DCF-driven audit and compliance reporting
One example method includes receiving, from a DCF (data confidence fabric) including a node that comprises a data source of an edge environment, a confidence score concerning a data stream associated with the data source, correlating the confidence score to a compliance level of the edge environment with regard to a specified requirement for the edge environment, generating, based on the confidence score and compliance information, an audit report that identifies a connection between the confidence score and the compliance level, and for a value of a performance gap between the compliance level and a required compliance level, associated with the specified requirement, that meets or exceeds a threshold, identifying a remedial action which, when implemented in the edge environment, causes a reduction of the performance gap to a value below the threshold.
1 . A method concerning data handling compliance in an edge environment, comprising:
receiving, from a DCF (data confidence fabric) including a node that comprises a data source of an edge environment and a secure hardware, a confidence score concerning a data stream associated with the data source, the confidence score being generated by the secure hardware based on accumulated trust metadata, the accumulated trust metadata comprising at least a secure-boot annotation, a device attestation signature, provenance metadata, and an indication of authentication enablement, the accumulated trust metadata being stored in an immutable ledger accessible to the edge environment;
correlating, by the secure hardware, the confidence score to a compliance level of the edge environment with regard to a specified requirement for the edge environment;
generating, based on the confidence score and compliance information, an audit report that identifies a connection between the confidence score and the compliance level and that identifies, from the accumulated trust metadata, one or more diagnosed trust factor(s) that cause a lower confidence score, and that maps a confidence score of the data source to an assessment of non-compliance; and
for a value of a performance gap between the compliance level and a required compliance level, associated with the specified requirement, that meets or exceeds a threshold, identifying a remedial action which, when implemented in the edge environment, causes a reduction of the performance gap to a value below the threshold, the remedial action being selected by the secure hardware based on the diagnosed trust factor(s) identified from the accumulated trust metadata, and the remedial action comprising one or more of: revoking or re-provisioning keys provided by the secure hardware, performing a firmware update of the data source, reconfiguring a data path in the DCF to avoid or reduce use of the data source, or removing the data source from the DCF, and implementation of the remedial action being effected by issuing the remediation command(s) from the secure hardware to the affected node(s) so that the confidence score for the data source is increased and the performance gap is reduced below the threshold,
wherein the secure hardware includes a trust platform module (TPM) chip or an advanced reduced instruction set computing (RISC) machine (ARM) secure enclave, and
wherein the secure hardware provides keys used to perform signature service on the data source.
2 . The method as recited in claim 1 wherein the data source comprises hardware and/or software.
3 . The method as recited in claim 1 , wherein the specified requirement is determined by a regulatory agency.
4 . The method as recited in claim 1 , wherein the confidence score concerns performance of hardware and/or software of the data source.
5 . The method as recited in claim 1 , wherein the data stream was generated and/or handled by the data source.
6 . The method as recited in claim 1 , wherein the remedial action comprises receipt, by the edge environment, of a change to hardware and/or software of the edge environment.
7 . The method as recited in claim 1 , wherein implementation of the remedial action brings the edge environment into compliance with the specified requirement.
8 . The method as recited in claim 1 , wherein the specified requirement indicates how the data stream should be handled by entities in the edge environment.
9 . The method as recited in claim 1 , wherein the data stream was generated by the data source.
10 . The method as recited in claim 1 , wherein the edge environment is monitored on an ongoing and/or ad hoc basis for compliance of the edge environment with the specified requirement.
11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:
receiving, from a DCF (data confidence fabric) including a node that comprises a data source of an edge environment and a secure hardware, a confidence score concerning a data stream associated with the data source, the confidence score being generated by the secure hardware based on accumulated trust metadata, the accumulated trust metadata comprising at least a secure-boot annotation, a device attestation signature, provenance metadata, and an indication of authentication enablement, the accumulated trust metadata being stored in an immutable ledger accessible to the edge environment;
correlating, by the secure hardware, the confidence score to a compliance level of the edge environment with regard to a specified requirement for the edge environment;
generating, based on the confidence score and compliance information, an audit report that identifies a connection between the confidence score and the compliance level and that identifies, from the accumulated trust metadata, one or more diagnosed trust factor(s) that cause a lower confidence score, and that maps a confidence score of the data source to an assessment of non-compliance; and
for a value of a performance gap between the compliance level and a required compliance level, associated with the specified requirement, that meets or exceeds a threshold, identifying a remedial action which, when implemented in the edge environment, causes a reduction of the performance gap to a value below the threshold, the remedial action being selected by the secure hardware based on the diagnosed trust factor(s) identified from the accumulated trust metadata, and the remedial action comprising one or more of: revoking or re-provisioning keys provided by the secure hardware, performing a firmware update of the data source, reconfiguring a data path in the DCF to avoid or reduce use of the data source, or removing the data source from the DCF, and implementation of the remedial action being effected by issuing the remediation command(s) from the secure hardware to the affected node(s) so that the confidence score for the data source is increased and the performance gap is reduced below the threshold,
wherein the secure hardware includes a trust platform module (TPM) chip or an advanced reduced instruction set computing (RISC) machine (ARM) secure enclave, and
wherein the secure hardware provides keys used to perform signature service on the data source.
12 . The non-transitory storage medium as recited in claim 11 wherein the data source comprises hardware and/or software.
13 . The non-transitory storage medium as recited in claim 11 , wherein the specified requirement is determined by a regulatory agency.
14 . The non-transitory storage medium as recited in claim 11 , wherein the confidence score concerns performance of hardware and/or software of the data source.
15 . The non-transitory storage medium as recited in claim 11 , wherein the data stream was generated and/or handled by the data source.
16 . The non-transitory storage medium as recited in claim 11 , wherein the remedial action comprises receipt, by the edge environment, of a change to hardware and/or software of the edge environment.
17 . The non-transitory storage medium as recited in claim 11 , wherein implementation of the remedial action brings the edge environment into compliance with the specified requirement.
18 . The non-transitory storage medium as recited in claim 11 , wherein the specified requirement indicates how the data stream should be handled by entities in the edge environment.
19 . The non-transitory storage medium as recited in claim 11 , wherein the data stream was generated by the data source.
20 . The non-transitory storage medium as recited in claim 11 , wherein the edge environment is monitored on an ongoing and/or ad hoc basis for compliance of the edge environment with the specified requirement.