Secure Policy Governance Through Hierarchical Domain Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information governance systems require specialized knowledge to adapt policies to changing business needs, leading to complex and brittle repositories that are hard to maintain, and lack efficient mechanisms for ubiquitous policy deployment and enforcement.
Innovation Solution
A system and method for secure policies-based information governance that uses a graphical user interface to define and enforce policies across multiple applications, employing an extensible hierarchical domain model and Policy Enforcement Points (PEPs) for automatic policy invocation, allowing non-technical users to manage policies efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing information governance systems use traditional policy management approaches, then policies can be enforced, but the systems require specialized knowledge to adapt policies to changing business needs, leading to complex and brittle repositories that are hard to maintain
Solution Approach 1:
The system segments policy management into distinct components: policy templates define the structure, domain models represent business concepts, and policy rules are generated automatically. This segmentation allows non-technical users to work with familiar business concepts rather than complex policy syntax, reducing the complexity burden while maintaining adaptability.
Solution Approach 2:
The patent introduces an intermediary layer between business users and policy enforcement systems. Domain models act as intermediaries that translate business concepts into policy rules, while the system automatically generates machine-enforceable policies from these domain models. This intermediary eliminates the need for specialized knowledge while maintaining policy adaptability.
2Extent of automation
If existing systems lack efficient mechanisms for ubiquitous policy deployment, then policy enforcement is limited, but implementing comprehensive policy enforcement across multiple applications increases system complexity
Solution Approach 1:
The system implements a universal domain model framework that can be applied across multiple applications and contexts. The same domain models and policy templates used for one application can be reused elsewhere, enabling ubiquitous policy deployment without proportionally increasing complexity. The framework provides multi-functionality by serving different policy enforcement needs through a common structure.
Solution Approach 2:
The system enables automated policy deployment by changing parameters from manual configuration to automatic generation. Domain models are automatically transformed into policy rules, and policies are dynamically enforced based on changing business requirements. This parameter change from static to dynamic configuration reduces the complexity burden of comprehensive enforcement.
3Productivity
If manual policy management is used, then policies can be maintained, but rapid response to changing business requirements is hindered
Solution Approach 1:
The system performs preliminary action by pre-defining domain models and policy templates that capture business concepts and rules. When business requirements change, the system automatically updates policies based on these pre-established structures, enabling rapid iteration without manual reconfiguration. This preliminary structuring reduces both maintenance time and speeds up policy adaptation.
Solution Approach 2:
The system implements feedback mechanisms where domain models automatically reflect changing business requirements and trigger corresponding policy updates. The automated generation and enforcement of policies based on domain models creates a feedback loop that continuously adapts to business changes, improving productivity while reducing the time loss associated with manual policy management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosure is directed to systems and methods for secure policies-based information governance. In various embodiments exemplary methods include displaying a Graphical User Interface (GUI), the graphical user interface receiving a business rule input from a business user; receiving a policy from a policy engine based on the business rule input, the policy engine generating a policy hierarchy; and defining a plurality of domain objects and a plurality of domain object representations in the Graphical User Interface (GUI) based on the policy and the policy hierarchy. Furthermore, exemplary methods include defining an extensible hierarchical domain model definition using the policy hierarchy, the extensible hierarchical domain model definition being modified using the plurality of domain object representations in the Graphical User Interface (GUI); and defining a Policy Enforcement Point (PEP) in an application based on the extensible hierarchical domain model definition.