Compliance Verification System for Cross-Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for ensuring user system compliance with security policies, particularly in regards to data-at-rest encryption, are insecure and unable to verify compliance across diverse operating systems, vendors, and devices.

Innovation Solution

The Compliance Check System (CCS) implements a mechanism to verify user system compliance by checking for adequate encryption, operating system updates, and other security measures, using a subscription service that interacts with the user's device to perform compliance checks independently of the encryption vendor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full disk encryption and full volume encryption are used to secure data at rest, then data security is improved, but verification of compliance becomes difficult across diverse operating systems, vendors, and devices

Engineering Contradiction:
Improvedata securityVSAvoidcompliance verification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal compliance verification system that can verify encryption compliance across multiple operating systems (Windows, macOS, Linux), multiple vendors (BitLocker, FileVault, LUKS), and various device types. The system uses a standardized verification process that works independently of the specific encryption implementation, allowing one system to verify compliance across diverse platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary compliance verification system that acts as a mediator between the encrypted data storage system and the users accessing it. This intermediary layer verifies compliance without needing to understand or interfere with the underlying encryption mechanisms, allowing verification while maintaining security and compatibility across different encryption implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users are required to complete compliance surveys to verify policy adherence, then compliance information collection is simplified, but security is compromised due to potential incorrect or fraudulent responses

Engineering Contradiction:
Improvecompliance verification processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a self-service compliance verification system where the compliance verification agent automatically collects and verifies compliance information from the user's system without requiring manual user input. The system self- verifies encryption status, operating system version, and other compliance criteria, eliminating the need for users to manually complete surveys while ensuring accurate and reliable compliance data.

Inventive Principle:
Principle #25Self-service

3Reliability

If specific software or modules are supplied to all devices to enforce compliance, then compliance verification is improved within the organization, but the system cannot verify compliance when different vendors, devices, and solutions are used

Engineering Contradiction:
Improvecompliance verificationVSAvoidvendor and device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal compliance verification system that can verify encryption compliance across multiple operating systems (Windows, macOS, Linux), multiple vendors (BitLocker, FileVault, LUKS), and various device types. The system uses a standardized verification process that works independently of the specific encryption implementation, allowing one system to verify compliance across diverse platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If users are permitted to bring own devices without device management, then ease of access is improved, but compliance requirements cannot be enforced and network security decreases

Engineering Contradiction:
Improvedevice accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary compliance verification system that acts as a mediator between the encrypted data storage system and the users accessing it. This intermediary layer verifies compliance without needing to understand or interfere with the underlying encryption mechanisms, allowing verification while maintaining security and compatibility across different encryption implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250126153A1Compliance Verification System
Publication Date: 2025.04.17 ALERTSEC INC
  • US20250126153A1 patent drawing
  • US20250126153A1 patent drawing
  • US20250126153A1 patent drawing

AI summary

A compliance checker system to enable use of a device with a plurality of partners by ensuring that the device complies with a partner policy for each of the plurality of partners, wherein the compliance checker is device neutral. A compliance checker application to determine whether the device complies with the partner policy of a particular partner, prior to permitting access to resources provided by the particular partner, the compliance checker including one or more specific checkers, the specific checker comprising one or more of: a device encryption compliance checker configured to determine whether a disk drive of the device is encrypted, an operating system checker configured to determine whether an operating system of the device is up-to-date, and a virus checker configured to determine whether the device has an active anti-virus application.