Platform Verification Portal for Dynamic Compliance Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing platform verification tools face challenges in providing enterprise-level usability and scalability, requiring significant user training for configuration item authoring and lacking dynamic selection of configuration items at runtime, leading to inefficient and erroneous compliance verification scans across multiple servers.
Innovation Solution
A platform verification portal system that remotely initiates and dynamically selects configuration items based on server criteria, allowing for on-demand verification scans across multiple servers without user login, using a web server and database server to manage configuration items and rules, and automatically generating configuration items from spreadsheet data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If known graphical authoring tools are used to create configuration items, then verification capability is provided, but user training requirements increase significantly and ease of operation deteriorates
Solution Approach 1:
The patent introduces a portal server as an intermediary between users and the verification scanning engine. The portal server provides a simplified web-based interface that abstracts the complexity of configuration item creation and execution. Users interact with the portal server through standard web browsers, which handles the complex tasks of communicating with the verification scanning engine, thereby reducing training requirements while maintaining verification capability.
Solution Approach 2:
The patent creates a simplified copy or representation of the verification system through a web-based portal interface. Instead of requiring users to directly operate the complex verification scanning engine, the portal server provides a simplified web interface that replicates the essential functionality in an easier-to-use format, reducing the learning curve while preserving verification capabilities.
2Productivity
If configuration items are distributed across target servers in advance of scheduled verification scans, then verification execution is enabled, but adaptability deteriorates due to inability to dynamically select configuration items at runtime
Solution Approach 1:
The patent implements dynamic configuration item selection by allowing the portal server to determine which configuration items to execute at runtime based on current server states and verification requirements. Instead of static pre-distribution, the system dynamically selects and distributes only the relevant configuration items to target servers when verification scans are initiated, enabling adaptability to changing conditions while maintaining execution efficiency.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring the portal server with a repository of configuration items and their associated metadata. This allows the portal server to quickly evaluate and select appropriate configuration items at runtime without requiring real-time complex decision-making, thus maintaining both speed and adaptability.
3Reliability
If verification scans are executed on multiple target servers, then compliance verification is provided, but device complexity increases due to need for individual server login and manual execution
Solution Approach 1:
The patent merges the functionality of multiple server verifications into a single unified operation through the portal server. Instead of requiring separate manual executions on each target server, the portal server consolidates the verification process, allowing a single initiation command to trigger coordinated verification scans across multiple target servers, thereby reducing operational complexity while maintaining comprehensive compliance verification.
Solution Approach 2:
The portal server serves multiple functions simultaneously: it acts as a user interface, a configuration item repository, a distribution mechanism, and a coordination hub for multi-server verification. This multi-functional design eliminates the need for separate tools or manual procedures for each verification task, reducing overall system complexity while enabling comprehensive compliance verification across multiple servers.
4Productivity
If configuration items are distributed in advance to target servers, then verification execution is enabled, but loss of information increases due to distribution of non-applicable configuration items causing erroneous non-compliance event logs
Solution Approach 1:
The patent applies local quality by tailoring the configuration items distributed to each target server based on its specific characteristics, such as server type, installed software, and configuration. The portal server evaluates target server properties and selects only the configuration items that are applicable to each specific server, ensuring that each server receives a customized set of verification commands rather than a generic distribution, thereby preventing erroneous non-compliance logs while maintaining verification productivity.
Data Source
AI summary
Described are computer-based methods and apparatuses, including computer program products, for a platform verification portal. A plurality of configuration items are stored with each comprising a plurality of verification commands capable of being executed by a verification scanning engine executing a verification scan on a target server to compare a set of actual software or configuration settings of the software against a desired software stack. A plurality of configuration item rules is stored. Execution of one or more verification scanning engines across a selected set of target servers is remotely initiated. A request for configuration items is received from each of the target servers. For each of the target servers a set of configuration items applicable to the target server is dynamically selected. For each of the target servers, a list identifying the set of configuration items is transmitted to the target server for execution by the verification scanning engine.


