Distributed Policy Management via Centralized Definition Store

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches to policy implementation in enterprises are not flexible or responsive to growth and change, leading to inconsistencies and conflicts in policy naming and scope, especially in distributed environments like Active Directory, where replicated policies can result in inconsistent user access.

Innovation Solution

A system and method for managing systems policies that ensure consistency with published policies by creating associations between published and systems policies, checking for violations before implementing changes, and using policy exceptions to allow deviations while maintaining compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If policies are replicated between domain controllers in a distributed enterprise, then policy implementation flexibility and responsiveness to growth improve, but policy consistency and naming conflicts worsen

Engineering Contradiction:
Improvepolicy implementation flexibilityVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent segments the monolithic policy store into multiple distributed policy stores across different domain controllers. Each domain controller maintains its own policy store, allowing independent policy management and replication. This segmentation enables the system to scale and adapt to enterprise growth while maintaining policy consistency through controlled replication mechanisms and centralized governance of policy definitions.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple policy stores are used to manage distributed groups of resources, then policy management adaptability improves, but policy conflicts and implementation inconsistencies worsen

Engineering Contradiction:
Improvepolicy management adaptabilityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of a centralized policy definition store that serves as the authoritative source for policy definitions. This intermediary allows multiple distributed policy stores to replicate policies consistently while providing a single point of control for policy naming, versioning, and validation. The intermediary resolves conflicts by establishing a hierarchical relationship between the central definition store and distributed implementation stores.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If replicated policies are not diligently maintained, then system operation simplicity improves, but user access consistency worsens

Engineering Contradiction:
Improvesystem operation simplicityVSAvoiduser access consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements feedback mechanisms through automated policy replication and validation processes. When policies are defined or modified in the centralized policy definition store, the system automatically replicates them to distributed domain controllers and validates consistency. This feedback loop ensures that user access consistency is maintained without requiring diligent manual maintenance, as the system self-corrects through automated synchronization and conflict detection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7607164B2Systems and processes for managing policy change in a distributed enterprise
Publication Date: 2009.10.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7607164B2 patent drawing
  • US7607164B2 patent drawing
  • US7607164B2 patent drawing

AI summary

A method for managing changes to policies in an enterprise includes receiving a systems policy change request to change a systems policy that implements a published enterprise policy, determining whether the requested systems policy change complies with the published enterprise policy, and updating the systems policy according to the requested systems policy change if the requested systems policy change complies with the published enterprise policy. A system for managing policies in an enterprise includes a policy management module configured for receiving published policies and generating corresponding systems policies having data for implementing the published policies, and a policy library storing the published policies and the systems policies.