Unified Resource Database Interface for Cross-Origin Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud security and management platforms are limited in scope to cloud resources and struggle with data visualization and searching, failing to effectively manage and secure resources across diverse origins and domains, including both cloud and application resources.

Innovation Solution

A resource database interface that collects and categorizes structured data from various origins, using JSON files, to enable cross-category querying and policy enforcement, allowing for comprehensive management and security of resources across multiple categories and origins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud security platforms operate only on cloud resources with structured data, then security management is simplified and focused, but the platform cannot manage or secure resources from diverse origins including application resources

Engineering Contradiction:
Improveresource origin coverageVSAvoidplatform architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal resource database interface that can collect, categorize, and manage structured data from multiple origins including cloud resources and application resources. The system uses a unified JSON-based data structure and common categorization fields (origin, type, identifier) to handle diverse resource types through a single platform, eliminating the need for separate security management systems for different resource origins.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If resources from multiple origins are collected into a unified database, then cross-category querying and correlation become possible, but data visualization and searching become more difficult

Engineering Contradiction:
Improvedata correlation capabilityVSAvoiddata search and visualization difficulty
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by maintaining consistent data structures and categorization schemes for different resource types while allowing each resource origin to retain its specific characteristics. The system uses origin-specific and type-specific field configurations within the unified JSON structure, enabling targeted querying and visualization strategies adapted to each resource category's specific needs while benefiting from cross-category correlation capabilities.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If a unified resource database interface is implemented to manage diverse resources, then comprehensive security management across multiple origins is achieved, but the complexity of data collection and categorization increases

Engineering Contradiction:
Improvemulti-origin resource managementVSAvoiddata collection and categorization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data collection and categorization process into distinct, manageable components: origin identification, type classification, and field extraction. Each resource is processed through standardized stages that collect specific fields (origin, type, identifier, description, creation time, modification time) while allowing origin-specific extensions. This segmented approach reduces complexity by breaking down the unified management task into reusable, modular operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12177257B2Domain-independent resource security and management
Publication Date: 2024.12.24 PALO ALTO NETWORKS INC
  • US12177257B2 patent drawing
  • US12177257B2 patent drawing
  • US12177257B2 patent drawing

AI summary

A resource database which stores structured data describing resources from a diverse array of origins (e.g., an application or cloud environment) is built and maintained to support querying, policy enforcement, and remediation of resources from any origin. Structured data representing resources are obtained from any origin for insertion and categorized based on their type and/or origin. Resources within a category have a shared set of potential object paths as defined by the hierarchical tree structure of their structured data. Resources may be correlated across categories based on having values at different object paths in common. Queries and rules/policies can thus reference resources of any category and also resources across different categories based on correlations between the resources, thereby extending rule/policy enforcement and incident remediation across multiple different origins of resources.