Dynamic Workspace Definition Adjustment via Endpoint Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques in Information Handling Systems (IHS) are inefficient in adapting to the specific context of user activities and locations, leading to over-provisioning of resources, which burdens system performance and security, as they rely solely on user identity without considering the actual usage context or changes during a session.

Innovation Solution

The system continuously evaluates the workspace definition using endpoint context information to dynamically adjust resource availability by calculating security and productivity scores, modifying the workspace definition to either reduce or increase resources based on the context, thereby optimizing resource utilization and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques provide comprehensive security protocols for all approved data and applications based solely on user identity, then security coverage is improved, but system resource consumption and complexity increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidvirtualization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic workspace definitions that automatically adjust security protocols and resource allocation based on real-time context factors such as user behavior, device characteristics, location, and data sensitivity. This replaces static, identity-based security with adaptive security that activates only the necessary protocols for each specific situation, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes multiple parameters simultaneously including security protocol activation, resource allocation levels, and workspace configuration based on context evaluation. By adjusting these parameters dynamically rather than applying fixed security settings to all users, the system achieves comprehensive security where needed while minimizing resource consumption in lower-risk scenarios.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional virtualization techniques implement comprehensive security protocols for all users, then security protection is improved, but system performance and resource utilization deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by implementing security protocols selectively rather than universally. The system evaluates context factors and activates only the necessary level of security protection for each specific situation, avoiding the excessive application of comprehensive security protocols to all users. This partial application of security measures maintains adequate protection while preserving system performance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts the intensity and scope of security protocols based on real-time context evaluation. High-risk scenarios trigger comprehensive security measures, while low-risk scenarios use minimal necessary protocols, optimizing the balance between security protection and system performance across different operating conditions.

Inventive Principle:
Principle #15Dynamics

3Productivity

If administrators configure workspaces with extensive resources and capabilities, then user productivity is improved, but security risks and system burden increase

Engineering Contradiction:
Improveuser productivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by tailoring workspace resource allocation and capability configuration to specific context factors such as user role, device type, location, and data sensitivity. Instead of providing extensive resources to all users uniformly, the system configures appropriate resource levels locally for each user-context combination, ensuring adequate productivity support while minimizing security risks associated with excessive resource availability.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If conventional virtualization environments provide support for many capabilities, then user versatility is improved, but system overhead and operation burden increase

Engineering Contradiction:
Improvecapability supportVSAvoidsystem overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically adjusts workspace capability configuration based on real-time context evaluation. Instead of statically provisioning all possible capabilities for every user, the system activates only the capabilities necessary for the current task and context, reducing system overhead while maintaining versatility when needed. This dynamic adaptation allows the system to support diverse capabilities without permanently bearing the overhead of all possible features.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10938743B1Systems and methods for continuous evaluation of workspace definitions using endpoint context
Publication Date: 2021.03.02 DELL PROD LP
  • US10938743B1 patent drawing
  • US10938743B1 patent drawing
  • US10938743B1 patent drawing

AI summary

Systems and methods for continuous evaluation of workspace definitions using endpoint context. In some embodiments, an Information Handling System (IHS) of a workspace orchestration service may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: receive context information from a local management agent of a client device; in response to the context information indicating that a current workspace provided via the local management agent is over-privileged, modify a current workspace definition into a modified workspace definition, where the modified workspace definition outlines fewer resources than the current workspace definition; and transmit, to the local management agent, one or more files configured to enable the local management agent to modify the current workspace based upon the modified workspace definition to reduce a number of resources available to a user of the client device.