Workspace Orchestration for Isolated Application Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHSs) face challenges in securely managing and deploying workspaces that isolate protected data while ensuring efficient access to hardware and software resources, as virtualized environments often limit access to these resources due to isolation protocols.

Innovation Solution

An IHS with a workspace orchestration service manages workspace deployment by communicating application parameters, identifying modifications, and sending information to modify applications, using an IHS management process to access and update these parameters, while maintaining isolation from the operating system and hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If workspaces are isolated using virtualization to protect data, then security is improved, but access to hardware and software resources is limited

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to resources
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a workspace orchestration service as an intermediary component that mediates between isolated workspaces and the underlying hardware/software resources. This service receives requests from workspaces, translates them into appropriate system calls, and manages resource allocation while maintaining isolation boundaries. The intermediary enables resource access without compromising security by controlling and monitoring all interactions between workspaces and the host system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If application parameters are stored in isolated workspace environments, then security is maintained, but management and modification of these parameters becomes complex

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal parameter storage mechanism where application parameters are stored in a standardized format and location that can be accessed and modified by multiple workspaces and management processes. This universal approach allows different workspaces to share common parameters while maintaining their isolation, and enables centralized management processes to modify parameters across multiple workspaces using a single interface, reducing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If workspaces maintain isolation from the operating system, then security is improved, but adaptability to changing contexts is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to context
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic parameter modification capabilities that allow workspaces to adapt to changing contexts while maintaining isolation. The workspace orchestration service monitors contextual changes and dynamically adjusts application parameters within workspaces in response to these changes. This dynamic approach enables workspaces to adapt their behavior, resource usage, and configuration based on contextual information without breaking isolation boundaries or requiring direct OS access.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12430157B2Workspace administration system and method for a workspace orchestration system
Publication Date: 2025.09.30 DELL PROD LP
  • US12430157B2 patent drawing
  • US12430157B2 patent drawing
  • US12430157B2 patent drawing

AI summary

According to one embodiment, an information Handling System (IHS) includes a workspace orchestration service that is executed to manage deployment of workspaces on the IHS having computer-executable instructions to, for each of a plurality of workspaces instantiated on the IHS, communicate with the workspace to receive application parameters associated with an application configured in the workspace, and store the application parameters at a specified location. The instructions further identify at least one of the application parameters that is to be modified using an IHS management process, and communicate with the workspace to send information associated with the at least one application parameter to the workspace, wherein the workspace is executed to modify the application according to the at least one application parameter. The IHS management process accesses the one or more application parameters from the specified location; using an IHS management process.