IP Library › Granted Patent US 11,334,675
Granted Patent B2
US 11,334,675 · App. 16/671,006 · Granted May 17, 2022

Systems and methods for supporting secure transfer of data between workspaces

Inventors: Carlton A. Andrews (Austin, TX); Girish S. Dhoble (Austin, TX); Nicholas D. Grobelny (Austin, TX); David Konetski (Austin, TX); Joseph Kozlowski (Hutto, TX); Ricardo L. Martinez (Leander, TX); Charles D. Robison (Buford, GA)
Assignee: Dell Products, L.P.
G06F21/606G06F9/544G06F21/602G06F21/6218H04L47/781H04L47/82
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,334,675
App. No.
16/671,006
Filed
Oct 31, 2019
Granted
May 17, 2022
Kind
B2
Art Unit
2492
USPC
713/189
Abstract

Systems and methods support secure transfer of data between workspaces operating on an IHS (Information Handling System). Upon a request for access to a first managed resource, such as protected data, a first workspace is deployed according to a first workspace definition. Upon a request for access to a second managed resource, a second workspace is deployed according to a second workspace definition. In response to an indication of a portion of the protected data from the first workspace being copied to a buffer supported by the IHS and of a request to paste the copied portion of the protected data to the second workspace, the protections provided by the second workspace are evaluated. If the protections of the second workspace are inadequate, an updated second workspace definition is selected that specifies additional protections. The second workspace is updated according to the updated second workspace definition and the transfer is permitted.

Claims (40)

1. A method, comprising:

deploying a first workspace on an IHS (Information Handling System) in response to a request for access to a first managed resource, wherein the first workspace is deployed according to a first workspace definition, and wherein the first managed resource comprises protected data;

deploying a second workspace on the IHS in response to a request for access to a second managed resource, wherein the second workspace is deployed according to a second workspace definition;

receiving an indication of a portion of the protected data from the first workspace copied to a buffer supported by the IHS and of a request to paste the copied portion of the protected data to the second workspace;

when the second workspace is does not provide protection for providing access to the copied portion of the protected data, selecting an updated second workspace definition that specifies protections for the copied portion of the protected data, wherein the protection provided by the second workspace is evaluated based on a security context for the second workspace, wherein the security context comprises a risk level associated with the copied portion of the protected data, wherein the risk level associated with the copied portion of the protected data is evaluated based on fuzzy hashing of the buffer and the protected data;

updating the second workspace to operate according to the updated second workspace definition; and

permitting transfer of the copied portion of the protected data to the updated second workspace.

2. The method of claim 1 , wherein the updated second workspace definition specifies availability of a software application for providing protected access to the copied portion of the protected data.

3. The method of claim 2 , wherein the buffer comprises a buffer supported by a workspace management agent of the IHS.

4. The method of claim 3 , wherein the buffer is an isolated memory of the IHS.

5. An Information Handling System (IHS), comprising:

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to:

initialize a first workspace providing access to a first managed resource according to a first workspace definition, wherein the first managed resource comprises protected data;

initialize a second workspace providing access to a second managed resource according to a second workspace definition;

provide an indication of a portion of the protected data from the first workspace being copied to a buffer supported by the IHS and of an attempt to paste the copied portion of the protected data to the second workspace;

receive, when the second workspace does not provide protection for providing access to the copied portion of the protected data, an updated second workspace definition that specifies protections for the copied portion of the protected data, wherein the protection provided by the second workspace is evaluated based on a security context for the second workspace, wherein the security context comprises a risk level associated with the copied portion of the protected data, wherein the risk level associated with the copied portion of the protected data is evaluated based on fuzzy hashing of the buffer and the protected data;

update the second workspace to operate according to an updated second workspace definition; and

permit transfer of the copied portion of the protected data to the updated second workspace.

6. The IHS of claim 5 , further comprising:

a trusted controller comprising a logic unit and a memory coupled to the logic unit, the memory having program instructions stored thereon that, upon execution by the processor, cause the trusted controller to generate the indication of a portion of the protected data from the first workspace being copied to a buffer supported by the IHS.

7. The IHS of claim 5 , wherein the buffer comprises a buffer supported using the memory of the trusted controller.

8. The IHS of 5 , wherein the updated second workspace definition specifies availability of a software application for providing protected access to the copied portion of the protected data.

9. A system comprising:

an Information Handling System (IHS), comprising a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to:

initialize a first workspace providing access to a first managed resource according to a first workspace definition, wherein the first managed resource comprises protected data;

initialize a second workspace providing access to a second managed resource according to a second workspace definition;

provide, to a workspace orchestration system, an indication of a portion of the protected data from the first workspace being copied to a buffer supported by the IHS and of an attempt to paste the copied portion of the protected data to the second workspace;

update the second workspace to operate according to an updated second workspace definition received from the workspace orchestration system; and

permit transfer of the copied portion of the protected data to the updated second workspace; and

the workspace orchestration system comprising a plurality of IHSs configured to:

receive the indication of the copied portion of the protected data and the request to paste the copied portion of the protected data to the second workspace;

determine whether the second workspace provides protection for providing access to the copied portion of the protected data;

when the second workspace does not provide protection for providing access to the copied portion of the protected data, select an updated second workspace definition that specifies protections for the copied portion of the protected data; and

transmit the updated second workspace definition to the IHS.

10. The system of claim 9 , wherein the updated second workspace definition specifies availability of a software application for providing protected access to the copied portion of the protected data.

11. The system of claim 9 , wherein the buffer is an isolated memory of the IHS.

12. The system of claim 9 , wherein protection provided by the second workspace is evaluated based on an updated security context for the second workspace that provides access to the copied portion of the protected data.

13. The system of claim 12 , wherein the security context comprises a risk level associated with the copied portion of the protected data.

14. The system of claim 13 , wherein the risk level associated with the copied portion of the protected data is evaluated based on fuzzy hashing of the buffer and the protected data.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2019
From: ANDREWS, CARLTON A.; DHOBLE, GIRISH S.; GROBELNY, NICHOLAS D.; KONETSKI, DAVID; KOZLOWSKI, JOSEPH; MARTINEZ, RICARDO L.; ROBISON, CHARLES D.
To: DELL PRODUCTS, L.P.
Reel/Frame 050885/0639 →
Continuity (1)
Related Publication 20210133336A1 · May 6, 2021
Cited By (2)
US 12,210,643 US 12,724,914