Subordinate Workspace Instantiation for Secure Third-Party Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inefficient and burdensome, consuming significant memory and processing resources while failing to account for the context of use, leading to inadequate data protection and degraded productivity.
Innovation Solution
The system facilitates secure communications between subordinate workspaces and third parties by transmitting cryptographic material to peripheral devices, enabling them to instantiate secure workspaces, and utilizing telemetry data to manage secure communications and data transmission, while accounting for the context of use through workspace orchestration services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but memory and processing resources are consumed significantly
Solution Approach 1:
The system segments the workspace environment into subordinate workspaces that can be independently instantiated on peripheral devices. Each subordinate workspace handles specific data access tasks, allowing security functions to be distributed rather than centralized in a single virtualization layer, thereby reducing overall resource consumption while maintaining security.
Solution Approach 2:
The patent introduces workspace orchestration services as intermediaries that manage subordinate workspaces on peripheral devices. These services act as mediators between the protected data environment and users, providing security verification and data access control without requiring full virtualization of the entire system, thus reducing memory and processing overhead.
2Reliability
If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but productivity is degraded
Solution Approach 1:
The system dynamically instantiates subordinate workspaces on peripheral devices based on real-time security verification results and data access requirements. Rather than maintaining static virtualization environments, the system creates and destroys workspaces as needed, reducing resource overhead and improving responsiveness to user productivity needs while maintaining security.
Solution Approach 2:
Subordinate workspaces are self-managed on peripheral devices with automatic security verification and instantiation capabilities. The workspace orchestration services enable these workspaces to autonomously handle their own security protocols and data access operations, reducing the administrative burden and improving system responsiveness to user productivity requirements.
3Reliability
If security protocols are extended to remote IHSs to leverage system security, then data security is improved, but system complexity increases
Solution Approach 1:
The system applies security protocols locally at the peripheral device level through subordinate workspaces rather than extending complex security infrastructure to all remote IHSs. Each subordinate workspace implements security measures tailored to its specific data access needs, reducing overall system complexity while maintaining adequate security protection.
4Reliability
If conventional virtualization environments are used to isolate protected data, then data security is improved, but resource overhead increases
Solution Approach 1:
The patent segments the protected data environment into multiple subordinate workspaces that can be independently managed and instantiated on peripheral devices. This segmentation allows security isolation to be applied only where needed for specific data access operations, reducing the resource overhead associated with maintaining comprehensive virtualization environments across the entire system.
Data Source
AI summary
Systems and methods for secure communications between subordinate workspaces and third parties are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: transmit one or more files received from a workspace orchestration service to a peripheral device, where the one or more files enable the peripheral device to instantiate a subordinate workspace; and facilitate secure communications between the subordinate workspace and a third-party.


