Centralized Security Policy Server for Heterogeneous Architectures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous computer architecture environments, implementing security policies on a platform-by-platform basis is inefficient and introduces security risks due to the need for multiple management points and different management tools, which can lead to compromised security if one platform is breached.

Innovation Solution

A common security policy is managed from a single management point, using a policy server to distribute and enforce access controls across multiple hardware platforms and virtual resources through security zones, reducing the number of access points and minimizing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security policies are implemented on a platform-by-platform basis in heterogeneous computer architecture environments, then each platform can have customized security management, but the system requires multiple management points and different management tools which increases complexity and security risks

Engineering Contradiction:
Improveplatform-specific security customizationVSAvoidmultiple management points and tools
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple platform-specific security management points into a single centralized security policy server. This security policy server consolidates the management of security policies across heterogeneous platforms (mainframe, UNIX, Windows, Linux, etc.), eliminating the need for separate management points for each platform and reducing overall system complexity while maintaining adaptability through platform-specific security agents.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security policy server is designed as a universal management system that can handle multiple types of hardware platforms and virtual resources through a common interface. It provides multi-functional capabilities including policy distribution, security zone management, and access control enforcement across diverse platforms, replacing the need for platform-specific management tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If multiple management tools are used for different hardware platforms, then each platform can be managed independently, but the number of access points increases which compromises security

Engineering Contradiction:
Improveindependent platform managementVSAvoidsecurity vulnerability from multiple access points
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Multiple security management access points are merged into a single centralized security policy server. This consolidation reduces the number of exposed access points while maintaining the ability to manage different platforms independently through their respective security agents that communicate with the centralized server.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security policy server acts as an intermediary between administrators and multiple hardware platforms. Instead of providing direct access points to each platform, the intermediary server centralizes policy management and distributes policies to platform-specific agents, thereby reducing security vulnerabilities while maintaining operational independence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a common security policy is managed from a single management point, then the number of access points is reduced and security is enhanced, but the system requires a centralized policy server to distribute and enforce access controls

Engineering Contradiction:
Improvesecurity from unified access controlVSAvoidcentralized policy server infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized security policy server is segmented into functional components: policy management functions, policy distribution mechanisms, and platform-specific security agents. This segmentation allows the system to achieve centralized security control while distributing enforcement capabilities across multiple points, thereby reducing the complexity burden on the central server.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security policy server serves as an intermediary that bridges centralized security policy management with distributed platform enforcement. It receives security policy configurations, translates them into platform-specific formats, and distributes them to appropriate security agents, thereby enabling unified security control without requiring a monolithic complex system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If platform-by-platform security management is implemented, then each platform can be secured independently, but security policies must be manually configured for each platform which is inefficient

Engineering Contradiction:
Improveindependent platform securityVSAvoidsecurity policy configuration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security policy server provides universal policy management capabilities that can configure security policies for multiple different hardware platforms through a single interface. It automatically translates universal security policies into platform-specific configurations and distributes them to respective security agents, eliminating manual configuration for each platform while maintaining independent platform security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates and distributes copies of the centralized security policy to multiple platform-specific security agents. Instead of manually configuring each platform, the security policy server replicates the security policy configuration across all connected platforms, ensuring consistent security enforcement while dramatically improving configuration efficiency.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9967288B2Providing a common security policy for a heterogeneous computer architecture environment
Publication Date: 2018.05.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9967288B2 patent drawing
  • US9967288B2 patent drawing
  • US9967288B2 patent drawing

AI summary

A common security policy for a heterogeneous computer architecture environment is provided. A configuration of a security policy of a heterogeneous computer architecture is received from a management console. The security policy is stored on a policy server that is communicatively connected, by a management network, to a plurality of hardware platforms of the of the heterogeneous computer architecture. The security policy is distributed to a plurality of policy agents of the heterogeneous computer architecture over the management network. The security policy includes a security policy administrator role that permits management of (i) one or more subjects in a plurality of security zones and (ii) one or more objects in the plurality of security zones. The security policy also includes security zone administrator roles, wherein each security zone administrator role (i) is associated with a respective security zone and (ii) permits management of object(s) in the respective security zone.