IP Library Granted Patent US 11,595,322
Granted Patent B2
US 11,595,322 · App. 17/124,295 · Granted Feb 28, 2023

Systems and methods for performing self-contained posture assessment from within a protected portable-code workspace

Inventors: Nicholas D. Grobelny (Austin, TX); Girish S. Dhoble (Austin, TX); Joseph Kozlowski (Hutto, TX); David Konetski (Austin, TX)
Assignee: Dell Products, L.P.
H04L47/781G06F8/36G06F16/958H04L47/803
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,322
App. No.
17/124,295
Granted
Feb 28, 2023
Kind
B2
Abstract

Systems and methods for performing self-contained posture assessment from within a protected portable-code workspace are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory having program instructions that, upon execution, cause the IHS to: transmit, from an orchestration service to a local agent, a workspace definition that references an application, where the application comprises a first portion of code provided by a developer and a second portion of code provided by the orchestration service; and receive, from a local agent at the orchestration service, a message in response to the execution of the second portion of code within a workspace instantiated based upon the workspace definition. The second portion of code may inspect the contents of the runtime memory of the workspace upon execution, for example, by performing a stack canary check, a hash analysis, a boundary check, and/or a memory scan.

Claims (25)

1. An Information Handling System (IHS), the IHS comprising:

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to:

transmit, from a workspace orchestration service to a local management agent, a workspace definition that references an application, wherein the application comprises a first portion of code provided by a developer and a second portion of code provided by the workspace orchestration service, wherein the workspace definition comprises: (a) a security target determined based upon a security context, and (b) a productivity target determined based upon a productivity context where a workspace is deployed, and wherein the second portion of code, upon execution, further causes the IHS to inspect contents of a runtime memory of the workspace through at least one of: a stack canary check, a hash analysis, or a boundary check; and

receive, from a local management agent at the workspace orchestration service, a message in response to the execution of the second portion of code within the workspace instantiated based upon the workspace definition, wherein the workspace orchestration service lacks the ability to inspect contents of a runtime memory of the workspace, wherein the second portion of code is retrieved from a library provided by the workspace orchestration service, wherein the library is configured to automatically update as new threats are discovered, and wherein the second portion of code is updated to incorporate one or more inspection techniques against the new threats.

2. The IHS of claim 1 , wherein the application comprises a progressive web application (PWA) or a browser-based application.

3. The IHS of claim 1 , wherein the second portion of code is configured to inspect the contents of the runtime memory of the workspace upon execution.

4. The IHS of claim 3 , wherein to inspect the contents of the runtime memory, the second portion of code is configured to perform, upon execution, at least one of: a stack canary check, a hash analysis, or a boundary check.

5. The IHS of claim 3 , wherein the message provides an assessment of the contents of the runtime memory of the workspace.

6. The IHS of claim 3 , wherein the program instructions, upon execution, further cause the IHS to, in response to the message, transmit a second workspace definition to the local management agent, wherein the local management agent is configured to instantiate a second workspace based upon the second workspace definition.

7. The IHS of claim 6 , wherein the program instructions, upon execution, further cause the IHS to, in response to the message, facilitate a migration of at least one of: an application, or document, from the workspace to the second workspace.

8. The IHS of claim 7 , wherein the program instructions, upon execution, further cause the IHS to, in response to the message, transmit another message to the local management agent to terminate the workspace.

9. The IHS of claim 1 , wherein the program instructions, upon execution, further cause the IHS to make the second portion of code available to the developer as a library.

10. A memory storage device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

receive a first portion of code from a developer;

receive a second portion of code from a workspace orchestration service, wherein the second portion of code is retrieved from a library provided by the workspace orchestration service, wherein the library is configured to automatically update as new threats are discovered, wherein the second portion of code is updated to incorporate one or more inspection techniques against the new threats, and wherein the second portion of code, upon execution, further causes the IHS to inspect contents of a runtime memory of the workspace through at least one of: a stack canary check, a hash analysis, or a boundary check; and

assemble the first and second portions of code into an application, wherein the application is referenced in a workspace definition that, upon instantiation into a workspace by a local management agent, sends a message to the workspace orchestration service indicating the contents of a runtime memory of the workspace, wherein the workspace definition comprises: (a) a security target determined based upon a security context, and (b) a productivity target determined based upon a productivity context where a workspace is deployed, and wherein the workspace orchestration service lacks the ability to inspect the contents of the runtime memory of the workspace.

11. The memory storage device of claim 10 , wherein the application comprises a progressive web application (PWA) or a browser-based application.

12. The memory storage device of claim 10 , wherein in response to the message, the workspace orchestration service is configured to transmit a second workspace definition to the local management agent, and wherein the local management agent is configured to instantiate a second workspace based upon the second workspace definition.

13. The memory storage device of claim 12 , wherein in response to the message, the workspace orchestration service is configured to facilitate a migration of at least one of: an application, or document, from the workspace to the second workspace.

14. The memory storage device of claim 13 , wherein in response to the message, the workspace orchestration service is configured to transmit another message to the local management agent to terminate the workspace.

15. The memory storage device of claim 13 , wherein the workspace orchestration service is configured to make the second portion of code available to the developer as a library.

16. A method, comprising:

transmitting, from a workspace orchestration service to a local management agent, a workspace definition that references an application, wherein the application comprises a first portion of code provided by a developer and a second portion of code provided by the workspace orchestration service, wherein the workspace definition comprises: (a) a security target determined based upon a security context, and (b) a productivity target determined based upon a productivity context where a workspace is deployed, and wherein the second portion of code, upon execution, further causes the IHS to inspect contents of a runtime memory of the workspace through at least one of: a stack canary check, a hash analysis, or a boundary check; and

receiving, from a local management agent at the workspace orchestration service, a message in response to the execution of the second portion of code within the workspace instantiated based upon the workspace definition, wherein the workspace orchestration service lacks the ability to inspect contents of a runtime memory of the workspace, wherein the second portion of code is retrieved from a library provided by the workspace orchestration service, wherein the library is configured to automatically update as new threats are discovered, and wherein the second portion of code is updated to incorporate one or more inspection techniques against the new threats.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2020
From: GROBELNY, NICHOLAS D.; DHOBLE, GIRISH S.; KOZLOWSKI, JOSEPH; KONETSKI, DAVID
To: DELL PRODUCTS, L.P.
Reel/Frame 054673/0271 →
Continuity (1)
Related Publication 20220191152A1 · Jun 16, 2022