Hosted Credential Service for Multi-Tenant Database Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a cloud-based model, organizations face challenges in securely managing access credentials for services from multiple service providers without exposing their infrastructure to security risks, especially when integrating services from different vendors like Salesforce and Dun & Bradstreet.

Innovation Solution

A system and method for managing access credentials using a hosted service system operated by a different party than the database system, involving an authentication service module, token management, key management, and identity and access management modules to securely authenticate and authorize access to external services, ensuring data separation and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations directly manage access credentials for multiple service providers, then service integration efficiency is improved, but security risks and infrastructure exposure increase

Engineering Contradiction:
Improveservice integration efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hosted service system operated by a third party as an intermediary between the organization and multiple service providers. This intermediary manages access credentials on behalf of the organization, enabling efficient service integration while the organization never directly handles sensitive credentials, thus eliminating security risks associated with credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the credential management function from the organization's infrastructure and places it in a separate hosted service system. By taking out the harmful element (credential exposure risk) from the organization's system, the solution maintains service integration efficiency while removing the security vulnerability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a single hosted service system manages all access credentials, then security and compliance are improved, but system complexity and vendor lock-in risks increase

Engineering Contradiction:
Improvesecurity and complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hosted service system is designed with multi-functionality to handle diverse credential management requirements for multiple service providers through a unified interface. This universal approach consolidates what could be many separate credential management systems into one, improving security and compliance while actually reducing overall system complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-generated harmful factors

If access credentials are stored externally at a hosted service system, then security liability is reduced, but access management complexity increases

Engineering Contradiction:
ImproveliabilityVSAvoidaccess management complexity
Core Design Contradiction:
Object-generated harmful factorsVSDevice complexity

Solution Approach 1:

The hosted service system implements self-service capabilities that automatically handle credential generation, rotation, and management without requiring complex manual intervention from the organization. This automation reduces liability while the standardized self-service interface actually simplifies access management compared to manual credential handling.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11089026B2Managing access credentials for a service provider
Publication Date: 2021.08.10 SALESFORCE INC
  • US11089026B2 patent drawing
  • US11089026B2 patent drawing
  • US11089026B2 patent drawing

AI summary

A computing device includes a memory and one or more processors coupled to the memory. The memory contains machine readable medium storing machine executable code which, when executed by the one or more processors, cause the one or more processors to: identify a service provider providing services or information to at least one of a plurality of organizations having access to a multi-tenant database system provided by a first party; establish an account for the service provider at a hosted service system, the hosted service system provided by a third party that is different from the first party providing the multi-tenant database system, the account for maintaining access credentials for the at least one of the plurality of organizations to the service provider's services or information, wherein the access credentials are not maintained at the multi-tenant database system; and using the credentials, authenticate the at least one of a plurality of organizations for access to the service provider's services or information through the multi-tenant database system. In some embodiments, the one or more processors create login credentials for the account and transmit the login credentials to the service provider so that the service provider may access the account.