Workspace Orchestration Service for Secure Multi-Agent Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inadequate for modern computing, as they fail to account for the specific context of data access and consume significant resources, leading to complex and burdensome administration and inadequate data protection.

Innovation Solution

The system employs a workspace orchestration service that receives context information and split keys from multiple local management agents, authenticates them, and transmits a collaborative workspace definition to instantiate a secure environment, granting or denying access based on a matching policy, thereby optimizing resource usage and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to secure access to protected data, then data protection is provided, but resource consumption increases and administration becomes complex

Engineering Contradiction:
Improvedata protectionVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments the virtualization approach by creating separate workspace environments for different data access scenarios. Each workspace is isolated and configured with specific security policies, allowing selective virtualization only where needed rather than comprehensive virtualization of all data access, thereby reducing overall resource consumption while maintaining data protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by tailoring security measures to specific contexts. The system evaluates context information (device type, location, user role) and applies appropriate virtualization and security controls only for specific data access requests, rather than uniformly applying heavy virtualization to all access scenarios, optimizing resource usage while maintaining protection.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional virtualization techniques are used to secure access to protected data, then data protection is provided, but administration becomes burdensome

Engineering Contradiction:
Improvedata protectionVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic workspace configuration that automatically adapts to context changes. The workspace environment is dynamically created, configured, and terminated based on real-time context evaluation, eliminating the need for manual administration of static virtualization settings and reducing administrative burden while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables self-service through automated context evaluation and workspace provisioning. The system automatically assesses context information, determines appropriate security policies, and provisions workspace environments without administrator intervention, significantly reducing administrative complexity while maintaining data protection.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security protocols are extended to remote IHSs, then data protection is improved, but system complexity and administration difficulty increase

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes security parameters dynamically based on context. Instead of applying fixed comprehensive security protocols to all remote access scenarios, the system adjusts security parameters (workspace isolation level, access controls, monitoring) according to evaluated context information, reducing system complexity while maintaining appropriate protection levels.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If context-aware workspace deployment is implemented across multiple agents, then data protection and resource optimization are improved, but authentication and coordination complexity increase

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a context evaluation service as an intermediary between multiple local management agents and the workspace orchestration service. This intermediary collects, evaluates, and standardizes context information from multiple agents, simplifying the authentication and coordination process while enabling context-aware workspace deployment and maintaining data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230325522A1Systems and methods for securely deploying a collective workspace across multiple local management agents
Publication Date: 2023.10.12 DELL PROD LP
  • US20230325522A1 patent drawing
  • US20230325522A1 patent drawing
  • US20230325522A1 patent drawing

AI summary

Systems and methods for securely deploying a collective workspace across multiple local management agents are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive, at a workspace orchestration service from a first local management agent, first context information and a first split key; receive, at the workspace orchestration service from a second local management agent, second context information and a second split key; determining, by the workspace orchestration service, that the first and second context information match a collaborative workspace policy; in response to the determination, authenticate the first and second split keys; and in response to the authentication, transmit a collaborative workspace definition to the first and second local management agents.