Proxy User Account SSO for Multi-Tenant Support Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for technical support access in multi-tenant platforms require creating individual accounts for support representatives, which is time-consuming and inefficient, especially when multiple representatives need access, and involves significant account management overhead.

Innovation Solution

Implementing a single sign-on (SSO) system with a proxy user account and security metadata in an identity provider module, allowing support users to access tenant accounts without creating individual local accounts, and dynamically managing access based on user and tenant status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individual local accounts are created for each technical support representative to access tenant accounts, then access capability is provided, but account management complexity and time consumption increase significantly

Engineering Contradiction:
Improveaccess capabilityVSAvoidaccount management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple support user accounts into a single proxy user account. Instead of creating separate local accounts for each support representative, a single proxy account is created that can be assumed by multiple users sequentially. This eliminates the need to manage multiple individual accounts while maintaining the ability to access tenant accounts for support purposes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The proxy user account serves multiple functions: it provides access to tenant accounts, maintains audit trails through assumption logs, and supports multiple support representatives without requiring individual account creation. The single proxy account is universally applicable across multiple support users and tenant accounts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If multiple individual accounts are created for multiple support representatives, then access capability is provided, but time consumption for account creation and administration increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidaccount creation and administration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The proxy user account is created in advance and pre-configured with necessary permissions to access tenant accounts. This preliminary setup eliminates the need for time-consuming account creation and configuration each time a support representative needs access. The account is ready for immediate use by any authorized support user.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Multiple support users share a single proxy account, eliminating the need to create and administer multiple individual accounts. This merging approach significantly reduces the time required for account management while maintaining the ability to provide access to multiple support representatives.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If individual local accounts are created for support access, then access control is provided, but security management overhead increases

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity management overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The proxy user account acts as an intermediary between support representatives and tenant accounts. It provides a controlled access mechanism where support users can be granted temporary assumption of the proxy account under monitored conditions. This intermediary layer maintains security through assumption logs and validation processes while simplifying access control management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms through assumption logs that track when and how the proxy account is assumed by support users. This logging provides security monitoring and audit capabilities without requiring complex individual account management. The feedback from the logging system enables security oversight while maintaining operational simplicity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11888838B2System and method for single sign-on technical support access to tenant accounts and data in a multi-tenant platform
Publication Date: 2024.01.30 ZUORA INC
  • US11888838B2 patent drawing
  • US11888838B2 patent drawing
  • US11888838B2 patent drawing

AI summary

Shown is single sign-on support access to tenant accounts in a multi-tenant service platform involving a proxy user account in an identity provider for a tenant account on the service platform having security metadata associated therewith, mapping in the identity provider maps a support user to a proxy user identifier, a corresponding security endpoint in the service platform and mapping of the proxy user account identifier to the tenant account and security metadata. The identity provider authenticates a request to access the tenant account on the service platform, obtains the security credentials for the proxy user identifier, and sends a security assertion with the proxy user identifier and the security metadata to the security endpoint. The endpoint receives and validates the security assertion against the mapping for the proxy user identifier to the tenant account and the security metadata in the service platform, and permits access by the support user to the tenant account in the service platform.