Trusted Local Workspace Orchestration with Instantiation Log Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inefficient and burdensome, consuming large portions of memory and processing capabilities, and fail to account for the specific context of IHS usage, leading to degraded productivity and insufficient data protection.

Innovation Solution

The implementation of a trusted local orchestration system that includes a processor, system memory, and a trusted controller with a TPM chip, which records and encrypts logs of workspace instantiation operations, and establishes connections based on successful authentication and verification, allowing secure workspace instantiation without external communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to secure access to protected data, then security is improved, but resource consumption (memory and processing capabilities) increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the security verification function from the continuous operation phase and performs it only during workspace instantiation. The trusted controller records a log of instantiation operations and verifies it against orchestration code, eliminating the need for continuous virtualization overhead during data access operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs security verification in advance during workspace instantiation by recording the log of operations in the trusted controller and verifying it against the orchestration code before the workspace becomes active. This preliminary action ensures security without requiring ongoing resource consumption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional virtualization techniques are used to secure access to protected data, then security is improved, but productivity deteriorates due to degraded performance

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent removes the continuous virtualization overhead that was degrading productivity and extracts only the essential security verification function, which is performed once during instantiation rather than continuously during operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Security verification is performed in advance during workspace instantiation, allowing the workspace to operate at full performance once established, thus maintaining both security and productivity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security protocols extend defenses to remote IHSs, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted controller on the local IHS autonomously records the instantiation log and performs verification against the orchestration code without requiring complex external security protocols or continuous communication with remote systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security verification is performed in advance during instantiation, eliminating the need for complex continuous security protocols during remote access operations.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If conventional virtualization environments are used to isolate protected data, then security is improved, but adaptability to different usage contexts deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to different usage contexts by allowing workspaces to be instantiated with context-specific configurations while maintaining security through the trusted controller's verification of the instantiation log, rather than using static virtualization environments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12407520B2Trusted local orchestration of workspaces
Publication Date: 2025.09.02 DELL PROD LP
  • US12407520B2 patent drawing
  • US12407520B2 patent drawing
  • US12407520B2 patent drawing

AI summary

Systems and methods for providing trusted local orchestration of workspaces are described. In some embodiments, an Information Handling System (IHS) may include a processor and a system memory coupled to the processor, the system memory having program instructions stored thereon that, upon execution, cause the IHS to: receive an orchestration code from a workspace orchestration service; record, using a trusted controller coupled to the processor, a log comprising: the orchestration code, and an indication of a sequence of operations performed during an instantiation of a workspace by the local management agent; provide a copy of the log to the workspace orchestration service; and establish a connection between the workspace and the workspace orchestration service in response to the workspace orchestration service's successful: (i) authentication of the orchestration code, and (ii) verification of the sequence of operations.