Reverse Proxy Data Encryption Across Frames
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional database systems face challenges in securely and efficiently managing sensitive data across multiple frames in an on-demand services environment, leading to potential data breaches and loss of trust among service providers.
Innovation Solution
Implementing a data security and communication mechanism that uses tokenization and encryption, facilitated by a reverse proxy server, to control and protect sensitive data as it traverses frames, ensuring it remains within geographic residency and minimizing exposure to unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is communicated across frames in web applications, then functionality and user experience are improved, but data security deteriorates due to potential leakage
Solution Approach 1:
The patent introduces a reverse proxy server as an intermediary component positioned between the web application frames and the data communication layer. This proxy intercepts data transmissions, applies encryption and tokenization, and forwards secured data to destination frames, thereby enabling cross-frame communication while preventing data leakage to unauthorized locations.
Solution Approach 2:
The patent transforms the data communication parameters by changing the state of data from plain text to encrypted and tokenized form. The reverse proxy modifies data characteristics through encryption algorithms and tokenization processes, altering the data's form while maintaining its functionality across frames.
2Ease of operation
If conventional database systems are used, then data accessibility is simplified, but data security and control over sensitive data deteriorates
Solution Approach 1:
The reverse proxy server acts as a mediator between database systems and web application frames, intercepting data requests and responses. It applies encryption and tokenization to sensitive data while maintaining database accessibility, thus preserving ease of operation while enhancing security and control.
Solution Approach 2:
The patent segments data into sensitive and non-sensitive portions, applying different security treatments. The reverse proxy identifies and encrypts only the sensitive portions of data while allowing non-sensitive data to pass through unchanged, maintaining accessibility for general operations while securing critical information.
3Object-affected harmful factors
If data encryption is applied, then data security is improved, but data processing complexity increases
Solution Approach 1:
The reverse proxy server consolidates encryption and tokenization operations into a single intermediary layer, handling data security transformations automatically without requiring complex processing at each individual frame level. This centralizes complexity in one component while keeping the overall system simple.
Solution Approach 2:
The reverse proxy implements self-service security by automatically detecting, encrypting, and tokenizing data as it passes through the proxy. The system performs security operations autonomously without requiring manual intervention or complex configuration at each data handling point, reducing processing complexity.
Data Source
AI summary
In accordance with embodiments, there are provided mechanisms and methods for facilitating protection of data in a database environment in an on-demand services environment according to one embodiment. In one embodiment and by way of example, a method includes detecting, by a first computing device in the database environment, sensitive data associated with a user having access to a second computing device, where the sensitive data is capable of being communicated within a geographic residency. The method may further include performing, by the first computing device, secured communication of the sensitive data between at least one of multiple computing devices and multiple application frames within the geographic residency, wherein the first computing device includes a proxy server that is locally situated within the geographic residency.


