Decentralized Policy Management System for Supply Chain Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security policy management systems face challenges such as complex and numerous policies, difficulty in policy authoring and enforcement, inflexible policy testing, and centralized trust management, which hinder effective security and risk management in IT systems.

Innovation Solution

A method and system for managing supply chain risks and security policies, which includes assisted policy management, contextual editor generation, flexible policy testing, decentralized and orthogonal management of policy and trust, and supply chain risk analysis and management. This system uses a processor to load and map data, analyze anomalies, and produce analysis results, enabling decentralized trust and orthogonal policy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If conventional centralized policy management systems are used, then policy enforcement can be maintained, but the system complexity and difficulty in managing numerous policies increases

Engineering Contradiction:
Improvepolicy management system complexityVSAvoidpolicy authoring and enforcement difficulty
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments policy management into decentralized policy modules distributed across multiple nodes in the system. Each node can independently manage and enforce policies locally, eliminating the need for a single complex centralized management system and reducing overall system complexity while improving ease of operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy as code as an intermediary layer between policy definitions and enforcement mechanisms. This intermediary enables automated policy management, reducing the complexity of managing numerous policies while improving ease of operation through programmable policy logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional policy testing methods are used, then basic policy validation can be performed, but the flexibility and adaptability of policy testing decreases

Engineering Contradiction:
Improvepolicy testing flexibilityVSAvoidtesting system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy testing that can adapt to different policy types and scenarios. The testing framework is designed to be flexible and configurable, allowing policies to be tested in various environments and conditions without requiring complex fixed testing infrastructure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses policy simulations and virtual environments to copy production policy behavior for testing purposes. This allows flexible policy testing in isolated environments without affecting actual systems, improving adaptability while avoiding the complexity of testing in production systems.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If centralized trust management is implemented, then trust verification can be maintained, but the system loses decentralization and orthogonal policy management capabilities

Engineering Contradiction:
Improvedecentralization capabilityVSAvoidtrust management reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments trust management into distributed trust verification mechanisms across multiple nodes. Each node can independently verify trust relationships locally, enabling decentralization while maintaining reliability through distributed consensus and verification protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal policy framework that can enforce both security policies and trust verification in a unified manner. This multi-functional approach allows the system to maintain reliability through comprehensive policy enforcement while achieving decentralization through the universal applicability of the policy-as-code framework across distributed nodes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12218978B2Method and system for policy management, testing, simulation, decentralization and analysis
Publication Date: 2025.02.04 LANG ULRICH
  • US12218978B2 patent drawing
  • US12218978B2 patent drawing
  • US12218978B2 patent drawing

AI summary

A method of managing supply chain risks having a supply chain risk analysis implementation, includes loading from a data storage or a memory, supply chain data for a supply chain which indicates information about the supply chain; mapping the supply chain data to a consistent input model; automatically analyzing, by an analytics module implemented on a processor, the input model to detect supply chain anomalies indicating the supply chain risks; producing an analysis results output of the analyzed input model; and outputting the analysis results output of the detected supply chain anomalies to the memory, the data storage, a display, or a message. A supply chain risk analysis system includes the processor, the data storage or the memory that stores the supply chain data for the supply chain which indicates information about the supply chain. The processor is configured to perform the processes.