US2008040343A1PendingUtilityA1

Extending the sparcle privacy policy workbench methods to other policy domains

Assignee: IBMPriority: Aug 14, 2006Filed: Aug 14, 2006Published: Feb 14, 2008
Est. expiryAug 14, 2026(~0 yrs left)· nominal 20-yr term from priority
G06Q 10/06
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system enable a user to develop domain-specific policy workbench. Domains may include, but are not limited to security, autonomic computing, workload management and systems management. The method and system in one aspect determines syntax of a policy in a selected domain and creates an instance of policy workbench specific to the selected domain. In one aspect, the instance of policy workbench includes at least machine-readable encodings of the selected policy and associated mapping. The instance of policy workbench also includes a compliance auditing tool enabled to check events logged at a target system against the selected policy and associated mapping to determine if one or more policy rules have been complied with. In another aspect, domain-specific policy workbench creation machine is provided that automatically creates an instance of domain-specific policy workbench.

Claims

exact text as granted — not AI-modified
1 . A method for creating a policy workbench for a given domain, comprising:
 analyzing a domain; and   providing a domain-specific policy workbench.   
   
   
       2 . The method of  claim 1 , wherein the step of analyzing a domain includes:
 determining syntax of one or more policy rules associated with the domain.   
   
   
       3 . The method of  claim 2 , wherein the step of determining syntax uses an encoding format as a basis. 
   
   
       4 . The method of  claim 2 , wherein the step of providing a domain-specific policy workbench includes:
 creating a natural language grammar based on the syntax.   
   
   
       5 . The method of  claim 1 , wherein the domain specific policy workbench provides an encoded rendering of a given policy. 
   
   
       6 . The method of  claim 5 , wherein the encoding is XML-based. 
   
   
       7 . The method of  claim 6 , wherein the XML-based encoding uses the OASIS XACML standard. 
   
   
       8 . The method of  claim 1 , wherein the domain includes security, autonomic computing, workload management, or systems management, or combination thereof. 
   
   
       9 . The method of  claim 1 , wherein providing the domain-specific policy workbench further includes:
 providing one or more mappings between one or more policy-rule elements and one or more domain elements.   
   
   
       10 . The method of  claim 9 , further including:
 obtaining one or more system activity events from a log;   using the one or more mappings to translate the one or more system activity events into policy language; and   comparing translated events to policy rules.   
   
   
       11 . A method of creating a domain-specific policy workbench, comprising:
 determining syntax of a policy in a selected domain;   creating an instance of policy workbench specific to the selected domain.   
   
   
       12 . The method of  claim 11 , further including:
 determining whether creating a policy for the selected domain is feasible, and if it is determined that creating a policy for the selected domain is feasible, performing the step of creating.   
   
   
       13 . The method of  claim 11 , wherein the step of creating includes at least:
 invoking an authoring tool creation handler to create an authoring tool operable to allow a practitioner to author a selected policy;   invoking a policy and mapping data handler creation handler to create a policy and mapping data handler operable to create a policy workbench instance including at least a machine-readable encodings of the selected policy and associated mapping; and   invoking a compliance auditing tool creation handler to create a compliance auditing tool operable to allow a practitioner to audit compliance of system activities according to the selected policy and the associated mapping.   
   
   
       14 . The method of  claim 13 , wherein the step of creating further includes at least:
 invoking a practitioner identification handler to identify one or more practitioners; and   invoking a practitioner skill identification handler to determine skills of the one or more practitioners.   
   
   
       15 . The method of  claim 13 , wherein the step of creating further includes at least:
 invoking a mapping handler to determine one or more mappings between one or more elements of a target system and the selected policy.   
   
   
       16 . A system for creating a domain-specific policy workbench, comprising:
 a policy grammar handler operable to determine syntax of a policy in a selected domain;   a policy and mapping data handler creation handler operable to create a policy and mapping data handler operable to create a policy workbench instance including at least a machine-readable encodings of the selected policy and associated mapping; and   a compliance auditing tool creation handler operable to create a compliance auditing tool operable to allow a practitioner to audit compliance of system activities according to the selected policy and the associated mapping.   
   
   
       17 . The system of  claim 16 , further including at least:
 a practitioner identification handler operable to identify one or more practitioners; and   a practitioner skill identification handler operable to determine skills of the one or more practitioners.   
   
   
       18 . The system of  claim 16 , further including at least:
 a mapping handler operable to determine one or more mappings between one or more elements of a target system and the selected policy.   
   
   
       19 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform a method of creating a domain-specific policy workbench, comprising:
 determining syntax of a policy in a selected domain;   creating an instance of policy workbench specific to the selected domain.   
   
   
       20 . The program storage device of  claim 19 , wherein the step of creating includes at least:
 invoking an authoring tool creation handler to create an authoring tool operable to allow a practitioner to author a selected policy;   invoking a policy and mapping data handler creation handler to create a policy and mapping data handler operable to create a policy workbench instance including at least a machine-readable encodings of the selected policy and associated mapping; and   invoking a compliance auditing tool creation handler to create a compliance auditing tool operable to allow a practitioner to audit compliance of system activities according to the selected policy and the associated mapping.

Join the waitlist — get patent alerts

Track US2008040343A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.