Security Control Governance via Intermediary Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web application firewalls are insufficient in providing governance over validators within systems, as they do not ensure that security controls are effectively executed during runtime when handling external and unvalidated data, leading to potential security vulnerabilities and increased attack surfaces.

Innovation Solution

A system and method that intercepts data transmitted to applications, identifies predetermined security controls, and compares them with actual security controls to ensure validation, allowing access only when there is a match, and generates error messages for mismatches or unassociated data, using a reverse proxy and digital signatures to verify the execution of security controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If web application firewalls are used to filter and reduce attack surfaces, then known vulnerabilities are stopped, but governance of validators within systems is not provided and uncertainty exists as to whether validators have actually done what they should have done

Engineering Contradiction:
Improvesecurity control executionVSAvoidsystem governance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a governor as an intermediary component that sits between the web application firewall and the internal validators. The governor intercepts data, identifies required security controls, and verifies that validators have executed them properly. This intermediary resolves the contradiction by providing the missing governance layer without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the governor receives evidence from validators about whether security controls were executed. Digital signatures and other proof mechanisms provide feedback loops that confirm validator execution, allowing the system to verify security control compliance and resolve the uncertainty about whether validators did what they should have done.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If validators are implemented within applications to handle external data, then data validation capability is provided, but there is no governance to make sure that the validators have actually done what they should have done

Engineering Contradiction:
Improvedata validation capabilityVSAvoidvalidator execution verification
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The governor performs preliminary actions by identifying required security controls and their expected behavior before data processing occurs. It establishes the governance framework and verification criteria in advance, enabling precise measurement of validator execution against predetermined security requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual verification mechanisms with automated digital signature validation and cryptographic proof systems. This substitution enables precise, automated verification of validator execution without requiring manual inspection, resolving the measurement precision issue through technological substitution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If web application firewalls filter incoming data, then attack surfaces are reduced, but they are not sufficient to provide governance of validators and ensure security controls are executed during runtime

Engineering Contradiction:
Improveattack surfaceVSAvoidsecurity control execution assurance
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The security architecture is segmented into distinct layers: the web application firewall for initial filtering, the governor for governance and verification, and the validators for data processing. This segmentation allows each component to specialize in its function while the governor provides the missing execution assurance layer that the firewall alone cannot provide.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a composite security architecture combining multiple components (firewall, governor, validators, digital signature mechanisms) into an integrated security solution. This composite approach provides both attack surface reduction from the firewall and execution assurance from the governor, resolving the contradiction by combining complementary security mechanisms.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS11757926B1Systems and methods of web application security control governance
Publication Date: 2023.09.12 WELLS FARGO BANK NA
  • US11757926B1 patent drawing
  • US11757926B1 patent drawing
  • US11757926B1 patent drawing

AI summary

Security control governance can significantly thwart attacks from external data. Inline processing can reduce and limit attack surfaces and enforce validators preselected for applications. Processing and saving data can be controlled based on confirmation that an application has implemented requisite security controls to validate data. The applicability of such a technical improvement to system operations improves the technical operations of most any system with one or more applications that accept potential attack surface items, such as data, data fields, or data types, from “open” or uncontrolled sources.