Automated Security Control System for Cloud Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual tasks for enabling and enforcing security controls in dynamic cloud environments are complex, costly, and prone to errors, leading to increased security vulnerabilities and troubleshooting challenges due to the lack of consistency in implementations.

Innovation Solution

A security control system that automates security controls between computer networks by using security control computing devices to receive requests, build token requests, correlate them with security policies, generate access tokens, and validate access, thereby enabling automated authentication and authorization based on declarative runtime dependency definitions and meta-data associated with application dependencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual tasks are used to enable security controls, then security controls can be implemented, but the complexity and cost increase significantly

Engineering Contradiction:
Improvesecurity control implementationVSAvoidmanual task complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service automation where the security control system automatically provisions, manages, and enforces security policies without requiring manual intervention. The automated system performs tasks such as creating security groups, assigning roles, and configuring access control lists autonomously based on service dependency graphs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes with automated computational systems. Manual configuration tasks are substituted by programmatic automation that uses service dependency graphs and metadata to automatically generate and enforce security controls, eliminating the need for manual policy creation and provisioning.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual configuration is used in dynamic cloud environments, then security controls can be established, but consistency and reliability decrease

Engineering Contradiction:
Improvesecurity control consistencyVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adapts security controls to changing cloud environments by continuously updating service dependency graphs and automatically adjusting security policies in real-time. This dynamic approach ensures consistency across fluctuating infrastructure configurations without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The automated system incorporates feedback mechanisms that monitor service interactions and security policy compliance, continuously adjusting security controls based on observed behavior. This feedback loop ensures consistent security enforcement across dynamic cloud environments by detecting and correcting deviations from intended policies.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual security control setup is performed, then initial security can be established, but troubleshooting complexity increases

Engineering Contradiction:
Improvesecurity control enforcementVSAvoidtroubleshooting difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system introduces an automated intermediary layer that manages the complexity between security policies and their enforcement. This intermediary automatically translates high-level security requirements into specific control configurations, providing standardized interfaces for monitoring and troubleshooting that simplify diagnostic processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments security control management into distinct modular components including service dependency graphs, security policy engines, and enforcement points. This segmentation isolates troubleshooting to specific modules, making it easier to identify and resolve issues by examining individual segments rather than the entire system.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If static hub-and-spoke architecture is used, then security controls are manageable, but adaptability to cloud environments decreases

Engineering Contradiction:
Improvesecurity control managementVSAvoidcloud environment adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system transitions from static hub-and-spoke architecture to dynamic service-oriented architecture where security controls are automatically adapted to service dependencies. The system dynamically discovers and configures security policies based on runtime service interactions, enabling adaptability to various cloud topologies while maintaining manageable operations through automation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The automated security control system provides universal applicability across different cloud environments and service architectures. The same automated platform manages security controls for diverse service types and deployment models, eliminating the need for architecture-specific manual configurations and enabling versatile security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10673831B2Systems and methods for automating security controls between computer networks
Publication Date: 2020.06.02 MASTERCARD INT INC
  • US10673831B2 patent drawing
  • US10673831B2 patent drawing
  • US10673831B2 patent drawing

AI summary

A security control (SC) system including one or more security control (SC) computing devices for automating security controls between computer networks is provided. The SC system is configured to receive a request to access a service including a system identifier that identifies a computer system requesting access to a service controlled by the one or more SC computing devices, build a token request based on the request, and correlate the token request to at least one security policy associated with the system identifier. The SC system is also configured to generate an access token in response to the token request, wherein the access token is included in an authorization request, and invoke the service using the authorization request. The SC system is further configured to validate the access token using the at least one security policy and authorize access to the service based on the at least one security policy.