Workspace Orchestration Service Secure Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face challenges in securely managing and isolating workspaces to protect data from unauthorized access, as existing virtualized environments may not adequately restrict access to hardware and software resources, leading to potential security breaches.
Innovation Solution
Implementing a workspace orchestration service that manages the deployment of workspaces on IHSs, using handles with tokens and APIs for secure access to resources, and ensuring isolation through remote access controllers, which provide secure communication channels and validate resource access based on security scores and conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If workspaces are isolated from hardware and operating system, then security is improved, but access to resources becomes restricted
Solution Approach 1:
The patent introduces a resource access manager as an intermediary component that sits between the isolated workspace and the hardware/operating system resources. This manager receives resource access requests from the workspace, validates them against security policies, and mediates the actual resource access. This resolves the contradiction by maintaining workspace isolation while enabling controlled resource access through the intermediary manager.
2Reliability
If virtualized environments provide abstraction from underlying hardware, then security is improved, but access to hardware capabilities is limited
Solution Approach 1:
The patent implements dynamic resource access policies that can adapt to different workspace requirements. The resource access manager evaluates requests in real-time and grants access based on current security context, workspace type, and resource sensitivity. This dynamic approach allows the system to maintain security while providing appropriate hardware capabilities to workspaces that need them, resolving the contradiction between security and adaptability.
3Reliability
If security protocols restrict workspace access to protected data, then data protection is improved, but application functionality is reduced
Solution Approach 1:
The patent implements preliminary security validation where the resource access manager pre-evaluates and caches security decisions for common resource access patterns. By performing security checks in advance and caching results, the system reduces the overhead of security validation during application execution. This resolves the contradiction by maintaining strong data protection while minimizing the impact on application functionality and performance.
Data Source
AI summary
Systems and methods support workspaces operating on an Information Handling System (IHS), where the workspaces utilize virtualization to operate in isolation from a portion of the hardware and software of the IHS. Resources of the IHS that are available for use by workspaces are registered with an orchestration service that is remote from the IHS and that manages deployment of workspaces on the IHS. A workspace is instantiated on the IHS according to a workspace definition provided by the orchestration service. The orchestration service also provides a handle that allows the workspace to access a particular resource of the IHS, where the handle includes an interface supported by an embedded controller of the IHS for providing access to the IHS resource. The workspace invokes the IHS resource using an interface provided in the handle. The handle thus provides a communication mechanism for workspaces to utilize local resources of the IHS.


