Proxy-Based Third-Party Account Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face challenges in managing third-party accounts for their users, including account creation, security credential management, and compliance with organizational guidelines, especially when users leave the organization, leading to cumbersome manual processes and difficulties in enforcing usage restrictions.
Innovation Solution
A unified management system that automates account creation, security credential rotation, and authentication, using a proxy server to inspect network traffic and enforce organizational rules, while maintaining transparency to third-party providers and allowing for centralized management of user accounts, including remote access and credential management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual account management is used for third-party services, then users can access required services, but the management process becomes cumbersome and difficult to enforce restrictions when users leave the organization
Solution Approach 1:
The patent introduces an authentication management service as an intermediary between users and third-party services. This service automatically manages account creation, credential rotation, and access restrictions. When a user leaves the organization, the authentication management service automatically revokes access by rotating credentials or disabling accounts, eliminating the need for manual intervention while maintaining ease of operation.
Solution Approach 2:
The authentication management service enables self-service automation where the system automatically performs account management tasks without human intervention. The service monitors user status, automatically creates accounts when users join, rotates credentials periodically, and automatically revokes access when users leave, making the management process autonomous and eliminating manual complexity.
2Reliability
If users personally create third-party accounts for work use, then access to services is obtained, but security credential management becomes difficult and compliance with organizational guidelines is hard to enforce
Solution Approach 1:
The authentication management service acts as an intermediary that handles all security credential operations. It generates and manages credentials for third-party accounts, automatically rotates them according to security policies, and enforces organizational guidelines by controlling which users can access which services. This centralized intermediary approach ensures both high reliability in credential management and ease of compliance enforcement.
Solution Approach 2:
The system implements feedback mechanisms where the authentication management service continuously monitors user access patterns and automatically adjusts credential management based on organizational policies. When compliance issues are detected or user status changes, the service receives feedback and automatically responds by rotating credentials or revoking access, making compliance enforcement straightforward and reliable.
3Productivity
If automated management systems are implemented for third-party accounts, then account creation and credential rotation are simplified, but system complexity increases
Solution Approach 1:
The authentication management service is designed as a universal multi-functional system that handles multiple third-party service accounts simultaneously. It provides a single interface for account creation, credential rotation, access control, and user management across various external services. This universality consolidates what would otherwise be multiple separate management systems into one, improving productivity while managing complexity through consolidation rather than proliferation.
Solution Approach 2:
By positioning the authentication management service as an intermediary layer between the organization's internal systems and external third-party services, the patent isolates the complexity within a single manageable component. This intermediary absorbs the complexity of automated account management, credential rotation protocols, and compliance enforcement, while presenting a simple interface to both users and organizational systems, thereby improving productivity without proportionally increasing visible system complexity.
Data Source
AI summary
Disclosed are various embodiments for management of third-party accounts for users in an organization. A request is received from a client corresponding to a user in an organization to access a third-party network site under management by the organization. The third-party network site is operated by a third party that does not correspond to the organization. It is determined whether network traffic between the client and the third-party network site is routed via a proxy server operated by the organization. Access of the client to a managed account with the third-party network site is denied in response to determining that the network traffic between the client and the third-party network site is not routed via the proxy server.


