Certificate-Based Distributed Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information rights management systems are limited in their ability to manage objects that cross security boundaries and enforce policies uniformly across different security domains, failing to effectively manage attributes of objects within a single security boundary.

Innovation Solution

A certificate-based distributed policy system where a policy server generates and validates object certificates using public key cryptography, incorporating a data structure with serialized public properties, hashes, and signatures, allowing for secure policy enforcement across communication boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing information rights management systems are used to enforce policies within a single security boundary, then policy enforcement is effective for that specific boundary, but the system cannot manage objects that cross multiple security boundaries or provide unified policy management across different domains

Engineering Contradiction:
Improveability to manage objects across security boundariesVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate as an intermediary object that mediates between the object and multiple security boundaries. The certificate contains the object's identity and associated policy information, allowing the object to be recognized and managed across different security domains without requiring each domain to understand the object's internal structure. This intermediary enables unified policy management while maintaining the independence of each security boundary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal certificate structure that can be used across multiple security boundaries and different types of objects. The certificate serves multiple functions: it identifies the object, carries policy information, enables verification of object integrity, and facilitates cross-boundary recognition. This multi-functional design allows a single system architecture to handle diverse objects across different security domains without requiring domain-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If persistent usage policies are applied to protect information after access, then information security is maintained for authorized users, but the system lacks flexibility to manage attributes and enforce policies uniformly across different security domains

Engineering Contradiction:
Improveinformation securityVSAvoidunified policy management across security domains
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by embedding policy information and object attributes into the certificate before the object crosses security boundaries. The certificate is generated in advance with all necessary policy constraints and object metadata, allowing receiving systems to enforce policies immediately upon receipt without needing to query the original system. This preliminary preparation enables both secure information protection and uniform policy management across distributed security domains.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If a unified framework is created to manage objects across security boundaries, then adaptability and unified policy management are improved, but the complexity of certificate generation, validation, and management increases

Engineering Contradiction:
Improveunified framework capabilityVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses copying by creating a certificate that contains a serialized representation of the object's public properties and policy information. Rather than managing the actual object across security boundaries, the system manages copies of the object's essential attributes and policy constraints in the certificate. This copying approach simplifies management because the certificate is a self-contained data structure that can be independently validated and processed without requiring access to the original object or complex inter-system coordination.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9237149B2Certificate based distributed policy enforcement
Publication Date: 2016.01.12 RED HAT INC
  • US9237149B2 patent drawing
  • US9237149B2 patent drawing
  • US9237149B2 patent drawing

AI summary

An apparatus and a method for a certificate-based distributed policy system is described. A policy server receives over a communication channel a data structure associated with an object to be managed across a communication boundary between a client and the policy server. The policy server generates an object certificate upon validation of the object and validation of an initiator of the object. The data structure includes a serialized representation of public properties of the object, a hash of the object in a canonical serialized form, and a signature of the public properties and hash using the initiator's private key.