Authorization Management Entity for Cloud Account Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to user account management in cloud platforms are inadequate, leading to cumbersome coordination of resources and vulnerability to unauthorized access, as they fail to securely map and associate multiple accounts for cohesive use alongside cloud computing resources.

Innovation Solution

A system that securely maps and associates multiple accounts by requesting authorization from external entities, verifying user identity through tokens, and storing access tokens to enable seamless integration and use of accounts within cloud platforms, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple accounts are manually coordinated for cloud platform resources, then account flexibility is improved, but system complexity and vulnerability to unauthorized access increase

Engineering Contradiction:
Improveaccount flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authorization management entity as an intermediary between users and cloud platform resources. This entity automatically maps multiple accounts to resources through standardized authorization flows, eliminating the need for manual coordination while maintaining account flexibility. The intermediary handles token management and authorization requests, reducing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service account mapping where users can autonomously associate multiple accounts with cloud resources through automated authorization procedures. The authorization management entity facilitates this by automatically obtaining access tokens and establishing mappings without requiring manual system administrator intervention, thus improving flexibility while keeping the system manageable.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If traditional authorization methods are used for multiple accounts, then implementation simplicity is maintained, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements preliminary authorization actions where the authorization management entity obtains access tokens and establishes account mappings before actual resource access occurs. This preliminary setup includes verifying user identities and securing authorizations in advance, which strengthens security while maintaining implementation simplicity through automated workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms where the authorization management entity continuously monitors authorization states, token validity, and access patterns. This feedback enables dynamic security adjustments and automatic revocation of unauthorized access, improving reliability without complicating the implementation through standardized monitoring protocols.

Inventive Principle:
Principle #23Feedback

3Device complexity

If accounts are not securely mapped to cloud resources, then system simplicity is maintained, but vulnerability to attacks increases

Engineering Contradiction:
Improvesystem simplicityVSAvoidvulnerability to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authorization system into distinct functional components: the authorization management entity, external authorization entities, and cloud platform resources. Each segment handles specific security functions independently, creating clear boundaries that simplify the overall system while reducing vulnerability through isolated security zones and targeted protection measures.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230093470A1Account authorization mapping
Publication Date: 2023.03.23 SALESFORCE INC
  • US20230093470A1 patent drawing
  • US20230093470A1 patent drawing
  • US20230093470A1 patent drawing

AI summary

Methods and systems for account authorization mapping are described. An application server may transmit one or more authorization requests to one or more authorization entities associated with one or more applications. The application server may receive one or more access tokens associated with the one or more applications and may store one or more indications of authorization. The application server may further associate, at the authorization management entity, the one or more indications of authorization.