Workspace Orchestration Service Secure Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) face challenges in securely managing and isolating workspaces to protect data from unauthorized access, as existing virtualized environments may not adequately restrict access to hardware and software resources, leading to potential security breaches.

Innovation Solution

Implementing a workspace orchestration service that manages the deployment of workspaces on IHSs, using handles with tokens and APIs for secure access to resources, and ensuring isolation through remote access controllers, which provide secure communication channels and validate resource access based on security scores and conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If workspaces are isolated from hardware and operating system, then security is improved, but access to resources becomes restricted

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to resources
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a resource access manager as an intermediary component that sits between the isolated workspace and the hardware/operating system resources. This manager receives resource access requests from the workspace, validates them against security policies, and mediates the actual resource access. This resolves the contradiction by maintaining workspace isolation while enabling controlled resource access through the intermediary manager.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtualized environments provide abstraction from underlying hardware, then security is improved, but access to hardware capabilities is limited

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to hardware capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic resource access policies that can adapt to different workspace requirements. The resource access manager evaluates requests in real-time and grants access based on current security context, workspace type, and resource sensitivity. This dynamic approach allows the system to maintain security while providing appropriate hardware capabilities to workspaces that need them, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If security protocols restrict workspace access to protected data, then data protection is improved, but application functionality is reduced

Engineering Contradiction:
Improvedata protectionVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary security validation where the resource access manager pre-evaluates and caches security decisions for common resource access patterns. By performing security checks in advance and caching results, the system reduces the overhead of security validation during application execution. This resolves the contradiction by maintaining strong data protection while minimizing the impact on application functionality and performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11595404B2Systems and methods for secure communications for modern workspaces
Publication Date: 2023.02.28 DELL PROD LP
  • US11595404B2 patent drawing
  • US11595404B2 patent drawing
  • US11595404B2 patent drawing

AI summary

Systems and methods support workspaces operating on an Information Handling System (IHS), where the workspaces utilize virtualization to operate in isolation from a portion of the hardware and software of the IHS. Resources of the IHS that are available for use by workspaces are registered with an orchestration service that is remote from the IHS and that manages deployment of workspaces on the IHS. A workspace is instantiated on the IHS according to a workspace definition provided by the orchestration service. The orchestration service also provides a handle that allows the workspace to access a particular resource of the IHS, where the handle includes an interface supported by an embedded controller of the IHS for providing access to the IHS resource. The workspace invokes the IHS resource using an interface provided in the handle. The handle thus provides a communication mechanism for workspaces to utilize local resources of the IHS.