Methods and systems for accessing remote user files associated with local resources
Claim Score by NHIP
Abstract
A system for accessing, by a resource, a setting in a virtualized user profile includes an isolation environment, a resource, and a filter driver. The resource executes outside an isolation environment on a local machine and requests access to a setting in a user profile. The filter driver intercepts the request for access and identifies one of the isolation environment and a remote machine, responsive to an application of a rule to the request. The filter driver redirects the request to the one of the isolation environment and the remote machine. A method includes intercepting an instruction from a resource to modify a setting on a local machine, the resource provided by a local machine and executing outside of an isolation environment. The method includes identifying the isolation environment, responsive to an application of a rule to the instruction. The method includes redirecting the instruction to the isolation environment.

Term
3.5 yearsto projected expiry
Projected expiry 12 March 2030, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
23 claims: 2 independent, 21 dependent
- 1A system for accessing, by a local resource, a setting in a virtualized user profile comprising:an isolation environment on a local machine;a resource provided by the local machine, executing outside the isolation environment, and requesting access to a setting in a user profile;and a filter driver: intercepting the request for access to the setting in the user profile;identifying one of the isolation environment and a remote machine, responsive to an application of a rule to the request;and redirecting the request for access to the setting in the user profile to the one of the isolation environment and the remote machine.
- 13Broadest claimClaim Score 76, broad(NHIP)A method for modifying, by a local resource, a setting in a virtualized user profile, the method comprising the steps of:(a) intercepting an instruction from a resource to modify a setting on a local machine, the resource provided by a local machine and executing outside of an isolation environment;(b) identifying the isolation environment, responsive to an application of a rule to the instruction;and (c) redirecting, to the isolation environment, the instruction to modify the setting on the local machine.
Independent claims2
159 paragraphs in 6 sections, as filed
RELATED APPLICATIONS
0001The present application claims priority to U.S. Provisional Patent Application Ser. No. 60/862,335, entitled “Systems and Methods for Providing Distributed, Virtualized Access to User Data,” filed Oct. 20, 2006, which is incorporated herein by reference.
FIELD OF THE INVENTION
0002The present disclosure relates to methods and systems for providing access to user files. In particular, the present disclosure relates to methods and systems for accessing, by local resources, virtualized user files.
BACKGROUND OF THE INVENTION
0003Administrators of modern enterprise environments may face many challenges when providing users with access to resources. One such challenge concerns providing a supportable environment on a target machine enabling execution of a resource without interfering with other resources, which may have conflicting requirements, and in environments in which the resource may not have been designed to run, while also providing users with access to user-specific files. Although some systems attempt to solve these challenges with roaming profiles, typically, these systems generate additional problems, including poor reconciliation, over-writing and corruption of files, conflicts when migrating between operating systems, prolonged log-on times, and a failure to support offline access.
0004Another concern in a typical enterprise environment involves the management of user-requested resources. Each user in the enterprise may request one or more additional, non-standard resources. Some users will install applications without informing an information technology (IT) department of the installation. This may result in the installation of applications with conflicting requirements from pre-approved and pre-installed applications, which can cause compatibility problems, create instability on the user system, and, in some cases, destabilize other users' access to approved resources.
BRIEF SUMMARY OF THE INVENTION
0005In one aspect, a system for accessing a setting in a user profile provides users with consistent data experiences across sessions, regardless of what access method users implement, with what device users interact, or from which location the users attempt to access resources. In another aspect, a system for accessing, by a local resource, a setting in a user profile includes an isolation environment, a resource, and a filter driver. The resource executes outside an isolation environment on a local machine and requests access to a setting in a user profile. The filter driver intercepts the request for access to the setting in the user profile. The filter driver identifies one of the isolation environment and a remote machine, responsive to an application of a rule to the request. The filter driver redirects the request for access to the setting in the user profile to the one of the isolation environment and the remote machine.
0006In one embodiment, the setting in the user profile includes a configuration file. In another embodiment, the setting in the user profile includes a registry key. In still another embodiment, the setting in the user profile includes a data file. In yet another embodiment, the setting in the user profile includes an executable file.
0007In still another aspect, a method for accessing, by a local resource, a setting in a virtualized user profile includes the step of intercepting a request from a resource for access to a setting in a user profile, the resource provided by a local machine and executing outside an isolation environment. The method includes the step of identifying one of the isolation environment and a remote machine, responsive to an application of a rule to the request. The method includes the step of redirecting, to the identified one of the isolation environment and the remote machine, the request for access to the setting in the user profile. In one embodiment, the method includes the step of transmitting, to the remote machine, an identification of a modification to the setting in the user profile.
0008In one embodiment, the method includes the step of intercepting a request from a resource for access to a setting in a user profile, the resource provided by a local machine and executing inside an isolation environment. In another embodiment, the method includes the step of identifying one of the isolation environment and a remote machine, responsive to an application of a rule to the request. In still another embodiment, the method includes the step of redirecting, to the identified isolation environment, the request for access to the setting in the user profile. In still even another embodiment, the method includes the step of identifying a modification to the setting in the user profile. In yet another embodiment, the method includes the step of transmitting, to the remote machine, an identification of the modification.
0009In still even another aspect, a system for modifying, by a local resource, a setting in a virtualized user profile includes an isolation environment on a local machine, a resource, and a filter driver. The resource executes on the local machine and outside the isolation environment. The filter driver intercepts an instruction from the resource to modify a setting on the local machine. The filter driver identifies the isolation environment, responsive to an application of a rule to the instruction. The filter driver redirects the request for access to the setting to the isolation environment.
0010In one embodiment, an agent, in communication with the filter driver, identifies the isolation environment. In another embodiment, the resource is an installer application selected by a user. In still another embodiment, a remote machine stores a copy of data associated with the isolation environment on the local machine. In still even another embodiment, a second remote machine stores data associated with a second isolation environment on the second remote machine, the data synchronized with the copy of the data stored on the remote machine and associated with the isolation environment on the local machine. In yet another embodiment, a second filter driver intercepts a request, by a second resource executing on the second remote machine, for access to a setting in a user profile on the second remote machine, and the second filter driver responds to the request with the synchronized data.
0011In yet another aspect, a method for modifying, by a local resource, a setting in a virtualized user profile includes the step of intercepting an instruction from a resource to modify a setting on a local machine, the resource provided by a local machine and executing outside of an isolation environment. The method includes the step of identifying the isolation environment, responsive to an application of a rule to the instruction. The request to modify the setting on the local machine is redirected to the isolation environment.
0012In one embodiment, an instruction from the resource to modify a setting in a user profile on the local machine is intercepted. In another embodiment, an instruction from the resource to install, on the local machine, at least one file associated with an application is intercepted. In still another embodiment, a copy of data associated with the isolation environment and stored on the remote machine is synchronized with a copy of the data associated with a second isolation environment stored on a second remote machine. In still even another embodiment, a request, by a second resource executing on the second remote machine, for access to a setting on the second remote machine is intercepted. In yet another embodiment, the request is responded to with the synchronized data associated with the second isolation environment on the second remote machine.
0013In one embodiment, a request, by a second resource executing on a remote machine, for access to a setting on the remote machine is intercepted. In another embodiment, the requested setting is retrieved from a copy of data stored on a second remote machine and associated with the isolation environment on the local machine, responsive to a determination that a second isolation environment on the second remote machine does not contain the file. In still another embodiment, the second resource is executed responsive to the retrieved setting.
BRIEF DESCRIPTION OF THE DRAWINGS
0014The foregoing and other objects, aspects, features, and advantages of the disclosure will become more apparent and better understood by referring to the following description taken in conjunction with the accompanying drawings, in which:
0015<figref idref="DRAWINGS">FIG. 1A</figref> is a block diagram depicting an embodiment of a network environment comprising local machines in communication with remote machines;
0016<figref idref="DRAWINGS">FIGS. 1B and 1C</figref> are block diagrams depicting embodiments of computing devices useful in connection with the methods and systems described herein;
0017<figref idref="DRAWINGS">FIG. 2A</figref> is a block diagram depicting one embodiment of a local machine requesting execution of a resource and a remote machine providing access to the resource;
0018<figref idref="DRAWINGS">FIG. 2B</figref> is a block diagram depicting one embodiment of a remote machine including a management service providing an enumeration of available resources;
0019<figref idref="DRAWINGS">FIG. 3A</figref> is a block diagram depicting one embodiment of a system for accessing, by a local resource, a setting in a user profile;
0020<figref idref="DRAWINGS">FIG. 3B</figref> is a block diagram depicting one embodiment of a system including a client agent for accessing, by a local resource, a setting in a user profile;
0021<figref idref="DRAWINGS">FIG. 3C</figref> is a block diagram depicting one embodiment of an agent in a system for accessing a setting in a user profile;
0022<figref idref="DRAWINGS">FIG. 4</figref> is a flow diagram depicting one embodiment of the steps taken in a method for accessing a setting in a virtualized user profile; and
0023<figref idref="DRAWINGS">FIG. 5</figref> is a flow diagram depicting one embodiment of the steps taken in a method for modifying, by a local resource, a setting in a virtualized user profile.
DETAILED DESCRIPTION OF THE INVENTION
0024Referring now to <figref idref="DRAWINGS">FIG. 1A</figref>, an embodiment of a network environment is depicted. In brief overview, the network environment comprises one or more local machines <b>102</b><i>a</i>-<b>102</b><i>n </i>(also generally referred to as client(s) <b>102</b>, client node(s) <b>102</b>, client computer(s) <b>102</b>, client device(s) <b>102</b>, or endpoint(s) <b>102</b>) in communication with one or more servers <b>106</b><i>a</i>-<b>106</b><i>n </i>(also generally referred to as server(s) <b>106</b>, or remote machine(s) <b>106</b>) via one or more networks <b>104</b>.
0025Although <figref idref="DRAWINGS">FIG. 1A</figref> shows a network <b>104</b> between the local machines <b>102</b> and the servers <b>106</b>, the local machines <b>102</b> and the servers <b>106</b> may be on the same network <b>104</b>. The network <b>104</b> can be a local-area network (LAN), such as a company Intranet, a metropolitan area network (MAN), or a wide area network (WAN), such as the Internet or the World Wide Web. In some embodiments, there are multiple networks <b>104</b>, <b>104</b>′ between the local machines <b>102</b> and the servers <b>106</b>. In one of these embodiments, a network <b>104</b>′ (not shown) may be a private network and a network <b>104</b> may be a public network. In another of these embodiments, a network <b>104</b> may be a private network and a network <b>104</b>′ a public network. In still another embodiment, networks <b>104</b> and <b>104</b>′ may both be private networks.
0026The network <b>104</b> may be any type and/or form of network and may include any of the following: a point to point network, a broadcast network, a wide area network, a local area network, a telecommunications network, a data communication network, a computer network, an ATM (Asynchronous Transfer Mode) network, a SONET (Synchronous Optical Network) network, a SDH (Synchronous Digital Hierarchy) network, a wireless network and a wireline network. In some embodiments, the network <b>104</b> may comprise a wireless link, such as an infrared channel or satellite band. The topology of the network <b>104</b> may be a bus, star, or ring network topology. The network <b>104</b> and network topology may be of any such network or network topology as known to those ordinarily skilled in the art capable of supporting the operations described herein. The network may comprise mobile telephone networks utilizing any protocol or protocols used to communicate among mobile devices, including AMPS, TDMA, CDMA, GSM, GPRS or UMTS. In some embodiments, different types of data may be transmitted via different protocols. In other embodiments, the same types of data may be transmitted via different protocols.
0027In one embodiment, the system may include multiple, logically-grouped servers <b>106</b>. In these embodiments, the logical group of servers may be referred to as a server farm <b>38</b>. In some of these embodiments, the servers <b>106</b> may be geographically dispersed. In some cases, a farm <b>38</b> may be administered as a single entity. In other embodiments, the server farm <b>38</b> comprises a plurality of server farms <b>38</b>. In one embodiment, the server farm executes one or more applications on behalf of one or more local machines <b>102</b>.
0028The servers <b>106</b> within each farm <b>38</b> can be heterogeneous. One or more of the servers <b>106</b> can operate according to one type of operating system platform (e.g., WINDOWS NT, manufactured by Microsoft Corp. of Redmond, Wash.), while one or more of the other servers <b>106</b> can operate on according to another type of operating system platform (e.g., Unix or Linux). In some embodiments, a server <b>106</b> executes an application on behalf of a user or a local machine <b>102</b>. In other embodiments, a server <b>106</b> executes a virtual machine, which provides an execution session within which applications execute on behalf of a user or a local machine <b>102</b>. In one of these embodiments, the execution session is a hosted desktop session. In another of these embodiments, the execution session provides access to a computing environment, which may comprise one or more of: an application, a plurality of applications, a desktop application, and a desktop session in which one or more applications may execute.
0029The servers <b>106</b> of each farm <b>38</b> do not need to be physically proximate to another server <b>106</b> in the same farm <b>38</b>. Thus, the group of servers <b>106</b> logically grouped as a farm <b>38</b> may be interconnected using a wide-area network (WAN) connection or a metropolitan-area network (MAN) connection. For example, a farm <b>38</b> may include servers <b>106</b> physically located in different continents or different regions of a continent, country, state, city, campus, or room. Data transmission speeds between servers <b>106</b> in the farm <b>38</b> can be increased if the servers <b>106</b> are connected using a local-area network (LAN) connection or some form of direct connection.
0030Server <b>106</b> may be a file server, application server, web server, proxy server, appliance, network appliance, gateway, application gateway, gateway server, virtualization server, deployment server, SSL VPN server, or firewall. In some embodiments, a server <b>106</b> provides a remote authentication dial-in user service, and is referred to as a RADIUS server. In other embodiments, a server <b>106</b> may have the capacity to function as either an application server or as a master application server. In still other embodiments, a server <b>106</b> is a blade server. In yet other embodiments, a server <b>106</b> executes a virtual machine providing, to a user or local machine <b>102</b>, access to a computing environment.
0031In one embodiment, a server <b>106</b> may include an Active Directory. The server <b>106</b> may be an application acceleration appliance. For embodiments in which the server <b>106</b> is an application acceleration appliance, the server <b>106</b> may provide functionality including firewall functionality, application firewall functionality, or load balancing functionality. In some embodiments, the server <b>106</b> comprises an appliance such as one of the line of appliances manufactured by the Citrix Application Networking Group, of San Jose, Calif., or Silver Peak Systems, Inc., of Mountain View, Calif., or of Riverbed Technology, Inc., of San Francisco, Calif., or of F5 Networks, Inc., of Seattle, Wash., or of Juniper Networks, Inc., of Sunnyvale, Calif.
0032The local machines <b>102</b> may also be referred to as client nodes, client machines, endpoint nodes, or endpoints. In some embodiments, a local machine <b>102</b> has the capacity to function as both a client seeking access to resources provided by a server and as a server providing access to hosted resources for other local machines <b>102</b><i>a</i>-<b>102</b><i>n. </i>
0033In some embodiments, a local machine <b>102</b> communicates with a server <b>106</b>. In one embodiment, the local machine <b>102</b> communicates directly with one of the servers <b>106</b> in a farm <b>38</b>. In another embodiment, the local machine <b>102</b> executes a program neighborhood application to communicate with a server <b>106</b> in a farm <b>38</b>. In still another embodiment, the server <b>106</b> provides the functionality of a master node. In some embodiments, the local machine <b>102</b> communicates with the server <b>106</b> in the farm <b>38</b> through a network <b>104</b>. Over the network <b>104</b>, the local machine <b>102</b> can, for example, request execution of various applications hosted by the servers <b>106</b><i>a</i>-<b>106</b><i>n </i>in the farm <b>38</b> and receive output data of the results of the application execution for display. In some embodiments, only the master node provides the functionality required to identify and provide address information associated with a server <b>106</b><i>b </i>hosting a requested application.
0034In one embodiment, the server <b>106</b> provides the functionality of a web server. In another embodiment, the server <b>106</b><i>a </i>receives requests from the local machine <b>102</b>, forwards the requests to a second server <b>106</b><i>b </i>and responds to the request by the local machine <b>102</b> with a response to the request from the server <b>106</b><i>b</i>. In still another embodiment, the server <b>106</b> acquires an enumeration of applications available to the local machine <b>102</b> and address information associated with a server <b>106</b> hosting an application identified by the enumeration of applications. In yet another embodiment, the server <b>106</b> presents the response to the request to the local machine <b>102</b> using a web interface. In one embodiment, the local machine <b>102</b> communicates directly with the server <b>106</b> to access the identified application. In another embodiment, the local machine <b>102</b> receives output data, such as display data, generated by an execution of the identified application on the server <b>106</b>.
0035In some embodiments, the server <b>106</b> or a server farm <b>38</b> may be running one or more applications, such as an application providing a thin-client computing or remote display presentation application. In one embodiment, the server <b>106</b> or server farm <b>38</b> executes as an application any portion of the CITRIX ACCESS SUITE by Citrix Systems, Inc., such as the METAFRAME or CITRIX PRESENTATION SERVER and/or any of the MICROSOFT WINDOWS Terminal Services manufactured by the Microsoft Corporation. In another embodiment, the application is an ICA client, developed by Citrix Systems, Inc. of Fort Lauderdale, Fla. In still another embodiment, the server <b>106</b> may run an application, which, for example, may be an application server providing email services such as MICROSOFT EXCHANGE manufactured by the Microsoft Corporation of Redmond, Wash., a web or Internet server, or a desktop sharing server, or a collaboration server. In yet another embodiment, any of the applications may comprise any type of hosted service or products, such as GOTOMEETING provided by Citrix Online Division, Inc. of Santa Barbara, Calif., WEBEX provided by WebEx, Inc. of Santa Clara, Calif., or Microsoft Office LIVE MEETING provided by Microsoft Corporation of Redmond, Wash.
0036A local machine <b>102</b> may execute, operate or otherwise provide an application, which can be any type and/or form of software, program, or executable instructions such as any type and/or form of web browser, web-based client, client-server application, a thin-client computing client, an ActiveX control, or a Java applet, or any other type and/or form of executable instructions capable of executing on a local machine <b>102</b>. In some embodiments, the application may be a server-based or a remote-based application executed on behalf of the local machine <b>102</b> on a server <b>106</b>. In one embodiments the server <b>106</b> may display output data to the local machine <b>102</b> using any thin-client or remote-display protocol, such as the Independent Computing Architecture (ICA) protocol manufactured by Citrix Systems, Inc. of Ft. Lauderdale, Fla. or the Remote Desktop Protocol (RDP) manufactured by the Microsoft Corporation of Redmond, Wash. The application can use any type of protocol and it can be, for example, an HTTP client, an FTP client, an Oscar client, or a Telnet client. In other embodiments, the application comprises any type of software related to voice over internet protocol (VoIP) communications, such as a soft IP telephone. In further embodiments, the application comprises any application related to real-time data communications, such as applications for streaming video and/or audio.
0037The local machine <b>102</b> and server <b>106</b> may be deployed as and/or executed on any type and form of computing device, such as a computer, network device or appliance capable of communicating on any type and form of network and performing the operations described herein. <figref idref="DRAWINGS">FIGS. 1B and 1C</figref> depict block diagrams of a computing device <b>100</b> useful for practicing an embodiment of the local machine <b>102</b> or a server <b>106</b>. As shown in <figref idref="DRAWINGS">FIGS. 1B and 1C</figref>, each computing device <b>100</b> includes a central processing unit <b>121</b>, and a main memory unit <b>122</b>. As shown in <figref idref="DRAWINGS">FIG. 1B</figref>, a computing device <b>100</b> may include a visual display device <b>124</b>, a keyboard <b>126</b> and/or a pointing device <b>127</b>, such as a mouse. As shown in <figref idref="DRAWINGS">FIG. 1C</figref>, each computing device <b>100</b> may also include additional optional elements, such as one or more input/output devices <b>130</b><i>a</i>-<b>130</b><i>b </i>(generally referred to using reference numeral <b>130</b>), and a cache memory <b>140</b> in communication with the central processing unit <b>121</b>.
0038The central processing unit <b>121</b> is any logic circuitry that responds to and processes instructions fetched from the main memory unit <b>122</b>. In many embodiments, the central processing unit is provided by a microprocessor unit, such as: those manufactured by Intel Corporation of Mountain View, Calif.; those manufactured by Motorola Corporation of Schaumburg, Ill.; those manufactured by Transmeta Corporation of Santa Clara, Calif.; the RS/6000 processor, those manufactured by International Business Machines of White Plains, N.Y.; or those manufactured by Advanced Micro Devices of Sunnyvale, Calif. The computing device <b>100</b> may be based on any of these processors, or any other processor capable of operating as described herein.
0039Main memory unit <b>122</b> may be one or more memory chips capable of storing data and allowing any storage location to be directly accessed by the microprocessor <b>121</b>, such as Static random access memory (SRAM), Burst SRAM or SynchBurst SRAM (BSRAM), Dynamic random access memory (DRAM), Fast Page Mode DRAM (FPM DRAM), Enhanced DRAM (EDRAM), Extended Data Output RAM (EDO RAM), Extended Data Output DRAM (EDO DRAM), Burst Extended Data Output DRAM (BEDO DRAM), Enhanced DRAM (EDRAM), synchronous DRAM (SDRAM), JEDEC SRAM, PC100 SDRAM, Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), SyncLink DRAM (SLDRAM), Direct Rambus DRAM (DRDRAM), or Ferroelectric RAM (FRAM). The main memory <b>122</b> may be based on any of the above described memory chips, or any other available memory chips capable of operating as described herein. In the embodiment shown in <figref idref="DRAWINGS">FIG. 1B</figref>, the processor <b>121</b> communicates with main memory <b>122</b> via a system bus <b>150</b> (described in more detail below). <figref idref="DRAWINGS">FIG. 1C</figref> depicts an embodiment of a computing device <b>100</b> in which the processor communicates directly with main memory <b>122</b> via a memory port <b>103</b>. For example, in <figref idref="DRAWINGS">FIG. 1C</figref> the main memory <b>122</b> may be DRDRAM.
0040<figref idref="DRAWINGS">FIG. 1C</figref> depicts an embodiment in which the main processor <b>121</b> communicates directly with cache memory <b>140</b> via a secondary bus, sometimes referred to as a backside bus. In other embodiments, the main processor <b>121</b> communicates with cache memory <b>140</b> using the system bus <b>150</b>. Cache memory <b>140</b> typically has a faster response time than main memory <b>122</b> and is typically provided by SRAM, BSRAM, or EDRAM. In the embodiment shown in <figref idref="DRAWINGS">FIG. 1C</figref>, the processor <b>121</b> communicates with various I/O devices <b>130</b> via a local system bus <b>150</b>. Various buses may be used to connect the central processing unit <b>121</b> to any of the I/O devices <b>130</b>, including a VESA VL bus, an ISA bus, an EISA bus, a MicroChannel Architecture (MCA) bus, a PCI bus, a PCI-X bus, a PCI-Express bus, or a NuBus. For embodiments in which the I/O device is a video display <b>124</b>, the processor <b>121</b> may use an Advanced Graphics Port (AGP) to communicate with the display <b>124</b>. <figref idref="DRAWINGS">FIG. 1C</figref> depicts an embodiment of a computer <b>100</b> in which the main processor <b>121</b> communicates directly with I/O device <b>130</b><i>b </i>via HyperTransport, Rapid I/O, or InfiniBand. <figref idref="DRAWINGS">FIG. 1C</figref> also depicts an embodiment in which local busses and direct communication are mixed: the processor <b>121</b> communicates with I/O device <b>130</b><i>a </i>using a local interconnect bus while communicating with I/O device <b>130</b><i>b </i>directly.
0041The computing device <b>100</b> may support any suitable installation device <b>116</b>, such as a floppy disk drive for receiving floppy disks such as 3.5-inch, 5.25-inch disks or ZIP disks, a CD-ROM drive, a CD-R/RW drive, a DVD-ROM drive, tape drives of various formats, USB device, hard-drive or any other device suitable for installing software and programs such as any client agent <b>120</b>, or portion thereof. The computing device <b>100</b> may further comprise a storage device, such as one or more hard disk drives or redundant arrays of independent disks, for storing an operating system and other related software, and for storing application software programs such as any program related to the client agent <b>120</b>. Optionally, any of the installation devices <b>116</b> could also be used as the storage device. Additionally, the operating system and the software can be run from a bootable medium, for example, a bootable CD, such as KNOPPIX, a bootable CD for GNU/Linux that is available as a GNU/Linux distribution from knoppix.net.
0042Furthermore, the computing device <b>100</b> may include a network interface <b>118</b> to interface to a Local Area Network (LAN), Wide Area Network (WAN) or the Internet through a variety of connections including, but not limited to, standard telephone lines, LAN or WAN links (e.g., 802.11, T1, T3, 56 kb, X.25, SNA, DECNET), broadband connections (e.g., ISDN, Frame Relay, ATM, Gigabit Ethernet, Ethernet-over-SONET), wireless connections, or some combination of any or all of the above. Connections can be established using a variety of communication protocols (e.g., TCP/IP, IPX, SPX, NetBIOS, Ethernet, ARCNET, SONET, SDH, Fiber Distributed Data Interface (FDDI), RS232, IEEE 802.11, IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, CDMA, GSM, WiMax and direct asynchronous connections). In one embodiment, the computing device <b>100</b> communicates with other computing devices <b>100</b>′ via any type and/or form of gateway or tunneling protocol such as Secure Socket Layer (SSL) or Transport Layer Security (TLS), or the Citrix Gateway Protocol manufactured by Citrix Systems, Inc. of Ft. Lauderdale, Fla. The network interface <b>118</b> may comprise a built-in network adapter, network interface card, PCMCIA network card, card bus network adapter, wireless network adapter, USB network adapter, modem or any other device suitable for interfacing the computing device <b>100</b> to any type of network capable of communication and performing the operations described herein.
0043A wide variety of I/O devices <b>130</b><i>a</i>-<b>130</b><i>n </i>may be present in the computing device <b>100</b>. Input devices include keyboards, mice, trackpads, trackballs, microphones, and drawing tablets. Output devices include video displays, speakers, inkjet printers, laser printers, and dye-sublimation printers. The I/O devices may be controlled by an I/O controller <b>123</b> as shown in <figref idref="DRAWINGS">FIG. 1B</figref>. The I/O controller may control one or more I/O devices such as a keyboard <b>126</b> and a pointing device <b>127</b>, e.g., a mouse or optical pen. Furthermore, an I/O device may also provide storage and/or an installation medium <b>116</b> for the computing device <b>100</b>. In still other embodiments, the computing device <b>100</b> may provide USB connections to receive handheld USB storage devices such as the USB Flash Drive line of devices manufactured by Twintech Industry, Inc. of Los Alamitos, Calif.
0044In some embodiments, the computing device <b>100</b> may comprise or be connected to multiple display devices <b>124</b><i>a</i>-<b>124</b><i>n</i>, which each may be of the same or different type and/or form. As such, any of the I/O devices <b>130</b><i>a</i>-<b>130</b><i>n </i>and/or the I/O controller <b>123</b> may comprise any type and/or form of suitable hardware, software, or combination of hardware and software to support, enable or provide for the connection and use of multiple display devices <b>124</b><i>a</i>-<b>124</b><i>n </i>by the computing device <b>100</b>. For example, the computing device <b>100</b> may include any type and/or form of video adapter, video card, driver, and/or library to interface, communicate, connect or otherwise use the display devices <b>124</b><i>a</i>-<b>124</b><i>n</i>. In one embodiment, a video adapter may comprise multiple connectors to interface to multiple display devices <b>124</b><i>a</i>-<b>124</b><i>n</i>. In other embodiments, the computing device <b>100</b> may include multiple video adapters, with each video adapter connected to one or more of the display devices <b>124</b><i>a</i>-<b>124</b><i>n</i>. In some embodiments, any portion of the operating system of the computing device <b>100</b> may be configured for using multiple displays <b>124</b><i>a</i>-<b>124</b><i>n</i>. In other embodiments, one or more of the display devices <b>124</b><i>a</i>-<b>124</b><i>n </i>may be provided by one or more other computing devices, such as computing devices <b>100</b><i>a </i>and <b>100</b><i>b </i>connected to the computing device <b>100</b>, for example, via a network. These embodiments may include any type of software designed and constructed to use another computer's display device as a second display device <b>124</b><i>a </i>for the computing device <b>100</b>. One ordinarily skilled in the art will recognize and appreciate the various ways and embodiments that a computing device <b>100</b> may be configured to have multiple display devices <b>124</b><i>a</i>-<b>124</b><i>n. </i>
0045In further embodiments, an I/O device <b>130</b> may be a bridge between the system bus <b>150</b> and an external communication bus, such as a USB bus, an Apple Desktop Bus, an RS-232 serial connection, a SCSI bus, a FireWire bus, a FireWire 800 bus, an Ethernet bus, an AppleTalk bus, a Gigabit Ethernet bus, an Asynchronous Transfer Mode bus, a HIPPI bus, a Super HIPPI bus, a SerialPlus bus, a SCI/LAMP bus, a FibreChannel bus, or a Serial Attached small computer system interface bus.
0046A computing device <b>100</b> of the sort depicted in <figref idref="DRAWINGS">FIGS. 1B and 1C</figref> typically operates under the control of operating systems, which control scheduling of tasks and access to system resources. The computing device <b>100</b> can be running any operating system such as any of the versions of the MICROSOFT WINDOWS operating systems, the different releases of the Unix and Linux operating systems, any version of the MAC OS for Macintosh computers, any embedded operating system, any real-time operating system, any open source operating system, any proprietary operating system, any operating systems for mobile computing devices, or any other operating system capable of running on the computing device and performing the operations described herein. Typical operating systems include: WINDOWS 3.x, WINDOWS 95, WINDOWS 98, WINDOWS 2000, WINDOWS NT 3.51, WINDOWS NT 4.0, WINDOWS CE, WINDOWS XP, and WINDOWS VISTA, all of which are manufactured by Microsoft Corporation of Redmond, Wash.; MACOS, manufactured by Apple Computer of Cupertino, Calif.; OS/2, manufactured by International Business Machines of Armonk, N.Y.; and Linux, a freely-available operating system distributed by Caldera Corp. of Salt Lake City, Utah, or any type and/or form of a Unix operating system, among others.
0047The computer system <b>100</b> can be any workstation, desktop computer, laptop or notebook computer, server, handheld computer, mobile telephone or other portable telecommunication device, media playing device, a gaming system, mobile computing device, or any other type and/or form of computing, telecommunications or media device that is capable of communication and that has sufficient processor power and memory capacity to perform the operations described herein. For example, the computer system <b>100</b> may comprise a device of the IPOD family of devices manufactured by Apple Computer of Cupertino, Calif., a PLAYSTATION 2, PLAYSTATION 3, or PERSONAL PLAYSTATION PORTABLE (PSP) device manufactured by the Sony Corporation of Tokyo, Japan, a NINTENDO DS, NINTENDO GAMEBOY, NINTENDO GAMEBOY ADVANCED or NINTENDO REVOLUTION device manufactured by Nintendo Co., Ltd., of Kyoto, Japan, or an XBOX or XBOX 360™ device manufactured by the Microsoft Corporation of Redmond, Wash.
0048In some embodiments, the computing device <b>100</b> may have different processors, operating systems, and input devices consistent with the device. For example, in one embodiment, the computing device <b>100</b> is a TREO 180, 270, 600, 650, 680, 700p, 700w, or 750 smart phone manufactured by Palm, Inc. In some of these embodiments, the TREO smart phone is operated under the control of the PalmOS operating system and includes a stylus input device as well as a five-way navigator device.
0049In other embodiments the computing device <b>100</b> is a mobile device, such as a JAVA-enabled cellular telephone or personal digital assistant (PDA), such as the i55sr, i58sr, i85s, i88s, i90c, i95cl, or the im1100, all of which are manufactured by Motorola Corp. of Schaumburg, Ill., the 6035 or the 7135, manufactured by Kyocera of Kyoto, Japan, or the i300 or i330, manufactured by Samsung Electronics Co., Ltd., of Seoul, Korea.
0050In still other embodiments, the computing device <b>100</b> is a Blackberry handheld or smart phone, such as the devices manufactured by Research In Motion Limited, including the Blackberry 7100 series, 8700 series, 7700 series, 7200 series, the Blackberry 7520, or the Blackberry Pearl 8100. In yet other embodiments, the computing device <b>100</b> is a smart phone, Pocket PC, Pocket PC Phone, or other handheld mobile device supporting Microsoft Windows Mobile Software. Moreover, the computing device <b>100</b> can be any workstation, desktop computer, laptop or notebook computer, server, handheld computer, mobile telephone, any other computer, or other form of computing or telecommunications device that is capable of communication and that has sufficient processor power and memory capacity to perform the operations described herein.
0051In some embodiments, the computing device <b>100</b> is a digital audio player. In one of these embodiments, the computing device <b>100</b> is a digital audio player such as the Apple IPOD, IPOD Touch, IPOD NANO, and IPOD SHUFFLE lines of devices, manufactured by Apple Computer of Cupertino, Calif. In another of these embodiments, the digital audio player may function as both a portable media player and as a mass storage device. In other embodiments, the computing device <b>100</b> is a digital audio player such as the DigitalAudioPlayer Select MP3 players, manufactured by Samsung Electronics America, of Ridgefield Park, N.J., or the Motorola m500 or m25 Digital Audio Players, manufactured by Motorola Inc. of Schaumburg, Ill. In still other embodiments, the computing device <b>100</b> is a portable media player, such as the Zen Vision W, the Zen Vision series, the Zen Portable Media Center devices, or the Digital MP3 line of MP3 players, manufactured by Creative Technologies Ltd. In yet other embodiments, the computing device <b>100</b> is a portable media player or digital audio player supporting file formats including, but not limited to, MP3, WAV, M4A/AAC, WMA Protected AAC, AIFF, Audible audiobook, Apple Lossless audio file formats and .mov, .m4v, and .mp4MPEG-4 (H.264/MPEG-4 AVC) video file formats.
0052In some embodiments, the computing device <b>100</b> comprises a combination of devices, such as a mobile phone combined with a digital audio player or portable media player. In one of these embodiments, the computing device <b>100</b> is a Motorola RAZR or Motorola ROKR line of combination digital audio players and mobile phones. In another of these embodiments, the computing device <b>100</b> is an iPhone smartphone, manufactured by Apple Computer of Cupertino, Calif.
0053In one embodiment, the server <b>106</b> includes a policy engine for controlling and managing the access to a resource, selection of an execution method for accessing the resource, and the delivery of resources. In another embodiment, the server <b>106</b> communicates with a policy engine. In some embodiments, the policy engine identifies the one or more resources a user or local machine <b>102</b> may access. In other embodiments, the policy engine determines how the resource should be delivered to the user or local machine <b>102</b>, e.g., the method of execution. In still other embodiments, the server <b>106</b> provides, responsive to a determination made by the policy engine, a plurality of delivery techniques from which to select a method of execution, such as a server-based computing, application streaming, or delivering the application locally to the local machine <b>102</b> for local execution. In yet other embodiments, an enumeration of a plurality of resources available to the local machine <b>102</b> is provided responsive to a determination by a policy engine regarding whether and how a local machine may access a resource. The policy engine may collect information about the local machine prior to making the determination.
0054In some embodiments, a server <b>106</b> may select a method of providing access to the requested resource that requires the resource to execute within an isolation environment on the local machine <b>102</b>. An isolation environment may consist of a core system able to provide file system virtualization, registry system virtualization, and named object virtualization. The isolation environment may redirect resource requests using hooking both in a user mode for registry and named object virtualization, and in a kernel using a file system filter driver for file system virtualization.
0055In some embodiments, a user isolation environment provides an isolation scope for each individual user. In other embodiments, the user isolation environment provides an isolation scope for a group of users, which may be defined by roles within the organization or may be predetermined by an administrator. In still other embodiments, no user isolation environment is provided. In still even other embodiments, a user isolation environment may be used in multi-user computers supporting concurrent execution of application programs by various users. In yet other embodiments, the user isolation environment may also be used on single-user computers.
0056Referring now to <figref idref="DRAWINGS">FIG. 2A</figref>, a block diagram depicts one embodiment of the system in which a local machine <b>102</b> requests execution of a resource and a remote machine <b>106</b> selects a method of executing the resource. In one embodiment, the remote machine <b>106</b> receives credentials from the local machine <b>102</b>. In another embodiment, the remote machine <b>106</b> receives a request for an enumeration of available resources from the local machine <b>102</b>.
0057In some embodiments, multiple, redundant, remote machines <b>106</b>, <b>106</b>′, <b>106</b>″, <b>106</b>′″, and <b>106</b>″″ are provided. In one of these embodiments, there may be, for example, multiple file servers, multiple session management servers, multiple staging machines, multiple web interfaces, or multiple access suite consoles. In another of these embodiments, if a remote machine fails, a redundant remote machine <b>106</b> is selected to provide the functionality of the failed machine. In other embodiments, although the remote machines <b>106</b>, <b>106</b>′, <b>106</b>″, <b>106</b>′″, and <b>106</b>″″, and the web interface <b>258</b> and access suite console <b>220</b> are described as separate remote machines <b>106</b> having the separate functionalities of a management server, a session management server, a staging machine, a file server, a web server, and an access suite console, a single remote machine <b>106</b> may be provided having the functionality of all of these machines. In still other embodiments, a remote machine <b>106</b> may provide the functionality and services of one or more of the other remote machines.
0058Referring now to <figref idref="DRAWINGS">FIG. 2A</figref>, and in connection with <figref idref="DRAWINGS">FIG. 2B</figref>, a block diagram depicts one embodiment of a remote machine <b>106</b> providing access to an application program. In some embodiments, the remote machine <b>106</b> may further include a management communication service <b>214</b>, an XML service <b>216</b>, and a management service <b>204</b>. The management service <b>204</b> may comprise an application management subsystem <b>206</b>, a server management subsystem <b>208</b>, a session management subsystem <b>210</b>, and a license management subsystem <b>212</b>. The remote machine <b>106</b> may be in communication with an access suite console <b>220</b>.
0059In one embodiment, the management service <b>204</b> further comprises a specialized remote procedure call subsystem, the MetaFrame Remote Procedure Call (MFRPC) subsystem <b>222</b>. In some embodiments, the MFRPC subsystem <b>222</b> routes communications between subsystems on the remote machine <b>106</b>, such as the XML service <b>216</b>, and the management service <b>204</b>. In other embodiments, the MFRPC subsystem <b>222</b> provides a remote procedure call (RPC) interface for calling management functions, delivers RPC calls to the management service <b>204</b>, and returns the results to the subsystem making the call.
0060The remote machine <b>106</b> may be in communication with an access suite console <b>220</b>. The access suite console <b>220</b> may host management tools to an administrator of a remote machine <b>106</b> or of a farm <b>38</b>. In some embodiments, the remote machine <b>106</b> communicates with the access suite console <b>220</b> using XML. In other embodiments, the remote machine <b>106</b> communicates with the access suite console <b>220</b> using the Simple Object Access Protocol (SOAP).
0061In some embodiments, and as depicted in <figref idref="DRAWINGS">FIG. 2A</figref>, the management service <b>204</b> may comprise a plurality of subsystems. In one embodiment, each subsystem is either a single-threaded or a multi-threaded subsystem. A thread is an independent stream of execution running in a multi-tasking environment. A single-threaded subsystem is capable of executing only one thread at a time. A multi-threaded subsystem can support multiple concurrently executing threads, i.e., a multi-threaded subsystem can perform multiple tasks simultaneously.
0062The application management subsystem <b>206</b> manages information associated with a plurality of applications capable of being streamed. In one embodiment, the application management subsystem <b>206</b> handles requests from other components, such as requests for storing, deleting, updating, enumerating or resolving applications. In another embodiment, the application management subsystem <b>206</b> handles requests sent by components related to an application capable of being streamed. These events can be classified into three types of events: application publishing, application enumeration and application launching, each of which will be described in further detail below. In other embodiments, the application management subsystem <b>206</b> further comprises support for application resolution, application publication and application publishing. In other embodiments, the application management subsystem <b>206</b> uses a data store to store application properties and policies.
0063The server management subsystem <b>208</b> handles configurations specific to application streaming in server farm configurations. In some embodiments, the server management subsystem <b>208</b> also handles events that require retrieval of information associated with a configuration of a farm <b>38</b>. In other embodiments, the server management subsystem <b>208</b> handles events sent by other components related to remote machines providing access to applications across application streams and properties of those remote machines. In one embodiment, the server management subsystem <b>208</b> stores remote machine properties and farm properties.
0064In some embodiments, the remote machine <b>106</b> further comprises one or more common application subsystems <b>224</b> providing services for one or more specialized application subsystems. These remote machines <b>106</b> may also have one or more common remote machine subsystem providing services for one or more specialized remote machine subsystems. In other embodiments, no common application subsystems <b>224</b> are provided, and each specialized application and remote machine subsystem implements all required functionality.
0065In one embodiment in which the remote machine <b>106</b> comprises a common application subsystem <b>224</b>, the common application subsystem <b>224</b> manages common properties for published applications. In some embodiments, the common application subsystem <b>224</b> handles events that require retrieval of information associated with published applications or with common properties. In other embodiments, the common application subsystem <b>224</b> handles all events sent by other components related to common applications and their properties.
0066A common application subsystem <b>224</b> can “publish” applications to the farm <b>38</b>, which makes each application available for enumeration and launching by a local machine <b>102</b>. Generally, an application is installed on each remote machine <b>106</b> on which availability of that application is desired. In one embodiment, to publish an application, an administrator runs an administration tool specifying information such as the remote machines <b>106</b> hosting the application, the name of the executable file on each remote machine, the required capabilities of a local machine for executing the application (e.g., audio, video, encryption, etc.), and a list of users that can use the application. This specified information is categorized into resource-specific information and common information. Examples of resource-specific information are: the path name for accessing the application and the name of the executable file for running the application. Common information (i.e., common resource data) includes, for example, the user-friendly name of the resource (e.g., “Microsoft WORD 2000”), a unique identification of the resource, and the users of the resource.
0067The resource-specific information and common information may be sent to a specialized application subsystem controlling the application on each remote machine <b>106</b> hosting the application. The specialized resource subsystem may write the application-specific information and the common information into a persistent store.
0068When provided, a common application subsystem <b>224</b> also provides a facility for managing the published applications in the farm <b>38</b>. Through a common application subsystem <b>224</b>, an administrator can manage the applications of the farm <b>38</b> using an administration tool such as the access suite console <b>220</b> to configure application groups and produce an application tree hierarchy of those application groups. Each application group may be represented as a folder in the application tree hierarchy. Each application folder in the application tree hierarchy can include one or more other application folders and specific instances of remote machines. The common application subsystem <b>224</b> provides functions to create, move, rename, delete, and enumerate application folders.
0069In one embodiment, the common application subsystem <b>224</b> supports the application management subsystem <b>206</b> in handling application enumeration and application resolution requests. In some embodiments, the common application subsystem <b>224</b> provides functionality for identifying an application for execution responsive to a mapping between a type of data file and an application for processing the type of data file. In other embodiments, a second application subsystem provides the functionality for file type association.
0070In some embodiments, the remote machine <b>106</b> may further comprise a policy subsystem. A policy subsystem includes a policy rule for determining whether an application may be streamed to a local machine <b>102</b> upon a request by the local machine <b>102</b> for execution of the application. In some embodiments, the policy subsystem identifies a server access option associated with a streamed application published in the access suite console <b>220</b>. In one of these embodiments, the policy subsystem uses the server access option as a policy in place of the policy rule.
0071The session monitoring subsystem <b>210</b> maintains and updates session status of an application streaming session associated with a local machine <b>102</b> and enforces license requirements for application streaming sessions. In one embodiment the session management subsystem <b>310</b> monitors sessions and logs events, such as the launching of an application or the termination of an application streaming session. In another embodiment, the session monitoring subsystem <b>210</b> receives communications, such as heartbeat messages, transmitted from the local machine <b>102</b> to the remote machine <b>106</b>. In still another embodiment, the session management subsystem <b>210</b> responds to queries about sessions from management tools, such as tools within the access suite console <b>220</b>. In some embodiments, the management service <b>204</b> further comprises a license management subsystem communicating with the session management subsystem to provide and maintain licenses to local machines for execution of applications.
0072In one embodiment, the management service <b>204</b> provides functionality for application enumeration and application resolution. In some embodiments, the management service <b>204</b> also provides functionality for application launching, session monitoring and tracking, application publishing, and license enforcement.
0073Referring now to <b>2</b>B, a block diagram depicts one embodiment of a remote machine <b>106</b> comprising a management service providing an application enumeration. The management service <b>204</b> may provide application enumeration through the use of a web interface interacting with an XML service <b>216</b>. In one embodiment, XML service <b>216</b> enumerates applications for a user of a local machine <b>102</b>. In another embodiment, the XML service <b>216</b> implements the functionality of the ICA browser subsystem and the program neighborhood subsystem described above. The XML service <b>216</b> may interact with a management communications service <b>214</b>. In one embodiment, the XML service <b>216</b> generates an application enumeration request using the management communications service <b>214</b>. The application enumeration request may include a client type indicating a method of execution to be used when executing the enumerated application. The application enumeration request is sent to a common application subsystem <b>224</b>. In one embodiment, the common application subsystem <b>224</b> returns an enumeration of applications associated with the client type of the application enumeration request. In another embodiment, the common application subsystem <b>224</b> returns an enumeration of applications available to the user of the local machine <b>102</b>, the enumeration selected responsive to an application of a policy to a credential associated with the local machine <b>102</b>. In still another embodiment, the enumeration of applications is returned and an application of a policy to the local machine <b>102</b> is deferred until an execution of an enumerated application is requested.
0074The management service <b>204</b> may provide application resolution service for identifying a second remote machine <b>106</b>′ hosting an application. In one embodiment, the second remote machine <b>106</b>′ is a file server or an application server. In some embodiments, the management service <b>204</b> consults a file including identifiers for a plurality of remote machines <b>106</b> hosting applications. In one embodiment, the management service <b>204</b> provides the application resolution service responsive to a request from a local machine <b>102</b> for execution of an application. In another embodiment, the management service <b>204</b> identifies a second remote machine <b>106</b>′ capable of implementing a different method of executing the application than a first remote machine <b>106</b>. In some embodiments, the management service <b>204</b> identifies a first remote machine <b>106</b>′ capable of streaming an application program to a local machine <b>102</b> and a second remote machine <b>106</b>′ capable of executing the application program and providing application-output data generated responsive to the execution of the application program to the local machine <b>102</b>.
0075In one embodiment, a web interface transmits an application resolution request to the XML service <b>216</b>. In another embodiment, the XML service <b>216</b> receives an application resolution request and transmits the request to the MFRPC subsystem <b>222</b>.
0076In one embodiment, the MFRPC subsystem <b>222</b> identifies a client type included with a received application resolution request. In another embodiment, the MFRPC subsystem applies a policy to the client type and determines to “stream” the application to the local machine <b>102</b>. In this embodiment, the MFRPC subsystem <b>222</b> may forward the application resolution request to an application management subsystem <b>206</b>. In one embodiment, upon receiving the application resolution request from the MFRPC subsystem <b>222</b>, the application management subsystem <b>206</b> may identify a remote machine <b>106</b>″″ functioning as a session management server <b>262</b> for the local machine <b>102</b>. In some embodiments, the local machine transmits a heartbeat message to the session management server <b>262</b>. In another embodiment, the application management subsystem <b>206</b> may identify a remote machine <b>106</b>′ hosting a plurality of application files comprising the application to be streamed to the local machine <b>102</b>.
0077In some embodiments, the application management subsystem <b>206</b> use a file enumerating a plurality of remote machines hosting the plurality of application files to identify the remote machine <b>106</b>′. In other embodiments, the application management subsystem <b>206</b> identifies a remote machine <b>106</b>′ having an IP address similar to an IP address of the local machine <b>102</b>. In still other embodiments, the application management subsystem <b>206</b> identifies a remote machine <b>106</b>′ having an IP address in a range of IP addresses accessible to the local machine <b>102</b>.
0078In one embodiment, the MFRPC subsystem <b>222</b> applies a policy to the client type and determines that the application may be executed on a remote machine <b>106</b>′, the remote machine <b>106</b>′ transmitting application-output data generated by an execution of the application to the local machine <b>102</b>. In this embodiment, the MFRPC subsystem <b>222</b> may forward the application resolution request to a common application subsystem <b>224</b> to retrieve an identifier of a host address for a remote machine <b>106</b>′. In another embodiment, the identified remote machine <b>106</b>′ may transmit the application-output data to the local machine using a presentation level protocol such as ICA or RDP or X Windows. In still another embodiment, the remote machine <b>106</b>′ receives the application from a second remote machine <b>106</b>′ across an application streaming session. In yet another embodiment, upon completion of application enumeration and application resolution, access information is transmitted to the local machine <b>102</b> that includes an identification of a method of execution for an enumerated application and an identifier of a remote machine <b>106</b>′ hosting the enumerated application.
0079Referring back to <figref idref="DRAWINGS">FIG. 2A</figref>, the local machine <b>102</b> may include an application streaming client <b>252</b>, a streaming service <b>254</b> and an isolation environment <b>256</b>. The application streaming client <b>252</b> may be an executable program. In some embodiments, the application streaming client <b>252</b> may be able to launch another executable program. In other embodiments, the application streaming client <b>252</b> may initiate the streaming service <b>254</b>. In one of these embodiments, the application streaming client <b>252</b> may provide the streaming service <b>254</b> with a parameter associated with executing an application program. In another of these embodiments, the application streaming client <b>252</b> may initiate the streaming service <b>254</b> using a remote procedure call.
0080The local machine <b>102</b> may include a client agent <b>260</b>. The client agent <b>260</b> may provide functionality for associating a file type with an application program and selecting a method of execution of the application program responsive to the association. In one embodiment, the client agent <b>260</b> is a program neighborhood application.
0081In one embodiment, the local machine <b>102</b> requests execution of an application program and receives access information from a remote machine <b>106</b> regarding execution. In another embodiment, the application streaming client <b>252</b> receives the access information. In still another embodiment, the application streaming client <b>252</b> provides the access information to the streaming service <b>254</b>. In yet another embodiment, the access information includes an identification of a location of a file associated with a plurality of application files comprising the application program.
0082In one embodiment, the streaming service <b>254</b> retrieves a file associated with a plurality of application files. In some embodiments, the retrieved file includes an identification of a location of the plurality of application files. In one of these embodiments, the streaming service <b>254</b> retrieves the plurality of application files. In another of these embodiments, the streaming service <b>254</b> executes the retrieved plurality of application files on the local machine <b>102</b>. In other embodiments, the streaming service <b>254</b> transmits heartbeat messages to a remote machine to maintain authorization to retrieve and execute a plurality of application files.
0083In some embodiments, the retrieved file includes an identification of a location of more than one plurality of application files, each plurality of application files comprising a different application program. In one of these embodiments, the streaming service <b>254</b> retrieves the plurality of application files comprising the application program compatible with the local machine <b>102</b>. In another of these embodiments, the streaming service <b>254</b> receives authorization to retrieve a particular plurality of application files, responsive to an evaluation of the local machine <b>102</b>.
0084In some embodiments, the plurality of application files are compressed and stored on a file server within an archive file such as a CAB, ZIP, SIT, TAR, JAR or other archive file. In one embodiment, a plurality of application files stored in an archive file comprises an application program. In another embodiment, multiple pluralities of application files stored in an archive file each comprise different versions of an application program. In still another embodiment, multiple pluralities of application files stored in an archive file each comprise different application programs. In some embodiments, an archive file includes metadata associated with each file in the plurality of application files. In one of these embodiments, the streaming service <b>254</b> generates a directory structure responsive to the included metadata, which may be used to satisfy requests by application programs for directory enumeration.
0085In one embodiment, the streaming service <b>254</b> decompresses an archive file to acquire the plurality of application files. In another embodiment, the streaming service <b>254</b> determines whether a local copy of a file within the plurality of application files exists in a cache on the local machine <b>102</b> prior to retrieving the file from the plurality of application files. In still another embodiment, a file system filter driver <b>264</b> determines whether the local copy exists in the cache. In some embodiments, the streaming service <b>254</b> modifies a registry entry prior to retrieving a file within the plurality of application files.
0086In some embodiments, the streaming service <b>254</b> stores a plurality of application files in a cache on the local machine <b>102</b>. In one of these embodiments, the streaming service <b>254</b> may provide functionality for caching a plurality of application files upon receiving a request to cache the plurality of application files. In another of these embodiments, the streaming service <b>254</b> may provide functionality for securing a cache on the local machine <b>102</b>. In another of these embodiments, the streaming service <b>254</b> may use an algorithm to adjust a size and a location of the cache.
0087In some embodiments, the streaming service <b>254</b> creates an isolation environment <b>256</b> on the local machine <b>102</b>. In one of these embodiments, the streaming service <b>254</b> uses an isolation environment application programming interface to create the isolation environment <b>256</b>. In another of these embodiments, the streaming service <b>254</b> stores the plurality of application files in the isolation environment <b>256</b>. In still another of these embodiments, the streaming service <b>254</b> executes a file in the plurality of application files within the isolation environment. In yet another of these embodiments, the streaming service <b>254</b> executes the application program in the isolation environment.
0088For embodiments in which authorization is received to execute an application on the local machine <b>102</b>, the execution of the application may occur within an isolation environment <b>256</b>. In some embodiments, a plurality of application files comprising the application is stored on the local machine <b>102</b> prior to execution of the application. In other embodiments, a subset of the plurality of application files is stored on the local machine <b>102</b> prior to execution of the application. In still other embodiments, the plurality of application files does not reside in the isolation environment <b>256</b>. In yet other embodiments, a subset of the plurality of applications files do not reside on the local machine <b>102</b>. Regardless of whether a subset of the plurality of application files or each application file in the plurality of application files reside on the local machine <b>102</b> or in isolation environment <b>256</b>, in some embodiments, an application file in the plurality of application files may be executed within an isolation environment <b>256</b>.
0089In some embodiments, isolation environments are used to provide additional functionality to the application streaming client <b>252</b>. In one of these embodiments, an application program is executed within an isolation environment. In another of these embodiments, a retrieved plurality of application files resides within the isolation environment. In still another of these embodiments, changes to a registry on the local machine <b>102</b> are made within the isolation environment.
0090In some embodiments, the application streaming client <b>252</b> includes a file system filter driver <b>264</b> intercepting application requests for files. In one of these embodiments, the file system filter driver <b>264</b> intercepts an application request to open an existing file and determines that the file does not reside in the isolation environment <b>256</b>. In another of these embodiments, the file system filter driver <b>264</b> redirects the request to the streaming service <b>254</b> responsive to a determination that the file does not reside in the isolation environment <b>256</b>. The streaming service <b>254</b> may extract the file from the plurality of application files and store the file in the isolation environment <b>256</b>. The file system filter driver <b>264</b> may then respond to the request for the file with the stored copy of the file. In some embodiments, the file system filter driver <b>264</b> may redirect the request for the file to a file server <b>240</b>, responsive to an indication that the streaming service <b>254</b> has not retrieved the file or the plurality of application files and a determination the file does not reside in the isolation environment <b>256</b>. In one embodiment, the streaming service <b>254</b> uses IOCTL commands to communicate with the filter driver. In another embodiment, communications to the file server <b>240</b> are received with the Microsoft SMB streaming protocol.
0091In some embodiments, the packaging mechanism <b>230</b> stores in a manifest file a list of file types published as available applications and makes this information available to application publishing software. In one of these embodiments, the packaging mechanism <b>230</b> receives this information from monitoring an installation of an application program into the isolation environment on the staging machine. In another of these embodiments, a user of the packaging mechanism <b>230</b> provides this information to the packaging mechanism <b>230</b>. In other embodiments, application publishing software within the access suite console <b>220</b> consults the manifest file to present to a user of the access suite console <b>220</b> the possible file types that can be associated with the requested application being published. The user selects a file type to associate with a particular published application. The file type is presented to the local machine <b>102</b> at the time of application enumeration.
0092In one embodiment, the application streaming client <b>252</b> requests access information associated with the application program from the remote machine <b>106</b>. In some embodiments, the application streaming client <b>252</b> receives an executable program containing the access information. In one of these embodiments, the application streaming client <b>252</b> receives an executable program capable of displaying on the local machine <b>102</b> application-output data generated from an execution of the application program on a remote machine. In another of these embodiments, the application streaming client <b>252</b> receives an executable program capable of retrieving the application program across an application streaming session and executing the application program in an isolation environment on the local machine <b>102</b>. In this embodiment, the application streaming client <b>252</b> may execute the received executable program. In still another of these embodiments, the remote machine <b>106</b> selects an executable program to provide to the local machine <b>102</b> responsive to performing an application resolution.
0093Referring still to <figref idref="DRAWINGS">FIG. 2A</figref>, in one embodiment, the first client, capable of receiving the application stream, is an application streaming client <b>252</b>. The application streaming client <b>252</b> receiving the file, retrieving an identification of a plurality of application files and at least one characteristic required for execution of the plurality of application files, responsive to the file, and determining whether the local machine <b>102</b> includes the at least one characteristic. In another embodiment, the second client is a client agent <b>260</b>. In some embodiments, the client agent <b>260</b> receives the file from the application streaming client <b>252</b> responsive to a determination, by the application streaming client <b>252</b>, that the local machine <b>102</b> lacks the at least one characteristic.
0094In some embodiments, an application executing on the local machine <b>102</b> enumerates files associated with the application using the Win32 FindFirstFile( ) and FindNextFile( ) API calls. In one of these embodiments, a plurality of application files comprises the application. In another of these embodiments, not all files in the plurality of application files reside on the local machine <b>102</b>. In still another of these embodiments, the streaming service <b>254</b> retrieved the plurality of application file in an archived files but extracted only a subset of the plurality of application files. In yet another of these embodiments, the streaming service <b>254</b> and the file system filter driver <b>264</b> provide functionality for satisfying the enumeration request, even when the requested file does not reside on the local machine <b>102</b>.
0095In one embodiment, the functionality is provided by intercepting the enumeration requests and providing the data as if all files in the plurality of application files reside on the local machine <b>102</b>. In another embodiment, the functionality is provided by intercepting, by the file system filter driver <b>264</b>, an enumeration request transmitted as an IOCTL command, such as IRP_MJ_DIRECTORY_CONTROL IOCTL. When the file system filter driver <b>264</b> intercepts the call, the file system filter driver <b>264</b> redirects the request to the streaming service <b>254</b>. In one embodiment, the file system filter driver <b>264</b> determines that the requested enumeration resides in an isolation environment on the local machine <b>102</b> prior to redirecting the request to the streaming service <b>254</b>. In another embodiment, the streaming service <b>254</b> fulfills the request using a file in the plurality of application files, the file including an enumeration of a directory structure associated with the plurality of application files. In still another embodiment, the streaming service <b>254</b> provides the response to the request to the file system filter driver <b>264</b> for satisfaction of the enumeration request.
0096Referring now to <figref idref="DRAWINGS">FIG. 3A</figref>, a system <b>300</b> for accessing, by a local resource, a setting in a user profile includes an isolation environment, a resource, and a filter driver. The resource <b>302</b> executes outside an isolation environment <b>256</b> on a local machine <b>102</b> and requests access to a setting in a user profile. The filter driver <b>264</b> intercepts the request for access to the setting in the user profile. The filter driver <b>264</b> identifies one of the isolation environment <b>256</b> and a remote machine <b>106</b>, responsive to an application of a rule to the request. The filter driver <b>264</b> redirects the request for access to the setting in the user profile to the identified one of the isolation environment <b>256</b> and the remote machine <b>106</b>.
0097In some embodiments, the system provides a user with access to a user profile, including personal files, configuration settings and registry keys associated with user-specific configurations. In one of these embodiments, the system provides the user with this access regardless of the computing environment from which the user makes the request; for example, a user may make a configuration change to an application from a first environment (such as a work desktop environment provided via a virtual machine), subsequently execute an application from a second environment (such as a home laptop providing access to the application via a method for thin-client computing) in which the application includes the configuration change made in the first environment. In other embodiments, the system provides a user with access, in a first environment, to synchronized personal files and settings, which are updated to include modifications previously made, by the user, to the files and settings, from a second environment.
0098Referring now to <figref idref="DRAWINGS">FIG. 3A</figref>, and in greater detail, the resource <b>302</b> executes outside the isolation environment <b>256</b> on a local machine <b>102</b> and requests access to a setting in a user profile. In one embodiment, a resource <b>302</b> is a program, an application, a document, a file, a plurality of applications, a plurality of files, an executable program file, a desktop environment, a computing environment, or other resource made available to a user of the local machine <b>102</b>. In another embodiment, a resource <b>302</b>′ is executed to provide a user with access to a requested resource <b>302</b>. For example, the user may request access to a file <b>302</b> on the local machine <b>102</b> and a resource <b>302</b>′ capable of processing the requested file <b>302</b> is executed on the local machine <b>102</b>. In still another embodiment, a user may request access to a single resource <b>302</b> and receive access to a plurality of applications, desktops, or computing environments. In still even another embodiment, a user may request access to a resource <b>302</b> from a corporate machine, such as a desktop or laptop, or from an un-managed environment, such as a kiosk or personal machine. In yet another embodiment, the resource <b>302</b> may be delivered to the local machine <b>102</b> via a plurality of access methods including, but not limited to, installation directly on the local machine <b>102</b>, delivery to the local machine <b>102</b> via a method for application streaming, delivery to the first machine <b>102</b> of output data generated by an execution of the resource <b>302</b> on a second machine <b>106</b><i>b </i>and communicated to the local machine <b>102</b> via a presentation layer protocol, delivery to the local machine <b>102</b> of output data generated by an execution of the resource <b>302</b> via a virtual machine executing on a second server <b>106</b><i>b</i>, or execution from a removable storage device connected to the local machine <b>102</b>, such as a USB device.
0099In one embodiment, the requested setting in the user profile includes application configuration files allowing a user to customize an application. In another embodiment, the requested setting is a temporarily-stored Internet file. In still another embodiment, the setting identifies items stored in personal folders associated with a user including, but not limited to, folders storing cookies, URLs for favorite sites on the Internet, resources with shortcuts visible on the desktop, resources with shortcuts accessible via a particular menu (such as the Start Menu or a menu of recently accessed applications), folders storing templates, or “My Documents” folders. In yet another embodiment, the requested setting is a data file generated by the user during interaction with a resource <b>302</b>.
0100In one embodiment, the requested setting is a registry key. In another embodiment, the requested setting is a configuration file. In still another embodiment, the requested setting is a data file for processing by an application. In yet another embodiment, the requested setting is an executable file. In some embodiments, the resource <b>302</b> requests access to a registry setting including, but not limited to, a desktop setting, a resource configuration, an application setting, or a security configuration file.
0101In one embodiment, the user profile stores a plurality of settings associated with a user. In another embodiment, the user profile stores a registry key associated with the user. In still another embodiment, the user profile stores a data file associated with the user. In yet another embodiment, the user profile stores a configuration file associated with the user.
0102In one embodiment, the user profile includes a plurality of settings and files that together define a personalized environment associated with a user. In another embodiment, the user profile is a collection of settings that contain user preferences and configuration settings including, but not limited to, screen color, application-specific configuration preferences, preferences associated with network connections, preferences associated with printer connections, input/output device settings, and window size and position preferences. In yet another embodiment, the user profile is a Windows profile.
0103In one embodiment, a user profile is associated with a user. In another embodiment, a user profile is associated with a group of users. In still another embodiment, when a user specifies a preference—for example, by resetting a default font, identifying a process for execution upon initiation of an operating system on the local machine, or changing a graphical display element, such as a theme, color, or background graphic—a setting in the user profile is updated to reflect the preference. In still even another embodiment, when a user specifies a preference, a setting in the user profile is generated; for example, a resource may generate a registry key, data file or configuration file to store an identification of the user-specified preference. In yet another embodiment, these preferences and settings provide the user with a customized, user-specific environment from session to session.
0104In one embodiment, the user profile includes a registry database storing settings for the user and the computer. In another embodiment, portions of the registry database may be stored in files referred to as hive files. In still another embodiment, the user profile includes a plurality of profile folders stored in a file system. In yet another embodiment, the profile folders store data files and configuration files, identifications of user-specified shortcuts, desktop images, documents, and other user-specific data.
0105In some embodiments, a user profile contains files and registry keys specific to an operating system on a local machine <b>102</b>. In one of these embodiments, the user profile is a profile for a user of a local machine executing a WINDOWS operating system. In another of these embodiments, the user profile is a profile for a user of a local machine executing a MAC OS operating system. In still another of these embodiments, the user profile is a profile for a user of a local machine executing a UNIX or LINUX operating system. In other embodiments, a user profile generated in one environment may be accessed and applied to resources executing in a second environment. In one of these embodiments, the user profile is generated on a local machine executing a WINDOWS operating system and accessed by an application executing on a MAC OS operating system.
0106In some embodiments, the request is made for a setting in a user profile on a local machine. In one embodiment, a response to the request is provided from a user profile residing on a remote machine <b>106</b>; for example, a file server <b>106</b>′ may store the user profile. In another embodiment, a response to the request is provided from the user profile residing on a local machine <b>102</b>; for example, a cache memory element on the local machine <b>102</b> may store the user profile. In still another embodiment, a local machine <b>102</b> includes an isolation environment storing the user profile. In still even another embodiment, an isolation environment stores at least one setting in the user profile while a remote machine <b>106</b> stores a copy of the user profile in its entirety. In another embodiment, the remote machine <b>106</b> stores the user profile within an archive file such as a CAB, ZIP, SIT, TAR, JAR or other archive file. In yet another embodiment, both an isolation environment <b>256</b> on a local machine <b>102</b> and a remote machine <b>106</b> store a copy of the user profile.
0107In one embodiment, an administrator generates a group profile for a plurality of users. In another embodiment, the agent <b>320</b> creates an instance of the group profile for each user in the plurality of users. In still another embodiment, an agent <b>310</b> on the local machine <b>102</b> retrieves an instance of the group profile associated with a user of the local machine <b>102</b>. In yet another embodiment, the group profile contains configuration files modifying the behavior or appearance of resources executing on the local machine <b>102</b>. In some embodiments, an administrator generates a group folder for a plurality of users, the group folder containing data files accessible to the plurality of users.
0108The filter driver <b>264</b> intercepts the request for access to the setting in the user profile and identifies one of the isolation environment <b>256</b> and a remote machine <b>106</b>, responsive to an application of a rule to the request. In one embodiment, the filter driver <b>264</b> includes a network request interceptor. In another embodiment, the filter driver <b>264</b> is a filter driver as described above in connection with <figref idref="DRAWINGS">FIG. 2A-2B</figref>. In still another embodiment, the filter driver accesses at least one rule and applies the at least one rule to the request.
0109The filter driver <b>264</b> redirects the request for access to the setting in the user profile to the identified one of the isolation environment <b>256</b> and the remote machine <b>106</b>. In some embodiments, the filter driver <b>264</b> is in communication with an agent <b>310</b>. In one of these embodiments, the filter driver <b>264</b> forwards the intercepted request to the agent <b>310</b> for transmission to the remote machine <b>106</b>. In still another of these embodiments, the filter driver <b>264</b> is a component in the agent <b>310</b>.
0110Referring now to <figref idref="DRAWINGS">FIG. 3B</figref>, a block diagram depicts an embodiment of a system including an agent for accessing a configuration file associated with a resource. In one embodiment, the agent <b>310</b>, executing on the local machine <b>102</b>, intercepts requests for content. In another embodiment, the agent <b>310</b> intercepts request for an Internet file; for example, the agent <b>310</b> may intercept a request for access to a list of bookmarked web sites or for a file storing web site content for offline access. In still another embodiment, the agent <b>310</b> intercepts a request for a data file for processing by an application.
0111In one embodiment, the agent <b>310</b> includes a network request interceptor. In another embodiment, the agent <b>310</b> includes a policy engine. In still another embodiment, the agent <b>310</b> accesses a set of policies and rules for application to requests. In yet another embodiment, the agent <b>310</b> includes the filter driver <b>264</b>.
0112In some embodiments, the agent <b>310</b> includes a routing engine (not shown). In one of these embodiments, the routing engine determines whether to route the request for the setting to the isolation environment <b>256</b>. In another of these embodiments, the routing engine determines whether to route the request for the setting to a cache element in the isolation environment <b>256</b>. In still another embodiment, the routing engine determines whether to route the request for the setting to the remote machine <b>106</b>. In yet another embodiment, the routing engine determines whether to route the request to an environment outside the isolation environment <b>256</b> on the local machine <b>102</b>; for example, the routing engine may determine to send the request to a file system on the local machine <b>102</b>. In other embodiments, the agent <b>310</b> includes at least one rule or policy, which the agent <b>310</b> accesses to determine whether to route the request to the isolation environment.
0113Referring now to <figref idref="DRAWINGS">FIG. 3C</figref>, a block diagram depicts one embodiment of an agent in a system for accessing a configuration file associated with a resource. In one embodiment, the agent <b>310</b> includes functionality for performing file system interception, functionality for operating system interception, a file system interface, a compression/expansion component, a network interface, an encryption component, and an interceptor for a communication stack, such as a WINSTACK interceptor intercepting communications in the TCP/IP stack. In some embodiments, the agent <b>310</b> includes a synchronization component and synchronizes files in the isolation environment <b>256</b> with files in a remote isolation environment associated with a user of the local machine <b>102</b> and located on a remote machine <b>106</b>. In one of these embodiments, the agent <b>310</b> includes a transceiver for exchanging synchronization messages with the remote machine <b>106</b>. In other embodiments, the agent <b>310</b> includes an encryption component for encrypting and decrypting file system traffic sent and received by the local machine <b>102</b>. In still other embodiments, the agent <b>310</b> includes a compression and decompression component for compressing and decompressing file system traffic sent and received by the local machine <b>102</b>. In yet another embodiment, the agent <b>310</b> includes a network interface, such as a TCP/IP interface for communicating with the remote machine <b>106</b>.
0114Referring back to <figref idref="DRAWINGS">FIG. 3B</figref>, the system <b>300</b> includes an agent <b>320</b> executing on the remote machine <b>106</b>. In one embodiment, the agent <b>320</b> implements remote file access and file synchronization functions. In another embodiment, the agent <b>320</b> is implemented in Java and the file system access component may include a library that can be used to access network-based files from the remote machine <b>106</b>. In some embodiments, the agent <b>320</b> includes an encryption component for encrypting and decrypting file system traffic sent and received by the remote machine <b>106</b>. In other embodiments, the agent <b>320</b> includes a compression and decompression component for compressing and decompressing file system traffic sent and received by the remote machine <b>106</b>.
0115Referring now to <figref idref="DRAWINGS">FIG. 4</figref>, a flow diagram depicts one embodiment of the steps taken in a method <b>400</b> for accessing a setting in a virtualized user profile associated with a resource. The method <b>400</b> includes the step of intercepting a request from a resource for access to a setting in a user profile, the resource provided by a local machine and executing outside an isolation environment (step <b>402</b>). The method <b>400</b> includes the step of identifying one of the isolation environment and a remote machine, responsive to an application of a rule to the request (step <b>404</b>). The method <b>400</b> includes the step of redirecting, to the identified one of the isolation environment and the remote machine, the request for access to the setting (step <b>406</b>).
0116In some embodiments, the resource <b>302</b> executes outside an isolation environment <b>256</b> on a local machine <b>102</b> and requests access to a setting in a user profile stored on the local machine <b>102</b>. In one of these embodiments, the filter driver <b>264</b> intercepts the request. In another of these embodiments, the filter driver <b>264</b> responds to the request with a copy of the setting stored by the isolation environment <b>256</b> instead of responding to the request with the setting stored on the local machine <b>102</b>. In still another of these embodiments, the filter driver <b>264</b> responds to the request with a copy of a setting in a user profile stored on a remote machine <b>106</b> instead of responding to the request with the setting stored on the local machine <b>102</b>. In yet another of these embodiments, the filter driver <b>264</b> forwards the intercepted request to an agent <b>310</b>, which responds with a copy of a setting in a user profile stored on a remote machine <b>106</b>.
0117With continued reference to <figref idref="DRAWINGS">FIG. 4</figref>, and in greater detail, a request from a resource for access to a setting in a user profile is intercepted, the resource provided by a local machine and executing outside an isolation environment (step <b>402</b>). In some embodiments, the filter driver <b>264</b> does execute within an isolation environment <b>256</b>. In other embodiments, the resource <b>302</b> executes within a second isolation environment <b>256</b>′. In one embodiment, the filter driver <b>264</b> intercepts the request.
0118In one embodiment, the resource <b>302</b> executes on a local machine <b>102</b> that resides on a first network. In another embodiment, the resource <b>302</b> requests access to a setting in a user profile stored on the local machine <b>102</b> and a determination is made to respond to the request with a setting in a user profile stored on a remote machine <b>106</b> residing on a second network. In still another embodiment, the local machine <b>102</b> provides authentication credentials associated with a user of the local machine <b>102</b> to access the remote machine <b>106</b>. In some embodiments, the remote machine <b>106</b> provides the resource <b>302</b> with access to a user profile stored on a second remote machine <b>106</b>′. In one of these embodiments, the remote machine <b>106</b>′ resides on the same network as the remote machine <b>106</b>. In another of these embodiments, the remote machine <b>106</b>′ resides on a third network. In still another of these embodiments, the second network, on which the remote machine <b>106</b> resides, and the third network, on which the remote machine <b>106</b>′ resides, are federated networks.
0119In some embodiments, a setting in a user profile is requested by a resource during initialization of a user session. For example, and in one of these embodiments, a user configuration file is retrieved and loaded at the beginning of a user session with a remote machine <b>106</b>. In other embodiments, application settings are requested from a user profile and loaded upon execution of an application on the local machine <b>102</b>. In still other embodiments, a setting is requested when a specific function is invoked by a resource.
0120One of an isolation environment and a remote machine is identified, responsive to an application of a rule to the request (step <b>404</b>). In one embodiment, the filter driver <b>264</b> applies a rule to the intercepted request to identify one of the isolation environment <b>256</b> and the remote machine <b>106</b>. In another embodiment, the filter driver <b>264</b> applies a rule to the intercepted request and forwards the intercepted request to an agent <b>310</b>, responsive to the application of the rule. In still another embodiment, the filter driver <b>264</b> applies a rule and identifies the isolation environment <b>256</b>. In yet another embodiment, the filter driver <b>264</b> forwards the intercepted request to the agent <b>310</b>, responsive to a determination that the isolation environment <b>256</b> does not store a copy of the requested setting.
0121In some embodiments, the local machine <b>102</b> retrieves, from the remote machine <b>106</b>, a copy of the user profile. In one of these embodiments, the isolation environment <b>256</b> stores the copy of the user profile; for example, the isolation environment <b>256</b> stores the copy of the user profile in a local cache memory element. In another of these embodiments, the isolation environment <b>256</b> stores a copy of the user profile and a remote machine <b>106</b>′ stores a second copy of the user profile. In still another of these embodiments, an identification is made as to which of the isolation environment <b>256</b> and the remote machine <b>106</b> should respond to the intercepted request for access to the setting in the user profile.
0122In other embodiments, the user profile is not copied to the local machine in its entirety. In one of these embodiments, a setting in the user profile is copied upon interception of a request for access to the setting. In another of these embodiments, copying settings upon request minimizes a length of time required to complete a user log-on process, since only portions of the user profile are copied to the local machine <b>102</b>. In still another of these embodiments, a determination is made as to whether the isolation environment <b>256</b> has a copy of a requested setting and whether to transmit a copy of the requested setting to the isolation environment <b>256</b>.
0123In some embodiments, a file system filter driver, or mini-filter, intercepts requests and determines if a process identifier associated with the intercepted request and with the resource has been associated with a set of rules. If so, the rules associated with the stored process identifier are used to virtualize the requests. If not, the access request is passed through to the file system or registry system unmodified. In other embodiments, a dynamically-linked library is loaded into the newly-created process and the library loads the isolation rules. In still other embodiments, both kernel mode techniques (hooking, filter driver, mini-filter) and user-mode techniques are used to intercept access calls. For embodiments in which a file system filter driver stores the rules, the library may load the rules from the file system filter driver.
0124In some embodiments, rules associated with an isolation environment are retrieved. In other embodiments, the rules are associated with the requested setting. In still other embodiments, the rules are associated with the resource making a request. In still even other embodiments, the rules are retrieved from a persistent storage element, such as a hard disk drive or other solid state memory element. The rules may be stored as a relational database, flat file database, tree-structured database, binary tree structure, or other persistent data structure. In yet other embodiments, the rules may be stored in a data structure specifically configured to store them.
0125In one embodiment, an identifier for the resource, such as a process id (PID), and the retrieved rules are stored in a memory element. In some embodiments, a kernel mode driver is provided that receives operating system messages concerning new process creation. In these embodiments, the PID and the retrieved rules may be stored in the context of the driver. In other embodiments, a file system filter driver, or mini-filter, is provided that intercepts requests. In these embodiments, the PID and the retrieved rules may be stored in the filter. In other embodiments still, interception is performed by user-mode hooking and no PID is stored at all.
0126In one embodiment, the identification of the one of the isolation environment and the remote machine is made responsive to an application of a rule to a characteristic of the local machine. In some embodiments, a determination is made as to whether the local machine <b>102</b> has access to a network on which the remote machine <b>106</b> resides. In one of these embodiments, a determination is made as to whether a user of the local machine <b>102</b> is authorized to access a resource provided by the local machine. In another embodiment, a determination is made as to whether the local machine <b>102</b> has an active Internet connection. In still another of these embodiments, a determination is made as to whether the local machine can access the remote machine <b>106</b> either via an intranet on which both machines <b>102</b> and <b>106</b> reside or via the Internet. In other embodiments, an identification is made of an environment on the local machine outside the isolation environment <b>256</b>; for example, the local file system may include a copy of a user profile. Table 1 depicts one embodiment of a set of rules for application: <tables id="TABLE-US-00001" num="1"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="1"><colspec colname="1" colwidth="217PT" align="center" /><thead><row><entry namest="1" nameend="1" align="center">TABLE 1</entry></row></thead><tbody valign="top"><row><entry /></row><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row><row><entry>Use of Local Cache vs. Use of Network File System</entry></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="5"><colspec colname="1" colwidth="42PT" align="left" /><colspec colname="2" colwidth="49PT" align="left" /><colspec colname="3" colwidth="49PT" align="left" /><colspec colname="4" colwidth="49PT" align="left" /><colspec colname="5" colwidth="28PT" align="left" /><tbody valign="top"><row><entry /><entry>Files in</entry><entry>Files on</entry><entry /><entry /></row><row><entry>Rule</entry><entry>Isolation</entry><entry>Remote</entry><entry /><entry>Local</entry></row><row><entry>Name</entry><entry>Environment</entry><entry>Machine</entry><entry>Sync</entry><entry>files</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row><row><entry>Mobile</entry><entry>Use: Off line</entry><entry>Use: On line</entry><entry>Sync when</entry><entry>Pass</entry></row><row><entry /><entry>only</entry><entry /><entry>online</entry><entry>through</entry></row><row><entry /><entry>Sync: on line</entry></row><row><entry>Laptop</entry><entry>Use: always</entry><entry /><entry>Sync: on line</entry></row><row><entry>Backup</entry></row><row><entry>Wireless</entry><entry>Use: If high</entry><entry>Use: If low</entry><entry>Sync: when</entry></row><row><entry /><entry>latency or low</entry><entry>latency</entry><entry>adequate</entry></row><row><entry /><entry>bandwidth</entry><entry>and high</entry><entry>bandwidth</entry></row><row><entry /><entry /><entry>bandwidth</entry></row><row><entry>Network</entry><entry>Use: always</entry><entry /><entry>Sync: when file</entry></row><row><entry>Master</entry><entry /><entry /><entry>first accessed</entry></row><row><entry /><entry /><entry /><entry>and online (i.e.</entry></row><row><entry /><entry /><entry /><entry>sync file before</entry></row><row><entry /><entry /><entry /><entry>use when</entry></row><row><entry /><entry /><entry /><entry>possible)</entry></row><row><entry>Wireless</entry><entry>Use: If high</entry><entry>Use: If high</entry><entry>Sync: If high</entry></row><row><entry>Network</entry><entry>latency or low</entry><entry>bandwidth and</entry><entry>bandwidth</entry></row><row><entry>Master</entry><entry>bandwidth</entry><entry>low latency</entry><entry>before local</entry></row><row><entry /><entry /><entry /><entry>use.</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0127In one embodiment, either the isolation environment <b>256</b> or the remote machine <b>106</b>′ is selected to respond to the intercepted request for access to a setting in the user profile. In another embodiment, if the local machine <b>102</b> lacks a network connection or experiences poor network performance, the isolation environment <b>256</b> is selected to respond to the request. In still another embodiment, and as will be described in greater detail below, if a user modifies a setting in the user profile while using the copy in the isolation environment <b>256</b>, the agent <b>310</b> synchronizes the modified local version with the copy of the setting on the remote machine <b>106</b>′. In still even another embodiment, if the local machine <b>102</b> has a network connection or experiences strong network performance, the remote machine <b>106</b>′ is selected to respond to the request. In yet another embodiment, if the local machine <b>102</b> has a more recent version of the setting—one having a date and time of last modification that is more recent than the date and time of a version on the remote machine <b>106</b>′—then the isolation environment <b>256</b> is selected to respond to the request.
0128The request for access to the setting in the user profile is redirected to the identified one of the isolation environment and the remote machine (step <b>406</b>). In one embodiment, the isolation environment <b>256</b> responds to the request with a setting retrieved from a copy of the user profile stored by the isolation environment <b>256</b> and synchronized with a copy of the user profile stored by the remote machine <b>106</b>. In another embodiment, the isolation environment <b>256</b> responds to the request with a copy of the setting retrieved from the user profile stored on the local machine. In still another embodiment, the remote machine <b>106</b> transmits, to the agent <b>310</b>, the setting from a copy of the user profile maintained by the remote machine <b>106</b>. In still another embodiment, the agent <b>310</b> responds to the request with a setting received from the remote machine <b>106</b>.
0129In one embodiment, the resource <b>302</b> modifies a resource configuration setting, responsive to processing a configuration file received from the identified one of the isolation environment <b>256</b> and the remote machine <b>106</b>. In another embodiment, the resource <b>302</b> modifies a resource configuration setting, responsive to processing a registry key received from the identified one of the isolation environment <b>256</b> and the remote machine <b>106</b>. In still another embodiment, the resource <b>302</b> displays, to the user, a user data file, responsive to processing a data file received from the identified one of the isolation environment <b>256</b> and the remote machine <b>106</b>. In yet another embodiment, the resource <b>302</b> executes according to an instruction in a setting from the user profile.
0130In one embodiment, the user changes a configuration preference, resulting in the modification of a configuration file in the user profile. In another embodiment, the user modifies a data file in the user profile. In still another embodiment, the user generates a new data file, configuration file or registry key in the user profile.
0131In one embodiment, a determination is made as to when to synchronize a modified setting in a user profile stored on one of the isolation environment <b>256</b> and the remote machine <b>106</b> with a version of the setting in a second copy of the user profile. In another embodiment, a determination is made to synchronize the modified setting with the copy of the setting upon initiation of a log-off procedure by a user. In still another embodiment, a determination is made to synchronize a modified file with the copy of the file upon closing of a file in the user profile. In yet another embodiment, a determination is made to periodically synchronize the modified setting with the copy of the setting; for example, upon expiration of a timer or at user-specified time intervals. In some embodiments, the agent <b>310</b> makes the determination as to when to synchronize the settings in the use profile and performs the synchronization.
0132In some embodiments, a user accessing a resource <b>302</b> executing outside an isolation environment modifies a setting in a user profile stored on an isolation environment <b>256</b>. In one of these embodiments, the setting is tagged to indicate that the user modified the setting. In another of these embodiments, an identification of a change to the modified setting is transmitted to the remote machine <b>106</b> when the local machine <b>102</b> and the remote machine <b>106</b>. In still another of these embodiments, the modified setting is transmitted to the remote machine <b>106</b>.
0133In other embodiments, a user accessing a resource <b>302</b> executing outside an isolation environment <b>256</b> modifies a setting in a user profile stored on a remote machine <b>106</b>. In one of these embodiments, the setting is tagged to indicate that the user modified the setting. In another of these embodiments, an identification of a change to the modified setting is transmitted to the isolation environment <b>256</b> when the local machine <b>102</b> and the remote machine <b>106</b> synchronize a copy of the user profile on the isolation environment <b>256</b> with a copy of the user profile on the remote machine <b>106</b>. In still another of these embodiments, the modified setting is transmitted to the isolation environment <b>256</b>.
0134In some embodiments, a user accessing a resource <b>302</b> executing inside an isolation environment <b>256</b> modifies a setting in a user profile stored on the isolation environment <b>256</b>. In one of these embodiments, the setting is tagged to indicate that the user modified the setting. In another of these embodiments, an identification of a change to the modified setting is transmitted to the remote machine <b>106</b> when the local machine <b>102</b> and the remote machine <b>106</b>. In still another of these embodiments, the modified setting is transmitted to the remote machine <b>106</b>.
0135In other embodiments, a user accessing a resource <b>302</b> executing inside an isolation environment <b>256</b> modifies a setting in a user profile stored on a remote machine <b>106</b>. In one of these embodiments, the setting is tagged to indicate that the user modified the setting. In another of these embodiments, an identification of a change to the modified setting is transmitted to the isolation environment <b>256</b> when the local machine <b>102</b> and the remote machine <b>106</b> synchronizes a copy of the user profile on the isolation environment <b>256</b> with a copy of the user profile on the remote machine <b>106</b>. In still another of these embodiments, the modified setting is transmitted to the isolation environment <b>256</b>.
0136In one embodiment, a determination is made as to which files in a user profile stored by the isolation environment <b>256</b> changed since the previous synchronization with the files in the user profile stored on the remote machine <b>106</b>′. In another embodiment, the determination is made by comparing modification dates and then transmitting block checksum information for those files which have changed. In still another embodiment, the block checksum data is then used to determine which blocks of data are missing on each machine and to generate a schedule of block updates. The generated schedule of block uploads and downloads is then performed.
0137In one embodiment, a user of a local machine <b>102</b> executes a resource on the local machine <b>102</b>, which accesses a version of a user profile provided by an isolation environment <b>256</b> and executes according to a setting retrieved from the version of the user profile. In another embodiment, the user of the local machine <b>102</b> modifies a setting in the user profile; for example, by changing a setting in an application or desktop environment. In still another embodiment, the filter driver <b>264</b> intercepts a request by the resource to save the modification. In still even another embodiment, the filter driver <b>264</b> redirects the request to an isolation environment <b>256</b> where a copy of the setting in the user profile is modified. In another embodiment, the agent <b>410</b> stores, in the isolation environment <b>256</b>, the modified copy of the setting in the user profile. In still another embodiment, the agent <b>410</b> synchronizes the modified copy of the setting in the user profile with a remote version of the setting; for example, by transmitting an identification of the modification to an agent <b>420</b> on a remote machine <b>106</b>. In yet another embodiment, the agent <b>420</b> modifies the copy of the setting on the remote machine <b>106</b>, responsive to the user modification identified by the agent <b>410</b>.
0138In one embodiment, the user of the local machine <b>102</b> logs off of the local machine <b>102</b>. In another embodiment, the user logs onto a second machine <b>102</b>′. In still another embodiment, the user executes a resource provided on the second machine <b>102</b>′. In still another embodiment, a filter driver <b>264</b>′ on the second machine <b>102</b>′ intercepts a request by the resource for access to the setting in the profile. In still even another embodiment, the filter driver <b>264</b>′ determines whether the setting in the profile is stored in an isolation environment <b>256</b>′ on the second machine <b>102</b>′. In still another embodiment, the filter driver <b>264</b>′ requests the setting from an agent <b>410</b>′. In yet another embodiment, the agent <b>410</b>′ retrieves the setting from the remote machine <b>106</b>. In some embodiments, the agent <b>410</b>′ retrieves, from the remote machine <b>106</b>, an identification of the modification made by the user on the local machine <b>102</b>. In one of these embodiments, the agent <b>410</b>′ applies the identified modification to a copy of the setting on the second machine <b>102</b>′.
0139Referring back to <figref idref="DRAWINGS">FIG. 3A</figref>, a system <b>300</b> for accessing, by a local resource, a setting in a user profile includes an isolation environment, a resource, and a filter driver. In one embodiment, the resource <b>302</b> executes on a local machine <b>102</b> and outside the isolation environment <b>256</b>. In another embodiment, the resource <b>302</b> attempts to modify a setting on the local machine. In still another embodiment, the resource <b>302</b> is an installer application installing a second application onto the local machine. In yet another embodiment, the resource <b>302</b> is an installer application selected by a user of the local machine <b>102</b>.
0140In one embodiment, the filter driver <b>264</b> intercepts the instruction to modify the setting on the local machine. In another embodiment, the filter driver <b>264</b> intercepts an instruction to install an application file on the local machine, the installer application executed by the user. In still another embodiment, the filter driver <b>264</b> identifies the isolation environment <b>256</b>, responsive to an application of a rule to the instruction. In yet another embodiment, the filter driver <b>264</b> redirects the instruction to modify the setting to the identified isolation environment <b>256</b>.
0141In one embodiment, an agent <b>310</b> applies a rule to the intercepted instruction. In another embodiment, the agent <b>310</b> identifies the isolation environment, responsive to the application of the rule to the instruction. In still another embodiment, the agent <b>310</b> applies a rule as described above in connection with <figref idref="DRAWINGS">FIGS. 3A-3C</figref> and <b>4</b>. In some embodiments, the agent <b>310</b> selects the isolation environment <b>256</b> from a plurality of isolation environments.
0142In one embodiment, the identified isolation environment includes a cache memory element. In another embodiment, the identified isolation environment has access to a cache memory element. In still another embodiment, the identified isolation environment stores a copy of the setting.
0143In one embodiment, data associated with the identified isolation environment includes modified settings and files, settings and files generated by resources on the local machine, user profile data, application files, and other data associated with a user and accessed, modified, or generated on the local machine responsive to an intercepted instruction. In another embodiment, the data associated with the identified isolation environment is synchronized with a copy of the data stored on a remote machine.
0144In one embodiment, a setting on the local machine may be a file. In another embodiment, the setting is an application file. For example, and in another embodiment, an application or other resource <b>302</b> includes a plurality of files. To install the resource <b>302</b>, the plurality of files is installed onto a machine <b>102</b>. In still another embodiment, the plurality of files may include registry keys, configuration files, and data files required to execute the resource <b>302</b>. In yet another embodiment, the plurality of files is stored in a user profile, which may also store other user settings in registry keys, configuration files, and data files. In some embodiments, a user executes an application, such as an installer application, to install a resource into an isolation environment. In one of these embodiments, the requests to modify settings in a user profile made by the installer application (for example, requests to read, write, edit, and create files, including registry keys, configuration files, and data files, in order to install a plurality of files associated with the resource) are intercepted by a filter driver <b>264</b> and redirected to the isolation environment, which generates a virtualized user profile.
0145Referring now to <figref idref="DRAWINGS">FIG. 5</figref>, a flow diagram depicts one embodiment of the steps taken in a method <b>500</b> for modifying, by a local resource, a setting in a virtualized user profile. In brief overview, the method includes the step of intercepting an instruction from a resource to modify a setting on a local machine, the resource provided by a local machine and executing outside an isolation environment (step <b>502</b>). The method includes the step of identifying the isolation environment, responsive to an application of a rule to the instruction (step <b>504</b>). The method includes the step of redirecting, to the identified isolation environment, the instruction to modify the setting (step <b>506</b>).
0146Referring now to <figref idref="DRAWINGS">FIG. 5</figref>, and in greater detail, an instruction from a resource to modify a setting on a local machine is intercepted (step <b>502</b>). In one embodiment, an instruction from an installer application to store a file on the local machine <b>102</b> is intercepted, the installer application executed by the user. In another embodiment, an instruction from the resource to install at least one application file on the local machine is intercepted, the at least one application file associated with an application the installer application attempts to install on the local machine <b>102</b>. In still another embodiment, an instruction from the resource to modify a setting in a user profile on the local machine is intercepted. In yet another embodiment, the filter driver <b>264</b> intercepts an instruction, from an installer application, to install an application file on the local machine, execution of the installer application initiated by a user of the local machine <b>102</b>.
0147An isolation environment is identified, responsive to an application of a rule to the request (step <b>504</b>). In one embodiment, the filter driver <b>264</b> identifies the isolation environment <b>256</b>. In another embodiment, the agent <b>410</b> receives the intercepted request from the filter driver <b>264</b> and identifies the isolation environment <b>256</b>. In still another embodiment, the isolation environment <b>256</b> is selected as described above in connection with <figref idref="DRAWINGS">FIG. 4</figref>.
0148In one embodiment, a user executes the resource issuing the instruction to modify the setting on the local machine. In some embodiments, the user executes the resource, an installer application, to make an application available on the local machine <b>102</b>. In one of these embodiments, the user subsequently requests access to the application available on the local machine <b>102</b> from a second local machine <b>102</b>′. In another of these embodiments, interception of installation instructions, redirection to an installation environment, and copying of the installation files to a centralized location accessible to the second local machine <b>102</b>′ allows the user to install an application on one machine and access a copy of the requested application from a second machine. In still another of these embodiments, the data stored by the isolation environment and copied to the centralized location form a virtualized user profile.
0149In other embodiments, the user executes an installer application to make a resource available to a plurality of users; for example, the user may execute an installer application installing a resource onto a local machine and the agent <b>310</b> may redirect the installation into an isolation environment generating a virtualized user profile for each member in a group of users. In one of these embodiments, the agent <b>320</b> creates an instance of a group profile for each user in the plurality of users. In another embodiment, an agent <b>310</b> on the local machine <b>102</b> retrieves an instance of the group profile associated with a user of the local machine <b>102</b>. In yet another embodiment, the group profile contains an application file for executing, on the local machine <b>102</b>, a resource <b>302</b> stored in the user profile, the resource <b>302</b> installed by a user in the plurality of users on a second local machine <b>102</b>.
0150The request to modify the setting on the local machine is redirected to the identified isolation environment (step <b>506</b>). In one embodiment, an application file is stored by the identified isolation environment <b>256</b>. In another embodiment, the setting on the local machine <b>102</b> is also modified as instructed. In still another embodiment, data stored by the isolation environment <b>256</b> is synchronized with a copy of the data stored on a remote machine <b>106</b>.
0151In one embodiment, the filter driver <b>264</b> redirects the instruction to the agent <b>410</b>, which makes a copy of the modified setting prior to allowing the instruction to modify the setting on the local machine to pass to the file system. In still another embodiment, the agent <b>310</b> transmits the copy of the modified setting to an agent <b>320</b> for packaging and storing on a file server <b>106</b>′ for later access by the user. In yet another embodiment, the agent <b>310</b> transmits the copy of the modified setting to a packaging mechanism, as described above in connection with <figref idref="DRAWINGS">FIG. 2A-2B</figref>.
0152In one embodiment, the agent <b>310</b>, in communication with a management service <b>204</b> on a remote machine <b>106</b>, identifies an installed application for publication. In another embodiment, the installed application is an application comprising a plurality of files whose installation was redirected to an isolation environment. In still another embodiment, the agent <b>310</b> identifies a subset of data stored in the isolation environment <b>256</b> as an installed application. In still even another embodiment, the agent <b>310</b> identifies the installed application for publication to the agent <b>320</b>, which transmits the identification to a management service <b>204</b>. In yet another embodiment, the agent <b>310</b> communicates with the common application subsystem <b>224</b> to publish the application as described above in connection with <figref idref="DRAWINGS">FIG. 2A-2B</figref>.
0153In one embodiment, a copy of data stored on the remote machine <b>106</b> and associated with the isolation environment <b>256</b> on the local machine <b>102</b> is synchronized with a copy of the data stored on a second remote machine <b>106</b>′ and associated with a second isolation environment <b>256</b>′. In some embodiments, the second isolation environment <b>256</b>′ is generated upon interception of the request by a user to execute the second resource <b>302</b>′. In one of these embodiments, the copy of the data stored on the remote machine <b>106</b> and associated with the isolation environment <b>256</b> on the local machine <b>102</b> is synchronized with data stored in the second isolation environment <b>256</b>′ upon generation of the second isolation environment. In another of these embodiments, the copy of the data stored on the remote machine <b>106</b> and associated with the isolation environment <b>256</b> on the local machine <b>102</b> is synchronized with data stored in the second isolation environment <b>256</b>′ upon interception of a request from the second resource <b>302</b> to access the data.
0154In another embodiment, a second filter driver <b>264</b>′ intercepts a request, by a second resource <b>302</b>′ executing on the second remote machine <b>102</b>′, for access to a setting on the second remote machine <b>102</b>′. In still another embodiment, the intercepted request is responded to with the synchronized data associated with the second isolation environment <b>256</b>′ on the second remote machine <b>102</b>′. In some embodiments, the synchronized data is an application file in a plurality of application files forming an executable resource. In one of these embodiments, the intercepted request is a request for the application file, which is accessed to execute the resource. In other embodiments, the second resource is executed responsive to the synchronized data from the second remote machine <b>102</b>′. In still other embodiments, the second resource <b>302</b>′ executes inside an isolation environment on the second remote machine <b>102</b>′. In yet other embodiments, the second resource <b>302</b>′ executes outside an isolation environment on the second remote machine <b>102</b>′.
0155In one embodiment, a second filter driver <b>264</b>′ intercepts the request, by a second resource <b>302</b>′ executing on a remote machine <b>102</b>, for access to a setting on the remote machine <b>102</b>. In another embodiment, the requested setting is retrieved from a copy of the data associated with the isolation environment <b>256</b> on the local machine and stored on a second remote machine <b>106</b>′. In still another embodiment, the requested setting is retrieved from the second remote machine <b>106</b>′, responsive to a determination that the second isolation <b>256</b>′ on the remote machine <b>102</b> does not contain the setting. In yet another embodiment, the intercepted request is responded to using the retrieved setting. In some embodiments, the synchronized data is an application file in a plurality of application files forming an executable resource. In one of these embodiments, the intercepted request is a request for the application file, which is accessed to execute the resource. In other embodiments, the second resource is executed responsive to the synchronized data from the second remote machine <b>102</b>′.
0156In some embodiments, a setting in a user profile is associated with a user-installed resource <b>302</b>. In one of these embodiments, the setting provides data for generating a graphical representation, or icon, of the user-installed resource <b>302</b>. In another of these embodiments, the graphical representation is associated with an instruction to intercept requests triggered by user interactions with the graphical representation. For example, and in still another of these embodiments, when a user selects the graphical representation to request execution of a resource <b>302</b> associated with the graphical representation, the filter driver <b>264</b> intercepts a command to execute the resource. In still even another of these embodiments, filter driver <b>264</b> redirects the request to an agent <b>410</b>. In still another of these embodiments, the agent <b>410</b> determines whether to provide access to a file needed to execute in the requested resource <b>302</b> from the copy of the user profile in the isolation environment <b>256</b> or by requesting the necessary file from a remote machine <b>106</b> storing a copy of the user profile including the file. In yet another of these embodiments, the identified one of the isolation environment <b>256</b> and the remote machine <b>106</b> responds to the request with the file, resulting in execution of the requested resource <b>302</b>.
0157In some embodiments, storing a plurality of application files in the user profile allows a user to select and install resources. In one of these embodiments, the user may execute an installation resource <b>302</b> to install a second resource <b>302</b>′, the installation resource <b>302</b> attempting to install the second resource <b>302</b>′ on the local machine <b>102</b>. In another of these embodiments, the installation resource <b>302</b> is allowed to install a second resource <b>302</b>′ directly onto the local machine <b>102</b>. In still another of these embodiments, instructions by the installation resource <b>302</b> for the installation of a resource <b>302</b> are directed to an isolation environment <b>256</b>. In another of these embodiments, the application files that comprise the resource <b>302</b> are stored in the isolation environment <b>256</b>. In still another of these embodiments, the application files that comprise the resource <b>302</b> are executed within the isolation environment <b>256</b>. In still even another of these embodiments in which a user profile is stored on a remote machine, when the user accesses a different computing environment than the environment in which the user installed the resource <b>302</b>—for example, from a second machine <b>102</b>′—the user profile may be synchronized with a user profile on the second machine <b>102</b>′, making the installed resource <b>302</b> available to the user from the second machine <b>102</b>′. In yet another of these embodiments, in synchronizing the user profile on the remote machine with the user profile on the second machine <b>102</b>′, the system allows a user to more rapidly and efficiently access a resource not previously installed on the second machine <b>102</b> while providing the user with a mechanism (such as the agent <b>410</b>) for maintaining synchronized files and data for later use from yet other computing environments.
0158The systems and methods described above may be provided as one or more computer-readable programs embodied on or in one or more articles of manufacture. The article of manufacture may be a floppy disk, a hard disk, a CD-ROM, a flash memory card, a PROM, a RAM, a ROM, or a magnetic tape. In general, the computer-readable programs may be implemented in any programming language, LISP, PERL, C, C++, PROLOG, or any byte code language such as JAVA. The software programs may be stored on or in one or more articles of manufacture as object code.
0159Having described certain embodiments of methods and systems for accessing, by A local resource, a setting in a virtualized user profile, it will now become apparent to one of skill in the art that other embodiments incorporating the concepts of the disclosure may be used. Therefore, the disclosure should not be limited to certain embodiments, but rather should be limited only by the spirit and scope of the following claims.
Contents6
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10419504B1 | Cited by | United States of America | Search report |
| US2011296526A1 | Cited by | United States of America | Pre-grant |
| US9584562B2 | Cited by | United States of America | Search report |
| US8707288B2 | Cited by | United States of America | Search report |
| US11803405B2 | Cited by | United States of America | Applicant |
| US2014372430A1 | Cited by | United States of America | Pre-grant |
| US2010211941A1 | Cited by | United States of America | Pre-grant |
| GB2479511A | Cited by | United Kingdom | Search report |
| US8640126B2 | Cited by | United States of America | Applicant |
| US2010070870A1 | Cited by | United States of America | Pre-grant |
| US2011225576A1 | Cited by | United States of America | Pre-grant |
| US11698885B2 | Cited by | United States of America | Applicant |
| US10606634B1 | Cited by | United States of America | Applicant |
| WO2013192023A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10592942B1 | Cited by | United States of America | Applicant |
| US2015078373A1 | Cited by | United States of America | Pre-grant |
| US11983196B2 | Cited by | United States of America | Search report |
| US9258382B2 | Cited by | United States of America | Applicant |
| US11538078B1 | Cited by | United States of America | Applicant |
| US9210211B2 | Cited by | United States of America | Search report |
| US10419504B1 | Cited by | United States of America | Search report |
| US12455936B2 | Cited by | United States of America | Applicant |
| US10693917B1 | Cited by | United States of America | Applicant |
| US9940466B2 | Cited by | United States of America | Applicant |
| US11301431B2 | Cited by | United States of America | Search report |
| US12603932B2 | Cited by | United States of America | Search report |
| US2015201009A1 | Cited by | United States of America | Pre-grant |
| US2014372430A1 | Cited by | United States of America | Search report |
| US2010299436A1 | Cited by | United States of America | Pre-grant |
| US2009031251A1 | Cited by | United States of America | Pre-grant |
| US2009216975A1 | Cited by | United States of America | Pre-grant |
| US11314560B1 | Cited by | United States of America | Applicant |
| US2014156805A1 | Cited by | United States of America | Pre-grant |
| US9444883B2 | Cited by | United States of America | Applicant |
| US12093429B2 | Cited by | United States of America | Applicant |
| US8914730B2 | Cited by | United States of America | Applicant |
| US2020336533A1 | Cited by | United States of America | Search report |
| US10896054B2 | Cited by | United States of America | Applicant |
| US10348780B2 | Cited by | United States of America | Applicant |
| US7882171B1 | Cited by | United States of America | Search report |
| US2015254455A1 | Cited by | United States of America | Pre-grant |
| WO2011111009A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11687610B2 | Cited by | United States of America | Applicant |
| US9241062B2 | Cited by | United States of America | Search report |
| US11741179B2 | Cited by | United States of America | Applicant |
| US10623243B2 | Cited by | United States of America | Applicant |
| US10142406B2 | Cited by | United States of America | Applicant |
| US12106137B2 | Cited by | United States of America | Applicant |
| US2016294980A1 | Cited by | United States of America | Search report |
| KR20150023425A | Cited by | Republic of Korea | Search report |
| WO2013192023A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US12455937B2 | Cited by | United States of America | Applicant |
| US2010107113A1 | Cited by | United States of America | Pre-grant |
| US8572066B1 | Cited by | United States of America | Applicant |
| US10686646B1 | Cited by | United States of America | Applicant |
| US9503542B1 | Cited by | United States of America | Search report |
| US2012036141A1 | Cited by | United States of America | Pre-grant |
| US8756227B2 | Cited by | United States of America | Search report |
| US10061605B2 | Cited by | United States of America | Applicant |
| US11016992B2 | Cited by | United States of America | Search report |
| US10120708B1 | Cited by | United States of America | Search report |
| US9288262B2 | Cited by | United States of America | Search report |
| US11880422B2 | Cited by | United States of America | Search report |
| US8984629B2 | Cited by | United States of America | Search report |
| US9906583B2 | Cited by | United States of America | Search report |
| US9584378B1 | Cited by | United States of America | Search report |
| US8806046B1 | Cited by | United States of America | Search report |
| US2016134683A1 | Cited by | United States of America | Pre-grant |
| US9467498B2 | Cited by | United States of America | Applicant |
| US2014372430A1 | Cited by | United States of America | Search report |
| US10616129B2 | Cited by | United States of America | Applicant |
| US9515954B2 | Cited by | United States of America | Applicant |
| EP3197132A1 | Cited by | European Patent Office (EPO) | Search report |
| CN102197374A | Cited by | China | Search report |
| US10313345B2 | Cited by | United States of America | Applicant |
| US11675930B2 | Cited by | United States of America | Applicant |
| US2012233235A1 | Cited by | United States of America | Pre-grant |
| WO2010093491A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10455055B2 | Cited by | United States of America | Search report |
| US8090744B1 | Cited by | United States of America | Search report |
| US2020250323A1 | Cited by | United States of America | Search report |
| US2021279256A1 | Cited by | United States of America | Search report |
| US8255806B2 | Cited by | United States of America | Search report |
| US9612823B2 | Cited by | United States of America | Applicant |
| US11314778B2 | Cited by | United States of America | Applicant |
| US11616821B1 | Cited by | United States of America | Search report |
| US2010268735A1 | Cited by | United States of America | Pre-grant |
| US9965622B2 | Cited by | United States of America | Search report |
| US11669359B2 | Cited by | United States of America | Applicant |
| US11314835B2 | Cited by | United States of America | Applicant |
| US9552366B2 | Cited by | United States of America | Applicant |
| US2002019941A1 | Cites | United States of America | Pre-grant |
| US2002099829A1 | Cites | United States of America | Pre-grant |
| US2002112155A1 | Cites | United States of America | Pre-grant |
| US2003126298A1 | Cites | United States of America | Pre-grant |
| US2005108297A1 | Cites | United States of America | Pre-grant |
| US2005234866A1 | Cites | United States of America | Pre-grant |
| US2005251516A1 | Cites | United States of America | Pre-grant |
| US2006070029A1 | Cites | United States of America | Pre-grant |
| US2006075381A1 | Cites | United States of America | Pre-grant |
10 members in 5 offices
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 86233506 | United States of America | P |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2008098006A1 | United States of America | A1 | |
| AU2007309183A1 | Australia | A1 | |
| CA2665873A1 | Canada | A1 | |
| WO2008051842A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008051842A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2078251A2 | European Patent Office (EPO) | A2 | |
| US8452812B2 | United States of America | B2 | |
| US2013246473A1 | United States of America | A1 | |
| US9418081B2 | United States of America | B2 | |
| EP2078251B1 | European Patent Office (EPO) | B1 |
92 transactions on the USPTO file
Allowed after 4 non-final rejections, 3 final rejections, 2 RCEs and 1 appeal.
- Non-final rejections
- 4
- Final rejections
- 3
- RCEs
- 2
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Year, Large EntityM1553 | M1553 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Post Issue Communication - Certificate of CorrectionN423 | N423 | |
| Mail-Petition Decision - DismissedMPTDI | MPTDI | |
| Petition Decision - DismissedPTDI | PTDI | |
| Adjustment of PTA Calculation by PTOP028 | P028 | |
| Petition EnteredPET2 | PET2 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner InitiatedEXIE | EXIE | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Applicant Initiated Interview SummaryMEXIA | MEXIA | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Mail Appeals conf. Reopen Prosec.MAPCR | MAPCR | |
| Pre-Appeals Conference Decision - Reopen ProsecutionAPCR | APCR | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Correspondence Address ChangeC.AD | C.AD | |
| Sent to Classification ContractorPGPC | PGPC | |
| Filing Receipt - UpdatedFLRCPT.U | FLRCPT.U | |
| Payment of additional filing fee/PreexamFLFEE | FLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Applicant has submitted new drawings to correct Corrected Papers problemsCORRDRW | CORRDRW | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| Fee paymentFPAY | FPAY | |
| Certificate of correctionCC | CC | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 20080098006
- Application
- 11875515
Titles
- English
- METHODS AND SYSTEMS FOR ACCESSING REMOTE USER FILES ASSOCIATED WITH LOCAL RESOURCES
Patent term adjustment
- A delay
- +340 daysthe office missed an examination deadline
- B delay
- +359 dayspendency past three years
- Applicant delay
- −31 days
- Net adjustment
- 875 days
Classification
- CPC, 7
- H04L67/1095
- G06F16/275
- H04L67/34
- H04L67/303
- H04L67/306
- H04L67/63
- G06F16/27
- IPC, 1
- G06F17 30