Unified Trust Platform for Multi-Cloud Security Control Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing security and compliance across multi-cloud environments is challenging due to the complexity of integrating various vendor tools and lack of timely visibility, leading to data breaches and increased security risks.

Innovation Solution

A trust platform that receives security and compliance policy specifications, generates corresponding controls, and deploys them across multiple cloud service providers using APIs, providing a unified view and automated management of security and compliance controls through monitoring tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple vendor tools are integrated to manage security across multi-cloud environments, then security coverage is improved, but system complexity increases and visibility is delayed

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple vendor-specific security tools and cloud provider interfaces into a single unified security management platform. This consolidation maintains comprehensive security coverage across multi-cloud environments while reducing system complexity by providing a common interface and centralized control mechanism that manages diverse security tools through standardized procedures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified security management platform acts as an intermediary layer between cloud providers and security tools. It provides standardized APIs and abstraction mechanisms that enable integration of multiple vendor tools without requiring direct complex connections between each tool and cloud provider, thereby improving security coverage while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual security control deployment is performed across multiple cloud providers, then customization to specific policies is improved, but time consumption and IT burden increase

Engineering Contradiction:
Improvepolicy customizationVSAvoidtime consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system enables preliminary definition of security policies and control templates that can be customized for specific organizational requirements. These pre-configured policies are stored and ready for deployment, allowing rapid instantiation across multiple cloud providers without manual reconfiguration for each deployment, thus maintaining policy adaptability while reducing time consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unified security management platform provides universal policy deployment capabilities that work across multiple cloud providers through standardized interfaces. A single policy definition can be applied universally across different cloud environments with automatic adaptation to provider-specific requirements, maintaining customization capabilities while dramatically reducing the time and effort required for deployment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If centralized security management is implemented across multi-cloud environments, then compliance visibility is improved, but integration complexity with vendor tools increases

Engineering Contradiction:
Improvecompliance visibilityVSAvoidintegration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the integration complexity by separating the centralized management functions from vendor-specific tool implementations. It uses standardized API layers and modular integration components that handle different cloud providers and security tools independently, allowing centralized compliance visibility while managing integration complexity through structured, manageable segments rather than monolithic integration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11962620B2Policy-driven management of security and compliance controls for multi-cloud workloads
Publication Date: 2024.04.16 EMC IP HLDG CO LLC
  • US11962620B2 patent drawing
  • US11962620B2 patent drawing
  • US11962620B2 patent drawing

AI summary

An apparatus comprises a processing device configured to receive, at a user interface of a trust platform configured to manage cloud assets operating in clouds of two or more cloud service providers, a specification of security and compliance policies of a given entity. The processing device is also configured to generate, based at least in part on the specified security and compliance policies of the given entity, security and compliance controls to be implemented for workloads of the given entity running on a subset of the cloud assets operating in the clouds of the two or more cloud service providers. The processing device is further configured to deploy, utilizing application programming interfaces of the trust platform, the generated security and compliance controls on first and second pluralities of monitoring tools operating in tenant and management environments of the clouds of the two or more cloud service providers.