Web Service Policy Enforcement via Segmented WS-Policy Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

WS-Policy, the standard language for web service policy documents, is limited in expressing certain security features and enforcing sequences or variations based on client context, such as internal or external access, which are not supported by its standard elements.

Innovation Solution

A method to generate a conforming web service policy document from a nonconforming document that includes unsupported functions, allowing for the inclusion or exclusion of elements and sequences based on client context, ensuring compliance and enforcement while maintaining conformance to WS-Policy standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a nonconforming web service policy document with unsupported functions is used, then advanced security features and context-dependent policies can be expressed, but the document cannot be directly transmitted to clients as it does not conform to WS-Policy standards

Engineering Contradiction:
Improvesecurity feature expression capabilityVSAvoidpolicy document compatibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The policy processing system segments the nonconforming policy document into conforming and nonconforming elements. The conforming elements are extracted and transmitted to the client in standard WS-Policy format, while the nonconforming elements containing advanced security features are retained and enforced separately by the web service, resolving the contradiction between expressiveness and compatibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The web service acts as an intermediary that receives the nonconforming policy document, processes it to generate a conforming version for client transmission, and simultaneously maintains the capability to enforce the original nonconforming document. This intermediary processing enables both advanced feature expression and standard compliance without direct client exposure to nonstandard elements

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the web service transmits only conforming policy documents to clients, then compatibility and standard compliance are maintained, but advanced security features unsupported by WS-Policy cannot be communicated to clients

Engineering Contradiction:
Improvepolicy document compatibilityVSAvoidsecurity feature expression capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The policy system segments functionality into two parts: conforming elements that are transmitted to clients for basic compatibility, and nonconforming elements that provide advanced security features. This segmentation allows the system to maintain WS-Policy compliance while still offering extended capabilities through the retained nonstandard elements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a conforming copy of the policy document from the nonconforming original. This copy contains only the elements that adhere to WS-Policy standards and can be safely transmitted to clients, while the original nonconforming document with advanced features remains with the web service for enforcement

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If the web service enforces context-dependent policies based on client context (internal or external access), then security can be enhanced with varying enforcement levels, but the standard WS-Policy language lacks the functions to express such context-dependent behavior

Engineering Contradiction:
Improvecontext-dependent policy enforcementVSAvoidpolicy language complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The policy enforcement mechanism is made dynamic by allowing the web service to evaluate client context (internal or external access) and selectively enforce different policy elements accordingly. The system dynamically determines which conforming elements to transmit and which nonconforming elements to enforce, enabling context-dependent security without requiring complex policy language extensions

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9021055B2Nonconforming web service policy functions
Publication Date: 2015.04.28 ORACLE INT CORP
  • US9021055B2 patent drawing
  • US9021055B2 patent drawing
  • US9021055B2 patent drawing

AI summary

Arrangements for enforcing a nonconforming web service policy document are presented. A request for a web service policy document may be received by a web service. A conforming web service policy document may be generated using the nonconforming web service policy document. The nonconforming web service policy document may comprise one or more functions unsupported by the web service description language. The conforming web service policy document may be transmitted to the web service client. The nonconforming web service policy document may be enforced by the web service, wherein the functions that are unsupported by the web service description language standard modifies enforcement of the web service policy document by the web service computer system. The conforming web service policy document may comprise sufficient information for the web service client computer system to comply with the nonconforming web service policy document.