Policy Enforcement Mechanism Self-Integrity Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective methods to ensure that policies enforcing system integrity and health validation are maintained, as software and hardware can circumvent DRM, archiving policies, software license management, and security settings, leading to compromised device integrity and security.

Innovation Solution

Implementing a policy enforcement mechanism that monitors and self-verifies its integrity, intercepts service requests, and dynamically enforces policies by checking for compliance with usage policies, reporting breaches, and denying service if integrity is compromised or policies are breached.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy enforcement programs are installed to restrict device behavior and ensure compliance, then system security and policy compliance are improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The policy enforcement mechanism performs self-integrity validation, where the policy enforcer program verifies its own integrity and the integrity of related system components. This self-service approach eliminates the need for external monitoring systems to continuously check program integrity, reducing system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the policy enforcer reports its integrity status and compliance information to external systems. This feedback loop allows the system to maintain security policies while reducing the burden of continuous external monitoring, as the enrolled device autonomously provides compliance information.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If monitoring programs are installed to detect and report unauthorized actions, then system integrity detection is improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improveintegrity detection accuracyVSAvoiduser convenience
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The policy enforcer program autonomously performs integrity validation of itself and related system components without requiring user intervention. The program self-validates its integrity, checks for tampering, and reports status automatically, maintaining high detection accuracy while preserving user convenience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary integrity validation during device enrollment and before policy enforcement begins. By pre-configuring the policy enforcer and validating its integrity in advance, the system establishes accurate monitoring capabilities without requiring ongoing user action or intervention.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive policy enforcement is implemented to prevent circumvention, then system security is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidenforcement mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The policy enforcer program autonomously validates its own integrity and monitors for circumvention attempts without requiring external validation systems. This self-service approach ensures comprehensive policy enforcement while minimizing the complexity of the overall enforcement mechanism.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system focuses integrity validation on critical components - the policy enforcer program itself and essential system components - rather than attempting to validate every aspect of the device. This targeted approach maintains strong policy compliance while avoiding excessive complexity.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If continuous integrity validation is performed to detect tampering, then reliability is improved, but use of energy and processing resources increases

Engineering Contradiction:
Improveintegrity validationVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The policy enforcer performs integrity validation at periodic intervals and at key system events rather than continuously monitoring every system state. This periodic validation approach maintains reliable integrity detection while significantly reducing energy consumption and processing resource usage compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9495521B2System self integrity and health validation for policy enforcement
Publication Date: 2016.11.15 ORACLE INT CORP
  • US9495521B2 patent drawing
  • US9495521B2 patent drawing
  • US9495521B2 patent drawing

AI summary

Embodiments of the invention provide methods and systems for enforcing system self integrity validation policies. The method includes accessing, by a policy enforcer, a plurality of policies configured to enforce system integrity, monitoring system performance to determine actions executed by the system, and based on at least one of the plurality of policies, comparing the system performance with system performance required by the at least one or the plurality of policies. The method further includes, based on the comparison, determining that the system has performed in a manner contrary to the requirements of the at least one policy, and in response, prohibiting access of the system to services provided by a service provider.