On-Demand Service Access Risk Management via Intermediary Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database systems are vulnerable to attacks such as phishing and keystroke logging, leading to unauthorized access to user accounts and associated organizations.

Innovation Solution

Implementing mechanisms to manage the risk of access to on-demand services by determining the source of access requests based on stored information, using techniques like authentication via email, token validation, and referencing white or black lists to permit or deny access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional database systems use traditional login authentication, then ease of operation is maintained, but security reliability deteriorates due to vulnerability to phishing and keystroke logging attacks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that acts as a mediator between the user and the database system. This intermediary validates access requests by checking multiple factors including login credentials, device identifiers, location information, and behavioral patterns before granting access to the database system, thereby enhancing security without significantly impacting user convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication actions before allowing database access. It pre-establishes security policies, device trust levels, and access rules that are evaluated in advance of each access attempt. This preliminary validation ensures that only authenticated and authorized requests proceed to the database system

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system implements comprehensive access risk management with multiple authentication factors, then security reliability improves, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into independent modular components: credential validation module, device identification module, location verification module, and behavioral analysis module. Each module handles a specific aspect of authentication independently, allowing the system to maintain high security through comprehensive checks while managing complexity through modular design and clear separation of concerns

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts authentication parameters such as the number of required factors, trust thresholds, and validation strictness based on risk assessment. For low-risk requests, fewer authentication factors are required, while high-risk requests trigger more stringent multi-factor authentication, thereby maintaining security reliability while adapting complexity to the actual risk level

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10313329B2On-demand service security system and method for managing a risk of access as a condition of permitting access to the on-demand service
Publication Date: 2019.06.04 SALESFORCE INC
  • US10313329B2 patent drawing
  • US10313329B2 patent drawing
  • US10313329B2 patent drawing

AI summary

In accordance with embodiments, there are provided mechanisms and methods for managing a risk of access to an on-demand service as a condition of permitting access to the on-demand service. These mechanisms and methods for providing such management can enable embodiments to help prohibit an unauthorized user from accessing an account of an authorized user when the authorized user inadvertently loses login information. The ability of embodiments to provide such management may lead to an improved security feature for accessing on-demand services.