Codified Policy Management for Cloud Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, managing access to resources becomes cumbersome due to the rapid growth of policies and rules across multiple machines, leading to complexity in deployment and analysis, especially when policies diverge over time or are expressed in different languages, resulting in inefficiencies in security and resource management.

Innovation Solution

A computer system that includes a policy repository, a policy codifier, and a policy manager, which generates codified policies by substituting symbols for semantic terms, de-duplicates entries, and manages access based on similarity comparisons between policies, allowing for efficient deployment and clustering of managed machines with similar security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If policies are managed individually across multiple machines without codification, then each machine can maintain its own policy details, but the complexity of deployment and analysis increases rapidly as policies grow across the system

Engineering Contradiction:
Improvepolicy customizationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments policies into machine-specific policy portions and common policy portions. Each machine receives only its relevant policy segment, reducing the complexity each machine must manage while maintaining full policy functionality. This segmentation allows scalable deployment across multiple machines without exponential growth in system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a codified policy structure that serves multiple functions: it enables automated deployment, facilitates similarity comparison for clustering, supports both individual and common policy management, and provides a standardized format for analysis. This universal structure resolves the contradiction by making the system adaptable to different machines while maintaining manageable complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If policies are expressed in different languages or formats across machines, then each machine can use its preferred format, but analysis and comparison of policies become inefficient

Engineering Contradiction:
Improvepolicy format flexibilityVSAvoidanalysis efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent introduces a codified policy structure as an intermediary representation that translates diverse policy languages and formats into a standardized form. This intermediary structure enables efficient automated analysis, similarity comparison, and clustering operations while preserving the ability to represent different policy types and formats, thus resolving the contradiction between format flexibility and analysis efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If all policy entries are deployed to each machine, then complete policy coverage is ensured, but deployment size and processing overhead increase

Engineering Contradiction:
Improvepolicy coverageVSAvoidpolicy data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the complete policy into machine-specific portions and common portions, deploying only the relevant segments to each machine. This segmentation maintains complete policy coverage for each machine while significantly reducing the policy data volume that must be stored and processed locally, resolving the contradiction between reliability and quantity.

Inventive Principle:
Principle #1Segmentation

4Productivity

If machines with different security levels are hosted together in the same cloud environment, then resource utilization is improved, but security risks increase as attackers can leverage lower security systems to access higher security systems

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent merges machines with similar policy characteristics into security clusters, allowing them to be hosted together in the same cloud environment. This merging improves resource utilization by grouping compatible workloads while maintaining security through policy-based isolation. The codified policy structure enables automated identification of machines that can safely be grouped together, resolving the contradiction between resource utilization and security risk.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8898304B2Managing access to resources of computer systems using codified policies generated from policies
Publication Date: 2014.11.25 CA TECH INC
  • US8898304B2 patent drawing
  • US8898304B2 patent drawing
  • US8898304B2 patent drawing

AI summary

A computer system is disclosed that includes a policy repository, a policy codifier, and a policy manager. The policy repository contains policies. The policy codifier generates codified policies from the policies. The policy manager manages access to resources of the computer system responsive to the codified policies. Related methods and computer program products for operating computer systems are also disclosed.