Model-Driven Security System Automating Policy Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security technologies struggle to effectively manage complex security policies in dynamic and interconnected IT environments, such as those found in IoT, M2M, and Cloud computing systems. Existing approaches like blacklisting and whitelisting are either unmanageable or inefficient in enforcing adequate security measures.
Innovation Solution
A model-driven security (MDS) system that uses a top-down approach to automate the translation of high-level security and compliance requirements into technical authorization policy rules, combined with model-driven security accreditation (MDSA) for verification and compliance. This system employs attributes, calculations, and mapping services to generate fine-grained, contextual security rules and supports advanced access control mechanisms like proximity-based access control (PBAC).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual policy implementation approaches are used, then security policies can be implemented, but they become unmanageable as IT environments become increasingly complex and dynamic
Solution Approach 1:
The system enables automated self-service through model-driven security technologies that automatically translate high-level security policies into machine-enforceable rules. The MDS platform autonomously generates, validates, and deploys security policies without requiring manual configuration, allowing the system to adapt dynamically to changing IT environments while maintaining policy effectiveness
Solution Approach 2:
The patent introduces model-driven security (MDS) as an intermediary layer between high-level security requirements and low-level technical implementations. This intermediary automatically translates business-level security policies into machine-enforceable rules, bridging the gap between security intent and technical execution while simplifying management of complex policies
2Object-affected harmful factors
If blacklisting approaches are used to block unwanted contents and access, then security threats can be mitigated, but they cannot implement the required fine-grained and contextual security policies
Solution Approach 1:
The system applies local quality by implementing fine-grained security policies that can be applied to specific subjects, objects, and contexts. The MDS platform enables different security rules to be applied to different parts of the system based on local conditions, such as proximity-based access control for specific devices or contextual policies for specific data types, rather than applying blanket blacklisting rules
3Adaptability or versatility
If whitelisting approaches are used to allow only appropriate contents and access, then fine-grained security control can be achieved, but they become unmanageable using manual policy implementation approaches
Solution Approach 1:
The automated MDS system performs self-service by autonomously generating, validating, and deploying fine-grained security policies. The platform automatically translates high-level whitelisting requirements into detailed machine-enforceable rules, managing the complexity of fine-grained control without requiring manual intervention
Solution Approach 2:
The patent replaces manual mechanical policy implementation with automated model-driven security technologies. The MDS platform uses automated model transformations and policy generation algorithms to substitute human manual work with intelligent systems that can handle complex fine-grained policy management at scale
4Reliability
If conventional accreditation methods are used, then security compliance can be verified, but they require too much manual effort and static system verification
Solution Approach 1:
The system implements continuous accreditation verification through automated model-driven security accreditation (MDSA). Instead of periodic static verification, the MDS platform continuously validates security policies against accreditation requirements as systems evolve, maintaining compliance verification without interruption or manual rework
5Reliability
If static system verification is used for accreditation, then compliance can be verified, but it cannot accommodate dynamically changing agile IT environments
Solution Approach 1:
The patent implements dynamic accreditation verification where the MDS platform continuously adapts security policies and compliance verification to changing system states. The system automatically updates security models and validates policies in real-time as IT environments evolve, maintaining both compliance verification and adaptability to agile changes
Data Source
AI summary
A system and method for managing implementation of policies in an information technologies system receives at least one policy function, at least one refinement template and at least one available policy function from the at least one memory, receives a policy input indicating a high-level policy for the IT system where the policy input is compliant with the at least one policy function and is received in a format that is not machine-enforceable at an enforcement entity of the IT system, based on the received policy input, automatically or semi-automatically generates a machine-enforceable rule and/or configuration by filling the at least one refinement template, where the machine-enforceable rule and/or configuration includes the at least one available policy function and being compliant with the received policy input, and distributes the machine-enforceable rule and/or configuration to the at least one memory of the IT system or another at least one memory to thereby enable implementation of the policies.


