Web Service Trust Level Selection via Audit Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In service-oriented architectures, selecting a web service based on specific audit and compliance qualities is challenging, as existing systems do not effectively filter services based on user-defined degrees of trust, leading to potential security and compliance issues.

Innovation Solution

A method that utilizes a service registry to assign hierarchical levels-of-trust to web services based on audit and compliance attributes, allowing users to select services with acceptable degrees of trust for invocation, utilizing digital signatures for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive audit and compliance attributes are provided for all web services, then the completeness of security information is improved, but the complexity of service selection and the risk of privacy violations increase

Engineering Contradiction:
Improvecompleteness of security informationVSAvoidcomplexity of service selection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by providing different levels of audit and compliance information tailored to the specific needs of each service consumer. Instead of uniformly providing all audit attributes to all consumers, the system filters and presents only the relevant audit attributes based on the consumer's trust level and compliance requirements. This resolves the contradiction by maintaining comprehensive security information availability while reducing the complexity burden on consumers who do not require all attributes.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by making the audit and compliance information presentation adaptive and configurable. The system dynamically adjusts the level of detail and type of audit information provided based on real-time factors such as the consumer's trust level, compliance requirements, and service context. This dynamic filtering mechanism maintains information completeness for those who need it while simplifying the selection process for those with lesser requirements.

Inventive Principle:
Principle #15Dynamics

2Reliability

If web services are filtered based on user-defined trust levels, then the security and compliance reliability is improved, but the service discovery complexity increases

Engineering Contradiction:
Improvesecurity and compliance reliabilityVSAvoidservice discovery complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling service consumers to autonomously define their own trust levels and compliance requirements without requiring complex manual configuration. The system provides standardized trust level definitions and compliance frameworks that consumers can directly configure, eliminating the need for complex security policy authoring while maintaining high security reliability. This resolves the contradiction by simplifying the service discovery process for security-filtered results.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements parameter changes by transforming complex security and compliance requirements into configurable parameter sets. Instead of requiring consumers to manually define complex security policies, the system provides predefined trust level parameters and compliance attributes that can be easily adjusted. This parameterization approach maintains security reliability while significantly reducing the complexity of service discovery and selection.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If audit data is collected and stored for compliance assessment, then the compliance accuracy is improved, but the data privacy risks and storage requirements increase

Engineering Contradiction:
Improvecompliance accuracyVSAvoiddata privacy risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies the extraction principle by selectively extracting and collecting only the specific audit attributes necessary for compliance assessment, rather than collecting all possible data. The system identifies and extracts minimal necessary information from service operations to satisfy compliance requirements, thereby maintaining compliance accuracy while reducing the scope of data collection and associated privacy risks. This is achieved through targeted audit attribute selection based on the specific compliance framework being applied.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by collecting and storing only the essential audit data required for compliance verification, rather than comprehensive data collection. The system performs partial auditing focused on critical compliance attributes, which is sufficient for maintaining compliance accuracy while minimizing data privacy exposures. This partial approach allows compliance assessment without the excessive data collection that would increase privacy risks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8572691B2Selecting a web service from a service registry based on audit and compliance qualities
Publication Date: 2013.10.29 BEIJING ZITIAO NETWORK TECH CO LTD
  • US8572691B2 patent drawing
  • US8572691B2 patent drawing
  • US8572691B2 patent drawing

AI summary

A particular web service is selected based on conformation to a particular degree-of-trust. Information about available web services is requested. Responsive to requesting that information on the particular web service, a list of possible services is presented. The list of possible services includes a plurality of services, each of the plurality having a levels-of-trust assigned thereto. An acceptable web service having an acceptable degree-of-trust can then be selected from the list of possible services. Responsive to selecting the acceptable service from the list of possible services, the acceptable service can be invoked.