Hierarchical Policy Management Architecture for Extensible Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current policy management systems lack a generic method applicable across various applications and are not extensible to situations with multiple policy generation points and hierarchies, often relying on specific policy formats and conveyance protocols.

Innovation Solution

A policy managed system with a network-connected policy executive element (PEE) and policy managed element (PME) that includes an element configuration manager (ECM), policy decision manager (PDP), policy enforcement manager (PEP), and policy generation point (PGP), allowing for hierarchical policy management independent of specific policy formats and protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If specific policy formats and conveyance protocols are used for policy management, then implementation is simplified for particular applications, but the system becomes non-extensible to multiple policy generation points and hierarchies

Engineering Contradiction:
Improveimplementation simplicityVSAvoidextensibility to multiple policy generation points
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal policy management architecture where policy elements can function both as consumers and generators of policies. The policy managed element and policy executive element can each act as policy sinks, policy sources, or both simultaneously, enabling the system to adapt to various application scenarios without requiring application-specific implementations. This multi-functionality resolves the contradiction by providing a generic framework that works across diverse policy management needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the policy management system into distinct functional elements: policy managed elements (PME), policy executive elements (PEE), element configuration managers (ECM), policy decision points (PDP), and policy enforcement points (PEP). This segmentation allows each component to have specialized responsibilities while maintaining clear interfaces, enabling the system to scale from simple single-point policy management to complex multi-gener ator hierarchies without increasing implementation complexity proportionally.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a generic policy management method is implemented across diverse applications, then adaptability and extensibility improve, but the system complexity increases due to hierarchical structures and multiple policy generation points

Engineering Contradiction:
Improveapplicability across diverse applicationsVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy management where elements can change their role from policy consumer to policy generator based on operational needs. The system dynamically adjusts policy hierarchies and relationships without requiring structural reconfiguration, allowing a single generic implementation to serve multiple application scenarios with varying complexity levels.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces intermediary components such as the element configuration manager and policy decision point that mediate between policy generation and enforcement. These intermediaries abstract the complexity of hierarchical policy management, providing standardized interfaces that simplify integration across diverse applications while handling the intricacies of multi-level policy relationships internally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If policy managed elements are allowed to generate policies for other devices, then the system becomes more flexible and extensible, but control and consistency management becomes more difficult

Engineering Contradiction:
Improvepolicy generation capabilityVSAvoidpolicy consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where policy decisions and enforcement outcomes are reported back to policy decision points and generation points. This feedback loop enables automatic consistency checking and conflict resolution, ensuring that policies generated by distributed elements maintain system-wide coherence without requiring centralized control of every policy decision.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent requires preliminary policy validation and configuration management before policies are deployed to policy managed elements. The element configuration manager performs preliminary checks and preparations, ensuring that generated policies conform to system requirements before they are activated, thereby maintaining consistency while enabling distributed policy generation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10057356B2Policy managed system and method thereof
Publication Date: 2018.08.21 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US10057356B2 patent drawing
  • US10057356B2 patent drawing
  • US10057356B2 patent drawing

AI summary

A method and a system of managing a policy managed system that includes a policy managed element. The method restricts the policy managed element so that internal configurations and actions of the policy managed element do not violate any policy rules generated external to the policy managed element. The method also prevents the policy managed element from generating policy that exit the policy managed element. The method, at a policy executive element (PEE) located remote from the policy managed element, restricts internal configurations and actions of the PEE so that the PEE does not violate any policy rules generated external to the PEE. The PEE includes a policy generation point (PGP) that the method allows to generate new policy rules that do not violate any existing policy and provides the new policy rules to the policy managed element.