Workload Security Policy Enforcement via Signed Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current workload execution systems inadequately enforce data security requirements, leading to potential violations due to human error and lack of systemic enforcement, as these requirements are not consistently visible or accessible to platforms after initial placement.

Innovation Solution

A method where a data security policy is expressed as digitally signed metadata that travels with platform-portable workloads, allowing validation and automatic determination of platform compliance, preventing execution on non-compliant platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data security policies are manually enforced by platforms after workload placement, then flexibility in workload execution is maintained, but security compliance reliability deteriorates due to human error and lack of systematic enforcement

Engineering Contradiction:
Improvesecurity compliance reliabilityVSAvoidsecurity enforcement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding data security policies as digitally signed metadata into workloads before they are placed on platforms. The security attributes are predetermined and attached to the workload, allowing automatic validation against platform capabilities before execution, thereby eliminating manual enforcement errors while maintaining systematic simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by automatically validating the digitally signed metadata against platform data security attributes and providing systematic enforcement feedback. The system compares workload security requirements with platform capabilities and automatically prevents execution if compliance is not met, creating a closed-loop security enforcement mechanism that improves reliability without increasing operational complexity.

Inventive Principle:
Principle #23Feedback

2Reliability

If data security policies are expressed as digitally signed metadata and automatically validated, then security compliance reliability improves, but system complexity increases due to validation and comparison mechanisms

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidvalidation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling workloads to carry their own security policy information in the form of digitally signed metadata. The workload essentially validates itself against platform capabilities through automatic comparison, reducing the need for complex external validation systems while maintaining high security enforcement reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security validation is performed as a preliminary action before workload execution. By validating the digitally signed metadata against platform attributes upfront, the system avoids the need for complex continuous monitoring and enforcement mechanisms during runtime, thereby improving security reliability without proportionally increasing system complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If platform capabilities are systematically compared with workload security requirements, then security compliance improves, but processing time increases due to validation overhead

Engineering Contradiction:
Improvedata security complianceVSAvoidworkload placement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security compliance validation as a preliminary action during workload placement rather than during execution. By comparing the digitally signed metadata with platform attributes upfront, the system ensures security compliance while minimizing time loss to a single validation event, avoiding continuous time overhead during workload operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9881159B1Workload execution systems and methods
Publication Date: 2018.01.30 QUEST SOFTWARE INC
  • US9881159B1 patent drawing
  • US9881159B1 patent drawing
  • US9881159B1 patent drawing

AI summary

In one embodiment, a method is executed by a computer system. The method includes receiving information related to a platform-portable workload, the information comprising a data security policy expressed as digitally signed metadata. The data security policy specifies one or more data security features that any platform executing the platform-portable workload should implement. The method further includes validating the digitally signed metadata as originating from an issuer of the platform-portable workload. In addition, the method includes, responsive to successful validation of the digitally signed metadata, automatically determining whether a particular platform can satisfy the data security policy based, at least in part, on a comparison of the digitally signed metadata with data security attributes of the particular platform. Further, the method includes, responsive to a determination that the particular platform cannot satisfy the data security policy, automatically preventing execution of the platform-portable workload on the particular platform.