Model-Driven Security System Automating Policy Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security technologies struggle to effectively manage complex security policies in dynamic and interconnected IT environments, such as those found in IoT, M2M, and Cloud computing systems. Existing approaches like blacklisting and whitelisting are either unmanageable or inefficient in enforcing adequate security measures.

Innovation Solution

A model-driven security (MDS) system that uses a top-down approach to automate the translation of high-level security and compliance requirements into technical authorization policy rules, combined with model-driven security accreditation (MDSA) for verification and compliance. This system employs attributes, calculations, and mapping services to generate fine-grained, contextual security rules and supports advanced access control mechanisms like proximity-based access control (PBAC).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual policy implementation approaches are used, then security policies can be implemented, but they become unmanageable as IT environments become increasingly complex and dynamic

Engineering Contradiction:
Improvesecurity policy effectivenessVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automated self-service through model-driven security technologies that automatically translate high-level security policies into machine-enforceable rules. The MDS platform autonomously generates, validates, and deploys security policies without requiring manual configuration, allowing the system to adapt dynamically to changing IT environments while maintaining policy effectiveness

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces model-driven security (MDS) as an intermediary layer between high-level security requirements and low-level technical implementations. This intermediary automatically translates business-level security policies into machine-enforceable rules, bridging the gap between security intent and technical execution while simplifying management of complex policies

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If blacklisting approaches are used to block unwanted contents and access, then security threats can be mitigated, but they cannot implement the required fine-grained and contextual security policies

Engineering Contradiction:
Improvesecurity threat mitigationVSAvoidsecurity policy granularity
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by implementing fine-grained security policies that can be applied to specific subjects, objects, and contexts. The MDS platform enables different security rules to be applied to different parts of the system based on local conditions, such as proximity-based access control for specific devices or contextual policies for specific data types, rather than applying blanket blacklisting rules

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If whitelisting approaches are used to allow only appropriate contents and access, then fine-grained security control can be achieved, but they become unmanageable using manual policy implementation approaches

Engineering Contradiction:
Improvesecurity policy granularityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The automated MDS system performs self-service by autonomously generating, validating, and deploying fine-grained security policies. The platform automatically translates high-level whitelisting requirements into detailed machine-enforceable rules, managing the complexity of fine-grained control without requiring manual intervention

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical policy implementation with automated model-driven security technologies. The MDS platform uses automated model transformations and policy generation algorithms to substitute human manual work with intelligent systems that can handle complex fine-grained policy management at scale

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If conventional accreditation methods are used, then security compliance can be verified, but they require too much manual effort and static system verification

Engineering Contradiction:
Improveaccreditation verificationVSAvoidaccreditation process duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements continuous accreditation verification through automated model-driven security accreditation (MDSA). Instead of periodic static verification, the MDS platform continuously validates security policies against accreditation requirements as systems evolve, maintaining compliance verification without interruption or manual rework

Inventive Principle:
Principle #20Continuity of useful action

5Reliability

If static system verification is used for accreditation, then compliance can be verified, but it cannot accommodate dynamically changing agile IT environments

Engineering Contradiction:
Improvecompliance verificationVSAvoidIT environment agility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic accreditation verification where the MDS platform continuously adapts security policies and compliance verification to changing system states. The system automatically updates security models and validates policies in real-time as IT environments evolve, maintaining both compliance verification and adaptability to agile changes

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12335313B2Automated and adaptive model-driven security system and method for operating the same
Publication Date: 2025.06.17 OBJECTSECURITY LLC
  • US12335313B2 patent drawing
  • US12335313B2 patent drawing
  • US12335313B2 patent drawing

AI summary

A system and method for managing implementation of policies in an information technologies system receives at least one policy function, at least one refinement template and at least one available policy function from the at least one memory, receives a policy input indicating a high-level policy for the IT system where the policy input is compliant with the at least one policy function and is received in a format that is not machine-enforceable at an enforcement entity of the IT system, based on the received policy input, automatically or semi-automatically generates a machine-enforceable rule and/or configuration by filling the at least one refinement template, where the machine-enforceable rule and/or configuration includes the at least one available policy function and being compliant with the received policy input, and distributes the machine-enforceable rule and/or configuration to the at least one memory of the IT system or another at least one memory to thereby enable implementation of the policies.