PCI DSS Compliance Detection in Virtualized Payment Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing compliance detection methods are inadequate for virtualized environments, as they do not account for the complexities of virtual machine connections and dynamic network boundaries, which can lead to non-compliance with PCI DSS isolation demands in payment applications.
Innovation Solution
A compliance detecting method that collects and processes network flows across physical and virtual machines to determine virtual machine domains and connection collections, comparing them to predetermined compliance states to identify compliance or non-compliance, and adjusts for discrepancies by removing non-compliant virtual machines, ensuring accurate PCI DSS compliance detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing compliance detection methods are used in virtualized environments, then the detection process is simple, but the detection accuracy and reliability are insufficient due to inability to account for virtual machine connections and dynamic network boundaries
Solution Approach 1:
The patent segments the compliance detection process into multiple distinct modules: network flow collection from physical and virtual machines, flow pre-processing to determine data streams, virtual machine domain determination, connection collection analysis, and compliance state comparison. This segmentation allows each module to handle specific aspects of virtualized environment complexity independently, improving detection accuracy while managing system complexity through modular design.
Solution Approach 2:
The patent introduces network flow data as an intermediary element that mediates between the complex virtualized environment and the compliance detection logic. By collecting and analyzing network flows as an intermediate representation, the system can accurately track communications between virtual machines and determine compliance states without directly managing the complexity of virtual machine connections and dynamic network boundaries.
2Productivity
If virtualization technology is applied to improve resource utilization, then multiple virtual machines can run on one physical machine, but new security risks arise due to complex virtual network connections that may violate PCI DSS isolation demands
Solution Approach 1:
The patent implements feedback by continuously collecting network flow data from virtual machines and physical machines, analyzing the data to determine current compliance states, and comparing these states against predetermined compliance requirements. This continuous feedback loop enables the system to reliably detect PCI DSS compliance violations in virtualized environments while maintaining high resource utilization through virtualization.
Solution Approach 2:
The patent applies preliminary action by establishing predetermined virtual machine domains and connection collections that represent compliant states before actual compliance detection occurs. These pre-defined compliance benchmarks allow the system to quickly compare actual network behavior against expected compliant patterns, enabling reliable PCI DSS compliance verification in virtualized environments without compromising resource utilization efficiency.
Data Source
AI summary
The invention provides a compliance detecting method of payment applications in a virtualized environment, and pertains to the field of security technology of payment applications. The detecting method is used for compliance detection for PCI DSS isolation demands. The detecting method can determine whether it is a compliance state by analyzing the current virtual machine domain and its connection from data stream, and can also determine whether it is a compliance state by analyzing the purity of network flow of virtual machines. The detecting method is suitable for a virtualized environment and makes the detection of compliance accurate in the virtualized environment, thus being advantageous for guaranteeing the security of payment applications.


