PaaS Compliance Interception for Third-Party App Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations using platform-as-a-service platforms face challenges in maintaining control over security and compliance policies, as outsourcing computing platforms reduces their ability to apply custom security measures to third-party application packages.

Innovation Solution

Implementing a system that intercepts third-party application packages, extracts metadata, and applies compliance policies to determine whether to allow installation, using modules for identification, interception, extraction, and policy application to ensure compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations outsource computing platforms to platform-as-a-service providers, then cost and time savings are achieved, but control over security and compliance policies is reduced

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a compliance policy engine as an intermediary component between the platform-as-a-service provider and the organization's applications. This engine intercepts application deployment requests, evaluates them against organization-defined compliance policies, and enforces security controls without requiring direct platform modification, thus maintaining both deployment efficiency and security control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The compliance control system is segmented into independent modular components including policy definition modules, policy evaluation modules, and enforcement modules. This segmentation allows the organization to implement and customize security policies independently without affecting the underlying platform operations or requiring platform provider involvement

Inventive Principle:
Principle #1Segmentation

2Device complexity

If platform-as-a-service providers manage application installations, then platform maintenance is simplified, but ability to apply custom compliance policies is lost

Engineering Contradiction:
Improveplatform management complexityVSAvoidpolicy customization
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary compliance policy evaluation and enforcement actions before applications are deployed to the platform. By pre-assessing application packages against compliance policies and making authorization decisions in advance, the system ensures policy adherence without adding complexity to ongoing platform management operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The compliance policy engine serves as an intermediary layer that sits between application developers and the platform-as-a-service infrastructure. It provides policy customization capabilities through configurable policy rules and evaluation criteria while maintaining simplified platform management by handling compliance enforcement transparently without requiring platform provider intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8973090B1Systems and methods for protecting platform-as-a-service platforms
Publication Date: 2015.03.03 CA TECH INC
  • US8973090B1 patent drawing
  • US8973090B1 patent drawing
  • US8973090B1 patent drawing

AI summary

A computer-implemented method for protecting platform-as-a-service platforms may include 1) identifying a platform-as-a-service platform that is configured to allow installations of third-party application packages, 2) intercepting a third-party application package in transit to the platform-as-a-service platform for installation, 3) extracting metadata from the third-party application package, and 4) applying a compliance policy to the third-party application package to determine whether to allow an installation of the third-party application package on the platform-as-a-service platform based on the metadata. Various other methods, systems, and computer-readable media are also disclosed.