发明名称 Generating secure roaming user profiles over a network
摘要 Embodiments are directed to providing access to a resource over a network. A client device may request access to a server. An application may be provided to the client device. The application may cause control of the client device to be switched from a first desktop to a secure desktop. The secure desktop may be configured to restrict applications access to within the secure desktop. An indication of the resource on the server to map to may be received at the client device. The indicated resource may be mapped onto a file system on the client device. Mapping may comprise using a remote file access protocol, using DLL injection, or adding a kernel module to an operating system on the client device. The mapped resource may be constrained to be accessed through the secure desktop.
申请公布号 US8955050(B1) 申请公布日期 2015.02.10
申请号 US201314080635 申请日期 2013.11.14
申请人 F5 Networks, Inc. 发明人 Shigapov Andrey
分类号 G06F7/04;G06F15/16;G06F17/30;H04L29/06;G06F21/62;H04L29/08 主分类号 G06F7/04
代理机构 Lowe Graham Jones PLLC 代理人 Branch John W.;Lowe Graham Jones PLLC
主权项 1. A network device for providing access to a resource over a network, comprising: a memory arranged to store data and instructions; and a processor arranged to enable actions embodied by at least a portion of the stored instructions, the actions comprising: selectively sending an application over the network to a client device, the client device having an operating system, the application configured to provide a secure desktop on the client device, and automatically switching control of the client device to the secure desktop; wherein access to resources is restricted by the secure desktop to being performed through the secure desktop; receiving a resource request from the client device to map onto a file system controlled by the secure desktop; restricting access to a requested resource indicated as being a non-mapped resource to read-only; and otherwise, enabling a mapping of the requested resource onto the secure desktop, wherein mapping the resource further includes adding to the operating system of the client device a kernel module configured to provide access to the resource; and when the secure desktop is closed, unmapping the requested resource, and further when the requested resource is cached on the client device, sending the requested resource to a server to synchronize the resource with the server.
地址 Seattle WA US