Multi-layered Web App Security via Hierarchical Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web application security configurations in cloud-based enterprise software-as-a-service solutions are complex and challenging to manage, particularly when new functionalities are added, as each tenant must configure security settings according to their business practices and services, leading to inefficiencies in multi-tenant database systems.

Innovation Solution

A system implementing multi-layered evaluation of web application hierarchy using qualified user information to create executable files that evaluate and enforce scope-based security configurations at both the server and browser layers, allowing progressive evaluation and efficient configuration of web application security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional web application security configuration methods are used, then each tenant can configure security settings according to their business practices, but the complexity of security configuration increases significantly when new functionalities are added

Engineering Contradiction:
Improvesecurity configuration adaptabilityVSAvoidsecurity configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security configuration into hierarchical layers (global security policies, module-level security settings, and function-specific security rules). This segmentation allows tenants to configure security at different levels of abstraction, reducing the complexity of managing security for individual functionalities while maintaining adaptability through the hierarchical structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by implementing security configuration across multiple dimensions: temporal (versioned security policies), hierarchical (multi-level security structure), and contextual (environment-specific security settings). This multi-dimensional framework enables efficient security management for new functionalities without linearly increasing complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive security configurations are implemented for all web application functionalities, then security coverage is improved, but the time and effort required for configuration and maintenance increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring security templates and policies for common web application functionalities. When new functionalities are added, the system automatically applies relevant pre-configured security settings, significantly reducing the time and effort required for security configuration while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms that automatically analyze new functionalities and determine appropriate security configurations based on historical data and security patterns. This feedback-driven approach reduces manual configuration time while ensuring comprehensive security coverage through automated security recommendations and validations.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If manual security reconfiguration is performed for each new web application functionality, then security accuracy is maintained, but productivity and deployment speed decrease

Engineering Contradiction:
Improvesecurity configuration accuracyVSAvoiddeployment speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent implements self-service by enabling the system to automatically generate, validate, and apply security configurations for new functionalities. The system performs self-validation to ensure security accuracy while eliminating manual reconfiguration steps, thereby maintaining high security precision while significantly improving deployment speed and productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system utilizes parameter changes to dynamically adjust security configurations based on the characteristics of new functionalities. By automatically detecting and applying appropriate security parameters and settings, the system maintains configuration accuracy while eliminating time-consuming manual processes, thus improving deployment speed without sacrificing security precision.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10083324B1Qualified web application security based on multi-layered evaluation of web application hierarchy
Publication Date: 2018.09.25 EMC IP HLDG CO LLC
  • US10083324B1 patent drawing
  • US10083324B1 patent drawing
  • US10083324B1 patent drawing

AI summary

Qualified web application security based on multi-layered evaluation of web application hierarchy is described. A system receives a web application login request from a web browser associated with a user device. The system identifies a portion of qualified user information associated with the user device. The system creates an executable file based on using the portion of the qualified user information to evaluate a web application hierarchy file comprising hierarchical nodes, wherein each of the hierarchical nodes is associated with a corresponding web application function, at least one corresponding business rule, and a corresponding scope-based security configuration. The system sends the executable file to the web browser, thereby enabling the web browser to use another portion of the qualified user information to evaluate the executable file and to execute the evaluated executable file to provide qualified web application security for web application access requests from the user device.