Security Wrapper for Legacy Hosted Software Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy hosted software applications face challenges in achieving and maintaining SOC 2 compliance due to outdated technology and changing security requirements, which often necessitate significant engineering resources.
Innovation Solution
A method that involves specifying a security feature for a software application, analyzing the application to identify instructions for modification, implementing the security feature by modifying the identified instructions, and initiating execution with the modified instructions, thereby enhancing security features such as authentication, authorization, and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security features are added to legacy hosted software applications through traditional modification methods, then security compliance is improved, but device complexity and engineering resources required increase significantly
Solution Approach 1:
The patent introduces an intermediary component (security wrapper or proxy layer) that sits between the legacy application and the security infrastructure. This intermediary handles security operations such as authentication, authorization, and encryption without requiring direct modification of the legacy application code, thereby improving security compliance while minimizing the complexity burden on the legacy system and reducing engineering resources needed.
Solution Approach 2:
The patent segments the security functionality from the legacy application by creating separate modular security services and components. These segmented security modules can be independently developed, deployed, and managed, allowing security features to be added without complicating the overall system architecture and reducing the engineering burden of integrating security into legacy code.
2Reliability
If security features are added to legacy hosted software applications, then security compliance is improved, but the application code must be altered which may affect stability
Solution Approach 1:
By introducing an intermediary security layer, the patent enables security feature integration without directly altering the legacy application code. The intermediary component mediates all security-related interactions, preserving the original application code and its stability while still achieving security compliance through the wrapper's security enforcement mechanisms.
Solution Approach 2:
The patent implements preliminary action by pre-configuring security policies, rules, and controls in the intermediary layer before the legacy application executes. This allows security enforcement to occur in advance of actual application operations, ensuring compliance without requiring changes to the application code structure or logic.
3Reliability
If traditional security integration methods are used in legacy applications, then security features are implemented, but the time and resources required for implementation increase
Solution Approach 1:
The patent uses copying by creating reusable security templates, configurations, and standardized intermediary components that can be replicated across multiple legacy applications. Instead of custom-building security integration for each application, pre-fabricated security patterns and wrapper templates can be copied and adapted, dramatically reducing implementation time and resource requirements while maintaining security effectiveness.
Data Source
AI summary
Methods, storage systems and computer program products implement embodiments of the present invention that include specifying a security feature for a software application including application instructions, and then analyzing the software application so as to identify a given application instruction for modification so as to implement the security feature. In response to analyzing the software application, the specified security feature is implemented by modifying the identified application instruction. Finally, execution of the software application with the modified application instruction is initiated so as to perform the specified security feature.


