Virtualized API Infrastructure for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions for data centers are expensive, time-consuming to implement, and limit flexibility due to the use of intermediaries like proxies and routers, which create bottlenecks and increase costs, while also being difficult to manage and audit.
Innovation Solution
The implementation of a virtualized Application Programming Interface (API) infrastructure using stubs that eliminate the need for intermediary components by distributing their functions to managed endpoint stubs, allowing direct, authenticated, and secure web service calls between computing devices through the creation of virtual pipes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proxies and intermediary components are used for network security, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the security function from traditional network intermediaries (proxies, routers, load balancers) and embeds it directly into the application layer through API gateways and service meshes. This eliminates the need for separate security infrastructure components while maintaining security functions at the application level.
Solution Approach 2:
The patent merges security functions with application programming interfaces by integrating authentication, authorization, and encryption directly into API gateways and service meshes. This consolidation combines what were previously separate security infrastructure components with the application layer, reducing overall system complexity.
2Reliability
If proxies and intermediaries are deployed for security, then security is improved, but productivity and performance deteriorate
Solution Approach 1:
The patent introduces API gateways and service meshes as new intermediaries that operate at the application layer rather than the network layer. These intermediaries provide security functions with lower overhead by leveraging application-level protocols and reducing the need for deep packet inspection and network-layer processing.
Solution Approach 2:
The patent changes the operational parameters of security enforcement by moving from network-layer security (which requires packet inspection, stateful firewalls, and complex routing) to application-layer security (which uses standardized API protocols, token-based authentication, and policy-based access control). This parameter change reduces processing overhead and improves performance.
3Reliability
If traditional network security infrastructure is implemented, then security is improved, but ease of operation and management deteriorate
Solution Approach 1:
The patent creates universal API gateways and service meshes that can handle multiple security functions (authentication, authorization, rate limiting, encryption, auditing) through a single platform. This multi-functionality eliminates the need to manage separate security appliances for each function, greatly simplifying operations.
Solution Approach 2:
The patent implements centralized management consoles and control planes that provide real-time feedback on security events, policy violations, and system status. This feedback mechanism enables automated policy enforcement, dynamic security adjustments, and simplified auditing without manual intervention in complex infrastructure configurations.
Data Source
AI summary
Methods and systems for the secure exchange of data within a network are provided. A method includes, registering, by a computer system, one or more stubs installed on at least one computing device. The method further includes constructing a virtual routing table using endpoint address information of the one or more stubs. The method further transmitting a portion of the virtual routing table to the one or more stubs such that the one or more stubs are configured to create a virtual pipe for exchanging data between the at least one computing device and at least one other computing device using the portion of the virtual routing table.


