US2002184398A1PendingUtilityA1

Secured system for accessing application services from a remote station

Priority: Dec 18, 1996Filed: Apr 17, 2002Published: Dec 5, 2002
Est. expiryDec 18, 2016(expired)· nominal 20-yr term from priority
H04L 67/01H04L 9/40H04L 69/329H04L 67/08H04L 63/105G06F 21/6218H04L 63/10G06F 9/5055
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secured system for accessing application services from at least one application program where at least one client station having low-level application independent logics stored therein and at least one controller for controlling the low-level application independent logics, the low-level application logics including a user interface logic, a device control logic for controlling devices, a file system logic, and a communication interface logic, and wherein at least one client station has means to restrict access to said application independent logics, at least one application server having high-level application logic stored in a server device for running at least one application program, the server device being coupled to said at least one application server and low-level interface between said at least one client station and said at least one server for connecting said at least one client station to said at least one application server, wherein upon accessing by said at least one client station, said at least one application server runs at least one application program which selectively controls said low-level application independent logics for controlling devices of said at least one client station and accessing data of said at least one client station without permanently storing said at least one client station data in said at least one server. There is also a description of a secure operating system and method and a secured system and method of construction of a computer system as well as description of system and method of how to preserve a running current state of an application program for security and relocation purpose.

Claims

exact text as granted — not AI-modified
I claim:  
     
         1 . A secure system for accessing application services from at least one application program, comprising: 
 at least one client station having application independent logics stored therein and at least one controller for controlling said application independent logics, said application independent logics including at least one of a user interface logic, a device control logic for controlling devices, a file system logic, and a communication interface logic;    at least one application server having application logic stored in a server device for running said at least one application program, said server device being coupled to said at least one application server; and    an interface between said at least one client station and said at least one application server for connecting said at least one client station to said at least one application server;    wherein upon accessing by said at least one client station, said at least one application server runs said at least one application program which selectively controls said application independent logics for controlling devices of said at least one client station and for accessing data of said at least one client station, and wherein said at least one application server is able to process said corresponding data of said at least one client station on said at least one application program.    
     
     
         2 . The system of  claim 1 , wherein said application independent logics consist of a finite set of further indivisible (primitive) application independent logics, wherein each said indivisible application independent logic can be individually accessed and controlled by said at least one application program.  
     
     
         3 . The system of  claim 2 , wherein said at least one client station is able to restrict access to said application independent logics by selectively refusing processing of said primitive logics for said at least one application program running on said at least one application server.  
     
     
         4 . The system of  claim 2 , wherein said at least one client station includes a means to associate a finite subset of said further indivisible application independent logics with said at least one application program running on said at least one application server, wherein said at least one application program is able to access and control said finite subset of said indivisible application logics and is unable to access and control other indivisible application independent logics.  
     
     
         5 . The system of  claim 2 , wherein said at least one client station is able to restrict access to said application independent logics by restricting what data can be used in processing of said primitive logics for said at least one application program running on said at least one application server.  
     
     
         6 . The system of  claim 4 , wherein said client station user controls which specific indivisible application independent logics are part of said subset which can be controlled by said at least one application program running on said at least one application server.  
     
     
         7 . The system of  claim 1 , wherein said at least one client station has means to store the state of said at least one application program to enable said at least one client station to restart said at least one application program at a later time at the same point in the said at least one application program.  
     
     
         8 . The system of  claim 7 , wherein said at least one application server encrypts said state of said at least one application program to protect said at least one application program state and to protect said at least one application server from corruption by said at least one client station by corrupting said state of said at least one application program.  
     
     
         9 . A computing machine comprising: 
 at least one user interface and input/output device (user console) having application independent logics stored therein and at least one controller for controlling said application independent logics, said application independent logics including at least one of a user interface logic, a device control logic for controlling devices, a file system logic, and a communication interface logic, and wherein said at least one user interface and input/output device has means to restrict access to said application independent logics;    at least one computational device having means to store application logic in said at least one computational device for running said at least one application program; and    an interface between said at least one user console and said at least one computational device for connecting said at least one user console to said at least one computational device,    wherein upon accessing by said at least one user console, said at least one computational device runs said at least one application program which selectively controls said application independent logics for controlling devices of said at least one user console and for accessing data of said at least one user console, and wherein said at least one computational device processes said corresponding data from said at least one user console on said at least one application program without having to permanently store said data in said at least one computational device.    
     
     
         10 . The system of  claim 9 , wherein said file system logic includes a file system capable of storing data corresponding to said at least one application program.  
     
     
         11 . The system of  claim 9 , wherein said application program is an operating system program to control said at least one computational device.  
     
     
         12 . The system of  claim 10 , wherein said operating system program code is retrieved by said at least one computational device from said at least one user console.  
     
     
         13 . The system of  claim 9 , wherein said operating system program is able to control said interface between said at least one user console and said at least one computational device.  
     
     
         14 . The system of  claim 9 , wherein said interface includes a common communication transport protocol.  
     
     
         15 . The system of  claim 9 , wherein said at least one computational device may select one of a plurality of operating system programs.  
     
     
         16 . A secure Operating System comprising: 
 at least one user interface and input/output software module (user console kernel) having application independent logics and at least one means for controlling said application independent logics, said application independent logics including at least one of a user interface logic, a device control logic for controlling devices, a file system logic, and a communication interface logic, and wherein said at least one user interface and input/output software module has means to restrict access to said application independent logics;    at least one computational software module (process kernel) having means to run application logic for running said at least one application program; and    an interface (operating system interface/OSSI) between said at least one user console kernel and said at least one computational kernel for connecting said at least one user console kernel to said at least one computational kernel,    wherein upon accessing by said at least one user console kernel, said at least one computational kernel runs said at least one application program which selectively controls said application independent logics for controlling application independent logics of said at least one user console kernel and for accessing data of said at least one user console kernel, and wherein said at least one computational kernel processes said corresponding data from said at least one user console kernel on said at least one application program.    
     
     
         17 . The system of  claim 16 , wherein said at least one user console kernel and said at least one process kernel run on separate physical devices.  
     
     
         18 . The system of  claim 16 , wherein said at least one user console kernel program and said at least one process kernel program have private program and data memory and wherein each of them is unable to access said program and data memory of the other.  
     
     
         19 . The system of  claim 14 , wherein said common communication transport protocol is TCP/IP.  
     
     
         20 . The system of  claim 1 , wherein said file system logic includes a file system capable of storing data corresponding to said at least one application program.  
     
     
         21 . A method of securely accessing application services from at least one application program, comprising the steps of: 
 accessing at least one application server by at least one client station to connect to said at least one application program running on said at least one application server;    wherein said at least one client station has application independent logics stored therein and at least one controller for controlling said application independent logics, said application independent logics including at least one of a user interface logic, a device control logic for controlling devices, a file system logic, and a communications interface logic; and    wherein said at least one application server has application logic stored in a server device coupled to said at least one application server, for running said at least one application program;    having said at least one application server selectively interact with said application independent logics to retrieve data corresponding to said at least one application program from said at least one client station upon optional authorization from said at least one client station;    processing said corresponding data on said at least one application program; and    without having to permanently store said data within said at least one application server when said application services are complete.    
     
     
         22 . The method of  claim 21 , wherein said file system logic includes a file system capable of storing data corresponding to said at least one application program.  
     
     
         23 . A secure system for managing devices and/or file systems of at least one client station, comprising: 
 at least one application server having application logic stored within a server device coupled to said at least one application server for running at least one management application program, and said at least one application server being capable of accessing multiple devices and file systems, each coupled to at least one respective client station, when each client station interfaces with said at least one application server to access said at least one application program;    wherein each interfaced server selectively accesses said devices, said file systems or both to form a centralized device and file management system for controlling and accessing devices, file systems, states, or configurations of said at least one client station;    wherein upon accessing by said client stations, said at least one application server runs at least one application program and selectively controls application independent logics of said at least one client station for controlling devices of said at least one client station and for accessing data of said at least one client station; and    wherein said at least one application server is able to process said corresponding data of said at least one client station on said at least one application program without having to permanently store said data in a server device coupled to said at least one application server or within said application server.    
     
     
         24 . A secure system for accessing application services from at least one service application, comprising: 
 at least one client station having at least a special purpose operating system stored therein for supporting said at least one client station connections to at least one application server and application independent logics stored therein, said special purpose operating system comprising application independent logics including at least one of a user interface logic, a device control logic for controlling devices, a file system logic, and a communication interface logic, wherein said at least one application server runs said at least one service application which controls said application independent logics stored within said at least one client station for controlling said special purpose operating system and devices of said at least one client station; wherein said at least one service application is at least one of software service application or hardwired service applications.    
     
     
         25 . A method of converting a conventional application program which has application programming interface specific to a particular operating system to a network application program which communicates with a client station via an operating system service interface communications protocol, comprising the steps of: 
 substituting operating system function calls of said conventional application program with code for generating command packets using said operating system service interface communications protocol, without modifying application code of said conventional application program, to convert said conventional application program to said network application program so that an application server is able to transport the command packets to said client station for controlling specific operating system or device operations of said client station;    wherein said code which generates command packets has identical application programming interface to said operating system functions of said particular operating system; and    wherein said network application program runs within an application server, accesses data of said client station, and is able to control specific operating system and device operations of said client station, when said client station connects to said network application program, as required by said network application program.    
     
     
         26 . An application service provider system, comprising: 
 at least one processing element containing application service logics therein;    at least one communication interface through which said system can be accessed; and    wherein said application service provider provides a service to an user system, said user being a client of said application service provider, by giving an user device access to said processing element via said communication interface for processing data corresponding to said user system on said application service logics without having to permanently co-locate said data with said application service provider system.    
     
     
         27 . A managed application service provider system, comprising: 
 at least one processing element containing application service logics therein;    at least one communication interface through which said system can be accessed;    at least one means to manage, update, maintain, or monitor said application service logics; and    wherein said application service provider system provides a service to an user, said user being a client of said application service provider, by giving an user device access to said processing element via said communication interface for processing data corresponding to said user on said application service.    
     
     
         28 . A collaborative application service system for sharing of data and devices, comprising: 
 at least one processing element containing application logics therein;    at least one communication interface through which said system can be accessed;    wherein said at least one processing element is accessed by at least two client devices via said at least one communication interface and said processing element performs said application service for said at least two client devices by processing and mediating exchange of data, according to said application logics, for said at least two client devices; and    wherein said at least one processing element retrieves said data corresponding to at least one of said at least two client devices, processes said data, and makes said processed data available to at least one of said at least two client devices.    
     
     
         29 . An application service system for managing of client devices, comprising: 
 at least one processing element containing managing application logics therein;    at least one communication interface through which said system can be accessed; and    wherein said at least one processing element is accessed by at least one client device via said at least one communication interface and said processing element performs said managing application service for said at least one client device by at least one of monitoring said client device state to insure correct operation, by modifying said client device state to an up to date state, by updating data of said client device, by interacting with said client device logics in order to control, access and manage other devices which may be coupled to said client device.    
     
     
         30 . A system to provide application services, comprising: 
 at least one processing element containing application logics therein;    at least one communication interface through which said system can be accessed; and    wherein said at least one processing element is accessed via said at least one communication interface by a client device and said processing element performs said application services for said at least one accessing client device by exchanging data, said data corresponding to said at least one client device, with said at least one client device and processing said data according to said application logics.    
     
     
         31 . The system of  claim 26 , wherein said application logics are loaded into said processing element from another device coupled to said system.  
     
     
         32 . The system of  claim 26 , wherein said user or client device cannot access code or instructions of said application service logics.  
     
     
         33 . The system of  claim 26 , wherein access to said application logics is limited to exploiting of functioning of said application logics for processing of data and precludes copying or examining of said application logics.  
     
     
         34 . The system of  claim 26 , further comprising of at least one means to access data corresponding to said at least one client device from sources other than said at least one client device.  
     
     
         35 . The system of  claim 34 , wherein said client device is able to restrict which said data, from sources other than said client device, may be accessed by said at least one means.  
     
     
         36 . The system of  claim 26  wherein said at least one processing element containing said application logics can be shared by a plurality of unrelated users and client devices without having to share data sources.  
     
     
         37 . The system of  claim 26 , further comprising at least one means to convert conventional application program operating system software calls to communication command packets for interacting with said at least one accessing client device; and 
 wherein said application logics are defined by said conventional application program and said at least one means enables said conventional application program to be accessed as said application services.    
     
     
         38 . The system of  claim 26 , wherein said exchange of data occurs according to a pre-agreed communication protocol known to said system for provisioning application services and known to said at least one client device.  
     
     
         39 . The system of  claim 26 , wherein access to said application services may be partially or entirely restricted for said at least one client device according to authorization of said at least one client device.  
     
     
         40 . The system of  claim 26 , wherein access to said application services may be partially or entirely restricted for said at least one client device according to criteria independent of said at least one client device.  
     
     
         41 . The system of  claim 40 , wherein said criteria may include at least one of time of day, date, geographical location, and other parameters.  
     
     
         42 . The system of  claim 26  which in addition comprises an interface to a persistent storage device, said device being able to store data not being processed by said processing element.  
     
     
         43 . The system of  claim 26 , in addition comprising the means to do at least one of managing, monitoring, maintaining, or updating said application logics and of managing, maintaining, or monitoring said processing element.  
     
     
         44 . The system of  claim 43 , wherein said means can be controlled via at least one communication interface.  
     
     
         45 . The system of  claim 44 , wherein said one means to manage, update, maintain, or monitor said application service logics is controlled through said at least one communication interface by an application service provider to manage, update, maintain, or monitor said application service logics.  
     
     
         46 . The system of  claim 44 , wherein said one means to manage, update, maintain, or monitor said application service logics is controlled through said at least one communication interface by an authorized user in a self-service application service provider system.  
     
     
         47 . The system of  claim 26 , in addition comprising at least one means to account for usage of said system for the purpose of selling said application services.  
     
     
         48 . The system of  claim 26 , in addition comprising at least one storage device containing code of said application logics and containing data needed by said application logics for providing said application services.  
     
     
         49 . The system of  claim 48 , wherein said system either partially or entirely restricts access to said at least one storage device by client devices to prevent copying or corruption of said code.  
     
     
         50 . The system of  claim 26 , wherein said system is unable to initiate a connection to a client device without said client device first initiating a connection to said system.  
     
     
         51 . The system of  claim 30 , wherein said application services are directory application services which provide client devices with information about other application services and/or where on a network to locate said other application services and/or how to connect to said other application services.  
     
     
         52 . The system of  claim 26 , wherein an application service provider provides physical space, electric power, physical security, hardware maintenance, and communication interfaces for said system.  
     
     
         53 . The system of  claim 28 , wherein said processing of said data by at least one processing element is limited to forwarding of said data from at least one client device of said at least two client devices to another one of said at least two client devices.  
     
     
         54 . The system of  claim 28 , wherein said at least two client devices are unable to communicate with each other directly but are able to communicate with said system for exchanging of said data by using said application logics.  
     
     
         55 . The system of  claim 26 , said application service system further includes operating system software wherein a subset of operating system function calls made by said application logics, said application logics being executed within said operating system software, is converted to communication command packets and dispatched to client devices, therefore protecting said operating system software and said application services system from being improperly accessed or corrupted by said application logics.  
     
     
         56 . A client system for accessing application services, comprising: 
 at least one communication interface through which to access said application services;    at least one processing element containing application independent logics therein; and    wherein upon connecting to a server providing application services, said server is able to control functioning of said client system by controlling said application independent logics through said at least one communication interface in order to provide said application services.    
     
     
         57 . The system of  claim 56 , wherein said application independent logics are limited to application independent logics which are incapable of permanently changing the state of said client system.  
     
     
         58 . The system of  claim 57 , wherein said application independent logics are limited to user interface application independent logics.  
     
     
         59 . The system of  claim 56 , wherein said processing element is a special purpose device for processing said application independent logics and said device is unable to process application logics in order to protect said client system from internal state corruption by mobile application logics code and to decrease cost of said client system.  
     
     
         60 . The system of  claim 56 , further comprising at least one means for accessing and controlling other devices coupled to said client system; 
 wherein said application independent logics contained in said at least one processing element in addition include application independent logics for accessing and controlling said other devices, said other devices coupled to said client system, by utilizing said at least one means; and    wherein said server providing application services is able to control said other devices, said other devices coupled to said client system, by controlling said application independent logics contained therein said at least one processing element.    
     
     
         61 . The system of  claim 60 , wherein said other devices, coupled to said system, may include at least one storage device for storing data corresponding to said application services.  
     
     
         62 . The system of  claim 56 , wherein said system further comprises of at least one storage device for storing data corresponding to said application services.  
     
     
         63 . The system of  claim 61 , wherein said one storage device may include a file system therein.  
     
     
         64 . The system of  claim 60 , wherein said at least one means for accessing and controlling said other coupled devices is a communication interface.  
     
     
         65 . The system of  claim 60 , wherein said other coupled devices may include at least one of user interface device or communication device or data acquisition device.  
     
     
         66 . The system of  claim 56 , wherein said communication interface data transmission is carried over at least one of wireless network, local area network, wide area network  
     
     
         67 . The system of  claim 66 , wherein said wide area network is the Internet.  
     
     
         68 . The system of  claim 56 , wherein said client system loads said application independent logics from another device, said device being coupled to said system, before said system is able to access said application services.  
     
     
         69 . The system of  claim 68 , wherein said loading of said application independent logics is done by using at least one communication interface.  
     
     
         70 . The system of  claim 63 , wherein said data corresponding to said application services is stored in at least one file of said file system.  
     
     
         71 . The system of  claim 70 , wherein said system/device for accessing application services is able to selectively restrict access by at least one system providing application services, said at least one file corresponding to said application services, to said at least one file in order to protect said client system/device for accessing application services from internal state corruption and to prevent unauthorized access of said file by said at least one system for providing application services.  
     
     
         72 . The system of  claim 56 , wherein said client system/device, further comprises of means to restrict access of said application independent logics to a limited subset of the entire set of said application independent logics.  
     
     
         73 . The system of  claim 72 , wherein said subset is chosen for said application services based on at least one of security profile of said application services, and said application server and security profile of said client system/device.  
     
     
         74 . The system of  claim 73 , wherein said security profiles may be based on how secure said application server is believed to be, and what type of damage or loss may be caused by said application server by processing any one particular application independent logic.  
     
     
         75 . The system of  claim 74 , wherein said damage or loss may include corruption and loss of data, unauthorized copying of data, unauthorized use of said client system resources.  
     
     
         76 . The system of  claim 72 , wherein said limited subset is a different subset for different combinations of said client system and said application services.  
     
     
         77 . The system of  claim 56 , wherein said at least one processing element is able to decline to process a particular application independent logic based on data supplied with and for processing said particular application independent logic.  
     
     
         78 . The system of  claim 34 , wherein said client device provides to said processing element location of said other data sources and information necessary to access said other data sources before said application services commence.  
     
     
         79 . The system of  claim 34 , wherein said processing element determines location and information necessary to access said other data sources by determining identity of said client device.  
     
     
         80 . The system of  claim 34 , wherein said client device inputs data from or outputs data to said other devices and exchanges said data with said at least one processing element as needed by said application logics.  
     
     
         81 . The system of  claim 55 , wherein said client system further comprises of special purpose operating system, said special purpose operating system implementing all functions of said client system by controlling said at least one processing element and said at least one communication interface.  
     
     
         82 . The system of  claim 26 , further comprising of means to determine the current state of said application services being provided to said at least one client device, wherein said current state may be preserved in a storage device and said application services suspended in order to save said system memory and computational resources.  
     
     
         83 . The system of  claim 82 , wherein said suspension of said application services is caused by at least one of client device request, idleness of said client device, failure of said communication interface.  
     
     
         84 . The system of  claim 82 , wherein said application services can be restarted at the same point by using said preserved current state upon said client device reconnection.  
     
     
         85 . The system of  claim 26 , wherein said communication interface includes a set of application independent functions for encoding command data packets with required parameter data and dispatching said command data packets to said client device in order to control application independent logics within said client device.  
     
     
         86 . The system of  claim 85 , wherein said dispatching of command data packets is done over at least one of available transport protocols and is done over at least one of wired and wireless physical medium.  
     
     
         87 . A method for at least two client devices to share data and devices coupled to said at least two client devices, comprising the steps of: 
 said at least two client devices wanting to share data or accessing one or more other devices, said other devices coupled to said at least two client devices, connecting to an application service server, said application server containing sharing application logics therein;    said at least two client devices interacting with said sharing application logics to access data and other devices coupled to another one of said at least two client devices; and    wherein said sharing application logics control said two client devices as needed to provide said sharing service.    
     
     
         88 . The method of  claim 87 , wherein said sharing application service server may use different communication protocols to interact with different ones of said at least two devices.  
     
     
         89 . The method of  claim 87 , said at least two client devices and said sharing application service server perform a step of mutual authentication to insure that said at least two client devices are authorized to use said sharing application service and that said application service logics are authorized to access data and other devices coupled to each of said at least two client devices, so that one of said at least two client devices can access data and other coupled devices of another one of said at least two client devices, with this step being performed before said sharing application services can proceed.  
     
     
         90 . The method of  claim 87 , in addition performing at least one step of accounting or metering usage of said application services to establish said application service value.  
     
     
         91 . A method for providing know-how for specialized data processing services without disclosing said know-how, comprising the steps of: 
 encoding said know-how for performing said specialized data processing in a software application and integrating said software application with a processing element or hardwiring said know-how within said processing element;    providing a communication protocol within said processing element to accept data for processing and for outputting processed data;    attaching said processing element, containing said know-how, to an interface, said interface being accessible to at least one client device;    accepting connections from said at least one client device needing said know-how to process data corresponding to said at least one client device;    retrieving data corresponding to said at least one client device, as needed by said software application or said hard-wired know-how logics;    making processed data available to said at least one client device; and    never disclosing said know-how to said at least one client device.    
     
     
         92 . The method of  claim 91 , wherein in said retrieving data step said corresponding data is internal state data of said at least one client device.  
     
     
         93 . The method of  claim 91 , wherein in said making processed data available step said processed data is control data in order to control operations of said at least one client device.  
     
     
         94 . A system to provide access to know-how for a business or industrial data processing task and to means for performing said business or industrial task according to said know-how, comprising: 
 at least one processing element containing said know-how logics as a software application code or hardwired logics;    at least one interface through which a client device needing said know-how could access said means; and    wherein said system can interact with said client device, when said client device connects with said system, and/or with other data sources, said other data sources corresponding to said client device, to perform said business or industrial task according to said know-how without having to transfer said know-how logics to said client device.    
     
     
         95 . A system enabling an individual or a company to provide access to his/its computerized know-how of a useful data processing process combined with means for performing said useful data processing process according to said know-how, comprising: 
 at least one processing element containing said know-how logics as a software application code or hardwired logics;    at least one interface through which a client device needing said know-how could access said means; and    wherein upon connecting of said client device, said system can interact with said client device and can perform said useful process according to said know-how without having to transfer said know-how logics to said client device.    
     
     
         96 . The system of  claim 95 , wherein said system in addition can interact with at least one, other than said client device, data source, said at least one data source needed for performing said useful process.  
     
     
         97 . The system of  claim 95 , wherein said useful process is a business process, an industrial process, an educational process, or an entertainment process.  
     
     
         98 . The system of  claim 95 , wherein said at least one interface is connected over any physical medium known to transmit information.  
     
     
         99 . System of  claim 1  wherein said at least one application server is able to process said corresponding data without having the necessity to permanently store said data in said at least one application server or in a server device coupled to said at least one application server.  
     
     
         100 . System of  claim 1  wherein said at least one client station is able to restrict access to said application independent logics.

Join the waitlist — get patent alerts

Track US2002184398A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.