Cloud Mainframe Security via External Policy Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current operating systems and database management systems face challenges in managing complex security models and providing fine-grained access control, particularly in environments like mainframe workloads migrated to cloud services, where existing security models are limited and cumbersome, especially in handling multiple users, groups, and roles.

Innovation Solution

An external policy management service is used to control access to operating system and database resources, employing a kernel-mode authorization interceptor and security hooks to enforce security policies externally managed by a policy database, allowing for customized permissions and compliance with regulatory constraints through mathematical proofs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional operating system security models are used to manage access control, then basic security functions are provided, but the system becomes complex and cumbersome when managing multiple users, groups, and roles with fine-grained access control requirements

Engineering Contradiction:
Improveaccess control managementVSAvoidsecurity model complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the security policy management functionality from the traditional operating system into a separate, external policy management service. This external service handles the complexity of managing users, groups, roles, and fine-grained access control policies, while the operating system itself remains relatively simple. The separation allows complex security requirements to be managed externally without increasing operating system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary component - the policy management service - that mediates between users and operating system resources. This intermediary handles authentication, authorization, and policy enforcement, simplifying the interaction for users while managing the complexity of security policies centrally. The intermediary translates user requests into security policy evaluations and enforces decisions without requiring the operating system to directly manage complex security models.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing security models are used in cloud environments for mainframe workloads, then basic access control is provided, but compliance with regulatory constraints cannot be mathematically verified

Engineering Contradiction:
Improvecompliance verificationVSAvoidsecurity management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by establishing a formal mathematical framework for security policies before enforcement. Security policies are defined using formal logic and mathematical models that enable proactive verification of compliance requirements. The system pre-defines security constraints and uses mathematical proofs to verify compliance before actual security incidents occur, rather than reacting afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical security management approaches with a mathematical and formal verification system. Instead of relying on manual security configuration and ad hoc access control mechanisms, the system uses mathematical models, formal logic, and automated verification to ensure compliance. This substitution transforms security from an art-based manual process into a science-based verifiable system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If manual security policy management is implemented, then flexibility in customization is achieved, but the process is time-consuming and inefficient

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidsecurity management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements self-service capabilities that allow users to independently manage their own security policies and access requests. The system provides automated policy evaluation, dynamic access control decisions, and self-provisioning mechanisms that eliminate the need for manual security administration for routine operations. Users can define their own security requirements and have them automatically enforced by the system, improving both customization and efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent enables dynamic parameter changes in security policies without requiring system reconfiguration. Security policies are defined with adjustable parameters that can be modified at runtime based on changing requirements. The system supports dynamic policy updates, conditional access rules, and flexible parameter adjustment while maintaining automated enforcement, allowing rapid adaptation to new security requirements without manual intervention.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12143398B1Cloud-based mainframe service
Publication Date: 2024.11.12 AMAZON TECH INC
  • US12143398B1 patent drawing
  • US12143398B1 patent drawing
  • US12143398B1 patent drawing

AI summary

Systems, devices, and methods are provided for implementing a cloud-based mainframe service. A cloud-based mainframe service may utilize various resources, including an operating system that is provisioned with an authorization interceptor that uses a first set of security policies stored in a policy database to determine whether to grant or deny access to resources managed by the operating system. The authorization interceptor may use the security policies of the policy database to determine whether to grant access to operating system resources. A database management system may use a second set of security policies stored in the policy database to determine whether to grant or deny access to resources managed by the database system. Security policies for a mainframe service may be centrally stored in a policy database managed by a policy management service.