Security Wrapper for Legacy Hosted Software Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy hosted software applications face challenges in achieving and maintaining SOC 2 compliance due to outdated technology and changing security requirements, which often necessitate significant engineering resources.

Innovation Solution

A method that involves specifying a security feature for a software application, analyzing the application to identify instructions for modification, implementing the security feature by modifying the identified instructions, and initiating execution with the modified instructions, thereby enhancing security features such as authentication, authorization, and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security features are added to legacy hosted software applications through traditional modification methods, then security compliance is improved, but device complexity and engineering resources required increase significantly

Engineering Contradiction:
Improvesecurity complianceVSAvoidengineering resources
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component (security wrapper or proxy layer) that sits between the legacy application and the security infrastructure. This intermediary handles security operations such as authentication, authorization, and encryption without requiring direct modification of the legacy application code, thereby improving security compliance while minimizing the complexity burden on the legacy system and reducing engineering resources needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security functionality from the legacy application by creating separate modular security services and components. These segmented security modules can be independently developed, deployed, and managed, allowing security features to be added without complicating the overall system architecture and reducing the engineering burden of integrating security into legacy code.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security features are added to legacy hosted software applications, then security compliance is improved, but the application code must be altered which may affect stability

Engineering Contradiction:
Improvesecurity complianceVSAvoidapplication code stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

By introducing an intermediary security layer, the patent enables security feature integration without directly altering the legacy application code. The intermediary component mediates all security-related interactions, preserving the original application code and its stability while still achieving security compliance through the wrapper's security enforcement mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-configuring security policies, rules, and controls in the intermediary layer before the legacy application executes. This allows security enforcement to occur in advance of actual application operations, ensuring compliance without requiring changes to the application code structure or logic.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional security integration methods are used in legacy applications, then security features are implemented, but the time and resources required for implementation increase

Engineering Contradiction:
Improvesecurity feature implementationVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses copying by creating reusable security templates, configurations, and standardized intermediary components that can be replicated across multiple legacy applications. Instead of custom-building security integration for each application, pre-fabricated security patterns and wrapper templates can be copied and adapted, dramatically reducing implementation time and resource requirements while maintaining security effectiveness.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250200171A1Security enablement for hosted software applications
Publication Date: 2025.06.19 ORCHID SECURITY INC
  • US20250200171A1 patent drawing
  • US20250200171A1 patent drawing
  • US20250200171A1 patent drawing

AI summary

Methods, storage systems and computer program products implement embodiments of the present invention that include specifying a security feature for a software application including application instructions, and then analyzing the software application so as to identify a given application instruction for modification so as to implement the security feature. In response to analyzing the software application, the specified security feature is implemented by modifying the identified application instruction. Finally, execution of the software application with the modified application instruction is initiated so as to perform the specified security feature.