Read-Only Domain Controller Partitioning for Branch Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing domain controller systems face challenges in balancing local configurability and security, particularly in branch locations with limited technical support, where centralized systems pose risks of single points of failure and security vulnerabilities due to lack of configurability and potential misuse by non-technical users.

Innovation Solution

Implementing a hub domain controller that partitions user accounts and resources to local read-only domain controllers, allowing only the hub to write configurations, thereby enhancing security and reducing liability by limiting access and ensuring that only authorized users can modify settings, while maintaining user account secrets locally for efficient authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local domain controllers are made writable to improve local configurability, then local users can modify settings directly, but security risks increase due to potential misuse by non-technical users

Engineering Contradiction:
Improvelocal configurabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the domain controller functionality by introducing read-only domain controllers (RODCs) that replicate only a subset of user accounts and settings from the writable hub domain controller. This segmentation allows local configurability for replicated settings while preventing unauthorized modifications to the complete system, thus resolving the contradiction between ease of operation and security risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the hub domain controller writable while keeping branch domain controllers read-only. This creates different operational characteristics at different levels of the hierarchy: the hub maintains full configurability under administrator control, while branches receive replicated configurations that cannot be locally modified, balancing local operational needs with centralized security control.

Inventive Principle:
Principle #3Local quality

2Productivity

If all domain controllers store complete user account information to improve authentication speed, then local authentication is faster, but security exposure increases if a controller is compromised

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments user account data by replicating only specific user accounts and settings from the hub domain controller to branch RODCs, rather than replicating all user information. This selective segmentation enables fast local authentication for authorized users while limiting the security exposure of each branch controller to only the replicated subset, resolving the contradiction between authentication speed and security exposure.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If a centralized hub domain controller is used to simplify management, then administrative control is improved, but the system becomes a single point of failure

Engineering Contradiction:
Improvemanagement complexityVSAvoidsingle point of failure
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-replicating user accounts, settings, and policies from the hub domain controller to branch read-only domain controllers before users need them. This advance replication ensures that branch controllers have the necessary authentication data locally cached, enabling them to function independently if the hub becomes unavailable, thus resolving the contradiction between simplified centralized management and reliability.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If local domain controllers are made read-only to improve security, then unauthorized changes are prevented, but local configurability is lost

Engineering Contradiction:
Improvesecurity protectionVSAvoidlocal configurability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by designing the hub domain controller to serve multiple functions: it acts as the primary writable controller for centralized management while simultaneously functioning as a replication source for multiple read-only branch controllers. The hub replicates appropriate user accounts and settings to each branch based on organizational needs, enabling read-only branches to maintain necessary local configurability while preserving security, thus resolving the contradiction between security protection and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8296824B2Replicating selected secrets to local domain controllers
Publication Date: 2012.10.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8296824B2 patent drawing
  • US8296824B2 patent drawing
  • US8296824B2 patent drawing

AI summary

A domain controller hierarchy includes one or more hub domain controllers in communication with one or more local domain controllers, such as local domain controllers at a branch office. The hub domain controller(s) is writable, while the local domain controller(s) is typically read-only. Non-secure and secure information is partitioned to specific local domain controllers at the one or more hub domain controllers. The non-secure and secure information is then passed from the hub domain controller only to the local domain controller associated with the given partition at the hub domain controller on request. For example, a user requests a logon at a client computer system at a local branch office, and the logon is passed from the local domain controller to the hub domain controller. If authenticated, the user logon account is passed to the local domain controller, where it can be cached to authenticate subsequent requests.