Third-Party Application Cloud Content Access via Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods lack an intuitive and integrated way for third-party applications to access content stored in cloud-based platforms, compromising user experience and security, especially in enterprise settings where sensitive documents are involved.

Innovation Solution

A system and method that enable third-party applications to access and edit content within a cloud-based platform securely, using a controlled launching interface and software library/framework, allowing users to choose preferred applications while ensuring content is stored back to the cloud-based environment, thereby maintaining security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party applications are allowed to access content in cloud-based platforms, then ease of operation and user experience are improved, but security and access control are compromised

Engineering Contradiction:
Improveaccess to contentVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between third-party applications and cloud-based platform content. The system uses token-based authentication where the platform verifies the application's credentials and issues access tokens, acting as a trusted intermediary that enables secure access without direct exposure of content to unverified applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments access control by implementing granular permission levels and scope-based access tokens. Instead of binary access control, the system divides access rights into specific segments (read, write, delete permissions) and scopes (specific files, folders, or workspaces), allowing precise control over what third-party applications can access while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple third-party applications can access cloud content, then adaptability and versatility are improved, but system complexity increases

Engineering Contradiction:
Improveapplication accessVSAvoidaccess control mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that works across multiple third-party applications and cloud-based platforms. The token-based access control system serves multiple functions: authentication, authorization, scope management, and session control, providing a multi-functional solution that handles diverse application access requirements through a single standardized mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter-based access control where access tokens contain configurable parameters such as scope, expiration time, permission levels, and resource identifiers. By changing these parameters dynamically, the system can adapt to different application requirements without changing the underlying access control structure, maintaining simplicity while providing versatility.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If third-party applications can store content locally, then ease of operation is improved, but security and data loss risks increase

Engineering Contradiction:
Improvecontent storageVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before allowing content storage operations. The system verifies the application's credentials, checks permission scopes, and validates storage destination permissions before permitting any write operations, preventing unauthorized or insecure storage actions from occurring in the first place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs feedback mechanisms where the cloud-based platform continuously monitors and reports on storage operations performed by third-party applications. The system provides feedback regarding access validity, permission compliance, and security status, enabling real-time control and auditing of storage operations to maintain security while allowing operational flexibility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9552444B2Identification verification mechanisms for a third-party application to access content in a cloud-based platform
Publication Date: 2017.01.24 BOX INC
  • US9552444B2 patent drawing
  • US9552444B2 patent drawing
  • US9552444B2 patent drawing

AI summary

Techniques are disclosed for using a third-party application to access or edit a file within a cloud-based environment within a cloud-based platform or environment. In one embodiment, a method includes, in response to a request to access the content in the cloud-based environment, providing the third-party application with a login view to verify an identity of a user. The login view is generated from a server hosting the environment. The method further includes, upon the verification of the user's identity, providing the requested content to the third-party application.