Cloud Configuration Engine Automating Compliance Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing infrastructures face challenges in ensuring compliance and security, particularly in managing complex compartmentalized environments, which leads to errors and increased costs due to manual configuration requirements and lack of automated compliance frameworks.

Innovation Solution

The implementation of a robust and secure cloud-based platform that automates the configuration of cloud computing services by creating virtual networks, subnets, and routing tables, enforcing traffic through firewalls, and using network security groups to ensure compliance with standards like HIPAA and NIST, thereby providing continuous configuration automation and zero-trust security models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration methods are used for cloud computing environments, then flexibility and customization are improved, but error rates increase and compliance management becomes difficult

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidcompliance assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs self-configuration of cloud computing environments by automatically generating and applying security rules, routing tables, and network policies based on compliance requirements, eliminating manual configuration errors while maintaining flexibility through programmable compliance frameworks

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically adjusts configuration parameters such as security rule sets, routing table entries, and network policy definitions based on compliance standards, allowing automatic adaptation to different regulatory requirements while ensuring consistent compliance enforcement

Inventive Principle:
Principle #35Parameter changes

2Reliability

If automated configuration systems are implemented, then compliance assurance and security are improved, but system complexity increases

Engineering Contradiction:
Improvecompliance assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces configuration engines as intermediary components that mediate between compliance requirements and cloud resource provisioning, automatically translating high-level compliance policies into specific configuration parameters without requiring direct complex manual intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary configuration actions by pre-defining compliance rule sets, security policies, and routing table templates before cloud resource deployment, ensuring compliance is built-in from the outset rather than requiring complex post-deployment adjustments

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security rules are enforced for all traffic, then security is improved, but processing overhead and costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system applies security rules with local quality by configuring zone-specific firewall policies and routing table entries that direct traffic through appropriate security checkpoints based on destination and source characteristics, ensuring comprehensive security coverage while minimizing unnecessary processing overhead through targeted rule application

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12041092B2Robust and secure cloud-based platform for data processing and management
Publication Date: 2024.07.16 SENTARA HEALTHCARE
  • US12041092B2 patent drawing
  • US12041092B2 patent drawing
  • US12041092B2 patent drawing

AI summary

Methods, devices and systems for providing a robust and secure cloud-based platform for data processing and management are described. In an example, a method for improving the configurability and compliance of a cloud-computing environment comprising a plurality of zones includes receiving, at a configuration engine, a plurality of parameters and a plurality of security rules for each of the plurality of zones, creating, based on the plurality of parameters, a virtual network and one or more subnets for each of the plurality of zones, and updating, based on the plurality of security rules, one or more routing tables assigned to the one or more subnets to ensure traffic to and from a zone of the plurality of zones passes through a corresponding firewall of the zone.