Hosted Directory Service API for Cross-Domain Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing managed directory services limit user management to administrators with access to a member server, restrict access to multiple directories, and do not allow applications or services without direct access to user lists to share resources across domains or directories.

Innovation Solution

A user management and authentication system that allows administrators to manage directories and domains using APIs from devices not associated with a domain, providing authorization and authentication mechanisms for applications and services to access directories through access tokens, enabling single sign-on and multi-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a data server is implemented on-premises to manage directory services, then administrators can control security policies and software on client devices, but the system requires expensive hardware, complex software configuration, and dedicated facilities for powering and cooling

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the directory service functionality from on-premises infrastructure and relocates it to a cloud-based data server. This allows administrators to maintain security policy enforcement capabilities while eliminating the need for local hardware, cooling facilities, and complex software configuration. The directory service is now accessible remotely through network connections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based directory service as an intermediary between administrators and client devices. This intermediary enables security policy management and authentication without requiring direct on-premises infrastructure. The service acts as a mediator that can enforce policies across multiple client devices through standard network protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a data server is implemented on-premises to manage directory services, then administrators can maintain user and device directories, but the system requires expensive network equipment for connectivity and additional hardware for backup and recovery

Engineering Contradiction:
Improvedata management capabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the directory service and its associated data management capabilities from on-premises hardware and relocates them to a cloud-based platform. This eliminates the need for local network equipment, storage hardware, and backup infrastructure while maintaining full data management functionality through remote access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based directory service provides universal access to data management capabilities across multiple client devices and locations. The service consolidates directory management, authentication, and backup functions into a single remotely accessible platform that can serve multiple organizational units without requiring duplicate hardware at each location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If managed directory service is used, then administrators can access directory management, but access is limited to those with direct access to a member server and single directory access only

Engineering Contradiction:
Improvedirectory management accessibilityVSAvoidmulti-directory access
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal directory service architecture that allows administrators to access and manage multiple directories through a single interface. The service provides multi-directory binding capabilities, enabling administrators to work across different directories and domains without requiring separate access to each member server. This enhances both ease of operation and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The cloud-based directory service acts as an intermediary that provides unified access to multiple underlying directory services. Administrators interact with a single service interface that mediates access to multiple directories, eliminating the need for direct member server access and enabling cross-directory operations through the service's coordination capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If traditional directory service access is used, then administrators can manage users and groups, but applications or services without direct access to user lists cannot share resources across domains

Engineering Contradiction:
Improveauthentication securityVSAvoidcross-domain resource sharing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a cloud-based directory service as an intermediary that enables cross-domain resource sharing while maintaining authentication security. The service mediates between applications and multiple directory services, providing unified authentication and authorization capabilities. Applications can access resources across domains through the service's coordination without requiring direct access to underlying user lists or member servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The directory service provides universal authentication and authorization capabilities that work across multiple domains and applications. The service implements multi-directory binding and cross-domain resource sharing through a unified interface, allowing applications to securely access resources across organizational boundaries while maintaining centralized security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10505929B2Management and authentication in hosted directory service
Publication Date: 2019.12.10 AMAZON TECH INC
  • US10505929B2 patent drawing
  • US10505929B2 patent drawing
  • US10505929B2 patent drawing

AI summary

A user, group, and device management and authentication system allows administrators to manage one or more directories with devices that are not associated with a domain of the one or more directories via a set of APIs. The system also allows applications and services that do not have direct access to a list of directory users to access the one or more directories. The user, group, and device management and authentication system may be an add-on system that works in conjunction with a centrally-managed directory service to provide such functionality. For example, the system may generate an access token associated with a particular directory that can be used by a service accessed by an administrator to call an API provided by the system. The API call may be translated into a directory-specific API call that can be used to perform an action in the particular directory.