Multi-Cloud Risk Ranking via Unified Trust Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing multi-cloud workloads across different cloud service providers is challenging due to the complexity of obtaining a holistic view of security and compliance, requiring multiple tools and services that lack interoperability, leading to timely visibility issues and increased security risks.

Innovation Solution

A trust platform that receives self-reported risk information and combines it with data from various monitoring tools to provide a unified view of security and compliance across multiple clouds, using relative risk ranking to manage cloud assets effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple monitoring tools and services are used to manage multi-cloud workloads, then security coverage is improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple monitoring tools and services into a single unified multi-cloud management platform that provides centralized control and visibility across all cloud assets. This consolidation maintains comprehensive security coverage while reducing the complexity of managing multiple separate tools by integrating their functions into one system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The management platform is designed with multi-functional capabilities that can monitor, manage, and secure diverse cloud assets across multiple cloud service providers through a single interface. This universal approach allows the system to perform multiple security functions simultaneously, improving coverage without requiring separate specialized tools for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If multiple monitoring tools from different vendors are deployed, then visibility across cloud assets is improved, but interoperability and integration difficulty increase

Engineering Contradiction:
ImprovevisibilityVSAvoidintegration difficulty
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent introduces a centralized management platform as an intermediary layer between various monitoring tools and cloud assets. This platform provides standardized interfaces and protocols that enable seamless integration and data exchange between different tools and cloud service providers, improving visibility while simplifying interoperability through unified communication standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive risk assessment across all cloud assets is performed, then security risk detection is improved, but time and computational resources required increase

Engineering Contradiction:
Improverisk detection accuracyVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic risk assessment that adjusts evaluation parameters and monitoring intensity based on the criticality and risk profile of each cloud asset. High-value assets receive more intensive assessment while lower-risk assets use streamlined evaluation, maintaining accurate risk detection across all assets while optimizing the time and computational resources required for comprehensive assessment.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220294818A1Management of multi-cloud workloads using relative risk ranking of cloud assets
Publication Date: 2022.09.15 EMC IP HLDG CO LLC
  • US20220294818A1 patent drawing
  • US20220294818A1 patent drawing
  • US20220294818A1 patent drawing

AI summary

An apparatus comprises a processing device configured to receive, at a trust platform configured to manage cloud assets operating in clouds of two or more cloud service providers, self-reported risk information for at least a subset of the cloud assets on which workloads of a given entity run. The processing device is also configured to obtain, utilizing application programming interfaces of the trust platform, first and second sets of cloud asset risk data generated by first and second pluralities of monitoring tools operating in tenant and management environments of the clouds. The processing device is further configured to determine multi-cloud relative risk information for the subset of cloud assets by adjusting the self-reported risk information utilizing the first and second sets of cloud asset risk data, and to perform risk management for the subset of cloud assets based at least in part on the determined multi-cloud relative risk information.