Application Data Protection Layer Security Capability Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Scaled-out, distributed applications are vulnerable to breaches and data theft due to inadequate protection mechanisms, particularly in data centers handling sensitive information, as existing security features fail to protect the entire distributed application system effectively.

Innovation Solution

An Application and Data Protection Layer (ADPL) determines and exchanges security features and capabilities among application instances via data socket descriptors, enabling dynamic protection mechanisms such as cache flushing, data redaction, and payload encryption based on peer security profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security mechanisms are used in distributed applications, then device complexity is reduced, but security reliability is insufficient

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An Application and Data Protection Layer (ADPL) is introduced as an intermediary component between applications and the underlying system. The ADPL includes a capability exchange module that enables peer applications to share security capabilities and a protection module that applies security measures based on exchanged capabilities. This intermediary structure enhances security reliability without requiring complex modifications to each individual application or the core system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security protection measures are applied to distributed applications, then security reliability is improved, but productivity may be reduced due to additional overhead

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidapplication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The ADPL implements self-service mechanisms where peer applications automatically exchange their security capabilities with each other through the capability exchange module. The protection module then automatically applies appropriate security measures based on the exchanged capabilities without requiring manual configuration or intervention. This automation reduces the overhead associated with security management while maintaining strong security protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system applies security measures selectively based on the exchanged capabilities rather than uniformly across all applications. The protection module evaluates the security needs of each application instance and applies only the necessary protection measures, avoiding excessive security overhead for applications that have adequate built-in security capabilities.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If security capabilities are exchanged among peer applications, then adaptability of security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity capability exchangeVSAvoidcommunication overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The ADPL is designed as a universal protection layer that can serve multiple peer applications simultaneously. The capability exchange module uses standardized protocols and data structures that can be applied across different application types, enabling the system to handle diverse security capabilities without requiring application-specific customization. This multi-functionality approach enhances adaptability while controlling complexity through reuse of common mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10193930B2Application security capability exchange via the application and data protection layer
Publication Date: 2019.01.29 AVOCADO SYSTEMS INC
  • US10193930B2 patent drawing
  • US10193930B2 patent drawing
  • US10193930B2 patent drawing

AI summary

According to one embodiment, a system includes a processing circuit and logic integrated with and/or executable by the processing circuit. The logic is configured to cause the processing circuit to determine, by an application operating on a first host in a network, one or more security features and/or capabilities available to the application for protecting the application and first data used by the application from unauthorized activity. The logic is also configured to cause the processing circuit to send, by an ADPL operating on the first host via a data socket descriptor, a first message to one or more peer applications in the network, the first message including indication of the one or more security features and/or capabilities available to the application. The logic may further cause the processing circuit to receive a second message indicating security features available to a peer application in the network operating on another host.