Workspace Orchestration Security via Location Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face challenges in securing data access across various locations and environments, as malicious actors can exploit vulnerabilities in the attack surface, especially when devices are used in different public and private locations, necessitating dynamic adjustment of security measures based on location and usage context.
Innovation Solution
The system observes and correlates location information of devices, adjusts security scores, and builds workspace definitions that include localized entitlements or remediation actions, such as limiting access or terminating workspaces, to enhance security posture based on the adjusted security scores.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the IHS provides data access to users in various locations, then productivity and accessibility are improved, but security risks increase due to expanded attack surface
Solution Approach 1:
The system dynamically adjusts security measures based on real-time location information and usage context. The security score and associated controls are continuously updated as the device moves between locations and usage patterns change, allowing the system to adapt security posture to current risk conditions rather than using static security policies.
Solution Approach 2:
The system changes security parameters such as access controls, authentication requirements, and data protection measures based on the device's location and security score. Different locations trigger different security parameter settings, enabling the system to maintain high productivity in safe locations while enhancing security in riskier environments.
2Reliability
If the system continuously monitors and adjusts security measures, then security posture is improved, but device complexity increases
Solution Approach 1:
The system implements a feedback loop where location information and usage context are continuously collected, security scores are calculated based on this data, and security measures are automatically adjusted. This automated feedback mechanism maintains high security posture while reducing the need for manual intervention and complex rule-based systems.
Solution Approach 2:
The system performs self-assessment by automatically calculating security scores based on location and usage patterns, and self-adjustment by automatically applying appropriate security measures without requiring manual configuration. This self-service approach simplifies system complexity while maintaining reliable security posture.
3Reliability
If the IHS uses location-based security adjustments, then security effectiveness is improved, but loss of time for security assessments increases
Solution Approach 1:
The system replaces manual security assessments with automated electronic location monitoring and algorithmic security scoring. Instead of time-consuming manual evaluations, the system uses automated location data processing and pre-established security algorithms to rapidly assess risk and adjust measures, significantly reducing assessment time while maintaining effectiveness.
Data Source
AI summary
An Information Handling System (IHS), such as a workspace orchestration service IHS, observes location information of a device, and receives location information logged by the device. The observed location information may include telemetry of the device, and/or the received device-logged location information may include below-OS telemetry of the device The IHS correlates the observed location information with the received device-logged location information, and adjusts a security score of the device in accordance with the resulting correlation. Where the device is a workspace instantiation client IHS, the logged location information is logged by the workspace, and the security score is the security score of the workspace. Also, the workspace orchestration service IHS may build a definition for the workspace, that includes one or more localized entitlements for the workspace, or may build the workspace definition to include remediation action, based on the location information and/or adjusted security score.


