Nova Patents
EP1102153A2

Mechanism for merging multiple policies

Abstract

A mechanism for merging multiple source policies to derive a resultant policy is disclosed. The source policies, which may represent sets of laws/regulations, and which may comprise zero or more entries with each entry comprising an identifier and a set of one or more limitations, are merged by first selecting a current entry in a first source policy. Then a determination is made as to whether there is an entry in a second source policy which corresponds to the current entry. If so, then the limitations in the current entry are processed with the limitations in the corresponding entry to derive a set of resultant limitations. The limitations are processed such that the resultant limitations comprise the most restrictive limitations of the current entry and the corresponding entry. By doing so, it is ensured that the resultant limitations comply with both the first and the second source policies. Once the resultant limitations are derived, a new entry is created in the resultant policy which comprises the resultant limitations. The resultant policy is thus populated.

EP1102153A2, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Projected expiry passed 7 November 2020, 5.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

50 claims: 22 independent, 28 dependent

  1. 1
    A method for processing a plurality of source policies to derive a resultant policy, each of the source policies comprising zero or more entries with each entry comprising an identifier and one or more limitations, said method comprising:selecting a current entry from afirst source policy;determining whether a second source policy comprises a corresponding entry which corresponds to said current entry;in response to a determination that said second source policy comprises a corresponding entry, processing the limitations in said current entry and the limitations in said corresponding entry to derive a set of resultant limitations, said resultant limitations comprising the limitations of said current entry and said corresponding entry which are most restrictive;and creating in a resultant policy a new entry comprising said resultant limitations.
  2. 5
    The method of any preceding claim, wherein the limitations of each entry comprises encryption limitations to be imposed on one or more encryption algorithms.
  3. 8
    The method of any preceding claim, wherein said resultant limitations are derived on a limitation by limitation basis.
  4. 9
    The method of any preceding claim, wherein said first source policy represents a first set of laws/regulations, and said second source policy represents a second and different set of laws/regulations.
  5. 11
    The method of any preceding claim, wherein each of said source policies comprises a default component which specifies default limitations to impose on one or more encryption algorithms.
  6. 12
    The method of any preceding claim, wherein each of said source policies comprises an exempt component which specifies limitations to impose on one or more encryption algorithms when one or more exemption mechanisms are enforced.
  7. 13
    The method of any preceding claim, further comprising:in response to a determination that said second source policy does not comprise a corresponding entry, determining whether said second source policy comprises a wildcard entry;in response to a determination that said second source policy comprises a wildcard entry, processing the limitations in said current entry and the limitations in said wildcard entry to derive a set of alternative resultant limitations, said alternative resultant limitations comprising the limitations of said current entry and said wildcard entry which are most restrictive;and creating in said resultant policy a new entry comprising said alternative resultant limitations.
  8. 17
    A computer system, comprising:a mechanism for processing multiple source policies to derive a set of specified limitations;a mechanism for determining a set of restrictions based at least upon said set of specified limitations;and a mechanism for enforcing said restrictions on an implementation of a service.
  9. 22
    The system of any of claims 18 to 21, wherein the limitations of each entry comprises encryption limitations to be imposed on one or more encryption algorithms.
  10. 25
    The system of any of claims 18 to 24, wherein said resultant limitations are derived on a limitation by limitation basis.
  11. 26
    The system of any of claims 18 to 25, wherein said first source policy represents a first set of laws/regulations, and said second source policy represents a second and different set of laws/regulations.
  12. 28
    The system of any of claims 18 to 27, wherein each of said source policies comprises a default component which specifies default limitations to impose on one or more encryption algorithms.
  13. 29
    The system of any of claims 18 to 28, wherein each of said source policies comprises an exempt component which specifies limitations to impose on one or more encryption algorithms when one or more exemption mechanisms are enforced.
  14. 30
    The system of any of claims 18 to 29, wherein the mechanism for processing multiple source policies further comprises:a mechanism for determining, in response to a determination that said second source policy does not comprise a corresponding entry, whether said second source policy comprises a wildcard entry;a mechanism for processing, in response to a determination that said second source policy comprises a wildcard entry, the limitations in said current entry and the limitations in said wildcard entry to derive a set of alternative resultant limitations, said alternative resultant limitations comprising the limitations of said current entry and said wildcard entry which are most restrictive;and a mechanism for creating in said resultant policy a new entry comprising said alternative resultant limitations.
  15. 34
    A computer program operable, when executed by one or more processors, to cause the one or more processors to process a plurality of source policies to derive a resultant policy, wherein each of the source policies comprises zero or more entries with each entry comprising an identifier and one or more limitations, said computer program comprising:instructions for causing one or more processors to select a current entry from a first source policy;instructions for causing one or more processors to determine whether a second source policy comprises a corresponding entry which corresponds to said current entry;instructions for causing one or more processors to process, in response to a determination that said second source policy comprises a corresponding entry, the limitations in said current entry and the limitations in said corresponding entry to derive a set of resultant limitations, said resultant limitations comprising the limitations of said current entry and said corresponding entry which are most restrictive;and instructions for causing one or more processors to create in a resultant policy a new entry comprising said resultant limitations.
  16. 38
    The computer program of any of claims 34 to 37, wherein the limitations of each entry comprises encryption limitations to be imposed on one or more encryption algorithms.
  17. 41
    The computer program of any of claims 34 to 40, wherein said resultant limitations are derived on a limitation by limitation basis.
  18. 42
    The computer program of any of claims 34 to 41, wherein said first source policy represents a first set of laws/regulations, and said second source policy represents a second and different set of laws/regulations.
  19. 44
    The computer program of any of claims 34 to 43, wherein each of said source policies comprises a default component which specifies default limitations to impose on one or more encryption algorithms.
  20. 45
    The computer program of any of claims 34 to 44, wherein each of said source policies comprises an exempt component which specifies limitations to impose on one or more encryption algorithms when one or more exemption mechanisms are enforced.
  21. 46
    The computer program of any of claims 34 to 45, further comprising:instructions for causing one or more processors to determine, in response to a determination that said second source policy does not comprise a corresponding entry, whether said second source policy comprises a wildcard entry;instructions for causing one or more processors to process, in response to a determination that said second source policy comprises a wildcard entry, the limitations in said current entry and the limitations in said wildcard entry to derive a set of alternative resultant limitations, said alternative resultant limitations comprising the limitations of said current entry and said wildcard entry which are most restrictive;and instructions for causing one or more processors to create in said resultant policy a new entry comprising said alternative resultant limitations.
  22. 50
    A computer program product comprising a computer program of any of claims 34 to 49 on a carrier medium.
Independent claims22