Distributed Ledger Governance for Cloud Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of enterprise IT structures and the lack of oversight in cloud environments make it difficult for enterprise IT departments to enforce compliance and security across multiple business units and external vendors, leading to challenges in monitoring and managing IT systems effectively.

Innovation Solution

A distributed ledger service is implemented within a service provider environment to provide an immutable audit log and govern access rights to computing resources, enabling real-time monitoring and enforcement of policies across multiple accounts, ensuring data integrity and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises allow business units and vendors to independently manage their own cloud accounts and infrastructure, then innovation and operational flexibility improve, but IT compliance enforcement and security monitoring deteriorate

Engineering Contradiction:
Improveoperational flexibilityVSAvoidcompliance enforcement
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a distributed ledger service as an intermediary between enterprise IT departments and independent cloud accounts. This mediator automatically receives, validates, and records compliance data from multiple sources without requiring direct control over individual accounts, thus maintaining operational flexibility while ensuring compliance enforcement through automated policy validation and immutable record-keeping

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises require external parties to share audit logs and compliance data, then compliance monitoring improves, but data integrity and trust deteriorate due to potential tampering

Engineering Contradiction:
Improvecompliance monitoringVSAvoiddata integrity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a distributed ledger where multiple independent copies of compliance data are maintained across different nodes in the network. Each participant receives identical copies of audit logs and compliance records, eliminating the need to trust any single source. The immutable nature of the distributed ledger ensures that once data is recorded, it cannot be tampered with or altered, preserving data integrity while enabling comprehensive compliance monitoring

Inventive Principle:
Principle #26Copying

3Reliability

If enterprises implement centralized oversight of all cloud accounts, then compliance enforcement improves, but system complexity and operational overhead increase

Engineering Contradiction:
Improvecompliance enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables cloud accounts and services to automatically publish their own compliance data and audit logs to the distributed ledger without requiring manual intervention from enterprise IT departments. The system self-regulates by automatically validating policies, recording compliance status, and maintaining immutable records. This automated self-service approach ensures compliance enforcement while minimizing the operational overhead and complexity for enterprise IT teams

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11146560B1Distributed governance of computing resources
Publication Date: 2021.10.12 AMAZON TECH INC
  • US11146560B1 patent drawing
  • US11146560B1 patent drawing
  • US11146560B1 patent drawing

AI summary

Technology is described for a distributed ledger service within a service provider environment. The distributed ledger service may implement a distributed ledger formed from immutable append-only data structure and used for governance of computing resources. A policy governing a computing resource may be created and published to the distributed ledger on behalf of an account. The policy may be retrieved from the distributed ledger to govern access to the computing resource by the account.