Sidecar Proxy for Data Source Security and Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security models are inadequate in protecting data sources from unauthorized access and are often complex and expensive to administer, with a lack of support for advanced security features like tokenization and federated identity management in conventional databases and modern data repositories.
Innovation Solution
A sidecar system is introduced that provides a protective layer around data sources, featuring a dispatcher and various services for authentication, tokenization, and behavioral baselining, which intercepts and inspects communications to ensure only authorized access, using a data-agnostic approach that can be deployed across different data sources without requiring changes to existing infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security models with secure perimeters are used, then data sources and servers are protected, but administration becomes complex and expensive
Solution Approach 1:
The patent introduces sidecar proxies as intermediary components that are deployed alongside data sources and servers. These sidecars handle security functions locally, acting as mediators between the secure perimeter architecture and individual data sources. This distributes security administration tasks from a centralized complex system to multiple simple, standardized sidecar components, reducing overall administrative complexity while maintaining protection.
Solution Approach 2:
The security architecture is segmented into distributed sidecar proxies deployed at each data source location rather than a single centralized security perimeter. Each sidecar is a independent, standardized component that handles security for its local data source. This segmentation transforms the complex administration of a unified secure perimeter into simpler, independent management of multiple standardized sidecar instances.
2Adaptability or versatility
If conventional databases and data repositories are used, then data storage is provided, but advanced security features like tokenization and federated identity management are not supported
Solution Approach 1:
Sidecar proxies serve as intermediaries between conventional databases and advanced security requirements. The sidecars implement tokenization, federated identity management, and other advanced security features externally, allowing conventional databases to gain these capabilities without internal modification. The sidecar mediates between the database's simple storage function and the complex security features needed.
Solution Approach 2:
The sidecar proxy is designed as a universal component that can be deployed with any conventional database or data repository regardless of its native capabilities. A single sidecar design provides multiple security functions including tokenization, federated identity management, encryption, and access control, making advanced security features universally available across diverse infrastructure without requiring different solutions for different systems.
3Reliability
If applications are left vulnerable in conventional security models, then secure perimeter administration is simplified, but data security is compromised
Solution Approach 1:
Security is segmented and pushed down to the application level through sidecar proxies deployed with each vulnerable application. Instead of relying on a single secure perimeter, each application gets its own sidecar that provides localized security protection. This segmentation allows vulnerable applications to be secured individually without requiring complex reconfiguration of the overall perimeter architecture.
Solution Approach 2:
Each application secures itself through its accompanying sidecar proxy rather than relying on centralized perimeter security. The sidecar is deployed alongside the application and handles that specific application's security needs autonomously. This self-service approach allows vulnerable applications to obtain security protection without requiring complex centralized management or modification of the application itself.
Data Source
AI summary
A method for accessing a data source is described. A communication for the data source is received from a proxy at a sidecar. The proxy mirrors the communication so that the communication is provided to the data source and the sidecar. The sidecar includes a dispatcher and service(s). The dispatcher receives the communication, is data agnostic, and provides the communication to the data source and service(s). The service(s) inspect the communication. In some embodiments, the dispatcher is an open systems interconnection (OSI) Layer 4 dispatcher and the service(s) include OSI Layer 7 service(s). The service(s) perform function(s) based on the communication.


