Dynamic Runtime SOA via ESB Mediator for Secure Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service-oriented architectures (SOA) implemented on publicly available networks face reliability and security issues due to the unrestricted nature of these networks, making business applications susceptible to malicious attacks and unreliable web services.

Innovation Solution

A dynamic runtime service-oriented architecture that incorporates an internal UDDI registry and authentication service to restrict access to approved web services, allowing business applications to select proxy endpoints based on specified policies and characteristics such as reliability and performance, ensuring secure and efficient execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web services are made publicly accessible on open networks, then service availability and accessibility are improved, but security and reliability deteriorate due to unrestricted access and malicious attacks

Engineering Contradiction:
Improveservice accessibilityVSAvoidservice reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an Enterprise Service Bus (ESB) as an intermediary component that sits between the public network and internal web services. The ESB provides a controlled access point that enables public accessibility while maintaining security through centralized authentication, authorization, and service registration mechanisms. This mediator filters and manages all interactions between external clients and internal services, resolving the contradiction between open access and reliable operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If web services are made publicly accessible on open networks, then service availability and accessibility are improved, but security and reliability deteriorate due to malicious attacks

Engineering Contradiction:
Improveservice accessibilityVSAvoidmalicious attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The ESB acts as a protective intermediary that blocks malicious attacks before they reach internal services. It implements security policies, authentication mechanisms, and access control lists that filter harmful requests while allowing legitimate traffic to pass through, thus maintaining service accessibility while protecting against malicious factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks and authentication before allowing access to web services. The ESB validates service endpoints, checks client credentials, and verifies access permissions in advance, preventing malicious attacks before they can affect the system. This preliminary action ensures that only authorized requests reach the services.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple proxy endpoints are made available for web services, then service versatility and adaptability are improved, but system complexity increases

Engineering Contradiction:
Improveservice versatilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The ESB provides a universal interface that handles multiple proxy endpoints through a single standardized mechanism. Rather than implementing separate handling logic for each endpoint, the ESB offers multi-functional capabilities that manage diverse service access requests through common authentication, routing, and policy enforcement mechanisms, reducing system complexity while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The ESB mediates between multiple proxy endpoints and internal services, providing a unified management layer that abstracts the complexity of handling multiple endpoints. It centralizes the management of service registrations, endpoint mappings, and access policies, making the system more adaptable without proportionally increasing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If unrestricted access is allowed to web services, then ease of access is improved, but security control deteriorates

Engineering Contradiction:
Improveaccess easeVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The ESB serves as a security intermediary that maintains ease of access through standardized interfaces while enforcing strict security controls. It provides a user-friendly service registration and access mechanism that simplifies operations, simultaneously implementing comprehensive security policies, authentication, and authorization that ensure reliable security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms through the ESB that monitor and control access to web services. It tracks service usage, validates access requests, and enforces security policies in real-time, providing continuous feedback that maintains both ease of access for legitimate users and strict security control against unauthorized access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7783782B2Dynamic runtime service oriented architecture
Publication Date: 2010.08.24 RAYTHEON CO
  • US7783782B2 patent drawing
  • US7783782B2 patent drawing
  • US7783782B2 patent drawing

AI summary

According to one embodiment, a dynamic access method for a service oriented architecture includes receiving a number of proxy endpoints from a business application, selecting one proxy endpoint from among the multiple proxy endpoints, and transmitting a request to an enterprise service bus (ESB). The request includes the one proxy endpoint for accessing the particular web service that it references.