Tag-Based Security Policy Generation in Distributed Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a distributed computing environment, the rapid evolution of networks and security needs poses challenges for creating and maintaining effective security policies, as custom applications and services are increasingly deployed on network-accessible hardware, making it difficult for creators to anticipate and address all potential security risks, leading to emerging vulnerabilities.

Innovation Solution

A tag-based security policy creation system where an orchestration platform generates inventory events that include tags associated with service entities, which are then processed by a security management platform to identify policy rules and compute a security policy, allowing for dynamic updates and application within the computing environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If services are deployed on network-accessible hardware in a virtualized environment, then flexibility and scalability are improved, but security vulnerabilities increase due to network accessibility

Engineering Contradiction:
Improveservice deployment flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security policy management into modular components: service recipes define service configurations with associated security tags, the orchestration platform manages service deployment and generates inventory events, and the security management platform processes events and computes policies. This segmentation allows independent updates of security policies without affecting service deployment flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by computing security policies before services are deployed or modified. The security management platform receives inventory events, identifies affected services, determines applicable policy rules, and computes updated security policies in advance, ensuring security measures are ready before vulnerabilities can be exploited.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security policies are updated in real-time in response to evolving threats, then security effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the security management platform continuously monitors inventory events from the orchestration platform, processes security tag information, and computes updated security policies. This closed-loop feedback system enables real-time security policy updates in response to changing service inventories and emerging threats without manual intervention.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service by automatically generating security policies through the security management platform. When inventory events are received, the platform autonomously identifies affected services, retrieves applicable policy rules, computes updated policies, and delivers them to the computing environment without requiring security expert intervention for each update.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security policies are created for all possible risks, then security coverage is improved, but policy creation time increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidpolicy creation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses parameter changes by dynamically adjusting security policies based on service-specific attributes and tags. Instead of creating static comprehensive policies for all possible risks, the system computes policies tailored to each service's actual configuration, enabling efficient policy generation that covers only relevant security requirements for deployed services.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements universality through reusable service recipes that define common service configurations with associated security tags. These recipes serve multiple functions: they standardize service deployment, automate inventory event generation, and enable consistent security policy application across similar services, reducing overall policy creation time while maintaining comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11171994B2Tag-based security policy creation in a distributed computing environment
Publication Date: 2021.11.09 AT&T INTELLECTUAL PROPERTY I L P
  • US11171994B2 patent drawing
  • US11171994B2 patent drawing
  • US11171994B2 patent drawing

AI summary

Concepts and technologies are disclosed herein for tag-based security policy creation in a distributed computing environment. A security management module can receive an inventory event that relates to instantiation of a service. The security management module can identify the service that was instantiated and obtain a tag set that relates to the service. The tag set can include security tags that include a string that identifies a communications link associated with the entities included in the service that was instantiated. The security management module can identify policy rules associated with the security tags. The policy rules can define security for the service that was instantiated. The security management module can compute a security policy for the service and can provide the security policy to the computing environment for implementation.