Centralized Security Policy Engine for Application Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing and managing security policies across multiple applications is a time-consuming, error-prone, and complex process, especially when numerous security policy options are involved, requiring substantial effort and advanced security expertise, and changes to policies often necessitate rewriting multiple applications.

Innovation Solution

An automated Security Policy as a Service (SPaaS) system that utilizes a security policy engine to retrieve and implement security models and specifications from centralized data stores, allowing for efficient and accurate implementation of security policies across multiple applications without manual intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are written directly into applications, then security policy implementation is achieved, but the process becomes time-consuming and error-prone

Engineering Contradiction:
Improvesecurity policy implementation accuracyVSAvoidtime to implement security policies
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts security policy logic from individual applications and consolidates it into a centralized security policy service. The security policy engine retrieves policies from a centralized repository and applies them uniformly across multiple applications, eliminating the need to manually write policies into each application and reducing errors.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized security policy service provides a universal mechanism that serves multiple applications simultaneously. A single security policy implementation can be reused across numerous applications, reducing the overall time and effort required for policy deployment while improving consistency and reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security policies are written directly into applications, then security policy implementation is achieved, but the process becomes complex especially with large number of security policy options

Engineering Contradiction:
Improvesecurity policy implementation accuracyVSAvoidcomplexity of security policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of security policy management from individual applications and centralizes it in a dedicated security policy engine. This engine handles the complexity of selecting, retrieving, and applying appropriate security policies from a centralized repository, simplifying the process for application developers while maintaining high reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security policy engine acts as an intermediary between the centralized policy repository and multiple applications. It manages the complexity of policy selection and application, shielding applications from the intricacies of security policy configuration while ensuring accurate and consistent policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security policies are written directly into applications, then security policy implementation is achieved, but changes to policies require rewriting multiple applications

Engineering Contradiction:
Improvesecurity policy update capabilityVSAvoidease of policy modification
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent extracts security policy definitions from application code and stores them in a centralized, externally accessible repository. This allows policies to be modified independently of applications, and changes are automatically retrieved by the security policy engine without requiring application rewriting, greatly improving ease of policy modification while maintaining adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security policy system is designed to be dynamic, allowing policies to be updated in the centralized repository and automatically picked up by the security policy engine and affected applications. This dynamic approach enables continuous adaptation to changing security requirements without disrupting application functionality or requiring rewrites.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If multiple applications need to support security policy changes, then security flexibility is improved, but the effort and expertise required increases substantially

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidcomplexity of policy management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The centralized security policy service provides a universal platform that serves multiple applications with a single policy management interface. This universal approach maintains security flexibility across diverse applications while reducing the overall complexity by consolidating management functions in one location rather than distributing complexity across multiple applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security policy engine serves as an intermediary that manages the complexity of supporting multiple applications with flexible security policies. It handles the intricacies of policy retrieval, interpretation, and application-specific enforcement, shielding users from the underlying complexity while maintaining high adaptability and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3696703B1Security policy as a service
Publication Date: 2024.04.03 SAP PORTALS ISRAEL
  • EP3696703B1 patent drawingFigure 1
  • EP3696703B1 patent drawingFigure 2
  • EP3696703B1 patent drawingFigure 3

AI summary

According to some embodiments, a security model data store may contain a plurality of potential security policies, each accessible by multiple external applications. A security specifications data store may contain a plurality of potential security specifications, each accessible by the multiple external applications. A security policy engine computer platform may receive from an external application an indication identifying a security policy package. The security policy engine may then retrieve, based on the received indication, one of the potential security models from the security policy data store. Similarly, the security policy engine may retrieve, based on the received indication, one of the potential security specifications from the security specifications data store. The security policy engine may then arrange for a security policy package to be implemented for the external application, the security policy packing being associated with the retrieved potential security model and the retrieved potential security specification.