Workspace Continuity via Dynamic Policy Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques for securing access to protected data in Information Handling Systems (IHS) are inadequate for modern computing, as they fail to account for the specific context of IHS usage and result in unnecessary overhead, degrading productivity and user experience due to complex security protocols that consume resources.

Innovation Solution

A system and method for workspace continuity and remediation, where a client IHS receives files or policies from a workspace orchestration service to instantiate a first workspace for non-vetted applications, and upon determining a security risk score exceeding a threshold, it migrates the workload to a second workspace with a vetted application, allowing for secure access and minimizing resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to secure access to protected data, then data security is improved, but device complexity and resource consumption increase due to unnecessary security protocols

Engineering Contradiction:
Improvedata securityVSAvoidsecurity protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic workspace definitions that adapt security protocols based on the actual context of data access. Instead of applying all possible security measures universally, the system dynamically selects and applies only the necessary security protocols for each specific workspace and access scenario, thereby reducing complexity while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters dynamically based on workspace context. Different workspaces have different security parameter sets (e.g., encryption requirements, authentication methods, network isolation levels) that are adjusted according to the specific data sensitivity, access location, and user profile, eliminating unnecessary security overhead.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional virtualization techniques implement all security protocols for approved data and applications, then data protection is improved, but productivity deteriorates due to resource consumption

Engineering Contradiction:
Improvedata protectionVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial security action by implementing only the necessary security protocols for each specific workspace rather than all possible protocols universally. This selective approach ensures adequate protection for each scenario while avoiding the excessive security overhead that would cripple productivity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Security parameters are dynamically adjusted based on the specific workspace requirements and access context, allowing the system to provide adequate protection where needed while minimizing resource consumption in lower-risk scenarios, thereby maintaining productivity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If conventional virtualization environments provide isolated computing environments, then data isolation is improved, but adaptability deteriorates as they cannot account for specific usage context

Engineering Contradiction:
Improvedata isolationVSAvoidusage context adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates dynamic workspace definitions that adapt to specific usage contexts such as location, network conditions, application type, and user profile. Each workspace can be customized to match the actual access scenario, providing both strong isolation and high adaptability to different contexts.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements local quality by tailoring security and functionality parameters to each specific workspace and access context. Instead of a one-size-fits-all approach, each workspace receives customized properties appropriate to its specific usage scenario, enhancing both isolation effectiveness and contextual adaptability.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If workspace definitions are customized for each access scenario, then adaptability is improved, but device complexity increases due to multiple security protocols

Engineering Contradiction:
Improveaccess scenario adaptabilityVSAvoidprotocol management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal workspace definition framework that can handle multiple access scenarios through a single unified system. The framework provides multi-functional capabilities by allowing one system to manage diverse security protocols and workspace configurations through standardized definition mechanisms, reducing overall system complexity despite high adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11843509B2Systems and methods for workspace continuity and remediation
Publication Date: 2023.12.12 DELL PROD LP
  • US11843509B2 patent drawing
  • US11843509B2 patent drawing
  • US11843509B2 patent drawing

AI summary

Systems and methods for modernizing workspace and hardware lifecycle management in an enterprise productivity ecosystem are described. In some embodiments, a client Information Handling System (IHS) may include a processor and a memory, the memory having program instructions that, upon execution by the processor, cause the client IHS to: receive, from a workspace orchestration service, one or more files or policies configured to enable the client IHS to instantiate a first workspace based upon a first workspace definition; allow a user to execute a non-vetted application in the first workspace; determine that the first workspace is compromised; and receive, in response to the determination, from the workspace orchestration service, one or more other files or policies configured to enable the client IHS to instantiate a second workspace based upon a second workspace definition, where the second workspace definition allows execution of a vetted application corresponding to the non-vetted application.