Cloud Compliance Representation for Secure Third-Party Audits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud environments face challenges in maintaining compliance with organizational policies without granting direct access to third-party auditors, requiring human intervention or computationally expensive automated monitoring, and necessitating cumbersome scanning processes.

Innovation Solution

A system and method that generates a representation of the computing environment and software inventory using cybersecurity inspection techniques, determines compliance based on this data, and provides compliance information to third parties without granting them access, utilizing a policy engine and large language models to process queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If third-party auditors are granted direct access to the cloud environment for compliance auditing, then compliance monitoring capability is improved, but security of the cloud environment deteriorates

Engineering Contradiction:
Improvecompliance monitoring capabilityVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary compliance monitoring service that acts as a mediator between third-party auditors and the cloud environment. This service receives compliance requirements from auditors, monitors the environment accordingly, and returns compliance status without allowing direct auditor access to the environment, thus resolving the contradiction between monitoring capability and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual representation or copy of the cloud environment's compliance state that can be inspected by third-party auditors. Instead of giving auditors access to the actual environment, the system generates compliance reports and status information that replicate the necessary audit data, maintaining security while enabling monitoring

Inventive Principle:
Principle #26Copying

2Measurement precision

If human intervention is used for compliance inspection, then accuracy of compliance determination is improved, but operational efficiency deteriorates

Engineering Contradiction:
Improvecompliance determination accuracyVSAvoidoperational efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements automated compliance monitoring services that perform compliance determination without requiring human intervention. The system self-monitors the cloud environment against compliance requirements, automatically generates compliance reports, and maintains continuous monitoring, thereby achieving both high accuracy and operational efficiency

Inventive Principle:
Principle #25Self-service

3Measurement precision

If computationally expensive automated monitoring services are deployed, then compliance monitoring accuracy is improved, but resource consumption deteriorates

Engineering Contradiction:
Improvecompliance monitoring accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential compliance-related data and metrics from the cloud environment rather than performing comprehensive computational analysis of the entire environment. The compliance monitoring service focuses specifically on retrieving and evaluating compliance-relevant information, reducing computational overhead while maintaining monitoring accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4546189B1System and method for providing third party compliance to computer and software environments
Publication Date: 2026.05.13 WIZ INC
  • EP4546189B1 patent drawingFigure 1
  • EP4546189B1 patent drawingFigure 2
  • EP4546189B1 patent drawingFigure 3

AI summary

A system and method for providing third party compliance to computing environments without providing access thereto. The method includes: generating a representation of the computing environment, the computing environment including a plurality of identities; generating a software inventory of the computing environment utilizing a cybersecurity inspection technique; determining compliance of the computing environment based on the representation and the software inventory; and providing the determined compliance to a third party, wherein the third party is not associated with the plurality of identities.