Dynamic Policy Enforcement Rule Generation from SLA Semantics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing service level agreement (SLA) policy enforcement systems face challenges in scalability, maintainability, agility, and operational stability due to the complexity of manually implementing and maintaining policies across large and feature-rich systems, leading to errors and inefficiencies in identifying and updating applicable policy enforcement rules.

Innovation Solution

A method and system for dynamically generating policy enforcement rules and actions from policy attachment semantics, where a processor at a policy enforcement point identifies enforceable provisions in defined SLAs and transforms them into runtime-executable processing rules, enabling automated enforcement of policies against runtime objects with enhanced specificity and granularity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual implementation and maintenance of SLA policies is used across large systems, then policy enforcement can be achieved, but system complexity and error rates increase significantly

Engineering Contradiction:
Improvepolicy enforcement accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service through automated policy rule generation and validation. The processor automatically transforms SLA policy definitions into executable policy enforcement rules, validating them against policy semantics without requiring manual intervention. This self-automating approach reduces human errors while managing system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary processing layer that acts as a mediator between SLA policy definitions and enforcement actions. The processor serves as an intermediary that automatically translates high-level policy definitions into detailed enforcement rules, reducing the complexity gap between policy specification and implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual updates of policy enforcement rules are performed, then policy changes can be implemented, but time consumption and operational inefficiency increase

Engineering Contradiction:
Improvepolicy update efficiencyVSAvoidtime for policy maintenance
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-compiling and validating policy enforcement rules from SLA definitions before runtime enforcement is needed. The processor generates and validates executable policy rules in advance, so that when policy updates are required, they can be rapidly deployed without time-consuming manual intervention or validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated policy rule generation system enables self-service for policy updates. When SLA definitions change, the processor automatically regenerates and validates the corresponding enforcement rules, eliminating the need for manual policy maintenance and significantly reducing the time required for policy updates.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive policy coverage is implemented across all runtime objects, then enforcement specificity improves, but rule identification complexity increases

Engineering Contradiction:
Improvepolicy enforcement specificityVSAvoidrule identification difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The system applies local quality by associating specific policy enforcement rules with individual runtime objects based on their characteristics. The processor analyzes runtime objects and applies only the relevant policy rules that match their specific attributes, achieving high enforcement specificity without requiring manual identification of applicable rules for each object.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The processor performs self-service by automatically identifying and selecting applicable policy enforcement rules for each runtime object. The system autonomously matches runtime objects with their corresponding policy rules based on object attributes and policy semantics, eliminating the need for manual rule identification while maintaining high enforcement specificity.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If dynamic policy generation is implemented at runtime, then policy agility improves, but processing overhead increases

Engineering Contradiction:
Improvepolicy agilityVSAvoidprocessing overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system resolves this contradiction by performing preliminary action - compiling and validating policy enforcement rules from SLA definitions before runtime. This pre-processing creates optimized executable rules that can be rapidly applied at runtime without significant processing overhead, enabling policy agility while minimizing energy consumption during enforcement.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11075956B2Dynamic generation of policy enforcement rules and actions from policy attachment semantics
Publication Date: 2021.07.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11075956B2 patent drawing
  • US11075956B2 patent drawing
  • US11075956B2 patent drawing

AI summary

At least one set of enforceable policy provisions is identified within at least one defined service level policy to be enforced during runtime by a policy enforcement point (PEP). Each set of enforceable policy provisions includes a policy subject, a reference to a policy domain, and at least one assertion. Each identified set of enforceable policy provisions is transformed by the PEP into at least one runtime-executable processing rule that each includes at least one PEP processing action that each represents an atomic unit of policy enforcement level behavior executable by the PEP to enforce the respective at least one assertion against runtime objects associated with the policy subject within an area of runtime policy enforcement specified by the policy domain.