Multilevel Workspace Authorization Using IHS Measurements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inadequate in modern computing environments, as they fail to account for the specific context of IHS usage and result in unnecessary overhead, degrading productivity and user experience.
Innovation Solution
The method involves calculating and validating IHS measurements based on identity, firmware, and session properties to dynamically configure and secure workspaces, using a trusted controller and workspace orchestration service to ensure secure and efficient access to managed resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virtualization techniques are used to secure access to protected data, then security is improved, but system overhead increases and productivity degrades
Solution Approach 1:
The patent implements dynamic virtualization configurations that adapt to the specific context of each IHS and user session. Instead of applying static, one-size-fits-all security protocols, the system dynamically determines the appropriate level of virtualization and security measures based on real-time context information, thereby reducing unnecessary overhead while maintaining security where required.
Solution Approach 2:
The system changes security parameters and virtualization levels based on contextual factors such as user identity, IHS characteristics, location, and session properties. By adjusting these parameters dynamically rather than maintaining fixed high-security configurations, the system reduces overhead for low-risk scenarios while preserving security for high-risk scenarios, thus improving productivity without compromising security.
2Reliability
If conventional virtualization techniques are used to secure access to protected data, then security is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent segments the virtualization and security decision-making process into multiple components: context information collection, context analysis, virtualization configuration determination, and implementation. This segmentation allows each component to focus on a specific task, reducing overall system complexity while maintaining comprehensive security through coordinated operation of the segmented components.
Solution Approach 2:
The system uses parameter changes to simplify complexity by adjusting virtualization levels based on context. Rather than implementing complex virtualization for all scenarios, the system changes parameters to apply appropriate virtualization only when necessary, thereby reducing system complexity while maintaining security where required.
3Reliability
If all security protocols are implemented to protect accessed data and applications, then security is improved, but memory and processing capabilities are consumed
Solution Approach 1:
The patent applies partial action by implementing only the necessary security protocols and virtualization measures required for each specific context. Instead of applying all security protocols universally, the system determines the appropriate level of security action needed based on context analysis, thereby reducing processing overhead while maintaining adequate security protection.
Solution Approach 2:
The system changes security and processing parameters based on contextual factors. By adjusting these parameters dynamically, the system reduces processing capabilities consumption for low-risk scenarios while maintaining robust security for high-risk scenarios, thus optimizing the balance between security and resource usage.
Data Source
AI summary
Systems and methods provide multilevel authorization of workspaces using certificates, where all of the authorization levels may be authorized separately or may instead be authorized at once. A measurement of an IHS (Information Handling System) is calculated based on the identity of the IHS and based on firmware of the IHS. A measurement of the configuration of the IHS is calculated based on information for configuring the IHS for supporting workspaces and also based on the IHS measurement. A measurement of a workspace session is calculated based on properties of a session used to remotely support operation of the workspace by the IHS and also based on the configuration measurement. Workspace session data may by authorized at all three levels by evaluating the session measurement against a reference session measurement.


