Group-Based Communication System Admin Access Token Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing admin-controlled access of external resources to multiple group-based communication interfaces becomes overwhelming due to the need for individual approval and authentication token management across numerous interfaces, leading to inefficiencies and increased storage requirements.

Innovation Solution

A group-based communication system that receives external resource access requests, transmits admin approval requests, and sets permission statuses, utilizing multi-interface and single-interface access tokens to streamline access and reduce storage burdens by generating and maintaining mappings between these tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual approval and authentication token management is performed for each communication interface, then access control security is improved, but device complexity and operational burden increase significantly

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual access control mechanisms into a unified permission-based system. Instead of managing separate authentication tokens for each communication interface, the system uses a single permission record that applies across all interfaces, thereby reducing operational complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The permission record serves multiple functions simultaneously: it acts as an access control mechanism, an authentication proxy, and a system-wide policy enforcer. This multi-functional design eliminates the need for interface-specific token management while preserving security across all communication interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication tokens are managed for each communication interface, then access security is improved, but storage requirements and operational overhead increase

Engineering Contradiction:
Improveaccess securityVSAvoidstorage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Multiple interface-specific authentication tokens are merged into a single permission record. This consolidation reduces storage requirements dramatically while maintaining the security function, as the permission record serves as a universal access control mechanism across all communication interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the essential security function from the complex token management system. By taking out only the critical permission verification logic and placing it in a centralized permission record, the system eliminates redundant storage of authentication tokens while preserving access security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If admin approval is processed for each individual interface, then access control precision is improved, but processing time and system response time increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidapproval processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by establishing a single permission record in advance that pre-authorizes access across all communication interfaces. This eliminates the need for repeated approval processing for each interface, reducing response time while maintaining precise access control through the unified permission framework.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The permission record enables continuous useful action by providing ongoing access authorization without requiring repeated approval processes. Once the permission record is established, it continuously validates access requests across all interfaces, eliminating intermittent processing delays and improving system response time.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11909742B2Managing admin controlled access of external resources to group-based communication interfaces via a group-based communication system
Publication Date: 2024.02.20 SALESFORCE INC
  • US11909742B2 patent drawing
  • US11909742B2 patent drawing
  • US11909742B2 patent drawing

AI summary

Embodiments of the present disclosure relate to managing admin-controlled access of external resources to group-based communication interfaces associated with an organization, via a group-based communication system including APIs for improved external resource permissioning, provisioning, and access handling. Embodiments include methods, computer program products, apparatuses, and systems configured to receive an external resource access request, determine an organization identifier, obtain an admin response indication, set an external resource permission status for the external resource based on the admin response indication, and cause rendering of the requested group-based communication interface based on the admin response indication. Embodiments further relate to provisioning and handling requests for services associated with an external resource by managing one or more single-interface access tokens linked to a multi-interface access token.