Agentless Access Control System for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex enterprise environments with large numbers of users and software applications face challenges in managing user access and permissions efficiently, leading to increased cyberattack risks due to unnecessary access and performance degradation caused by local agents used in conventional access control systems.

Innovation Solution

An agentless system for managing access to network resources, which includes an access rights management server, an agentless distribution system, and an API, that automates user profile management, password synchronization, and configuration changes across thousands of computer servers without requiring local agents, improving security and reducing computational resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a local agent is deployed on each computer server to manage access control, then access control functionality can be implemented, but the local agent consumes computing resources and degrades performance of the host computer server

Engineering Contradiction:
Improveaccess control managementVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the access control management functionality from the host computer server by implementing it as a separate, standalone agentless distribution system. This externalizes the computational burden, allowing the host server to focus on its primary functions while the distribution system handles access control, authentication, and configuration management independently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary agentless distribution system that acts as a mediator between administrators and the network resources. This distribution system receives configuration changes, formulates executable instructions, and distributes them to target computer servers without requiring persistent local agents, thus reducing the computational overhead on host systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a local agent is deployed on each computer server to manage access control, then configuration changes can be deployed, but the local agent may crash or be unavailable, causing downtime in configuration management

Engineering Contradiction:
Improveconfiguration deploymentVSAvoidagent availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the configuration management functionality from vulnerable local agents and consolidates it into a resilient, centralized agentless distribution system. This architecture eliminates the single point of failure represented by individual local agents, as the distribution system can manage configurations across the entire network from a centralized location with built-in redundancy and failover capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements prior cushioning by designing the agentless distribution system with pre-built resilience mechanisms, including redundant infrastructure, automated failover protocols, and comprehensive error handling. This ensures that even if individual components experience issues, the overall system maintains availability and continues to deploy configurations reliably across the network.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Adaptability or versatility

If local agents are deployed across thousands of computer servers, then access control can be managed, but the collective computational resources consumed by local agents siphon substantial computing resources

Engineering Contradiction:
Improvenetwork-wide access controlVSAvoidcollective computing resource consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent extracts access control management from numerous distributed local agents and consolidates it into a single, efficient agentless distribution system. This eliminates the multiplicative computational overhead of running agents on thousands of servers, while maintaining the ability to manage access control across the entire network through centralized instruction distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the functionality of numerous分散ed local agents into a single, unified agentless distribution system. By combining these distributed functions into one centralized system, the patent achieves network-wide access control management with significantly reduced total computational resource consumption, while maintaining comprehensive adaptability across all network resources.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If members are assigned access to software applications they do not need, then they gain broader access to resources, but the organization is exposed to increased risk of cyberattack

Engineering Contradiction:
Improveresource accessVSAvoidcyberattack risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms in the agentless distribution system that continuously monitor and evaluate access patterns, user roles, and security events. This enables dynamic adjustment of access permissions based on actual needs and security requirements, automatically revoking unnecessary access while maintaining essential connectivity, thus reducing cyberattack risk without significantly impacting ease of operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11388057B1Agentless control system for lifecycle event management
Publication Date: 2022.07.12 BANK OF AMERICA CORP
  • US11388057B1 patent drawing
  • US11388057B1 patent drawing
  • US11388057B1 patent drawing

AI summary

Systems and methods are provided for efficient and automated control of software permissions and access to network resources across a complex enterprise environment. Systems may configure computer servers in response to an employment status change. Changes to employment status may include leave, termination or hiring. System may interface with a human resources data feed and detect changes to employment status. The system may enable, disable and/or delete a user's account on all appropriate computer servers. Systems may disconnect a software profile in response a detected employment change. Systems may create new software profiles in response to a detected employment change.