Automated Third-Party Network Compliance Scanning with Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Entities face challenges in ensuring third-party network compliance with their security and control standards without compromising the third party's privacy and security, and existing manual assessment methods are cumbersome and prone to missing vulnerabilities between assessments.

Innovation Solution

A method and system for assessing third-party network compliance by generating a scanning file with compliance standards, executing it at the third-party network to scan hardware and software, digitally signing the log file to make it immutable, and transmitting the results to the host entity network for reporting, allowing for ongoing, real-time monitoring without direct access to the third-party network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual weekly, monthly and/or annual assessments are performed, then the assessment process can be completed with basic tools, but the efforts required are cumbersome and vulnerabilities may incur and build up between assessments

Engineering Contradiction:
Improvecompliance assessment reliabilityVSAvoidtime between assessments
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements continuous automated scanning that performs compliance assessments continuously rather than waiting for scheduled manual assessments. This preliminary continuous action identifies vulnerabilities immediately when they occur, preventing them from building up between periodic assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary automated scanning system that runs between the host entity and third-party networks. This intermediary continuously monitors compliance without requiring direct access to third-party networks, eliminating the need for cumbersome manual assessment efforts while maintaining reliable detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If an organization enters the third party network to assess compliance standards, then direct compliance verification can be performed, but the third party's privacy and security within their network may be compromised

Engineering Contradiction:
Improvecompliance verification accuracyVSAvoidprivacy and security compromise
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent uses an intermediary automated scanning system that acts as a mediator between the host entity and third-party networks. This intermediary performs compliance verification by scanning for specific indicators without requiring direct access to or entry into the third-party network, thereby maintaining measurement precision while protecting privacy and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts only the essential compliance verification functions needed to assess third-party networks without requiring full access to the third-party environment. The scanning system extracts and analyzes specific compliance-related data points while leaving the third-party network intact and protected.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If third party vendors are required to comply with specific organization standards, then security control requirements can be maintained, but the vendors may not be willing to allow assessment access to their networks

Engineering Contradiction:
Improvesecurity control complianceVSAvoidassessment access cooperation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary automated scanning system that performs compliance verification without requiring third-party vendor cooperation or network access. This intermediary approach maintains security control compliance by continuously monitoring for specific indicators while eliminating the need for vendors to grant assessment access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a self-service automated scanning system that independently performs compliance assessments without requiring third-party vendor involvement. The system autonomously scans for compliance indicators and generates reports, allowing vendors to maintain their networks independently while still meeting organizational security control requirements.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Ensures continuous compliance assessment and immediate identification of vulnerabilities, protecting third-party network privacy while maintaining high security standards, reducing the risk of compromised vulnerabilities and enhancing overall network security.

Implementation Method 1

Digitally signing may encrypt the log file with digital codes that may be difficult to duplicate and/or change. The digitally signing may convert the log file to an immutable log file.

Methodology Applied
Scientific EffectDigital signing/Encryption:

Data Source

PatentUS11893116B2Assessment plug-in system for providing binary digitally signed results
Publication Date: 2024.02.06 BANK OF AMERICA CORP
  • US11893116B2 patent drawing
  • US11893116B2 patent drawing
  • US11893116B2 patent drawing

AI summary

A method for determining third party network compliance with a host entity network is provided. The method may include generating a scanning file that includes host entity network compliance standards and transferring the scanning file to an intermediary entity network. The method may further include generating an executable file that may run a plug-in scanning file to scan hardware and software resident at the third-party network for compliance. The method may further include transferring the executable file from the intermediary entity network to the third party network. The method may further include executing the executable file, generating a log file upon the completion of the running of the plug-in scanning file and digitally signing the log file. The method may further include deciphering the log file at the intermediary entity network, generating a readable report based on the deciphering and transferring the readable report to the host entity network.