Platform-Independent Security Token for Heterogeneous Application Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous application environments, disparate secure applications struggle to communicate directly due to format conversion requirements for security information, necessitating labor-intensive and costly converter development, and repetitive authentication and authorization processes.

Innovation Solution

A system utilizing a security application program interface, authentication authority, data store, and application program interfaces to generate and validate tokens in a platform-independent format, such as XML or SAML, allowing secure communication between disparate applications without human intervention and eliminating the need for format conversion and repetitive authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary authentication products are used for each application, then security credential validation is reliable, but device complexity and integration effort increase significantly

Engineering Contradiction:
Improvesecurity credential validationVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication system where a single authentication authority and token format (XML/SAML) serve multiple disparate applications across different platforms (J2EE, CORBA, .NET). This eliminates the need for separate proprietary authentication products for each application, reducing integration complexity while maintaining security validation reliability through centralized token issuance and verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary authentication authority that mediates between client applications and server applications. This intermediary issues standardized tokens that facilitate secure communication between disparate applications without requiring direct integration between them, thereby reducing device complexity while preserving security credential validation through the intermediary's verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If format conversion is implemented for security information between applications, then communication between disparate applications is enabled, but development time and costs increase

Engineering Contradiction:
Improveapplication compatibilityVSAvoidconverter development time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent enforces homogeneity by requiring all applications to use a standardized XML-based token format for security credential exchange. This eliminates the need for format conversion between disparate applications, as all systems communicate using the same homogeneous format. The authentication authority issues tokens in this standardized format, enabling direct compatibility without conversion overhead.

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The standardized XML/SAML token format serves as a universal intermediary that can be used across multiple application platforms and protocols. This single format replaces the need for multiple format conversion mechanisms, reducing development time while maintaining adaptability to different application environments through the universality of the token standard.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If repetitive authentication processes are required for each application access, then security validation is thorough, but operational efficiency decreases

Engineering Contradiction:
Improvesecurity validationVSAvoidapplication access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication where the authentication authority validates security credentials once and issues a token that contains the authentication result. This preliminary action eliminates the need for repetitive authentication processes when accessing multiple applications. The token, issued in advance, carries the authentication information needed for subsequent access requests, maintaining security validation while improving operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables continuous secure access by allowing applications to present the authentication token for multiple subsequent requests without re-authentication. This continuity of useful action maintains thorough security validation through token verification while eliminating repetitive authentication processes, thereby improving application access efficiency without compromising security.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS7823192B1Application-to-application security in enterprise security services
Publication Date: 2010.10.26 T MOBILE INNOVATIONS LLC
  • US7823192B1 patent drawing
  • US7823192B1 patent drawing
  • US7823192B1 patent drawing

AI summary

The present system allows disparate secure applications to communicate directly with one another in a heterogeneous application environment by providing for the creation of tokens that can be passed between the applications without human intervention. Security information is passed between applications in the form of a token with a string data type. Since a string is a primitive data type, it can be recognized by a large number of applications and interfaces. The token has no header and therefore no application-specific header configuration, making it platform and technology independent. This eliminates the need for conversion of security information between different formats. The use of tokens also eliminates the need for an application to be authenticated and authorized every time it sends a message to another application. Instead of a permanent context or session, a context is created with every invocation from one application to another.