Workspace Orchestration for Secure Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face challenges in securely managing access to protected resources across various operational scenarios, including public and private locations, due to the dynamic nature of user environments and the risk of malicious access.
Innovation Solution
The method involves receiving a request for access to a protected resource, determining security and productivity contexts, identifying applications with overlapping capabilities, and selecting these applications for operation within a primary workspace. This approach generates a workspace definition that includes the selected applications and transmits it to the IHS for instantiation, allowing for secure and productive access to protected resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple applications with overlapping capabilities are installed to provide access to protected resources, then the productivity and functionality are improved, but the security risk and complexity of the system increases
Solution Approach 1:
The patent merges multiple applications with overlapping capabilities into a unified workspace environment. Instead of running separate applications, the system combines their functions into a single integrated workspace that provides the same access to protected resources while reducing the attack surface and managing security contexts more effectively.
Solution Approach 2:
The workspace is designed as a universal environment that can host multiple applications with different capabilities. The workspace framework provides multi-functional support by allowing various applications to operate within the same secure boundary, sharing security contexts and resource access rights, thereby reducing overall system complexity while maintaining productivity.
2Adaptability or versatility
If the system dynamically adjusts security contexts based on user environment, then the adaptability and security are improved, but the device complexity and processing overhead increases
Solution Approach 1:
The workspace framework implements dynamic security context adjustment by automatically adapting security settings based on the user's environment, location, and device state. The system can transition between different security contexts (e.g., public workspace, private workspace, secure enclave) depending on the detected conditions, providing flexibility without requiring manual configuration.
Solution Approach 2:
The system performs self-service by automatically determining appropriate security contexts and adjusting access rights without requiring user intervention. The workspace manager monitors environmental factors and autonomously configures security settings, reducing the complexity burden on both the user and the system administrator.
3Productivity
If applications are selected based on overlapping capabilities, then the productivity is improved, but the difficulty of detecting and measuring security contexts increases
Solution Approach 1:
The patent replaces manual security assessment mechanisms with automated computational methods. Instead of requiring complex manual evaluation of security contexts, the system uses algorithmic approaches to detect, measure, and compare security parameters automatically, selecting applications based on predefined capability overlaps and security context matching rules.
Data Source
AI summary
Systems and methods are provided for managing capabilities of workspaces operating on an Information Handling System (IHS). A request is received from a user of the IHS for access to a protected resource. A security context and a productivity context are determined for operation of a primary workspace on the IHS. Two or more applications are identified for operation within the primary workspace, where the applications provide access to the protected resource, and where the applications include overlapping capabilities. Based on the security context and the productivity context for the primary workspace deployment, two or more of the applications with overlapping capabilities are selected for operation within the primary workspace.


