Policy Governor Dynamic Security Policy Adjustment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing systems face challenges in securely activating functionality with flexible, yet secure, low overhead and cost, due to inefficiencies in security asset usage and static security policies.
Innovation Solution
A data processing system with a security subsystem that includes a policy governor to dynamically adjust security policies during runtime, ensuring coherence with system state and security status, and allowing for fail-operational modes and flexible key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static security policy is used, then security integrity is maintained, but system flexibility and adaptability to runtime conditions are reduced
Solution Approach 1:
The patent implements a dynamic security policy system where the Policy Governor can modify security policies at runtime based on system state changes, security events, or administrator commands. This allows the security policy to transition from static to dynamic, enabling the system to adapt to changing conditions while maintaining security integrity through controlled policy adjustments.
2Loss of energy
If security assets are used only during system initialization, then security overhead is reduced, but security functionality is unavailable during runtime operations
Solution Approach 1:
The patent performs preliminary actions by establishing a secure boot process and initializing security assets during system startup. The Policy Governor is pre-configured with initial security policies before runtime operations begin, allowing security functionality to be ready for immediate use without requiring continuous heavy computational overhead during normal operation.
Solution Approach 2:
The system enables self-service by allowing the Policy Governor to automatically adjust security policies based on detected security events or system state changes without requiring manual intervention. This automated approach maintains security functionality during runtime while minimizing the need for continuous manual security management.
3Reliability
If a hierarchical trust model with sequential initialization is used, then security authenticity is ensured, but system complexity and initialization time are increased
Solution Approach 1:
The patent segments the security initialization process into distinct phases: secure boot phase for verifying authenticity, policy establishment phase for configuring security policies, and runtime operation phase for executing with adjusted policies. This segmentation allows the hierarchical trust model to maintain security authenticity while reducing overall initialization complexity by separating critical security operations from general system initialization.
4Device complexity
If security policies are fixed until system reboot, then implementation simplicity is maintained, but response time to security events is delayed
Solution Approach 1:
The patent introduces dynamics to the security policy system by enabling the Policy Governor to modify policies in response to security events during runtime. When a security event is detected, the system can dynamically adjust the relevant security policy without requiring a complete system reboot, thereby reducing response time while maintaining relatively simple implementation through automated policy enforcement mechanisms.
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
A system, method, and apparatus are provided for securely controlling operations of a data processing system in which security subsystem is activated to provide security services by responding to a security service request, evaluating the request against an adjustable set of system security policies to determine if the security service request is granted access to a protected asset, by generating a response to the security service request using the protected asset if the security service request is granted access to the protected asset, by adjusting a security access policy for the protected asset in the adjustable set of system security policies, and by sending the response from the security subsystem to the external application subsystem.