Centralized Server User Rights Control via Verification Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Windows Active Directory lacks centralized control over user rights across multiple servers, leading to security vulnerabilities and complex configuration management, particularly in mixed operating system environments and large networks.
Innovation Solution
A system and method for centralized user rights control involving multiple verification servers and a control server that process and synchronize user rights information, using binding data between IP addresses and user accounts to ensure precise control and security, with local LDAP servers enhancing performance and reducing network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Windows Active Directory is used to manage user rights, then user rights can be managed in a centralized manner, but the system cannot support multiple operating platforms (e.g., Linux) and requires complex configuration
Solution Approach 1:
The system divides user rights management into separate modules for different operating platforms (Windows, Linux, etc.), with each platform having its own verification server. This segmentation allows multi-platform support while keeping each platform's configuration independent and manageable, reducing overall system complexity.
Solution Approach 2:
The patent introduces a centralized control server as an intermediary that manages user rights information and distributes it to various platform-specific verification servers. This mediator layer handles platform compatibility issues centrally, allowing individual servers to work with their native operating systems without complex cross-platform configuration.
2Ease of operation
If user rights information is stored in business servers, then local access is fast, but centralized control and precise management become difficult
Solution Approach 1:
The control server pre-processes and validates user rights information before distributing it to verification servers. This preliminary action ensures data consistency and correctness upfront, reducing the need for frequent corrections and re-synchronization, thereby minimizing synchronization time while maintaining centralized control.
Solution Approach 2:
The system implements a feedback mechanism where verification servers report status changes and errors back to the control server. This allows the control server to detect and correct synchronization issues promptly, maintaining data consistency across distributed servers without requiring constant manual intervention.
3Adaptability or versatility
If one user account can login to all business servers, then user mobility is improved, but security control is weakened
Solution Approach 1:
The patent implements platform-specific verification servers that apply different security policies and verification methods tailored to each operating system. This allows user mobility across platforms while maintaining appropriate security controls for each platform, as each verification server enforces security rules specific to its platform rather than using a one-size-fits-all approach.
Solution Approach 2:
The control server acts as an intermediary that authenticates user accounts and determines which servers the user can access based on centralized policies. This mediator layer enables user mobility by allowing login to multiple servers while maintaining security control through centralized authentication and authorization decisions.
4Adaptability or versatility
If multiple verification servers are used to support multiple platforms, then platform compatibility is improved, but system complexity increases
Solution Approach 1:
The patent merges the common functionality of user rights management into a centralized control server, while keeping platform-specific verification logic in separate verification servers. This combining of centralized control with distributed platform-specific implementation allows multi-platform support while reducing overall system complexity through functional separation and reuse of common components.
Data Source
AI summary
Methods and systems for centralizedly controlling server user rights are provided herein. In an exemplary method, a first verification server can receive an instruction sent by a control server. The instruction can include a user-right-processing instruction or a user-right-adding instruction. The first verification server can process stored information of user rights in response to the user-right-processing instruction sent by the control server to generate processed information of the user rights, or the first verification server can store newly added information of the user rights in response to the user-right-adding instruction sent by the control server. The first verification server can then synchronize the processed information of the user rights or the newly added information of the user rights with a second verification server. The second verification server can be in a communication connection with the first verification server.


