Compliance Aggregation for Hybrid Cloud Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in aggregating compliance postures across hybrid cloud deployments, which involve multiple cloud form factors and technology platforms, leading to fragmented compliance validation and assessment.

Innovation Solution

A computer-implemented method and system that receives security definitions and customer profiles, uses automated assessment tools to evaluate compliance, generates a compliance posture, and provides it to a reviewer for remediation recommendations, thereby aggregating compliance validation across disparate systems and domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated assessment tools are used to evaluate compliance across hybrid cloud deployments, then compliance validation efficiency is improved, but the complexity of aggregating compliance postures across multiple cloud form factors and technology platforms increases

Engineering Contradiction:
Improvecompliance validation efficiencyVSAvoidcompliance aggregation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments compliance assessment by creating separate assessment modules for different cloud form factors (IaaS, PaaS, SaaS) and technology platforms. Each module independently evaluates compliance for its specific domain, then results are aggregated into a unified compliance posture. This segmentation allows automated tools to efficiently assess each segment while managing the overall complexity of hybrid cloud environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary compliance aggregation layer that sits between the diverse cloud platforms and the compliance evaluation system. This intermediary standardizes compliance data from multiple sources, translating various cloud provider formats into a unified assessment model. This mediator enables efficient automated assessment while handling the complexity of aggregating across different platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security definitions are enforced across all cloud deployments, then security compliance is improved, but the difficulty of assessing compliance across disparate systems increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidcompliance assessment difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a universal compliance assessment framework that can evaluate multiple cloud platforms (AWS, Azure, Google Cloud, private clouds) using a single set of security definitions. The system maps platform-specific security controls to universal security requirements, enabling comprehensive security compliance enforcement across disparate systems while simplifying the assessment process through standardized evaluation criteria.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms complex security definitions into parameterized assessment rules that can be systematically applied across different cloud platforms. By converting security requirements into structured parameters with defined evaluation criteria, the system makes compliance detection and measurement more manageable while maintaining comprehensive security enforcement across heterogeneous environments.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12309165B2Compliance aggregation
Publication Date: 2025.05.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12309165B2 patent drawing
  • US12309165B2 patent drawing
  • US12309165B2 patent drawing

AI summary

A method includes receiving, by a computing device, security definitions from an owner of a cloud deployment; receiving, by the computing device, a customer profile having intents to use the cloud deployment; assessing, by the computing device and using automated assessment tools, compliance of the cloud deployment with the security definitions in view of the intents; generating, by the computing device, a compliance posture using the assessment; and providing, by the computing device, the compliance posture to a reviewer.