Directory Service Data Decoupling for Flexible Restore

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for backing up and restoring directory services in computing environments are complex and error-prone due to the tight integration of directory services with operating systems, leading to delays or prohibitions in restore processes, especially in adverse events, and can persist problematic executable code across restoration.

Innovation Solution

A technology that decouples directory service data from operating system backups, allowing for independent backup and restoration, enabling the directory service to be restored on different devices and enhancing security by avoiding the persistence of malicious or defective code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If directory services are tightly integrated with operating systems for backup, then backup completeness is improved, but restore complexity and error-proneness increase

Engineering Contradiction:
Improvebackup completenessVSAvoidrestore complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the backup process into two independent components: operating system backup and directory service backup. The directory service backup is further segmented into data extraction, validation, and storage phases. This segmentation allows the directory service to be backed up and restored independently from the operating system, reducing restore complexity while maintaining backup completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts directory service data from the tightly integrated operating system environment. The directory service data is separated into its core components (user accounts, group policies, security settings) and stored independently. This extraction enables the directory service to be restored to different computing devices without requiring the original operating system to be restored, thereby reducing restore complexity and error-proneness.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of manufacture

If traditional backup methods are used for directory services, then backup process is simpler, but restore process is delayed or prohibited in adverse events

Engineering Contradiction:
Improvebackup simplicityVSAvoidrestore delay
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent performs preliminary validation of directory service data during the backup process. The system validates the extracted directory service data against a known good state before storage, identifying and correcting potential issues in advance. This preliminary action ensures that when restoration is needed, the process can proceed immediately without delays for validation or error correction, even in adverse events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service capabilities in the backup and restore process. The system automatically detects the state of directory services, performs validation, and executes restoration without requiring complex manual intervention. The self-service nature of the process reduces both the simplicity of backup execution and the time required for restoration, as the system handles all operations autonomously.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If operating system and directory service are restored together, then system integrity is maintained, but problematic executable code persists across restoration

Engineering Contradiction:
Improvesystem integrityVSAvoidmalicious code persistence
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts directory service data from the operating system executable code. By separating the directory service data (configuration, user accounts, policies) from the operating system binaries and executable code, the system can restore only the necessary data components without restoring potentially problematic executable code. This extraction maintains system integrity by preserving directory service functionality while eliminating the persistence of malicious or defective code.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent discards the operating system executable code during the restore process and recovers only the essential directory service data. The system identifies which components are necessary for directory service functionality and restores only those, deliberately excluding the operating system executable code that may contain malicious or defective elements. This selective discarding and recovering approach maintains system integrity while preventing harmful code persistence.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS10346085B1Distributed restore anywhere for directory services
Publication Date: 2019.07.09 SEMPERIS LTD
  • US10346085B1 patent drawing
  • US10346085B1 patent drawing
  • US10346085B1 patent drawing

AI summary

Technology for backing up and restoring directory services that have a domain hierarchy (e.g., a domain forest). The technology may analyze operating system level backup data of multiple domain controllers and decouple data of the directory service from the backup data. The decoupled data may be absent executable data and may represent the backed up state of the directory service. The decoupled data may be enriched to include additional information about the computing environment and stored in a storage object (e.g., a forest recovery object). The technology may use the storage object to restore the directory service to the same set of computing devices or to a different set of computing device. This may involve configuring one or more of the computing devices to support directory services and coordinating an update to the configured computing devices to restore the backed up state of the directory service.