Secure SOA Intermediaries Embedding Artifacts for Message-Level Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service Oriented Architecture (SOA) environments face compromised security due to complexity in managing ownership and versioning of resources, as well as inadequate tracking and auditing of access, especially with existing SSL technologies that lack end-to-end confidentiality, non-repudiation, and message-level security.

Innovation Solution

Implementing a secure SOA environment with a data dictionary engine that embeds security profiles in every component, allowing for dynamic visibility and control of data, and using intermediaries to inject security artifacts into SOAP messages, ensuring secure interoperability by managing access and tracking activities with Globally Unique Identifiers and multi-part structure identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL technology is used for securing communications, then basic encryption is provided, but end-to-end confidentiality, non-repudiation, and message-level security are lacking

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments security functionality into distinct components: transport-level security (SSL) and message-level security (security artifacts embedded in SOAP messages). This allows SSL to handle basic encryption while the patent adds layered security artifacts for end-to-end confidentiality, non-repudiation, and fine-grained access control that SSL alone cannot provide.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security intermediaries (security agents) that mediate between the application layer and the transport layer. These intermediaries embed security artifacts into messages, manage security policies, and enforce access controls, thereby enhancing SSL's basic encryption with advanced security capabilities without replacing the underlying SSL infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If SOA enables flexible interoperability between different services, then service accessibility is improved, but security management complexity increases

Engineering Contradiction:
Improveservice interoperabilityVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates universal security artifacts that can be embedded in any SOAP message regardless of the service type, protocol, or platform. The security framework provides multi-functional capabilities including authentication, authorization, encryption, digital signatures, and audit logging through a unified artifact structure, simplifying security management across diverse SOA environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter of security management from centralized complex policy administration to distributed lightweight artifact embedding. Security policies are transformed into portable artifacts that can be attached to individual messages, allowing flexible security enforcement without complex centralized management infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If resource ownership and versioning are managed in SOA, then resource sharing is enabled, but tracking and auditing access becomes difficult

Engineering Contradiction:
Improveresource sharingVSAvoidaccess tracking
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms through security artifacts that automatically record access information including user identity, timestamp, resource accessed, and access outcome. This creates an automated audit trail that provides continuous feedback on resource usage, enabling comprehensive access tracking and auditing without manual intervention while maintaining resource sharing capabilities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7647627B2System and methods for secure service oriented architectures
Publication Date: 2010.01.12 METASECURE CORP
  • US7647627B2 patent drawing
  • US7647627B2 patent drawing
  • US7647627B2 patent drawing

AI summary

Provided is a method for intercepting a message between a requesting web service and a source web service, validating the message, logging the result of the validations, and adding a security profile to the message. The method may also include examining the message to determine whether a security profile is embedded therein. If the message is valid, access to the message by the requesting web service is permitted. If the message is not valid, access to the message by the requesting web service is prevented.