Proprietary Mediating Entity for Web Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web service security measures are inadequate against sophisticated malicious attacks due to widespread vulnerabilities in open source and proprietary solutions, with architectural information and security flaws being widely published, leaving information servers defenseless.

Innovation Solution

A proprietary mediating entity is injected between the application server and the information server, enforcing proprietary security protocols to intercept and authenticate requests, thereby separating vulnerabilities and requiring attackers to learn the system's workings before accessing the information server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If open source and proprietary web service solutions are widely used, then interoperability and ease of implementation are improved, but security vulnerabilities increase due to widely available architectural information and security flaws

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proprietary mediating entity that sits between the application server and information server. This intermediary enforces security protocols and intercepts requests, preventing direct access to the information server. The mediator translates standard web service calls into secured proprietary protocol calls, maintaining interoperability while blocking vulnerabilities from reaching the core system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system architecture is segmented into distinct layers: the public-facing application server using standard web services, the proprietary mediating entity with security enforcement, and the protected information server. This segmentation isolates vulnerabilities in the upper layers from the critical data layer, allowing open source solutions to be used where needed while protecting sensitive operations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security patches are implemented after identifying system vulnerabilities, then security measures are improved, but attackers have time to exploit vulnerabilities during the patch development period

Engineering Contradiction:
Improvesecurity measuresVSAvoidtime between vulnerability identification and patch implementation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The proprietary mediating entity is configured with pre-established security protocols and authentication mechanisms before any attacks occur. Security policies, encryption keys, and access control rules are set up in advance, eliminating the need for reactive patching. When vulnerabilities are discovered in standard web services, the mediator's pre-configured security layer already protects the information server.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If proprietary security protocols are enforced through a mediating entity, then security is improved, but device complexity and development costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex security enforcement logic is extracted from the core information server and placed in the separate mediating entity. This allows the information server to remain simple and focused on data storage, while the mediator handles all security protocol complexity. The extraction enables independent development and maintenance of security mechanisms without complicating the core system.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If attackers gain access to credential repositories through lower security areas, then authentication is bypassed, but this exposes the entire system to compromise

Engineering Contradiction:
Improveauthentication processVSAvoidsystem compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The mediating entity implements preliminary authentication and authorization checks before any requests reach the information server. Credentials are verified and access rights are validated in the mediator layer, preventing unauthorized access even if lower security areas are compromised. This preliminary security barrier stops attacks before they can reach credential repositories or sensitive data.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10158618B2System and method for securely accessing data through web applications
Publication Date: 2018.12.18 NUESOFT TECH
  • US10158618B2 patent drawing
  • US10158618B2 patent drawing
  • US10158618B2 patent drawing

AI summary

A system for providing information server security in a distributed computing environment achieved by injecting a proprietary mediating entity into the solicitation of service request process via web server between application servers and information servers. The system comprises a computer apparatus, a mediating entity, solicitation for service requests and responses to the solicitations for service requests. The mediating entity is comprised of an application server hosting a proprietary mediating entity client and a mediating entity server, where the proprietary mediating entity client comprises industry-recognized business organization selected security protocols. The information server comprises a database server and a database, the database comprises data that is extracted or stored based on the service request.