Cloud Mainframe Security via External Policy Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current operating systems and database management systems face challenges in managing complex security models and providing fine-grained access control, particularly in environments like mainframe workloads migrated to cloud services, where existing security models are limited and cumbersome, especially in handling multiple users, groups, and roles.
Innovation Solution
An external policy management service is used to control access to operating system and database resources, employing a kernel-mode authorization interceptor and security hooks to enforce security policies externally managed by a policy database, allowing for customized permissions and compliance with regulatory constraints through mathematical proofs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional operating system security models are used to manage access control, then basic security functions are provided, but the system becomes complex and cumbersome when managing multiple users, groups, and roles with fine-grained access control requirements
Solution Approach 1:
The patent extracts the security policy management functionality from the traditional operating system into a separate, external policy management service. This external service handles the complexity of managing users, groups, roles, and fine-grained access control policies, while the operating system itself remains relatively simple. The separation allows complex security requirements to be managed externally without increasing operating system complexity.
Solution Approach 2:
The patent introduces an intermediary component - the policy management service - that mediates between users and operating system resources. This intermediary handles authentication, authorization, and policy enforcement, simplifying the interaction for users while managing the complexity of security policies centrally. The intermediary translates user requests into security policy evaluations and enforces decisions without requiring the operating system to directly manage complex security models.
2Reliability
If existing security models are used in cloud environments for mainframe workloads, then basic access control is provided, but compliance with regulatory constraints cannot be mathematically verified
Solution Approach 1:
The patent implements preliminary action by establishing a formal mathematical framework for security policies before enforcement. Security policies are defined using formal logic and mathematical models that enable proactive verification of compliance requirements. The system pre-defines security constraints and uses mathematical proofs to verify compliance before actual security incidents occur, rather than reacting afterward.
Solution Approach 2:
The patent replaces traditional mechanical security management approaches with a mathematical and formal verification system. Instead of relying on manual security configuration and ad hoc access control mechanisms, the system uses mathematical models, formal logic, and automated verification to ensure compliance. This substitution transforms security from an art-based manual process into a science-based verifiable system.
3Adaptability or versatility
If manual security policy management is implemented, then flexibility in customization is achieved, but the process is time-consuming and inefficient
Solution Approach 1:
The patent implements self-service capabilities that allow users to independently manage their own security policies and access requests. The system provides automated policy evaluation, dynamic access control decisions, and self-provisioning mechanisms that eliminate the need for manual security administration for routine operations. Users can define their own security requirements and have them automatically enforced by the system, improving both customization and efficiency.
Solution Approach 2:
The patent enables dynamic parameter changes in security policies without requiring system reconfiguration. Security policies are defined with adjustable parameters that can be modified at runtime based on changing requirements. The system supports dynamic policy updates, conditional access rules, and flexible parameter adjustment while maintaining automated enforcement, allowing rapid adaptation to new security requirements without manual intervention.
Data Source
AI summary
Systems, devices, and methods are provided for implementing a cloud-based mainframe service. A cloud-based mainframe service may utilize various resources, including an operating system that is provisioned with an authorization interceptor that uses a first set of security policies stored in a policy database to determine whether to grant or deny access to resources managed by the operating system. The authorization interceptor may use the security policies of the policy database to determine whether to grant access to operating system resources. A database management system may use a second set of security policies stored in the policy database to determine whether to grant or deny access to resources managed by the database system. Security policies for a mainframe service may be centrally stored in a policy database managed by a policy management service.


