Distributed Recovery of Secure Workspaces via Combined Image Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The recovery of a user computing device on which secure workspaces are deployed is a complex, time-consuming, and technically demanding process, especially when the device or its operating system fails, requiring manual intervention and significant technical expertise.

Innovation Solution

The implementation of a system for end-to-end distributed recovery, which involves creating and storing images of the user computing device and its secure workspaces, allowing for the creation of a combined image that can be deployed to quickly recover the device to its pre-crash state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual recovery procedures are used for crashed devices, then technical expertise can be applied, but the recovery process becomes time-consuming and labor-intensive

Engineering Contradiction:
Improverecovery reliabilityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates images of the user computing device and secure workspaces before the crash occurs and stores them in a recovery image repository. When a crash happens, the pre-created images are immediately available for recovery, eliminating the need for real-time manual recovery procedures and significantly reducing recovery time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a combined image that is a copy of both the user computing device and its secure workspaces. This combined image is stored in the recovery image repository and can be deployed to recover the device, replacing the need for manual recovery procedures while maintaining technical expertise through automated image deployment.

Inventive Principle:
Principle #26Copying

2Ease of manufacture

If complete manual recovery is performed, then all components can be restored, but the process requires significant technical know-how and administrator time

Engineering Contradiction:
Improverecovery easeVSAvoidrecovery process complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The system enables self-service recovery by automatically creating images of the device and secure workspaces, storing them in the recovery image repository, and providing automated deployment of combined images. This eliminates the need for administrators to manually perform recovery procedures while maintaining complete restoration of all components.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The recovery process is segmented into distinct components: creating device images, creating secure workspace images, storing them in the recovery image repository, and deploying combined images. This segmentation simplifies the overall recovery process by breaking down complex recovery tasks into manageable, automated steps.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secure workspaces are deployed on user computing devices, then application isolation is achieved, but recovery becomes more complex when devices fail

Engineering Contradiction:
Improveworkspace isolation reliabilityVSAvoidrecovery complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the recovery processes of the user computing device and secure workspaces into a single combined image. This combined image includes both the device state and all secure workspace states, allowing simultaneous recovery of both components through a single deployment operation, thereby reducing recovery complexity despite the presence of multiple isolated environments.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12339955B2End-to-end distributed recovery of a user computing device on which secure workspaces are deployed
Publication Date: 2025.06.24 DELL PROD LP
  • US12339955B2 patent drawing
  • US12339955B2 patent drawing
  • US12339955B2 patent drawing

AI summary

End-to-end distributed recovery of a user computing device on which secure workspaces are deployed is provided. An image of a user computing device and images of secure workspaces deployed on the user computing device can be created and stored. In response to a crash of the user computing device, a combined image can be created from the image of the user computing device and the images of the secure workspaces deployed on the user computing device. The combined image can then be deployed on the user computing device to recover the user computing device.