Workspace Root-of-Trust via Peripheral Certificate Aggregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In modern shared workspaces, ensuring the integrity and security of a user's workspace, which includes various peripheral devices and applications, is challenging due to the dynamic nature of device connections and the need for secure data management and trust verification across multiple devices.
Innovation Solution
The system creates a unique workspace certificate by combining digital certificates from peripheral devices and encrypts it using a Trusted Platform Module's public Endorsement Key, allowing remote verification of the workspace integrity and updating the certificate upon device additions or removals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificates from multiple peripheral devices are combined to create a workspace certificate, then workspace integrity verification is improved, but device complexity and certificate management overhead increase
Solution Approach 1:
The patent introduces a workspace certificate as an intermediary that aggregates individual device certificates. This workspace certificate serves as a mediator between multiple peripheral devices and the verification system, consolidating trust verification into a single certificate that represents the entire workspace configuration, thereby simplifying management while maintaining comprehensive integrity verification
Solution Approach 2:
The patent combines multiple individual device certificates into a single workspace certificate that represents the entire workspace. This merging process consolidates the trust verification of multiple devices (IHS, display, audio device, input device, etc.) into one unified certificate, reducing the complexity of managing and verifying individual certificates separately
2Reliability
If the workspace certificate is encrypted with TPM's public Endorsement Key, then security and trust verification are improved, but processing overhead and computational requirements increase
Solution Approach 1:
The patent performs preliminary encryption of the workspace certificate using the TPM's public Endorsement Key during the certificate creation phase. By pre-encrypting the certificate with a secure key before transmission or storage, the system ensures that the certificate remains protected throughout its lifecycle, and the computational overhead is incurred once during creation rather than repeatedly during verification operations
3Reliability
If the system monitors for device additions or removals to update the workspace certificate, then workspace integrity is maintained, but system responsiveness and operational continuity may be affected
Solution Approach 1:
The patent implements a feedback mechanism where the system continuously monitors for changes in workspace device configuration (additions or removals of peripheral devices). When changes are detected, the system automatically triggers an update to the workspace certificate, ensuring that the certificate always reflects the current workspace state. This feedback loop maintains integrity without requiring manual intervention, balancing monitoring overhead with automated response
Data Source
AI summary
Systems and methods for providing a workspace Root-of-Trust (RoT) are described. In an embodiment, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to receive a digital certificate from each of a plurality of peripheral devices coupled to the IHS in a workspace and combine at least portions of the digital certificates to create a workspace certificate unique to the workspace.


