ObjectSecurity, an information security leader  and the company driving model-driven security policy automation globally, today announced that one of their core patent applications has been allowed by the USPTO. This is one of a series of ObjectSecurity’s patent applications that cover OpenPMF’s core inventions. Please contact ObjectSecurity if you are interested in licensing the intellectual property.

The patent application “Method and system for rapid accreditation/re-accreditation of agile it environments, for example service oriented architecture (soa)” pertains to model-driven security for automated auditing, reporting, documenting, and analysis (e.g. for compliance and accreditation). OpenPMF enables the consistent, easy-to-administer management and enforcement of rich access control policies (e.g. for SOA, the industrial internet of things etc.)

Model-driven security (MDS) [1] means applying model-driven approaches (and especially the concepts behind model-driven software development) to security. The general concept of Model-driven security in its earliest forms has been around since the late 1990s (mostly in university research), and was first commercialized around 2002. There is also a body of later scientific research in this area, which continues to this day. A more specific definition of Model-driven security specifically applies model-driven approaches to automatically generate technical security implementations from security requirements models. In particular, “Model driven security (MDS) is the tool supported process of modelling security requirements at a high level of abstraction, and using other information sources available about the system (produced by other stakeholders). These inputs, which are expressed in Domain Specific Languages (DSL), are then transformed into enforceable security rules with as little human intervention as possible. MDS explicitly also includes the run-time security management (e.g. entitlements/authorisations), i.e. run-time enforcement of the policy on the protected IT systems, dynamic policy updates and the monitoring of policy violations.” Particularly related to the allowed patent application, model-driven security is also well-suited for automated auditing, reporting, documenting, and analysis (e.g. for compliance and accreditation), because the relationships between models and technical security implementations are traceably defined through the model-transformations.