Workspace Access Control with Context-Aware Sensitive Data Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inefficient and burdensome, failing to account for the context of use and consuming significant memory and processing resources, while also providing unnecessary capabilities that degrade productivity.

Innovation Solution

An Information Handling System (IHS) determines the presence of sensitive data and evaluates a security score to decide whether to process, mask, or withhold data based on a workspace definition, using a local management agent to manage workspaces and peripheral devices, thereby optimizing data access and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but memory and processing resources are consumed and productivity is degraded

Engineering Contradiction:
Improvedata securityVSAvoidsystem productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the security evaluation parameters from static user-identity-based decisions to dynamic context-aware security scores. The security score is calculated based on multiple parameters including user identity, device state, location, and requested operation, allowing the system to adjust security measures dynamically rather than applying fixed virtualization overhead for all access scenarios.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of applying full virtualization security measures for all data access operations, the system applies security controls selectively based on the calculated security score. When the score indicates low risk, the system permits direct access without virtualization overhead, applying security measures only partially when necessary to maintain both productivity and security.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but processing overhead increases and user experience is degraded

Engineering Contradiction:
Improvedata securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements dynamic security evaluation that adapts to changing context during user sessions. The security score is recalculated based on real-time factors such as device state changes, location changes, and operation types, allowing the system to adjust processing overhead dynamically rather than maintaining constant virtualization overhead throughout the session.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary security score calculation before granting access to determine whether virtualization is necessary. By evaluating security context in advance and making access decisions based on the calculated score, the system avoids unnecessary virtualization setup and reduces processing overhead before it begins.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but system complexity increases and unnecessary capabilities are provided

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies security measures locally and selectively rather than globally. Instead of implementing comprehensive virtualization for all data access scenarios, the system applies security controls only to specific operations or data types based on the calculated security score, reducing overall system complexity while maintaining necessary security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security system is segmented into discrete evaluation components that assess different aspects of access requests (user identity, device state, location, operation type). This modular approach allows the system to evaluate only relevant security factors for each access request rather than implementing a monolithic complex virtualization framework for all scenarios.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250252201A1Information access control in workspace ecosystems
Publication Date: 2025.08.07 DELL PROD LP
  • US20250252201A1 patent drawing
  • US20250252201A1 patent drawing
  • US20250252201A1 patent drawing

AI summary

Systems and methods for hierarchical workspace orchestration are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: determine, by a local management agent configured to instantiate a primary workspace, that an operation involving a subordinate workspace instantiated by a peripheral device coupled to the IHS comprises sensitive data; and determine whether to process the sensitive data prior to execution of the operation.