Federated Web Service Security Provider Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current federated web service models require manual redeployment of applications to incorporate new security mechanisms or business logic, leading to increased costs and complexity due to the lack of automated management of security lifecycle and internal functionality.

Innovation Solution

A deployment tool and method that separates security mechanisms from business logic, using software components within a container to generate and process messages according to federation protocols, allowing for automated management of security lifecycle and simplified implementation of federation protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual redeployment is used to incorporate new security mechanisms, then security can be updated, but costs and complexity increase

Engineering Contradiction:
Improvesecurity update capabilityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the web service application into distinct modules: business logic components and security mechanism components. This segmentation allows security mechanisms to be independently deployed, updated, and managed without affecting the core business logic, thereby reducing management complexity while maintaining security update capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a deployment tool as an intermediary that automates the process of integrating new security mechanisms and business logic. This intermediary handles the complexity of coordination, configuration, and deployment, eliminating the need for manual redeployment while ensuring security updates are properly implemented.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security mechanisms are integrated into business logic, then security can be enforced, but automation of security lifecycle management is lost

Engineering Contradiction:
Improvesecurity enforcementVSAvoidsecurity lifecycle automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent separates security mechanisms from business logic into independent deployable units. The business logic remains automated and unchanged, while security mechanisms are managed separately through automated deployment processes. This segmentation enables both security enforcement and automation of the security lifecycle.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The deployment tool provides self-service automation for security lifecycle management. It automatically handles the integration, deployment, and updating of security mechanisms without requiring manual intervention in the business logic, thereby maintaining both security enforcement and automation.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If federated model is implemented, then user privacy and convenience improve, but security management complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The deployment tool acts as an intermediary that automates the complex security management tasks required by the federated model. It handles protocol implementation, security mechanism coordination, and lifecycle management, thereby maintaining user convenience while reducing the operational complexity of security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service automation where the deployment tool automatically manages security mechanisms, configurations, and updates. This eliminates the need for manual security management interventions while preserving the federated model's user privacy and convenience benefits.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8275985B1Infrastructure to secure federated web services
Publication Date: 2012.09.25 ORACLE AMERICAN INC
  • US8275985B1 patent drawing
  • US8275985B1 patent drawing
  • US8275985B1 patent drawing

AI summary

A federation participant in communication with other participants of a federation according to a federation protocol is described. The web service participant includes business logic and a security provider. The business logic implements a web service consumer (WSC) or a web service provider (WSP) business logic. The business logic is configured to generate an outgoing message for transmission to a recipient and receive an incoming message from the recipient, the recipient being a WSP if the business logic is a WSC business logic and a WSC if the business logic is a WSP business logic. The security provider is configured to receive the generated messages and apply header information to the outgoing message according to the federation protocol to form a modified outgoing message. The security provider then transmits the modified outgoing message to the recipient. Methods of operation for the WSC and WSP are also described.