Compliance Check System Driver Stack Encryption Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for ensuring encryption compliance across diverse operating systems, vendors, and devices are insecure and difficult to enforce, particularly when users access sensitive data, as they rely on self-reported surveys or specific software implementations, which can be inaccurate or unverifiable.
Innovation Solution
A Compliance Check System (CCS) that verifies encryption compliance by interacting with the device's driver stack, using upper and lower compliance drivers to check for encrypted data integrity, and provides a subscription-based service for continuous validation, ensuring that devices meet encryption requirements before accessing sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If self-reported surveys are used to enforce compliance, then ease of operation is improved, but reliability deteriorates
Solution Approach 1:
The system uses self-service by having the compliance verification agent installed on the user's own device, which automatically performs compliance checks without requiring manual intervention from security administrators. The agent independently verifies encryption status and reports findings, combining ease of operation with improved reliability through automated verification.
Solution Approach 2:
The patent replaces the manual mechanical process of filling out compliance surveys with an automated software agent that programmatically checks encryption compliance. This substitution eliminates human error and intentional misreporting while maintaining ease of operation through automated execution.
2Reliability
If specific software is required on all devices to enforce compliance, then reliability is improved, but adaptability deteriorates
Solution Approach 1:
The compliance verification agent is designed with universality to function across multiple operating systems and device types. It can detect and verify encryption compliance on Windows, macOS, Linux, and mobile devices, allowing a single solution to enforce reliability across diverse platforms without requiring device-specific implementations.
Solution Approach 2:
The patent introduces a universal compliance verification agent as an intermediary component that sits between the encryption software and the verification process. This agent uses standardized detection methods to verify encryption compliance across different vendors and platforms, maintaining reliability while adapting to various device environments.
3Ease of operation
If BYOD without device management is permitted, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The system implements feedback by having the compliance verification agent continuously monitor encryption status and report back to the security system. This feedback mechanism allows the organization to maintain security oversight of BYOD devices without restricting user access, as the agent provides real-time information about compliance status enabling informed security decisions.
Data Source
AI summary
A compliance checker to verify that a device complies with a policy is described. In one embodiment, the compliance checker comprises a compliance checker agent, to initiate the compliance check, in response to receiving the request, and an encryption checker upper driver above a level of a disk encryption driver, and an encryption checker lower driver, below the level of the disk encryption driver with a comparator to determine whether known data read from the upper driver is identical to known data read from the lower driver. The compliance checker plug-in in one embodiment verifies the compliance status of the device, based on the data from the comparator.


