Virtual Service Connector for Secure Cloud-Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for accessing enterprise services from cloud-based systems are laborious and insecure, requiring manual configuration of VPN connections and exposing private networks to potential security breaches.

Innovation Solution

A system comprising a tenant administration proxy, a connector service, and a configuration manager that facilitates secure communication between cloud-based and enterprise services using virtual communication circuits and secure protocols, eliminating the need for site-to-site VPN connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If site-to-site VPN connections are established between cloud services and enterprise services, then secure access to enterprise services is achieved, but configuration complexity and labor requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A virtual service connector is introduced as an intermediary component that simplifies the connection between cloud services and enterprise services. Instead of requiring direct site-to-site VPN configurations, the virtual service connector acts as a mediator that automatically establishes connections, reducing configuration complexity while maintaining security through centralized authentication and virtual circuit management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual mechanical VPN configuration processes with automated virtual circuit establishment. The system automatically creates virtual circuits between cloud services and enterprise services through software-based virtual service connectors, eliminating the need for manual VPN tunnel setup and reducing configuration labor requirements

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If multiple VPN tunnels are established for different cloud services, then access to various enterprise services is enabled, but security exposure and attack surface increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network connection architecture by introducing virtual service connectors that operate as isolated virtual circuits. Each virtual service connector handles specific cloud service connections independently, allowing granular security control. This segmentation enables selective exposure of enterprise services only to authenticated cloud services that require access, rather than opening broad VPN tunnels

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual service connector serves as a security intermediary that sits between the public cloud network and the private enterprise network. It authenticates cloud services, establishes secure virtual circuits, and mediates all communications, thereby enabling versatile service access while maintaining security through centralized authentication and controlled virtual circuit establishment

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual VPN configuration is performed for each cloud service, then secure connections are established, but setup time and operational overhead increase

Engineering Contradiction:
Improveconnection securityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service capabilities where cloud services can automatically discover available enterprise services and establish connections through the virtual service connector without manual intervention. The virtual service connector automatically handles authentication, virtual circuit creation, and connection management, eliminating time-consuming manual VPN configuration tasks

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The virtual service connector is pre-configured with authentication mechanisms and virtual circuit templates before cloud services need to connect. This preliminary setup allows cloud services to rapidly establish secure connections by simply presenting authentication credentials, rather than requiring manual VPN tunnel configuration for each connection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10171590B2Accessing enterprise communication systems from external networks
Publication Date: 2019.01.01 CA TECH INC
  • US10171590B2 patent drawing
  • US10171590B2 patent drawing
  • US10171590B2 patent drawing

AI summary

A computer system implements a plurality of modules, including a tenant administration proxy that receives session credentials from a tenant application in the private communication system and authenticates the tenant application in response to the session credentials, a connector service that receives a bridge setup request from the tenant application and establishes a bridge connection with the tenant application in response to the bridge setup request; and a configuration manager that stores service information regarding a cloud-based service that is accessible through the computer system. The tenant administration proxy retrieves the service information from the configuration manager and provides the service information to the tenant application in response to a request from the tenant application, and wherein the connector service facilitates communication between the cloud-based service and an enterprise service in the private communication system over the bridge connection.