PaaS Automation Control via Delegated Privilege Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in automating software deployment across segregated entities for security and auditing purposes in cloud computing, particularly with Platform as a Service (PaaS), due to complexities in managing responsibilities and security controls, which existing solutions fail to address effectively.

Innovation Solution

A system and method for automated software component rollout in an enterprise-wide IT platform using delegated privilege commands (DPCs) and a privilege activities management server to verify user privileges, enabling secure and controlled deployment from development to production without human intervention, while maintaining segregation of duties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple entities manage hosts, databases and applications separately for Segregation of Duty purposes, then security control and auditing are improved, but automation complexity and coordination difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidautomation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments automation responsibilities into distinct roles: automation developers create scripts, automation administrators approve and manage them, and the system executes them. This segmentation maintains security controls while enabling automation through the DPC mechanism that enforces role-based access and approval workflows.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Delegated Privileged Command (DPC) mechanism acts as an intermediary layer between different entities. It provides a standardized interface for privilege delegation, command approval, and execution tracking, reducing coordination complexity while maintaining security boundaries between hosts, databases, and applications managers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual intervention is used in deployment processes, then security control and auditing are improved, but deployment speed and productivity decrease

Engineering Contradiction:
Improvesecurity controlVSAvoiddeployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Automation scripts are pre-approved by automation administrators through the DPC mechanism before deployment. This preliminary approval process establishes security controls in advance, allowing subsequent automated executions to proceed without manual intervention, thus maintaining security while improving deployment speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service automation where approved scripts automatically execute deployment tasks without requiring manual intervention for each operation. The DPC mechanism handles privilege management and execution control automatically, maintaining security controls while eliminating manual bottlenecks in the deployment process.

Inventive Principle:
Principle #25Self-service

3Productivity

If full automation is implemented without privilege verification, then deployment speed is improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The DPC mechanism implements feedback through automated privilege verification at each deployment step. The system checks whether the executing entity has appropriate delegated privileges before allowing automation scripts to access hosts, databases, or applications, providing continuous security validation without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies preliminary anti-action by pre-defining and enforcing privilege policies that restrict automation scripts to only authorized operations. The DPC mechanism prevents unauthorized access by verifying privileges before execution, countering potential security risks before they can manifest during automated deployment.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11194559B2Method and apparatus for platform as a service (PaaS) automation control
Publication Date: 2021.12.07 SAUDI ARABIAN OIL CO
  • US11194559B2 patent drawing
  • US11194559B2 patent drawing
  • US11194559B2 patent drawing

AI summary

Platform as a service (PaaS) automation control systems and methods are provided for automating the deployment of software solutions or middleware into an enterprise or cloud-computing system. The system comprises a distributed network of virtual and physical computing devices arranged in layers including a platform operation layer, development layer, platform administration layer, operating system administration layer and security administration layer. A development automation server and production automation server are configured to selectively advance an automation project from development to production rollout as a function of delegated privilege command (DPC). Using the DPCs, the PaaS automation control system enforces a controlled use of configuration commands needed to implement an automated deployment while limiting access to the infrastructure layer. The PaaS automation control system is further configured to provide an automated and controlled mechanism for development, quality assurance and production rollout.