Bidirectional Attestation for Context-Aware Workspace Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inefficient and burdensome, consuming significant memory and processing resources while failing to account for the context of IHS usage, leading to degraded productivity and insufficient data protection.

Innovation Solution

Implement bi-directional attestation for workspace orchestrators, where an IHS receives requests from a workspace orchestrator to attest workspace components, sending an indication to an attester and receiving attestation evidence signed with an attestation key, considering factors like user identity, locale, network, hardware, and risk metrics to optimize workspace instantiation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but memory and processing resources are significantly consumed

Engineering Contradiction:
Improvedata securityVSAvoidmemory and processing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic workspace instantiation that adapts to context factors (user identity, locale, network, hardware, risk metrics) rather than using static conventional virtualization. This allows the system to create workspaces only when needed and terminate them when not in use, optimizing resource utilization while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameters of workspace configuration based on context assessment. Instead of always using full virtualization, the system adjusts workspace parameters (isolation level, resource allocation, duration) based on the assessed risk and context factors, reducing resource consumption while maintaining adequate security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but productivity is degraded

Engineering Contradiction:
Improvedata securityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic workspace instantiation that adapts to context factors (user identity, locale, network, hardware, risk metrics) rather than using static conventional virtualization. This allows the system to create workspaces only when needed and terminate them when not in use, optimizing resource utilization while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system automatically assesses context factors and makes decisions about workspace instantiation without requiring manual administrative intervention. This self-service capability improves productivity by eliminating the burden of manual security management while maintaining adequate security controls.

Inventive Principle:
Principle #25Self-service

3Reliability

If all security protocols are implemented to secure access to protected data, then data security is improved, but resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system changes the parameters of workspace configuration based on context assessment. Instead of always using full virtualization, the system adjusts workspace parameters (isolation level, resource allocation, duration) based on the assessed risk and context factors, reducing resource consumption while maintaining adequate security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements selective security measures based on context assessment. Instead of applying all security protocols uniformly, the system applies only the necessary level of security (partial action) based on the assessed risk and context factors, avoiding excessive resource consumption from unnecessary security measures.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If conventional virtualization environments are used, then data isolation is improved, but adaptability to different usage contexts is reduced

Engineering Contradiction:
Improvedata isolationVSAvoidadaptability to usage context
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic workspace instantiation that adapts to context factors (user identity, locale, network, hardware, risk metrics) rather than using static conventional virtualization. This allows the system to create workspaces only when needed and terminate them when not in use, optimizing resource utilization while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies different levels and types of isolation and security measures to different workspaces based on their specific context factors. Instead of using a uniform approach, each workspace is configured with local quality appropriate to its specific usage context, user, data sensitivity, and risk profile.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250254110A1Bidirectional attestation for workspace orchestrators
Publication Date: 2025.08.07 DELL PROD LP
  • US20250254110A1 patent drawing
  • US20250254110A1 patent drawing
  • US20250254110A1 patent drawing

AI summary

Systems and methods for bi-directional attestation for workspace orchestrators are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: receive, from a workspace orchestrator, a request to attest a workspace component within a workspace instantiated by a client IHS; send an indication of the request to an attester within the workspace component; and receive attestation evidence from the attester, where the attestation evidence is signed with an attestation key.