Secure Complex Event Processing via Hierarchical Disclosure Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing complex event processing technologies in heterogeneous environments fail to ensure secure data disclosure, as they do not account for individual security and confidentiality concerns of autonomous sub-systems, leading to limitations in analyzing and recognizing patterns across distributed and heterogeneous systems.

Innovation Solution

A system for secure complex event processing that includes an input adaptor for receiving events with disclosure permissions, a CEP engine for processing events, a security enforcer for removing non-compliant data, and an output adaptor for sending filtered events, maintaining event-specific, source-specific, target-specific, and global disclosure permissions to ensure secure data aggregation and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual sub-systems maintain control over their data disclosure to ensure security and confidentiality, then security is improved, but the ability to perform meaningful complex event processing analysis is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddata disclosure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments data disclosure permissions into multiple hierarchical levels: global permissions applying to all data, source-specific permissions for individual sub-systems, and event-specific permissions for individual events. This segmentation allows each level to control disclosure appropriately, enabling CEP engines to access necessary data while maintaining security constraints.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security enforcer as an intermediary component between event sources and CEP engines. This mediator automatically manages disclosure permissions, determining what data can be shared without requiring manual intervention from sub-system operators, thus enabling seamless secure CEP processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized database security mechanisms are applied to distributed heterogeneous sub-systems, then access control is improved, but adaptability to different systems is worsened

Engineering Contradiction:
Improveaccess controlVSAvoidheterogeneous system compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal permission model that can be applied across heterogeneous sub-systems regardless of their specific technologies. The multi-level permission structure (global, source-specific, event-specific) provides a unified approach that adapts to different systems while maintaining consistent security and CEP processing capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2469797B1System and method for secure complex event processing in heterogeneous environments
Publication Date: 2019.01.30 SOFTWARE AG
  • EP2469797B1 patent drawingFigure 1

AI summary

The present invention concerns a system (1) for secure complex event processing (CEP), wherein the system (1) comprises: a. an input adaptor (10), adapted for receiving at least one input event from at least one external source system (2), wherein the at least one input event comprises at least one event-specific disclosure permission concerning data of the input event; b. a CEP engine (20), adapted for processing the at least one input event and for producing at least one corresponding complex output event; c. a security enforcer (35), adapted for removing data from the at least one output event that is not in accordance with the at least one event-specific disclosure permission defined in the corresponding at least one input event; and d. an output adaptor (30), adapted for sending the at least one output event to at least one external target system (3).