Secure Workspace Resource Enabler Selective Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current resource enablers provide an all-or-nothing approach to accessing external resources from secure workspaces, compromising the security intended by these workspaces.
Innovation Solution
Implementing a system that selectively validates and enables resource enablers based on the trustworthiness of applications and external resources, using a local service that processes validation requests and instructs resource enablers to enable or block access accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If resource enablers are deployed to allow applications in secure workspaces to access external resources, then application functionality and user productivity are improved, but workspace security is compromised
Solution Approach 1:
The patent implements granular access control where each application within the secure workspace is evaluated individually for trustworthiness. The local service assigns different access permissions to different applications based on their specific trust levels, rather than applying a uniform security policy to all applications. This allows trusted applications to access external resources while untrusted applications remain isolated, resolving the contradiction between functionality and security.
Solution Approach 2:
The patent segments the resource access control mechanism into distinct components: a local service that validates trust, a resource enabler that executes access decisions, and individual application-level permissions. This segmentation allows the system to maintain overall workspace security while enabling selective access for specific applications, thus improving functionality without compromising security.
2Ease of operation
If an all-or-nothing approach is used for resource access, then workspace security is simplified to manage, but application flexibility and user productivity are reduced
Solution Approach 1:
The patent implements dynamic access control where permissions are not fixed but can change based on application behavior, trust assessments, and security conditions. The local service continuously evaluates applications and adjusts access permissions accordingly, allowing the system to adapt to changing security requirements while maintaining manageable complexity through automated decision-making.
Solution Approach 2:
The local service acts as an intermediary between applications and external resources, mediating access requests by evaluating trust criteria and making authorization decisions. This intermediary layer simplifies security management by centralizing decision logic while providing fine-grained control over which applications can access which resources, thus maintaining both ease of operation and application flexibility.
3Reliability
If resource enablers are selectively validated based on trust, then workspace security is maintained, but system complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where applications automatically undergo trust validation through the local service without requiring manual administrator intervention for each access request. The system autonomously evaluates trust criteria, makes access decisions, and enforces permissions, reducing the operational complexity of managing selective validation while maintaining high security standards.
Solution Approach 2:
The patent performs preliminary trust validation and permission assignment before applications attempt to access external resources. By pre-establishing trust relationships and access permissions through automated evaluation, the system reduces the complexity of real-time security decisions while maintaining robust security controls throughout application execution.
Data Source
AI summary
Resource enablers of a secure workspace can be selectively validated and enabled. Resource enablers can be configured to selectively allow an application hosted in a secure workspace to access an external resource based on a trust of the application and/or of the external resource. As a result, the security of the secure workspace can be maintained without having to restrict all access to external resources.


