Remote Orchestrator Workspace Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHSs) face challenges in securely managing credentials for orchestrating workspaces across multiple remote orchestrators, particularly in ensuring secure access and state transitions while maintaining appropriate security and productivity levels.

Innovation Solution

The system allows a first remote orchestrator to manage a workspace using a first credential, and enables a second remote orchestrator to manage the workspace by determining if the second orchestrator has a second credential provided by the first remote orchestrator, while enforcing state transition policies to ensure secure access and transitions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple remote orchestrators are allowed to manage a workspace, then workspace accessibility and productivity are improved, but security and credential management complexity worsen

Engineering Contradiction:
Improveworkspace accessibilityVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments credential management by introducing domain-specific credentials and orchestrators. Each domain (e.g., enterprise domain, personal domain) has its own credential set and orchestrator, allowing fine-grained control over who can access the workspace. This segmentation resolves the complexity by organizing the credential management into manageable, isolated units rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a credential provider as an intermediary component that issues credentials to orchestrators. This intermediary simplifies the overall system by centralizing credential issuance logic, allowing multiple orchestrators to obtain credentials without direct trust relationships between them. The credential provider acts as a mediator that enforces security policies while enabling multi-orchestrator access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If state transition policies are enforced for credential management, then security is improved, but system performance and productivity worsen

Engineering Contradiction:
ImprovesecurityVSAvoidworkspace access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-defining state transition policies and credential validity periods before workspace access is needed. Credentials are issued with built-in expiration times and scope restrictions, and the orchestrator knows in advance what states are allowed. This eliminates the need for real-time security decisions, allowing fast credential validation while maintaining strong security through pre-established rules.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by managing credentials through defined states (e.g., valid, expired, revoked, pending) and transitioning between these states based on policies. The system changes credential parameters (validity period, scope, status) rather than making real-time binary security decisions. This parameter-based approach enables smooth, predictable state transitions that maintain security while minimizing performance impact.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12309138B2Managing credentials usable in the orchestration of workspaces by multiple remote orchestrators
Publication Date: 2025.05.20 DELL PROD LP
  • US12309138B2 patent drawing
  • US12309138B2 patent drawing
  • US12309138B2 patent drawing

AI summary

Systems and methods for managing credentials usable in the orchestration of workspaces by multiple remote orchestrators are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS), may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: allow a first remote orchestrator to manage a workspace instantiated by the IHS in response to the first remote orchestrator having a first credential, where the first remote orchestrator is associated with a first domain; receive a request from a second remote orchestrator to manage the workspace, where the second remote orchestrator is associated with a second domain within the first domain; and allow the second remote orchestrator to manage the workspace in response to a determination that the second remote orchestrator has a second credential provided by the first remote orchestrator.