Trusted Server Policy Deployment via Metric and Verification Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted server policy management solutions lack independence and flexibility due to the use of a single metric algorithm for all metric objects, leading to cumbersome deployment and management processes that consume significant time and effort.

Innovation Solution

A method and system for policy deployment in trusted servers that involve sending metric and verification policies to a service center, where inconsistencies between metric and verification algorithms are detected and addressed through reminder information, allowing for the redeployment of consistent algorithms, enabling flexible and independent policy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single metric algorithm is used for all metric objects, then the system maintains simplicity and consistency, but the deployment and management process becomes cumbersome and time-consuming

Engineering Contradiction:
Improvepolicy flexibilityVSAvoiddeployment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the unified policy management into separate metric policies and verification policies that can be independently configured and deployed. Each policy can be tailored to specific metric objects or verification objects, allowing flexible adaptation without requiring complete redeployment of a unified system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from a static, unified policy structure to a dynamic, modular architecture where metric policies and verification policies can be independently updated, deployed, and managed. This dynamic separation enables rapid policy changes without affecting the entire system.

Inventive Principle:
Principle #15Dynamics

2Reliability

If metric policy and verification policy are tightly coupled, then consistency is maintained, but independent deployment and updates become impossible

Engineering Contradiction:
Improvepolicy consistencyVSAvoiddeployment independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the coupled policy system into separate metric policy modules and verification policy modules. Each module can be independently deployed, updated, or modified while maintaining their respective functions, eliminating the constraint of tight coupling.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism that coordinates between metric policies and verification policies, ensuring consistency without requiring direct tight coupling. This intermediary layer allows independent deployment while maintaining policy coherence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual policy management is used, then fine-grained control is achieved, but significant time and effort are consumed

Engineering Contradiction:
Improvepolicy management easeVSAvoidmanagement effort
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables automated self-service capabilities where policies can be automatically deployed, configured, and managed without extensive manual intervention. The modular architecture allows the system to self-configure metric and verification policies based on predefined rules and parameters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent utilizes parameter-based policy configuration where policies are defined by configurable parameters rather than hard-coded rules. This allows rapid policy adjustments through parameter changes without requiring manual reconfiguration of the entire policy structure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10999327B2Policy deployment method, apparatus, system and computing system of trusted server
Publication Date: 2021.05.04 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10999327B2 patent drawing
  • US10999327B2 patent drawing
  • US10999327B2 patent drawing

AI summary

A method, an apparatus, a system and a computing system for policy deployment of a trusted server are provided. The method includes sending a metric policy of at least one metric object and a verification policy of at least one verification object in a process of policy deployment of a trusted server to a service center; the trusted server receiving reminder information returned by the service center, wherein the reminder information is used for representing a reminder to the trusted server to redeploy a metric algorithm and a verification algorithm that are consistent if a metric algorithm of a metric object is detected to be inconsistent with a verification algorithm of a corresponding verification object. The present disclosure solves the technical problems of poor independence and flexibility due to the use of a same metric algorithm for all metric objects by existing trusted server policy management solutions.