Compliance Verification System for Cross-Platform Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for ensuring user system compliance with security policies, particularly in regards to data-at-rest encryption, are insecure and unable to verify compliance across diverse operating systems, vendors, and devices.
Innovation Solution
The Compliance Check System (CCS) implements a mechanism to verify user system compliance by checking for adequate encryption, operating system updates, and other security measures, using a subscription service that interacts with the user's device to perform compliance checks independently of the encryption vendor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full disk encryption and full volume encryption are used to secure data at rest, then data security is improved, but verification of compliance becomes difficult across diverse operating systems, vendors, and devices
Solution Approach 1:
The patent creates a universal compliance verification system that can verify encryption compliance across multiple operating systems (Windows, macOS, Linux), multiple vendors (BitLocker, FileVault, LUKS), and various device types. The system uses a standardized verification process that works independently of the specific encryption implementation, allowing one system to verify compliance across diverse platforms.
Solution Approach 2:
The patent introduces an intermediary compliance verification system that acts as a mediator between the encrypted data storage system and the users accessing it. This intermediary layer verifies compliance without needing to understand or interfere with the underlying encryption mechanisms, allowing verification while maintaining security and compatibility across different encryption implementations.
2Ease of operation
If users are required to complete compliance surveys to verify policy adherence, then compliance information collection is simplified, but security is compromised due to potential incorrect or fraudulent responses
Solution Approach 1:
The patent implements a self-service compliance verification system where the compliance verification agent automatically collects and verifies compliance information from the user's system without requiring manual user input. The system self- verifies encryption status, operating system version, and other compliance criteria, eliminating the need for users to manually complete surveys while ensuring accurate and reliable compliance data.
3Reliability
If specific software or modules are supplied to all devices to enforce compliance, then compliance verification is improved within the organization, but the system cannot verify compliance when different vendors, devices, and solutions are used
Solution Approach 1:
The patent creates a universal compliance verification system that can verify encryption compliance across multiple operating systems (Windows, macOS, Linux), multiple vendors (BitLocker, FileVault, LUKS), and various device types. The system uses a standardized verification process that works independently of the specific encryption implementation, allowing one system to verify compliance across diverse platforms.
4Ease of operation
If users are permitted to bring own devices without device management, then ease of access is improved, but compliance requirements cannot be enforced and network security decreases
Solution Approach 1:
The patent introduces an intermediary compliance verification system that acts as a mediator between the encrypted data storage system and the users accessing it. This intermediary layer verifies compliance without needing to understand or interfere with the underlying encryption mechanisms, allowing verification while maintaining security and compatibility across different encryption implementations.
Data Source
AI summary
A compliance checker system to enable use of a device with a plurality of partners by ensuring that the device complies with a partner policy for each of the plurality of partners, wherein the compliance checker is device neutral. A compliance checker application to determine whether the device complies with the partner policy of a particular partner, prior to permitting access to resources provided by the particular partner, the compliance checker including one or more specific checkers, the specific checker comprising one or more of: a device encryption compliance checker configured to determine whether a disk drive of the device is encrypted, an operating system checker configured to determine whether an operating system of the device is up-to-date, and a virus checker configured to determine whether the device has an active anti-virus application.


