Automated Security Check Generation from Annotated Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The disconnection between architectural design and implementation in software and security engineering makes it difficult to trace changes in system operations back to their architectural rationale, leading to potential security risks and inefficiencies in assessing the impact of modifications on system security.

Innovation Solution

An apparatus that annotates architectural source models with security requirement and countermeasure information, generating security checks based on these annotations to ensure compliance and detect potential security breaches, utilizing a model editor, code generation engine, and runtime engine to automate the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If security requirements are translated into countermeasures during development or deployment, then the forward link from architecture to implementation is established, but the reverse link from countermeasures to security requirements becomes difficult to maintain and trace

Engineering Contradiction:
Improveloss of architectural rationaleVSAvoidcomplexity of maintaining reverse link
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by annotating architectural elements with security requirement information and countermeasure information during the development phase. This advance documentation creates traceability links before the disconnection problem occurs, allowing automatic reconstruction of the reverse link from countermeasures to security requirements without manual intervention later.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by creating bidirectional traceability between security requirements and countermeasures. The system automatically generates reports that show which countermeasures satisfy which security requirements, providing continuous feedback about the state of security implementation and enabling assessment of impact when modifications are made.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual methods are used to trace links from countermeasures to security requirements, then traceability can be established, but the process becomes time-consuming and error-prone

Engineering Contradiction:
Improveaccuracy of traceabilityVSAvoidtime to establish traceability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical methods with automated computational methods. The system uses software to automatically annotate architectural elements, generate security checks, and create traceability reports, eliminating manual effort and reducing errors while maintaining high accuracy in establishing and maintaining the reverse link.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If the operating context of a system changes, then the system can adapt to new conditions, but it becomes difficult to trace changes back to architectural rationale and assess security impact

Engineering Contradiction:
Improveadaptability to context changesVSAvoiddifficulty of assessing security impact
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses feedback mechanisms to automatically assess security impact when system changes occur. The traceability links enable the system to automatically determine which security requirements are affected by context changes and which countermeasures need to be reviewed, making the impact assessment process systematic and efficient.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary layer of annotations that connect architectural elements to security requirements and countermeasures. This intermediary structure serves as a bridge that enables automatic tracing and impact assessment when changes occur, without requiring direct manual analysis of the complex relationships between architecture, security requirements, and countermeasures.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If security checks are manually created and maintained, then security verification can be performed, but the process lacks automation and efficiency

Engineering Contradiction:
Improveefficiency of security verificationVSAvoidlevel of automation in security checks
Core Design Contradiction:
ProductivityVSExtent of automation

Solution Approach 1:

The patent applies self-service by enabling the system to automatically generate and maintain security checks based on the annotated architectural model. The system autonomously creates security verification activities, associates them with appropriate countermeasures, and updates them when the architecture changes, eliminating the need for manual creation and maintenance of security checks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses preliminary action by generating security checks automatically during the development or deployment phase when the architectural model is available. This advance generation ensures that security verification is prepared in advance rather than created manually later, significantly improving productivity and automation of the security verification process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8955115B2Automatic generation of security checks
Publication Date: 2015.02.10 SAP SE
  • US8955115B2 patent drawing
  • US8955115B2 patent drawing
  • US8955115B2 patent drawing

AI summary

The embodiments encompass an apparatus for generating security checks including a model editor configured to annotate at least one element in an architectural source model with security requirement information and countermeasure information. The security requirement information identifies the at least one element and provides a textual description of a corresponding security requirement, and the countermeasure information identifies the at least one element and indicates a countermeasure type to the corresponding security requirement. The apparatus also includes a code generation engine configured to generate a security check for the countermeasure information based on the countermeasure type.