instructions that embody an operational logic to carry out a function or functions that are loaded from memory, for example, RAM, ROM, firmware and / or or virtual memory. In some exemplary embodiments where circuitry includes a combination of hardware and software, an implementer can write source code that embodies logic that is subsequently compiled to give machine-readable code that can be executed by means of a logic processor. Because one skilled in the art can appreciate that the state of the art has evolved to a point where there is little difference between hardware, software, or a combination of hardware / software, the selection of hardware versus software to implement practical functions is merely a design option. Therefore, because a person skilled in the art can appreciate that a software process can be transformed into an equivalent hardware structure, and a hardware structure can transform itself into an equivalent software process, selection of a hardware implementation versus a software implementation is trivial and is left to an implementer.
ES 2 709 275 T3
Figure 1 illustrates an example of a computer system that is configured with some aspects of the disclosure. The computer system may include a computer 20 or the like, including a processing unit 21, a system memory 22, and a system bus 23 that couples various system components, including system memory, with processing unit 21. System bus 23 can be any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, and a local bus that makes use of any of a variety of bus architectures. System memory includes read only memory (ROM) 24 and random access memory (RAM) 25. A basic input / output system 26 (BIOS), which contains the basic routines that help transfer information between elements within computer 20, such as during boot, is stored in ROM 24. Computer 20 may further include a hard disk drive 27 for reading from and writing to a hard disk, not shown, a magnetic disk drive 28 for reading from or writing to a removable magnetic disk 29, and a optical disc drive 30 for reading from or writing to a removable optical disc 31 such as a CD ROM or other optical media. In some exemplary embodiments, computer-executable instructions embodying some aspects of the disclosure may be stored in ROM 24, a hard disk (not shown), a RAM 25, a removable magnetic disk 29, an optical disk 31 and / or a cache memory of the processing unit 21. The hard disk drive 27, the magnetic disk drive 28, and the optical disk drive 30 are connected to the system bus 23 by means of a hard disk drive interface 32, a magnetic disk drive interface 33, and a optical disc drive interface 34, respectively. The drives and their associated computer-readable media provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computer 20. Although the environment described herein employs a hard disk, a removable magnetic disk 29, and a removable optical disk 31, those skilled in the art should appreciate that other types may also be used in the operating environment. computer-readable media that can store data that can be accessed by a computer, such as magnetic cassettes, flash memory cards, digital video discs, Bernoulli cartridges, Random Access Memory (RAM), Read Only Memory (ROM) and the like.
A number of program modules can be stored on the hard disk, magnetic disk 29, optical disk 31, ROM 24 or RAM 25, including an operating system 35, one or more application programs 36, other program modules 37 and program data 38. A user can enter commands and information into computer 20 through input devices such as keyboard 40 and pointing device 42. Other input devices (not shown) may include a microphone, joystick, game controller, satellite dish, scanner, or the like. These and other input devices are often connected to the processing unit 21 through a serial port interface 46 that couples to the system bus, but can be connected through other interfaces, such as a parallel port, a game port or a universal serial bus (USB, universal serial bus). A rendering system 47 or other type of rendering device can also be connected to the system bus 23 via an interface, such as a video adapter 48. In addition to the rendering system 47, computers generally include other devices. peripheral output devices (not shown), such as speakers and printers. The system of Figure 1 also includes a host adapter 55, a Small Computer System Interface (SCSI) bus 56, and an external storage device 62 that is connected to the SCSI bus 56.
Computer 20 can operate in a networked environment using logical connections with one or more remote computers, such as remote computer 49. The remote computer 49 can be another computer, a server, a router, a network PC, a peer or other common network node, a virtual machine, and generally can include many or all of the elements. which have been described above in connection with the computer 20, although only one memory storage device 50 is illustrated in FIG. 1. The logical connections illustrated in Figure 1 may include a local area network (LAN) 51 and a wide area network (WAN) 52. Such networking environments are common in offices. , computer networks at the enterprise level, intranets and the Internet.
When used in a LAN-type networking environment, the computer 20 can be connected to the LAN 51 through a network adapter or interface 53. When used in a WAN-type networking environment, for computer 20 may generally include a modem 54 or other means for establishing communications over wide area network 52, such as the Internet. The modem 54, which can be internal or external, can be connected to the system bus 23 via the serial port interface 46. In a networked environment, the program modules illustrated in relation to the computer 20 , or portions thereof, may be stored on the remote memory storage device. It will be appreciated that the network connections shown are exemplary and that other means of establishing a communication link between the computers may be used. Furthermore, although numerous embodiments of the disclosure are envisioned to be particularly well suited for computer systems, nothing herein is intended to limit the disclosure to such embodiments.
Referring now to Figure 2, a high-level block diagram of a computer system that is configured to implement virtual machines is illustrated. As shown in the figures, the computer system 100 may include some elements that are described in figures 1 and 2 and components
ES 2 709 275 T3 operational to implement virtual machines. One such component is a hlpervlsor 202 which may also be referred to in the art as a virtual machine monitor. The hypervisor 202 in the illustrated embodiment can be configured to control and arbitrate access to the hardware of the computer system 100. Broadly stated, the hypervisor 202 can generate runtime environments that are called partitions such as secondary partition 1 to secondary partition N (where N is an integer greater than or equal to 1). In some embodiments, a secondary partition can be considered the basic unit of isolation that is supported by the hypervisor 202, that is, each secondary partition can be mapped to a set of hardware resources, e.g. memory, devices, cycles logic processor, etc., which is under the control of the hypervisor 202 and / or the primary partition and the hypervisor 202 can isolate access by one partition to the resources of another partition. In some embodiments, the hypervisor 202 can be a stand-alone software product, a part of an operating system, embedded within the motherboard firmware, specialized integrated circuits, or a combination thereof.
In the example above, the computer system 100 includes a primary partition 204 which can also be thought of as domain 0 in the open source community. Primary partition 204 can be configured to provide resources to guest operating systems running on secondary 1-N partitions through the use of a virtualization service. Each secondary partition can include one or more virtual processors such as virtual processors 230-232 that guest operating systems 220-222 can manage and schedule threads to run on. In general, virtual processors 230-232 are executable instructions and associated state information that provide a representation of a physical processor with a specific architecture. For example, one virtual machine may have a virtual processor that has the characteristics of an Intel x86 processor, while another virtual processor may have the characteristics of a PowerPC-type processor. The virtual processors in the present example can be mapped to the logical processors of the computer system such that the instructions implemented by the virtual processors will be backed up by the logical processors. Thus, in these exemplary embodiments, multiple virtual processors may be running simultaneously while, for example, another logical processor is executing hypervisor instructions. Generally speaking, and as illustrated by means of the figures, the combination of virtual processors and memory in a partition can be considered a virtual machine such as virtual machine 240 or 242.
In general, the guest operating systems 220-222 can include any operating system such as, for example, operating systems from Microsoft®, Apple®, the open source community, etc. Guest operating systems can include user / kernel modes of operation and can have kernels that can include schedulers, memory managers, and so on. A kernel mode can include a mode of execution in a logical processor that grants access to at least the privileged processor instructions. Each guest operating system 220-222 may have associated file systems that may have applications stored therein such as terminal servers, e-commerce servers, email servers, etc., and the operating systems themselves. guest. Guest operating systems 220-222 can schedule threads to run on virtual processors 230-232 and instances of such applications can be implemented.
Figure 3 and the following description are intended to provide a brief and general description of an exemplary computing environment in which the embodiments described herein can be implemented. In particular, Figure 3 illustrates an illustrative operating environment 300 that includes data centers 308 for providing computing resources. Data centers 308 can provide computing resources to run applications and provide data services on a continuous or on-demand basis. The computing resources that are provided by data centers 308 can include various types of resources, such as data processing resources, data storage resources, data communications resources, and the like. Each type of computing resource can be general purpose or can be found available in a number of specific configurations. For example, data processing resources may be available as virtual machine instances. Virtual machine instances can be configured to run applications, including web servers, application servers, media servers, database servers, and the like. The data storage resources can include file storage devices, block storage devices, and the like. The data center includes computing resources other than those of the virtual machine, including a number of physical computing devices that can be configured to run one or more virtual machines that can be migrated from one side of the physical resources to the other for load balancing .
The computing resources that are provided by data centers 308 can be enabled by one or more individual data centers. Data centers 308 are facilities used to house and operate computer systems and associated components. Typically, 308 data centers include redundant and backup power, communications, cooling, and security systems. Data centers 302 could also be located in geographically separate locations. An illustrative configuration for a data center 308 that implements the concepts and technologies disclosed herein for scalable delivery of a virtualized computing infrastructure will be described as follows.
ES 2 709 275 T3 successively with respect to figure 3.
Customers and other consumers of data centers 308 can access the computing resources that are provided by data centers 302 through a network 306. It should be appreciated that a local area network ("LAN", local area network), the Internet, or any other networking topology that is known in the art that connects data centers 308 with remote consumers. It should also be appreciated that combinations of such networks could also be used.
User computer 304 may be a computer that is used by a customer or other consumer of data centers 308. For example, user computer 304 may be a server computer, a personal desktop or laptop computer, a thin client, a tablet computer, a cordless phone, a personal digital assistant ("PDA"). , an electronic reader, a game console, a set-top box, or any other computing device that is capable of accessing data centers 308.
The user computer 304 can be used to configure some aspects of the computing resources that are provided by the data centers 308. In this regard, the data centers 308 can provide a web interface through which some aspects can be configured. of its operation through the use of a web browser application program that is running on the client computer system 304. Alternatively, a standalone application program running on client computer system 304 could access an application programming interface ("API") that is exposed by data centers 308 to perform configuration operations. Other mechanisms could also be used to configure the operation of data centers 308, including distributing updates to an application.
Figure 4 illustrates a computer system diagram illustrating a configuration for a data center 308, including the concepts and technologies disclosed herein for scalable delivery of a virtualized computing infrastructure. FIG. 2 includes server computers 402 for providing computing resources to run an application. The server computers 402 may be conventional server computers that are appropriately configured to provide the computing resources described above. For example, in one implementation, server computers 402 are configured to provide processes 406.
In one embodiment, the processes 406 can be virtual machine instances. A virtual machine instance can be an instance of a software implementation of a machine (that is, a computer) that runs programs in much the same way as a physical machine runs programs. In the virtual machine instances example, each of the 402 servers can be configured to run an instance manager that is capable of running the instances. The instance manager could be a hypervisor or other type of program that is configured to enable multiple processes 406 to run on a single server 402, for example.
It should be appreciated that while some of the embodiments disclosed in this document are discussed in the context of virtual machine instances, other types of instances can be used with the concepts and technologies disclosed. in the present document. For example, the technologies disclosed in this document may be used with storage resource instances, processing resources, data communications resources, and other types of resources. The embodiments disclosed herein could also be used with computer systems that do not use virtual machine instances, that is, that use a combination of physical machines and virtual machines.
In the exemplary data center shown in Figure 4, a LAN 401 is used to interconnect the server computers 402. The LAN 401 can also be connected to the WAN 306 illustrated in Figure 3. It should be appreciated that the network topology illustrated in Figures 3 and 4 has been greatly simplified and that many more networks and networking devices can be used to interconnect the various computer systems disclosed herein. . Appropriate load balancing devices or software modules could also be used to balance a load between data centers, between each of the 402 server computers in each data center, and between the 406 instances that are purchased by each customer. of data centers. These devices and network topologies and should be apparent to those skilled in the art.
In general, cloud computing refers to a computing environment to enable on-demand network access to a shared pool of computing resources (for example, applications, servers, and storage) such as those described above. . Such a computing environment can be delivered and released quickly with minimal service provider interaction or management effort. Cloud computing services generally do not require end-user knowledge of the physical location and configuration of the system that delivers the services. Services can be consumption-based and delivered over the Internet. Many cloud computing services involve virtualized resources such as those described above and can take the form of web-based applications or tools to which
ES 2 709 275 T3 that users can access and that they can use through a web browser as if they were programs that are installed locally on their own computers.
Typically, cloud computing services are built on a certain type of platform. For some applications, such as those running inside an organization's data center, this platform may include an operating system and a data warehouse service that is configured to store data. Applications running in the cloud can use a similar foundation.
Figure 5 provides additional details to the exemplary environment shown in Figure 3. An administrator at user computer 304 can configure desktop configuration 501, including identifying an operating system, applications, policies, and settings. storage. Such preferences may be changed by the administrator and the service provider may charge a fee to the administrator to provide the requested settings.
In one embodiment and, as further described in Figure 6, a cloud service may implement an architecture comprising a four-layer stack as follows:
• A 601 cloud computing platform that is configured to provide the resources to support cloud services.
• A 602 desktop management and provisioning layer for creating and managing cloud computing assets that enable application providers to deliver applications, enterprise desktop providers and desktop resellers to create and manage desktops, users connect to their desktops, etc. This layer can translate the logical view of applications and desktops to the physical assets of the cloud computing platform.
• An application provider / enterprise desktop provider / desktop reseller / user experiences layer 603 that provides differentiated end-to-end experiences for each of the four entity types described above.
• A 604 vertical layer that provides a set of experiences tailored to particular user groups and is provided by desktop resellers.
In one embodiment of a cloud computing platform, a flag can be implemented and used to define an isolation unit and can be configured to define a traditional remote desktop distribution. A remote desktop controller component can be provided that maintains client credentials and artifacts, manages payloads across the flags, and provision and resizes the flags. A remote desktop controller can also create and manage applications and desktops. While a particular endpoint provides the virtual equivalent of a user's desktop, the brand (or multiple brands) provides the virtual equivalent of a company's IT infrastructure.
The layers that have been described above can involve a number of components. Such components may include the following which are further described hereinafter.
• A compute component (for example, Figure 8) that runs applications in the cloud.
• A storage component (for example, Figure 9) that stores binary and structured data in the cloud.
• A fabric control component (for example, Figure 10) that distributes, manages, and monitors applications. The fabric controller can also handle updates to system software across the entire platform.
• A content delivery network component (for example, Figure 11) that increases the speed for global access to data in cloud storage by maintaining cached copies of that data throughout the world. world.
• A connection component (for example, Figure 12) that allows you to create IP-level connections between local computers and cloud applications.
Referring to Figure 8 illustrating a compute component 810, an application can be implemented as one or more roles 800 801 802 as described above. The cloud service can run multiple instances of each role, using load balancing to spread requests across the roles.
A portal can be provided to allow a developer to submit an application to the cloud service. The portal can be configured to receive configuration information that informs the cloud platform about how many instances of each role to run. The fabric control component can create a virtual machine (VM) for each instance and run the code for the appropriate role on that VM. Requests from application users can be made using protocols such as HTTP, HTTPS, and TCP. Requests can be load balanced across all instances of a role.
ES 2 709 275 T3
Referring to Figure 9 illustrating a storage component 910, the cloud platform can provide data storage using a number of data structures and formats. For example, a data store can be provided as an unstructured blob of 900 binary data. Metadata can be used to provide information regarding content. In order to allow applications to work with data in a more structured way, cloud storage services can provide storage as groups of entities that are associated with properties. Applications can also be provided with a means to query data such as, for example, an API that includes search parameters. Additionally, cloud storage can provide a way for web role instances to communicate asynchronously with worker role instances. For example, a user could submit a request to perform a certain computationally intensive task through a web interface that is implemented through a web role. The web role instance that receives this request can write a message to queue 902 that describes the work to be done. A worker role instance that is waiting in this queue can then read the message and perform the specified task. Results can be returned via another queue.
The cloud storage service can replicate data in order to provide fault tolerance. Additionally, data can be backed up to another data center in a different physical location for redundancy and enhanced availability reasons.
Referring to FIG. 10, a fabric control component 1000 may be a distributed application that replicates across a group of machines. The fabric control component can be configured to own all of the resources in your environment, such as computers, switches, and load balancers. The fabric control component 1000 can also monitor running applications, determine where new applications should run, and select physical servers to optimize hardware utilization. The fabric control component can also be configured to start, monitor, and terminate virtual machines.
In one embodiment and referring to FIG. 11, the cloud service can store copies of the data at sites closer to the clients 1100 using the data. For example, the first time a user accesses a particular piece of data, the content delivery network component may store a copy of that data (i.e., cache it) in a location that is geographically close. to that user. The next time the data is accessed, the contents can be delivered from the cache instead of the original, more remote.
In one embodiment and referring to Figure 11, in order to support the applications and data that are used within an organization, local environments can be connected to the cloud service. In one embodiment, this type of combination can be implemented by providing IP-level connectivity between a cloud application and machines that are running outside the cloud. An endpoint agent 1201 can be installed on each local computer 1202 that connects to a cloud application. The cloud application can also be configured to work with the 1200 cloud connection component. The agent can use protocols such as IPsec to interact with a particular role in that application. By using such an agent, the potential complexity of configuring protocols such as the IPsec 1203 protocol can be transparent to the user, while providing a much simpler connection than procedures such as those for virtual private networks. (VPN, virtual private network). Once the connection has been established, it can appear that the roles in a cloud application are on the same IP network as the local machine.
By establishing such connections, a cloud application can directly access a local database. A cloud application can also present a domain join to the local environment, allowing a single login to the cloud application by local users, and the use of existing active directory accounts and groups for control of access.
In various embodiments, a remote desktop computing experience can be provided in which a desktop provider can provide a flexible pool of desktops from which an administrator can easily provision and manage numerous user desktops, in a highly efficient way. similar to providing and managing a single user desktop. Therefore, the remote desktop user can be provided with a desktop experience that is always available, free from administrative procedures, and billed based on consumption. For application providers, such a service can enable application providers, with minimal effort, to provide traditional desktop applications to users in the form of web applications.
As businesses move to adopt remote or virtual desktops as a means of centralizing the management of secure and compliant employee desktops, it would be advantageous if IT administrators were able to provide a homogeneous desktop environment in order to control and minimize costs. Thus, a platform that can provide a plurality of remote or virtual desktops can provide homogeneous and scalable computing environments at low cost. When you architect a desktop solution hosted on a cloud platform in a similar way to that of a
ES 2 709 275 T3 homogeneous computing model, IT administrators can be provided with an environment that can significantly lower cost compared to traditional “Desktop as a Service” alternatives.
A cloud computing platform can be configured to operate with and provide benefits to multiple users and providers. For example, for an application provider that provides applications to an enterprise desktop provider or desktop reseller, a cloud computing platform can be configured to provide and sell traditional desktop applications in a scalable cloud model. . The application provider can be enabled to create an application provider account with a payment account information, upload application packages, test uploaded applications on a selected trading system, publish the application in an application market in the cloud, monitor application usage, and charge users per user.
Referring to Figure 13, an exemplary block diagram is illustrated illustrating a process for providing remote desktop services in a cloud computing framework. A user can access, through a browser, a web page that provides an entry point to remote desktop services that the user can access and that are configured according to the requirements of the user's IT departments . The user can log into the system using credentials that are provided to the user. The credentials can be a persistent ID such as a Windows Live ID or an OpenID. A user will then be redirected to an authentication server that may require the entry of a username and password over a secured connection. Once authenticated, the user can be issued a password that is saved for that user, with the password being provided to other services in such a way that no additional authorization is required. In one embodiment, the password can be saved for that user even if the desktop session ends, unless the user explicitly logs out.
A mechanism can be provided to automatically log in to a cloud-based system in which a single user authentication and authorization process allows a user to access resources in the cloud-based system in which the user has access permission, without the need to enter multiple passwords. The provision of a single login allows users to log in once and access multiple applications without the need to enter more passwords. A single login is desirable for businesses by increasing security and efficiency by reducing the number of passwords to maintain. For cloud service providers, a single sign-on provides a better user experience by allowing users greater access without additional authentication effort.
A cloud-based service may not accept token login credentials that are generated by a single login service. For example, a web ID provider or a single sign-on service can ask a user to provide sign-in credentials, and the service can generate a ticket or tokens that can be used to connect to others. services. Examples of such systems can include Windows, Linux, and iOS. It is desirable to give users in a local enterprise domain, for example, single sign-on access to applications that are running in the cloud service.
In one embodiment, when a user logs into a cloud-based desktop and provides authentication credentials, a one-time password can be generated and saved automatically. The generated one-time password can be used to automatically log into additional processes in the cloud-based system. In one embodiment, the generated one-time password can be saved until the user explicitly logs out. Therefore, even when the desktop session is terminated unexpectedly, the password can be saved.
In another embodiment, a user may have an account with a service that provides integrated online services such as Windows Live or Yahoo! Such a service can provide a set of software products and services such as email and multimedia services that can be accessed using a single user ID and password. In one embodiment, a user of such an integrated service may also be provided with an option to access cloud-based computing services as described above. Therefore, when a user has opted for cloud-based computing services as part of such an integrated service, once the user has logged into the service, the user may be presented with an option to access the cloud-based computing service and request a remote desktop session. Because the cloud-based service, for example remote desktop, may not accept credentials from such an integrated service, the cloud-based service may generate an account with a one-time password that Allows the user to access the desktop session. One-time password details do not need to be provided to the user as the password only exists for the duration of the session or until the user logs out. In one embodiment, the one-time password can be saved such that the user can return to the desktop if the desktop is accidentally disconnected without having to re-initiate the login process.
In one embodiment illustrated in Figure 14, the client 1404 may enter a URL for the home page.
ES 2 709 275 T3 start 1400 of your company's cloud-based service. Alternatively, the user can enter a URL for an integrated online service. The user can be directed to an online authentication service 1401 that requests the user to indicate authentication credentials. The 1401 online authentication service can be a service that is used by the administrator for the user and the user's credential information can be provided by the administrator to the cloud service, authorizing the service to create a user profile and allowing that the user launches and accesses desktops. Alternatively, the online authentication service 1401 may be provided by the integrated online service. Once the user has been authenticated, the user is directed to a home page 1402, the user can access the cloud service 1410 with the credentials that are provided by the online authentication service. Cloud service 1410 generates a one-time password 1405 and / or a temporary user account, and the user's one-time password is sent 140 to endpoint 1407. As described above, connection point 1407 can be a user desktop session.
The one-time password can be generated based on the credentials that are received by the online authentication service. In one embodiment, the password can be stored in a local credential store on the virtual machine hosting the user session. Therefore, the password is not saved with the user in the user's profile, thus providing enhanced security and avoiding the need for the cloud service to maintain permanent passwords for each user.
The user may be presented with a number of desktops, for example an engineering desk, a finance desk, etc., which can be selected and logged into. For example, each desktop can be tailored to a specific functionality. The user can be presented with specific desktops based on a previously defined authorization. After users have selected a desktop, a new desktop instance can be created for that user. If a previous desktop instance is selected, the session that is associated with the previous desktop instance can be resumed. The session for this user and the session for other users can be launched as endpoints within a virtual machine that hosts a number of such sessions. A saved profile can be associated with each endpoint that is created or resumed, which includes user preferences and status information from a previous session and other information that is necessary to maintain user status accordingly. that the user's session can be saved, paused and resumed. In general, a desktop can consist of an operating system, applications, and settings. In general, a desktop instance refers to a desktop plus a specific user profile. In some cases, desktop instance and desktop session can be used interchangeably.
In one embodiment, multiple sessions can be launched for additional users. Referring to the exemplary embodiment illustrated in Figure 14, multiple sessions that correspond to multiple connection points can be instantiated as additional users log into the system. Additionally, users can comprise multiple user types as defined by the administrator for the user group. For example, as shown in the figure, multiple users of both Type 1 and Type 2 can log into the system and begin sessions. For example, Type 1 can be a financial type desk and Type 2 can be an engineering type desk. Obviously, other examples are also possible. A virtual machine can be configured to host a number of sessions of one or more types. In one embodiment, the session numbers may be independent of the underlying virtual machine configuration that is hosting the various user sessions. As additional user session instances are created in the virtual machine, additional virtual machines can be launched. In one embodiment, a set number of remote desktop sessions can be configured to run on a virtual machine. As more remote desktop sessions are needed, another virtual machine can be launched. A flexible pool of virtual machines can be provided such that sessions can be added dynamically at any time without the need for an end user or administrator to understand the underlying details for the frameworks that provide the services.
Because the user can be assigned a virtual machine (VM) endpoint from a pool of available VM endpoints, the next time a user logs in, the user can connect to one any of the VM endpoints in the group. In order to create a personalized desktop experience for the user, user preferences and status data can be saved. In one embodiment, user preferences and status data can be saved in a data set that can be associated with the user such that anytime the user logs in and is assigned a desktop , user preferences and status data can be obtained such that the user's previous desktop status can be resumed. So, for example, if the user is associated with a session (that is, an endpoint) on a first virtual machine and is later assigned to a different session on a different virtual machine, in general, the state of The user's desktop from the first virtual machine would not be available for the session on the second virtual machine. However, according to one aspect of the disclosure, the user's state is saved regardless of the session and the particular VM endpoint. As described in the present disclosure, such a set of user data can be referred to as a virtual profile. In various embodiments, the virtual profile can be implemented and referred to as a virtual hard disk drive or virtual hard disk (VHD, virtual hard drive, or virtual hard disk). In this sense, when the user connects to a session in a different virtual machine, the previous state of the user can be migrated to the new session. This feature
ES 2 709 275 T3 allows a single master desk that is designed to serve a particular Type to have a personalized feel for each particular user. The result is that a user of an otherwise generic session environment is perceived by the user as having the look and feel of a personal desktop.
As discussed above, during the course of a user session, a client can open and close remote access connections to the cloud service, and during any given connection, the client can change settings and preferences. in the session. This document describes a mechanism to provide remote desktops in a cloud-based infrastructure while maintaining user personalization. In cloud-based systems, a user may not always reconnect to the same virtual desktop. In one embodiment, the virtual profile that is assigned to a user can be mounted at the connection point that is assigned to the user. The virtual profile can include information such as the user's personal data and personalization information (for example, settings, profiles, files, application data, etc.).
When the user disconnects from or logs out of the remote desktop, the virtual profile is unmounted from the endpoint and saved for subsequent user sessions. Therefore, the virtual profile saves information regarding the user's state when the user disconnects and provides the information as needed to launch the next user session.
Because a user can be assigned one VM endpoint from a pool of available VM endpoints, the next time a user logs in, the user can connect to any one of the endpoints VM in the group. In order to create a personalized desktop experience for the user, the user's saved preferences and status data can be used to provide the personalized desktop experience regardless of the particular VM endpoint that the user is connected to.
Although the terms virtual profile and VHD are used to describe a data structure for storing a user's preferences and status information, it should be understood that the present disclosure is not intended to be limited to a particular file or data format. any. In one embodiment, a virtual profile or a VHD can be a virtual hard disk file format that is configured as data that is typically found on a physical data disk drive.
Initially, a virtual profile or a VHD can be populated with operational data to configure a user's desktop according to conventional desktop settings as defined, for example, by an enterprise IT administrator. Therefore, a virtual profile or a VHD can include data that defines the "blueprint" of the desktop (ie, the conventional desktop configuration for a user role). However, as a user uses a particular remote desktop and begins to customize the desktop, for example by changing the wallpaper, adding music, saving local documents, etc., that information is stored in the virtual profile or a VHD and each time thereafter a user connects to a conventional remote desktop, it is populated with data from the virtual profile or a VHD to provide the look and feel of a personalized user experience.
Any combination of user types (that is, desktop types) can be defined within the limits of a single cloud service limit. For example, cloud service limit 1410 can define a single service limit as defined and configured for a set of services that are provided to a particular company and can be accessed using a pre-determined URL which, when entered through a browser, you can provide a web interface to log into the service and access the desktops that are configured for the service.
In one embodiment, when a user session is requested, a connection to a connection broker may be requested at first. The connection broker can determine the brand that is associated with the requested user session and select a virtual machine that is hosting user sessions within the identified brand. For example, if the request indicates that a user session is desired, the connection broker can search a database that includes combinations of IP address port numbers or network identifiers to find a suitable virtual machine that is hosted on a cloud server. The connection broker can generate a redirect request that results in the user session being associated with the identified virtual machine.
Referring to the embodiment described in FIG. 17, a connection point can be notified 1700 that a user has logged into the system. The system searches for a virtual profile 1701 and determines if a virtual profile already exists for user 1702. If there is no virtual profile for the user, then a virtual profile is created 1703. If a virtual profile already exists for the user or if a virtual profile was created, then the user's virtual profile is moved 1704 to the endpoint. The user desktop session can be launched 1705. When the user is determined to be logged out 1706, then the virtual profile is unmounted 1707 from the endpoint and saved for later use.
ES 2 709 275 T3
Access to multi-tenant applications
A mechanism for presenting a software application to a plurality of users in a cloud computing environment is described below. For example, an application that was designed for use by a single user is provided on a cloud-based platform without re-architecture of the application. Using a web-based interface, multiple cloud users can launch and run the application. The various instances of the application are presented to users in the cloud as if the application were designed as a multi-user application.
In one embodiment, an application whose architecture has been created for a single user can be provided on a cloud-based platform. An application provider can access a website or other user interface to upload a single-user application and request that the single-user application be accessed by multiple users through the cloud-based platform. Although the application was not designed for multi-user access, this disclosure provides a mechanism by which such an application can be made accessible by an unlimited number of users without the need for the provider. re-architecture the application.
In a cloud computing environment, running an application whose architecture is built for a single user can result in a circumstance where hardware / processing power is readily available but where the software architecture is such that the application is not amenable to presentation to multiple users or multiple user sessions. For example, in the case of a single user, a single-use application can be allocated resources according to the needs of the application, and the application can run on a single set of resources.
In one embodiment, one or more portions of a single-use application can be analyzed and multiple instances of the one or more portions of the software can be created on one or more endpoints that are running on one or more machines. virtual. Each of the one or more pieces of software can then be associated with one or more user sessions and lend itself to presentation to each of the user sessions. Each of the one or more user sessions may be in communication with the corresponding instance of the one or more portions of the software and may send and receive data that is indicative of instructions that are associated with the application processes. Therefore, the one or more pieces of software that are associated with the one or more user sessions can send data to and receive data from a user via the user session. A request that is received by an instance of the one or more pieces of software can be executed on the one or more virtual machines.
In another embodiment, a single instance of an application whose architecture has been created for a single user can run in a virtual machine. A multi-tenant application manager can be in communication with a plurality of user sessions, and for each user session, the multi-tenant application manager can maintain a state of the user session interaction with the application. The application can receive and process requests from user sessions. A snapshot of the user representation can be processed for each user session.
In one embodiment, the multi-tenant application manager can add and / or remove resources from a pool of resources available to the application. Additionally, the multi-tenant application manager can queue requests for each user session. In another embodiment, multiple instances of the application can be created, each instance being associated with a user session. Each instance of the application can then maintain its own states for its respective user sessions.
In one embodiment, an application provider can access the cloud data service and, using a web or other user interface, can upload a single-user application that the provider wishes to provide to multiple users. The provider can select options such as a URL (for example, www.miunicaaplic.com) and a structure of charges that users should pay in order to use a single-use application. Typically, such a single-use application would be a complex application that was originally designed for single users and where it would be costly to re-architecture the application to offer it as a multi-user application in a unique way. use function. Often times, a user may be willing to pay a fixed charge for a single use of such an application rather than the high cost of purchasing a complex application that may be used infrequently. The application provider can upload the software to the cloud and select a charge based on usage, or a daily, monthly or weekly access, for example. Users can pay by credit card, be billed, etc.
The cloud service provider can host a website that you can access via the URL that is selected by the application provider. The user may be provided with a web page that provides information about a single-use application. The user may be provided with options to select a charge payment option. Referring to FIG. 18, the user may be directed to a payment and authentication service 1401 that prompts the user to enter payment information. Once the user is authenticated, the user is directed to a welcome home page 1402. The cloud service 1410 generates a one-time password 1405 and / or a temporary user account, and a password for a one-time user. alone
Instead of the user, 140 is sent to a connection point 1407. As described above, the connection point 1407 may be a user's desktop session. The user desktop session then begins an instance of a one-time application 1807 and in accordance with one of the embodiments described above. The user is presented, via the user screen, with a graphical representation of a single-use application that appears to the user to be an instance of a single-use application.
In another embodiment, from a user session perspective, after logging into the cloud computing system via a web page, the user may be presented with a desktop that may additionally include an option to select one. single use application. The user can select a single-use application and can be presented, via the user's web browser, an interface that represents the look and feel of the actual user interface for a single-use application as if an application A single use will run locally on a local set of computing resources. Multiple users can access a single-use application in parallel user sessions, with each session appearing to independently access and run a single-use application.
As described above, user preferences and status data can be saved in a data structure that can be associated with the user such that anytime the user logs in and is logged on. assign a desktop to it, user preferences and status data can be obtained, and the user's previous desktop status can be resumed. In accordance with one aspect of the invention, the user's state with respect to a one-time application is saved regardless of the particular session and the particular virtual machine host. Such a set of user data can be referred to as VHD, as discussed above. Therefore, when the user revisits the website in order to access a single-use application or relaunches a single-use application through a remote desktop session, the previous user data and saved data files and any preferences for a single-use application can be migrated to the new session.
Figure 15 illustrates an exemplary operating procedure for distributing a software application to multiple users in a virtualized computing environment that includes operations 1500, 1502, 1504, 1506, and 1508. Referring to FIG. 15, step 1500 begins the operating procedure and step 1502 illustrates creating an instance of a virtualized computing infrastructure that facilitates, via a remote network connection, one or more remote desktop operating environments from user to user. a plurality of users via a web-based user interface. The user's remote desktop configuration can include saved state information for an operating environment and software applications that are running in the operating environment. Each of the remote desktop configurations can correspond to a user role. For example, an administrator can use a user interface to define two desktop environments for a medium-sized company. The administrator can define a first desktop environment for the engineering staff and can select an operating system and version, an email and calendar application, a browser application, an office application, and a drawing application. The administrator can further specify that up to fifty such desktops can be used at the same time. The administrator can also define a second desktop environment for the finance staff and can select an operating system and version, an email and calendar application, a browser application, an office application, and a database application. The administrator can further specify that up to twenty-five desktops of this type can be used at the same time. Remote desktop settings can be accessed over the Internet using a URL. For example, after setting up desktop environments, individual users can access desktop environments by entering, for example, www.company.com/tecnywww.ecompany.com/finances.
Step 1504 illustrates providing access, via the one or more user's remote desktop operating environments, to an indication of an application that is capable of accepting input from a single user.
Step 1506 illustrates receiving, via the one or more user's remote desktop operating environments, requests to access a single user's application.
Operation 1508 illustrates, for each request, creating a single user application instance in each of the one or more user's remote desktop operating environments and allowing each of the plurality of users to access, substantially simultaneously , to one of the instantiated single-user applications.
Operation 1510 illustrates maintaining state data for instantiated single-user applications such that instantiated single-user applications can be resumed in a later session.
Figure 16 illustrates an exemplary system for distributing a software application to multiple users in a virtualized computing environment as described above. Referring to Figure 16, system 1600 comprises a processor 1610 and memory 1620. Memory 1620 further comprises computer instructions for distributing a software application to multiple users in an environment.
ES 2 709 275 T3 virtualized computing. Block 1622 illustrates creating an Instance of a Virtualized Computing Infrastructure that facilitates, by means of a remote network connection, one or more user remote desktop operating environments to a plurality of users by means of a web-based user interface. . Block 1624 illustrates providing access, via the one or more user's remote desktop operating environments, to an indication of an application that is capable of accepting input from a single user. Block 1626 illustrates receiving, via the one or more user's remote desktop operating environments, requests to access a single user's application. Block 1628 illustrates, for each request, creating a single user application instance in each of the one or more user's remote desktop operating environments and allowing each of the plurality of users to access, substantially simultaneously , to one of the instantiated single-user applications. Block 1630 illustrates maintaining state data for instantiated single-user applications such that instantiated single-user applications can be resumed in a later session.
Any of the aforementioned aspects can be implemented in procedures, systems, computer-readable media, or any type of fabrication. For example, a computer-readable medium may store computer-executable instructions thereon for distributing a software application to multiple users in a virtualized computing environment. Such means may comprise a first subset of instructions for creating an instance of a virtualized computing infrastructure that facilitates, by means of a remote network connection, one or more user remote desktop operating environments to a plurality of users via an interface. web-based user; a second subset of instructions for providing access, via the one or more user's remote desktop operating environments, to an indication of an application that is capable of accepting input from a single user; a third set of instructions for receiving, via the one or more user's remote desktop operating environments, requests to access a single user's application; a fourth set of instructions to create an instance, for each request, of the application of a single user in each of the one or more user's remote desktop operating environments and allow each of the plurality of users to access, in a manner substantially concurrent, to one of the instantiated single-user applications; and a fifth set of instructions for maintaining state data for the instantiated single-user applications such that the instantiated single-user applications can be resumed in a later session. Those skilled in the art will appreciate that additional sets of instructions can be used to capture the various other aspects disclosed herein, and that the five subsets of instructions disclosed herein may vary in detail depending on the present disclosure.
Contents6
12 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 201113232863 | United States of America | A | |
| 201113232863 | United States of America | – | |
| 2012054539 | United States of America | W |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| CN102932405A | China | A | |
| US2013066945A1 | United States of America | A1 | |
| WO2013039846A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2013039846A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US8589481B2 | United States of America | B2 | |
| US2014082059A1 | United States of America | A1 | |
| EP2756392A2 | European Patent Office (EPO) | A2 | |
| EP2756392A4 | European Patent Office (EPO) | A4 | |
| CN102932405B | China | B | |
| US9361080B2 | United States of America | B2 | |
| EP2756392B1 | European Patent Office (EPO) | B1 | |
| ES2709275T3This record | Spain | T3 |
Numbers
- Publication
- 2709275
- Application
- 12832167
Titles2
- Spanish
- Acceso multi-inquilino a aplicaciones
- English
- Multi-tenant access to applications
Classification
- CPC, 7
- G06F8/60
- G06F9/4843
- G06F21/41
- G06F9/452
- H04L69/329
- G06F15/16
- G06F21/00
- IPC, 8
- G06F9 44
- G06F8 60
- G06F9 445
- G06F9 451
- G06F9 455
- G06F9 48
- G06F21 41
- H04L29 08