Intermediate Platform for Serverless SaaS Security Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in developing and deploying new applications due to the time-consuming process of building application infrastructure, ensuring compliance with privacy and security policies, and integrating new applications with existing systems, which can be complex and prone to security vulnerabilities.

Innovation Solution

The use of a serverless environment facilitated by an intermediate platform that acts as a mediator between developers, SaaS platforms, and serverless environments, allowing for the development and implementation of applications without managing servers, and ensuring compliance with privacy and security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If companies build their own application infrastructure and manage servers, then they have full control over security and compliance, but the development process becomes time-consuming and complex

Engineering Contradiction:
Improvesecurity complianceVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediate platform that mediates between the serverless environment and the SaaS platform. This platform handles security compliance verification, privacy policy enforcement, and integration coordination, allowing companies to benefit from serverless speed without sacrificing security control. The intermediate platform acts as a trusted intermediary that automates compliance checking and security validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security and compliance verification through the intermediate platform before applications are deployed to the SaaS platform. By pre-validating security requirements, privacy policies, and compliance standards during the deployment process, the system eliminates time-consuming security checks later, thereby reducing overall development time while maintaining security standards.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If companies integrate new applications with existing systems, then they achieve seamless workflow integration, but the integration process becomes complex and prone to security vulnerabilities

Engineering Contradiction:
Improveintegration capabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The intermediate platform serves as a mediator between new applications and existing SaaS systems, providing standardized integration interfaces and protocols. It handles authentication, authorization, and data exchange protocols, reducing integration complexity. The platform translates between different system interfaces and maintains security policies, enabling seamless integration without direct complex point-to-point connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediate platform provides universal integration capabilities that work across multiple SaaS platforms and application types. It implements a standardized set of integration protocols and interfaces that can accommodate various integration scenarios, reducing the need for custom integration logic for each new application and thereby reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If companies use third-party application providers, then they accelerate application deployment, but they face challenges in ensuring compliance with privacy and security policies

Engineering Contradiction:
Improvedeployment speedVSAvoidpolicy compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The intermediate platform implements continuous feedback mechanisms that monitor and verify compliance with privacy and security policies during application deployment and operation. It automatically checks whether third-party applications meet required standards and provides feedback to both the application provider and the company, enabling rapid deployment while maintaining compliance through automated verification loops.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies preliminary anti-action by pre-screening third-party applications for compliance with privacy and security policies before they are deployed. The intermediate platform validates application security requirements, privacy policy adherence, and compliance standards in advance, blocking non-compliant applications from deployment and thereby ensuring policy compliance while maintaining fast deployment speeds for approved applications.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20250173450A1Digital processing systems and methods for facilitating the development and implementation of applications in conjunction with a serverless environment
Publication Date: 2025.05.29 MONDAY COM LTD
  • US20250173450A1 patent drawing
  • US20250173450A1 patent drawing
  • US20250173450A1 patent drawing

AI summary

Systems, methods, and computer program products are disclosed perform data access operations in association with a multi-tenant SaaS application within a Multi-tenant SaaS Platform. Code for a multi-tenant SaaS application includes a call to a token associated with retrieving tenant-specific data. A first request is received for first data access using a first token associated with a first tenant associated with a first storage location, the first request lacking an identification of the first storage location. Tenant-specific data associated with the first tenant is retrieved and provided to the multi-tenant SaaS application. A second request is received for second data access using a second token associated with a second storage location associated with a second tenant. The second token is mapped to the second storage location. The second tenant tenant-specific data is retrieved from the second storage location and provided to the multi-tenant SaaS application.