Composite Application Security Identity Propagation via Persistent Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Composite applications face inefficiencies in maintaining security identity information during lengthy processing times and potential system restarts, leading to resource wastage and security concerns due to the need to maintain processing threads for inactive entities.

Innovation Solution

The method involves transferring state data with identity attributes to a non-transitory storage medium, allowing for the reallocation of processing threads and reevaluation of security attributes upon retrieval, ensuring secure and efficient continuation of composite application processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If processing threads are maintained for entities during lengthy periods of inactivity, then security identity information remains readily accessible, but system resources are wasted and efficiency decreases

Engineering Contradiction:
Improvesecurity identity information availabilityVSAvoidsystem resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts security identity information from in-memory processing threads and stores it in persistent storage media. This separation allows the system to discard processing threads during inactivity periods while preserving security attributes in storage, resolving the contradiction between maintaining security information availability and improving resource efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If processing threads are maintained for active processing, then security authentication can be performed continuously, but resource consumption increases during inactive periods

Engineering Contradiction:
Improvesecurity authentication capabilityVSAvoidprocessing thread resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs preliminary actions by storing security identity information in persistent storage before processing threads are terminated. This allows the system to quickly restore authentication capability after thread reallocation without maintaining continuous thread presence, thus reducing energy loss while preserving security authentication capability.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If state data including security attributes is stored in persistent storage, then system restarts can be tolerated and threads can be reallocated, but security attributes must be reevaluated upon retrieval

Engineering Contradiction:
Improvesystem restart toleranceVSAvoidsecurity attribute reevaluation process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary reevaluation process that acts as a mediator between stored security attributes and active processing requirements. This intermediary layer validates security attributes upon retrieval from persistent storage, enabling system restart tolerance while managing the complexity of security verification through a standardized intermediate step.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8973117B2Propagating security identity information to components of a composite application
Publication Date: 2015.03.03 ORACLE INT CORP
  • US8973117B2 patent drawing
  • US8973117B2 patent drawing
  • US8973117B2 patent drawing

AI summary

Various methods and systems for propagating identity information in a composite application are presented. State data of a composite application, as executed for a particular entity, may be transferred to and stored by a computer-readable storage medium. The state data may include a portion of a set of subject information linked with the entity. A security attribute of the subject may not be present in the portion of the set of subject information in the state data transferred to the non-transitory computer-readable storage medium. After a period of time, such as an hour or a day, the state data of the composite application as executed for the entity may be retrieved and the security attribute of the set of subject information linked with the entity may be determined The composite application may then continue to be executed for the entity.