Systems and methods for securely deploying a collective workspace across multiple local management agents
Systems and methods for securely deploying a collective workspace across multiple local management agents are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the IHS to: receive, at a workspace orchestration service from a first local management agent, first context information and a first split key; receive, at the workspace orchestration service from a second local management agent, second context information and a second split key; determining, by the workspace orchestration service, that the first and second context information match a collaborative workspace policy; in response to the determination, authenticate the first and second split keys; and in response to the authentication, transmit a collaborative workspace definition to the first and second local management agents.
1 . A memory storage device configured with program instructions stored thereon that, upon execution by an orchestrator Information Handling System (IHS) configured to manage deployment of workspaces on a plurality of user IHSs, cause the orchestrator IHS to:
initiate deployment of a collaborative workspace to provide collaborative access to protected data by two or more of the plurality of user IHSs;
receive from a first local management agent via a first user IHS, first context information that comprises a description of an operation context of the first user IHS, and a first split key;
determine that the first context information is a match to a collaborative workspace policy configured to require that multiple individuals participate in the collaborative workspace in order for the collaborative workspace to provide access to the protected data;
compute a security score and a productivity score based at least in part on the first context information and second context information received from a second local management agent via a second user IHS identified in the collaborative workspace policy;
derive a collaborative workspace definition comprising at least one of a threat monitor level, a threat detection level, a threat analytics level, a threat response level, a storage confidentiality level, a network confidentiality level, a memory confidentiality level, a display confidentiality level, a user authentication level, an IT administration level, a regulatory compliance level, a local storage control level, a CPU access level, a graphics access level, an application usage level, or an application installation level, wherein the collaborative workspace definition is configured to specify access provided via the collaborative workspace to the protected data by the first IHS and by the second IHS;
when fewer than a plenary session is present, redact portions of the protected data and reduce redaction as additional participants join until full access at plenary attendance;
wait for the second local management agent to transmit a second split key to the orchestrator IHS; and
in response to receipt of the second split key, transmit a first portion of the collaborative workspace definition to the first local management agent and a second portion of the collaborative workspace definition to a second local management agent via the second user IHS, wherein the agents are configured to instantiate different aspects of the collaborative workspace in accordance with the respective portions of the collaborative workspace definitions, and wherein the respective portions of the collaborative workspace definitions are configured to specify access provided via the collaborative workspace to the protected data by the first IHS and by the second IHS.
2 . The memory storage device of claim 1 , wherein the program instructions, upon execution, further cause the orchestrator IHS to:
authenticate the first split key received from the first local management agent and the second split key received from the second local management agent; and
in response to the authentication, transmit the collaborative workspace definition to the first and second local management agents.
3 . The memory storage device of claim 2 , wherein the first context information received from the first local management agent comprises at least one of: an identification of a locale of the first local management agent, an identification of a user of the first local management agent, an identification of a network of the first local management agent, an identification of hardware of the first local management agent, an identification of a requested datafile, or an identification of a storage system of the requested datafile.
4 . The memory storage device of claim 2 , wherein the program instructions, upon execution, further cause the orchestrator IHS to, in response to the authentication, grant access to the protected data via the collaborative workspace in accordance with the collaborative workspace policy, wherein the first user IHS is granted privileges to edit the protected data, and wherein the second user IHS is granted privileges limited to read of the protected data.
5 . The memory storage device of claim 4 , wherein the program instructions, upon execution, further cause the orchestrator IHS to grant access to the protected data to both the first user IHS and the second user IHS in response to a determination that the first and second local management agents meet a quorum of participants for access to the protected data, as indicated in the collaborative workspace policy.
6 . The memory storage device of claim 2 , wherein the program instructions, upon execution, further cause the orchestrator IHS to, in response to the authentication, redact a portion of the protected data provided via the workspace to the first user IHS and provide full access to the protected data to the second user IHS.
7 . The memory storage device of claim 1 , wherein the program instructions, upon execution, further cause the orchestrator IHS to:
receive, at a workspace orchestration service from a third local management agent via a third user IHS, third context information and a third split key;
authenticate the third split key;
in response to the authentication, transmit the collaborative workspace definition to the third local management agent; and
grant or remove access to a portion of the protected data by the third user IHS.
8 . An orchestrator Information Handling System (IHS) configured to manage deployment of workspaces on a plurality of user IHSs, wherein the orchestrator IHS is configured to:
initiate deployment of a collaborative workspace to provide collaborative access to protected data by two or more of the plurality of user IHSs;
receive from a first local management agent via a first user IHS, first context information that comprises a description of an operation context of the first user IHS, and a first split key;
determine that the first context information is a match to a collaborative workspace policy configured to require that multiple individuals participate in the collaborative workspace in order for the collaborative workspace to provide access to the protected data;
compute a security score and a productivity score based at least in part on the first context information and second context information received from a second local management agent via a second user IHS identified in the collaborative workspace policy;
derive a collaborative workspace definition comprising at least one of a threat monitor level, a threat detection level, a threat analytics level, a threat response level, a storage confidentiality level, a network confidentiality level, a memory confidentiality level, a display confidentiality level, a user authentication level, an IT administration level, a regulatory compliance level, a local storage control level, a CPU access level, a graphics access level, an application usage level, or an application installation level, wherein the collaborative workspace definition is configured to specify access provided via the collaborative workspace to the protected data by the first IHS and by the second IHS;
when fewer than a plenary session is present, redact portions of the protected data and reduce redaction as additional participants join until full access at plenary attendance;
wait for the second local management agent operating on a second user IHS identified in the collaborative workspace policy to transmit a second split key to the orchestrator IHS; and
in response to receipt of the second split key, transmit a first portion of the collaborative workspace definition to the first local management agent and a second portion of the collaborative workspace definition to a second local management agent via the second user IHS, wherein the agents are configured to instantiate different aspects of the collaborative workspace in accordance with the respective portions of the collaborative workspace definitions, and wherein the respective portions of the collaborative workspace definitions are configured to specify access provided via the collaborative workspace to the protected data by the first IHS and by the second IHS.
9 . The orchestrator IHS of claim 8 , wherein the orchestrator IHS is further configured to:
authenticate the first split key received from the first local management agent and the second split key received from the second local management agent; and
in response to the authentication, transmit the collaborative workspace definition to the first and second local management agents.
10 . The orchestrator IHS of claim 8 , wherein the first context information received from the first local management agent comprises at least one of: an identification of a locale of the first local management agent, an identification of a user of the first local management agent, an identification of a network of the first local management agent, an identification of hardware of the first local management agent, an identification of a requested datafile, or an identification of a storage system of the requested datafile.
11 . A method for managing deployment of a collaborative workspace on a plurality of user Information Handling Systems (IHSs) by an orchestrator IHS, the method comprising:
initiating deployment of the collaborative workspace for providing collaborative access to protected data by two or more of the plurality of user IHSs;
receiving from a first local management agent operating on a first user IHS, first context information describing an operating context of the first user IHS, and a first split key;
determining that the first context information matches a collaborative workspace policy that requires multiple individuals to participate in the collaborative workspace in order for the collaborative workspace to provide access to the protected data;
computing a security score and a productivity score based at least in part on the first context information and second context information received from a second local management agent via a second user IHS identified in the collaborative workspace policy;
deriving a collaborative workspace definition comprising at least one of a threat monitoring level, a threat detection level, a threat analytics level, a threat response level, a storage confidentiality level, a network confidentiality level, a memory confidentiality level, a display confidentiality level, a user authentication level, an IT administration level, a regulatory compliance level, a local storage control level, a CPU access level, a graphics access level, an application usage level, or an application installation level, wherein the collaborative workspace definition is configured to specify access provided via the collaborative workspace to the protected data by the first IHS and by the second IHS;
when fewer than a plenary session is present, redacting portions of the protected data and reducing redaction as additional participants join until full access at plenary attendance;
waiting for the second local management agent operating on a second user IHS identified in the collaborative workspace policy to transmit a second split key to the orchestrator IHS; and
in response to receiving the second split key, transmitting a first portion of the collaborative workspace definition to the first local management agent and a second portion of the collaborative workspace definition to a second local management agent via the second user IHS, wherein the agents are configured to instantiate different aspects of the collaborative workspace in accordance with the respective portions of the collaborative workspace definitions, and wherein the respective portions of the collaborative workspace definitions are configured to specify access provided via the collaborative workspace to the protected data by the first IHS and by the second IHS.
12 . The method of claim 11 , further comprising:
authenticating, by the orchestrator IHS, the first split key received from the first local management agent operating on the first user IHS and the second split key received from the second local management agent operating on the second user IHS; and
in response to the authentication by the orchestrator IHS, transmitting the collaborative workspace definition to the first and second local management agents.
13 . The method of claim 11 , wherein the first context information received from the first local management agent operating on the first IHS comprises at least one of: an identification of a locale of the first local management agent, an identification of a user of the first local management agent, an identification of a network of the first local management agent, an identification of hardware of the first local management agent, an identification of a requested datafile, or an identification of a storage system of the requested datafile.