Workspace Management Isolating Protected Resources via Subordinate Workspaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face challenges in securely managing access to protected resources across diverse operational scenarios, particularly due to the variability in user environments and the risk of malicious access attempts, as they are often used in multiple locations and coupled with both public and private devices.
Innovation Solution
The implementation of a workspace management system that allows a primary workspace to instantiate and manage subordinate workspaces on peripheral devices, using role-based orchestration to control access and communications, thereby isolating protected data and restricting access based on defined roles and APIs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a primary workspace provides access to protected resources in multiple locations with various peripheral devices, then user productivity and flexibility are improved, but the attack surface and security risk increase
Solution Approach 1:
The system segments the workspace into a primary workspace and multiple subordinate workspaces, each operating in isolated contexts. The primary workspace manages protected resources while subordinate workspaces handle peripheral device operations, creating security boundaries that limit the attack surface while maintaining versatility across different locations and devices.
Solution Approach 2:
The primary workspace acts as an intermediary between protected resources and subordinate workspaces. It mediates access requests, enforces security policies, and manages communication between peripheral devices and protected data, thereby reducing direct exposure and minimizing the attack surface while enabling flexible multi-location access.
2Ease of operation
If subordinate workspaces are instantiated on peripheral devices to support authorized operations, then ease of operation is improved, but device complexity increases
Solution Approach 1:
Subordinate workspaces are automatically instantiated and configured on peripheral devices based on their capabilities and authorized roles. The system self-manages the creation, configuration, and termination of subordinate workspaces without requiring manual intervention, simplifying operation while the underlying orchestration handles the complexity of workspace management.
Solution Approach 2:
The primary workspace provides a universal management interface that works across diverse peripheral devices and locations. It implements role-based access control and standardized communication protocols that enable ease of operation with various devices while the system internally manages the complexity of device-specific configurations and capabilities.
3Reliability
If role-based orchestration is implemented to control access and communications, then security is improved, but the system complexity increases
Solution Approach 1:
The system uses role-based parameters to dynamically control access and communications. Each subordinate workspace is assigned specific roles that define its authorized operations and communication capabilities. These parameter-based role definitions enable robust security control while maintaining manageable system complexity through standardized role templates and policies.
Data Source
AI summary
System and methods support workspaces operating on an Information Handling Systems (IHS). A primary workspace definition is received by the IHS from a remote orchestrator. A primary workspace is instantiated based upon the primary workspace definition, where the instantiated primary workspace provides access to a protected resource. One or more subordinate workspaces are identified that operate by peripheral devices that are coupled to the IHS, where each subordinate workspace supports one or more roles of authorized operations by a respective peripheral device. The roles may correspond to specific functions of the first of the reported peripheral device that are available for use by the primary workspace. One or more of the subordinate workspaces are selected for use by the primary workspace based on the roles supported by the subordinate workspaces.


