Virtual Service Connector for Secure Cloud-Enterprise Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for accessing enterprise services from cloud-based systems are laborious and insecure, requiring manual configuration of VPN connections and exposing private networks to potential security breaches.
Innovation Solution
A system comprising a tenant administration proxy, a connector service, and a configuration manager that facilitates secure communication between cloud-based and enterprise services using virtual communication circuits and secure protocols, eliminating the need for site-to-site VPN connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If site-to-site VPN connections are established between cloud services and enterprise services, then secure access to enterprise services is achieved, but configuration complexity and labor requirements increase
Solution Approach 1:
A virtual service connector is introduced as an intermediary component that simplifies the connection between cloud services and enterprise services. Instead of requiring direct site-to-site VPN configurations, the virtual service connector acts as a mediator that automatically establishes connections, reducing configuration complexity while maintaining security through centralized authentication and virtual circuit management
Solution Approach 2:
The patent replaces manual mechanical VPN configuration processes with automated virtual circuit establishment. The system automatically creates virtual circuits between cloud services and enterprise services through software-based virtual service connectors, eliminating the need for manual VPN tunnel setup and reducing configuration labor requirements
2Adaptability or versatility
If multiple VPN tunnels are established for different cloud services, then access to various enterprise services is enabled, but security exposure and attack surface increase
Solution Approach 1:
The patent segments the network connection architecture by introducing virtual service connectors that operate as isolated virtual circuits. Each virtual service connector handles specific cloud service connections independently, allowing granular security control. This segmentation enables selective exposure of enterprise services only to authenticated cloud services that require access, rather than opening broad VPN tunnels
Solution Approach 2:
The virtual service connector serves as a security intermediary that sits between the public cloud network and the private enterprise network. It authenticates cloud services, establishes secure virtual circuits, and mediates all communications, thereby enabling versatile service access while maintaining security through centralized authentication and controlled virtual circuit establishment
3Reliability
If manual VPN configuration is performed for each cloud service, then secure connections are established, but setup time and operational overhead increase
Solution Approach 1:
The system implements self-service capabilities where cloud services can automatically discover available enterprise services and establish connections through the virtual service connector without manual intervention. The virtual service connector automatically handles authentication, virtual circuit creation, and connection management, eliminating time-consuming manual VPN configuration tasks
Solution Approach 2:
The virtual service connector is pre-configured with authentication mechanisms and virtual circuit templates before cloud services need to connect. This preliminary setup allows cloud services to rapidly establish secure connections by simply presenting authentication credentials, rather than requiring manual VPN tunnel configuration for each connection
Data Source
AI summary
A computer system implements a plurality of modules, including a tenant administration proxy that receives session credentials from a tenant application in the private communication system and authenticates the tenant application in response to the session credentials, a connector service that receives a bridge setup request from the tenant application and establishes a bridge connection with the tenant application in response to the bridge setup request; and a configuration manager that stores service information regarding a cloud-based service that is accessible through the computer system. The tenant administration proxy retrieves the service information from the configuration manager and provides the service information to the tenant application in response to a request from the tenant application, and wherein the connector service facilitates communication between the cloud-based service and an enterprise service in the private communication system over the bridge connection.


