Runtime Policy Enforcement via Metadata Annotation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud and mobile computing, it is challenging to enforce application rules and regulations at runtime, especially in highly elastic dynamic infrastructures where data flows across international boundaries, due to the unknown host environment or geographic location of executing code and data.
Innovation Solution
Annotating computer code and data with metadata defining runtime policies, dynamically determining execution parameters such as geographic location, and enforcing these policies at runtime to ensure compliance with specified conditions, either allowing or preventing application execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If application code is executed in highly elastic dynamic infrastructures across international boundaries, then computing flexibility and resource utilization are improved, but enforcement of application rules and regulations at runtime becomes difficult
Solution Approach 1:
The patent applies preliminary action by annotating application code with metadata defining runtime policies before execution. This pre-prepared policy information is embedded in the code itself, enabling runtime enforcement without requiring advance knowledge of the execution environment or geographic location.
Solution Approach 2:
The patent introduces an intermediary mechanism - a runtime policy enforcement system that acts as a mediator between the application code and the execution environment. This intermediary dynamically determines execution parameters and enforces policies by either allowing or preventing code execution based on policy compliance, without requiring direct control over the underlying infrastructure.
2Reliability
If runtime policy enforcement is implemented in unknown host environments, then regulatory compliance is ensured, but system complexity increases
Solution Approach 1:
The patent extracts policy enforcement capabilities from the infrastructure layer and embeds them directly in the application code through metadata annotations. This separation allows policy enforcement to work independently of the host environment complexity, making the system adaptable to unknown or varying infrastructure without increasing overall system complexity.
Data Source
AI summary
Embodiments of the present invention provide approaches for enforcing runtime policies in a networked computing environment (e.g., a cloud computing environment). Specifically, in a typical embodiment, computer code and data of an application is annotated with metadata defining a set of runtime policies for executing the computer code and data. Once a request is received to run the application, a set of parameters (e.g., geographic location) corresponding to the execution of the computer code and data of the application is dynamically determined, and compared to the runtime policies. The runtime policies for executing the computer code and data are then enforced at runtime. This includes either running the application, or preventing the running of the application in the case that the set of parameters corresponding to the execution of the computer code and data of the application do not satisfy the runtime policies.


