Policy Interface Framework for Automated Service Exposure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing approaches to resource interoperability, such as the Parlay framework, do not effectively allow for automated control and management of resource exposure, independent service function composition, and validation of access conditions, limiting their adoption and efficiency.
Innovation Solution
A framework that intercepts requests for resource interface descriptions, determines associated policies, and transmits both resource interface descriptions and policy parameters to requesters, enabling efficient exposure and validation of resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized framework like Parlay is used for service discovery and management, then service enablers can be instantiated and protected through authentication, but the framework does not support generic web services, requires skilled developers with IIOP/CORBA knowledge, and limits automated control and management of resource exposure
Solution Approach 1:
The patent introduces a framework that acts as an intermediary between web services and requesters, automatically managing service exposure and policy enforcement. This framework mediates the interaction by intercepting requests, determining applicable policies, and coordinating service access without requiring developers to manually compose complex IIOP/CORBA interfaces, thus reducing skill requirements while maintaining security
Solution Approach 2:
The patent creates a universal framework that can work with generic web services rather than being limited to specific service types. The framework provides multi-functional capabilities including service discovery, policy determination, and automated management across different service enablers, making the system adaptable to various web service scenarios without requiring service-specific customizations
2Reliability
If service interfaces are composed manually using IIOP or CORBA architectures, then services can be instantiated and protected, but the process is not simple and does not allow automated control and management of resource exposure
Solution Approach 1:
The patent enables services to self-register and self-describe their interfaces and policies within the framework. Service enablers automatically publish their capabilities and associated policies to the framework, which then manages their exposure and access control. This self-service approach eliminates the need for manual interface composition by skilled developers, significantly simplifying the process while maintaining robust service protection
Solution Approach 2:
The framework performs preliminary actions by pre-determining and storing service policies and interface descriptions before actual service access occurs. Services register their interfaces and policies in advance with the framework, which prepares the service exposure configuration ahead of time. This preliminary setup automates the control and management of resource exposure, removing the need for complex manual interface composition at runtime
3Adaptability or versatility
If existing approaches are used for service access, then resources can be made available, but requesters cannot determine and satisfy access conditions, and providers cannot validate that conditions are met
Solution Approach 1:
The patent implements a feedback mechanism where the framework continuously monitors and validates whether requesters satisfy the determined policies and access conditions. The framework receives feedback from services about their requirements and provides feedback to requesters about what conditions must be met. This automated feedback loop enables both requesters to understand and satisfy conditions, and providers to validate that conditions are met, enhancing the extent of automation in access control
Data Source
AI summary
Methods, systems, and machine-readable mediums are disclosed for providing resource interface descriptions with policy parameters. In one embodiment, a method comprises intercepting, at a framework, a request for a resource interface description. The resource interface description is obtained at the framework and at least one policy associated with the resource is determined. For each of the determined policies, one or more policy parameters associated with the policy are determined.


