Compliance Checking for Shared Computer Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods for shared computer resources rely on authentication and authorization, which are insufficient as they do not account for compromised operating environments, leading to potential security threats and malware spread.

Innovation Solution

Implementing a method that checks the security compliance of requesting computing facilities with a compliance center, regulating further communications based on adherence to a defined security policy, using a security storage facility and resident security software to prevent unauthorized access from non-compliant endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication and authorization mechanisms are used to control access to shared resources, then access control is established, but security threats from compromised operating environments cannot be prevented

Engineering Contradiction:
Improvesecurity protectionVSAvoidmalware spread
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security compliance checking before allowing access to shared resources. The compliance center verifies that requesting computing facilities meet defined security policies (antivirus software, firewall, patch levels) before granting access rights, preventing compromised systems from accessing shared resources even if they pass authentication and authorization

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security compliance checking is implemented for all computing facilities, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A compliance center is introduced as an intermediary component between computing facilities and shared resources. This dedicated mediator handles all security compliance checking, policy enforcement, and communication protocols, separating the complexity of security verification from the core access control mechanism and allowing shared resources to maintain simpler access control logic

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If compliance information is requested and verified for each communication, then malware transmission is prevented, but communication efficiency decreases

Engineering Contradiction:
Improveinfection spreadVSAvoidcommunication speed
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Security compliance information is verified in advance before data communication begins. The compliance center establishes trust relationships and validates security policies beforehand, so that once compliance is confirmed, subsequent data communications can proceed efficiently without repeated verification delays

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where computing facilities provide compliance status information to the compliance center, and the compliance center returns verification results. This feedback loop allows for efficient communication by establishing trust once and using it for multiple subsequent interactions, rather than verifying security on every single data packet

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8392972B2Protected access control method for shared computer resources
Publication Date: 2013.03.05 SOPHOS LTD
  • US8392972B2 patent drawing
  • US8392972B2 patent drawing
  • US8392972B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for providing protected computer communications. The present invention may provide for computer communications where in response to a receipt of a communication at a first computing facility from a second computing facility, the first computing facility may be caused to send a request to a compliance center for security compliance information relating to the second computing facility. In response to the request for security compliance information, the first computing facility may receive compliance information related to the second computing facility, which may cause the first computing facility to perform an action regulating further communications from the second computing facility if the second computing facility security compliance information indicates that the second client computing facility is not compliant with a current security policy.