Cloud Security Policy Management System for Multi-Cloud Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud security approaches fail to provide contextual visibility and scalability, unable to automatically discover and prioritize security risks, and are complex and error-prone, especially in hybrid or multi-cloud environments with disparate security controls.

Innovation Solution

A method and system for managing security policies in a decentralized manner, creating cloud-independent policies that are shared and enforced across distributed enterprises, using graph representations to generate actionable and contextual insights for proactive security management and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cloud security approaches are used to secure cloud computing environments, then security coverage is provided, but contextual visibility of the cloud environment cannot be obtained

Engineering Contradiction:
Improvesecurity coverageVSAvoidcontextual visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a policy management system as an intermediary layer between security policies and cloud assets. This system includes policy definition, translation, enforcement, and exception management components that collectively provide contextual visibility by translating high-level security policies into cloud-specific enforcement rules while maintaining a unified view of cloud assets and their security states

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal policy management system that can manage security policies across multiple cloud platforms (AWS, Azure, GCP, etc.) through a single interface. The system performs multiple functions including policy definition, translation to cloud-specific formats, enforcement, monitoring, and exception handling, thereby providing comprehensive contextual visibility without requiring separate tools for each cloud platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If existing cloud security approaches are used, then security enforcement is provided, but security risks cannot be automatically discovered or prioritized

Engineering Contradiction:
Improvesecurity enforcementVSAvoidautomatic risk discovery and prioritization
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements feedback mechanisms where the policy management system continuously monitors cloud asset states, compares them against defined security policies, and automatically generates findings about policy violations. The system prioritizes these findings based on predefined criteria and provides feedback loops that enable automatic remediation workflows, thereby achieving automatic risk discovery and prioritization while maintaining security enforcement

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables automatic self-service capabilities where security policies are automatically translated, enforced, and monitored across cloud assets without manual intervention. The policy management system autonomously discovers security risks by comparing actual asset states against policy requirements and automatically prioritizes findings based on configured criteria, reducing the need for manual security analysis

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If security policies are enforced to adapt to organization needs such as increasing usage of cloud services, then security coverage is expanded, but the existing approaches become complex, error-prone, and slow to keep up with agile organization needs

Engineering Contradiction:
Improvesecurity coverage expansionVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management process into distinct modular components: policy definition (creating high-level security requirements), policy translation (converting to cloud-specific formats), policy enforcement (applying rules to assets), and exception management (handling deviations). This segmentation allows organizations to expand security coverage by adding new policies without increasing overall system complexity, as each component handles a specific aspect of policy management independently

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If assets and identities are disparate in various cloud computing environments, then multi-cloud flexibility is achieved, but the existing approaches cannot scale elastically

Engineering Contradiction:
Improvemulti-cloud flexibilityVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements a universal policy management system that can manage security policies across multiple cloud platforms (AWS, Azure, GCP, and private clouds) through a single interface. The system translates high-level security policies into cloud-specific enforcement rules automatically, enabling elastic scaling across disparate cloud environments without requiring separate management approaches for each platform, thereby achieving both multi-cloud flexibility and scalability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11991216B1Policy-based cloud asset and security management system
Publication Date: 2024.05.21 ARIKSA INC
  • US11991216B1 patent drawing
  • US11991216B1 patent drawing
  • US11991216B1 patent drawing

AI summary

A method and system for implementing and managing security policies in a cloud environment of enterprises are disclosed. In some embodiments, the method includes creating cloud-independent policies associated with enterprise assets in the cloud environment and sharing the cloud-independent policies across one or more distributed enterprises in the cloud environment. The method also includes translating and enforcing the policies in run-time across the distributed enterprises. The method further includes applying the policies collaboratively in the distributed enterprises based on distributing policy enforcement in the distributed enterprises while centralizing policy operations, where applying the policies includes discovering cloud-based assets of the enterprises and enterprise asset data related to the cloud-based assets and creating, based on the enterprise asset data, at least one graph (organization, user, resource) representing the relationships among the assets. The enterprise asset data includes information used to detect, protect, and investigate potential problems of the assets.