Centralized Server User Rights Control via Verification Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Windows Active Directory lacks centralized control over user rights across multiple servers, leading to security vulnerabilities and complex configuration management, particularly in mixed operating system environments and large networks.

Innovation Solution

A system and method for centralized user rights control involving multiple verification servers and a control server that process and synchronize user rights information, using binding data between IP addresses and user accounts to ensure precise control and security, with local LDAP servers enhancing performance and reducing network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Windows Active Directory is used to manage user rights, then user rights can be managed in a centralized manner, but the system cannot support multiple operating platforms (e.g., Linux) and requires complex configuration

Engineering Contradiction:
Improveplatform compatibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides user rights management into separate modules for different operating platforms (Windows, Linux, etc.), with each platform having its own verification server. This segmentation allows multi-platform support while keeping each platform's configuration independent and manageable, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized control server as an intermediary that manages user rights information and distributes it to various platform-specific verification servers. This mediator layer handles platform compatibility issues centrally, allowing individual servers to work with their native operating systems without complex cross-platform configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user rights information is stored in business servers, then local access is fast, but centralized control and precise management become difficult

Engineering Contradiction:
Improvecentralized controlVSAvoidsynchronization time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The control server pre-processes and validates user rights information before distributing it to verification servers. This preliminary action ensures data consistency and correctness upfront, reducing the need for frequent corrections and re-synchronization, thereby minimizing synchronization time while maintaining centralized control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where verification servers report status changes and errors back to the control server. This allows the control server to detect and correct synchronization issues promptly, maintaining data consistency across distributed servers without requiring constant manual intervention.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If one user account can login to all business servers, then user mobility is improved, but security control is weakened

Engineering Contradiction:
Improveuser mobilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements platform-specific verification servers that apply different security policies and verification methods tailored to each operating system. This allows user mobility across platforms while maintaining appropriate security controls for each platform, as each verification server enforces security rules specific to its platform rather than using a one-size-fits-all approach.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The control server acts as an intermediary that authenticates user accounts and determines which servers the user can access based on centralized policies. This mediator layer enables user mobility by allowing login to multiple servers while maintaining security control through centralized authentication and authorization decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple verification servers are used to support multiple platforms, then platform compatibility is improved, but system complexity increases

Engineering Contradiction:
Improvemulti-platform supportVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the common functionality of user rights management into a centralized control server, while keeping platform-specific verification logic in separate verification servers. This combining of centralized control with distributed platform-specific implementation allows multi-platform support while reducing overall system complexity through functional separation and reuse of common components.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9524382B2System and method for centralizedly controlling server user rights
Publication Date: 2016.12.20 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9524382B2 patent drawing
  • US9524382B2 patent drawing
  • US9524382B2 patent drawing

AI summary

Methods and systems for centralizedly controlling server user rights are provided herein. In an exemplary method, a first verification server can receive an instruction sent by a control server. The instruction can include a user-right-processing instruction or a user-right-adding instruction. The first verification server can process stored information of user rights in response to the user-right-processing instruction sent by the control server to generate processed information of the user rights, or the first verification server can store newly added information of the user rights in response to the user-right-adding instruction sent by the control server. The first verification server can then synchronize the processed information of the user rights or the newly added information of the user rights with a second verification server. The second verification server can be in a communication connection with the first verification server.