Preauthorized Domain Join via Authorization Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Original equipment manufacturers (OEMs) face challenges in preconfiguring computing devices to join a domain managed by a directory service, such as Microsoft Active Directory, due to customer concerns about sharing sensitive administrative credentials.
Innovation Solution
A system that preauthorizes client devices to join a domain by providing authorization information to OEMs, which is then installed on the device, allowing it to automatically join the domain when user credentials are provided, using a network environment with a provisioning server, cache server, and cloud domain controller.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If the OEM configures the computing device to be joined to a domain managed by a directory service, then the configuration process is simplified and automated, but sensitive administrative credentials must be shared with the OEM which creates security risks
Solution Approach 1:
The solution segments the domain joining process into two distinct phases: (1) preauthorization phase where the OEM receives an authorization token without credentials, and (2) execution phase where the actual domain joining occurs using the token. This segmentation allows the OEM to perform configuration tasks without ever handling sensitive administrative credentials, thus resolving the contradiction between ease of manufacture and security risk.
Solution Approach 2:
The patent introduces an authorization token as an intermediary mechanism between the directory service and the OEM. The token acts as a mediator that enables the OEM to perform domain joining operations without direct access to administrative credentials. The token can be validated by the directory service to authorize the domain join operation, thus eliminating the need for the OEM to handle sensitive information while still enabling automated configuration.
2Reliability
If the OEM does not configure domain joining, then administrative credentials remain secure, but the configuration process requires manual intervention and is time-consuming
Solution Approach 1:
The solution implements preliminary action by preauthorizing the client device with an authorization token before the device is deployed to the user. This preauthorization enables the device to automatically join the domain without requiring manual intervention during or after deployment, thus reducing configuration time while maintaining security since the OEM never handles credentials.
Solution Approach 2:
The patent enables the client device to perform self-service domain joining by automatically using the pre-installed authorization token to join the domain managed by the directory service. This self-service capability eliminates the need for manual configuration intervention, reducing configuration time while the token-based mechanism ensures that security is maintained as no credentials are exposed to the OEM.
3Object-affected harmful factors
If manual domain joining is required, then security is maintained by not sharing credentials, but the configuration process becomes complex and requires additional steps
Solution Approach 1:
The authorization token serves as an intermediary that simplifies the configuration process while maintaining security. Instead of requiring complex manual credential entry and validation steps, the token-based mechanism allows the OEM to configure domain joining through simplified procedures. The token encapsulates the necessary authorization information, reducing the complexity of the configuration process while the directory service validates the token to ensure security.
Data Source
AI summary
Disclosed are various approaches for preauthorizing the joining of a client device to a domain managed by a cloud-based directory service. An authorization token can be generated prior to a client device joining the domain. The authorization token can be subsequently installed on a client device at an OEM facility. When a user first logs into the client device, the client device can send the authorization token to the cloud-based directory service in lieu of administrative credentials to prove that the client device has been previously authorized to join the domain.


