Automated IT Stack Security Control Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT environments face challenges in configuring optimal security controls across complex IT stacks due to conflicting compliance requirements, inadequate standard recommendations, and the need for deep expertise, leading to sub-optimal security and performance.

Innovation Solution

An automated security control configuration system that maps abstract input security information to specific configuration instructions using a knowledge base correlating security levels, industry verticals, compliance specifications, and technology components, enabling technology and product-agnostic configuration of security controls across different layers of the IT stack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration of security controls is performed by IT administrators, then customization to business requirements is possible, but complexity and expertise requirements increase significantly

Engineering Contradiction:
Improvecustomization to business requirementsVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an automated security control configuration system as an intermediary between IT administrators and the complex security configuration tasks. This system includes a knowledge base that maps security levels, industry verticals, compliance specifications, and technology components to specific configuration instructions, thereby mediating the complexity and reducing the expertise required while maintaining customization capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of security configuration with an automated system. Instead of requiring IT administrators to manually navigate complex configuration settings, the system automatically generates configuration instructions based on input parameters such as security levels, industry verticals, and compliance specifications, substituting human expertise with an automated knowledge-based system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive security controls are implemented across all IT stack layers, then security improvement is achieved, but performance degradation may occur

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by tailoring security controls to specific layers and components of the IT stack based on their individual security requirements and performance characteristics. Rather than applying uniform security measures across all layers, the system customizes security controls for each layer (hardware, firmware, software) and component based on the mapped configuration instructions, achieving optimal security-performance balance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent utilizes parameter changes by adjusting security control parameters dynamically based on input parameters such as security levels, industry verticals, and compliance specifications. The system modifies configuration parameters (e.g., encryption strength, authentication mechanisms, access control policies) to optimize the balance between security and performance for each specific IT environment.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If automated configuration system is implemented, then configuration time is reduced, but system complexity increases

Engineering Contradiction:
Improveconfiguration timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent segments the security configuration system into distinct functional components: a knowledge base module for storing mapped configuration instructions, an automated configuration module for generating settings, and an interface for input parameters. This segmentation allows the system to manage complexity through modular design while providing automated configuration capabilities that reduce time consumption.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11601473B2Information technology stack security control configuration
Publication Date: 2023.03.07 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11601473B2 patent drawing
  • US11601473B2 patent drawing
  • US11601473B2 patent drawing

AI summary

In some examples, a system receives input information relating to a security level for an information technology (IT) stack comprising a plurality of layers including a hardware layer and a software layer, where the input information is technology and product agnostic. The system discovers components of the plurality of layers of the IT stack, accesses a knowledge base that maps the security level and the discovered components to configuration instructions relating to security controls, and configures the IT stack with the security controls using the configuration instructions.