Cluster Session Event Propagation via Security Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face tedious and time-consuming session management operations when working on multiple machines, requiring repeated identification, session locking, closing, or rebooting across different devices, which can be insecure and inefficient.
Innovation Solution
A method for propagating session management events across a cluster of machines, where a single operation on a first machine is detected, transmitted to a security service, and processed to execute the same event on other machines in the cluster, ensuring security and traceability without the need for repeated user intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user performs session management operations (identification, locking, closing, rebooting) on each machine individually, then security and traceability are maintained, but user time is wasted and operations become tedious
Solution Approach 1:
The system segments session management operations by introducing intermediate components (plugin, security service, directory service) that handle different aspects of the propagation process. The plugin detects events locally, the security service validates and transmits events, and the directory service manages machine clusters, allowing automated propagation while maintaining security controls.
Solution Approach 2:
The invention introduces intermediary components between the user and multiple machines. The plugin acts as a local intermediary that detects events, while the security service and directory service act as central intermediaries that coordinate event propagation across the machine cluster, eliminating the need for direct user intervention on each machine.
2Productivity
If session management events are propagated automatically across all machines in a cluster, then user time is saved and operations are streamlined, but system complexity increases
Solution Approach 1:
The security service performs multiple functions: validating events, determining target machines, transmitting events, and ensuring secure communication. The plugin also serves multiple purposes by detecting various types of session management events and initiating propagation. This multi-functionality reduces the need for separate dedicated components for each function.
Solution Approach 2:
The system performs preliminary actions by pre-configuring machine clusters in the directory service and pre-installing plugins on all machines. This preparation work is done in advance, so that when session management events need to be propagated, the infrastructure is already in place and events can be transmitted immediately without complex real-time decision-making.
3Reliability
If secure identification methods (smart card, biometric system) are used on each machine, then user traceability is improved, but installation complexity and cost increase due to required readers and sensors
Solution Approach 1:
The system creates a virtual copy of the secure identification capability through the plugin architecture. Instead of requiring physical smart card readers or biometric sensors on each machine, the plugin replicates the security functionality by communicating with the user's home machine where the actual identification hardware resides, eliminating the need for duplicate hardware installations.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The present invention essentially relates to a method for propagating session management events between a plurality of machines (101, 102, 103) forming a machine cluster (104). Said method is characterized in that it comprises the following separate steps: generating, by means of a session management user interface (105), a session management event (AUTH, INIT, VER, FER) on a first machine (101) of the machine cluster (104); detecting (134), by means of an installment (106) of the interface (105), the generated event (AUTH, INIT, VER, FER); sending (121), from the installment (106) to a first security service (107) related to the first machine (101), a set of specific information (IS) that is related to the detected event; determining, by means of the first security service (107), a set of target machines; sending (122) the specific information (SI) from the first security service (107) to target security services (109) that are related to the target machines; and processing the specific information at each target security service (109) of the target machines so as to execute, on each target machine that has received said specific information (SI), the session management event (AUTH, INIT, VER, FER) generated on the first machine (101).