Run-time Workspace Attestation via Application Broker

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face delays in setting up contractors with the necessary infrastructure, as configuring and providing enterprise images, security, and software can be time-consuming.

Innovation Solution

Implementing a method for run-time attestation of a user workspace using an application broker with a dynamically attestable runtime properties model, which establishes a trust relationship between client and server information handling systems, provisions entitlements, and generates an attestation based on compliance with the model, allowing for secure and efficient setup and management of user workspaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an information handling system is configured with enterprise image, security, and software for contractors, then security and compliance are ensured, but setup time increases

Engineering Contradiction:
ImprovesecurityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining workspace images with all necessary enterprise security configurations, software, and entitlements stored in a library. When a contractor needs access, the pre-configured image is rapidly deployed without requiring time-consuming setup procedures, thus maintaining security while reducing setup time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating standardized workspace images that can be replicated and deployed multiple times. These images contain pre-configured security settings, software installations, and entitlements that are copied to contractor devices, eliminating the need to configure each device individually while ensuring consistent security standards

Inventive Principle:
Principle #26Copying

2Reliability

If runtime attestation and trust verification are implemented, then security compliance is improved, but system complexity increases

Engineering Contradiction:
ImprovecomplianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component called the application broker that handles runtime attestation and trust verification processes. This broker mediates between the workspace environment and the verification system, managing the complexity of compliance checks while presenting a simplified interface to users and maintaining security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If workspace images are pre-configured with all necessary software and security settings, then deployment speed increases, but storage requirements increase

Engineering Contradiction:
Improvedeployment speedVSAvoidstorage requirements
Core Design Contradiction:
ProductivityVSVolume of stationary object

Solution Approach 1:

The patent applies segmentation by dividing the workspace image into modular components including base image, software packages, security configurations, and entitlements. These segmented components can be stored separately and selectively assembled, reducing overall storage requirements while enabling rapid deployment of specific workspace configurations as needed

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11757859B2Run-time attestation of a user workspace
Publication Date: 2023.09.12 DELL PROD LP
  • US11757859B2 patent drawing
  • US11757859B2 patent drawing
  • US11757859B2 patent drawing

AI summary

Run-time attestation of a workspace including deploying, at a client information handling system, an application broker, the application broker including a model that defines characteristics of a computer-implemented application accessible through a server information handling system; establishing a trust relationship between a control vault system of the client information handling system and the server information handling system; provisioning entitlements, by the application broker, that are associated with the computer-implemented application at the client information handling system; identifying an execution of the entitlements at the client computing device, and comparing the execution of the entitlements with the model; determining, based on the comparing, a violation of the model, and in response, procuring a trust challenge from the server information handling system; generating, by the application broker and in response to the trust challenge, an attestation of the trust relationship between the control vault system and the server information handling system.