Compliance Checking for Shared Computer Resources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods for shared computer resources rely on authentication and authorization, which are insufficient as they do not account for compromised operating environments, leading to potential security threats and malware spread.
Innovation Solution
Implementing a method that checks the security compliance of requesting computing facilities with a compliance center, regulating further communications based on adherence to a defined security policy, using a security storage facility and resident security software to prevent unauthorized access from non-compliant endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication and authorization mechanisms are used to control access to shared resources, then access control is established, but security threats from compromised operating environments cannot be prevented
Solution Approach 1:
The system performs preliminary security compliance checking before allowing access to shared resources. The compliance center verifies that requesting computing facilities meet defined security policies (antivirus software, firewall, patch levels) before granting access rights, preventing compromised systems from accessing shared resources even if they pass authentication and authorization
2Reliability
If security compliance checking is implemented for all computing facilities, then security protection is improved, but system complexity increases
Solution Approach 1:
A compliance center is introduced as an intermediary component between computing facilities and shared resources. This dedicated mediator handles all security compliance checking, policy enforcement, and communication protocols, separating the complexity of security verification from the core access control mechanism and allowing shared resources to maintain simpler access control logic
3Object-affected harmful factors
If compliance information is requested and verified for each communication, then malware transmission is prevented, but communication efficiency decreases
Solution Approach 1:
Security compliance information is verified in advance before data communication begins. The compliance center establishes trust relationships and validates security policies beforehand, so that once compliance is confirmed, subsequent data communications can proceed efficiently without repeated verification delays
Solution Approach 2:
The system implements feedback mechanisms where computing facilities provide compliance status information to the compliance center, and the compliance center returns verification results. This feedback loop allows for efficient communication by establishing trust once and using it for multiple subsequent interactions, rather than verifying security on every single data packet
Data Source
AI summary
In embodiments of the present invention improved capabilities are described for providing protected computer communications. The present invention may provide for computer communications where in response to a receipt of a communication at a first computing facility from a second computing facility, the first computing facility may be caused to send a request to a compliance center for security compliance information relating to the second computing facility. In response to the request for security compliance information, the first computing facility may receive compliance information related to the second computing facility, which may cause the first computing facility to perform an action regulating further communications from the second computing facility if the second computing facility security compliance information indicates that the second client computing facility is not compliant with a current security policy.


