Data Source Protective Layer With Wrapper-Based Access Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security models fail to adequately protect data sources from unauthorized access and are complex and expensive to manage, with applications remaining vulnerable despite secure perimeters, and lack support for tokenization and federated identity management.
Innovation Solution
Implementing a protective layer at the data source with a dispatcher and services that provide authentication, tokenization, behavioral baselining, and federated identity management, using a data agnostic dispatcher to intercept and inspect communications, and collectors to gather application context for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure perimeter is implemented around the organization to protect data sources, then security against unauthorized access is improved, but device complexity and management cost increase
Solution Approach 1:
The patent introduces a wrapper as an intermediary component that sits between applications and data sources. This wrapper provides authentication, tokenization, and behavioral baselining services, effectively mediating access control without requiring complex perimeter security infrastructure. The wrapper acts as a local security gatekeeper at each data source, simplifying overall security management while maintaining strong protection.
Solution Approach 2:
The security function is segmented and distributed to individual data sources through the wrapper architecture. Instead of implementing a centralized perimeter security system that protects the entire organization, each data source has its own wrapper that independently provides security services. This segmentation reduces the complexity of managing a single large-scale security perimeter while maintaining comprehensive protection across multiple data sources.
2Adaptability or versatility
If conventional security models are used to protect data sources, then basic access control is provided, but tokenization and federated identity management are not supported
Solution Approach 1:
The wrapper is designed as a multi-functional security component that provides authentication, tokenization, behavioral baselining, and federated identity management capabilities. This universal security layer can adapt to different data source types and provide multiple security features through a single integrated solution, enhancing both the versatility of security feature support and the reliability of data protection simultaneously.
3Reliability
If applications are made vulnerable-free through secure perimeter, then data protection is improved, but administration becomes complex and expensive
Solution Approach 1:
The wrapper implements self-service security by autonomously performing authentication, tokenization, and behavioral analysis without requiring manual intervention for each access request. The behavioral baselining feature learns normal access patterns and automatically detects anomalies, reducing the need for complex administrative oversight while maintaining strong data protection.
4Reliability
If a protective layer is implemented at each data source, then security against unauthorized access is improved, but system complexity increases
Solution Approach 1:
The wrapper serves as a standardized intermediary component that can be deployed at each data source with a consistent interface and functionality. This standardization reduces system architecture complexity compared to implementing custom security solutions at each data source, as the same wrapper template can be replicated across multiple data sources with minimal configuration.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method and system for performing at least one service are disclosed. The method and system include receiving a communication for a data source at a wrapper. The wrapper includes a dispatcher and at least one service. The dispatcher receives the communication and is data agnostic. The method and system also include providing the communication from the dispatcher to the data source and to the at least one service. The at least one service inspects the communication and may perform additional functions.