Declarative System Configuration Model for Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administration is often performed by users with limited knowledge, leading to incorrectly configured, unreliable, and insecure computer systems, resulting in productivity losses and increased costs due to inefficient system performance and potential security vulnerabilities.

Innovation Solution

A declarative approach to system configuration is employed, where a hierarchical system model is defined to integrate sub-models, producing a statically typed, fully configured system instance that can be checked against established policies, ensuring system integrity and dependability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individual users with limited knowledge perform system administration tasks, then system configuration can be done by end users, but system correctness, reliability, and security deteriorate

Engineering Contradiction:
Improvesystem configuration accessibilityVSAvoidsystem correctness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a declarative system model as an intermediary layer between users and the actual system configuration. Users specify desired system states in high-level declarative statements rather than performing low-level configuration commands. The system automatically translates these declarative specifications into concrete configuration actions, ensuring correctness while maintaining ease of use. This mediator approach allows untrained users to achieve reliable system configurations without direct exposure to complex administration tasks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates and maintains a declarative system model that serves as an idealized copy or representation of the desired system state. This model captures the intended configuration, relationships, and constraints in a formal, verifiable format. By working with this abstract model rather than directly manipulating the live system, the approach ensures that configurations are derived from a validated specification, improving reliability while keeping the user interface simple and accessible.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If sequential installs and uninstalls are performed to configure systems, then system flexibility is maintained, but productivity is reduced due to time-consuming manual operations

Engineering Contradiction:
Improvesystem configuration flexibilityVSAvoidsystem configuration speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent performs preliminary actions by maintaining a declarative system model that pre-specifies the desired system state, dependencies, and relationships before actual configuration actions are executed. The system analyzes the model to determine the optimal sequence of operations and automatically performs necessary installs, uninstalls, and configuration changes in the correct order. This eliminates manual sequential operations while preserving flexibility, as the declarative model can represent complex dependencies and the system automatically resolves them efficiently.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamics by enabling the system to automatically adapt and generate configuration sequences based on the declarative model and current system state. Rather than requiring fixed manual procedures, the system dynamically determines the appropriate actions and ordering based on dependencies, constraints, and the desired end state. This dynamic approach maintains flexibility for different configuration scenarios while dramatically improving productivity by eliminating repetitive manual operations.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If manual system configuration is performed, then user control over system details is maintained, but system security deteriorates due to incorrect configurations

Engineering Contradiction:
Improveuser controlVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a declarative system model as an intermediary that formalizes security requirements and constraints. Users express their security policies and requirements in the declarative model, which then automatically translates these high-level security intentions into concrete, secure configuration actions. This intermediary layer ensures that security-critical configurations are derived from validated specifications rather than manual user actions, reducing vulnerabilities while preserving user control through the declarative policy definition interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously validates the declarative system model against security policies, constraints, and best practices. The system provides feedback to users about potential security issues in their specifications and automatically adjusts configurations to meet security requirements. This feedback loop ensures that security considerations are integrated into the configuration process while maintaining user control through iterative refinement of the declarative model.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8892694B2Declarative system configurations
Publication Date: 2014.11.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8892694B2 patent drawing
  • US8892694B2 patent drawing
  • US8892694B2 patent drawing

AI summary

A declarative approach is used for system configuration. The declarative approach improves a system's integrity which makes the system more dependable. An overall system model is defined that describes the system as a whole. The models are hierarchical and can reference and incorporate any number of sub-models. The models within the system model are used to define the programs within the system. The system model is applied to a collection of system parameters that produces a statically typed, fully configured system instance. Each system instance may then be checked against established system policies that can express a variety of additional ad hoc rules defining which system instances are acceptable.