Hosted Credential Service for Multi-Tenant Database Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a cloud-based model, organizations face challenges in securely managing access credentials for services from multiple service providers without exposing their infrastructure to security risks, especially when integrating services from different vendors like Salesforce and Dun & Bradstreet.
Innovation Solution
A system and method for managing access credentials using a hosted service system operated by a different party than the database system, involving an authentication service module, token management, key management, and identity and access management modules to securely authenticate and authorize access to external services, ensuring data separation and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If organizations directly manage access credentials for multiple service providers, then service integration efficiency is improved, but security risks and infrastructure exposure increase
Solution Approach 1:
The patent introduces a hosted service system operated by a third party as an intermediary between the organization and multiple service providers. This intermediary manages access credentials on behalf of the organization, enabling efficient service integration while the organization never directly handles sensitive credentials, thus eliminating security risks associated with credential management.
Solution Approach 2:
The patent extracts the credential management function from the organization's infrastructure and places it in a separate hosted service system. By taking out the harmful element (credential exposure risk) from the organization's system, the solution maintains service integration efficiency while removing the security vulnerability.
2Reliability
If a single hosted service system manages all access credentials, then security and compliance are improved, but system complexity and vendor lock-in risks increase
Solution Approach 1:
The hosted service system is designed with multi-functionality to handle diverse credential management requirements for multiple service providers through a unified interface. This universal approach consolidates what could be many separate credential management systems into one, improving security and compliance while actually reducing overall system complexity through standardization.
3Object-generated harmful factors
If access credentials are stored externally at a hosted service system, then security liability is reduced, but access management complexity increases
Solution Approach 1:
The hosted service system implements self-service capabilities that automatically handle credential generation, rotation, and management without requiring complex manual intervention from the organization. This automation reduces liability while the standardized self-service interface actually simplifies access management compared to manual credential handling.
Data Source
AI summary
A computing device includes a memory and one or more processors coupled to the memory. The memory contains machine readable medium storing machine executable code which, when executed by the one or more processors, cause the one or more processors to: identify a service provider providing services or information to at least one of a plurality of organizations having access to a multi-tenant database system provided by a first party; establish an account for the service provider at a hosted service system, the hosted service system provided by a third party that is different from the first party providing the multi-tenant database system, the account for maintaining access credentials for the at least one of the plurality of organizations to the service provider's services or information, wherein the access credentials are not maintained at the multi-tenant database system; and using the credentials, authenticate the at least one of a plurality of organizations for access to the service provider's services or information through the multi-tenant database system. In some embodiments, the one or more processors create login credentials for the account and transmit the login credentials to the service provider so that the service provider may access the account.


