Reverse Proxy Data Encryption Across Frames

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database systems face challenges in securely and efficiently managing sensitive data across multiple frames in an on-demand services environment, leading to potential data breaches and loss of trust among service providers.

Innovation Solution

Implementing a data security and communication mechanism that uses tokenization and encryption, facilitated by a reverse proxy server, to control and protect sensitive data as it traverses frames, ensuring it remains within geographic residency and minimizing exposure to unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is communicated across frames in web applications, then functionality and user experience are improved, but data security deteriorates due to potential leakage

Engineering Contradiction:
Improvedata communication across framesVSAvoiddata leakage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a reverse proxy server as an intermediary component positioned between the web application frames and the data communication layer. This proxy intercepts data transmissions, applies encryption and tokenization, and forwards secured data to destination frames, thereby enabling cross-frame communication while preventing data leakage to unauthorized locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the data communication parameters by changing the state of data from plain text to encrypted and tokenized form. The reverse proxy modifies data characteristics through encryption algorithms and tokenization processes, altering the data's form while maintaining its functionality across frames.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If conventional database systems are used, then data accessibility is simplified, but data security and control over sensitive data deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The reverse proxy server acts as a mediator between database systems and web application frames, intercepting data requests and responses. It applies encryption and tokenization to sensitive data while maintaining database accessibility, thus preserving ease of operation while enhancing security and control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments data into sensitive and non-sensitive portions, applying different security treatments. The reverse proxy identifies and encrypts only the sensitive portions of data while allowing non-sensitive data to pass through unchanged, maintaining accessibility for general operations while securing critical information.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If data encryption is applied, then data security is improved, but data processing complexity increases

Engineering Contradiction:
Improvedata breach riskVSAvoiddata processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The reverse proxy server consolidates encryption and tokenization operations into a single intermediary layer, handling data security transformations automatically without requiring complex processing at each individual frame level. This centralizes complexity in one component while keeping the overall system simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The reverse proxy implements self-service security by automatically detecting, encrypting, and tokenizing data as it passes through the proxy. The system performs security operations autonomously without requiring manual intervention or complex configuration at each data handling point, reducing processing complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10659433B2Encrypting and securing data with reverse proxies across frames in an on-demand services environment
Publication Date: 2020.05.19 SALESFORCE INC
  • US10659433B2 patent drawing
  • US10659433B2 patent drawing
  • US10659433B2 patent drawing

AI summary

In accordance with embodiments, there are provided mechanisms and methods for facilitating protection of data in a database environment in an on-demand services environment according to one embodiment. In one embodiment and by way of example, a method includes detecting, by a first computing device in the database environment, sensitive data associated with a user having access to a second computing device, where the sensitive data is capable of being communicated within a geographic residency. The method may further include performing, by the first computing device, secured communication of the sensitive data between at least one of multiple computing devices and multiple application frames within the geographic residency, wherein the first computing device includes a proxy server that is locally situated within the geographic residency.