Dynamic Compliance Validation for Multi-Tenant Cloud Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Validating configuration and security compliance in multi-tenant cloud managed services is challenging due to varied security and configuration settings, customized policies, and differing procedures for gathering and consolidating evidence, which can lead to increased difficulty without domain expertise.

Innovation Solution

An automated method and system that dynamically composes a checklist for validating configuration and compliance based on customer requests, utilizing script functions and plug-ins to execute configuration and security checks, and storing results for quality assurance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual validation processes are used for configuration and security compliance, then flexibility in handling customized policies is improved, but labor intensity and time consumption increase

Engineering Contradiction:
Improveflexibility in handling customized policiesVSAvoidtime consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The validation system dynamically generates checklists based on service type, tenant policies, and configuration parameters. The checklist generation adapts to different service scenarios automatically, transforming static manual validation into a dynamic automated process that maintains policy flexibility while reducing time consumption

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables self-service validation by automatically generating and executing validation checklists without requiring manual intervention. The automated validation engine processes configurations and security compliance independently, freeing operators from manual validation tasks while maintaining adaptability to customized policies

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive validation checklists are generated for all services, then validation thoroughness is improved, but system complexity increases

Engineering Contradiction:
Improvevalidation thoroughnessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation system segments the validation process into distinct components: service type identification, parameter extraction, checklist generation, and validation execution. Each component handles a specific aspect of the validation process, making the overall complex system manageable through modular organization while maintaining comprehensive validation coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs a universal validation framework that can handle multiple service types (DNS, email, file sharing, etc.) through a single automated engine. The checklist generation mechanism serves multiple functions by adapting to different service configurations and policy requirements, reducing system complexity through consolidation while maintaining thoroughness

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated validation is implemented across multiple service types, then productivity is improved, but adaptability to different security settings decreases

Engineering Contradiction:
Improvevalidation efficiencyVSAvoidadaptability to different security settings
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The validation system applies local quality by customizing validation parameters and checklist items according to specific service types and tenant policies. Each service receives tailored validation rules appropriate to its security requirements, maintaining high adaptability while operating within the automated framework that ensures productivity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11265229B2Compliance validation for services based on user selection
Publication Date: 2022.03.01 KYNDRYL INC
  • US11265229B2 patent drawing
  • US11265229B2 patent drawing
  • US11265229B2 patent drawing

AI summary

Aspects of the present invention disclose a method, computer program product, and system for validation of services. The method includes one or more processors receiving a request of a service. The method further includes one or more processors parsing the received request of the service to identify information included in the received request of the service. The method further includes one or more processors generating a checklist that corresponds to the received request of the service based on the identified information, wherein the generated checklist includes configuration and security checks that are associated with the received request of the service. The method further includes one or more processors determining a validation result utilizing the generated checklist, wherein the validation result indicates whether the requested service is deployed on a corresponding endpoint according to the configuration and security checks in the generated checklist.