Remote Orchestrator Workspace Credential Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Information Handling Systems (IHSs) face challenges in securely managing credentials for orchestrating workspaces across multiple remote orchestrators, particularly in ensuring secure access and state transitions while maintaining appropriate security and productivity levels.
Innovation Solution
The system allows a first remote orchestrator to manage a workspace using a first credential, and enables a second remote orchestrator to manage the workspace by determining if the second orchestrator has a second credential provided by the first remote orchestrator, while enforcing state transition policies to ensure secure access and transitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple remote orchestrators are allowed to manage a workspace, then workspace accessibility and productivity are improved, but security and credential management complexity worsen
Solution Approach 1:
The patent segments credential management by introducing domain-specific credentials and orchestrators. Each domain (e.g., enterprise domain, personal domain) has its own credential set and orchestrator, allowing fine-grained control over who can access the workspace. This segmentation resolves the complexity by organizing the credential management into manageable, isolated units rather than a monolithic system.
Solution Approach 2:
The patent introduces a credential provider as an intermediary component that issues credentials to orchestrators. This intermediary simplifies the overall system by centralizing credential issuance logic, allowing multiple orchestrators to obtain credentials without direct trust relationships between them. The credential provider acts as a mediator that enforces security policies while enabling multi-orchestrator access.
2Reliability
If state transition policies are enforced for credential management, then security is improved, but system performance and productivity worsen
Solution Approach 1:
The patent implements preliminary action by pre-defining state transition policies and credential validity periods before workspace access is needed. Credentials are issued with built-in expiration times and scope restrictions, and the orchestrator knows in advance what states are allowed. This eliminates the need for real-time security decisions, allowing fast credential validation while maintaining strong security through pre-established rules.
Solution Approach 2:
The patent uses parameter changes by managing credentials through defined states (e.g., valid, expired, revoked, pending) and transitioning between these states based on policies. The system changes credential parameters (validity period, scope, status) rather than making real-time binary security decisions. This parameter-based approach enables smooth, predictable state transitions that maintain security while minimizing performance impact.
Data Source
AI summary
Systems and methods for managing credentials usable in the orchestration of workspaces by multiple remote orchestrators are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS), may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: allow a first remote orchestrator to manage a workspace instantiated by the IHS in response to the first remote orchestrator having a first credential, where the first remote orchestrator is associated with a first domain; receive a request from a second remote orchestrator to manage the workspace, where the second remote orchestrator is associated with a second domain within the first domain; and allow the second remote orchestrator to manage the workspace in response to a determination that the second remote orchestrator has a second credential provided by the first remote orchestrator.


