Automated Configuration Management for Secure Software Builds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual review and selection of updates and patches for software components is time-consuming, especially for enterprises with numerous changes, making it impractical for efficient management of multiple versions, modifications, and patches.

Innovation Solution

A system and method that utilize a back-end configuration management computer server to retrieve secure configuration benchmarks, provision an initial operating system build, apply enterprise-specific modifications, validate through secure configuration and vulnerability checks, and apply updates to create a service instance, enabling automated and efficient management of software configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual review and selection of updates and patches is performed, then security and accuracy of configuration management is improved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvesecurity and accuracy of configuration managementVSAvoidtime consumption for reviewing and selecting updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically retrieving, validating, and preparing configuration updates and patches before they are needed for deployment. The configuration management server proactively fetches updates from repositories, validates them against benchmarks, and prepares them for application, eliminating the need for manual review at the time of deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The configuration management system performs self-service by automatically managing the entire update lifecycle including retrieval, validation, and application of patches and configuration changes. The system validates updates against secure configuration benchmarks and automatically applies approved changes without requiring manual human intervention for each update.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated configuration management is implemented, then productivity and operational efficiency are improved, but system complexity and validation requirements increase

Engineering Contradiction:
Improveoperational efficiency in managing software configurationsVSAvoidcomplexity of automated configuration management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The configuration management server acts as an intermediary between the update repositories and the target computing devices. It mediates the update process by retrieving updates from repositories, validating them against benchmarks, and automatically applying approved updates to devices, thereby simplifying the overall system architecture while maintaining security and control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by validating configuration updates against secure configuration benchmarks before deployment. The validation process provides feedback on whether updates meet security requirements, and the system only applies updates that pass validation, ensuring continuous compliance while automating the process.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive validation of configuration updates is performed, then security and compliance are improved, but processing time and operational overhead increase

Engineering Contradiction:
Improvesecurity and compliance of configuration updatesVSAvoidprocessing time for validation and application of updates
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The system performs validation as a preliminary action before updates are deployed to production environments. Configuration updates are validated against secure configuration benchmarks in advance, and only pre-validated updates are stored and deployed, eliminating the need for time-consuming validation during deployment while maintaining security and compliance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10805154B2Secure configuration management system
Publication Date: 2020.10.13 HARTFORD FIRE INSURANCE CO
  • US10805154B2 patent drawing
  • US10805154B2 patent drawing
  • US10805154B2 patent drawing

AI summary

According to some embodiments, a configuration benchmark data store may include a plurality of secure configuration benchmarks. A back-end configuration management computer server may retrieve one of the secure configuration benchmarks and provision, by an orchestration engine, an initial operating system build in accordance with the retrieved secure configuration benchmark and an automation template. The back-end configuration management computer server may then apply, by a provisioning tool, enterprise-specific modifications to the initial operating system build to create an environment compliant with an enterprise standard benchmark. The back-end configuration management computer server may validate the enterprise standard benchmark via secure configuration and vulnerability checks, apply at least one configuration update to the enterprise standard benchmark to create a service instance, and then apply application code to the service instance.