Network Administration Rights Control via White List Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing and enforcing security controls in large networks with numerous computers and varying software versions is challenging due to the difficulty in manually applying and maintaining 'white lists' of approved software and administrator privileges, especially with laptops joining and leaving the network randomly.

Innovation Solution

A network management system that identifies and approves software, determines user administration rights, and automatically withdraws privileges from users on other computers if they are not authorized, using a suite of control programs and white lists to enforce security policies across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual methods are used to apply security controls and maintain white lists, then security policy enforcement can be implemented, but the complexity and difficulty of management increases significantly in large networks

Engineering Contradiction:
Improvesecurity control enforcementVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables automatic self-service through the suite of control programs that autonomously identify software, verify white list status, determine administration rights, and enforce security policies without manual intervention. The network management system automatically discovers computers and software, compares against white lists, and enforces restrictions based on pre-defined security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-defining white lists of approved software and pre-configuring security policies before deployment. The control programs are pre-installed on network computers to automatically enforce these pre-established rules, eliminating the need for manual policy application to each computer.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual tracking of software installations and administration rights is performed, then security policies can be monitored, but the time and resources required increase dramatically

Engineering Contradiction:
Improvesecurity policy monitoringVSAvoidmanagement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The control programs continuously monitor software installations and administration rights, providing real-time feedback to the network management system. The system automatically detects when unauthorized software is installed or when administration rights are improperly granted, and immediately enforces corrective actions based on white list comparisons.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs automatic self-monitoring through control programs installed on each network computer that continuously report software status and administration rights to the central management system, eliminating the need for manual tracking and auditing.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive security controls are implemented across all computers, then network security is enhanced, but the difficulty of deployment and maintenance increases with network size

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The suite of control programs provides universal functionality across all network computers, performing multiple security functions including software identification, white list verification, administration rights management, and policy enforcement through a single integrated system that adapts to each computer's specific software inventory.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables easy deployment through pre-configured white lists and security policies that are automatically distributed to all network computers. The control programs are pre-installed and automatically begin enforcing security controls when computers join the network, eliminating complex manual deployment procedures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9608994B2Controlling administration rights
Publication Date: 2017.03.28 1E LTD
  • US9608994B2 patent drawing
  • US9608994B2 patent drawing
  • US9608994B2 patent drawing

AI summary

A computer in a network has an operating system. The operating system is configured to prevent running of software not identified in a list of approved software referred to as a white list. Software absent from the list is prevented from running by the operating system. The network has a server which determines, for each item of software on the white list, the administration rights of the users of computers having that item of software. If a white listed software item is present on one or more computers used by users without admin rights, then the admin rights of any user of other computers having the same white listed software item are withdrawn by instructions sent by the server to the computer.