Proxy-Based Third-Party Account Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in managing third-party accounts for their users, including account creation, security credential management, and compliance with organizational guidelines, especially when users leave the organization, leading to cumbersome manual processes and difficulties in enforcing usage restrictions.

Innovation Solution

A unified management system that automates account creation, security credential rotation, and authentication, using a proxy server to inspect network traffic and enforce organizational rules, while maintaining transparency to third-party providers and allowing for centralized management of user accounts, including remote access and credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual account management is used for third-party services, then users can access required services, but the management process becomes cumbersome and difficult to enforce restrictions when users leave the organization

Engineering Contradiction:
Improveaccount managementVSAvoidmanagement process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an authentication management service as an intermediary between users and third-party services. This service automatically manages account creation, credential rotation, and access restrictions. When a user leaves the organization, the authentication management service automatically revokes access by rotating credentials or disabling accounts, eliminating the need for manual intervention while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication management service enables self-service automation where the system automatically performs account management tasks without human intervention. The service monitors user status, automatically creates accounts when users join, rotates credentials periodically, and automatically revokes access when users leave, making the management process autonomous and eliminating manual complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If users personally create third-party accounts for work use, then access to services is obtained, but security credential management becomes difficult and compliance with organizational guidelines is hard to enforce

Engineering Contradiction:
Improvesecurity credential managementVSAvoidcompliance enforcement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication management service acts as an intermediary that handles all security credential operations. It generates and manages credentials for third-party accounts, automatically rotates them according to security policies, and enforces organizational guidelines by controlling which users can access which services. This centralized intermediary approach ensures both high reliability in credential management and ease of compliance enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the authentication management service continuously monitors user access patterns and automatically adjusts credential management based on organizational policies. When compliance issues are detected or user status changes, the service receives feedback and automatically responds by rotating credentials or revoking access, making compliance enforcement straightforward and reliable.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated management systems are implemented for third-party accounts, then account creation and credential rotation are simplified, but system complexity increases

Engineering Contradiction:
Improveaccount management efficiencyVSAvoidmanagement system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication management service is designed as a universal multi-functional system that handles multiple third-party service accounts simultaneously. It provides a single interface for account creation, credential rotation, access control, and user management across various external services. This universality consolidates what would otherwise be multiple separate management systems into one, improving productivity while managing complexity through consolidation rather than proliferation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By positioning the authentication management service as an intermediary layer between the organization's internal systems and external third-party services, the patent isolates the complexity within a single manageable component. This intermediary absorbs the complexity of automated account management, credential rotation protocols, and compliance enforcement, while presenting a simple interface to both users and organizational systems, thereby improving productivity without proportionally increasing visible system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10560435B2Enforcing restrictions on third-party accounts
Publication Date: 2020.02.11 AMAZON TECH INC
  • US10560435B2 patent drawing
  • US10560435B2 patent drawing
  • US10560435B2 patent drawing

AI summary

Disclosed are various embodiments for management of third-party accounts for users in an organization. A request is received from a client corresponding to a user in an organization to access a third-party network site under management by the organization. The third-party network site is operated by a third party that does not correspond to the organization. It is determined whether network traffic between the client and the third-party network site is routed via a proxy server operated by the organization. Access of the client to a managed account with the third-party network site is denied in response to determining that the network traffic between the client and the third-party network site is not routed via the proxy server.