Decentralized Policy Management System for Supply Chain Risk Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security policy management systems face challenges such as complex and numerous policies, difficulty in policy authoring and enforcement, inflexible policy testing, and centralized trust management, which hinder effective security and risk management in IT systems.
Innovation Solution
A method and system for managing supply chain risks and security policies, which includes assisted policy management, contextual editor generation, flexible policy testing, decentralized and orthogonal management of policy and trust, and supply chain risk analysis and management. This system uses a processor to load and map data, analyze anomalies, and produce analysis results, enabling decentralized trust and orthogonal policy management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If conventional centralized policy management systems are used, then policy enforcement can be maintained, but the system complexity and difficulty in managing numerous policies increases
Solution Approach 1:
The patent segments policy management into decentralized policy modules distributed across multiple nodes in the system. Each node can independently manage and enforce policies locally, eliminating the need for a single complex centralized management system and reducing overall system complexity while improving ease of operation.
Solution Approach 2:
The patent introduces policy as code as an intermediary layer between policy definitions and enforcement mechanisms. This intermediary enables automated policy management, reducing the complexity of managing numerous policies while improving ease of operation through programmable policy logic.
2Adaptability or versatility
If traditional policy testing methods are used, then basic policy validation can be performed, but the flexibility and adaptability of policy testing decreases
Solution Approach 1:
The patent implements dynamic policy testing that can adapt to different policy types and scenarios. The testing framework is designed to be flexible and configurable, allowing policies to be tested in various environments and conditions without requiring complex fixed testing infrastructure.
Solution Approach 2:
The patent uses policy simulations and virtual environments to copy production policy behavior for testing purposes. This allows flexible policy testing in isolated environments without affecting actual systems, improving adaptability while avoiding the complexity of testing in production systems.
3Adaptability or versatility
If centralized trust management is implemented, then trust verification can be maintained, but the system loses decentralization and orthogonal policy management capabilities
Solution Approach 1:
The patent segments trust management into distributed trust verification mechanisms across multiple nodes. Each node can independently verify trust relationships locally, enabling decentralization while maintaining reliability through distributed consensus and verification protocols.
Solution Approach 2:
The patent implements a universal policy framework that can enforce both security policies and trust verification in a unified manner. This multi-functional approach allows the system to maintain reliability through comprehensive policy enforcement while achieving decentralization through the universal applicability of the policy-as-code framework across distributed nodes.
Data Source
AI summary
A method of managing supply chain risks having a supply chain risk analysis implementation, includes loading from a data storage or a memory, supply chain data for a supply chain which indicates information about the supply chain; mapping the supply chain data to a consistent input model; automatically analyzing, by an analytics module implemented on a processor, the input model to detect supply chain anomalies indicating the supply chain risks; producing an analysis results output of the analyzed input model; and outputting the analysis results output of the detected supply chain anomalies to the memory, the data storage, a display, or a message. A supply chain risk analysis system includes the processor, the data storage or the memory that stores the supply chain data for the supply chain which indicates information about the supply chain. The processor is configured to perform the processes.


