Compliance Check System Driver Stack Encryption Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for ensuring encryption compliance across diverse operating systems, vendors, and devices are insecure and difficult to enforce, particularly when users access sensitive data, as they rely on self-reported surveys or specific software implementations, which can be inaccurate or unverifiable.

Innovation Solution

A Compliance Check System (CCS) that verifies encryption compliance by interacting with the device's driver stack, using upper and lower compliance drivers to check for encrypted data integrity, and provides a subscription-based service for continuous validation, ensuring that devices meet encryption requirements before accessing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If self-reported surveys are used to enforce compliance, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improvecompliance verification processVSAvoidcompliance verification accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system uses self-service by having the compliance verification agent installed on the user's own device, which automatically performs compliance checks without requiring manual intervention from security administrators. The agent independently verifies encryption status and reports findings, combining ease of operation with improved reliability through automated verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of filling out compliance surveys with an automated software agent that programmatically checks encryption compliance. This substitution eliminates human error and intentional misreporting while maintaining ease of operation through automated execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If specific software is required on all devices to enforce compliance, then reliability is improved, but adaptability deteriorates

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The compliance verification agent is designed with universality to function across multiple operating systems and device types. It can detect and verify encryption compliance on Windows, macOS, Linux, and mobile devices, allowing a single solution to enforce reliability across diverse platforms without requiring device-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a universal compliance verification agent as an intermediary component that sits between the encryption software and the verification process. This agent uses standardized detection methods to verify encryption compliance across different vendors and platforms, maintaining reliability while adapting to various device environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If BYOD without device management is permitted, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvedevice access policyVSAvoidnetwork security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback by having the compliance verification agent continuously monitor encryption status and report back to the security system. This feedback mechanism allows the organization to maintain security oversight of BYOD devices without restricting user access, as the agent provides real-time information about compliance status enabling informed security decisions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10860723B1Encryption compliance verification system
Publication Date: 2020.12.08 ALERTSEC INC
  • US10860723B1 patent drawing
  • US10860723B1 patent drawing
  • US10860723B1 patent drawing

AI summary

A compliance checker to verify that a device complies with a policy is described. In one embodiment, the compliance checker comprises a compliance checker agent, to initiate the compliance check, in response to receiving the request, and an encryption checker upper driver above a level of a disk encryption driver, and an encryption checker lower driver, below the level of the disk encryption driver with a comparator to determine whether known data read from the upper driver is identical to known data read from the lower driver. The compliance checker plug-in in one embodiment verifies the compliance status of the device, based on the data from the comparator.