Integrated Hosted Directory with Edge Servers for Low-Latency Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing IT infrastructure across disparate devices, applications, and users in a cloud and SaaS-based environment is labor-intensive and complex, with challenges in system administration, security, and interoperability.
Innovation Solution
A central directory system that integrates user authentication, authorization, and management across devices and applications, allowing for multitenant directory management with edge servers and replica modules to reduce latency and increase usability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a central directory system is implemented for enterprise-wide management, then system administration efficiency is improved, but device complexity increases
Solution Approach 1:
The directory system is segmented into multiple edge servers distributed across different locations. Each edge server manages a portion of the directory, allowing the system to scale horizontally. This segmentation reduces the complexity burden on any single server while maintaining centralized management capabilities through the master directory.
Solution Approach 2:
Edge servers act as intermediaries between the master directory and client devices. These intermediaries cache directory information locally, reducing latency and decreasing the complexity of direct communication paths. The edge servers handle authentication and authorization locally, simplifying the overall system architecture.
2Ease of operation
If cloud-based SaaS infrastructure is adopted, then ease of operation is improved, but interoperability between disparate resources deteriorates
Solution Approach 1:
The directory system is designed with universal protocols and standardized interfaces that enable it to manage diverse resources including cloud-based SaaS applications, on-premises servers, and various device types. The system provides unified authentication and authorization mechanisms that work across different platforms, maintaining interoperability while preserving the ease of cloud-based operation.
Solution Approach 2:
The system dynamically adjusts its operational parameters based on the resource type being accessed. When connecting to cloud resources, it uses cloud-specific authentication protocols, while maintaining compatibility with on-premises systems through standardized LDAP and other protocols. This parameter adaptation allows seamless interoperability without compromising ease of operation.
3Power
If multiple edge servers are activated for multitenant directory management, then system load capacity is improved, but device complexity increases
Solution Approach 1:
Edge servers are pre-configured with directory synchronization capabilities and authentication protocols before being activated. The master directory automatically provisions new edge servers with necessary credentials and configuration parameters, eliminating the need for manual complex setup. This preliminary preparation enables rapid scaling while keeping individual server configuration simple.
Solution Approach 2:
The system implements automated monitoring and feedback mechanisms that track system load across edge servers. When load thresholds are exceeded, the system automatically activates additional edge servers and redistributes directory partitions. This feedback-driven scaling handles increased load capacity requirements without requiring manual intervention or complex reconfiguration of existing servers.
Data Source
AI summary
Methods, systems, and devices for enterprise-wide management of disparate devices, applications, and users are described. A cloud-based central server may maintain an integrated hosted directory, which may allow user authentication, authorization, and management of information technology (IT) resources across device types, operating systems, and software-as-a-service (SaaS) and on-premises applications. IT resources for multiple and separate customers may be managed from a single, central directory, and servers may be brought online to allow access to the directory according to system loading.


