Proxy Login Authentication Module for Enterprise Account Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems for managing business data in enterprises lack efficient mechanisms for proxy login, leading to increased account management resources and potential authorization issues, such as multi-tiered proxies and mutual proxies.
Innovation Solution
An authentication device and computer-readable medium that implement a first login module for general accounts and a second login module for specialist accounts, allowing proxy login with preset permissions, thereby minimizing the need for additional accounts and preventing inappropriate authorizations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate accounts are issued for general users and specialist users with authorization, then access control to general user data is improved, but account management complexity increases
Solution Approach 1:
The patent introduces a proxy account as an intermediary that mediates between specialist users and general user data. Instead of creating complex multi-level authorization chains, the proxy account serves as a simplified mediator that allows specialists to access data on behalf of general users through a standardized interface, reducing account management complexity while maintaining secure access control
Solution Approach 2:
The proxy account is designed with multi-functionality to handle various authorization scenarios. A single proxy account can serve multiple specialists and manage access to multiple general user accounts, eliminating the need for creating numerous specialized accounts for different authorization combinations, thus simplifying account management while maintaining reliable access control
2Adaptability or versatility
If multiple specialist accounts are created for different authorization levels, then data edit permissions are improved, but the number of accounts and management resources increase
Solution Approach 1:
The patent merges multiple specialist accounts into a single proxy account that consolidates their authorization capabilities. Instead of maintaining separate accounts for each specialist with different permission levels, the proxy account combines their access rights into one unified account, reducing the total number of accounts while preserving the necessary data edit permissions through role-based access control
3Productivity
If proxy login functionality is added to allow specialists to access general user accounts, then operational efficiency is improved, but the risk of unauthorized proxy setups increases
Solution Approach 1:
The system performs preliminary actions by pre-configuring proxy accounts with authorized specialist information before actual data access operations. The proxy account is预先 set up with the necessary authorization credentials and permissions, so that when specialists need to access general user data, they can do so through the pre-validated proxy account without risking unauthorized setups during the access process
Solution Approach 2:
The patent implements feedback mechanisms that monitor and track proxy account usage. The system provides feedback on authorization attempts, access patterns, and proxy operations to detect and prevent unauthorized proxy setups. This continuous monitoring ensures that while proxy login functionality improves operational efficiency, any deviations from authorized usage can be immediately detected and addressed
Data Source
AI summary
An authentication device includes a first login module and a second login module. Upon a login request accompanied by entry of correct authentication information on any one of accounts, the first login module approves a request for first login using the account in account information, the account information comprising the registered accounts distinguished between one or more first accounts and one or more second accounts, the second accounts being allowed for proxy login using the first accounts. Upon a further request for login using any one of the first accounts in a login session started by the first login using any one of the second accounts, the second login module approves a request for second login using the first account, the first account having a preset proxy for approving the proxy login using the second account in the account information.


