Secure Tenant Assessment of IT Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based information processing systems, tenants face challenges in verifying the security compliance of shared computing environments without compromising security, as direct privileged access is impractical and risky.

Innovation Solution

A secure assessment environment is isolated from the shared computing environment by an 'air gap', allowing tenants to access compliance evidence through a tenant assessment interface, enabling secure verification of security policies without broad access privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If direct privileged access is granted to tenants for security assessment, then measurement precision of security compliance is improved, but security of the shared computing environment deteriorates

Engineering Contradiction:
Improvesecurity compliance verification accuracyVSAvoidsecurity risk to shared environment
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary assessment environment that sits between the tenant and the shared computing environment. This intermediary collects compliance evidence from the shared environment through controlled interfaces, allowing tenants to perform security assessments without direct access to production systems. The intermediary acts as a buffer that enables measurement while preventing security compromises.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the shared computing environment's compliance state in the assessment environment. Instead of accessing the live system directly, tenants interact with replicated compliance data and configurations. This copying approach allows full assessment capability while isolating the assessment process from the actual production environment.

Inventive Principle:
Principle #26Copying

2Ease of operation

If direct privileged access is granted to tenants for security assessment, then ease of operation for compliance verification is improved, but reliability of the shared computing environment deteriorates

Engineering Contradiction:
Improvecompliance verification accessibilityVSAvoidsecurity stability of shared environment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The intermediary assessment environment provides tenants with ease of operation by offering familiar assessment tools and interfaces, while simultaneously protecting the reliability of the shared environment by preventing direct tenant access. The intermediary handles all assessment operations without requiring tenants to have privileged access credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the assessment function from the production environment. The assessment environment is separated into a distinct system that handles compliance verification operations, while the shared computing environment maintains its production focus. This segmentation allows each system to be optimized for its specific purpose without compromising the other.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive access is provided for full compliance assessment, then measurement precision of security controls is improved, but device complexity of the access management system worsens

Engineering Contradiction:
Improvesecurity control assessment accuracyVSAvoidaccess management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the compliance evidence collection function from the complex access management system. The intermediary environment collects and stores compliance evidence separately, allowing tenants to perform comprehensive assessments without requiring complex real-time access to production systems. This extraction simplifies the access management architecture while maintaining assessment capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8782795B1Secure tenant assessment of information technology infrastructure
Publication Date: 2014.07.15 EMC IP HLDG CO LLC
  • US8782795B1 patent drawing
  • US8782795B1 patent drawing
  • US8782795B1 patent drawing

AI summary

Information technology infrastructure comprises a computing environment shared by multiple tenants of a service provider, and a secure assessment environment separate from the shared computing environment. An evidence collection module associated with the shared computing environment collects compliance evidence from the shared computing environment for storage in the secure assessment environment. A tenant assessment interface to the secure assessment environment is provided, through which the tenants can access the compliance evidence as stored in the secure assessment environment in a manner that does not undermine security of the shared computing environment. The compliance evidence may include, for example, information sufficient to allow a tenant to verify that the shared computing environment is configured in accordance with a specified security policy. In an illustrative embodiment, the information technology infrastructure comprises cloud infrastructure of a cloud service provider and the shared computing environment comprises a cloud computing environment.