Hierarchical Policy Management Architecture for Extensible Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current policy management systems lack a generic method applicable across various applications and are not extensible to situations with multiple policy generation points and hierarchies, often relying on specific policy formats and conveyance protocols.
Innovation Solution
A policy managed system with a network-connected policy executive element (PEE) and policy managed element (PME) that includes an element configuration manager (ECM), policy decision manager (PDP), policy enforcement manager (PEP), and policy generation point (PGP), allowing for hierarchical policy management independent of specific policy formats and protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If specific policy formats and conveyance protocols are used for policy management, then implementation is simplified for particular applications, but the system becomes non-extensible to multiple policy generation points and hierarchies
Solution Approach 1:
The patent implements a universal policy management architecture where policy elements can function both as consumers and generators of policies. The policy managed element and policy executive element can each act as policy sinks, policy sources, or both simultaneously, enabling the system to adapt to various application scenarios without requiring application-specific implementations. This multi-functionality resolves the contradiction by providing a generic framework that works across diverse policy management needs.
Solution Approach 2:
The patent segments the policy management system into distinct functional elements: policy managed elements (PME), policy executive elements (PEE), element configuration managers (ECM), policy decision points (PDP), and policy enforcement points (PEP). This segmentation allows each component to have specialized responsibilities while maintaining clear interfaces, enabling the system to scale from simple single-point policy management to complex multi-gener ator hierarchies without increasing implementation complexity proportionally.
2Adaptability or versatility
If a generic policy management method is implemented across diverse applications, then adaptability and extensibility improve, but the system complexity increases due to hierarchical structures and multiple policy generation points
Solution Approach 1:
The patent implements dynamic policy management where elements can change their role from policy consumer to policy generator based on operational needs. The system dynamically adjusts policy hierarchies and relationships without requiring structural reconfiguration, allowing a single generic implementation to serve multiple application scenarios with varying complexity levels.
Solution Approach 2:
The patent introduces intermediary components such as the element configuration manager and policy decision point that mediate between policy generation and enforcement. These intermediaries abstract the complexity of hierarchical policy management, providing standardized interfaces that simplify integration across diverse applications while handling the intricacies of multi-level policy relationships internally.
3Adaptability or versatility
If policy managed elements are allowed to generate policies for other devices, then the system becomes more flexible and extensible, but control and consistency management becomes more difficult
Solution Approach 1:
The patent implements feedback mechanisms where policy decisions and enforcement outcomes are reported back to policy decision points and generation points. This feedback loop enables automatic consistency checking and conflict resolution, ensuring that policies generated by distributed elements maintain system-wide coherence without requiring centralized control of every policy decision.
Solution Approach 2:
The patent requires preliminary policy validation and configuration management before policies are deployed to policy managed elements. The element configuration manager performs preliminary checks and preparations, ensuring that generated policies conform to system requirements before they are activated, thereby maintaining consistency while enabling distributed policy generation.
Data Source
AI summary
A method and a system of managing a policy managed system that includes a policy managed element. The method restricts the policy managed element so that internal configurations and actions of the policy managed element do not violate any policy rules generated external to the policy managed element. The method also prevents the policy managed element from generating policy that exit the policy managed element. The method, at a policy executive element (PEE) located remote from the policy managed element, restricts internal configurations and actions of the PEE so that the PEE does not violate any policy rules generated external to the PEE. The PEE includes a policy generation point (PGP) that the method allows to generate new policy rules that do not violate any existing policy and provides the new policy rules to the policy managed element.


