Middleware Audit Provider Plugin for Centralized Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current middleware platforms lack a centralized audit framework for efficiently managing and storing audit data across different systems, making it difficult to enforce compliance, support business intelligence, and perform analytics.

Innovation Solution

Integrating a transactional middleware platform with a centralized audit framework by providing an audit provider as a plug-in module that processes audit requests and configures audit data for components, allowing for centralized data storage and management of audit policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a centralized audit framework is integrated with transactional middleware platform, then audit data management efficiency and compliance capability are improved, but system complexity increases

Engineering Contradiction:
Improveaudit data management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

An audit provider component is introduced as an intermediary between the transactional middleware platform and the centralized audit framework. This audit provider receives audit requests from the platform, processes them according to audit policies, and stores audit data in a centralized data store, thereby improving audit management efficiency while managing system complexity through a well-defined interface layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The audit provider is designed as a universal component that can handle multiple types of audit requests from different sources within the transactional middleware platform. It provides centralized audit data collection, storage, and management capabilities that serve compliance support, business intelligence, and analytics functions across the entire system

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If audit data is centralized from different systems, then compliance support and business intelligence capabilities are improved, but data integration complexity increases

Engineering Contradiction:
Improvecompliance support capabilityVSAvoiddata integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The audit data integration process is segmented into distinct components: audit event generation in different systems, audit request transmission to the audit provider, audit policy processing, and centralized storage in the audit data store. This segmentation allows each component to be independently managed and configured, reducing overall integration complexity while maintaining reliable compliance support

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The audit provider acts as a mediator that standardizes the integration process between diverse systems and the centralized audit framework. It provides a uniform interface for receiving audit requests from different sources, applying consistent audit policies, and storing data in a standardized format, thereby improving compliance capability without proportionally increasing integration complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9940178B2System and method for integrating a transactional middleware platform with a centralized audit framework
Publication Date: 2018.04.10 ORACLE INT CORP
  • US9940178B2 patent drawing
  • US9940178B2 patent drawing
  • US9940178B2 patent drawing

AI summary

In accordance with an embodiment, described herein is a system and method for integrating a transactional middleware platform with a centralized audit framework for a SOA middleware platform. An audit provider in the centralized audit framework can be provided as a plug-in module to the transactional middleware platform, and registered as an internal audit service therein. The internal audit service can be advertised on an audit server, and can process audit requests from within the transactional middleware platform. One or more configuration files can be provided to the audit provider, for use in generating audit data for audit events occurring in one or more components in the transactional middleware platform. The audit provider itself can be configured to represent an audit aware component within the centralized audit framework, thereby utilizing a plurality of functionalities available in the centralized audit framework, including saving the audit data in a central data store.