Unified Trust Platform for Multi-Cloud Security Control Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security and compliance across multi-cloud environments is challenging due to the complexity of integrating disparate tools and services, leading to difficulties in obtaining a holistic view of security and compliance, which can result in data breaches and increased security risks.

Innovation Solution

A trust platform is implemented to provide a unified view of security and compliance across multiple cloud service providers, using APIs to collect and manage security and compliance controls, and automate the deployment of policies and access management, thereby simplifying the management of cloud assets and reducing the attack surface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple monitoring tools are used to manage security and compliance controls across multi-cloud environments, then the comprehensiveness of security monitoring is improved, but the complexity of integrating and managing these tools increases

Engineering Contradiction:
Improvesecurity monitoring comprehensivenessVSAvoidtool integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple monitoring tools (first plurality in tenant environments, second plurality in management environments) into a unified trust platform that collects, normalizes, and correlates security data from all sources through a single interface, eliminating the complexity of managing separate tools while maintaining comprehensive monitoring

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The trust platform serves as a universal security management system that performs multiple functions: collecting data from diverse monitoring tools, normalizing data formats, correlating security events, enforcing compliance policies, and providing unified access control across all cloud environments through a single platform

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If manual provisioning of security controls is performed, then the flexibility to customize security policies is improved, but the time required to deploy security measures increases

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidsecurity deployment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system pre-defines security control specifications and compliance policies that can be automatically applied to cloud workloads before they are deployed. The trust platform automatically provisions security controls based on pre-established templates and policies, eliminating manual configuration time while maintaining policy customization through configurable parameter sets

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If centralized security management is implemented, then the ease of obtaining a holistic view of security posture is improved, but the requirement for unified access and data collection mechanisms increases

Engineering Contradiction:
Improvesecurity visibilityVSAvoidunified access mechanisms
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The trust platform acts as an intermediary layer between diverse cloud service providers and security monitoring tools, providing standardized APIs and data collection mechanisms that simplify access to security data. It mediates between the need for centralized visibility and the complexity of integrating multiple cloud environments by providing a uniform interface for data collection and access control

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11503078B2Management of security and compliance controls for multi-cloud workloads
Publication Date: 2022.11.15 EMC IP HLDG CO LLC
  • US11503078B2 patent drawing
  • US11503078B2 patent drawing
  • US11503078B2 patent drawing

AI summary

An apparatus comprises a processing device configured to receive, at a user interface of a trust platform configured to manage cloud assets operating in clouds of two or more cloud service providers, a specification of security and compliance controls to be implemented for workloads of a given entity running on a subset of the cloud assets. The processing device is also configured to obtain, utilizing application programming interfaces of the trust platform, information characterizing deployed security and compliance controls for the subset of the plurality of cloud assets from first and second pluralities of monitoring tools operating in tenant and management environments of the clouds. The processing device is further configured to modify, utilizing the application programming interfaces of the trust platform, the deployed security and compliance controls responsive to determining that there are discrepancies between the specified security and compliance controls and the deployed security and compliance controls.