Script-Based Computer Maintenance Without Password Logins
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT management systems require significant manual intervention and password-based access for managing and monitoring large numbers of computers, which is time-consuming and poses security risks.
Innovation Solution
A system and method using a framework script to execute sub-task scripts on computers, which are stored in directories corresponding to execution accounts, allowing automated management and monitoring without passwords, and utilizing a Task 1 framework script to schedule and run Task 2 sub-task scripts, including self-healing and data collection, while using secure accounts like Network Service to access resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual password-based access is used for managing computers, then IT professionals can perform management and monitoring tasks, but it consumes large amounts of time and poses security risks
Solution Approach 1:
The system enables self-service automation where the management framework automatically discovers computers, assigns permissions based on organizational units, and executes maintenance tasks without requiring IT professionals to manually log in or manage passwords for each computer individually
Solution Approach 2:
A permission assignment system acts as an intermediary between IT professionals and computers. The system automatically manages permission assignments based on organizational units, eliminating the need for direct password-based access while still enabling comprehensive computer management and monitoring
2Adaptability or versatility
If manual password-based access is used for granting remote resource access, then computers can access remote file systems, but it requires individual attention and password maintenance by IT professionals
Solution Approach 1:
The permission assignment system provides a universal solution that automatically handles remote resource access for all computers in an organizational unit. Instead of individually configuring permissions for each computer, the system applies permission templates universally across groups of computers, reducing administrative complexity while maintaining versatile access capabilities
Solution Approach 2:
The system segments computers into organizational units and applies permission assignments at the unit level rather than individual computer level. This segmentation approach simplifies permission administration by allowing IT professionals to manage access rights for groups of computers simultaneously based on their organizational structure
3Extent of automation
If automated script execution is implemented, then management tasks are automated without passwords, but it requires a framework system to discover and execute sub-task scripts
Solution Approach 1:
The automation framework is segmented into distinct functional components: a permission assignment system that handles authentication, a script discovery mechanism that locates sub-task scripts, and an execution engine that runs the scripts. This segmentation reduces overall system complexity by dividing the automation function into manageable, specialized modules that can operate independently
Data Source
AI summary
A system and method may manage a computer by executing, by a job scheduler on the computer, a framework script written in a scripting language which discovers installed sub-task scripts and executes discovered sub-task scripts. Sub-task scripts may be stored in directories corresponding to accounts in which a sub-task script is to be run. Sub-task scripts may perform maintenance or monitoring tasks. A system and method may assign resource access or permissions for a set of computers, by, for each computer of a set of computers, determining the organizational unit and sub-organizational unit of the computer; and for each computer of the set of computers assigning the computer to a security group, based on the organizational unit and sub-organizational unit of the computer. For each computer, the security group the computer is assigned to may be associated with permissions enforced for each computer in the group.


