Web Services Layer Security Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in application security due to the use of different security measures across various systems, leading to increased integration complexities and risks of information leakage when implementing authentication, authorization, and audit (AAA) in web services, which often require dedicated servers or third-party tools, resulting in additional layers of integration and higher security costs.

Innovation Solution

A centralized architecture within the web services layer that handles authentication, authorization, and audit by using a Ping Security Token Service (STS) to generate a one-time SAML token for user access, eliminating the need for maintaining user profiles and integrating with a central repository system for authorization and logging user actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated AAA servers or third-party tools are integrated with the web services layer, then authentication, authorization and audit functions are provided, but integration complexity and security costs increase

Engineering Contradiction:
Improveauthentication and authorization capabilityVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the AAA (Authentication, Authorization, and Audit) functions directly into the web services layer by implementing a security interceptor that handles all three functions within the existing web services infrastructure, eliminating the need for separate dedicated AAA servers and reducing integration complexity while maintaining comprehensive security capabilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security interceptor implemented in the web services layer serves multiple functions simultaneously - it performs authentication by verifying credentials, authorization by checking access rights, and audit by logging user actions - all within a single component, making the system multi-functional and reducing the need for separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated AAA servers or third-party tools are integrated with the web services layer, then authentication, authorization and audit functions are provided, but additional layers of integration are created

Engineering Contradiction:
Improvesecurity function provisionVSAvoidnumber of integration layers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines authentication, authorization, and audit functions into the existing web services layer through a security interceptor, eliminating the need for separate dedicated AAA servers and reducing the number of integration layers from multiple separate systems to a single integrated component within the web services infrastructure

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If centralized architecture within web services layer is implemented, then integration layers are reduced, but new security mechanisms must be developed

Engineering Contradiction:
Improveintegration layersVSAvoidsecurity mechanism implementation
Core Design Contradiction:
Device complexityVSEase of manufacture

Solution Approach 1:

The security interceptor is implemented as a self-contained component within the web services layer that autonomously handles authentication, authorization, and audit functions using built-in Java security mechanisms and standard protocols, requiring no external AAA servers or third-party tools, thereby reducing integration complexity while maintaining comprehensive security capabilities

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9973500B2Security architecture for authentication and audit
Publication Date: 2018.05.15 BANK OF AMERICA CORP
  • US9973500B2 patent drawing
  • US9973500B2 patent drawing
  • US9973500B2 patent drawing

AI summary

A mechanism for consolidating communications between a computer tenant and a web services layer is provided. The mechanism may include a web services layer. The web services layer may be configured to receive communications, via an authentication validation module, from an authentication service. The authentication service may be in communication with the computer tenant and/or the web services layer. The web services layer may be configured to receive authorization data, via an authorization module, from an authorization data store. The web services layer may also receive and transmit logged calls from a log database. The logged calls may store calls from the computer tenant to the web services layer and calls from the web services layer to the authentication server. The computer tenant may initiate communication with the web services layer. Included in the communications may be a token.