Virtualized File Server Domain Join via Intermediary Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtualization environments become increasingly complex to maintain and administer, presenting security risks, particularly in securing access to portions of the system without compromising access credentials.
Innovation Solution
A virtualized file server architecture is implemented with File Server Virtual Machines (FSVMs) that execute on host machines, communicating with storage controllers to store and retrieve storage items, using a storage map to determine item locations and redirect requests for improved performance and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If domain joining is implemented in virtualized file server environments, then system functionality and resource utilization are improved, but security risks and system complexity increase
Solution Approach 1:
The patent introduces a domain controller as an intermediary component that handles domain joining operations separately from the file server virtual machine. The domain controller acts as a mediator that processes authentication and domain management tasks, allowing the file server to maintain its primary function while gaining domain joining capability through the intermediary's support. This resolves the contradiction by adding functionality through a separate component rather than complicating the file server itself.
Solution Approach 2:
The system is segmented into distinct functional components: the file server virtual machine handles file storage and retrieval, while the domain controller handles domain authentication and management. This segmentation allows each component to specialize in its core function, improving overall system functionality without requiring the file server to become a complex multi-functional system. The domain joining capability is provided through the domain controller segment rather than being integrated into the file server segment.
2Ease of operation
If security credentials are provided to the file server for domain joining, then domain access is enabled, but security risks increase
Solution Approach 1:
The patent extracts the security credential management function from the file server and places it in the domain controller. The domain controller is the component that should possess and manage security credentials for domain authentication, not the file server. By taking out the credential storage responsibility from the file server, the system enables domain access functionality while reducing security risks, as credentials are held only by the authorized domain controller rather than being distributed to file servers.
Solution Approach 2:
The domain controller serves as an intermediary that manages security credentials on behalf of the file server. Instead of the file server directly holding or processing domain credentials, the domain controller acts as a mediator that handles authentication requests and manages credential security. This intermediary approach enables domain access functionality while centralizing security management in a dedicated component designed for that purpose.
Data Source
AI summary
Examples described herein include virtualized environments including a virtualized file server. Examples of secure domain join processes are described which may facilitate joining a virtualized file server or portions thereof to a domain. In some examples, the secure domain join process itself, and/or an associated file server virtual machine, may have insufficient credentials to write objects into an active directory. The active directory credentials need not be shared with the file server virtual machine. Rather, in some examples, the secure domain join process may provide a user system with a list of actions to be performed using active directory credentials.


