Pipeline Handlers Decoupling Security Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in efficiently defending applications across different platforms and stacks against intrusions and rolling out fixes quickly, due to the complexity and high costs associated with engineering efforts.

Innovation Solution

A framework as a service is provided, utilizing pipeline handlers and cubes that run in separate processes from applications, allowing for decentralized management of requests and responses, and enabling the plugging of security and other pipeline handlers and cubes into the infrastructure for flexible and rapid security updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security fixes are implemented directly in application stacks across different platforms, then security reliability is improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security infrastructure into independent pipeline handlers that can be deployed separately from application stacks. Each handler operates as a standalone component in its own process, allowing security functionality to be divided into modular units that can be updated independently without affecting the entire application ecosystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces pipeline handlers as intermediary components between the infrastructure and application stacks. These handlers act as mediators that intercept and process requests/responses, enabling security updates to be rolled out through the infrastructure layer without requiring direct modification of application code across multiple platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security fixes are rolled out across multiple application stacks, then security coverage is improved, but loss of time and implementation cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidrollout time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates universal pipeline handlers that can operate across different application stacks and platforms through a common infrastructure interface. This multi-functional design allows a single security fix implemented in the infrastructure to automatically apply to all connected applications, eliminating the need for separate rollout efforts for each platform or stack.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes pipeline handlers in advance within the infrastructure layer, positioned to intercept requests before they reach application stacks. This preliminary positioning allows security updates to be pre-deployed in the infrastructure and automatically activated across all applications without requiring time-consuming individual installations or configurations.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If pipeline handlers are tightly integrated within application processes, then processing efficiency is improved, but adaptability and ease of updates deteriorate

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidupdate flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments pipeline handlers into separate processes that communicate with applications through standardized interfaces. This segmentation maintains processing efficiency through direct communication channels while simultaneously enabling independent deployment and updates of handlers without requiring application process modifications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables pipeline handlers to operate autonomously in separate processes, self-managing their execution and communication with applications. This self-service capability allows handlers to be updated, restarted, or modified independently without affecting application stability, providing both efficiency and adaptability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9633204B2Method and system for log aggregation
Publication Date: 2017.04.25 PAYPAL INC
  • US9633204B2 patent drawing
  • US9633204B2 patent drawing
  • US9633204B2 patent drawing

AI summary

Systems and methods for aggregating one or more log records are provided. An example method includes receiving an indication that a request has been completed. The method also includes aggregating, at the log aggregator, log records that were created based on processing the request. The log records include a unique identifier associated with the request. The method further includes sending the aggregated log records to the log client.