Cloud Service API Connector Hub Secure Credential Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud service broker implementations are limited by the maximum number of contracts they can support, and they rely on a central entity with credentials that can result in insecure exposure of API connectors between cloud service brokers.
Innovation Solution
A method for securely extending cloud service APIs in a cloud service marketplace involves deploying an API connector instance, transmitting provisioning channel credentials, and establishing secure communication channels between cloud service providers and brokers, ensuring authentication and secure access without exposing credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a central entity distributes credentials to multiple cloud service brokers, then authentication is simplified, but security is compromised as credentials can be exposed between brokers
Solution Approach 1:
The patent segments the credential distribution system by creating separate provisioning channels for each cloud service broker. Instead of a single centralized credential distribution, the system establishes individual secure channels between the cloud service provider and each broker, eliminating credential exposure risks while maintaining authentication simplicity.
Solution Approach 2:
The patent introduces an intermediary provisioning channel that mediates credential distribution. This intermediary layer establishes secure authenticated connections between the cloud service provider and brokers without exposing credentials directly between brokers, thus maintaining both security and operational simplicity.
2Productivity
If each cloud service broker has direct contracts with cloud service providers, then service access is direct, but the system scales poorly due to contract limitations
Solution Approach 1:
The patent creates a universal provisioning channel infrastructure that can serve multiple cloud service brokers simultaneously. This multi-functional channel system allows the cloud service provider to authenticate and provision services to any number of brokers through a standardized interface, enabling both direct service access and unlimited scalability.
3Ease of operation
If credentials are distributed among multiple brokers, then access control is simplified, but API connector exposure occurs between brokers
Solution Approach 1:
The patent extracts the credential distribution mechanism from direct broker-to-broker interactions. By removing credentials from the shared broker environment and establishing individual provisioning channels, the system maintains simple access control while eliminating API connector exposure between brokers.
Data Source
AI summary
Technologies for securely extending cloud service application programming interfaces (APIs) in a cloud service marketplace include a connector hub of a marketplace computing device communicatively coupled to a cloud service provider interface of a cloud service provider and a cloud service broker interface of a cloud service broker. The connector hub is configured to deploy an API connector instance in a connection factory of the marketplace computing device, transmit provider provisioning channel credentials to the API connector instance and the cloud service provider interface and transmit broker provisioning channel credentials to the API connector instance and the cloud service broker interface. The connector hub is additionally configured establish a provisioning channel between the cloud service provider interface and the cloud service broker interface. Additional embodiments are described herein.


