Unified Cloud Intelligence Model for Multi-Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises using multi-cloud deployments face significant challenges in securing data across multiple cloud providers due to the lack of a cohesive security model for identities and data movement, leading to increased vulnerabilities and compliance complexities.

Innovation Solution

A cloud data control intelligence framework that utilizes a unified cloud intelligence model to dynamically manage and report on cloud resources, providing continuous security and compliance across multiple cloud environments, including identity and data activity monitoring across cloud accounts and third-party data stores.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises use multiple cloud providers and cloud accounts to reduce costs and improve service delivery, then productivity and service delivery are improved, but device complexity and security management difficulty increase significantly

Engineering Contradiction:
Improveservice deliveryVSAvoidcloud account complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud control intelligence framework as an intermediary layer between enterprises and multiple cloud providers. This framework includes a cloud intelligence data model that abstracts and unifies the management of identities, data, and resources across different cloud accounts and providers, allowing enterprises to manage multi-cloud environments without directly dealing with the complexity of each individual cloud platform

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud intelligence data model is designed to be universal and provider-agnostic, capable of representing and managing resources from multiple cloud providers through a unified schema. The framework provides multi-functional capabilities including security management, compliance monitoring, cost tracking, and resource orchestration across heterogeneous cloud environments through a single system

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If enterprises expand cloud deployments rapidly to meet growing data needs, then productivity and scalability are improved, but security vulnerabilities and compliance risks increase

Engineering Contradiction:
Improvedata processing capacityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The framework performs preliminary security assessments and compliance checks before resources are deployed to cloud environments. The cloud intelligence data model pre-defines security policies, compliance rules, and risk assessment criteria that are applied automatically during resource provisioning and configuration, preventing security vulnerabilities before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors cloud resource configurations, data movements, and access patterns, providing real-time feedback on security risks and compliance status. This feedback loop enables dynamic risk assessment and automatic remediation actions, allowing enterprises to maintain security posture even as cloud deployments expand rapidly

Inventive Principle:
Principle #23Feedback

3Reliability

If enterprises implement comprehensive security monitoring across multiple cloud accounts, then reliability and security are improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity assuranceVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security monitoring, compliance tracking, cost management, and resource orchestration functions into a single cloud control intelligence framework. By combining these previously separate functions into one unified system, the framework reduces operational overhead and simplifies management while maintaining comprehensive security monitoring across all cloud accounts

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If enterprises use provider-specific security tools for each cloud account, then reliability of individual cloud security is improved, but adaptability across multiple providers deteriorates

Engineering Contradiction:
Improvecloud securityVSAvoidmulti-cloud compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The cloud intelligence data model is designed with universal, provider-agnostic data structures that can represent resources, identities, and security configurations from multiple cloud providers through a unified schema. This universality enables the framework to work across different cloud providers without requiring provider-specific tools, while maintaining the ability to enforce consistent security policies across heterogeneous environments

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240187474A1Cloud intelligence data model and framework
Publication Date: 2024.06.06 SONRAI SECURITY INC
  • US20240187474A1 patent drawing
  • US20240187474A1 patent drawing
  • US20240187474A1 patent drawing

AI summary

A network-accessible service provides an enterprise with a view of identity and data activity in the enterprise's cloud accounts. The service enables distinct cloud provider management models to be normalized with centralized analytics and views across large numbers of cloud accounts. The service enables an enterprise to model all activity and relationships across cloud vendors, accounts and third party stores. Using a domain-specific query language, the system enables rapid interrogation of a complete and centralized data model of all data and identity relationships. User reports may be generated showing all privileges and data to which a particular identity has access. Using the display views, a user can pivot all functions across teams, applications and data, geography, provider and compliance mandates, and the like.