Graphical Security Rule Generation for Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring security policies for large data models in Enterprise Systems is error-prone, leading to undesirable access by unauthorized users due to complex security rule writing.

Innovation Solution

A graphical user interface-based method and system for generating security rules that allow security officers to graphically indicate operations, aspects, and access types, using data models to define accessibility and implement rules through a rule interpretation engine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security rules are written manually for complex Enterprise Systems, then security coverage can be comprehensive, but error rate increases leading to unauthorized access

Engineering Contradiction:
Improvesecurity accuracyVSAvoidrule configuration difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a rule generation engine as an intermediary between security personnel and the rule interpretation engine. This engine automatically generates security rules based on inputs from users, eliminating manual rule writing and reducing errors. The intermediary processes user requirements and transforms them into precise security rules that are then executed by the rule interpretation engine.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing security personnel to configure security policies through a user interface without needing to manually write complex rules. The rule generation engine automatically processes the configured parameters and generates the appropriate security rules, making the system self-configuring and reducing human error in rule creation.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If manual security rule writing is used, then flexibility in customization is achieved, but error-proneness increases

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidaccess control accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The rule generation engine serves as an intermediary that receives high-level security policy requirements from users and automatically translates them into precise, error-free security rules. This maintains full customization capability while eliminating the errors associated with manual rule writing, as the intermediary handles the complex translation process automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If graphical user interface is implemented for rule generation, then ease of use improves, but system complexity increases

Engineering Contradiction:
Improvesecurity rule configurationVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The graphical user interface acts as an intermediary layer between the user and the complex rule generation engine. It presents simplified controls and parameters to users while the underlying engine handles the complexity of rule generation automatically. This allows the system to maintain high ease of use while managing the inherent complexity through the intermediary interface layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7596803B1Method and system for generating access policies
Publication Date: 2009.09.29 ADVANCED MICRO DEVICES INC
  • US7596803B1 patent drawing
  • US7596803B1 patent drawing
  • US7596803B1 patent drawing

AI summary

A method and system for generating security rules for implementation by a rule interpretation engine to define accessibility to one or more aspects of an Enterprise System is described. The method and system allow a security officer to graphically indicate an operation to be affected by the security rule being defined; a specific aspect of the system affected by the rule; a security regulation to be implemented by the rule; and an access type to be permitted by the rule.