Centralized Access Control for Windows Server Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems for Windows Servers lack scalability and flexibility, often granting excessive privileges and failing to provide real-time updates and on-demand access management, leading to security risks and inefficiencies in large-scale environments.

Innovation Solution

A system and method for managing access to multiple target servers using an access control processor with a discovery engine, event trigger engine, and client action trigger engine, which enables real-time updates and granular control of user rights through a centralized management server, leveraging existing components like Microsoft System Center Operations Manager (SCOM) for notification and security event handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If local authorization model is used to provide flexible access controls in large scale environment, then access control flexibility is improved, but scalability and administrative manageability deteriorate

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidadministrative manageability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized access control management system that acts as an intermediary between administrators and distributed servers. This management system provides a unified interface for administering access controls across multiple servers, eliminating the need for administrators to manually configure each server individually. The intermediary system handles the complexity of distributed access control while presenting a simplified administrative interface, thus resolving the contradiction between flexibility and manageability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control management system is designed to work across multiple server platforms and environments universally. It can manage access controls for different types of resources (files, printers, applications) across various servers simultaneously through a single unified system. This multi-functional capability allows the system to maintain flexible access controls across diverse environments while centralizing administration, thereby improving both flexibility and manageability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Manufacturing precision

If policy-based access control is implemented with granular control, then access control precision is improved, but system complexity and number of policy objects increase

Engineering Contradiction:
Improveaccess control granularityVSAvoidnumber of policy objects
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent segments access control policies into hierarchical levels: global policies, server-specific policies, and resource-specific policies. This segmentation allows granular control at each level without requiring a separate policy object for every possible access scenario. The segmented approach enables precise access control by combining policies at different levels, reducing the overall number of policy objects needed while maintaining high granularity where required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements partial policy application where not all servers require all policy configurations. Administrators can apply policies selectively to specific servers or groups of servers based on actual needs, rather than creating comprehensive policies for all possible scenarios. This partial action approach reduces the number of policy objects while maintaining necessary granular control where required.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If uniform access rights are granted to administrative groups across all servers, then ease of administration is improved, but security and flexibility deteriorate

Engineering Contradiction:
Improveadministration simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by allowing different access rights configurations for different servers and resources while maintaining centralized management. Administrative groups can have different permission levels on different servers based on local requirements, rather than uniform rights across all systems. The centralized management system handles the complexity of these local variations, preserving both security and ease of administration.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access control system is designed to be dynamic, allowing access rights to be modified in real-time based on changing security requirements. Administrative group memberships and permissions can be adjusted without requiring system reconfiguration or downtime. This dynamic capability enables the system to maintain simple administration while adapting security levels to specific needs, resolving the contradiction between uniformity and security.

Inventive Principle:
Principle #15Dynamics

4Manufacturing precision

If access control changes are made manually on each server, then control precision is improved, but time consumption and labor increase

Engineering Contradiction:
Improveaccess control control precisionVSAvoidaccess control implementation speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent implements preliminary action by allowing administrators to pre-configure access control policies and templates that can be automatically deployed to multiple servers. Rather than manually configuring each server individually, the system prepares access control configurations in advance and applies them systematically across the server fleet. This preliminary preparation maintains precision while dramatically reducing the time and labor required for implementation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control management system incorporates feedback mechanisms that automatically detect and report access control configurations across managed servers. This feedback capability allows the system to verify that policies have been correctly applied and to make automated adjustments if needed, ensuring precision without requiring manual verification on each server. The feedback loop reduces labor while maintaining high control precision.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11930010B2Access control system and method
Publication Date: 2024.03.12 JPMORGAN CHASE BANK NA
  • US11930010B2 patent drawing
  • US11930010B2 patent drawing
  • US11930010B2 patent drawing

AI summary

A system controls access to target servers in a network and includes: a user interface accessible to the target servers; a memory storing a database providing information to the interface; and a server implementing a discovery engine discovering user rights stored at the target servers and delivering the stored user rights to the database, and a trigger engine. The trigger engine is invoked by detection of a request to add or delete a user or group to a list of privileged groups from a first target server, updates the user rights at a local cache on the first target server, and delivers the updated user rights to database. The trigger engine modifies the discovery engine based on the detection of the request. A local security account manager database is changed to insert or remove a domain account to a local group, in response to the request.