Unified Identity Graph for Multi-Cloud Vulnerability Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for cloud workload vulnerability scanning are costly, time-consuming, and fail to provide comprehensive coverage of cloud environments, particularly for multi-tenant setups and hybrid cloud architectures.

Innovation Solution

A method and system for generating a security graph using a unified model across multiple cloud computing environments, which involves receiving data on resources, principals, and permissions, and creating nodes and connections in the graph based on this data to visualize and manage access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized scanning agents are deployed for each cloud environment, then vulnerability detection capability is improved, but device complexity and resource usage increase

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidcomplexity of scanning tools
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a unified identity model that serves multiple cloud environments (AWS, Azure, GCP) simultaneously. Instead of deploying separate scanning agents for each cloud platform, a single agentless system uses standardized identity graphs to represent principals, resources, and permissions across all environments, enabling universal vulnerability detection without increasing device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer (the unified identity model and graph representation system) between the scanning system and diverse cloud environments. This intermediary translates various cloud platform-specific identities and permissions into a standardized graph format, allowing vulnerability scanning without direct integration with each cloud provider's proprietary systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple separate cloud environments are used, then architectural flexibility is improved, but management complexity increases

Engineering Contradiction:
Improvearchitectural flexibilityVSAvoidcomplexity of user account management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple cloud environment identity systems into a single unified graph representation. By combining principals, resources, and permissions from different cloud platforms into one standardized model, the system maintains architectural flexibility while reducing management complexity through consolidation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies homogeneity by standardizing the representation of identities and permissions across heterogeneous cloud environments. All cloud providers' principals and resources are represented using the same graph structure and permission models, creating uniform management interfaces despite underlying architectural differences

Inventive Principle:
Principle #33Homogeneity

3Reliability

If comprehensive vulnerability scanning is implemented across all cloud workloads, then security coverage is improved, but loss of time and computational resources increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidtime for scanning operations
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-building and maintaining identity graphs that represent the cloud environment's principals, resources, and permissions. This pre-structuring of security context enables faster vulnerability scanning because the system already has an organized understanding of the attack surface before actual vulnerability detection begins

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces mechanical scanning agents with an agentless approach based on graph analysis. Instead of deploying physical or virtual scanning software on each workload, the system uses computational graph theory to model and analyze security relationships, substituting mechanical deployment with mathematical computation for faster, more efficient scanning

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250193252A1Efficient representation of multiple cloud computing environments through unified identity mapping
Publication Date: 2025.06.12 WIZ INC
  • US20250193252A1 patent drawing
  • US20250193252A1 patent drawing
  • US20250193252A1 patent drawing

AI summary

A system and method for generating a security graph utilizing a unified model based on multiple cloud environments are provided. The method includes receiving data from a first cloud environment pertaining to: resources, principals, and permissions; generating for each resource a corresponding resource node in the security graph, the corresponding resource node including an identifier of the resource, wherein the resource is a cloud entity deployed in the first cloud environment; generating for each principal a corresponding principal node in the security graph, the corresponding principal node including an identifier of the principal, wherein the principal is a cloud entity in the first cloud environment that generates an operation request in the first cloud environment; and generating a connection between at least a principal node and at least a resource node in the security graph, in response to detecting a permission indicating that a principal can access a resource.