Policy Enforcement System for Virtual Organizations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems enforcing policies for virtual private organizations face inefficiencies in large-scale operations, inflexibility in managing changes in device numbers or structures, and inability to enforce high-level policies across multiple devices due to fixed classification methods and increased processing loads.
Innovation Solution
A policy enforcement system that distributes a policy description program to management entities, utilizing dynamic conversion and enforcement units to correlate access and operation requests across management entities, enabling flexible and scalable policy enforcement through normalization and caching, and allowing requests to be bridged across multiple management layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If the number of devices in each managing layer is increased, then the system can manage more resources, but the processing load on determination units increases and efficiency decreases
Solution Approach 1:
The patent divides the determination unit into multiple determination units, one for each managing layer. Each determination unit independently processes policies for its specific layer, distributing the processing load and preventing any single unit from becoming a bottleneck as the number of devices increases.
Solution Approach 2:
The patent introduces a new dimension of organization by classifying determination units according to managing layers rather than processing all devices uniformly. This layered classification allows parallel processing across different dimensions (layers), improving overall system efficiency.
2Device complexity
If policies are classified into fixed managing layers in advance, then the system structure is simplified, but the system cannot cope with changes in device numbers or structures
Solution Approach 1:
The patent makes the classification of determination units dynamic by allowing determination units to be added or removed based on actual needs. The system can adapt its structure in response to changes in device numbers or configurations without requiring complete redesign of the entire system.
Solution Approach 2:
The patent creates a universal framework where determination units can serve multiple purposes. Each determination unit handles policies for its assigned managing layer, but the framework allows flexible assignment and reassignment of determination units to accommodate various device types and configurations.
3Ease of manufacture
If the system uses fixed classification of policies into managing layers, then implementation is straightforward, but high-level policies cannot be enforced across multiple devices
Solution Approach 1:
The patent merges the functionality of multiple determination units through the introduction of a higher-level determination unit that can access and coordinate policies across managing layers. This allows high-level policies to be enforced by combining the capabilities of lower-level determination units while maintaining the simplicity of individual layer management.
Solution Approach 2:
The patent introduces an intermediary determination unit that acts as a mediator between high-level policy requirements and lower-level device implementations. This intermediary layer translates high-level policies into actionable instructions for specific managing layers without complicating the basic implementation of individual layers.
Data Source
AI summary
System formed of a group of management entities including an enforcement environment of a policy description program, and service, data, software and hardware, in which the enforcement environment of the policy description program correlates resources to be managed (group) with a management entity which is to enforce a policy and includes a dynamic conversion unit, an enforcement unit, a unit of an interface between the management entities and a unit of an interface to the resources to be managed (group).


