Dynamic Workspace Security for Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virtualization techniques in Information Handling Systems (IHS) are inadequate for modern computing, as they fail to account for the specific context of data access and usage, leading to inefficient resource usage and inadequate protection of sensitive data, especially when accessed from various locations and networks.
Innovation Solution
Deploying dynamic workspaces with adjustable security protocols based on real-time risk assessments, using fuzzy hashing to evaluate the security context and updating workspace definitions to ensure adequate protection for transferred data, allowing secure access and transfer of protected data across different workspaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virtualization techniques are used to isolate protected data, then data security is improved, but device complexity and resource consumption increase
Solution Approach 1:
The patent implements dynamic workspace definitions that can be adjusted in real-time based on the data being accessed. Instead of static security isolation, the system dynamically modifies workspace properties (such as security protocols, resource allocation, and access controls) according to the specific data characteristics and user context, thereby maintaining security while reducing unnecessary complexity.
Solution Approach 2:
The system applies different security protocols and workspace configurations tailored to each specific data type and access context. Rather than applying uniform isolation to all data, the patent implements localized security measures that match the actual risk level and requirements of individual datasets, reducing overall system complexity while maintaining appropriate protection.
2Reliability
If conventional virtualization techniques provide isolated computing environments, then data protection is improved, but productivity decreases due to resource consumption
Solution Approach 1:
The workspace environment dynamically adjusts its resource allocation and security protocols based on real-time needs. When data is transferred between workspaces, the system automatically modifies workspace definitions to provide adequate protection only when necessary, allowing more resource-intensive operations during high-security periods and more flexible operations during low-risk periods, thus optimizing productivity.
Solution Approach 2:
The patent changes key parameters of the workspace environment (such as security protocol strength, resource limits, and isolation levels) based on the specific data being accessed and the current security context. This allows the system to provide strong protection when needed while maintaining higher productivity settings during lower-risk operations.
3Reliability
If security protocols isolate the entire network, then data security is improved, but adaptability to modern computing requirements decreases
Solution Approach 1:
The patent segments the network security approach into individual workspace-level protocols rather than applying network-wide isolation. Each workspace can be configured with specific security measures appropriate to the data it contains, allowing flexible access patterns while maintaining security. This segmentation enables users to access data from various locations and devices without compromising overall system security.
Solution Approach 2:
The workspace definitions dynamically adapt to modern computing requirements by adjusting security protocols based on the specific data access context. The system can enable or disable certain security measures, modify access controls, and adjust resource allocation in real-time based on the user, data, and environment, thereby maintaining both security and adaptability.
Data Source
AI summary
Systems and methods support secure transfer of data between workspaces operating on an IHS (Information Handling System). Upon a request for access to a first managed resource, such as protected data, a first workspace is deployed according to a first workspace definition. Upon a request for access to a second managed resource, a second workspace is deployed according to a second workspace definition. In response to an indication of a portion of the protected data from the first workspace being copied to a buffer supported by the IHS and of a request to paste the copied portion of the protected data to the second workspace, the protections provided by the second workspace are evaluated. If the protections of the second workspace are inadequate, an updated second workspace definition is selected that specifies additional protections. The second workspace is updated according to the updated second workspace definition and the transfer is permitted.


