Trusted Local Workspace Orchestration with Instantiation Log Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inefficient and burdensome, consuming large portions of memory and processing capabilities, and fail to account for the specific context of IHS usage, leading to degraded productivity and insufficient data protection.
Innovation Solution
The implementation of a trusted local orchestration system that includes a processor, system memory, and a trusted controller with a TPM chip, which records and encrypts logs of workspace instantiation operations, and establishes connections based on successful authentication and verification, allowing secure workspace instantiation without external communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virtualization techniques are used to secure access to protected data, then security is improved, but resource consumption (memory and processing capabilities) increases significantly
Solution Approach 1:
The patent extracts the security verification function from the continuous operation phase and performs it only during workspace instantiation. The trusted controller records a log of instantiation operations and verifies it against orchestration code, eliminating the need for continuous virtualization overhead during data access operations.
Solution Approach 2:
The system performs security verification in advance during workspace instantiation by recording the log of operations in the trusted controller and verifying it against the orchestration code before the workspace becomes active. This preliminary action ensures security without requiring ongoing resource consumption.
2Reliability
If conventional virtualization techniques are used to secure access to protected data, then security is improved, but productivity deteriorates due to degraded performance
Solution Approach 1:
The patent removes the continuous virtualization overhead that was degrading productivity and extracts only the essential security verification function, which is performed once during instantiation rather than continuously during operations.
Solution Approach 2:
Security verification is performed in advance during workspace instantiation, allowing the workspace to operate at full performance once established, thus maintaining both security and productivity.
3Reliability
If security protocols extend defenses to remote IHSs, then security is improved, but system complexity increases
Solution Approach 1:
The trusted controller on the local IHS autonomously records the instantiation log and performs verification against the orchestration code without requiring complex external security protocols or continuous communication with remote systems.
Solution Approach 2:
Security verification is performed in advance during instantiation, eliminating the need for complex continuous security protocols during remote access operations.
4Reliability
If conventional virtualization environments are used to isolate protected data, then security is improved, but adaptability to different usage contexts deteriorates
Solution Approach 1:
The system dynamically adapts to different usage contexts by allowing workspaces to be instantiated with context-specific configurations while maintaining security through the trusted controller's verification of the instantiation log, rather than using static virtualization environments.
Data Source
AI summary
Systems and methods for providing trusted local orchestration of workspaces are described. In some embodiments, an Information Handling System (IHS) may include a processor and a system memory coupled to the processor, the system memory having program instructions stored thereon that, upon execution, cause the IHS to: receive an orchestration code from a workspace orchestration service; record, using a trusted controller coupled to the processor, a log comprising: the orchestration code, and an indication of a sequence of operations performed during an instantiation of a workspace by the local management agent; provide a copy of the log to the workspace orchestration service; and establish a connection between the workspace and the workspace orchestration service in response to the workspace orchestration service's successful: (i) authentication of the orchestration code, and (ii) verification of the sequence of operations.


