Policy Decision Point Namespace Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deployment of attribute-based access control (ABAC) policies across multiple applications in a company leads to significant overhead costs and resource consumption in IT administration and management, as well as potential instability due to the need for separate deployments to isolate applications and prevent malfunctions from affecting each other.
Innovation Solution
A policy decision point (PDP) that stores multiple distinct policy packages, each associated with a unique endpoint address, allowing a single PDP to handle access requests from multiple applications without interference, thereby reducing the burden on IT resources and hardware capacity, and enabling efficient isolation of policy packages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate deployments are used to isolate applications and prevent malfunctions from affecting each other, then reliability is improved, but device complexity and IT administration overhead increase
Solution Approach 1:
The patent segments the policy management system by introducing namespace identifiers that logically separate policy packages into distinct namespaces. Each namespace acts as an isolated container for policies, attributes, and rules, preventing cross-contamination between applications while sharing the same physical infrastructure. This logical segmentation achieves application isolation without requiring separate physical deployments.
Solution Approach 2:
The patent makes the single PDP universal by enabling it to handle multiple namespaces and policy packages simultaneously. The PDP is designed to process access requests from different applications within the same system, providing multi-functionality that eliminates the need for separate deployments while maintaining reliability through namespace-based isolation.
2Reliability
If multiple separate deployments are used to manage ABAC policies across applications, then application isolation is improved, but IT administration overhead and resource consumption increase
Solution Approach 1:
The patent merges multiple application policy management into a single PDP deployment by introducing namespace identifiers. Multiple policy packages from different applications are combined within the same PDP system, each tagged with its namespace identifier. This consolidation reduces IT resource consumption while maintaining application isolation through the namespace mechanism.
Solution Approach 2:
The PDP is designed as a universal system that can simultaneously manage policies for multiple applications within different namespaces. This multi-functional capability allows a single deployment to serve multiple applications, reducing the overall IT infrastructure requirements and resource consumption compared to separate deployments.
3Device complexity
If a single PDP is used to handle access requests from multiple applications, then device complexity is reduced, but policy evaluation accuracy may be compromised due to potential interference
Solution Approach 1:
The patent applies local quality by associating each policy package with a specific namespace identifier. When evaluating access requests, the PDP uses the namespace identifier to selectively apply only the relevant policy package, ensuring that policies from different applications do not interfere with each other. This localized policy application maintains evaluation accuracy while using a single PDP.
Solution Approach 2:
The namespace identifier acts as an intermediary that mediates between multiple policy packages and the PDP evaluation engine. It ensures that the correct policy package is selected and applied for each access request, preventing cross-contamination and maintaining policy evaluation accuracy in a multi-application environment.
Data Source
AI summary
A policy decision point for interacting with a computer system including a plurality of resources, to which subjects' access is controlled by corresponding policy enforcement points. The PDP includes: a memory storing at least two policy packages, each controlling access rights to resources, and a connection table associating each policy package with an end point address; a network interface operable to communicate with the PEPs, wherein the network interface obtains access requests from a PEP and returns access decisions to the PEP, each access request including an end point address for directing the access request to the PDP; and a processor operable to: analyze an access request and determine, based on the end point address receiving the access request, an associated policy package; and evaluate the access request against the policy package thus determined.


