Directory Service Data Decoupling for Flexible Restore
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for backing up and restoring directory services in computing environments are complex and error-prone due to the tight integration of directory services with operating systems, leading to delays or prohibitions in restore processes, especially in adverse events, and can persist problematic executable code across restoration.
Innovation Solution
A technology that decouples directory service data from operating system backups, allowing for independent backup and restoration, enabling the directory service to be restored on different devices and enhancing security by avoiding the persistence of malicious or defective code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If directory services are tightly integrated with operating systems for backup, then backup completeness is improved, but restore complexity and error-proneness increase
Solution Approach 1:
The patent segments the backup process into two independent components: operating system backup and directory service backup. The directory service backup is further segmented into data extraction, validation, and storage phases. This segmentation allows the directory service to be backed up and restored independently from the operating system, reducing restore complexity while maintaining backup completeness.
Solution Approach 2:
The patent extracts directory service data from the tightly integrated operating system environment. The directory service data is separated into its core components (user accounts, group policies, security settings) and stored independently. This extraction enables the directory service to be restored to different computing devices without requiring the original operating system to be restored, thereby reducing restore complexity and error-proneness.
2Ease of manufacture
If traditional backup methods are used for directory services, then backup process is simpler, but restore process is delayed or prohibited in adverse events
Solution Approach 1:
The patent performs preliminary validation of directory service data during the backup process. The system validates the extracted directory service data against a known good state before storage, identifying and correcting potential issues in advance. This preliminary action ensures that when restoration is needed, the process can proceed immediately without delays for validation or error correction, even in adverse events.
Solution Approach 2:
The patent implements self-service capabilities in the backup and restore process. The system automatically detects the state of directory services, performs validation, and executes restoration without requiring complex manual intervention. The self-service nature of the process reduces both the simplicity of backup execution and the time required for restoration, as the system handles all operations autonomously.
3Stability of the object's composition
If operating system and directory service are restored together, then system integrity is maintained, but problematic executable code persists across restoration
Solution Approach 1:
The patent extracts directory service data from the operating system executable code. By separating the directory service data (configuration, user accounts, policies) from the operating system binaries and executable code, the system can restore only the necessary data components without restoring potentially problematic executable code. This extraction maintains system integrity by preserving directory service functionality while eliminating the persistence of malicious or defective code.
Solution Approach 2:
The patent discards the operating system executable code during the restore process and recovers only the essential directory service data. The system identifies which components are necessary for directory service functionality and restores only those, deliberately excluding the operating system executable code that may contain malicious or defective elements. This selective discarding and recovering approach maintains system integrity while preventing harmful code persistence.
Data Source
AI summary
Technology for backing up and restoring directory services that have a domain hierarchy (e.g., a domain forest). The technology may analyze operating system level backup data of multiple domain controllers and decouple data of the directory service from the backup data. The decoupled data may be absent executable data and may represent the backed up state of the directory service. The decoupled data may be enriched to include additional information about the computing environment and stored in a storage object (e.g., a forest recovery object). The technology may use the storage object to restore the directory service to the same set of computing devices or to a different set of computing device. This may involve configuring one or more of the computing devices to support directory services and coordinating an update to the configured computing devices to restore the backed up state of the directory service.


