Firewall Stub with Inbound Write-Only Directory for Secure Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to ensure secure transfer of critical business data from a customer system to a hosted system without compromising data security, particularly in the context of the SaaS model where robust security is crucial for medium and large enterprises.

Innovation Solution

A system and method involving a stub integrated with a firewall, comprising an inbound write-only directory on the customer system side and an outbound layer on the hosted system side, with a demon that encrypts data in the inbound layer and moves it to the outbound layer for secure access by the hosted system, ensuring only encrypted data is available for upload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data is transferred from customer system to hosted system in SaaS model, then data processing efficiency is improved, but data security is compromised

Engineering Contradiction:
Improvedata processing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting data in advance within the customer system's inbound layer before transfer to the hosted system. The encryption process occurs locally at the source, ensuring data is protected before leaving the customer environment, thus maintaining security while enabling efficient hosted processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption mechanism that acts as a mediator between the customer system and hosted system. The encryption layer serves as a protective intermediary that allows data transfer while maintaining security boundaries, enabling both productivity and reliability requirements to be satisfied.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to protect data during upload, then data security is improved, but processing time is increased

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Encryption is performed as a preliminary action within the customer system's inbound layer before data leaves the customer environment. By pre-encrypting data locally, the patent minimizes the time data is exposed and allows parallel processing of multiple data elements, reducing overall processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption process serves itself by being automatically triggered when data enters the inbound layer. The system self-manages the encryption workflow without requiring manual intervention or complex coordination, streamlining the process and reducing time loss while ensuring consistent security application.

Inventive Principle:
Principle #25Self-service

3Reliability

If a stub with inbound and outbound layers is implemented, then data security is improved, but system complexity is increased

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data transfer system into distinct inbound and outbound layers within the stub structure. The inbound layer handles encryption and the outbound layer handles decryption, creating clear functional separation. This segmentation organizes complexity into manageable, well-defined components that can be independently implemented and maintained.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The stub structure serves multiple functions: it acts as a security boundary, an encryption/decryption gateway, and a data transfer intermediary. By making the stub multi-functional, the patent consolidates several security and transfer operations into a single integrated component, reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8707023B2Secure transfer of business data to a hosted system
Publication Date: 2014.04.22 SAP SE
  • US8707023B2 patent drawing
  • US8707023B2 patent drawing
  • US8707023B2 patent drawing

AI summary

A system and method for uploading data from a customer system to a hosted system is disclosed. A stub is integrated with a firewall between the customer system and the hosted system. The stub includes an inbound layer on the customer system side of the firewall and an outbound layer on the hosted system side of the firewall, and the inbound layer includes a write-only directory. A demon is connected between the inbound layer and the outbound layer of the stub. The demon is configured to recognize newly received data in the write-only directory of the inbound layer, encrypt the newly received data to generate encrypted data, and move the encrypted data to the outbound layer for access by the hosted system.