Security Annotation in Class Diagrams for Web Service Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring web service security settings in web service applications is cumbersome due to the large number of setting items, requiring both application developers and security developers to collaborate effectively, yet application developers lack the necessary technical knowledge to correctly configure security requirements.

Innovation Solution

A software development apparatus that allows application developers to define security requirements using security annotations in a class diagram, which are then transformed into a configuration model based on a markup language, enabling security developers to create a configuration file that satisfies these requirements, facilitating collaboration and accurate configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application developers directly configure web service security settings using existing editors, then security configuration can be performed, but the process becomes very cumbersome due to the large number of setting items and lack of security technical knowledge

Engineering Contradiction:
Improveease of security configurationVSAvoidcomplexity of security settings
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a security requirement specification as an intermediary document between application developers and security settings. This specification serves as a mediator that translates high-level security requirements into detailed configuration parameters, reducing the cognitive burden on developers while maintaining security accuracy through structured requirement documentation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security configuration process into two distinct phases: first, application developers define security requirements at a high level without dealing with implementation details; second, security specialists or automated tools translate these requirements into specific configuration settings. This segmentation allows each participant to work at their appropriate expertise level, reducing overall complexity

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If security developers configure web service security settings directly, then accurate security configuration can be achieved, but collaboration with application developers becomes difficult due to knowledge gaps

Engineering Contradiction:
Improveaccuracy of security configurationVSAvoidcollaboration capability
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The security requirement specification acts as a common intermediary language that both application developers and security developers can understand and work with. It bridges the knowledge gap by providing a structured format that captures security needs in terms that are accessible to application developers while containing sufficient detail for security developers to implement accurate configurations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security requirement specification format that serves multiple functions: it documents security requirements for application developers to understand, provides a translation blueprint for security developers, and enables systematic collaboration between both parties. This multi-functional document enhances both accuracy and collaboration capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If detailed security settings are exposed to application developers, then complete control over security configuration is achieved, but the complexity of the configuration process increases significantly

Engineering Contradiction:
Improvecontrol over security configurationVSAvoidease of configuration process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments security configuration control into two layers: a high-level requirement specification layer that application developers control, and a detailed implementation layer that remains abstracted away. This segmentation allows developers to maintain control over security requirements without being overwhelmed by implementation complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the complex detailed security settings from the application development process and places them in a separate translation phase. Application developers only need to specify high-level requirements, while the detailed configuration parameters are extracted and handled separately by security specialists or automated tools, reducing the operational burden on developers

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8386998B2Software development apparatus for model that requires security
Publication Date: 2013.02.26 SERVICENOW INC
  • US8386998B2 patent drawing
  • US8386998B2 patent drawing
  • US8386998B2 patent drawing

AI summary

A software development apparatus for developing application software based on an object model that requires security in a web service application is provided. The software development apparatus includes a display unit that displays, in a class diagram of the application software, security annotation for adding security requirements for a service, input means for inputting the security annotation, transforming means for transforming the class diagram into a configuration model based on a markup language, and configuration-file creating means for creating a configuration file based on a markup language by serializing the configuration model based on a markup language. The security annotation includes the security requirements and a token class of a security token that is a certificate for declaring identity of a client to a server.