Route Proxy Agent for Cross-Space UAA Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing user authorization and authentication across multiple microservices and versions in a cloud computing environment is challenging, especially when dealing with numerous users and applications, due to limitations in sharing UAA instances across spaces and the need for duplicate installations, which complicates trust establishment and user access management.

Innovation Solution

Implementing a cloud computing environment with a SAAS UAA component, route proxy agent, and route service broker to route communications securely and handle binding requests, allowing for efficient and accurate UAA access across spaces by validating user requests and managing user access through a single managed UAA server, thereby overcoming the limitations of current CF platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single UAA instance is shared across multiple spaces, then user access management is simplified, but trust establishment between spaces becomes problematic

Engineering Contradiction:
Improveuser access managementVSAvoidtrust establishment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a route proxy agent as an intermediary component that sits between the UAA instance and microservices in different spaces. This proxy agent validates and routes authentication requests, enabling a single UAA instance to serve multiple spaces while maintaining trust boundaries. The proxy agent acts as a mediator that ensures secure communication without requiring duplicate UAA installations in each space.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If duplicate UAA installations are deployed in each space, then trust establishment is improved, but system complexity and maintenance burden increase

Engineering Contradiction:
Improvetrust establishmentVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the route proxy agent a universal component that can serve multiple spaces and microservices simultaneously. Instead of deploying dedicated UAA instances in each space, the single route proxy agent performs authentication and authorization functions across multiple spaces, reducing system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication and authorization functionality into a single route proxy agent that serves multiple spaces. This consolidation eliminates the need for separate UAA installations in each space, reducing overall system complexity while maintaining trust through the proxy's validation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple versions of applications are maintained, then service availability is improved, but user authorization management becomes more difficult

Engineering Contradiction:
Improveservice availabilityVSAvoidauthorization management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authorization validation in the route proxy agent before requests are routed to specific microservice versions. User credentials and permissions are verified in advance, allowing the system to handle multiple application versions without complicating authorization management. The proxy agent prepares and validates authorization tokens beforehand, simplifying access to different service versions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11134083B2User authorization and authentication accessing microservices across spaces
Publication Date: 2021.09.28 SAP SE
  • US11134083B2 patent drawing
  • US11134083B2 patent drawing
  • US11134083B2 patent drawing

AI summary

A cloud computing environment may have a landscape space for singleton applications including a SAAS UAA component to receive a subscription request associated with a user and a platform SAAS application. A user system registry may indicate spaces in which the user is registered, a route proxy agent may route communications via a first secure communication channel in accordance with information in the user system registry, and a route service broker may handle binding requests. The environment may also include a first system space for first system microservices with a first system onboarding application that receives provisioning application information via the route proxy agent and the secure communication channel. First backend microservices may similarly receive application router information, and a first route service shared instance clone may provide binding requests to the route service broker. A second system space for second system microservices may similarly be provided.