Cluster Session Event Propagation via Security Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face tedious and time-consuming session management operations when working on multiple machines, requiring repeated identification, session locking, closing, or rebooting across different devices, which can be insecure and inefficient.

Innovation Solution

A method for propagating session management events across a cluster of machines, where a single operation on a first machine is detected, transmitted to a security service, and processed to execute the same event on other machines in the cluster, ensuring security and traceability without the need for repeated user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user performs session management operations (identification, locking, closing, rebooting) on each machine individually, then security and traceability are maintained, but user time is wasted and operations become tedious

Engineering Contradiction:
Improvesecurity and traceabilityVSAvoiduser time for repeated operations
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments session management operations by introducing intermediate components (plugin, security service, directory service) that handle different aspects of the propagation process. The plugin detects events locally, the security service validates and transmits events, and the directory service manages machine clusters, allowing automated propagation while maintaining security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces intermediary components between the user and multiple machines. The plugin acts as a local intermediary that detects events, while the security service and directory service act as central intermediaries that coordinate event propagation across the machine cluster, eliminating the need for direct user intervention on each machine.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If session management events are propagated automatically across all machines in a cluster, then user time is saved and operations are streamlined, but system complexity increases

Engineering Contradiction:
Improvesession management efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security service performs multiple functions: validating events, determining target machines, transmitting events, and ensuring secure communication. The plugin also serves multiple purposes by detecting various types of session management events and initiating propagation. This multi-functionality reduces the need for separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary actions by pre-configuring machine clusters in the directory service and pre-installing plugins on all machines. This preparation work is done in advance, so that when session management events need to be propagated, the infrastructure is already in place and events can be transmitted immediately without complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure identification methods (smart card, biometric system) are used on each machine, then user traceability is improved, but installation complexity and cost increase due to required readers and sensors

Engineering Contradiction:
Improveuser traceabilityVSAvoidinstallation complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system creates a virtual copy of the secure identification capability through the plugin architecture. Instead of requiring physical smart card readers or biometric sensors on each machine, the plugin replicates the security functionality by communicating with the user's home machine where the actual identification hardware resides, eliminating the need for duplicate hardware installations.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2537314B1Method and apparatus for propagating session-management events
Publication Date: 2015.04.15 EVIDIAN
  • EP2537314B1 patent drawingFigure 1~2
  • EP2537314B1 patent drawingFigure 3
  • EP2537314B1 patent drawingFigure 4~5

AI summary

The present invention essentially relates to a method for propagating session management events between a plurality of machines (101, 102, 103) forming a machine cluster (104). Said method is characterized in that it comprises the following separate steps: generating, by means of a session management user interface (105), a session management event (AUTH, INIT, VER, FER) on a first machine (101) of the machine cluster (104); detecting (134), by means of an installment (106) of the interface (105), the generated event (AUTH, INIT, VER, FER); sending (121), from the installment (106) to a first security service (107) related to the first machine (101), a set of specific information (IS) that is related to the detected event; determining, by means of the first security service (107), a set of target machines; sending (122) the specific information (SI) from the first security service (107) to target security services (109) that are related to the target machines; and processing the specific information at each target security service (109) of the target machines so as to execute, on each target machine that has received said specific information (SI), the session management event (AUTH, INIT, VER, FER) generated on the first machine (101).