Escrow User Account Access Control Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud storage administered accounts, removing a user account is challenging as it requires trust between employer and employee to ensure access and return of personal and work-related content items, leading to potential misuse.
Innovation Solution
Placing the user account in escrow, requiring simultaneous login credentials from both employer and employee to access the account, ensuring mutual consent for access and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the user account is assigned to either the employee or the employer, then access rights are simplified and easy to manage, but the other party cannot access their content without trust-based manual return
Solution Approach 1:
The patent introduces an escrow state as an intermediary condition between employee-only access and employer-only access. When a user account is removed from an administered account, it transitions to an escrow state where both the employee and employer are granted access rights. This intermediary state resolves the contradiction by providing a structured transition period that maintains content security through dual authorization while simplifying access management compared to trust-based manual return procedures.
2Device complexity
If trust-based manual return of content items is used, then the system remains simple, but unauthorized access or loss of content may occur
Solution Approach 1:
The patent applies preliminary anti-action by establishing the escrow state before any potential unauthorized access or content loss can occur. When a user account is removed from administration, the system proactively grants both parties access rights in advance, preventing the harmful scenario where one party might unauthorizedly access or lose content. This preemptive measure adds minimal complexity while effectively preventing unauthorized access through the mechanism of shared escrow access.
3Reliability
If dual authorization is required for account access, then content security is improved, but access procedures become more complex
Solution Approach 1:
The patent segments the access control mechanism into distinct states: administered account state (employer-controlled), escrow state (dual access), and removed state. By segmenting the access control into these discrete states, the system maintains simplicity in each state while providing strong security in the critical transition period. The escrow state specifically implements segmentation by separating access rights from the traditional binary choice and creating a intermediate state with shared access permissions.
Data Source
AI summary
Disclosed are systems, methods, and non-transitory computer-readable storage media for placing a user account in escrow to remove it from an administered account. An employee and/or an employer can select to remove a user account from an administered account associated with the employer. To ensure that the each party, the employer and employee, has an opportunity to retain their content stored in the removed user account, the user account can be placed into escrow, requiring login credentials of both the user and the administrator (employer) to access the user account. The user account can therefore not be accessed unless both the employer and employee each login to the account at the same time. By placing the user account in escrow, both parties can be assured that they can access the content items in the user account, and that the other party cannot access the content without their knowledge.


