Domain-Wide Authentication Token Mapping for Cloud Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based environments, users of third-party services often face redundant authentication processes and time-consuming onboarding when accessing cloud-based storage systems, leading to user frustration and administrative inefficiencies.

Innovation Solution

A method and system for domain-wide authentication and authorization that maps users from third-party services to cloud-based storage system accounts, generating tokens for access, and includes a backfill process for automatic authentication and authorization of multiple users, reducing the need for redundant login steps and streamlining user onboarding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users of third-party services log into their service but attempt to access cloud-based storage system services, then they must perform a second login process for the cloud-based storage system, but this redundant authentication step causes user frustration and increases authentication time

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges the authentication processes of the third-party service and the cloud-based storage system into a unified authentication mechanism. When a user logs into the third-party service, the system automatically performs domain-wide authentication and generates tokens that grant access to both services simultaneously, eliminating the need for a separate login process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed with universality to work across multiple services within the domain. A single authentication event at the third-party service automatically provisions access to the cloud-based storage system and any other services in the domain, making the authentication mechanism multi-functional rather than service-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If administrators individually onboard each new user to the cloud-based storage system services, then user accounts can be created, but this individual onboarding process is time-consuming and reduces administrative efficiency

Engineering Contradiction:
Improveadministrative efficiencyVSAvoidonboarding time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and authorization actions automatically when users are added to the third-party service. Administrators can pre-configure domain-wide authentication settings and user groups, so that when new users are added to the third-party service, their access to the cloud-based storage system is automatically provisioned without requiring manual administrator intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The onboarding process is transformed into a self-service mechanism where the system automatically handles user provisioning across services. When a user authenticates at the third-party service, the system automatically creates necessary user accounts and grants appropriate access permissions to cloud-based storage system services without requiring administrator action.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240154946A1Methods and systems for performing domain-wide authentication and authorization
Publication Date: 2024.05.09 BOX INC
  • US20240154946A1 patent drawing
  • US20240154946A1 patent drawing
  • US20240154946A1 patent drawing

AI summary

According to one embodiment, a method for performing domain-wide authentication and authorization in a cloud-based environment can comprise receiving, from a third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the third-party service for accessing a cloud-based storage system of the cloud-based environment. A mapping of the user of the third-party service to a user account of the cloud-based storage system can be generated and one or more tokens for the user of the third-party service can in turn be generated based on the mapping of the user of the third-party service to the user account of the cloud-based storage system. The one or more tokens can provide access to services of the cloud-based storage system. The one or more tokens can be provided to the third-party service.