Entity Aggregation Covenants for Secure Computing Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for decision-making in business and analytics fail to effectively facilitate the presentation of alternative points of view and handling of diverse organizational structures, limiting the ability to model and simulate various perspectives.
Innovation Solution
A system for entity aggregation in a computing environment that includes user-type, data-type, and process-type entities, with an aggregation covenant defining computing environment capabilities, an aggregation rule configuration module, and an aggregation configuration module to define entity instances within an aggregation, allowing for the combination of capabilities and enabling secure resource management through entity-specific and aggregation-specific sets of access and privilege information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If entities are aggregated with combined capabilities from multiple sources, then the system's versatility and functional richness improve, but the security management complexity and difficulty of capability coordination worsen
Solution Approach 1:
The patent introduces an aggregation covenant as an intermediary mechanism that mediates between multiple entity capabilities and the aggregation. The covenant acts as a contract defining which capabilities are transferred, how they are combined, and under what conditions, thereby simplifying the management of complexity while enabling versatile capability aggregation.
Solution Approach 2:
The patent segments capability management into distinct components: entity-specific capabilities, aggregation-specific capabilities, and covenant-defined capability transfers. This segmentation allows each component to be managed independently, reducing overall complexity while maintaining functional versatility through their coordinated interaction.
2Adaptability or versatility
If entity instances are defined with capabilities from aggregation covenants, then the system's ability to handle alternative points of view improves, but the difficulty of detecting and measuring capability boundaries worsens
Solution Approach 1:
The patent applies local quality by allowing different entities to have different capability sets defined by their specific covenants. Each entity instance can have locally optimized capabilities tailored to its role, enabling diverse perspectives while maintaining clear local boundaries. The capability boundaries are made detectable through entity-specific capability registries.
3Adaptability or versatility
If root capabilities are superseded by covenant capabilities, then the system's adaptability to new organizational structures improves, but the reliability of original security guarantees worsens
Solution Approach 1:
The patent introduces dynamics by making capability assignments flexible and context-dependent. The aggregation covenant dynamically determines which capabilities supersede root capabilities based on the specific aggregation context, organizational structure, and security requirements. This allows adaptability while maintaining reliability through context-aware capability management.
Solution Approach 2:
The system implements feedback mechanisms where capability supersession decisions are monitored and can be adjusted. The covenant framework provides feedback loops that allow verification of security guarantees even when root capabilities are superseded, ensuring reliability is maintained through continuous validation and adjustment.
Data Source
AI summary
Entity aggregation for security computing resources involves an aggregation covenant that conditionally conveys rights to aggregation members. The ruling covenant is defined for protecting one or more computing resources by overriding system-level and/or entity-specific rights (e.g., super-users). An aggregation configuration module defines an aggregation-specific instance of an entity (user/device, process, or data) that receives the conveyed rights. The entity can use the rights conveyed only through its corresponding instance.


