IP Library Granted Patent US 11,240,109
Granted Patent B2
US 11,240,109 · App. 16/670,516 · Granted Feb 1, 2022

Systems and methods for workspace continuity and remediation

Inventors: Carlton A. Andrews (Austin, TX); Girish S. Dhoble (Austin, TX); Nicholas D. Grobelny (Austin, TX); David Konetski (Austin, TX); Joseph Kozlowski (Hutto, TX); Ricardo L. Martinez (Leander, TX); Charles D. Robison (Buford, GA)
Assignee: Dell Products, L.P.
H04L41/0893H04L63/102H04L63/20H04L67/12H04L67/38H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,240,109
App. No.
16/670,516
Granted
Feb 1, 2022
Kind
B2
Abstract

Systems and methods for modernizing workspace and hardware lifecycle management in an enterprise productivity ecosystem are described. In some embodiments, a client Information Handling System (IHS) may include a processor and a memory, the memory having program instructions that, upon execution by the processor, cause the client IHS to: receive, from a workspace orchestration service, one or more files or policies configured to enable the client IHS to instantiate a first workspace based upon a first workspace definition; allow a user to execute a non-vetted application in the first workspace; determine that the first workspace is compromised; and receive, in response to the determination, from the workspace orchestration service, one or more other files or policies configured to enable the client IHS to instantiate a second workspace based upon a second workspace definition, where the second workspace definition allows execution of a vetted application corresponding to the non-vetted application.

Claims (43)

1. A client Information Handling System (IHS), the client IHS comprising:

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the client IHS to:

instantiate, using one or more files or policies, a first workspace based upon a first workspace definition;

allow a user to execute a non-vetted application in the first workspace;

determine that the first workspace is compromised because the application is non-vetted; and

in response to the determination:

identify a vetted application that corresponds to the non-vetted application, wherein the vetted application is different than the non-vetted application;

instantiate, using one or more other files or policies, a second workspace based upon a second workspace definition, wherein the second workspace definition indicates the vetted application corresponding to the non-vetted application;

cause the client IHS to migrate a workload from the first workspace to the second workspace;

cause the client IHS to transmit, to a workspace orchestration service, cloned user actions and data collected during execution of the non-vetted application in the first workspace, and wherein the one or more other files or policies comprise an indication of the cloned user actions and data that is applicable to the vetted application in the second workspace; and

allow the user to execute the vetted application in the second workspace.

2. The client IHS of claim 1 , wherein the non-vetted application comprises an application that is not vetted, trusted, or recommended by an entity employing the workspace orchestration service.

3. The client IHS of claim 1 , wherein the non-vetted application comprises a first web browser and the vetted application comprises a second web browser.

4. The client IHS of claim 1 , wherein the program instructions, upon execution, further cause the client IHS to notify a workspace orchestration service that the non-vetted application is being executed, and wherein the workspace orchestration service is configured to select the one or more other files or policies in anticipation of the determination that the first workspace is compromised.

5. The client IHS of claim 1 , wherein the program instructions, upon execution, further cause the client IHS to determine that the first workspace is compromised in response to a security risk score being equal to or greater than a threshold value.

6. The client IHS of claim 5 , wherein the threshold value is a security target associated with the first workspace definition.

7. The client IHS of claim 5 , wherein the security risk score is calculated based upon at least one of: a risk metric associated with a locale of the client IHS, a risk metric associated with the user of the client IHS, a risk metric associated with a network of the client IHS, a risk metric associated with hardware of the client IHS, a risk metric associated with a requested datafile, or a regulatory risk metric associated with the user, the locale, and the requested datafile.

8. A memory storage device having program instructions stored thereon that, upon execution by one or more processors of an Information Handling System (IHS) of a workspace orchestration service, cause the IHS to:

instantiate, using one or more files or policies, a first workspace based upon a first workspace definition;

determine that that the first workspace has been compromised due to execution of a non-vetted application; and

in response to the determination:

identify a vetted application that corresponds to the non-vetted application, wherein the vetted application is different than the non-vetted application;

cause the client IHS to migrate a workload from the first workspace to the second workspace;

cause the client IHS to transmit, to a workspace orchestration service, cloned user actions and data collected during execution of the non-vetted application in the first workspace, and wherein the one or more other files or policies comprise an indication of the cloned user actions and data that is applicable to the vetted application in the second workspace; and

instantiate, using one or more other files or policies, a second workspace based upon a second workspace definition, wherein the second workspace definition allows execution of a vetted application corresponding to the non-vetted application, wherein the second workspace definition indicates the vetted application corresponding to the non-vetted application.

9. The memory storage device of claim 8 , wherein the non-vetted application comprises an application that is not vetted, trusted, or recommended by an entity employing the workspace orchestration service.

10. The memory storage device of claim 8 , wherein the non-vetted application is a first web browser and the vetted application is a second web browser.

11. The memory storage device of claim 8 , wherein the program instructions, upon execution, further cause the IHS to receive a notification from the client IHS that the non-vetted application is being executed, and wherein the one or more other files or policies are selected in anticipation of the determination that the first workspace is compromised.

12. The memory storage device of claim 8 , wherein the program instructions, upon execution, further cause the client IHS to determine that the first workspace is compromised in response to a security risk score being equal to or greater than a threshold value, wherein the security risk score is calculated based upon at least one of: a risk metric associated with a locale of the client IHS, a risk metric associated with a user of the client IHS, a risk metric associated with a network of the client IHS, a risk metric associated with hardware of the client IHS, a risk metric associated with a requested datafile, or a regulatory risk metric associated with the user, the locale, and the requested datafile.

13. A method, comprising:

instantiating, using one or more files or policies, a first workspace based upon a first workspace definition;

receiving user actions and data collected during execution of a non-vetted application in the first workspace; and

in response to a determination that the first workspace has been compromised due to execution of the non-vetted application:

identifying a vetted application that corresponds to the non-vetted application, wherein the vetted application is different than the non-vetted application;

instantiating, using one or more other files or policies, a second workspace based upon a second workspace definition, wherein the second workspace definition indicates a vetted application corresponding to the non-vetted application, and wherein the one or more other files or policies comprise at least a subset of the user actions and data to be applied to the vetted application in the second workspace;

cause the client IHS to migrate a workload from the first workspace to the second workspace;

cause the client IHS to transmit, to a workspace orchestration service, cloned user actions and data collected during execution of the non-vetted application in the first workspace, and wherein the one or more other files or policies comprise an indication of the cloned user actions and data that is applicable to the vetted application in the second workspace; and

allowing the user to execute the vetted application in the second workspace.

14. The method of claim 13 , wherein the non-vetted application comprises an application that is not vetted, trusted, or recommended by an entity employing the workspace orchestration service.

15. The method of claim 13 , wherein the non-vetted application is a first web browser and the vetted application is a second web browser.

16. The method of claim 13 , further comprising determining that the first workspace is compromised in response to a security risk score being equal to or greater than a threshold value, wherein the security risk score is calculated based upon at least one of: a risk metric associated with a locale of the client IHS, a risk metric associated with a user of the client IHS, a risk metric associated with a network of the client IHS, a risk metric associated with hardware of the client IHS, a risk metric associated with a requested datafile, or a regulatory risk metric associated with the user, the locale, and the requested datafile.

17. The method of claim 13 , further comprising terminating the first workspace.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2019
From: ANDREWS, CARLTON A.; DHOBLE, GIRISH S.; GROBELNY, NICHOLAS D.; KONETSKI, DAVID; KOZLOWSKI, JOSEPH; MARTINEZ, RICARDO L.; ROBISON, CHARLES D.
To: DELL PRODUCTS, L.P.
Reel/Frame 050932/0110 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2019
From: ANDREWS, CARLTON A.; DHOBLE, GIRISH S.; KONETSKI, DAVID; KOZLOWSKI, JOSEPH; MARTINEZ, RICARDO L.; ROBISON, CHARLES D.
To: DELL PRODUCTS, LP.
Reel/Frame 050883/0616 →
Continuity (1)
Related Publication 20210135943A1 · May 6, 2021
Cited By (1)
US 12,695,789