Intermediary Service Component Authentication Data Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Authentication data is vulnerable to corruption and attacks when transmitted through an intermediary service component from a consumer system to a provider system, as it cannot be discarded after the authentication action is completed, compromising security.

Innovation Solution

An intermediary service component processes and securely propagates authentication data by performing authentication actions, generating digests, and creating new assertions with attester signatures and certificates, ensuring the data's integrity and security throughout the transmission process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication data is transmitted through an intermediary service component, then the consumer system can access services from the provider system, but the authentication data becomes vulnerable to corruption and attacks

Engineering Contradiction:
Improveservice access capabilityVSAvoidauthentication data security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies the intermediary principle by introducing a secure authentication data propagation mechanism within the intermediary service component. The intermediary component receives authentication data from the consumer system, maintains it securely in memory, and propagates it to the provider system without exposing it to external attacks. This resolves the contradiction by enabling service access through the intermediary while protecting the authentication data from corruption and attacks during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication data handling process into distinct secure operations: reception at the consumer interface, secure storage in memory, processing by the service logic, and controlled propagation to the provider interface. This segmentation isolates the authentication data within secure boundaries at each stage, preventing attacks while maintaining the necessary service access functionality.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If authentication data is retained in the intermediary system for service access, then service functionality is enabled, but the data remains vulnerable to attacks during transmission

Engineering Contradiction:
Improveservice operation capabilityVSAvoidauthentication data vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies beforehand cushioning by implementing preventive security measures before authentication data becomes vulnerable. The intermediary service component establishes secure reception protocols at the consumer interface, implements protected storage mechanisms in memory, and prepares controlled propagation pathways to the provider interface before any transmission occurs. This preemptive approach enables smooth service operation while cushioning the authentication data from attacks and corruption throughout the process.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Productivity

If authentication data flows through the intermediary system, then service provision is enabled, but security precautions must be relaxed compared to direct authentication

Engineering Contradiction:
Improveservice provision efficiencyVSAvoidauthentication security level
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses the intermediary principle to maintain high security levels while enabling efficient service provision. The intermediary service component acts as a secure conduit that receives authentication data from the consumer system, maintains it in protected memory, and propagates it to the provider system without requiring the consumer to re-authenticate. This approach preserves authentication security comparable to direct authentication while significantly improving service provision efficiency by eliminating redundant authentication steps.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8302160B2Propagation of authentication data in an intermediary service component
Publication Date: 2012.10.30 SAP SE
  • US8302160B2 patent drawing
  • US8302160B2 patent drawing
  • US8302160B2 patent drawing

AI summary

A system may include a sender computing system, an intermediary service component, and a receiver computing system. The sender computing system may transmit a message and authentication data, and the intermediary service component may receive the message and the authentication data from the sender computing system, process the message, and transmit the authentication data and the processed message. The receiver computing system may receive the authentication data and the processed message.