Compliance Configuration Management for Secure Asset Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer systems, efficient data transfer between network nodes is hindered by compliance level mismatches between source and target compute nodes, leading to security vulnerabilities and inefficiencies in data migration.

Innovation Solution

Dynamic compliance level adjustment of assets based on the compliance configuration of the target compute node, facilitated by a hypervisor, to ensure secure and efficient data transfer by aligning compliance levels and security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If compliance level adjustment is performed manually during asset migration, then security control is maintained, but data transfer efficiency decreases and resource usage increases

Engineering Contradiction:
Improvesecurity controlVSAvoiddata transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The compliance configuration management system automatically detects compliance mismatches during asset migration and performs dynamic compliance level adjustments without requiring manual security administrator intervention. The system self-manages the compliance adjustment process by comparing source and target compliance configurations, identifying mismatches, and executing appropriate adjustments to enable efficient data transfer while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs compliance configuration comparison and mismatch detection before the asset migration actually occurs. By identifying compliance level mismatches in advance and pre-adjusting compliance settings, the system prepares the migration environment to avoid security blocks during the actual data transfer, thereby improving overall transfer efficiency.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If compliance configuration is dynamically adjusted during migration, then data transfer efficiency improves, but system complexity increases

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The compliance configuration management system acts as an intermediary layer between the asset migration process and the underlying compliance configurations of compute nodes. It mediates by comparing compliance configurations, detecting mismatches, and coordinating automatic adjustments, thereby simplifying the overall system architecture while enabling efficient migration without requiring complex manual coordination between multiple security systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If compliance mismatches are not detected, then migration speed increases, but security vulnerabilities arise

Engineering Contradiction:
Improvemigration speedVSAvoidsecurity vulnerabilities
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism where compliance configurations are compared and mismatches are detected during the asset migration process. When a mismatch is detected, the system provides feedback by triggering automatic compliance level adjustments to resolve the mismatch before migration proceeds, thereby preventing security vulnerabilities while maintaining efficient migration speeds through automation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10375115B2Compliance configuration management
Publication Date: 2019.08.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10375115B2 patent drawing
  • US10375115B2 patent drawing
  • US10375115B2 patent drawing

AI summary

Disclosed aspects relate to compliance configuration management for asset migration on a shared pool of configurable computing resources having a set of compute nodes. A migration request to migrate an asset coupled with a first compliance configuration from a source compute node to a target compute node may be detected. The first compliance configuration coupled with the asset on the source compute node may be compared with an expected compliance configuration for the target compute node. Based on and in response to the comparing, a mismatch of the first compliance configuration with respect to the expected compliance configuration may be determined. A set of response actions may be performed with respect to the migration request.