Workspace Access Control with Context-Aware Sensitive Data Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inefficient and burdensome, failing to account for the context of use and consuming significant memory and processing resources, while also providing unnecessary capabilities that degrade productivity.
Innovation Solution
An Information Handling System (IHS) determines the presence of sensitive data and evaluates a security score to decide whether to process, mask, or withhold data based on a workspace definition, using a local management agent to manage workspaces and peripheral devices, thereby optimizing data access and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but memory and processing resources are consumed and productivity is degraded
Solution Approach 1:
The patent changes the security evaluation parameters from static user-identity-based decisions to dynamic context-aware security scores. The security score is calculated based on multiple parameters including user identity, device state, location, and requested operation, allowing the system to adjust security measures dynamically rather than applying fixed virtualization overhead for all access scenarios.
Solution Approach 2:
Instead of applying full virtualization security measures for all data access operations, the system applies security controls selectively based on the calculated security score. When the score indicates low risk, the system permits direct access without virtualization overhead, applying security measures only partially when necessary to maintain both productivity and security.
2Reliability
If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but processing overhead increases and user experience is degraded
Solution Approach 1:
The patent implements dynamic security evaluation that adapts to changing context during user sessions. The security score is recalculated based on real-time factors such as device state changes, location changes, and operation types, allowing the system to adjust processing overhead dynamically rather than maintaining constant virtualization overhead throughout the session.
Solution Approach 2:
The system performs preliminary security score calculation before granting access to determine whether virtualization is necessary. By evaluating security context in advance and making access decisions based on the calculated score, the system avoids unnecessary virtualization setup and reduces processing overhead before it begins.
3Reliability
If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but system complexity increases and unnecessary capabilities are provided
Solution Approach 1:
The patent applies security measures locally and selectively rather than globally. Instead of implementing comprehensive virtualization for all data access scenarios, the system applies security controls only to specific operations or data types based on the calculated security score, reducing overall system complexity while maintaining necessary security.
Solution Approach 2:
The security system is segmented into discrete evaluation components that assess different aspects of access requests (user identity, device state, location, operation type). This modular approach allows the system to evaluate only relevant security factors for each access request rather than implementing a monolithic complex virtualization framework for all scenarios.
Data Source
AI summary
Systems and methods for hierarchical workspace orchestration are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: determine, by a local management agent configured to instantiate a primary workspace, that an operation involving a subordinate workspace instantiated by a peripheral device coupled to the IHS comprises sensitive data; and determine whether to process the sensitive data prior to execution of the operation.


