Data Source Protective Layer With Wrapper-Based Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security models fail to adequately protect data sources from unauthorized access and are complex and expensive to manage, with applications remaining vulnerable despite secure perimeters, and lack support for tokenization and federated identity management.

Innovation Solution

Implementing a protective layer at the data source with a dispatcher and services that provide authentication, tokenization, behavioral baselining, and federated identity management, using a data agnostic dispatcher to intercept and inspect communications, and collectors to gather application context for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure perimeter is implemented around the organization to protect data sources, then security against unauthorized access is improved, but device complexity and management cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a wrapper as an intermediary component that sits between applications and data sources. This wrapper provides authentication, tokenization, and behavioral baselining services, effectively mediating access control without requiring complex perimeter security infrastructure. The wrapper acts as a local security gatekeeper at each data source, simplifying overall security management while maintaining strong protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security function is segmented and distributed to individual data sources through the wrapper architecture. Instead of implementing a centralized perimeter security system that protects the entire organization, each data source has its own wrapper that independently provides security services. This segmentation reduces the complexity of managing a single large-scale security perimeter while maintaining comprehensive protection across multiple data sources.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If conventional security models are used to protect data sources, then basic access control is provided, but tokenization and federated identity management are not supported

Engineering Contradiction:
Improvesecurity feature supportVSAvoiddata protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The wrapper is designed as a multi-functional security component that provides authentication, tokenization, behavioral baselining, and federated identity management capabilities. This universal security layer can adapt to different data source types and provide multiple security features through a single integrated solution, enhancing both the versatility of security feature support and the reliability of data protection simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If applications are made vulnerable-free through secure perimeter, then data protection is improved, but administration becomes complex and expensive

Engineering Contradiction:
Improvedata protectionVSAvoidadministration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The wrapper implements self-service security by autonomously performing authentication, tokenization, and behavioral analysis without requiring manual intervention for each access request. The behavioral baselining feature learns normal access patterns and automatically detects anomalies, reducing the need for complex administrative oversight while maintaining strong data protection.

Inventive Principle:
Principle #25Self-service

4Reliability

If a protective layer is implemented at each data source, then security against unauthorized access is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wrapper serves as a standardized intermediary component that can be deployed at each data source with a consistent interface and functionality. This standardization reduces system architecture complexity compared to implementing custom security solutions at each data source, as the same wrapper template can be replicated across multiple data sources with minimal configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3854057B1Architecture having a protective layer at the data source
Publication Date: 2025.08.27 CYRAL INC
  • EP3854057B1 patent drawingFigure 1~2
  • EP3854057B1 patent drawingFigure 3
  • EP3854057B1 patent drawingFigure 4

AI summary

A method and system for performing at least one service are disclosed. The method and system include receiving a communication for a data source at a wrapper. The wrapper includes a dispatcher and at least one service. The dispatcher receives the communication and is data agnostic. The method and system also include providing the communication from the dispatcher to the data source and to the at least one service. The at least one service inspects the communication and may perform additional functions.