Security QoS Controller for Computing System Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems lack the capability to manage fine-grained security Quality of Service (QoS) across the entire software and hardware stack, especially in dynamic environments involving microservices and edge devices, where security requirements are not adequately supported or guaranteed.

Innovation Solution

A computing system architecture that includes a security QoS controller, QoS profile manager, interdependency flow graph generator, and configuration recommender to analyze and configure security QoS requirements by generating an interdependency flow graph based on available components and real-time telemetry data, ensuring optimal power and performance while meeting specific security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dynamic allocation of software and hardware components is implemented to support microservices and edge devices, then system adaptability and versatility are improved, but the ability to guarantee fine-grained security QoS across the complete stack deteriorates

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidsecurity QoS guarantee
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security QoS management into distinct functional modules: a QoS profile manager that handles security policy definitions, an interdependency flow graph generator that maps component relationships, and a configuration recommender that provides specific guidance. This segmentation allows each module to specialize in its function while working together to maintain security QoS across dynamically allocated components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security QoS management layer that sits between the dynamic component allocation and the security requirements. This intermediary layer uses interdependency flow graphs to mediate between component configurations and security QoS guarantees, translating dynamic allocations into verified security-compliant states through automated analysis and recommendation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fine-grained security QoS management across the complete SW and HW stack is implemented, then security QoS reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity QoS guaranteeVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates universal security QoS management tools that can operate across diverse software and hardware platforms. The QoS profile manager, interdependency flow graph generator, and configuration recommender are designed to work with multiple component types and configurations, providing a unified approach to security QoS management that reduces the need for platform-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service capabilities where the interdependency flow graph automatically analyzes component relationships and the configuration recommender provides automated guidance for maintaining security QoS. This self-service approach reduces the burden on system administrators and simplifies the management of fine-grained security QoS across complex stacks by enabling automatic analysis and recommendation generation.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If automated configuration recommendation system is implemented with interdependency flow graph analysis, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveconfiguration management easeVSAvoidmanagement system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-generating interdependency flow graphs that capture component relationships before configuration decisions are made. The QoS profile manager pre-defines security policies and the flow graph generator pre-analyzes component interdependencies, so that when configuration recommendations are needed, the system can quickly provide guidance based on pre-computed analysis rather than performing complex analysis in real-time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240223611A1Managing computing system configurations for security quality of service (QOS)
Publication Date: 2024.07.04 INTEL CORP
  • US20240223611A1 patent drawing
  • US20240223611A1 patent drawing
  • US20240223611A1 patent drawing

AI summary

The technology described herein includes determining a security quality of service (Qos) profile matching configuration attributes of a first computing system, generating an interdependency flow graph based at least in part on the security QoS profile and the configuration attributes, generating a recommended configuration for the first computing system from the interdependency flow graph, and sending the recommended configuration to a second computing system.