Hybrid Cloud API Management via Local Proxy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing API management systems face challenges in securing data transmissions and complying with security and compliance regulations, such as HIPAA and Gramm-Leach-Bliley Act, while also being resource-intensive and requiring local computing resources.

Innovation Solution

A hybrid cloud API management system is implemented, where a local API proxy is deployed in close proximity to backend data/services, cooperating with a remote API management server to manage APIs, reducing the need for local infrastructure and enhancing security and compliance by offloading processing and storage to the remote server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If API management service is implemented locally, then security and compliance control is improved, but resource consumption and infrastructure cost increase

Engineering Contradiction:
Improvesecurity and compliance controlVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments API management functionality into two parts: a lightweight local API proxy that handles security and compliance control, and a remote cloud-based API management service that handles resource-intensive operations. This segmentation allows security control to remain local while reducing local resource consumption by offloading other functions to the cloud.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The local API proxy acts as an intermediary between client applications and backend services. It enforces security and compliance policies locally while forwarding other management functions to the remote API management service, thus maintaining security control without requiring full local infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If third party provides API management service, then local infrastructure cost is reduced, but security and compliance control is compromised

Engineering Contradiction:
Improvelocal infrastructureVSAvoidsecurity and compliance control
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies local quality by placing specific security and compliance control functions locally at the API proxy, while other API management functions remain remote. This ensures that sensitive security operations occur within the organization's controlled environment while still benefiting from cloud-based service management.

Inventive Principle:
Principle #3Local quality

3Reliability

If local API proxy is deployed, then security control is improved, but network latency increases

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts resource-intensive API management functions from the local environment and places them in the cloud. The local API proxy retains only the essential security control functions, minimizing local processing and reducing network round-trips for non-critical operations.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If full API management service is deployed locally, then complete control is achieved, but infrastructure cost and complexity increase

Engineering Contradiction:
Improvecomplete controlVSAvoidinfrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The remote API management service provides universal, multi-functional API management capabilities in the cloud. The local API proxy focuses on specific security and compliance functions, creating a division of labor that achieves comprehensive control without requiring the organization to maintain complex full-featured local infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10425465B1Hybrid cloud API management
Publication Date: 2019.09.24 GOOGLE LLC
  • US10425465B1 patent drawing
  • US10425465B1 patent drawing
  • US10425465B1 patent drawing

AI summary

A method of serving an API request includes receiving the API request at a local API proxy deployed at a local deployment environment. The method includes utilizing the local API proxy to service the API request at the local deployment environment, establishing a connection with a remote API management server, and providing to the remote API management server, via the connection, at least metadata about the API request.