Agentless Access Control System for Server Resource Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex enterprise environments with large numbers of users and software applications face challenges in managing user access and permissions efficiently, leading to increased cyberattack risks due to unnecessary access permissions and performance degradation caused by local agents used in conventional access control systems.
Innovation Solution
An agentless access control system that automates user profile management and access rights management across thousands of computer servers, using an agentless distribution system and an access rights management server to provision configuration settings without local agents, improving security and reducing computational resource consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If local agents are deployed on each computer server for access control, then access management functionality is provided, but computing resources are consumed and performance degrades
Solution Approach 1:
The patent extracts the access control agent from the host computer servers and places it on dedicated access control servers. This separation removes the computational burden from the primary servers while maintaining access management functionality. The agent now runs on specialized infrastructure rather than consuming resources on each individual server.
Solution Approach 2:
The patent creates a universal access control infrastructure where a single agent instance on each access control server can manage multiple host servers. This multi-functional approach allows one agent to serve multiple purposes and manage multiple systems, reducing the total number of agents needed and thereby reducing overall computing resource consumption.
2Ease of operation
If local agents are deployed on each computer server for access control, then configuration changes can be implemented, but reliability decreases due to agent crashes or unavailability
Solution Approach 1:
The patent segments the access control architecture into dedicated access control servers separate from host servers. This segmentation isolates the control plane from the data plane, so that agent crashes on access control servers do not directly impact host server availability. The architectural separation provides fault isolation and improved system reliability.
Solution Approach 2:
The patent introduces access control servers as intermediary components between the central management system and the host servers. These intermediaries buffer and manage communication, so that if an agent on an access control server fails, the impact is contained and does not directly affect the host servers. The intermediary layer provides a buffer that protects the overall system from single points of failure.
3Ease of operation
If local agents are deployed on each computer server, then access control is provided, but device complexity increases
Solution Approach 1:
The patent merges multiple access control agent instances into a single unified agent on each access control server. Instead of having distributed agents on every host server, the system combines access control functionality into centralized access control servers, reducing the number of individual agent components and simplifying the overall system architecture.
Solution Approach 2:
The patent shifts the access control architecture from a horizontal distribution model (agents on each server) to a vertical hierarchical model (centralized access control servers managing multiple hosts). This dimensional change in architecture organizes the system in layers, separating management functions from execution functions, which simplifies deployment and maintenance.
4Ease of operation
If local agents are deployed on each computer server, then access management is enabled, but time consumption increases for deployment across thousands of servers
Solution Approach 1:
The patent performs preliminary actions by pre-configuring access control servers with agents before they need to manage host servers. The access control servers are prepared in advance with the necessary access control logic and credentials, so that when they need to manage host servers, the deployment is rapid. This pre-positioning of control infrastructure eliminates the need to deploy agents on thousands of individual servers at once.
Data Source
AI summary
Systems and methods are provided for efficient and automated control of software permissions and access to network resources across a complex enterprise environment. User access is may be governed by software bundles. Such bundles and bundles may or may not include all programs or access to all systems needed by the user. An access request management tool is provided that includes new process flows and artificial intelligence for automated refining of software access across a complex and large network of computer servers. The management tool may eliminate conventional intermediary systems needed when utilizing centralized access request management. The management tool may check which user has access to a software bundle and may assign the bundle to other users. The management tool may revoke or grant access to a software bundle.


