Workspace Deployment via Secondary Trusted Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques in Information Handling Systems (IHSs) are inadequate for modern computing, as they fail to account for the specific context of IHS usage and result in complex, resource-intensive security protocols that burden system operation and productivity, especially when users access protected data from various locations and networks.

Innovation Solution

The system employs a secondary trusted device to establish a secure connection with a workspace orchestration service, which authenticates device identification, calculates security and productivity targets based on context, and creates a workspace definition to optimize security and productivity settings dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to secure protected data, then data security is improved, but system complexity and resource consumption increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security protocols that adapt to the specific context of each IHS and user session. Instead of applying static, one-size-fits-all virtualization security measures, the system evaluates context information (device type, network location, user role, application being accessed) and dynamically adjusts the security posture. This resolves the contradiction by making security protocols flexible and context-aware, reducing unnecessary complexity while maintaining adequate protection levels for each specific scenario.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters based on context evaluation. Rather than maintaining fixed security configurations, the patent modifies security parameters (such as isolation levels, authentication requirements, and resource allocation) according to the evaluated context of each IHS usage scenario. This allows the system to optimize security measures for each specific case, avoiding the overhead of maximum-security protocols when they are not needed.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive security protocols are implemented for all IHS access scenarios, then data security is improved, but user productivity decreases due to resource consumption

Engineering Contradiction:
Improvedata securityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies the principle of local quality by tailoring security measures to the specific local context of each IHS access scenario. Instead of uniformly applying comprehensive security protocols to all access attempts, the system evaluates context information (such as device trustworthiness, network security, user role, and application sensitivity) and applies security measures appropriate to that specific local situation. This resolves the contradiction by ensuring that security overhead is proportional to the actual risk and requirements of each access scenario, thereby maintaining productivity while securing data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial security actions based on context evaluation. Rather than always applying the full suite of security protocols, the patent applies only the necessary portion of security measures required for each specific access scenario. When context indicates low risk or already-secured environments, the system applies minimal necessary security, preserving system resources for productivity-critical operations while still maintaining adequate protection.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security protocols are extended to remote IHSs to maintain security perimeter, then data security is improved, but system complexity and administrative burden increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem administration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a context evaluation service as an intermediary between the security system and remote IHSs. This intermediary automatically assesses the security context of remote access requests (evaluating device characteristics, network conditions, user credentials, and access patterns) and makes dynamic security decisions. This resolves the administrative burden by automating what would otherwise require manual security configuration and monitoring, allowing the system to extend security to remote IHSs without proportionally increasing administrative complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where context information from remote IHS access attempts is continuously evaluated and used to adjust security protocols in real-time. The context evaluation service receives feedback about access patterns, device states, and security events, and dynamically modifies security measures accordingly. This automated feedback loop reduces administrative burden by eliminating the need for manual security policy adjustments when extending protection to remote IHSs.

Inventive Principle:
Principle #23Feedback

4Productivity

If context-aware security evaluation is implemented, then security efficiency is improved, but initial system complexity increases

Engineering Contradiction:
Improvesecurity efficiencyVSAvoidinitial system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing a context evaluation framework and service infrastructure before deploying context-aware security protocols. The context evaluation service is pre-configured with evaluation criteria, data sources, and decision-making logic, allowing it to automatically assess security contexts without requiring complex real-time analysis. This preliminary setup resolves the contradiction by front-loading the complexity into a reusable framework that subsequently enables efficient context-aware security decisions without proportionally increasing ongoing system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11757881B2Workspace deployment using a secondary trusted device
Publication Date: 2023.09.12 DELL PROD LP
  • US11757881B2 patent drawing
  • US11757881B2 patent drawing
  • US11757881B2 patent drawing

AI summary

Systems and methods for workspace deployment using a secondary trusted device are described. In some embodiments, a first Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the first IHS to: establish a first connection with a second IHS, where the second IHS is configured to establish a second connection with a workspace orchestration service, and where the workspace orchestration service is configured to: receive device identification information of the first IHS from the second IHS; and authenticate the device identification information against a database provided by a manufacturer of the first IHS; and in response to a successful authentication, establish a third connection with the workspace orchestration service.