Pre-authorizing Client Apps via Installer Tags

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems require users to re-enter login credentials when installing a client-side application, posing a security risk if the installer is used by a different user, and lack efficient pre-authorization mechanisms.

Innovation Solution

The content management system tags a client installer with an information tag linking it to a user account, allowing the client-side application to automatically log in without re-entering credentials, while implementing verification measures such as limited usage, time restrictions, and IP address controls to ensure proper authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the client installer automatically logs in the user without requiring login credentials, then the ease of operation is improved, but the reliability deteriorates due to security risks if the installer is used by a different user

Engineering Contradiction:
Improveautomatic loginVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by tagging the installer with identification information during the installation process, and the client application subsequently uses this pre-prepared information to automatically authenticate with the content management system, eliminating the need for users to manually enter credentials while maintaining security through verification measures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (identification tag embedded in the installer) that mediates between the installer and the content management system, allowing automatic authentication without directly exposing credentials, thus balancing convenience and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the client installer requires users to re-enter login credentials, then the reliability is improved through security verification, but the ease of operation deteriorates due to repeated login requirements

Engineering Contradiction:
Improvesecurity verificationVSAvoidrepeated login
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication credentials from the manual input process and embeds them within the installer package itself, allowing the client application to automatically retrieve and use these credentials for authentication, thereby eliminating repeated login requirements while maintaining security verification

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If the identification tag is made universally usable without restrictions, then the ease of operation is improved, but the reliability deteriorates due to potential misuse by unauthorized users

Engineering Contradiction:
Improveunrestricted usageVSAvoidauthorization control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by implementing specific restrictions on the identification tag's usability, such as limiting it to particular client devices, time periods, or usage counts, thereby ensuring that the automatic login feature remains convenient for authorized users while preventing misuse by unauthorized parties

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10484383B2Pre-authorizing a client application to access a user account on a content management system
Publication Date: 2019.11.19 DROPBOX INC
  • US10484383B2 patent drawing
  • US10484383B2 patent drawing
  • US10484383B2 patent drawing

AI summary

A content management system can tag a client installer with an information tag linking the client installer to a user account. The client installer can be configured to install the client-side application on the client device and pass the identification tag to the installed client-side application. The client-side application can transmit the identification tag to the content management system, which can use the identification tag to identify the linked user account and log the client-side application into the user account. The content management system can implement several verification measures such as limiting the number of times and when an identification tag can be used, as well as IP addresses that can use the identification tag. The content management system can also use data cached by the web-browser application to determine if the web-browser application was used to access the user account in the past.