Distributed Recovery of Secure Workspaces via Combined Image Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The recovery of a user computing device on which secure workspaces are deployed is a complex, time-consuming, and technically demanding process, especially when the device or its operating system fails, requiring manual intervention and significant technical expertise.
Innovation Solution
The implementation of a system for end-to-end distributed recovery, which involves creating and storing images of the user computing device and its secure workspaces, allowing for the creation of a combined image that can be deployed to quickly recover the device to its pre-crash state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual recovery procedures are used for crashed devices, then technical expertise can be applied, but the recovery process becomes time-consuming and labor-intensive
Solution Approach 1:
The system creates images of the user computing device and secure workspaces before the crash occurs and stores them in a recovery image repository. When a crash happens, the pre-created images are immediately available for recovery, eliminating the need for real-time manual recovery procedures and significantly reducing recovery time.
Solution Approach 2:
The system creates a combined image that is a copy of both the user computing device and its secure workspaces. This combined image is stored in the recovery image repository and can be deployed to recover the device, replacing the need for manual recovery procedures while maintaining technical expertise through automated image deployment.
2Ease of manufacture
If complete manual recovery is performed, then all components can be restored, but the process requires significant technical know-how and administrator time
Solution Approach 1:
The system enables self-service recovery by automatically creating images of the device and secure workspaces, storing them in the recovery image repository, and providing automated deployment of combined images. This eliminates the need for administrators to manually perform recovery procedures while maintaining complete restoration of all components.
Solution Approach 2:
The recovery process is segmented into distinct components: creating device images, creating secure workspace images, storing them in the recovery image repository, and deploying combined images. This segmentation simplifies the overall recovery process by breaking down complex recovery tasks into manageable, automated steps.
3Reliability
If secure workspaces are deployed on user computing devices, then application isolation is achieved, but recovery becomes more complex when devices fail
Solution Approach 1:
The system merges the recovery processes of the user computing device and secure workspaces into a single combined image. This combined image includes both the device state and all secure workspace states, allowing simultaneous recovery of both components through a single deployment operation, thereby reducing recovery complexity despite the presence of multiple isolated environments.
Data Source
AI summary
End-to-end distributed recovery of a user computing device on which secure workspaces are deployed is provided. An image of a user computing device and images of secure workspaces deployed on the user computing device can be created and stored. In response to a crash of the user computing device, a combined image can be created from the image of the user computing device and the images of the secure workspaces deployed on the user computing device. The combined image can then be deployed on the user computing device to recover the user computing device.


