Secure Workspace Layer Trust Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure workspace technologies do not provide an option for trust verification when multiple layers with distributed ownership are involved, which can lead to security and operational issues.
Innovation Solution
A management service maintains a repository of layers and a certificate vault for owner certificates, with a host agent on user computing devices verifying the trust of each layer using the corresponding owner certificates before deploying the secure workspace.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a secure workspace is defined as a collection of layers with distributed ownership, then customers can maintain their own layers independent of third-party layers, but there is no option for performing trust verification on the secure workspace
Solution Approach 1:
The secure workspace is segmented into multiple layers with distributed ownership, where each layer can be independently maintained by different owners (customer or third-party). This segmentation enables flexible composition while the patent introduces certificate-based verification to ensure reliability across these segmented layers.
Solution Approach 2:
A certificate authority acts as an intermediary to issue and manage certificates for layer owners. The host agent uses these certificates to verify the trustworthiness of each layer during deployment, mediating between the distributed layer owners and the secure workspace deployment process.
2Adaptability or versatility
If multiple layers with different owners are combined in a secure workspace, then functionality and customization are enhanced, but security verification becomes complex and unavailable
Solution Approach 1:
Instead of creating complex verification logic for each layer combination, the patent uses certificate copies distributed to host agents. These certificates serve as trusted copies of owner identities, simplifying the verification process while supporting multi-owner layer composition.
Solution Approach 2:
The patent changes the verification parameter from complex multi-layer analysis to simple certificate validation. By transforming the verification problem into checking cryptographic signatures against stored certificates, the system handles multi-owner complexity through parameter transformation rather than complex process logic.
3Reliability
If trust verification is implemented for each layer, then security is enhanced, but deployment time and processing overhead increase
Solution Approach 1:
Certificate verification is performed as a preliminary action during the deployment phase rather than during runtime operations. The host agent verifies certificates before applying layers to the secure workspace, ensuring security while minimizing ongoing deployment time overhead.
Solution Approach 2:
The patent replaces complex mechanical verification processes with cryptographic signature validation. Instead of analyzing layer contents or ownership structures, the system uses mathematical cryptography to verify trust, significantly reducing processing overhead while maintaining strong security guarantees.
Data Source
AI summary
Trust of a secure workspace that has multiple layers with distributed ownership can be verified. A management service can maintain a repository of layers for secure workspaces and a certificate vault storing certificates of the owners of the layers. The management service can also maintain workspace metadata defining secure workspaces that pertain to a particular user and the layers that form the secure workspaces. When a secure workspace is to be deployed on a user computing device, the management service can send the layers that form the secure workspace and the workspace metadata for the secure workspace to a host agent on the user computing device. The host agent can then leverage the certificates of the owners of the layers to verify the trust of each layer and, if trust is verified for all layers that form the secure workspace, can deploy the secure workspace on the user computing device.


