Secure Serverless Interface for Multi-Application SaaS-CRM Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SaaS-CRM platforms incur high license costs for multiple user accounts and API calls, and pose security risks due to external hosting, necessitating a cost-effective and scalable integration solution.

Innovation Solution

A serverless interface is used to integrate applications on SaaS-CRM platforms, authenticating user devices, generating access tokens, and leveraging a composite API to reduce the number of API calls and user licenses through a virtual private cloud and JSON web token authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple user accounts are created on SaaS-CRM platform for each internal application, then application integration capability is improved, but license cost increases significantly

Engineering Contradiction:
Improveapplication integration capabilityVSAvoidlicense cost
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent creates a single multi-functional user account on the SaaS-CRM platform that can authenticate and authorize multiple internal applications through service accounts and API keys, eliminating the need for separate licensed user accounts for each application while maintaining integration capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces service accounts as intermediary entities that act as bridges between internal applications and the SaaS-CRM platform, allowing applications to authenticate and interact with the platform without requiring individual user licenses for each application

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If applications make multiple API calls to interact with multiple SaaS-CRM objects, then data access completeness is improved, but API call cost increases

Engineering Contradiction:
Improvedata access completenessVSAvoidAPI call cost
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent combines multiple individual API calls into a single batch API call that can retrieve or manipulate multiple SaaS-CRM objects (leads, opportunities, contacts) in one request, maintaining complete data access while reducing the number of API calls and associated costs

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If SaaS-CRM platform is hosted externally on Internet, then platform accessibility is improved, but security risk increases

Engineering Contradiction:
Improveplatform accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy layer as an intermediary component hosted within the organization's secure network that mediates between internal applications and the externally hosted SaaS-CRM platform, allowing maintained accessibility while enforcing security policies and protecting internal systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12425385B2Method and system for integrating applications on software-as-a-service platform using serverless interface
Publication Date: 2025.09.23 JPMORGAN CHASE BANK NA
  • US12425385B2 patent drawing
  • US12425385B2 patent drawing
  • US12425385B2 patent drawing

AI summary

A method and a system for integration of applications on a software-as-a-service-customer relationship management (SaaS-CRM) platform using a serverless interface are disclosed. The method comprises: (1) authenticating a user device application, by an authenticator, and generating an access token; (2) sending, by the user device application, request to an application programming interface (API) gateway to integrate the user device application with the SaaS-CRM platform, wherein the request includes the access token; (3) validating, by an authorizer, the access token to generate a policy; (4) granting access to the user device application for the serverless interface; (5) retrieving, by the serverless interface, a client credential data and a private key from a digital key manager; and (6) integrating, via the serverless interface, the user device application on the SaaS-CRM platform.