Permissioned Blockchain for Enterprise Security Event Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise security systems face inefficiencies due to the lack of data sharing among multiple security vendors, leading to duplicative actions and performance impairments, as each vendor stores data on proprietary servers without a common platform for exchange.
Innovation Solution
A decentralized and distributed security data exchange system utilizing a permissioned blockchain service for secure, tamper-resistant data sharing among security vendors, implementing secure data streams, incentive-based programs, and smart contracts to prevent duplicate remedial actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security vendors use proprietary servers for data storage, then data security and vendor independence are maintained, but data sharing and collaboration among vendors are prevented
Solution Approach 1:
The patent introduces a permissioned blockchain as an intermediary platform that enables secure data sharing among security vendors. The blockchain acts as a neutral mediator where vendors can store and share security event data without compromising their proprietary server architecture. Smart contracts on the blockchain automatically manage data access permissions and ensure that data sharing occurs in a controlled, secure manner, thus resolving the contradiction between maintaining data security and enabling data sharing.
Solution Approach 2:
The permissioned blockchain platform provides universal data storage and sharing capabilities that serve multiple security vendors simultaneously. Instead of each vendor maintaining separate proprietary systems, the blockchain offers a multi-functional platform that supports various security event types, multiple vendors, and different data access patterns while maintaining security through permission management. This universal platform enables collaboration without sacrificing vendor independence.
2Loss of information
If point-to-point integration is performed between security vendors, then data exchange is enabled, but system complexity and integration effort increase significantly
Solution Approach 1:
The patent merges multiple point-to-point integration relationships into a single centralized blockchain platform. Instead of having separate integration interfaces between each pair of vendors (creating an N×(N-1) integration matrix), all vendors connect to the shared blockchain platform, reducing integration complexity from quadratic to linear scaling. The blockchain's native data exchange mechanisms eliminate the need for custom integration logic between vendor pairs.
Solution Approach 2:
The blockchain platform serves as a universal integration layer that handles all data exchange needs between vendors through standardized interfaces. Smart contracts provide multi-functional capabilities for data submission, querying, validation, and sharing through a single unified system, eliminating the need for multiple specialized integration components that would be required in a point-to-point architecture.
3Adaptability or versatility
If multiple security vendors independently analyze security events, then comprehensive security coverage is achieved, but duplicative remedial actions occur causing performance impairment
Solution Approach 1:
The blockchain platform implements a feedback mechanism where security event data and remedial action status are recorded on-chain. When one vendor performs remediation on a security event, this action is recorded on the blockchain and visible to other vendors. Subsequent vendors can query the blockchain to check if remediation has already been performed and avoid duplicative actions. This feedback loop maintains comprehensive security monitoring while preventing performance degradation from redundant remediation attempts.
Solution Approach 2:
The patent merges the remedial action execution functions of multiple vendors into a coordinated process through the blockchain. Instead of each vendor independently attempting remediation (leading to duplication), the blockchain enables vendors to share remediation status and coordinate their actions. This combining of remediation efforts maintains the versatility of multiple security products while improving overall system performance by eliminating redundant operations.
Data Source
AI summary
Various examples are disclosed for exchanging and acting on detected security events using permissioned blockchain. A unique identifier for a client device is obtained in response to a detected security event being identified. Security event data associated with the detected security event is sent to a plurality of nodes of a blockchain service, where the nodes are associated with a respective one of a plurality of computer security services and are configured to validate the security event data and endorse the security event data in response to predetermined criteria being satisfied. In response to the security event data being validated by the nodes, the security event data is published into the blockchain service as a block that is broadcasted to the nodes, where individual ones of the nodes are configured to store the security event data of the block in a local ledger.


