Secure Web Hosting Application Pool Isolation via Unique Security Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing user accounts for web applications in a secure and efficient manner is challenging for system administrators, particularly when deploying web applications across multiple web servers, as it requires configuring accounts with correct security attributes and managing permissions to prevent security vulnerabilities and errors.

Innovation Solution

A secure web hosting system automatically creates unique security tokens (SIDs) for each web application based on its name, using a one-way hash function, allowing for secure isolation of application pools and relieving administrators from manual account management by loading configuration files when the web server starts or changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If system administrators manually configure user accounts for each web application, then security attributes and permissions can be properly managed, but the complexity and time required for deploying web applications across multiple servers increases significantly

Engineering Contradiction:
Improvesecurity managementVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically creates and configures user accounts and security tokens for web applications without requiring administrator intervention. The account management system performs self-service by reading application manifests, generating unique SIDs, and configuring security attributes automatically when applications are deployed to the file system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures security attributes and permissions in application manifests before deployment. When applications are copied to the file system, the security configuration is already prepared and automatically applied, eliminating the need for post-deployment account management.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If system administrators manually manage user accounts for each web application, then security policies can be enforced, but the complexity of account management increases with the number of applications

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically enforces security policies by reading predefined rules from configuration files and applying them to create and manage user accounts. Security attribute templates define permitted permissions, and the system self-configures accounts according to these templates without administrator intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses security attribute templates that define parameters for user account configuration. These templates specify permitted security attributes and permissions, allowing the system to automatically configure accounts with appropriate security parameters based on the application type and deployment context.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If unique user accounts are created for each web application to ensure isolation, then security is improved, but the number of accounts to manage increases significantly

Engineering Contradiction:
Improveapplication isolationVSAvoidnumber of user accounts
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the account management function from manual administrator tasks and transfers it to automated system processes. The account management system automatically creates, configures, and manages user accounts based on application deployment, removing the burden of manual account creation and management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The account management system provides universal functionality by handling multiple aspects of security management through a single automated process: creating user accounts, generating security tokens, configuring permissions, and enforcing isolation policies all through one system that operates automatically upon application deployment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If passwords are required for security compliance, then security policies are satisfied, but password management becomes more complex and error-prone

Engineering Contradiction:
Improvesecurity complianceVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates and manages passwords as part of the account creation process. Passwords are generated according to security policies defined in templates, and the system self-manages password storage and configuration without requiring administrator handling of sensitive password information.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables easy and secure deployment of web applications by automatically creating and managing SIDs independently of the computer system and user accounts, reducing the burden on system administrators and minimizing the risk of security vulnerabilities through automated account configuration and management.

Implementation Method 1

The secure web hosting system can employ a one-way hash function to create the SID based on an application name indicated in a configuration file

Methodology Applied
Scientific EffectOne-way hash function:

Data Source

PatentUS8640215B2Secure isolation of application pools
Publication Date: 2014.01.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8640215B2 patent drawing
  • US8640215B2 patent drawing
  • US8640215B2 patent drawing

AI summary

A secure web hosting system is provided. In various embodiments, the secure web hosting system identifies an application that is to be loaded, creates a security token that is unique to the computer system and based on a name of the identified application, receives a request to load the identified application, and creates a process in which to load the identified application, the process having security attributes associated with the created security token. In various embodiments, the secure web hosting system includes an isolation service component that creates a security token based on an application name of an application identified by the configuration file.