Provenance Tracking for Cloud Policy Deviation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid cloud environments, the complexity of multiple parties involved in data governance and management leads to a risk of unintended actions that can negatively impact cloud services, with existing Identity and Access Management (IAM) tools inadequately addressing data security and integrity issues due to lack of end-to-end transaction tracking and consideration of dependent nodes.

Innovation Solution

A method and system that create an immutable ledger of transaction provenance to track end-to-end transactions, plotting persona data as a bipartite graph with edge weights representing trust levels, correlating these to detect policy deviations in real-time and send alerts, and potentially perform corrective actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IAM tools are used for access management, then ease of operation is maintained, but reliability of data security and integrity deteriorates due to lack of end-to-end transaction tracking

Engineering Contradiction:
Improvedata security and integrityVSAvoidtransaction tracking system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that sits between traditional IAM tools and the cloud infrastructure. This intermediary captures transaction data from multiple sources, maintains an immutable ledger of provenance information, and enables end-to-end tracking without replacing existing IAM infrastructure. The intermediary acts as a mediator that adds security monitoring capabilities while maintaining compatibility with current systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a nested architecture where the provenance tracking system is embedded within the existing cloud infrastructure. The immutable ledger and graph analysis components are nested within the data flow between personas, systems, and data sources, allowing the system to track transactions at multiple levels of abstraction simultaneously without adding external complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If end-to-end transaction tracking is implemented across multiple cloud parties, then reliability of data governance is improved, but device complexity increases due to multiple involved parties and systems

Engineering Contradiction:
Improvedata governanceVSAvoidmulti-party system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal provenance tracking system that can handle multiple types of transactions across different cloud service providers, infrastructure vendors, and administrative roles through a single unified approach. The immutable ledger and graph analysis framework are designed to be role-agnostic and protocol-agnostic, allowing the same system to track transactions from platform service providers, facilities providers, infrastructure vendors, and network providers simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the complex multi-party governance problem into manageable components by representing each party, system, and transaction type as discrete nodes in a graph structure. This segmentation allows the system to process and analyze transactions from multiple parties independently while maintaining the ability to correlate them through the immutable ledger, reducing the complexity of managing end-to-end tracking across diverse entities.

Inventive Principle:
Principle #1Segmentation

3Reliability

If real-time detection of policy deviations is implemented, then reliability of security monitoring is improved, but speed of processing increases the computational load and time requirements

Engineering Contradiction:
Improvesecurity monitoringVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by continuously maintaining an updated graph representation of the cloud environment and pre-establishing trust relationships between personas and systems. This allows the system to quickly evaluate new transactions against the pre-computed graph structure and trust models, enabling real-time detection without requiring intensive computational analysis at the moment of transaction evaluation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors transactions, compares them against the immutable ledger and graph-based trust models, and provides real-time alerts when policy deviations are detected. The feedback loop includes automated responses that can trigger corrective actions, creating a closed-loop system that improves security monitoring efficiency by learning from detected deviations and adjusting monitoring priorities accordingly.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11553005B1Provenance based identification of policy deviations in cloud computing environments
Publication Date: 2023.01.10 KYNDRYL INC
  • US11553005B1 patent drawing
  • US11553005B1 patent drawing
  • US11553005B1 patent drawing

AI summary

Policy deviations for distributed computing environments are detected and recorded an immutable ledger of transaction provenance from end to end transactions performed in the distributed computing environment. From the immutable ledger, persona data for transaction types is plotted as an bipartite graph. Edge weights of the bipartite graphs are correlated to trust levels between personas from the persona data and the transaction types from the immutable ledger. Trust levels from the edge weights are correlated to rules illustrating when the transaction provenance indicate a policy deviation in the distributed computing environment. The rules are then employed to detect in real time end to end provenance when a policy deviation in the distributed computing environment is occurring. An alert of policy deviations may be sent to stakeholders for the distributed computing environment.