Integrated Hosted Directory for Enterprise IT Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and security concerns in managing cloud and SaaS-based IT infrastructure due to disparate servers, devices, and users have led to challenges in system administration and user authentication, particularly in achieving efficient and seamless management across various devices and applications.

Innovation Solution

A central integrated hosted directory system that allows for user authentication, authorization, and management of IT resources across devices and applications, with edge servers replicating portions of the directory to reduce latency and increase accessibility, and an authentication server facilitating secure access using multiple protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a central directory system is implemented to manage IT resources across multiple customers, then management efficiency and security are improved, but system complexity and infrastructure requirements increase

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the directory system into multiple independent edge servers, each handling specific customer data. This allows the central directory to manage multiple customers without becoming a single point of failure or complexity bottleneck, as each edge server operates semi-independently with its own directory copy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces edge servers as intermediary components between the central directory and individual customers. These edge servers act as mediators that replicate directory data locally, reducing the complexity of direct central management while maintaining security and efficiency benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If directory data is replicated to edge servers to reduce latency, then access speed and usability are improved, but data synchronization complexity and storage requirements increase

Engineering Contradiction:
Improveaccess speedVSAvoidsynchronization complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-replicating directory data from the central server to edge servers before it is needed. This allows users to access directory information locally at edge servers without real-time network latency, while synchronization is handled proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying to create local replicas of directory data at edge servers. Instead of complex real-time synchronization mechanisms, the system creates copies of the directory database that can be independently maintained and updated, simplifying the overall synchronization architecture.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple authentication protocols are supported for different devices and applications, then interoperability and accessibility are improved, but security management complexity increases

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing the central directory to support multiple authentication protocols (LDAP, Kerberos, RADIUS, etc.) simultaneously. This allows a single directory system to serve diverse devices and applications with different authentication requirements without requiring separate systems for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server acts as an intermediary that translates between different authentication protocols and the central directory's internal authentication mechanisms. This mediator approach allows multiple protocols to be supported while maintaining a unified security management model at the central directory level.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If edge servers are activated based on system load to handle customer requests, then system scalability and resource utilization are improved, but activation/deactivation complexity and service continuity challenges increase

Engineering Contradiction:
Improveresource utilizationVSAvoidactivation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by making edge servers dynamically activatable and deactivatable based on system load conditions. This allows the system to scale resources up or down automatically, with edge servers being brought online or taken offline according to demand without requiring permanent deployment of all servers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback mechanisms to monitor system load and automatically trigger edge server activation or deactivation decisions. This closed-loop control allows the system to respond to changing conditions automatically, reducing the complexity of manual activation management while maintaining service quality.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10630685B2Integrated hosted directory
Publication Date: 2020.04.21 JUMPCLOUD INC
  • US10630685B2 patent drawing
  • US10630685B2 patent drawing
  • US10630685B2 patent drawing

AI summary

Methods, systems, and devices for enterprise-wide management of disparate devices, applications, and users are described. A cloud-based central server may maintain an integrated hosted directory, which may allow user authentication, authorization, and management of information technology (IT) resources across device types, operating systems, and software-as-a-service (SaaS) and on-premises applications. IT resources for multiple and separate customers may be managed from a single, central directory, and servers may be brought online to allow access to the directory according to system loading.