IP Library Granted Patent US 12,170,686
Granted Patent B2
US 12,170,686 · App. 17/124,324 · Granted Dec 17, 2024

Fleet remediation of compromised workspaces

Inventors: Nicholas D. Grobelny (Austin, TX); Charles D. Robison (Buford, GA); Ricardo L. Martinez (Leander, TX)
Assignee: Dell Products, L.P.
H04L63/1441G06Q10/06315G06Q10/10H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,170,686
App. No.
17/124,324
Granted
Dec 17, 2024
Kind
B2
Abstract

Systems and methods for providing fleet remediation of compromised workspaces are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive, from a first local management agent configured to provide a first workspace in a fleet of workspaces, an indication that the first workspace has suffered a security compromise, where the first workspace is instantiated based upon a first workspace definition; and in response to the indication, transmit a second workspace definition to a second local management agent configured to provide a second workspace in the fleet of workspaces, where the second workspace is instantiated based upon the first workspace definition, and where the second local management agent is configured to instantiate a third workspace based upon the second workspace definition.

Claims (37)

1. An Information Handling System (IHS), the IHS comprising:

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to:

receive, at a workspace orchestration service and from a first local management agent configured to provide a first workspace in a fleet of workspaces, an indication that the first workspace has suffered a security compromise, wherein the first workspace is instantiated based upon a first workspace definition; and

in response to the indication received from the first local management agent that the first workspace has suffered the security compromise, transmit, by the workspace orchestration service, a second workspace definition, with a different attack surface than the first workspace definition, to a second local management agent configured to provide a second workspace in the fleet of workspaces, wherein the second workspace is instantiated based upon the first workspace definition, wherein the second local management agent is configured to instantiate a third workspace based upon the second workspace definition, with the different attack surface, that was transmitted by the workspace orchestration service, and wherein the second local management agent is further configured to instantiate the third workspace without an indication that the second workspace has suffered the security compromise.

2. The IHS of claim 1 , wherein the indication comprises the absence of a heartbeat, token, or handshake from the first local management agent.

3. The IHS of claim 1 , wherein the program instructions, upon execution, further cause each local management agent instantiating a respective workspace in the fleet of workspaces to be identified in or associated with the first and second workspace definitions.

4. The IHS of claim 1 , wherein the security compromise comprises at least one of: a denial-of-service (DOS) attack, a man-in-the-middle (MitM) attack, a phishing attack, a drive-by attack, a password attack, an SQL injection attack, a cross-site scripting (XSS) attack, an eavesdropping attack, or a malware attack.

5. The IHS of claim 1 , wherein the first local management agent is configured to indicate that the first workspace has suffered the security compromise in response to a failed authentication of at least one of: a key derivation function (KDF), a nested hash, a blockchain, a one-time-password (OTP) algorithm, prime factoring, a monotonic counter, or a public key infrastructure (PKI) challenge-response protocol.

6. The IHS of claim 1 , wherein the second workspace definition has a smaller attack surface than the first workspace definition.

7. The IHS of claim 1 , wherein the second workspace definition comprises at least one modified: minimum security score for a workspace, authentication requirement, isolation requirements, ability to access a browser, ability to transfer data between workspaces, the ability to extend a workspace.

8. The IHS of claim 1 , wherein the second local management agent is configured to terminate the second workspace.

9. The IHS of claim 1 , wherein the second local management agent is configured to migrate a context of the second workspace onto the third workspace.

10. A memory storage device having program instructions stored thereon that, upon execution by an Information Handling System (IHS), cause the IHS to:

receive a first workspace definition from a workspace orchestration service at a first local management agent; instantiate a first workspace based upon the first workspace definition;

receive a second workspace definition, with a different attack surface than the first workspace definition, from the workspace orchestration service in response to the workspace orchestration service having received an indication that a second workspace instantiated by a second local management agent based upon the first workspace definition has suffered a security compromise, wherein the first and second workspaces are part of a fleet of workspaces; and

instantiate a third workspace based upon the second workspace definition, with the different attack surface, that was transmitted by the workspace orchestration service in response to the indication that the second workspace has suffered the security compromise, wherein the third workspace is instantiated without an indication that the first workspace has suffered the security compromise.

11. The memory storage device of claim 10 , wherein the first and second workspace definitions comprise an identification of or are associated with the fleet of workspaces.

12. The memory storage device of claim 10 , wherein the security compromise comprises at least one of: a denial-of-service (DOS) attack, a man-in-the-middle (MitM) attack, a phishing attack, a drive-by attack, a password attack, an SQL injection attack, a cross-site scripting (XSS) attack, an eavesdropping attack, or a malware attack.

13. The memory storage device of claim 10 , wherein the second local management agent is configured to indicate that the second workspace has suffered the security compromise in response to a failed authentication of at least one of: a key derivation function (KDF), a nested hash, a blockchain, a one-time-password (OTP) algorithm, prime factoring, a monotonic counter, or a public key infrastructure (PKI) challenge-response protocol.

14. The memory storage device of claim 10 , wherein the second workspace definition has a smaller attack surface than the first workspace definition.

15. The memory storage device of claim 10 , wherein the second workspace definition comprises at least one modified: minimum security score for a workspace, authentication requirement, isolation requirements, ability to access a browser, ability to transfer data between workspaces, the ability to extend a workspace.

16. The memory storage device of claim 10 , wherein the program instructions, upon execution, further cause the IHS to terminate the first workspace.

17. The memory storage device of claim 10 , wherein the program instructions, upon execution, further cause the IHS to migrate a context of the first workspace onto the third workspace.

18. A method, comprising:

receiving, at a workspace orchestration service and from a first local management agent configured to provide a first workspace in a fleet of workspaces, an indication that the first workspace has suffered a security compromise, wherein the first workspace is instantiated based upon a first workspace definition; and

in response to the indication received from the first local management agent that the first workspace has suffered the security compromise, transmitting, by the workspace orchestration service, a second workspace definition, with a different attack surface than the first workspace definition, to a second local management agent configured to provide a second workspace in the fleet of workspaces, wherein the second workspace is instantiated based upon the first workspace definition, and wherein the second local management agent is configured to instantiate a third workspace based upon the second workspace definition, with the different attack surface, that was transmitted by the workspace orchestration service, without an indication that the second workspace has suffered the security compromise.

19. The method of claim 18 , further comprising:

instantiating, by the second local management agent, the second workspace based upon the first workspace definition;

receiving, by the second local management agent from the workspace orchestration service, the second workspace definition with the different attack surface than the first workspace definition;

instantiating, by the second local management agent, the third workspace based upon the received second workspace definition; and

terminating, by the second local management agent, the second workspace, without the indication that the second workspace has suffered the security compromise.

20. The method of claim 18 , further comprising:

instantiating, by the second local management agent, the second workspace based upon the first workspace definition;

receiving, by the second local management agent from the workspace orchestration service, the second workspace definition with the different attack surface than the first workspace definition;

instantiating, by the second local management agent, the third workspace based upon the received second workspace definition; and

migrating, by the second local management agent, a context of the second workspace onto the third workspace, without the indication that the second workspace has suffered the security compromise.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2020
From: GROBELNY, NICHOLAS D.; ROBISON, CHARLES D.; MARTINEZ, RICARDO L.
To: DELL PRODUCTS, L.P.
Reel/Frame 054673/0417 →
Continuity (1)
Related Publication 20220191239A1 · Jun 16, 2022