Workspace Deployment via Secondary Trusted Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional virtualization techniques in Information Handling Systems (IHSs) are inadequate for modern computing, as they fail to account for the specific context of IHS usage and result in complex, resource-intensive security protocols that burden system operation and productivity, especially when users access protected data from various locations and networks.
Innovation Solution
The system employs a secondary trusted device to establish a secure connection with a workspace orchestration service, which authenticates device identification, calculates security and productivity targets based on context, and creates a workspace definition to optimize security and productivity settings dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional virtualization techniques are used to secure protected data, then data security is improved, but system complexity and resource consumption increase significantly
Solution Approach 1:
The patent implements dynamic security protocols that adapt to the specific context of each IHS and user session. Instead of applying static, one-size-fits-all virtualization security measures, the system evaluates context information (device type, network location, user role, application being accessed) and dynamically adjusts the security posture. This resolves the contradiction by making security protocols flexible and context-aware, reducing unnecessary complexity while maintaining adequate protection levels for each specific scenario.
Solution Approach 2:
The system changes security parameters based on context evaluation. Rather than maintaining fixed security configurations, the patent modifies security parameters (such as isolation levels, authentication requirements, and resource allocation) according to the evaluated context of each IHS usage scenario. This allows the system to optimize security measures for each specific case, avoiding the overhead of maximum-security protocols when they are not needed.
2Reliability
If comprehensive security protocols are implemented for all IHS access scenarios, then data security is improved, but user productivity decreases due to resource consumption
Solution Approach 1:
The patent applies the principle of local quality by tailoring security measures to the specific local context of each IHS access scenario. Instead of uniformly applying comprehensive security protocols to all access attempts, the system evaluates context information (such as device trustworthiness, network security, user role, and application sensitivity) and applies security measures appropriate to that specific local situation. This resolves the contradiction by ensuring that security overhead is proportional to the actual risk and requirements of each access scenario, thereby maintaining productivity while securing data.
Solution Approach 2:
The system implements partial security actions based on context evaluation. Rather than always applying the full suite of security protocols, the patent applies only the necessary portion of security measures required for each specific access scenario. When context indicates low risk or already-secured environments, the system applies minimal necessary security, preserving system resources for productivity-critical operations while still maintaining adequate protection.
3Reliability
If security protocols are extended to remote IHSs to maintain security perimeter, then data security is improved, but system complexity and administrative burden increase
Solution Approach 1:
The patent introduces a context evaluation service as an intermediary between the security system and remote IHSs. This intermediary automatically assesses the security context of remote access requests (evaluating device characteristics, network conditions, user credentials, and access patterns) and makes dynamic security decisions. This resolves the administrative burden by automating what would otherwise require manual security configuration and monitoring, allowing the system to extend security to remote IHSs without proportionally increasing administrative complexity.
Solution Approach 2:
The system implements feedback mechanisms where context information from remote IHS access attempts is continuously evaluated and used to adjust security protocols in real-time. The context evaluation service receives feedback about access patterns, device states, and security events, and dynamically modifies security measures accordingly. This automated feedback loop reduces administrative burden by eliminating the need for manual security policy adjustments when extending protection to remote IHSs.
4Productivity
If context-aware security evaluation is implemented, then security efficiency is improved, but initial system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-establishing a context evaluation framework and service infrastructure before deploying context-aware security protocols. The context evaluation service is pre-configured with evaluation criteria, data sources, and decision-making logic, allowing it to automatically assess security contexts without requiring complex real-time analysis. This preliminary setup resolves the contradiction by front-loading the complexity into a reusable framework that subsequently enables efficient context-aware security decisions without proportionally increasing ongoing system complexity.
Data Source
AI summary
Systems and methods for workspace deployment using a secondary trusted device are described. In some embodiments, a first Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the first IHS to: establish a first connection with a second IHS, where the second IHS is configured to establish a second connection with a workspace orchestration service, and where the workspace orchestration service is configured to: receive device identification information of the first IHS from the second IHS; and authenticate the device identification information against a database provided by a manufacturer of the first IHS; and in response to a successful authentication, establish a third connection with the workspace orchestration service.


