Connectivity Component for Secure On-Premise SaaS Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication between on-premise and off-premise platforms in SaaS environments leads to excessive network traffic and security concerns due to frequent data exchanges and the need for sharing security credentials.

Innovation Solution

A connectivity component that manages communication by breaking data flows into sub-flows, allowing minimal data exchange and secure tunnel establishment between platforms, avoiding port mapping and credential exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure gateways are used to map ports between SaaS and on-premise systems, then direct access to systems of record is enabled, but excessive data transfer and I/O performance bottlenecks occur due to frequent calls

Engineering Contradiction:
Improvedirect access to systems of recordVSAvoidI/O performance
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by pre-fetching data from on-premise systems of record and caching it in the SaaS environment before it is actually needed. This allows the SaaS application to operate with locally cached data, reducing the frequency of calls to on-premise systems and thereby decreasing I/O operations and improving performance while maintaining reliable access to the systems of record when needed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If secure gateways map ports allowing SaaS software to access on-premise systems of record, then communication is established, but security credentials must be exposed to SaaS environment

Engineering Contradiction:
Improvecommunication establishmentVSAvoidsecurity credential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security credentials from the SaaS environment and keeps them exclusively in the on-premise environment. By using data caching and pre-fetching mechanisms, the system eliminates the need for SaaS software to possess or expose security credentials, thereby maintaining secure communication while preventing credential exposure to the SaaS environment.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If VPN technology or TLS connections are used to integrate SaaS with on-premise systems, then data flow integration is achieved, but excessive network traffic and latency occur

Engineering Contradiction:
Improvedata flow integrationVSAvoidnetwork response time
Core Design Contradiction:
Adaptability or versatilityVSSpeed

Solution Approach 1:

The patent applies preliminary action by pre-fetching and caching data from on-premise systems before it is actually required by the SaaS application. This reduces the frequency and volume of network transactions, thereby decreasing network traffic and latency while maintaining the adaptability to integrate various data flows between SaaS and on-premise systems.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If SaaS software makes frequent calls to on-premise systems of record, then data access is maintained, but excessive network traffic is generated

Engineering Contradiction:
Improvedata accessVSAvoidnetwork traffic volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by pre-fetching data from on-premise systems and caching it in the SaaS environment. This reduces the frequency of data access calls, thereby maintaining reliable data access while significantly reducing the volume of network traffic generated by frequent communications between SaaS and on-premise systems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10348516B2On-premise and off-premise communication
Publication Date: 2019.07.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10348516B2 patent drawing
  • US10348516B2 patent drawing
  • US10348516B2 patent drawing

AI summary

Proposed are concepts for managing communication between off-premise and on-premise servers. A flow execution request from an application of an off-premise server or an on-premise server is received and a requested flow is determined based on the received flow execution request. Stored endpoint data associated with the requested flow can then be identified. The flow execution request is then communicated to an on-premise server or off-premise server based on the identified endpoint data.