PaaS Automation Control via Delegated Privilege Commands
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in automating software deployment across segregated entities for security and auditing purposes in cloud computing, particularly with Platform as a Service (PaaS), due to complexities in managing responsibilities and security controls, which existing solutions fail to address effectively.
Innovation Solution
A system and method for automated software component rollout in an enterprise-wide IT platform using delegated privilege commands (DPCs) and a privilege activities management server to verify user privileges, enabling secure and controlled deployment from development to production without human intervention, while maintaining segregation of duties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple entities manage hosts, databases and applications separately for Segregation of Duty purposes, then security control and auditing are improved, but automation complexity and coordination difficulty increase
Solution Approach 1:
The system segments automation responsibilities into distinct roles: automation developers create scripts, automation administrators approve and manage them, and the system executes them. This segmentation maintains security controls while enabling automation through the DPC mechanism that enforces role-based access and approval workflows.
Solution Approach 2:
The Delegated Privileged Command (DPC) mechanism acts as an intermediary layer between different entities. It provides a standardized interface for privilege delegation, command approval, and execution tracking, reducing coordination complexity while maintaining security boundaries between hosts, databases, and applications managers.
2Reliability
If manual intervention is used in deployment processes, then security control and auditing are improved, but deployment speed and productivity decrease
Solution Approach 1:
Automation scripts are pre-approved by automation administrators through the DPC mechanism before deployment. This preliminary approval process establishes security controls in advance, allowing subsequent automated executions to proceed without manual intervention, thus maintaining security while improving deployment speed.
Solution Approach 2:
The system enables self-service automation where approved scripts automatically execute deployment tasks without requiring manual intervention for each operation. The DPC mechanism handles privilege management and execution control automatically, maintaining security controls while eliminating manual bottlenecks in the deployment process.
3Productivity
If full automation is implemented without privilege verification, then deployment speed is improved, but security risks and unauthorized access increase
Solution Approach 1:
The DPC mechanism implements feedback through automated privilege verification at each deployment step. The system checks whether the executing entity has appropriate delegated privileges before allowing automation scripts to access hosts, databases, or applications, providing continuous security validation without manual intervention.
Solution Approach 2:
The system applies preliminary anti-action by pre-defining and enforcing privilege policies that restrict automation scripts to only authorized operations. The DPC mechanism prevents unauthorized access by verifying privileges before execution, countering potential security risks before they can manifest during automated deployment.
Data Source
AI summary
Platform as a service (PaaS) automation control systems and methods are provided for automating the deployment of software solutions or middleware into an enterprise or cloud-computing system. The system comprises a distributed network of virtual and physical computing devices arranged in layers including a platform operation layer, development layer, platform administration layer, operating system administration layer and security administration layer. A development automation server and production automation server are configured to selectively advance an automation project from development to production rollout as a function of delegated privilege command (DPC). Using the DPCs, the PaaS automation control system enforces a controlled use of configuration commands needed to implement an automated deployment while limiting access to the infrastructure layer. The PaaS automation control system is further configured to provide an automated and controlled mechanism for development, quality assurance and production rollout.


