Mediated Cloud Service Authentication via Secure Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in securely interacting with unfamiliar cloud service providers, particularly in establishing trust relationships and managing employee access and billing for cloud services, which can be cumbersome and insecure.

Innovation Solution

A trusted provider acts as a centrally trusted business identity, mediating authentication and authorization for users to access cloud services without revealing detailed employee information, using a secure cloud connector tunnel and user mapper to grant cloud tokens for service usage, while handling billing internally.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a large enterprise establishes direct trust relationships with every cloud service provider, then access to diverse cloud services is enabled, but system complexity and security risk increase

Engineering Contradiction:
Improveaccess to cloud servicesVSAvoidtrust relationship management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud service broker as an intermediary between the large enterprise and cloud service providers. The broker establishes and manages trust relationships with providers on behalf of the enterprise, while the enterprise maintains a single trusted relationship with the broker. This mediator approach enables access to multiple cloud services without requiring the enterprise to directly manage complex trust relationships with each provider individually.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If individual employees create personal accounts with cloud service providers, then service access is simplified, but security and billing management become problematic

Engineering Contradiction:
Improveservice accessVSAvoidsecurity and billing control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cloud service broker acts as an intermediary that manages employee access to cloud services. Instead of employees creating personal accounts, the broker provides centralized authentication and authorization. The broker handles billing aggregation and management, eliminating the need for individual employee accounts while maintaining ease of access through the broker's unified interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cloud service broker provides multi-functional services including authentication, authorization, billing aggregation, and service provisioning. This universal platform serves multiple purposes simultaneously, replacing the need for separate personal accounts and billing arrangements for each employee, thereby improving security and billing control while maintaining operational ease.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If corporate accounts payable departments handle individual reimbursement requests, then billing is processed, but time consumption and operational complexity increase

Engineering Contradiction:
Improvebilling processingVSAvoidreimbursement request handling
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges individual employee billing with corporate accounts payable processing. The cloud service broker aggregates billing information from all employees and services into a single consolidated invoice that is processed through the existing corporate accounts payable system. This eliminates the need for individual reimbursement requests, significantly reducing processing time and operational complexity while maintaining accurate billing.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If detailed employee information is shared with cloud service providers, then authentication is enabled, but information security and privacy are compromised

Engineering Contradiction:
ImproveauthenticationVSAvoidemployee information exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The cloud service broker serves as an intermediary that manages authentication without exposing detailed employee information to cloud service providers. The broker handles authentication logic centrally, using secure communication channels to verify employee identities. This mediator approach enables authentication functionality while minimizing information exposure, as providers only receive necessary authentication tokens rather than detailed employee data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10708270B2Mediated authentication and authorization for service consumption and billing
Publication Date: 2020.07.07 SAP SE
  • US10708270B2 patent drawing
  • US10708270B2 patent drawing
  • US10708270B2 patent drawing

AI summary

A request is received for execution of a cloud service for a user of a customer of a cloud-computing platform, the request including a user identifier of the user but not a password for the user. The customer is determined from the user identifier included in the request for execution of the cloud service. A cloud connector endpoint for the customer is determined, where the cloud connector endpoint identifies a secure cloud connector tunnel for communication with a user mapper installed in a customer landscape of the customer. An authorization and authentication request is sent to the user mapper using the secure cloud connector tunnel, where the user mapper is configured to authenticate the user within the customer landscape and determine whether the user is authorized to use the requested cloud service. An authorization and authentication response is received from the user mapper that indicates whether the user is an authenticated user who is authorized to use the cloud service. In response to the authorization and authentication response indicating that the user is an authenticated user who is authorized to use the cloud service, a cloud token is granted that enables use of the cloud service.