Cloud Security Policy Data Filtering via Interactive Workload Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in determining relevant security requirements for cloud environments due to the vast and complex nature of security policy data, requiring tedious manual intervention from security experts, which is inefficient and time-consuming.

Innovation Solution

An interactive program that takes user input about technical workloads and maps it to a tailored list of individual security requirements from a first-party enterprise's security policy data store, allowing users with limited knowledge to obtain relevant security requirements efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If users manually review security policy data to determine relevant security requirements, then accuracy of security requirement identification is improved, but time consumption and operational complexity increase significantly

Engineering Contradiction:
Improveaccuracy of security requirement identificationVSAvoidtime consumption for security requirement review
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an interactive program as an intermediary between users and security policy data. This program acts as a mediator that automatically filters, maps, and presents only the relevant security requirements based on user input about technical workloads, eliminating the need for manual review of entire policy documents while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual review process with an automated computational system. The interactive program uses algorithms to process security policy data, map it to technical workload categories, and generate relevant requirement lists automatically, substituting human manual inspection with automated information processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If security experts manually intervene to determine security requirements, then reliability of security compliance is improved, but device complexity and operational burden increase

Engineering Contradiction:
Improvereliability of security complianceVSAvoidoperational complexity for users
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables users to perform security requirement determination independently through self-service interaction. The interactive program guides users through a simplified questionnaire about their technical workloads and automatically generates relevant security requirements, eliminating the need for security expert intervention while maintaining compliance reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the complex security policy data into manageable categories and presents them through a structured interactive interface. By dividing the overwhelming security policy into discrete, relevant sections based on user input, the system reduces operational complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If users access comprehensive security policy data stores, then completeness of security requirements is improved, but ease of operation deteriorates due to voluminous data

Engineering Contradiction:
Improvecompleteness of security requirementsVSAvoidease of navigating security policy data
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent extracts only the relevant security requirements from the comprehensive policy data store based on user input about technical workloads. The interactive program filters and extracts pertinent information, presenting a customized subset of security requirements that is both complete for the user's needs and easy to navigate, rather than overwhelming users with the entire policy database.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11349883B2Determining relevant security policy data based on cloud environment
Publication Date: 2022.05.31 AT&T INTELLECTUAL PROPERTY I L P
  • US11349883B2 patent drawing
  • US11349883B2 patent drawing
  • US11349883B2 patent drawing

AI summary

A system and method for returning security policy requirements data based on user input that identifies a cloud environments, a service model, first or third party responsibilities, and/or code deployment information. A user provides answers to straightforward, generally non-expert questions directed to the user's cloud environment, first or third party responsibilities, and/or code deployment information for the user's scenario, e.g., technical workload. The answers result in determining which architecture layers apply (are in-scope architecture layers) relevant to the user's scenario. The in-scope architecture layers map to security requirements maintained in a security policy data store. The security requirements are returned (e.g., as a list) in response to the user's answers.