Global User Account for Cross-Domain Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, users associated with multiple entities face challenges in managing and authenticating across multiple local user accounts, as conventional single sign-on systems fail to reconcile and propagate personal information consistently across different client-specific accounts, leading to duplicative information collection and privacy concerns.

Innovation Solution

A system that allows users to establish a global user account linked with local accounts, using verifiable information such as email addresses or phone numbers to propagate personal details across multiple accounts, reducing the need for duplicative data entry and enhancing privacy by respecting context-specific permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional single sign-on systems are used to authenticate users across multiple entities, then authentication is simplified, but personal information cannot be consistently reconciled and propagated across different client-specific accounts

Engineering Contradiction:
Improveauthentication processVSAvoidpersonal information consistency
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces a global user account as an intermediary layer between multiple local user accounts across different entities. This global account stores and reconciles personal information (name, email, phone number) that can then be propagated to relevant local accounts, solving the information consistency problem while maintaining authentication simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The global user account serves multiple functions: it acts as a central repository for personal information, a reconciliation point for data from different entities, and a propagation mechanism to distribute verified information across multiple local accounts. This multi-functionality resolves the contradiction by providing both authentication ease and information consistency

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If personal information is collected for each local user account separately, then each entity has complete user data, but duplicative information collection increases user burden and raises privacy concerns

Engineering Contradiction:
Improveuser data completenessVSAvoidaccount management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the function of storing personal information from multiple local accounts into a single global user account. Instead of each entity separately collecting and storing duplicative personal information, the global account consolidates this data, reducing user burden while maintaining data completeness through selective propagation to local accounts

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system allows personal information to be stored with different levels of accessibility: the global account has complete information for reconciliation, while individual local accounts receive only the information relevant to their specific entity context. This local quality approach maintains data completeness where needed while reducing duplicative collection

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11425132B2Cross-domain authentication in a multi-entity database system
Publication Date: 2022.08.23 SALESFORCE INC
  • US11425132B2 patent drawing
  • US11425132B2 patent drawing
  • US11425132B2 patent drawing

AI summary

An on-demand database system may receive a request to create a user account associated with a subdomain of the database system. The system may identify a pre-existing user account associated with a different subdomain of the database system where the pre-existing user account is associated with a personal communications address identified in the request. The system may create the requested account using personal information retrieved from the pre-existing user account.