Secure Workspace Layer Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure workspace technologies do not provide an option for trust verification when multiple layers with distributed ownership are involved, which can lead to security and operational issues.

Innovation Solution

A management service maintains a repository of layers and a certificate vault for owner certificates, with a host agent on user computing devices verifying the trust of each layer using the corresponding owner certificates before deploying the secure workspace.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a secure workspace is defined as a collection of layers with distributed ownership, then customers can maintain their own layers independent of third-party layers, but there is no option for performing trust verification on the secure workspace

Engineering Contradiction:
Improvelayered architecture with distributed ownershipVSAvoidtrust verification capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The secure workspace is segmented into multiple layers with distributed ownership, where each layer can be independently maintained by different owners (customer or third-party). This segmentation enables flexible composition while the patent introduces certificate-based verification to ensure reliability across these segmented layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A certificate authority acts as an intermediary to issue and manage certificates for layer owners. The host agent uses these certificates to verify the trustworthiness of each layer during deployment, mediating between the distributed layer owners and the secure workspace deployment process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple layers with different owners are combined in a secure workspace, then functionality and customization are enhanced, but security verification becomes complex and unavailable

Engineering Contradiction:
Improvemulti-owner layer compositionVSAvoidtrust verification process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of creating complex verification logic for each layer combination, the patent uses certificate copies distributed to host agents. These certificates serve as trusted copies of owner identities, simplifying the verification process while supporting multi-owner layer composition.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the verification parameter from complex multi-layer analysis to simple certificate validation. By transforming the verification problem into checking cryptographic signatures against stored certificates, the system handles multi-owner complexity through parameter transformation rather than complex process logic.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If trust verification is implemented for each layer, then security is enhanced, but deployment time and processing overhead increase

Engineering Contradiction:
Improvelayer trust verificationVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Certificate verification is performed as a preliminary action during the deployment phase rather than during runtime operations. The host agent verifies certificates before applying layers to the secure workspace, ensuring security while minimizing ongoing deployment time overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical verification processes with cryptographic signature validation. Instead of analyzing layer contents or ownership structures, the system uses mathematical cryptography to verify trust, significantly reducing processing overhead while maintaining strong security guarantees.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12292948B2Verifying trust of a secure workspace that is formed of multiple layers with distributed ownership
Publication Date: 2025.05.06 DELL PROD LP
  • US12292948B2 patent drawing
  • US12292948B2 patent drawing
  • US12292948B2 patent drawing

AI summary

Trust of a secure workspace that has multiple layers with distributed ownership can be verified. A management service can maintain a repository of layers for secure workspaces and a certificate vault storing certificates of the owners of the layers. The management service can also maintain workspace metadata defining secure workspaces that pertain to a particular user and the layers that form the secure workspaces. When a secure workspace is to be deployed on a user computing device, the management service can send the layers that form the secure workspace and the workspace metadata for the secure workspace to a host agent on the user computing device. The host agent can then leverage the certificates of the owners of the layers to verify the trust of each layer and, if trust is verified for all layers that form the secure workspace, can deploy the secure workspace on the user computing device.