Preauthorized Domain Join via Authorization Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Original equipment manufacturers (OEMs) face challenges in preconfiguring computing devices to join a domain managed by a directory service, such as Microsoft Active Directory, due to customer concerns about sharing sensitive administrative credentials.

Innovation Solution

A system that preauthorizes client devices to join a domain by providing authorization information to OEMs, which is then installed on the device, allowing it to automatically join the domain when user credentials are provided, using a network environment with a provisioning server, cache server, and cloud domain controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the OEM configures the computing device to be joined to a domain managed by a directory service, then the configuration process is simplified and automated, but sensitive administrative credentials must be shared with the OEM which creates security risks

Engineering Contradiction:
Improveconfiguration processVSAvoidsecurity risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The solution segments the domain joining process into two distinct phases: (1) preauthorization phase where the OEM receives an authorization token without credentials, and (2) execution phase where the actual domain joining occurs using the token. This segmentation allows the OEM to perform configuration tasks without ever handling sensitive administrative credentials, thus resolving the contradiction between ease of manufacture and security risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authorization token as an intermediary mechanism between the directory service and the OEM. The token acts as a mediator that enables the OEM to perform domain joining operations without direct access to administrative credentials. The token can be validated by the directory service to authorize the domain join operation, thus eliminating the need for the OEM to handle sensitive information while still enabling automated configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the OEM does not configure domain joining, then administrative credentials remain secure, but the configuration process requires manual intervention and is time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The solution implements preliminary action by preauthorizing the client device with an authorization token before the device is deployed to the user. This preauthorization enables the device to automatically join the domain without requiring manual intervention during or after deployment, thus reducing configuration time while maintaining security since the OEM never handles credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the client device to perform self-service domain joining by automatically using the pre-installed authorization token to join the domain managed by the directory service. This self-service capability eliminates the need for manual configuration intervention, reducing configuration time while the token-based mechanism ensures that security is maintained as no credentials are exposed to the OEM.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If manual domain joining is required, then security is maintained by not sharing credentials, but the configuration process becomes complex and requires additional steps

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authorization token serves as an intermediary that simplifies the configuration process while maintaining security. Instead of requiring complex manual credential entry and validation steps, the token-based mechanism allows the OEM to configure domain joining through simplified procedures. The token encapsulates the necessary authorization information, reducing the complexity of the configuration process while the directory service validates the token to ensure security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11595383B2Preauthorized domain join
Publication Date: 2023.02.28 OMNISSA LLC
  • US11595383B2 patent drawing
  • US11595383B2 patent drawing
  • US11595383B2 patent drawing

AI summary

Disclosed are various approaches for preauthorizing the joining of a client device to a domain managed by a cloud-based directory service. An authorization token can be generated prior to a client device joining the domain. The authorization token can be subsequently installed on a client device at an OEM facility. When a user first logs into the client device, the client device can send the authorization token to the cloud-based directory service in lieu of administrative credentials to prove that the client device has been previously authorized to join the domain.