Data-Source Protective Wrapper for Application Access Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security models protect data and electronic assets by providing a secure perimeter around an organization, but applications remain vulnerable, and data sources like databases lack configurations for security measures such as tokenization and federated identity management, making them susceptible to unauthorized data access and administration complex and expensive.
Innovation Solution
Implementing a protective layer at the data source with a wrapper that includes a dispatcher and various services to authenticate, tokenize, and manage access, using behavioral baselining and federated identity management to secure data sources and applications, while allowing seamless integration with diverse data sources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure perimeter is provided around an organization to protect data and electronic assets, then security is improved, but administration becomes complex and expensive
Solution Approach 1:
The patent introduces a wrapper as an intermediary component that sits between applications and data sources. This wrapper handles security functions (authentication, authorization, tokenization) centrally, eliminating the need for complex perimeter security administration. The wrapper mediates all access requests to data sources, providing security without requiring complex organizational perimeter management.
Solution Approach 2:
The patent extracts security functionality from the traditional perimeter security model and consolidates it into a dedicated wrapper component. By taking out security functions (authentication, tokenization, access control) from the general perimeter infrastructure and placing them in a specialized wrapper at the data source level, the system achieves security with reduced administrative complexity.
2Reliability
If conventional security models are used with a secure perimeter, then organizational assets are protected, but data sources remain vulnerable to unauthorized access
Solution Approach 1:
The patent segments security protection into two layers: (1) traditional perimeter security for organizational assets, and (2) a wrapper-based security layer specifically for data sources. This segmentation allows each layer to address specific vulnerabilities - perimeter security protects the organization boundary while the wrapper protects data sources from application-level attacks, SQL injection, and unauthorized access.
Solution Approach 2:
The wrapper provides beforehand cushioning by implementing security measures before data sources are exposed to applications. The wrapper pre-authenticates requests, validates queries, and tokenizes sensitive data before they reach the data source, cushioning the data source from potential attacks and unauthorized access attempts.
3Reliability
If data sources are configured with security measures like tokenization and federated identity management, then data security is improved, but device complexity and cost increase
Solution Approach 1:
The wrapper implements self-service by automatically handling tokenization, authentication, and authorization without requiring manual configuration of each data source. The wrapper autonomously manages security credentials, performs behavioral baselining, and enforces access policies, eliminating the need for complex manual configuration of tokenization and federated identity management at each data source.
Solution Approach 2:
The wrapper provides universal security functionality that works across multiple data sources with different configurations. Instead of configuring security measures individually for each data source, the wrapper implements a unified security framework that handles tokenization, authentication, and authorization universally across all connected data sources, reducing configuration complexity and cost.
4Ease of operation
If applications are allowed direct access to data sources, then ease of operation is improved, but security is compromised
Solution Approach 1:
The wrapper acts as an intermediary that applications use to access data sources. Applications continue to operate with ease by sending requests to the wrapper using standard protocols, while the wrapper handles security concerns. This intermediary approach maintains application simplicity while enforcing security policies, authentication, and authorization before requests reach data sources.
Solution Approach 2:
The wrapper performs preliminary security actions (authentication, authorization, query validation) before allowing applications to access data sources. By completing security checks in advance, the wrapper enables applications to operate freely without security concerns, as all security requirements are satisfied beforehand by the wrapper.
Data Source
AI summary
A method and system for performing at least one service are disclosed. The method and system include receiving a communication for a data source at a wrapper. The wrapper includes a dispatcher and at least one service. The dispatcher receives the communication and is data agnostic. The method and system also include providing the communication from the dispatcher to the data source and to the at least one service. The at least one service inspects the communication and may perform additional functions.


