Consolidated Authentication for Isolated Workspaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) face challenges in securely managing authentication across multiple isolated workspaces, leading to inefficiencies and redundancies in accessing shared authentication resources due to each workspace operating independently.

Innovation Solution

Implementing a workspace orchestration service that registers and manages authentication capabilities, provides single-sign-on credentials, and validates workspace integrity, allowing authentication clients to operate securely across multiple applications within isolated environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each workspace operates independently with its own authentication resources, then workspace isolation and security are maintained, but authentication efficiency deteriorates due to redundancies and inability to share credentials across workspaces

Engineering Contradiction:
Improveworkspace isolationVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges authentication resources across multiple isolated workspaces by introducing a workspace orchestration service that consolidates authentication capabilities. This service enables shared credential stores and single-sign-on functionality that allows users to authenticate once and access multiple workspaces, eliminating redundant authentication while maintaining workspace isolation through controlled access mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The workspace orchestration service acts as an intermediary between isolated workspaces and authentication resources. It provides a handle-based interface that allows workspaces to access consolidated authentication capabilities without direct exposure, enabling credential sharing while preserving isolation boundaries. The intermediary manages the complexity of cross-workspace authentication transparently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If authentication resources are consolidated across workspaces, then authentication efficiency improves through single-sign-on capabilities, but workspace isolation may be compromised

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidworkspace isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments authentication access control by implementing fine-grained permissions within the consolidated authentication system. The workspace orchestration service divides authentication resources into workspace-specific contexts and manages access through handles that enforce isolation policies. This allows credential sharing while maintaining logical separation and access control between workspaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing customized authentication views for each workspace while maintaining a unified backend. Each workspace receives authentication capabilities tailored to its specific needs and security requirements, while the underlying consolidated system provides efficient shared credentials. This enables both isolation and efficiency simultaneously.

Inventive Principle:
Principle #3Local quality

3Reliability

If a handle-based interface is introduced to manage authentication capabilities, then access control and security are improved, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses copying by creating handle representations of authentication capabilities without duplicating the underlying complex authentication systems. Each handle is a simplified reference that points to consolidated authentication resources, allowing workspaces to access complex authentication functionality through simple, manageable interfaces. This reduces the apparent complexity for individual workspaces while maintaining comprehensive security controls.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11593472B2Systems and methods for consolidated authentication for modern workspaces
Publication Date: 2023.02.28 DELL PROD LP
  • US11593472B2 patent drawing
  • US11593472B2 patent drawing
  • US11593472B2 patent drawing

AI summary

Systems and methods are provided for consolidation of IHS (Information Handling System) authentication resources utilized by workspaces operating on the IHS, where the workspaces operate in isolation from the operating system of the IHS. A remote workspace orchestration service manages deployment of workspaces on the IHS. The workspaces are instantiated and operate according to a workspace definition provided by the workspace orchestration service. An embedded controller of the IHS registers authentication functions of the IHS with the workspace orchestration service, which notifies the workspaces of the consolidated authentication functions. An authentication agent is instantiated that supports operating system authentications for applications operating within the workspaces. The respective workspace definitions of the workspaces are updated to route credential requests to the authentication agent. Upon receiving a credential request, the authentication agent validates the workspace and provides the validated workspace with credentials.