Data-Source Protective Wrapper for Application Access Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security models protect data and electronic assets by providing a secure perimeter around an organization, but applications remain vulnerable, and data sources like databases lack configurations for security measures such as tokenization and federated identity management, making them susceptible to unauthorized data access and administration complex and expensive.

Innovation Solution

Implementing a protective layer at the data source with a wrapper that includes a dispatcher and various services to authenticate, tokenize, and manage access, using behavioral baselining and federated identity management to secure data sources and applications, while allowing seamless integration with diverse data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure perimeter is provided around an organization to protect data and electronic assets, then security is improved, but administration becomes complex and expensive

Engineering Contradiction:
Improvedata securityVSAvoidadministration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a wrapper as an intermediary component that sits between applications and data sources. This wrapper handles security functions (authentication, authorization, tokenization) centrally, eliminating the need for complex perimeter security administration. The wrapper mediates all access requests to data sources, providing security without requiring complex organizational perimeter management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts security functionality from the traditional perimeter security model and consolidates it into a dedicated wrapper component. By taking out security functions (authentication, tokenization, access control) from the general perimeter infrastructure and placing them in a specialized wrapper at the data source level, the system achieves security with reduced administrative complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If conventional security models are used with a secure perimeter, then organizational assets are protected, but data sources remain vulnerable to unauthorized access

Engineering Contradiction:
Improveorganizational asset protectionVSAvoiddata source vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security protection into two layers: (1) traditional perimeter security for organizational assets, and (2) a wrapper-based security layer specifically for data sources. This segmentation allows each layer to address specific vulnerabilities - perimeter security protects the organization boundary while the wrapper protects data sources from application-level attacks, SQL injection, and unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The wrapper provides beforehand cushioning by implementing security measures before data sources are exposed to applications. The wrapper pre-authenticates requests, validates queries, and tokenizes sensitive data before they reach the data source, cushioning the data source from potential attacks and unauthorized access attempts.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If data sources are configured with security measures like tokenization and federated identity management, then data security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wrapper implements self-service by automatically handling tokenization, authentication, and authorization without requiring manual configuration of each data source. The wrapper autonomously manages security credentials, performs behavioral baselining, and enforces access policies, eliminating the need for complex manual configuration of tokenization and federated identity management at each data source.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The wrapper provides universal security functionality that works across multiple data sources with different configurations. Instead of configuring security measures individually for each data source, the wrapper implements a unified security framework that handles tokenization, authentication, and authorization universally across all connected data sources, reducing configuration complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If applications are allowed direct access to data sources, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improveapplication accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The wrapper acts as an intermediary that applications use to access data sources. Applications continue to operate with ease by sending requests to the wrapper using standard protocols, while the wrapper handles security concerns. This intermediary approach maintains application simplicity while enforcing security policies, authentication, and authorization before requests reach data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The wrapper performs preliminary security actions (authentication, authorization, query validation) before allowing applications to access data sources. By completing security checks in advance, the wrapper enables applications to operate freely without security concerns, as all security requirements are satisfied beforehand by the wrapper.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12423455B2Architecture having a protective layer at the data source
Publication Date: 2025.09.23 CYRAL INC
  • US12423455B2 patent drawing
  • US12423455B2 patent drawing
  • US12423455B2 patent drawing

AI summary

A method and system for performing at least one service are disclosed. The method and system include receiving a communication for a data source at a wrapper. The wrapper includes a dispatcher and at least one service. The dispatcher receives the communication and is data agnostic. The method and system also include providing the communication from the dispatcher to the data source and to the at least one service. The at least one service inspects the communication and may perform additional functions.