Cloud Proxy for Secure Cross-Cloud API Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in cloud-to-cloud authentication and monitoring is the inability to directly monitor communication between applications of different cloud systems due to security constraints, which limits the validation of target cloud system services and introduces operational risks for both service and target cloud systems.

Innovation Solution

A test cloud system acts as a proxy for the service cloud system, allowing for the provisioning and authentication of tenants to monitor and validate the target cloud system's services through a C2C authenticated communication channel, using a global directory of tenants to manage public and private keys and establish trust relationships while adhering to strict security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If direct monitoring of communication between cloud systems is implemented, then service validation capability is improved, but security constraints are violated and private keys are exposed

Engineering Contradiction:
Improveservice validation capabilityVSAvoidsecurity constraint compliance
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

A test cloud system is introduced as an intermediary between the service cloud system and target cloud system. The test cloud system establishes separate authenticated communication channels with both systems, enabling monitoring and validation of services without directly accessing or exposing private keys of either cloud system. This intermediary approach allows service validation while maintaining security constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a test cloud system is introduced as intermediary, then service monitoring capability is improved, but system complexity increases

Engineering Contradiction:
Improveservice monitoring capabilityVSAvoidcloud system architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The test cloud system is designed to perform multiple functions: establishing authenticated communication with both service and target cloud systems, validating API functions, monitoring service operations, and generating test reports. By consolidating these diverse functions into a single multi-functional system, the architecture manages complexity while achieving comprehensive service monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security tokens are used for authentication, then communication security is improved, but authentication setup complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication setup
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security tokens are pre-configured and established during the tenant provisioning phase before actual service communication begins. The test cloud system pre-establishes authenticated communication channels with both the service cloud system and target cloud system using security tokens. This preliminary authentication setup eliminates the need for complex real-time authentication negotiations during service operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12041170B2Cloud to cloud test set up for authentication and monitoring
Publication Date: 2024.07.16 SALESFORCE INC
  • US12041170B2 patent drawing
  • US12041170B2 patent drawing
  • US12041170B2 patent drawing

AI summary

A method and system uses a test cloud system for monitoring cloud to cloud performance. The method includes initiating a first trust relationship by the test cloud system with a first target cloud system, receiving a success indicator for the trust relationship, in response to the first target cloud verifying the test cloud system is whitelisted, generating a security token using a private key of the test cloud system, and invoking a function of an application programming interface of the first target cloud using the security token to validate functionality of the function of the application programming interface of the first target cloud.