Data processing device for policy-controlled execution of tool calls with logging and reset function

The data processing device addresses dynamic control of tool calls by integrating policy evaluation, isolated execution, and tamper-proof logging to ensure secure, traceable, and recoverable system operations with adaptive policy adjustments.

DE202026102013U1Active Publication Date: 2026-06-03ATREYA MAYANK CUMMING +3

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
ATREYA MAYANK CUMMING
Filing Date
2026-04-11
Publication Date
2026-06-03
Patent Text Reader

Abstract

Data processing device for policy-controlled execution of tool calls, comprising a processing unit, a storage unit for storing multi-level defined execution guidelines and state images, a control unit for context-dependent validation and release of tool calls, as well as an execution environment for the isolated execution of released tool calls, the control unit is designed to evaluate each tool call using a multidimensional policy model, taking into account system state, call history and execution parameters, and to generate a consistent state image before execution, which, together with artifacts generated during execution, enables a deterministic resetting of the system to a previous state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The present invention belongs to the technical field of data processing systems, secure execution control, and software-based system architectures. In particular, the invention relates to a data processing device for the policy-controlled execution of tool calls with integrated state management, logging, and a reset function. The invention further lies within the field of distributed computing systems, embedded control units, and secure runtime environments, and comprises technical solutions for the controlled execution of system operations taking into account defined policies and state conditions. Moreover, the invention relates to ensuring the traceability, integrity, and recoverability of system states, especially through the combination of state images, tamper-proof logging, and adaptive rule processing within a data processing device. State of the art

[0002] Modern data processing systems increasingly employ automated execution mechanisms, in which software components, services, or tools are called independently or semi-autonomously to process complex tasks. Such systems are used particularly in distributed computing environments, orchestration platforms, safety-critical infrastructures, and intelligent assistance systems. However, with increasing automation, the risk of uncontrolled or erroneous tool calls also grows, which can cause undesirable state changes, security breaches, or system instability.

[0003] Existing systems of rules and guidelines define access rights, permissions, or specific execution conditions for system operations. However, such solutions are often limited to static permission mechanisms or simple access controls and do not adequately consider the current system state, the history of previous calls, or the specific execution context. As a result, finely tuned and context-dependent control of tool calls is often lacking.

[0004] Furthermore, logging systems are known that record execution events or system activities for monitoring purposes. However, these known logging systems primarily serve for subsequent analysis and not for the active control or safeguarding of ongoing tool execution. In particular, known solutions often lack a tamper-proof, temporally consistent log structure linked to state information, which enables complete traceability and reliable integrity checks.

[0005] Furthermore, recovery and backup systems are known that save system states through backups, snapshots, or checkpoints. However, these known methods are generally geared towards general data backup and are not specifically designed to monitor individual tool calls in a running environment, capture differential state changes, and, if necessary, perform a targeted rollback to a defined previous state. Moreover, known systems often lack a close integration between policy checks, execution control, logging, and the rollback mechanism.

[0006] Furthermore, isolated runtime environments, such as sandboxing or virtualization techniques, are known from the state of the art. These primarily serve to separate processes or limit system access, but are not combined with multi-stage policy evaluation, state-based reset logic, and adaptive optimization of execution rules. Similarly, machine learning systems for optimizing decision-making processes are known, but here too, a comprehensive technical solution is lacking that integrates historical log data, detected deviations, and state histories into a secure and controlled adaptation of execution policies.

[0007] Therefore, there remains a need for a technical device that not only controls tool calls based on predefined guidelines, but also provides an isolated execution environment, tamper-proof logging, efficient versioned state management, and a deterministic reset function within an integrated architecture. In particular, the state of the art lacks a data processing device that enables secure tool execution while dynamically considering system state, call history, and security policies, and simultaneously ensures complete traceability and recoverability of system operations. Object of the invention

[0008] The present invention is based on the objective of overcoming the disadvantages of the known prior art and providing a data processing device which enables a safe, controlled and traceable execution of tool calls.

[0009] The specific task is to create a device that evaluates and approves tool calls not only based on static guidelines, but also dynamically considering the system state, execution context, and call history. This should ensure multi-stage and context-dependent validation to prevent erroneous or unwanted executions.

[0010] Another object of the invention is to provide a technical solution for the deterministic resetting of system states, in which state images and artifacts generated before and during execution enable targeted restoration.

[0011] Furthermore, tamper-proof and complete logging of all execution processes should be ensured in order to enable full traceability and integrity verification.

[0012] Furthermore, the task is to provide a device that enables continuous improvement of system security and stability through adaptive adjustment of execution guidelines based on historical data. Summary of the invention

[0013] The present invention relates to a data processing device for the policy-controlled execution of tool calls, which enables safe and traceable control of automated system operations. The device comprises a processing unit, a storage unit for managing execution policies and state images, and a control unit for context-dependent validation of tool calls.

[0014] The invention is characterized in that tool calls are evaluated based on a multidimensional policy model, taking into account system state, call history, and execution parameters. Before execution, a consistent state image is generated, which, together with artifacts generated during execution, enables a deterministic system reset.

[0015] Furthermore, an isolated execution environment is provided in which tool calls are executed in a controlled manner. A tamper-proof logging unit ensures complete traceability of all system operations. In addition, adaptive rule adjustments based on historical data enable continuous improvement of execution reliability and system stability. Detailed description of the invention

[0016] The present invention relates to a data processing device for the policy-controlled execution of tool calls, which is particularly suitable for use in automated and safety-critical system environments. The device comprises a processing unit, a storage unit, a control unit, an execution environment, and a logging unit, which together enable controlled, traceable, and reversible execution of system operations.

[0017] The processing unit is designed to perform calculation and control tasks and is connected to the storage unit, which serves to store execution guidelines, state images, and log data. The execution guidelines define permissible conditions, parameter limits, and safety-related specifications for the execution of tool calls. The state images represent consistent snapshots of the system state at defined points in time.

[0018] The control unit is configured to receive incoming tool calls and validate them using a multidimensional policy model. This process takes into account, in particular, the current system state, the history of previous calls, and specific execution parameters. Validation is preferably performed in multiple stages, with separate checks applied before, during, and after the tool call is completed.

[0019] Before a tool call is released, the device generates a state image of the system, which includes all relevant state information. During execution, execution artifacts are also generated, documenting the changes caused by the tool call. These artifacts can include, for example, differential state information or event logs. The combination of the state image and execution artifacts enables a deterministic resetting of the system to a previous state.

[0020] The execution of authorized tool calls takes place within an isolated execution environment. This environment is designed with resource constraints, access controls, and security mechanisms to prevent unwanted interactions with other system components. During execution, the control unit continuously monitors state changes and compares them with the expected results according to the defined guidelines.

[0021] The logging unit is designed to store all relevant events, including tool calls, validation decisions, state changes, and reset operations, in a tamper-proof log structure. This log structure can, for example, be designed as a cryptographically secured, time-linked data chain, thus ensuring the integrity and immutability of the stored information. This enables complete traceability of all system operations.

[0022] The storage unit can also include versioned state management, where multiple system states are stored in parallel. Differential state images can be used to reduce storage requirements while enabling efficient restoration of any previous state.

[0023] In a preferred embodiment, the device also includes an adaptive control adjustment unit. This unit analyzes the historical data stored in the logging unit as well as detected deviations between expected and actual execution results. Based on this analysis, the execution guidelines are automatically adjusted within defined safety limits to continuously improve system performance, safety, and stability.

[0024] The device can be used in various system environments, such as distributed computing systems, cloud-based platforms, or embedded control systems. Its communication interfaces enable integration into higher-level systems and interaction with external components.

[0025] The present invention thus enables a technically advanced solution for the safe and controlled execution of tool calls. The combination of policy-based validation, an isolated execution environment, a deterministic reset function, tamper-proof logging, and adaptive rule adjustment ensures a high level of system security, transparency, and recoverability.

Claims

[1] Data processing device for policy-controlled execution of tool calls, comprising a processing unit, a storage unit for storing multi-level defined execution guidelines and state images, a control unit for context-dependent validation and release of tool calls, as well as an execution environment for the isolated execution of released tool calls, the control unit is designed to evaluate each tool call using a multidimensional policy model, taking into account system state, call history and execution parameters, and to generate a consistent state image before execution, which, together with artifacts generated during execution, enables a deterministic resetting of the system to a previous state. [2] Data processing device according to claim 1, characterized by, that the execution environment is designed as an isolated, restrictively configured runtime environment in which tool calls are executed under controlled resource conditions and with restricted access, continuously capturing state changes during execution and comparing them with the previously generated state image. [3] Data processing device according to claim 1, characterized by , that the storage unit includes versioned state management with differential state images, where changes between successive system states are stored in the form of compressed state differences to enable efficient and selective recovery of any previous state. [4] Data processing device according to claim 1, characterized bythat the device includes a tamper-proof logging unit which stores all tool calls, validation decisions, state changes and reset operations in a cryptographically secured, immutable and time-linked log structure, so that complete traceability and integrity verification of all system operations is ensured. [5] Data processing device according to claim 1, characterized by that the control unit includes an adaptive control optimization unit which automatically makes adjustments to the execution guidelines based on the logged execution data, detected deviations and historical state histories, whereby the adjustment is made taking into account defined safety limits in order to achieve a continuous improvement in execution safety and system stability.