Workspace Architecture Swapping to Reduce Attack Surface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious actors can gain access to Information Handling Systems (IHS) through various entry points, potentially downloading or uploading data, compromising the security of the system.

Innovation Solution

Implement a method for generating a first workspace definition on an IHS using a first computing architecture, initiating a timer, and upon expiration, redeploying the workspace using a second computing architecture, with the duration of the timer based on security and productivity metrics, and potentially involving different hardware and software resources, including virtual machines and cloud resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the workspace is deployed using a static computing architecture, then the system is easier to operate and maintain, but the attack surface remains exposed allowing malicious actors to compromise the system

Engineering Contradiction:
Improvesystem securityVSAvoidcomputing architecture dynamics
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing architecture is transformed from static to dynamic by implementing automated architecture swapping. The system periodically changes between different computing architectures (e.g., virtualized, containerized, bare-metal) based on timer expiration or security events, making the system adaptable and difficult for malicious actors to compromise through static exploitation methods.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements periodic architecture swapping by initiating timers upon workspace deployment. When the timer expires or security events occur, the system automatically swaps to a different computing architecture, creating periodic changes that disrupt malicious actors' ability to maintain persistent access or exploit known vulnerabilities.

Inventive Principle:
Principle #19Periodic action

2Reliability

If the workspace is frequently redeployed using different computing architectures, then the attack surface is reduced and security is enhanced, but the deployment complexity and resource overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service automated architecture swapping without requiring manual intervention. The workspace manager autonomously monitors timer expiration and security events, automatically generates new workspace definitions with different computing architectures, and redeloys workspaces, thereby reducing deployment complexity despite frequent architecture changes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The workspace manager is designed with multi-functionality to handle diverse computing architectures (virtualized, containerized, bare-metal) through a unified interface. This universal approach simplifies deployment complexity by providing consistent management mechanisms across different architecture types rather than requiring separate management for each architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the timer duration is randomized based on security metrics, then the unpredictability enhances security against timing-based attacks, but the complexity of timer management increases

Engineering Contradiction:
Improvesecurity against timing-based attacksVSAvoidtimer management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The timer duration parameter is changed from fixed to randomized values based on security metrics. The system calculates randomized timer durations using security-related seed values, creating unpredictable expiration times that enhance security against timing-based attacks while the workspace manager automatically handles the complexity of generating and managing these variable timer parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12541603B2Architecture swapping for workspaces
Publication Date: 2026.02.03 DELL PROD LP
  • US12541603B2 patent drawing
  • US12541603B2 patent drawing
  • US12541603B2 patent drawing

AI summary

Systems and methods are provided for swapping computing architectures used by workspaces operating on an Information Handling System (IHS). A first workspace definition is generated for deployment of a workspace on the IHS using a first computing architecture. A timer is initiated upon deployment of the workspace on the IHS according to the first workspace definition. Upon expiration of the timer, a second workspace definition is generated for redeployment of the workspace using a second computing architecture. The workspace is then redeployed on the IHS according to the second workspace definition. The duration of the timer may be a randomized interval, or may be selected based on security and/or productivity metrics for the deployment of the workspace on the IHS. Through swapping of the computing architecture used by the workspace, the attack surface presented by the workspace is regularly altered, thus thwarting malicious actors attempting to compromise the workspace.