Cloud Service API Connector Hub Secure Credential Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud service broker implementations are limited by the maximum number of contracts they can support, and they rely on a central entity with credentials that can result in insecure exposure of API connectors between cloud service brokers.

Innovation Solution

A method for securely extending cloud service APIs in a cloud service marketplace involves deploying an API connector instance, transmitting provisioning channel credentials, and establishing secure communication channels between cloud service providers and brokers, ensuring authentication and secure access without exposing credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a central entity distributes credentials to multiple cloud service brokers, then authentication is simplified, but security is compromised as credentials can be exposed between brokers

Engineering Contradiction:
Improveauthentication simplicityVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the credential distribution system by creating separate provisioning channels for each cloud service broker. Instead of a single centralized credential distribution, the system establishes individual secure channels between the cloud service provider and each broker, eliminating credential exposure risks while maintaining authentication simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary provisioning channel that mediates credential distribution. This intermediary layer establishes secure authenticated connections between the cloud service provider and brokers without exposing credentials directly between brokers, thus maintaining both security and operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If each cloud service broker has direct contracts with cloud service providers, then service access is direct, but the system scales poorly due to contract limitations

Engineering Contradiction:
Improveservice access efficiencyVSAvoidsystem scalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal provisioning channel infrastructure that can serve multiple cloud service brokers simultaneously. This multi-functional channel system allows the cloud service provider to authenticate and provision services to any number of brokers through a standardized interface, enabling both direct service access and unlimited scalability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If credentials are distributed among multiple brokers, then access control is simplified, but API connector exposure occurs between brokers

Engineering Contradiction:
Improveaccess control simplicityVSAvoidAPI connector exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential distribution mechanism from direct broker-to-broker interactions. By removing credentials from the shared broker environment and establishing individual provisioning channels, the system maintains simple access control while eliminating API connector exposure between brokers.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12206665B2Technologies for securely extending cloud service APIs in a cloud service marketplace
Publication Date: 2025.01.21 CLOUDBLUE LLC
  • US12206665B2 patent drawing
  • US12206665B2 patent drawing
  • US12206665B2 patent drawing

AI summary

Technologies for securely extending cloud service application programming interfaces (APIs) in a cloud service marketplace include a connector hub of a marketplace computing device communicatively coupled to a cloud service provider interface of a cloud service provider and a cloud service broker interface of a cloud service broker. The connector hub is configured to deploy an API connector instance in a connection factory of the marketplace computing device, transmit provider provisioning channel credentials to the API connector instance and the cloud service provider interface and transmit broker provisioning channel credentials to the API connector instance and the cloud service broker interface. The connector hub is additionally configured establish a provisioning channel between the cloud service provider interface and the cloud service broker interface. Additional embodiments are described herein.