Global Policy Attachment for Enterprise Resource Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for configuring and managing service policies in distributed computer systems lack a comprehensive mechanism for ensuring that all resources adhere to specified quality of service requirements, particularly in scenarios where policies are not explicitly attached by developers or administrators.

Innovation Solution

The implementation of global policy attachments, which allow administrators to specify desired attributes for policy subjects, enabling automatic association of policies across the enterprise system, ensuring that all resources comply with defined quality of service parameters, including security and network communication settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If global policy attachments are implemented to automatically associate policies with policy subjects, then compliance with quality of service requirements is improved, but system complexity increases

Engineering Contradiction:
Improvecompliance with quality of service requirementsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically associates policies with policy subjects by evaluating attributes and scope precedence without requiring manual administrator intervention. The policy attachment mechanism self-configures by comparing the policy attachment scope with the policy subject scope, allowing the system to serve itself in maintaining compliance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Policies are attached to scopes in advance before policy subjects are evaluated. The global policy attachment is configured with a scope and associated policies beforehand, so when a policy subject is encountered, the matching and attachment process occurs automatically without requiring real-time manual configuration.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If policies are explicitly attached to each policy subject, then policy control precision is improved, but administrative overhead increases

Engineering Contradiction:
Improvepolicy control precisionVSAvoidadministrative overhead
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

A single global policy attachment can serve multiple policy subjects that share the same scope characteristics. Instead of attaching policies individually to each subject, the system creates one universal policy attachment at the scope level that automatically applies to all matching policy subjects, reducing repetitive administrative work.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The scope acts as an intermediary between the policy attachment and individual policy subjects. Rather than directly attaching policies to each subject, the scope mediates the relationship, allowing policies to be attached once at the scope level and automatically inherited by all subjects within that scope.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If default security configuration is inherited by new resources, then security consistency is improved, but flexibility in customization decreases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidflexibility in customization
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

While global policy attachments provide default security configuration at the scope level, individual policy subjects can still have specific policies attached directly to them, allowing local customization where needed. The system supports both global defaults and local overrides, enabling security consistency across the board while permitting specific deviations when required.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10791145B2Attaching web service policies to a group of policy subjects
Publication Date: 2020.09.29 ORACLE INT CORP
  • US10791145B2 patent drawing
  • US10791145B2 patent drawing
  • US10791145B2 patent drawing

AI summary

In one set of embodiments, methods, systems, and apparatus are provided to attach one or more service policies to resources in an enterprise by receiving a first service policy, receiving a first policy attachment that identifies one or more policy attachment attributes of resources in the enterprise, and generate a first global policy attachment that references the first policy attachment and the first service policy. The method can include receiving a request to access a resource including an attribute that matches one of the policy attachment attributes. The method can include determining that the first service policy is an effective policy for the resource based on the matching resource attribute with the policy attachment attribute. The method can include controlling access to the resource responsive to the request using the effective policy.