Endpoint Policy Selection Scoring for SOAP Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of an effective and efficient mechanism for choosing among different endpoint policy alternatives in Web Services security, particularly in SOAP messages, which results in considerable overhead in parsing message XML and applying cryptographic operations, impacting CPU cycles and process efficiency.

Innovation Solution

A computer-based system and method that assigns scores to each endpoint policy alternative based on policy assertions and selects the most suitable one using a predetermined selection criterion, optimizing the selection process by weighing policy assertions and applying bit masks to efficiently apply security policies to messages conveyed over data communications networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple endpoint policy alternatives are provided to accommodate different Web Service providers and security requirements, then adaptability and security flexibility are improved, but device complexity and difficulty of selection increase

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidpolicy selection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent pre-computes and stores scores for each endpoint policy alternative based on their policy assertions before runtime selection. This preliminary scoring action eliminates the need for complex real-time analysis when selecting policies, resolving the contradiction by preparing selection criteria in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the complex policy selection problem into a simple score-based comparison by changing the selection parameter from analyzing entire policy assertions to comparing pre-computed numerical scores. This parameter transformation simplifies the selection process while maintaining adaptability across different security requirements.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If endpoint policy alternatives are selected without optimization, then security coverage is maintained, but processing time and CPU cycles increase due to overhead in parsing message XML and applying cryptographic operations

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-computes scores for all endpoint policy alternatives based on their policy assertions before runtime. This preliminary action eliminates the need for complex real-time policy analysis, significantly reducing processing time while maintaining comprehensive security coverage through score-based selection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a simplified score representation (a copy of the essential selection criteria) from the complex policy assertions. Instead of parsing and analyzing entire XML policy documents at runtime, the system uses pre-computed score copies that capture the essential security requirements, reducing CPU cycles while maintaining security integrity.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive policy assertions are evaluated in real-time, then selection accuracy is improved, but computational overhead and CPU cycles increase

Engineering Contradiction:
Improvepolicy selection accuracyVSAvoidCPU cycles
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent creates score representations that copy the essential selection criteria from complex policy assertions. These score copies enable accurate policy selection without requiring real-time evaluation of comprehensive policy details, significantly reducing CPU cycles while maintaining selection accuracy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the selection criterion from comprehensive policy assertion evaluation to simple score comparison. This parameter change maintains selection accuracy by preserving the essential differentiation between policies while eliminating computationally expensive real-time analysis.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8799982B2System and methods for efficiently classifying and selecting among security policy alternatives for outbound network communications
Publication Date: 2014.08.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8799982B2 patent drawing
  • US8799982B2 patent drawing
  • US8799982B2 patent drawing

AI summary

A computer-implemented method of selecting among a plurality of endpoint policy alternatives to apply to a message conveyed over a data communications network is provided. The method can include assigning a score to each of the plurality of endpoint policy alternatives, wherein an assigned score is based upon policy assertions of the endpoint policy alternative to which the score is assigned. The method can further include selecting, according to a predetermined selection criterion, one of the plurality of endpoint policy alternatives based upon the assigned scores.