Centralized Policy Management for Directory Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

On-premises data servers that implement directory services are burdensome, requiring expensive hardware, complex software configuration, and dedicated facilities, as well as additional hardware and software for backup and recovery, and administrators face challenges in managing access across different computing resource service providers.

Innovation Solution

A centralized policy management system allows a single set of credentials to access both managed directory services and other services, with a policy management subsystem that enables administrators to specify and assign policies to users and groups, reducing administrative burden by using template and custom policies stored within the managed directory service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized policy management system is implemented, then administrative burden is reduced and ease of operation improves, but device complexity and system infrastructure requirements worsen

Engineering Contradiction:
Improveadministrative burdenVSAvoidsystem infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a centralized policy management system that acts as an intermediary between directory services and computing resource service providers. This system stores credentials and policies centrally, allowing administrators to manage access to multiple services through a single interface without directly configuring each service provider's infrastructure, thus reducing administrative burden while managing the complexity centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The policy management system provides universal credential storage and policy assignment capabilities that work across multiple different computing resource service providers. A single set of credentials stored in this centralized system can access multiple services, eliminating the need for separate credential management for each service and reducing overall administrative complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple sets of credentials are required for different services, then access control precision improves, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess control precisionVSAvoidcredential management
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The centralized policy management system enables a single set of credentials to function universally across multiple computing resource service providers. The system maintains precise access control by storing service-specific policies associated with each credential, allowing one credential to access multiple services while enforcing service-specific permissions, thus combining operational simplicity with precise access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments access control into two layers: a unified credential layer for authentication and a service-specific policy layer for authorization. This segmentation allows users to have a single credential for logging in while maintaining precise, service-specific access controls through the centralized policy management system's policy assignment mechanisms.

Inventive Principle:
Principle #1Segmentation

3Reliability

If on-premises data servers are deployed, then reliability and security improve, but cost and device complexity worsen

Engineering Contradiction:
Improveservice availabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential storage and policy management functions from traditional on-premises directory service infrastructure and places them in a centralized cloud-based policy management system. This extraction maintains reliability and security by providing centralized control while eliminating the need for organizations to maintain expensive on-premises hardware infrastructure for directory services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of requiring each organization to deploy and maintain their own directory service infrastructure, the system creates a centralized copy of credential storage and policy management capabilities that serves multiple organizations. This approach maintains the reliability of centralized directory services while eliminating the need for duplicate hardware infrastructure across multiple locations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10652235B1Assigning policies for accessing multiple computing resource services
Publication Date: 2020.05.12 AMAZON TECH INC
  • US10652235B1 patent drawing
  • US10652235B1 patent drawing
  • US10652235B1 patent drawing

AI summary

A centralized policy management may allow for one set of credentials to various applications and services offered by a computing resource service provider or other third-party servers. An entity responsible for the administration of a directory made available through a managed directory service may specify one or more policies for users and/or groups of users that utilize the directory. For example, the managed directory service may include a policy management subsystem that manages a set of policies for users and/or groups of users that controls a level of access to applications and services. Administrators can assign one or more policies to a user or a group of users and users can select one or more policies provided to the user by the administrator when attempting to access an application or service.