Workspace Root-of-Trust via Peripheral Certificate Aggregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern shared workspaces, ensuring the integrity and security of a user's workspace, which includes various peripheral devices and applications, is challenging due to the dynamic nature of device connections and the need for secure data management and trust verification across multiple devices.

Innovation Solution

The system creates a unique workspace certificate by combining digital certificates from peripheral devices and encrypts it using a Trusted Platform Module's public Endorsement Key, allowing remote verification of the workspace integrity and updating the certificate upon device additions or removals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates from multiple peripheral devices are combined to create a workspace certificate, then workspace integrity verification is improved, but device complexity and certificate management overhead increase

Engineering Contradiction:
Improveworkspace integrity verificationVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a workspace certificate as an intermediary that aggregates individual device certificates. This workspace certificate serves as a mediator between multiple peripheral devices and the verification system, consolidating trust verification into a single certificate that represents the entire workspace configuration, thereby simplifying management while maintaining comprehensive integrity verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple individual device certificates into a single workspace certificate that represents the entire workspace. This merging process consolidates the trust verification of multiple devices (IHS, display, audio device, input device, etc.) into one unified certificate, reducing the complexity of managing and verifying individual certificates separately

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If the workspace certificate is encrypted with TPM's public Endorsement Key, then security and trust verification are improved, but processing overhead and computational requirements increase

Engineering Contradiction:
Improvesecurity and trust verificationVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary encryption of the workspace certificate using the TPM's public Endorsement Key during the certificate creation phase. By pre-encrypting the certificate with a secure key before transmission or storage, the system ensures that the certificate remains protected throughout its lifecycle, and the computational overhead is incurred once during creation rather than repeatedly during verification operations

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system monitors for device additions or removals to update the workspace certificate, then workspace integrity is maintained, but system responsiveness and operational continuity may be affected

Engineering Contradiction:
Improveworkspace integrityVSAvoidsystem responsiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors for changes in workspace device configuration (additions or removals of peripheral devices). When changes are detected, the system automatically triggers an update to the workspace certificate, ensuring that the certificate always reflects the current workspace state. This feedback loop maintains integrity without requiring manual intervention, balancing monitoring overhead with automated response

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12141263B2Workspace root-of-trust
Publication Date: 2024.11.12 DELL PROD LP
  • US12141263B2 patent drawing
  • US12141263B2 patent drawing
  • US12141263B2 patent drawing

AI summary

Systems and methods for providing a workspace Root-of-Trust (RoT) are described. In an embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to receive a digital certificate from each of a plurality of peripheral devices coupled to the IHS in a workspace and combine at least portions of the digital certificates to create a workspace certificate unique to the workspace.