Workspace Remediation via Definition Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtualization techniques in Information Handling Systems (IHSs) are inadequate for modern computing, as they fail to account for the specific context of use during a session and provide unnecessary capabilities, leading to increased memory and processing consumption, reduced productivity, and insufficient data protection when users access protected data from various locations and devices.

Innovation Solution

The system implements a method for fleet remediation of compromised workspaces by receiving indications of security compromises from local management agents, transmitting modified workspace definitions to instantiate secure workspaces, and migrating contexts to maintain security and productivity, using cryptographic protocols and workspace orchestration services to manage and adapt security and productivity settings dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional virtualization techniques are used to provide isolated computing environments, then data protection and security are improved, but memory and processing consumption increase significantly

Engineering Contradiction:
Improvedata protectionVSAvoidmemory and processing consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the virtualization layer from the hardware/OS level and relocates it to the application level. Instead of providing full system-level virtualization (which consumes significant memory and processing resources), the system provides application-level virtualization through workspace definitions that isolate only the necessary application context. This extraction principle allows the system to maintain security isolation while dramatically reducing resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local quality by providing isolation and security properties only where needed at the application level, rather than uniformly across the entire system. Each workspace definition provides targeted isolation for specific applications based on their security requirements, allowing fine-grained control over protection levels and minimizing unnecessary resource consumption in areas that do not require enhanced isolation.

Inventive Principle:
Principle #3Local quality

2Reliability

If conventional virtualization techniques provide isolated computing environments, then security is improved, but productivity decreases due to unnecessary capabilities and complex overhead

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by providing only the necessary security isolation features required for each specific application context, rather than implementing full virtualization capabilities universally. The workspace definition mechanism allows administrators to specify exactly which isolation and security features are needed, eliminating unnecessary capabilities and reducing overhead that would otherwise diminish productivity.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts the level and type of isolation provided based on the specific application context and security requirements. Instead of static full virtualization, the workspace definitions can be dynamically modified to provide appropriate isolation levels for different applications, allowing the system to optimize between security and productivity for each specific use case.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If conventional virtualization techniques implement security protocols based solely on user identity, then access control is simplified, but the system becomes burdensome to administer and data remains insufficiently protected

Engineering Contradiction:
Improveaccess controlVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameters for access control from static user identity alone to a multi-dimensional approach that includes user identity, application context, environment characteristics, and security requirements. The workspace definition mechanism allows administrators to configure access based on multiple parameters simultaneously, providing more robust data protection while maintaining ease of operation through automated policy enforcement.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The workspace definition mechanism provides multi-functionality by simultaneously handling access control, security isolation, resource allocation, and policy enforcement through a single framework. This universal approach consolidates multiple administration functions into one system, reducing administrative burden while enhancing data protection capabilities through unified policy management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12170686B2Fleet remediation of compromised workspaces
Publication Date: 2024.12.17 DELL PROD LP
  • US12170686B2 patent drawing
  • US12170686B2 patent drawing
  • US12170686B2 patent drawing

AI summary

Systems and methods for providing fleet remediation of compromised workspaces are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive, from a first local management agent configured to provide a first workspace in a fleet of workspaces, an indication that the first workspace has suffered a security compromise, where the first workspace is instantiated based upon a first workspace definition; and in response to the indication, transmit a second workspace definition to a second local management agent configured to provide a second workspace in the fleet of workspaces, where the second workspace is instantiated based upon the first workspace definition, and where the second local management agent is configured to instantiate a third workspace based upon the second workspace definition.