Virtualized Software Compliance Enforcement via Dynamic Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computing environments, existing technologies lack a mechanism to assess and enforce compliance with resource characteristics, especially in elastic service-based technologies where resources can change dynamically, leading to outdated compliance assessments and potential non-compliance issues.
Innovation Solution
An apparatus and method that identify resources instantiated for a software application, retrieve compliance characteristics, select appropriate software components, evaluate compliance criteria, and modify the application to ensure compliance, with a detector component monitoring changes to resources and repeating the process as needed to maintain compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If resources are provided in a virtualized and distributed manner in service-based technologies, then resource flexibility and scalability are improved, but transparency of underlying technologies and auditability of resource characteristics deteriorate
Solution Approach 1:
The patent introduces a compliance assessment component as an intermediary layer between the service consumer and the virtualized resources. This component continuously monitors resource characteristics, assesses compliance against required criteria, and provides visibility into the actual state of resources without requiring changes to the virtualized infrastructure itself. The intermediary resolves the contradiction by maintaining resource flexibility while restoring transparency through automated assessment and reporting mechanisms.
Solution Approach 2:
The system implements continuous feedback loops where the compliance assessment component regularly evaluates resource characteristics and compares them against required compliance criteria. When changes in resource configuration affect compliance status, the system generates feedback signals that trigger re-assessment and potential compliance enforcement actions. This feedback mechanism ensures ongoing transparency and auditability despite dynamic resource changes in virtualized environments.
2Ease of operation
If compliance assessment is performed periodically for software applications, then compliance checking is simplified, but compliance assurance deteriorates in dynamic environments where resources change
Solution Approach 1:
The patent transitions from static periodic compliance assessment to a dynamic continuous assessment model. The compliance assessment component is designed to operate continuously in the background, automatically detecting and responding to resource changes without requiring manual re-initiation. This dynamic approach maintains the simplicity of automated checking while significantly improving reliability by ensuring compliance is assessed whenever resource changes occur, not just at predetermined intervals.
Solution Approach 2:
The system performs preliminary compliance assessment during application deployment and configuration, establishing a baseline compliance state before the application begins operation. This preliminary action ensures that compliance requirements are evaluated upfront, and any non-compliance issues are identified and addressed before the application goes live, reducing the need for corrective actions during runtime.
3Adaptability or versatility
If service providers abstract resources from service consumers, then service deployment flexibility is improved, but ability to audit and verify resource characteristics deteriorates
Solution Approach 1:
The compliance assessment component serves as a trusted intermediary that bridges the gap between service providers and service consumers. It has the authority to access and monitor resource characteristics on behalf of service consumers without requiring service providers to expose their underlying infrastructure. The intermediary component collects, evaluates, and reports compliance information, making resource characteristics auditable while preserving the abstraction and deployment flexibility provided by service-based technologies.
Data Source
AI summary
Techniques for enforcing a compliance requirement for a software application executing in a virtualized computing environment are disclosed. An identifier identifies a resource instantiated for the application's execution. A retriever retrieves a compliance characteristic for the application. The compliance characteristic is retrieved based on the identified resource and has an associated compliance criterion based on a formal parameter. The compliance criterion defines compliant resource states. A selector selects a software component for providing an actual parameter corresponding to the formal parameter . An evaluator evaluates the compliance criterion using the actual parameter. An application modifier, responsive to the resource lacking a compliant resource state, modifies the software application to have a resource with a compliant state. The identifier, selector, and evaluator respond to resource changes. The selector selects the software component based on an identification of one or more data items that the software component can provide.


