Run-time Workspace Attestation via Application Broker
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems face delays in setting up contractors with the necessary infrastructure, as configuring and providing enterprise images, security, and software can be time-consuming.
Innovation Solution
Implementing a method for run-time attestation of a user workspace using an application broker with a dynamically attestable runtime properties model, which establishes a trust relationship between client and server information handling systems, provisions entitlements, and generates an attestation based on compliance with the model, allowing for secure and efficient setup and management of user workspaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an information handling system is configured with enterprise image, security, and software for contractors, then security and compliance are ensured, but setup time increases
Solution Approach 1:
The patent applies preliminary action by pre-defining workspace images with all necessary enterprise security configurations, software, and entitlements stored in a library. When a contractor needs access, the pre-configured image is rapidly deployed without requiring time-consuming setup procedures, thus maintaining security while reducing setup time
Solution Approach 2:
The patent uses copying by creating standardized workspace images that can be replicated and deployed multiple times. These images contain pre-configured security settings, software installations, and entitlements that are copied to contractor devices, eliminating the need to configure each device individually while ensuring consistent security standards
2Reliability
If runtime attestation and trust verification are implemented, then security compliance is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary component called the application broker that handles runtime attestation and trust verification processes. This broker mediates between the workspace environment and the verification system, managing the complexity of compliance checks while presenting a simplified interface to users and maintaining security requirements
3Productivity
If workspace images are pre-configured with all necessary software and security settings, then deployment speed increases, but storage requirements increase
Solution Approach 1:
The patent applies segmentation by dividing the workspace image into modular components including base image, software packages, security configurations, and entitlements. These segmented components can be stored separately and selectively assembled, reducing overall storage requirements while enabling rapid deployment of specific workspace configurations as needed
Data Source
AI summary
Run-time attestation of a workspace including deploying, at a client information handling system, an application broker, the application broker including a model that defines characteristics of a computer-implemented application accessible through a server information handling system; establishing a trust relationship between a control vault system of the client information handling system and the server information handling system; provisioning entitlements, by the application broker, that are associated with the computer-implemented application at the client information handling system; identifying an execution of the entitlements at the client computing device, and comparing the execution of the entitlements with the model; determining, based on the comparing, a violation of the model, and in response, procuring a trust challenge from the server information handling system; generating, by the application broker and in response to the trust challenge, an attestation of the trust relationship between the control vault system and the server information handling system.


