IP Library Granted Patent US 11,929,989
Granted Patent B2
US 11,929,989 · App. 17/209,549 · Granted Mar 12, 2024

Systems and methods for orchestrated VPN consolidation for modern workspaces

Inventors: Vivek Viswanathan Iyer (Austin, TX); Gokul Thiruchengode Vajravel (Bangalore, IN); Michael S. Gatson (Austin, TX)
Assignee: Dell Products, L.P.
H04L63/0272G06F9/54
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,929,989
App. No.
17/209,549
Granted
Mar 12, 2024
Kind
B2
Abstract

Systems and methods are provided for consolidation of IHS (Information Handling System) VPN (Virtual Private Network) resources utilized by workspaces operating on the IHS, where the workspaces operate in isolation from the operating system of the IHS. A remote workspace orchestration service manages deployment of workspaces on the IHS. The workspaces are instantiated and operate according to a workspace definition provided by the workspace orchestration service. An embedded controller of the IHS registers a VPN consolidation function of the IHS with the workspace orchestration service, which notifies the workspaces of the VPN consolidation function. A VPN workspace is instantiated that operates according to a workspace definition provided by the workspace orchestration service. The respective workspace definitions of the workspaces are updated to route VPN communications to the VPN workspace. Based on the updated workspace definitions, the VPN communications in each of the workspaces are redirected to the VPN consolidation function.

Claims (43)

1. A method for VPN (Virtual Private Network) session management for a plurality of workspaces operating on an Information Handling System (IHS), the method comprising:

registering a VPN consolidation function of the IHS with a workspace orchestration service that is remote from the IHS and manages deployment of the plurality of workspaces on the IHS;

instantiating a first workspace according to a first workspace definition provided by the workspace orchestration service;

instantiating a second workspace on the IHS, wherein the second workspace comprise a VPN workspace that operates according to a second workspace definition provided by the workspace orchestration service, wherein the second workspace definition comprises credentials for tunneling to a first VPN endpoint;

receiving, from the workspace orchestration service, a handle for communicating VPN data between the first workspace and the VPN workspace; and

transmitting the VPN data between the VPN workspace and the first VPN endpoint via a tunnel generated based on the credentials provided in the second workspace definition.

2. The method of claim 1 , wherein the handle further comprises a token specifying a duration of the validity of the handle for communicating VPN data between the first workspace and the VPN workspace.

3. The method of claim 2 , wherein the handle further comprises one or more conditions for evaluating the validity of the token.

4. The method of claim 3 , wherein the conditions comprise a minimum security score that must be maintained for the handle to remain valid, wherein the security score is determined based on a validation of an integrity of the first workspace.

5. The method of claim 2 , wherein the token is generated by the workspace orchestration service based on a unique identifier of the IHS and based a unique identifier of the first workspace.

6. The method of claim 1 , wherein the first workspace is not provided credentials for tunneling to the first VPN endpoint.

7. The method of claim 1 , further comprising instantiating a third workspace on the IHS, wherein the third workspace comprises an additional VPN workspace that operates according to a third workspace definition provided by the workspace orchestration service, wherein the third workspace definition comprises credentials for tunneling to a second VPN endpoint.

8. The method of claim 1 , wherein the interface of the handle comprises an API (Application Programming Interface) for communicating VPN data between the first workspace and the VPN workspace.

9. The method of claim 1 , wherein the handle further comprises an IPC (Inter-Process Communication) resource of the IHS for use in communicating VPN data between the first workspace and the VPN workspace.

10. The system of claim 1 , wherein the first workspace is not provided credentials for tunneling to the first VPN endpoint.

11. The system of claim 1 , wherein execution of the instructions by the processors further causes the IHS to instantiate third workspace on the IHS, wherein the third workspace comprises an additional VPN workspace that operates according to a third workspace definition provided by the workspace orchestration service, wherein the third workspace definition comprises credentials for tunneling to a second VPN endpoint.

12. The system of claim 1 , wherein the handle further comprises a token specifying a duration of the validity of the handle for communicating VPN data between the first workspace and the VPN workspace.

13. An Information Handling System (IHS) supporting VPN (Virtual Private Network) session management for a plurality of workspaces operating on the IHS, the IHS comprising:

an embedded controller comprising a logic unit and a memory storing program instructions that, upon execution by the logic unit, cause the embedded controller to:

register a VPN consolidation function of the IHS with a workspace orchestration service that is remote from the IHS and manages deployment of the plurality of workspaces on the IHS;

one or more processors; and

a memory coupled to the processors, the memory storing program instructions that, upon execution by the processors, cause the IHS to:

instantiate a first workspace according to a first workspace definition provided by the workspace orchestration service;

instantiate a second workspace on the IHS, wherein the second workspace comprises a VPN workspace that operates according to a second workspace definition provided by the workspace orchestration service, wherein the second workspace definition comprises credentials for tunneling to a first VPN endpoint;

receive, from the workspace orchestration service, a handle for communicating VPN data between the first workspace and the VPN workspace; and

transmit the VPN data between the VPN workspace and the first VPN endpoint via a tunnel generated based on the credentials provided in the second workspace definition.

14. The IHS of claim 13 , wherein the first workspace is not provided credentials for tunneling to the first VPN endpoint.

15. The IHS of claim 13 , wherein execution of the instructions by the processors further causes the IHS to instantiate third workspace on the IHS, wherein the third workspace comprises an additional VPN workspace that operates according to a third workspace definition provided by the workspace orchestration service, wherein the third workspace definition comprises credentials for tunneling to a second VPN endpoint.

16. The IHS of claim 13 , wherein the handle further comprises a token specifying a duration of the validity of the handle for communicating VPN data between the first workspace and the VPN workspace.

17. The IHS of claim 13 , wherein the handle further comprises a token specifying a duration of the validity of the handle for communicating VPN data between the first workspace and the VPN workspace.

18. The IHS of claim 17 , wherein the handle further comprises one or more conditions for evaluating the validity of the token.

19. The IHS of claim 18 , wherein the conditions comprise a minimum security score that must be maintained for the handle to remain valid, wherein the security score is determined based on a validation of an integrity of the first workspace.

20. A system supporting a plurality of workspaces operating on an Information Handling System (IHS), the system comprising:

a workspace orchestration service that is remote from the IHS and that manages deployment of workspaces on the IHS; and

the IHS comprising:

an embedded controller comprising a logic unit and a memory storing program instructions that, upon execution by the logic unit, cause the embedded controller to:

register a VPN consolidation function of the IHS with a workspace orchestration service;

a processor; and

a memory coupled to the processor, the memory storing program instructions that, upon execution by the processor, cause the IHS to:

instantiate a first workspace according to a first workspace definition provided by the workspace orchestration service;

instantiate a second workspace on the IHS, wherein the second workspace comprises a VPN workspace that operates according to a second workspace definition provided by the workspace orchestration service, wherein the second workspace definition comprises credentials for tunneling to a first VPN endpoint;

receive, from the workspace orchestration service, a handle for communicating VPN data between the first workspace and the VPN workspace; and

transmit the VPN data between the VPN workspace and the first VPN endpoint via a tunnel generated based on the credentials provided in the second workspace definition.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2021
From: IYER, VIVEK VISWANATHAN; VAJRAVEL, GOKUL THIRUCHENGODE; GATSON, MICHAEL S.
To: DELL PRODUCTS, L.P.
Reel/Frame 055684/0743 →