On-demand Service Security System for Phishing Risk Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

On-demand database systems are vulnerable to attacks such as phishing and keystroke logging, leading to unauthorized access to user accounts and associated organizations.

Innovation Solution

Implementing mechanisms to manage the risk of access by determining the source of requests and challenging unauthorized access attempts through authentication methods such as email verification or token validation, utilizing white and black lists to control access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional database systems use traditional login mechanisms, then ease of operation is maintained, but security against phishing and keystroke logging attacks deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to phishing and keystroke logging
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism between the user and the database system. Instead of direct login, the system uses a verification server that mediates the authentication process, checking for malicious software and validating credentials before allowing access. This intermediary layer blocks phishing sites and keystroke loggers from directly accessing user accounts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks before allowing login. The verification server checks for the presence of malicious software on the user's system and validates login credentials against stored information before permitting access. This preliminary action prevents unauthorized access even if login information is compromised.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If access control mechanisms are strengthened to prevent unauthorized access, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification server performs multiple functions within a single system component: it checks for malicious software, validates login credentials, manages user accounts, and controls access rights. By consolidating these functions into one universal authentication service, the patent reduces overall system complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system automatically performs security checks and credential validation without requiring manual intervention. The verification server self-manages the authentication process, automatically detecting malicious software and validating credentials, which simplifies operation while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If the system verifies login information against stored information, then security against compromised credentials is improved, but loss of time for authentication increases

Engineering Contradiction:
Improvecredential verification securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system provides immediate feedback on authentication status by comparing submitted login information against stored credentials in real-time. The verification server quickly determines whether the provided credentials match the stored information and returns this feedback immediately, allowing for rapid authentication decisions without significant time delay.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8898753B1On-demand service security system and method for managing a risk of access as a condition of permitting access to the on-demand service
Publication Date: 2014.11.25 SALESFORCE INC
  • US8898753B1 patent drawing
  • US8898753B1 patent drawing
  • US8898753B1 patent drawing

AI summary

Provided are mechanisms and methods for managing a risk of access to an on-demand service as a condition of permitting access to the on-demand service. These mechanisms and methods for providing such management can help prohibit an unauthorized user from accessing an account of an authorized user when the authorized user inadvertently loses login information. The ability to provide such management may lead to an improved security feature for accessing on-demand services.