Proxy User Account SSO for Multi-Tenant Support Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for technical support access in multi-tenant platforms require creating individual accounts for support representatives, which is time-consuming and inefficient, especially when multiple representatives need access, and involves significant account management overhead.
Innovation Solution
Implementing a single sign-on (SSO) system with a proxy user account and security metadata in an identity provider module, allowing support users to access tenant accounts without creating individual local accounts, and dynamically managing access based on user and tenant status.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individual local accounts are created for each technical support representative to access tenant accounts, then access capability is provided, but account management complexity and time consumption increase significantly
Solution Approach 1:
The patent merges multiple support user accounts into a single proxy user account. Instead of creating separate local accounts for each support representative, a single proxy account is created that can be assumed by multiple users sequentially. This eliminates the need to manage multiple individual accounts while maintaining the ability to access tenant accounts for support purposes.
Solution Approach 2:
The proxy user account serves multiple functions: it provides access to tenant accounts, maintains audit trails through assumption logs, and supports multiple support representatives without requiring individual account creation. The single proxy account is universally applicable across multiple support users and tenant accounts.
2Ease of operation
If multiple individual accounts are created for multiple support representatives, then access capability is provided, but time consumption for account creation and administration increases
Solution Approach 1:
The proxy user account is created in advance and pre-configured with necessary permissions to access tenant accounts. This preliminary setup eliminates the need for time-consuming account creation and configuration each time a support representative needs access. The account is ready for immediate use by any authorized support user.
Solution Approach 2:
Multiple support users share a single proxy account, eliminating the need to create and administer multiple individual accounts. This merging approach significantly reduces the time required for account management while maintaining the ability to provide access to multiple support representatives.
3Reliability
If individual local accounts are created for support access, then access control is provided, but security management overhead increases
Solution Approach 1:
The proxy user account acts as an intermediary between support representatives and tenant accounts. It provides a controlled access mechanism where support users can be granted temporary assumption of the proxy account under monitored conditions. This intermediary layer maintains security through assumption logs and validation processes while simplifying access control management.
Solution Approach 2:
The system implements feedback mechanisms through assumption logs that track when and how the proxy account is assumed by support users. This logging provides security monitoring and audit capabilities without requiring complex individual account management. The feedback from the logging system enables security oversight while maintaining operational simplicity.
Data Source
AI summary
Shown is single sign-on support access to tenant accounts in a multi-tenant service platform involving a proxy user account in an identity provider for a tenant account on the service platform having security metadata associated therewith, mapping in the identity provider maps a support user to a proxy user identifier, a corresponding security endpoint in the service platform and mapping of the proxy user account identifier to the tenant account and security metadata. The identity provider authenticates a request to access the tenant account on the service platform, obtains the security credentials for the proxy user identifier, and sends a security assertion with the proxy user identifier and the security metadata to the security endpoint. The endpoint receives and validates the security assertion against the mapping for the proxy user identifier to the tenant account and the security metadata in the service platform, and permits access by the support user to the tenant account in the service platform.


