Unified Directory Service for Multi-Cloud Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face difficulties in managing multiple directories for on-premises and off-premises data, leading to increased administrative burdens and the need for multiple accounts, as well as complex credential management for accessing various computing resource services.

Innovation Solution

A managed directory service that allows a single set of credentials to access both directory and computing resource services, using a policy management subsystem to generate user policies and obtain temporary credentials for access, thereby reducing the need for multiple accounts and simplifying administrative tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a customer maintains separate directories for on-premises and off-premises data, then data management flexibility is improved, but administrative burden and complexity increase

Engineering Contradiction:
Improvedata management flexibilityVSAvoidadministrative burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple directory services into a single unified directory service that can be accessed both on-premises and off-premises. The directory service is replicated across multiple locations (on-premises data center and off-premises cloud data center), allowing customers to maintain data management flexibility while reducing administrative burden through centralized management of user accounts and credentials across all locations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The directory service is designed to be universal, serving multiple functions and locations simultaneously. A single directory service instance can be accessed from on-premises systems and off-premises cloud services, eliminating the need for separate directory services. This multi-functionality allows the same directory to support both on-premises and off-premises data management needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple directory services are maintained, then access control for different locations is improved, but credential management complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple credential management systems into a single unified credential store within the directory service. User credentials, authentication mechanisms, and authorization policies are centralized in one directory service that can be accessed from multiple locations, eliminating the need to manage separate credentials for on-premises and off-premises access while maintaining security and access control.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate accounts are created for each user in multiple directories, then location-specific access control is improved, but user management complexity increases

Engineering Contradiction:
Improvelocation-specific access controlVSAvoiduser management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The directory service is designed to provide universal user management that works across multiple locations. A single user account created in the unified directory service automatically provides access control capabilities for both on-premises and off-premises locations. The system maintains location-specific access control policies while managing all users through a single centralized user repository, eliminating the need to create and synchronize separate user accounts in multiple directories.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3468103B1Single set of credentials for accessing multiple computing resource services
Publication Date: 2020.07.01 AMAZON TECH INC
  • EP3468103B1 patent drawingFigure 1
  • EP3468103B1 patent drawingFigure 2
  • EP3468103B1 patent drawingFigure 3

AI summary

A user may utilize a set of credentials to access, through a managed directory service, one or more services provided by a computing resource service provider. The managed directory service may be configured to identify one or more policies applicable to the user. These policies may define the level of access to the one or more services provided by the computing resource service provider. Based at least in part on these policies, the managed directory service may transmit a request to an identity management system to obtain a set of temporary credentials that may be used to enable the user to access the one or more services. Accordingly, the managed directory service may be configured to enable the user, based at least in part on the policies and the set of temporary credentials, to access an interface, which can be used to access the one or more services.