SaaS Application Identity Linking for Enterprise Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Software-as-a-Service (SaaS) models face challenges in identifying decision makers for enterprise licensing, managing SaaS applications within enterprises, enforcing enterprise IT policies, and ensuring data privacy and compliance, particularly in scenarios where users adopt SaaS applications without explicit IT department knowledge or control.

Innovation Solution

A programming model that enables SaaS applications to support organic adoption using app-local or social identities, integrates with enterprise identities for single sign-on authentication, and allows seamless transition to enterprise management without code changes, providing features like identity linking, data ownership, and compliance with enterprise policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users adopt SaaS applications without explicit IT department knowledge or control, then ease of operation is improved, but IT department control deteriorates

Engineering Contradiction:
Improveuser adoptionVSAvoidIT management control
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by automatically discovering applications users have adopted before IT management is involved. The discovery mechanism proactively identifies SaaS applications through various signals (login patterns, data flows, user feedback) and prepares management options before IT intervention is required, thus maintaining ease of user adoption while enabling subsequent IT control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops where user adoption behaviors generate signals that are fed back to the discovery mechanism. This continuous feedback enables the system to automatically detect and report on applications users are using, allowing IT to maintain control through informed decision-making without restricting user access.

Inventive Principle:
Principle #23Feedback

2Reliability

If enterprise policies are enforced after software purchase and management, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvepolicy enforcementVSAvoidcode modification
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The programming model incorporates preliminary action by designing the software architecture to be policy-ready from the outset. The model includes pre-configured hooks and interfaces that allow enterprise policies to be applied without requiring code modifications later, thus maintaining ease of operation while ensuring reliable policy enforcement.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses parameter changes to enforce enterprise policies by modifying configuration parameters rather than code structure. The programming model allows policies to be implemented through parameter adjustments in the software configuration, enabling reliable policy enforcement without requiring code changes that would compromise ease of operation.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If SaaS applications use app-local or social identities for organic adoption, then ease of operation is improved, but adaptability deteriorates

Engineering Contradiction:
Improveidentity integrationVSAvoidenterprise identity support
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The programming model implements universality by designing an identity system that can function with multiple identity types (app-local, social, and enterprise identities) through a unified interface. This multi-functional identity framework allows the software to adapt to different enterprise requirements while maintaining ease of operation with various authentication methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system applies dynamics by making the identity mechanism flexible and adaptable. The programming model allows the identity system to dynamically switch between or combine different identity types based on enterprise needs, transforming from a static single-identity approach to a dynamic multi-identity framework that enhances both ease of operation and adaptability.

Inventive Principle:
Principle #15Dynamics

4Ease of repair

If seamless transition to enterprise management is enabled without code changes, then ease of repair is improved, but manufacturing precision deteriorates

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidpolicy implementation accuracy
Core Design Contradiction:
Ease of repairVSManufacturing precision

Solution Approach 1:

The programming model uses parameter changes to enable seamless transition to enterprise management. By implementing policies through configurable parameters rather than code changes, the system achieves ease of deployment and modification while maintaining precise policy implementation through structured parameter validation and enforcement mechanisms.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system introduces an intermediary layer (the programming model interface) that mediates between the software code and enterprise policies. This intermediary allows policy changes to be implemented without modifying the underlying code, providing ease of deployment while ensuring precise policy implementation through the structured interface that translates policies into executable configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10977359B2Automatic takeover of applications installed on client devices in an enterprise network
Publication Date: 2021.04.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10977359B2 patent drawing
  • US10977359B2 patent drawing
  • US10977359B2 patent drawing

AI summary

A system includes a processor and machine readable instructions stored on a tangible machine readable medium and executable by the processor, for a computer program, configured to allow one or more accounts of an enterprise to access the computer program before the enterprise purchases and manages the computer program and to allow the computer program to implement, after the enterprise purchases and manages the computer program, one or more policies of the enterprise regarding use of the computer program without modifying the computer program.