Automated Provisioning Framework for Secure Cloud Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of creating and securing large computer-based analytical environments is time-consuming and costly, often taking weeks or months, and is hindered by the need for extensive resources and compliance with security protocols, which delays data analysis and hampers computing agility.

Innovation Solution

An automated provisioning framework that allows users to customize and deploy secure big data analytics environments in the cloud by creating virtual private clouds, provisioning scripts, and integrating infrastructure, analysis tools, and security controls, thereby reducing the time and effort required for security compliance and environment setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional manual processes are used to create and secure analytical environments, then security compliance and proper configuration are ensured, but the process takes weeks or months and incurs high costs

Engineering Contradiction:
Improvesecurity complianceVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring secure analytical environments using automated provisioning frameworks and templates before deployment. Security controls, infrastructure, and configurations are prepared in advance through standardized templates that encode compliance requirements, allowing rapid deployment without manual security assessment during each provisioning event.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating reusable templates and blueprints of secure analytical environments that can be replicated multiple times. These templates contain pre-validating security configurations and infrastructure definitions that can be copied and deployed automatically, eliminating the need to manually recreate security-compliant environments for each new analytical project.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive security protocols are implemented, then data and analytical processes are protected, but the provisioning process is further delayed

Engineering Contradiction:
Improvedata securityVSAvoidprovisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges security protocol implementation with the environment provisioning process itself. Security controls, access policies, and compliance measures are integrated into the automated provisioning framework, so that security is not added as a separate sequential step but is built-in during the initial environment creation, simultaneously achieving both security and speed.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies self-service by implementing automated security validation and compliance checking within the provisioning framework. The system automatically validates security configurations, checks compliance with protocols, and enforces security policies without requiring manual security audits or human intervention, allowing the environment to provision itself with built-in security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If custom analytical environments are built from scratch, then specific requirements are met, but the process requires extensive human capital and resources

Engineering Contradiction:
Improveenvironment customizationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by breaking down analytical environments into modular, reusable components represented as templates. Each template encapsulates specific functional segments (data ingestion, processing, analysis, security controls) that can be independently configured and combined. This modular approach allows customization through composition of standardized segments rather than building entire environments from scratch.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality by creating multi-functional templates that can serve multiple analytical workloads and requirements. A single template framework can be adapted to different analytical needs by configuring parameters and selecting from available components, allowing the same underlying infrastructure and security model to support diverse analytical environments without requiring separate custom-built systems for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10795709B2Systems and method for deploying, securing, and maintaining computer-based analytic environments
Publication Date: 2020.10.06 THE MITRE CORPORATION
  • US10795709B2 patent drawing
  • US10795709B2 patent drawing
  • US10795709B2 patent drawing

AI summary

A method for automatically provisioning a secure data analytic environment is provided. In one or more embodiments, the method can include receiving one or more specifications regarding the data analytic environment to be created from a user, and using the specifications to automatically implement the data analytic environment on a cloud computing environment. In one or more embodiments, the created data analytic environment can be analyzed to determine if the environment is compliant with one or more computing security rules. If the environment is found to be compliant, then the provisioning scripts can be used to generate clones of the originally created analytic environment or modify the pre-existing data analytic environment without requiring the newly created or modified environment to undergo the level of security scrutiny provided when the original analytic environment was created.