Domainless Cluster Virtual Name Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional failover clusters require domain membership for virtual names, leading to management complexity and exposure to group policy management, which complicates the deployment of highly available file server services and limits authentication options.

Innovation Solution

Implementing a domainless cluster authentication method that uses a virtual name to authenticate with a security domain controller, allowing domainless machines to impersonate domain membership through a ticket-based authentication protocol, such as enhanced Kerberos, to provide secure and highly available file server services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain membership is required for virtual names in traditional failover clusters, then authentication security is maintained through domain controllers, but administrative complexity increases and deployment flexibility decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication function from domain membership by creating a dedicated cluster authentication mechanism. The cluster service account is separated from domain-joined machine accounts, allowing domainless machines to authenticate through alternative means (cluster service credentials, certificate-based authentication) while maintaining security. This segmentation resolves the contradiction by preserving authentication reliability without requiring domain membership overhead.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication layer between domainless machines and the domain controller. Instead of direct domain membership, the system uses cluster service accounts, certificates, or tickets as intermediaries to establish secure authentication. This intermediary mechanism maintains authentication security while eliminating the need for domain joining, thus reducing administrative complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If domain membership is required for virtual names, then group policy management provides centralized control, but deployment flexibility and service availability options are limited

Engineering Contradiction:
Improvegroup policy managementVSAvoiddeployment flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional approach by allowing domainless machines to participate in clustered services without domain membership. Instead of requiring machines to join the domain to access group policy benefits, the system provides alternative authentication mechanisms that achieve the same security and management goals. This inversion resolves the contradiction by maintaining centralized control through other means while significantly increasing deployment flexibility.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the authentication parameters from domain-based credentials to alternative mechanisms such as cluster service accounts, certificates, or tickets. This parameter change allows machines to maintain secure authenticated access to domain resources and group policies without actual domain membership, thereby enhancing deployment flexibility while preserving centralized management capabilities.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If domain joining is performed for cluster machines, then security domain integration is achieved, but overhead and complexity of domain membership management increases

Engineering Contradiction:
Improvesecurity domain integrationVSAvoiddomain membership overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication function from the domain membership requirement. By separating the need for security domain integration from the requirement of actual domain joining, the system uses extracted authentication mechanisms (cluster service accounts, certificates) that provide the same security benefits without the overhead of domain membership management. This resolves the contradiction by maintaining security domain integration while eliminating domain membership complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10798092B2Domain joined virtual names on domainless servers
Publication Date: 2020.10.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10798092B2 patent drawing
  • US10798092B2 patent drawing
  • US10798092B2 patent drawing

AI summary

Services from domainless machines are made available in a security domain under a virtual name. Each machine is not joined to the domain but can reach a security domain controller. The controller controls at least one security domain using an authentication protocol, such as a modified Kerberos protocol. One obtains a set of security domain credentials, generates a cluster name secret, gives the cluster a virtual name, and authenticates the machines to the domain controller using these items. In some cases, authentication uses a ticket-based protocol which accepts the cluster name secret in place of a proof of valid security domain membership. In some, the domain controller uses a directory service which is compatible with an active directory service; the cluster virtual name is provisioned as an account in the directory service. The cluster virtual name may concurrently serve clients on different security domains of the directory service.