Cloud Sandbox Folders for Third-Party App Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based services face security and privacy concerns when third-party applications require access, as they often necessitate user account authentication, which can compromise user experience and security by requiring access codes.

Innovation Solution

Implementing application-specific 'sandbox' folders that allow third-party applications to access a limited area using a user identifier, such as an email address, without triggering the conventional authentication process, using a unique identifier generated by the third-party application and a special token for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication process is used for third-party application access, then security is maintained, but user experience deteriorates due to requiring access codes

Engineering Contradiction:
Improveuser experienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The user's storage space is segmented into a general area and a sandbox area. The sandbox area is specifically allocated for third-party applications, allowing them to access only this limited portion without requiring authentication for the entire user account. This segmentation enables third-party apps to operate with restricted access rights, improving ease of operation while maintaining security through scope limitation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A sandbox area acts as an intermediary between the third-party application and the user's storage space. Instead of direct access requiring authentication, the sandbox serves as a mediated interface where apps can access user data within predefined boundaries. This intermediary structure eliminates the need for access codes while maintaining security through controlled access mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If third-party applications are given broad access to user data, then application functionality is improved, but security and privacy risks increase

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity and privacy risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The storage space is divided into a general area for user data and a sandbox area for application-specific data. Third-party applications are confined to the sandbox area, which limits their access scope to only the data they need for their specific functionality. This segmentation enables adequate application functionality while minimizing security and privacy risks through restricted access boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different areas of the storage space have different access qualities. The sandbox area provides access rights tailored specifically for third-party applications, allowing them to access only the local data within that sandbox. This local quality approach ensures applications get the functionality they need while preventing broader access that would create security and privacy vulnerabilities.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9553758B2Sandboxing individual applications to specific user folders in a cloud-based service
Publication Date: 2017.01.24 BOX INC
  • US9553758B2 patent drawing
  • US9553758B2 patent drawing
  • US9553758B2 patent drawing

AI summary

An example system and method comprises receiving a request from the third-party application, wherein the request includes a user identifier; allocating an area that is specific for the third-party application and for the user; and granting access of the area to the third-party application. In one embodiments, the method further comprises providing to the third-party application a token which allows the third-party application to access a given area. Additional embodiments provided herein enable a third-party application to use a user identifier (e.g., an email address or other identifiers) of its user to access area specific of a cloud-based environment/platform/services (e.g., collaboration, file sharing, and/or storage services) without necessarily triggering user account authentication, thereby avoiding the process of requiring access codes from the user which can adversely impact user experience as well as compromise security and/or user's privacy.