Information Processing for Security-Policy-Aligned Operation Procedures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems lack support for constructing configurations that align with security policies, despite advancements in IT technology making systems increasingly complex.

Innovation Solution

An information processing apparatus and method that includes a policy analysis unit to analyze security policies, a dataflow information analysis unit to analyze system dataflow, and an operation procedure construction unit to integrate these analyses to construct operation procedures aligned with security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing apparatuses for network visualization and dataflow analysis are used, then network path detection and system overview are improved, but security policy compliance is not achieved

Engineering Contradiction:
Improvenetwork path detection accuracyVSAvoidsecurity policy compliance
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system segments the security analysis process into three distinct functional modules: network configuration analysis unit, dataflow analysis unit, and security policy compliance determination unit. Each module handles a specific aspect of the analysis, allowing comprehensive security verification while maintaining clear functional boundaries and improving overall system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary information processing apparatus that acts as a mediator between the target system and security policy requirements. This apparatus receives network configuration and dataflow information, performs intermediate analysis, and determines compliance with security policies, thereby bridging the gap between system operation and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Manufacturing precision

If comprehensive security analysis is performed, then security policy compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidanalysis system complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The information processing apparatus is designed with multi-functional capabilities, serving as a universal system that can perform network configuration analysis, dataflow analysis, and security policy compliance determination all through a single integrated platform. This reduces overall system complexity by consolidating multiple analysis functions into one apparatus.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary analysis of network configurations and dataflows before final security policy compliance determination. By pre-processing and organizing information in advance, the system simplifies the subsequent compliance checking process and reduces the complexity of real-time analysis.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If detailed dataflow analysis is conducted, then security vulnerability detection is improved, but processing time increases

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidanalysis processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary organization and classification of network configuration information and dataflow information before conducting detailed security analysis. This pre-processing step structures the data in advance, enabling faster and more efficient vulnerability detection without compromising analysis depth.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The analysis process is segmented into distinct phases: network configuration analysis, dataflow analysis, and compliance determination. Each phase processes specific information independently, allowing parallel processing and reducing overall analysis time while maintaining comprehensive security checking.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250217497A1Information processing apparatus, information processing method, and computer-readable recording medium
Publication Date: 2025.07.03 NEC CORP
  • US20250217497A1 patent drawing
  • US20250217497A1 patent drawing
  • US20250217497A1 patent drawing

AI summary

An information processing apparatus includes: a policy analysis unit that analyzes a security policy of operation of a target system; a dataflow information analysis unit that analyzes dataflow information of the target system; and an operation procedure construction unit that searches operation procedures registered in advance, using a result of analysis of the security policy, to specify a corresponding operation procedure, and applies a result of analysis of the dataflow information to the specified operation procedure to construct an operation procedure of the target system.