Secure Bridge Mechanism for Transparent Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise resources are not transparently accessible across enterprise and cloud boundaries using standard mechanisms, protocols, and portals in cloud computing environments, hindering seamless integration and resource sharing.

Innovation Solution

A secure bridge mechanism interconnects enterprise and cloud computing environments, providing transparent and secure access by using a first secure bridge portion within the enterprise and a second secure bridge portion within the cloud, enabling resources from one environment to access those of the other without requiring firewall modifications, through mechanisms like VPN-type technology, proxy tunneling, and SSH tunneling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard mechanisms and protocols are used for cloud access, then ease of operation is maintained, but transparent access to enterprise resources across cloud boundaries is not achieved

Engineering Contradiction:
Improveease of operationVSAvoidtransparent access
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

A secure bridge mechanism is introduced as an intermediary component between the enterprise computing environment and the cloud computing environment. This bridge includes a bridge agent in the enterprise environment and a bridge service in the cloud environment, which work together to enable transparent resource access without requiring changes to standard protocols or mechanisms. The intermediary handles the complexity of cross-environment communication while maintaining ease of operation for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If firewall modifications are implemented to enable resource access, then transparent access is improved, but device complexity and security risk increase

Engineering Contradiction:
Improvetransparent accessVSAvoidfirewall configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure bridge mechanism acts as an intermediary that operates within existing firewall constraints rather than requiring firewall modifications. The bridge agent and bridge service establish secure communication channels through permitted ports and protocols, enabling transparent resource access without complicating firewall configurations or introducing security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The bridge mechanism creates virtual copies or representations of enterprise resources that are accessible from the cloud environment. Instead of opening direct access through firewalls, the system creates secure virtual access points that replicate resource functionality, thereby maintaining firewall integrity while enabling transparent access.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If cloud resources are integrated into enterprise infrastructure, then adaptability is improved, but maintaining security and operational independence becomes more difficult

Engineering Contradiction:
Improveresource integrationVSAvoidsecurity maintenance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the integration architecture into distinct components: the enterprise computing environment, the secure bridge mechanism, and the cloud computing environment. Each segment maintains its security boundaries and operational independence while enabling controlled resource sharing. The bridge agent resides in the enterprise environment and the bridge service resides in the cloud environment, creating clear security perimeters.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure bridge mechanism serves as an intermediary layer that mediates all resource access requests between the enterprise and cloud environments. This intermediary enforces security policies, authenticates access requests, and manages resource sharing while maintaining the reliability and security of both environments. The bridge includes components such as a bridge agent, bridge service, and resource manager that work together to maintain security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8286232B2System and method for transparent cloud access
Publication Date: 2012.10.09 MICRO FOCUS SOFTWARE INC
  • US8286232B2 patent drawing
  • US8286232B2 patent drawing
  • US8286232B2 patent drawing

AI summary

System and method for transparent cloud access are described. In one embodiment, the system comprises an enterprise computing environment maintained by an enterprise and a cloud computing environment maintained by a cloud provider; and a secure bridge mechanism for interconnecting the enterprise computing environment and the cloud computing environment. The secure bridge mechanism comprises a first secure bridge portion associated with the enterprise and a second secure bridge portion associated with the cloud computing environment. The first and second secure bridge portions interoperate to provide transparent and secure access by resources of one of the computing environments to those of the other computing environment.