Automated Configuration Change Enforcement via Selective Locks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current configuration management systems for computational systems lack automatic enforcement and monitoring of configuration changes, relying on human discipline and being prone to errors and deviations from defined processes.

Innovation Solution

A method and system that enforce and monitor configuration changes by using selective locks and authentication to ensure changes comply with defined rules, generating status information, and reporting on configuration changes within configurable computational systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If human discipline and monitoring are used to enforce configuration management processes, then the system can operate with simple mechanisms, but the reliability and compliance of configuration changes deteriorate due to human errors and deviations

Engineering Contradiction:
Improvesimplicity of enforcement mechanismVSAvoidcompliance of configuration changes
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces the mechanical system of human discipline and manual monitoring with an automated electronic system that uses software agents, authentication protocols, and digital locks to enforce configuration management rules. This substitution eliminates human error while maintaining systematic control, directly resolving the contradiction between simplicity and reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements self-service through automated authentication and authorization mechanisms where the configuration management system itself enforces its own rules without requiring human intervention. The selective locks and authentication protocols operate autonomously to prevent unauthorized changes, improving reliability while reducing the need for complex human oversight.

Inventive Principle:
Principle #25Self-service

2Reliability

If automatic enforcement mechanisms are implemented to ensure configuration change compliance, then reliability improves, but device complexity increases due to additional authentication and locking systems

Engineering Contradiction:
Improvecompliance of configuration changesVSAvoidcomplexity of enforcement mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing authentication and locking mechanisms that serve multiple functions: they not only enforce configuration change rules but also provide audit trails, track system state, and manage permissions across different configuration elements. This multi-functionality reduces overall system complexity while maintaining high reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements nesting by embedding authentication and authorization logic within the configuration management workflow itself. The selective locks are nested within the configuration change process, and authentication protocols are integrated into the existing system architecture, allowing automatic enforcement without adding significant external complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Manufacturing precision

If selective locks are used to control configuration changes, then configuration precision and compliance improve, but the ease of operation deteriorates due to restricted access

Engineering Contradiction:
Improveprecision of configuration changesVSAvoidease of making configuration changes
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication credentials, authorization rules, and lock conditions before configuration changes are needed. This preparation ensures that when configuration changes are required, the authentication process is streamlined and the selective locks are already configured to allow legitimate changes, thus maintaining precision without significantly hindering ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by providing real-time status information about configuration lock states, authentication outcomes, and compliance status. This feedback mechanism helps operators understand why certain changes are restricted and what steps are needed to authorize changes, improving ease of operation while maintaining the precision control provided by selective locks.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9864868B2Method and apparatus for process enforced configuration management
Publication Date: 2018.01.09 MCAFEE LLC
  • US9864868B2 patent drawing
  • US9864868B2 patent drawing
  • US9864868B2 patent drawing

AI summary

A system for and method of automatically enforcing a configuration change process for change requests of one or more configurable element within one or more configurable computation systems. The system comprises means for managing a configuration change process for one or more configurable elements within a corresponding configurable computation system, means for generation a configuration request, means for applying a set of authorization rules to the configuration change requests to generate selective authorization of the CEs, and means for selectively locking and unlocking changes to configurable elements within the configurable computational systems.