Multi-Forest Manager Proxy Generation for Cross-Forest Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current implementations for managing user accounts and groups across multiple computer networks, or forests, are complex due to the rules governing security proxies and contact proxies, which complicate access and membership between different network forests.

Innovation Solution

The method involves generating contact objects and security proxy objects to represent user accounts and groups in other forests, allowing for cross-forest access and membership, with a multi-forest manager system determining the appropriate representation based on forest trust relationships and group types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security proxies and contact proxies are generated to enable cross-forest access and membership, then interoperability between forests is improved, but system complexity increases due to complex rules for determining and managing proxies

Engineering Contradiction:
Improveinteroperability between forestsVSAvoidcomplexity of proxy management rules
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a forest trust relationship as an intermediary mechanism that mediates cross-forest access. Instead of complex direct proxy management between all forest pairs, the trust relationship acts as a mediator that simplifies the interaction model. When Forest A trusts Forest B, users and groups from Forest B can access resources in Forest A through this trusted relationship, reducing the need for intricate proxy generation rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the complex cross-forest access problem into manageable parts by introducing hierarchical levels: forest level (with trust relationships), domain level (with users and groups), and object level (with proxies). This segmentation allows each level to handle specific aspects of access management independently, reducing overall system complexity while maintaining interoperability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If multiple forests share user accounts and groups through proxies, then resource accessibility is improved, but configuration complexity increases

Engineering Contradiction:
Improveresource accessibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing forest trust relationships in advance before configuring cross-forest access. Administrators first define which forests trust each other, creating a pre-configured access framework. Then, when users or groups need cross-forest access, the system automatically leverages these pre-established trust relationships to generate appropriate proxies, significantly reducing configuration complexity compared to setting up each access relationship individually.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security proxies are generated for group members in cross-forest groups, then cross-forest security is improved, but management complexity increases

Engineering Contradiction:
Improvecross-forest securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the system to automatically generate and manage security proxies for group members in cross-forest scenarios. When a user from a trusted forest is added to a security group, the system automatically determines the appropriate forest trust relationship and generates the necessary security proxy without manual intervention. This automation maintains security reliability while reducing management complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8095629B2Managing user accounts and groups in multiple forests
Publication Date: 2012.01.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8095629B2 patent drawing
  • US8095629B2 patent drawing
  • US8095629B2 patent drawing

AI summary

Methods, systems, and computer program products are provided for managing contact proxies and security proxies in networks that are organized as forests. For instance, contact proxies may be generated to represent user accounts and groups in forests other than the home forests of the user accounts and groups. Security proxy objects may be generated to represent group members (e.g., security principals and groups) in groups in forests other than the home forests of the group members. Furthermore, when both a contact object and a security proxy object exist for a member added to a group, one of the contact object or the security proxy object may be selected to represent the member in the group.