Multi-tier Platform Intermediary Layer Security Buffer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to securing computer systems, such as implementing a demilitarized zone (DMZ), often expose networks to security vulnerabilities due to redirects between service providers and lack effective management of static and dynamic data components.

Innovation Solution

A multi-tier platform with an intermediate layer that interacts with the web layer and registered data sources, determining whether data is static or dynamic, and accessing or generating messages for data components accordingly, thereby enhancing security by buffering application and database layers and managing data access and updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional DMZ is implemented to secure the network perimeter, then network security is improved, but security vulnerabilities are introduced due to redirects between service providers

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediate layer as a mediator between the web layer and application layer. This intermediate layer acts as a security buffer that receives requests from the web layer, determines whether data components are static or dynamic, and selectively accesses stored static data or generates messages for dynamic data without requiring redirects to external service providers. This eliminates the security vulnerabilities associated with traditional DMZ redirects while maintaining network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct layers: web layer, intermediate layer, and application layer. The intermediate layer is further segmented into static data storage and dynamic data processing functions. This segmentation isolates the security-critical components from external redirects while maintaining controlled access paths, thereby improving security without introducing vulnerability points.

Inventive Principle:
Principle #1Segmentation

2Speed

If static data is stored at the intermediate layer to improve access speed, then data access efficiency is improved, but data currency deteriorates without update mechanisms

Engineering Contradiction:
Improvedata access speedVSAvoiddata currency
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The patent implements a dynamic data access mechanism where the intermediate layer determines whether each data component is static or dynamic. For dynamic data components, the system automatically generates messages to registered sources to retrieve current data, ensuring data currency is maintained. This dynamic approach allows the system to adapt to different data types and maintain both speed and currency as needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs periodic message generation to registered sources for updating dynamic data components. This periodic action ensures that static data stored at the intermediate layer is refreshed at appropriate intervals, maintaining data currency while preserving the performance benefits of local storage. The system periodically checks and updates data based on its dynamic nature.

Inventive Principle:
Principle #19Periodic action

3Reliability

If an intermediate layer is introduced to manage data components and improve security, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The intermediate layer is designed as a multi-functional component that performs multiple security and data management functions: determining data component type (static or dynamic), accessing stored static data, generating messages for dynamic data, and managing registered sources. By consolidating these functions into a single universal layer, the patent improves security without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Object-affected harmful factors

If redirects are eliminated to reduce security vulnerabilities, then security is improved, but data access flexibility deteriorates

Engineering Contradiction:
Improvesecurity vulnerabilitiesVSAvoiddata access flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The intermediate layer serves as an intermediary that maintains data access flexibility without requiring external redirects. It manages registered sources internally and can retrieve both static and dynamic data through controlled access paths. This intermediary approach preserves the flexibility to access various data types while eliminating the security vulnerabilities associated with redirects to external service providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9832229B2Multi-tiered protection platform
Publication Date: 2017.11.28 BANK OF AMERICA CORP
  • US9832229B2 patent drawing
  • US9832229B2 patent drawing
  • US9832229B2 patent drawing

AI summary

A multi-tier platform supports a messaging platform. An intermediate layer interacts with a web layer and registered sources of data components, where a registered source may be an application executing on the computer system or an external source of an external service provider. A data request is received at the web layer and is passed to the intermediate layer for requested data, which may comprise one or more data components. The intermediate layer determines the authoritative source for a data component and whether the data component comprises static or dynamic data. If data component comprises dynamic data, the intermediate layer functions as a messaging platform by generating a message to the registered source to access the dynamic data. If the data component comprises static data, the intermediate layer accesses the static data stored at the intermediate layer. The intermediate layer then returns the requested data via the web layer.