Sidecar Proxy for Data Source Security and Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security models are inadequate in protecting data sources from unauthorized access and are often complex and expensive to administer, with a lack of support for advanced security features like tokenization and federated identity management in conventional databases and modern data repositories.

Innovation Solution

A sidecar system is introduced that provides a protective layer around data sources, featuring a dispatcher and various services for authentication, tokenization, and behavioral baselining, which intercepts and inspects communications to ensure only authorized access, using a data-agnostic approach that can be deployed across different data sources without requiring changes to existing infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security models with secure perimeters are used, then data sources and servers are protected, but administration becomes complex and expensive

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity administration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces sidecar proxies as intermediary components that are deployed alongside data sources and servers. These sidecars handle security functions locally, acting as mediators between the secure perimeter architecture and individual data sources. This distributes security administration tasks from a centralized complex system to multiple simple, standardized sidecar components, reducing overall administrative complexity while maintaining protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security architecture is segmented into distributed sidecar proxies deployed at each data source location rather than a single centralized security perimeter. Each sidecar is a independent, standardized component that handles security for its local data source. This segmentation transforms the complex administration of a unified secure perimeter into simpler, independent management of multiple standardized sidecar instances.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If conventional databases and data repositories are used, then data storage is provided, but advanced security features like tokenization and federated identity management are not supported

Engineering Contradiction:
Improvesecurity featuresVSAvoidinfrastructure changes
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

Sidecar proxies serve as intermediaries between conventional databases and advanced security requirements. The sidecars implement tokenization, federated identity management, and other advanced security features externally, allowing conventional databases to gain these capabilities without internal modification. The sidecar mediates between the database's simple storage function and the complex security features needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The sidecar proxy is designed as a universal component that can be deployed with any conventional database or data repository regardless of its native capabilities. A single sidecar design provides multiple security functions including tokenization, federated identity management, encryption, and access control, making advanced security features universally available across diverse infrastructure without requiring different solutions for different systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If applications are left vulnerable in conventional security models, then secure perimeter administration is simplified, but data security is compromised

Engineering Contradiction:
Improveapplication securityVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security is segmented and pushed down to the application level through sidecar proxies deployed with each vulnerable application. Instead of relying on a single secure perimeter, each application gets its own sidecar that provides localized security protection. This segmentation allows vulnerable applications to be secured individually without requiring complex reconfiguration of the overall perimeter architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each application secures itself through its accompanying sidecar proxy rather than relying on centralized perimeter security. The sidecar is deployed alongside the application and handles that specific application's security needs autonomously. This self-service approach allows vulnerable applications to obtain security protection without requiring complex centralized management or modification of the application itself.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11770377B1Non-in line data monitoring and security services
Publication Date: 2023.09.26 CYRAL INC
  • US11770377B1 patent drawing
  • US11770377B1 patent drawing
  • US11770377B1 patent drawing

AI summary

A method for accessing a data source is described. A communication for the data source is received from a proxy at a sidecar. The proxy mirrors the communication so that the communication is provided to the data source and the sidecar. The sidecar includes a dispatcher and service(s). The dispatcher receives the communication, is data agnostic, and provides the communication to the data source and service(s). The service(s) inspect the communication. In some embodiments, the dispatcher is an open systems interconnection (OSI) Layer 4 dispatcher and the service(s) include OSI Layer 7 service(s). The service(s) perform function(s) based on the communication.