Agentless Access Control System for Server Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex enterprise environments with large numbers of users and software applications face challenges in managing user access and permissions efficiently, leading to increased cyberattack risks due to unnecessary access permissions and performance degradation caused by local agents used in conventional access control systems.

Innovation Solution

An agentless access control system that automates user profile management and access rights management across thousands of computer servers, using an agentless distribution system and an access rights management server to provision configuration settings without local agents, improving security and reducing computational resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local agents are deployed on each computer server for access control, then access management functionality is provided, but computing resources are consumed and performance degrades

Engineering Contradiction:
Improveaccess management functionalityVSAvoidcomputing resources
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent extracts the access control agent from the host computer servers and places it on dedicated access control servers. This separation removes the computational burden from the primary servers while maintaining access management functionality. The agent now runs on specialized infrastructure rather than consuming resources on each individual server.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal access control infrastructure where a single agent instance on each access control server can manage multiple host servers. This multi-functional approach allows one agent to serve multiple purposes and manage multiple systems, reducing the total number of agents needed and thereby reducing overall computing resource consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If local agents are deployed on each computer server for access control, then configuration changes can be implemented, but reliability decreases due to agent crashes or unavailability

Engineering Contradiction:
Improveconfiguration change implementationVSAvoidaccess control availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access control architecture into dedicated access control servers separate from host servers. This segmentation isolates the control plane from the data plane, so that agent crashes on access control servers do not directly impact host server availability. The architectural separation provides fault isolation and improved system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces access control servers as intermediary components between the central management system and the host servers. These intermediaries buffer and manage communication, so that if an agent on an access control server fails, the impact is contained and does not directly affect the host servers. The intermediary layer provides a buffer that protects the overall system from single points of failure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If local agents are deployed on each computer server, then access control is provided, but device complexity increases

Engineering Contradiction:
Improveaccess control provisionVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple access control agent instances into a single unified agent on each access control server. Instead of having distributed agents on every host server, the system combines access control functionality into centralized access control servers, reducing the number of individual agent components and simplifying the overall system architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent shifts the access control architecture from a horizontal distribution model (agents on each server) to a vertical hierarchical model (centralized access control servers managing multiple hosts). This dimensional change in architecture organizes the system in layers, separating management functions from execution functions, which simplifies deployment and maintenance.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Ease of operation

If local agents are deployed on each computer server, then access management is enabled, but time consumption increases for deployment across thousands of servers

Engineering Contradiction:
Improveaccess managementVSAvoiddeployment time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-configuring access control servers with agents before they need to manage host servers. The access control servers are prepared in advance with the necessary access control logic and credentials, so that when they need to manage host servers, the deployment is rapid. This pre-positioning of control infrastructure eliminates the need to deploy agents on thousands of individual servers at once.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11575679B2Agentless access control system for dynamic calibration of software permissions
Publication Date: 2023.02.07 BANK OF AMERICA CORP
  • US11575679B2 patent drawing
  • US11575679B2 patent drawing
  • US11575679B2 patent drawing

AI summary

Systems and methods are provided for efficient and automated control of software permissions and access to network resources across a complex enterprise environment. User access is may be governed by software bundles. Such bundles and bundles may or may not include all programs or access to all systems needed by the user. An access request management tool is provided that includes new process flows and artificial intelligence for automated refining of software access across a complex and large network of computer servers. The management tool may eliminate conventional intermediary systems needed when utilizing centralized access request management. The management tool may check which user has access to a software bundle and may assign the bundle to other users. The management tool may revoke or grant access to a software bundle.