Database Security Model Deployment via Node Grouping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database security models for cloud databases are time-consuming to generate and deploy, increasing vulnerability during the creation phase due to the need for compatibility with specific cloud database systems, and often require full security servers that consume resources and take longer to install.

Innovation Solution

A method to recommend an initial database security model by grouping nodes with similar characteristics into a self-organized centerless network, generating federated security models for these groups, and deploying a tailored security model for new nodes based on their similarities, reducing the need for full security servers and accelerating deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional database security models are generated and deployed, then security coverage is achieved, but deployment time is excessive and vulnerability period increases

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-generates multiple security model templates before actual deployment needs arise. These templates are created in advance based on common security requirements and configurations, so when a database node needs security protection, a pre-prepared template can be immediately selected and deployed rather than creating a security model from scratch at that moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the security model generation process by changing parameters from custom-built to template-based selection. Instead of generating security models with specific parameters for each individual case, the system uses predefined templates with configurable parameters that can be quickly adapted to different scenarios, significantly reducing the time required while maintaining security effectiveness.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If full security servers are deployed, then comprehensive security protection is provided, but resource consumption increases and installation time extends

Engineering Contradiction:
Improvesecurity protectionVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by matching security model templates to specific node characteristics rather than deploying uniform full-featured security servers to all nodes. Each node receives a security model tailored to its specific requirements, resource capacity, and security needs, providing appropriate security protection while avoiding unnecessary resource consumption on nodes that don't require maximum security configurations.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by deploying security models with appropriate feature sets based on actual needs rather than always deploying complete full-featured security servers. The template selection process identifies the minimum necessary security features for each node, deploying only those features and omitting unnecessary components, thus reducing resource consumption while maintaining adequate security protection.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If custom security models are generated for each node, then compatibility with specific cloud database systems is ensured, but generation time increases

Engineering Contradiction:
ImprovecompatibilityVSAvoidgeneration speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent creates security model templates that are universal in nature, designed to work across multiple cloud database systems and node types. These templates incorporate common security requirements and configurations that apply broadly, allowing a single template to serve multiple purposes and different scenarios, thereby maintaining compatibility without requiring separate custom generation for each individual node or system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary analysis and classification of node characteristics before template selection. By pre-processing node information to identify key attributes, cloud database system types, and security requirements, the system can quickly match nodes to appropriate pre-existing templates without performing time-consuming custom generation, thus ensuring compatibility while maintaining rapid deployment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12003542B2Rapid initial deployment database security model
Publication Date: 2024.06.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12003542B2 patent drawing
  • US12003542B2 patent drawing
  • US12003542B2 patent drawing

AI summary

A method, system, and computer program product for recommending an initial database security model. The method may include identifying a plurality of nodes connected to a security network. The method may also include analyzing security characteristics of each node of the plurality of nodes. The method may also include identifying, from the security characteristics, key factors for each node. The method may also include calculating similarities between each node of the plurality of nodes. The method may also include building a self-organized centerless network across the plurality of nodes by grouping nodes with high similarities based on the similarities between each node, where the self-organized centerless network is a centerless network without a central management server, and includes groups of nodes from the plurality of nodes. The method may also include generating federated security models for the groups of nodes.