Proxy Server Application for Network Site Control Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online merchants face challenges in customizing their network sites when using third-party electronic commerce hosting due to compliance with Payment Card Industry Data Security Standards (PCI DSS) and other security standards, which restricts their control and flexibility.

Innovation Solution

Implementing a proxy server application that separates control of network sites, allowing merchants to manage certain portions themselves while ensuring compliance with security standards, and enables seamless migration between hosting providers by routing requests through a proxy server application external to the trusted network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If merchants use third-party electronic commerce hosting to ensure PCI DSS compliance, then security compliance is improved, but flexibility in customizing network sites deteriorates

Engineering Contradiction:
ImprovePCI DSS complianceVSAvoidcustomization flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments control into two distinct parts: a hosted portion managed by the third-party provider for PCI DSS compliance, and a self-managed portion allowing merchant customization. This segmentation enables merchants to customize their network sites while the provider maintains security compliance through separate control domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a proxy server as an intermediary between the hosted and self-managed portions. The proxy server receives requests, determines which portion to serve, and routes traffic appropriately. This intermediary enables seamless integration of both controlled and customizable portions without compromising security compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If merchants use self-managed electronic commerce platforms for full customization control, then customization flexibility is improved, but security compliance burden increases

Engineering Contradiction:
Improvecustomization flexibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the electronic commerce platform into compliance-critical functions managed by the provider and customization functions managed by the merchant. This segmentation allows merchants to focus only on customization aspects without bearing the burden of maintaining PCI DSS compliance for security-critical operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables merchants to self-manage their customizable portions of the network site through direct access and control interfaces. This self-service capability allows merchants to customize their sites according to their specific needs while the provider automatically maintains security compliance for the hosted portion.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If merchants migrate network sites between hosting providers using traditional methods, then hosting provider switching is possible, but propagation delays and caching issues occur

Engineering Contradiction:
Improvehosting provider switching capabilityVSAvoidmigration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent uses a proxy server as an intermediary that can be reconfigured to point to different hosting providers. During migration, the proxy server maintains a consistent entry point for users while backend routing changes occur, eliminating propagation delays associated with DNS changes and avoiding caching issues by maintaining the same network address.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables seamless migration by maintaining a proxy server configuration that can copy or replicate routing rules across different hosting providers. This allows the merchant to switch providers without changing the public-facing network site address, avoiding the need for DNS propagation and cache invalidation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10013691B1Separating control of network sites
Publication Date: 2018.07.03 AMAZON TECH INC
  • US10013691B1 patent drawing
  • US10013691B1 patent drawing
  • US10013691B1 patent drawing

AI summary

Disclosed are various embodiments for separating control of network sites through the use of a proxy server application. A request for network content is received from a computing device. The network content is hosted by an organization on behalf of a customer. The network content is requested from one application on a trusted network that is subject to security supervision by the organization when the network content is determined to correspond to a secured portion of a network site. The network content is instead requested from another application managed by the customer on an untrusted network that is not subject to security supervision by the organization when the network content is determined to correspond to an unsecured portion of the network site. The network content is then sent to the computing device.