Agentless Access Control System for Enterprise Profile Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex enterprise environments face challenges in managing user access and permissions across large networks due to the inefficiencies and reliability issues of traditional local agent-based systems, which can lead to significant downtime and resource consumption, compromising security and performance.

Innovation Solution

An agentless access control system that automates user profile management and configuration distribution across thousands of computer servers, using an Access Rights Management (ARM) server and an agentless distribution system to provision configuration changes without local agents, improving consistency, reliability, and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a local agent is deployed on each computer server to manage access control, then access control functionality can be implemented, but system reliability deteriorates due to agent crashes and unavailability

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the access control management functionality from the individual server agents and consolidates it into a centralized access control server. The local agents become thin clients that only execute received commands rather than maintaining independent access control logic, thereby eliminating the reliability issues of distributed agents while preserving access control functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges multiple distributed access control agents into a single centralized access control server. This consolidation ensures that access control management is handled by one reliable system rather than multiple potential failure points, resolving the contradiction between maintaining access control functionality and ensuring system reliability.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If a local agent is deployed on each computer server, then configuration changes can be pushed to servers, but computational resources are significantly consumed by the agents

Engineering Contradiction:
Improveconfiguration managementVSAvoidcomputational resources
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent extracts the heavy computational workload of configuration management from the local agents and relocates it to the centralized access control server. Local agents only perform lightweight tasks of receiving and executing commands, dramatically reducing their resource consumption while maintaining configuration management capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized access control server acts as an intermediary that handles all complex configuration management operations. Instead of each local agent independently managing configurations, the server mediates all configuration changes, pushing only simple execution commands to agents, thereby reducing their computational burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If local agents are deployed across thousands of servers, then access control can be managed, but the collective computational resources consumed by agents siphon substantial computing resources

Engineering Contradiction:
Improvedistributed access controlVSAvoidcollective computational resources
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent merges thousands of distributed agent functions into a single centralized server, eliminating the cumulative resource consumption of multiple agents. The centralized architecture maintains distributed access control capability while concentrating computational resources in one location, preventing the siphoning effect across the network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the resource-intensive access control management functions from the distributed agent network and consolidates them in a centralized server. This extraction eliminates the collective resource drain while preserving the ability to manage access control across distributed systems.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If frequent agent patching is performed to maintain security, then security vulnerabilities are addressed, but system downtime increases

Engineering Contradiction:
ImprovesecurityVSAvoiddowntime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts security management from the local agents and centralizes it in the access control server. Since the server hosts the master security policies and agent binaries, security updates can be pushed to multiple agents simultaneously in one operation rather than patching each agent individually, reducing total downtime while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized server maintains pre-compiled security patches and updated agent binaries ready for deployment. When security updates are needed, they can be pushed to all agents simultaneously without requiring sequential patching, reducing the cumulative downtime across the system while ensuring security is maintained.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11489729B2Agentless access control system for profile management
Publication Date: 2022.11.01 BANK OF AMERICA CORP
  • US11489729B2 patent drawing
  • US11489729B2 patent drawing
  • US11489729B2 patent drawing

AI summary

Systems and methods are provided for efficient and automated control of software permissions and access to network resources across a complex enterprise environment. An access request management (“ARM”) system may formulate a list of functions and associated parameters that may be processed by an agentless distribution system. In response to receiving the set of instructions, the agentless distribution system may generate system-specific executable instructions for performing automated control of one or more of the network resources. The agentless distribution system may formulate system-specific executable instructions for a network resource using commands that, when executed on the network resource, implement automated control in accordance with the parameters defined in the set of instructions provided by the ARM system.