Multi-Customer Support Account Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on access mechanisms in cybersecurity computing environments are unscalable, ineffective, and insecure, failing to provide secure and granular multi-customer support access, which is critical for managed detection and response (MDR) services that require thousands of customers to be supported by a limited number of security engineers.
Innovation Solution
A method and system for configuring and provisioning secure, granular multi-customer support access by creating a multi-customer support account that uses varying access limits and authentication information to selectively access customer accounts and applications, with real-time adjustments based on security policies and machine learning models to optimize access durations and minimize unnecessary access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing single sign-on access mechanisms are used to provide access to multiple customer devices and applications, then security engineers can access multiple customer accounts, but the access control is not granular and cannot be selectively adjusted for different customers
Solution Approach 1:
The patent implements local quality by assigning different access limits to different customer accounts. The system allows the same user account to have varying access permissions (time limits, application restrictions, device limits) for each customer, enabling granular control where each customer receives customized access parameters based on their specific needs and security requirements
Solution Approach 2:
The patent applies dynamics by making access limits adjustable and modifiable in real-time. The system allows administrators to dynamically change access parameters for different customers without creating new user accounts, enabling flexible adaptation to changing operational needs while maintaining secure, customer-specific access control
2Productivity
If a security engineer accesses multiple customer accounts with a single sign-on credential, then operational efficiency is improved, but security and logistical control are compromised
Solution Approach 1:
The patent implements parameter changes by introducing multiple adjustable parameters for each customer account (access time limits, application-specific restrictions, device quotas). These parameters can be individually configured and modified for each customer, allowing the system to maintain secure, customized access controls while enabling efficient multi-customer support through a single user account
3Ease of manufacture
If access limits are set uniformly for all customer accounts, then provisioning is simplified, but the system cannot accommodate varying security policies and operational needs of different customers
Solution Approach 1:
The patent applies universality by creating a single user account structure that can serve multiple customer accounts with different parameters. This multi-functional account system allows one user profile to adapt to various customer needs through configurable access limits, combining the simplicity of universal access with the flexibility of customer-specific customization
Data Source
AI summary
Disclosed herein are methods, systems, and processes to configure and facilitate selective and granular multi-customer support access in cloud-based cybersecurity computing environments. A request to authorize a multi-customer support account (MCSA) is received. Customer accounts that include an anchor tenant customer account and several secondary tenant customer accounts as well as a set of applications associated with the customer accounts are identified. The MCSA is configured to selectively access customer accounts and granularly access associated applications by being designated with a set of varying access limits for the anchor tenant customer account and another set of varying access limits for the secondary tenant customer accounts, each set of varying access limits being made applicable to various instances of applications associated with each of those customer accounts. The designation further restricts a subsequently modifiable access time of the MCSA at least at a client-level, an application level, and a feature-level. The request to authorize the MCSA is then approved.


