Proprietary Mediating Entity for Web Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current web service security measures are inadequate against sophisticated malicious attacks due to widespread vulnerabilities in open source and proprietary solutions, with architectural information and security flaws being widely published, leaving information servers defenseless.
Innovation Solution
A proprietary mediating entity is injected between the application server and the information server, enforcing proprietary security protocols to intercept and authenticate requests, thereby separating vulnerabilities and requiring attackers to learn the system's workings before accessing the information server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If open source and proprietary web service solutions are widely used, then interoperability and ease of implementation are improved, but security vulnerabilities increase due to widely available architectural information and security flaws
Solution Approach 1:
The patent introduces a proprietary mediating entity that sits between the application server and information server. This intermediary enforces security protocols and intercepts requests, preventing direct access to the information server. The mediator translates standard web service calls into secured proprietary protocol calls, maintaining interoperability while blocking vulnerabilities from reaching the core system.
Solution Approach 2:
The system architecture is segmented into distinct layers: the public-facing application server using standard web services, the proprietary mediating entity with security enforcement, and the protected information server. This segmentation isolates vulnerabilities in the upper layers from the critical data layer, allowing open source solutions to be used where needed while protecting sensitive operations.
2Reliability
If security patches are implemented after identifying system vulnerabilities, then security measures are improved, but attackers have time to exploit vulnerabilities during the patch development period
Solution Approach 1:
The proprietary mediating entity is configured with pre-established security protocols and authentication mechanisms before any attacks occur. Security policies, encryption keys, and access control rules are set up in advance, eliminating the need for reactive patching. When vulnerabilities are discovered in standard web services, the mediator's pre-configured security layer already protects the information server.
3Reliability
If proprietary security protocols are enforced through a mediating entity, then security is improved, but device complexity and development costs increase
Solution Approach 1:
The complex security enforcement logic is extracted from the core information server and placed in the separate mediating entity. This allows the information server to remain simple and focused on data storage, while the mediator handles all security protocol complexity. The extraction enables independent development and maintenance of security mechanisms without complicating the core system.
4Ease of operation
If attackers gain access to credential repositories through lower security areas, then authentication is bypassed, but this exposes the entire system to compromise
Solution Approach 1:
The mediating entity implements preliminary authentication and authorization checks before any requests reach the information server. Credentials are verified and access rights are validated in the mediator layer, preventing unauthorized access even if lower security areas are compromised. This preliminary security barrier stops attacks before they can reach credential repositories or sensitive data.
Data Source
AI summary
A system for providing information server security in a distributed computing environment achieved by injecting a proprietary mediating entity into the solicitation of service request process via web server between application servers and information servers. The system comprises a computer apparatus, a mediating entity, solicitation for service requests and responses to the solicitations for service requests. The mediating entity is comprised of an application server hosting a proprietary mediating entity client and a mediating entity server, where the proprietary mediating entity client comprises industry-recognized business organization selected security protocols. The information server comprises a database server and a database, the database comprises data that is extracted or stored based on the service request.


