Unified Directory Service for Multi-Cloud Credential Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers face difficulties in managing multiple directories for on-premises and off-premises data, leading to increased administrative burdens and the need for multiple accounts, as well as complex credential management for accessing various computing resource services.
Innovation Solution
A managed directory service that allows a single set of credentials to access both directory and computing resource services, using a policy management subsystem to generate user policies and obtain temporary credentials for access, thereby reducing the need for multiple accounts and simplifying administrative tasks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a customer maintains separate directories for on-premises and off-premises data, then data management flexibility is improved, but administrative burden and complexity increase
Solution Approach 1:
The patent merges multiple directory services into a single unified directory service that can be accessed both on-premises and off-premises. The directory service is replicated across multiple locations (on-premises data center and off-premises cloud data center), allowing customers to maintain data management flexibility while reducing administrative burden through centralized management of user accounts and credentials across all locations.
Solution Approach 2:
The directory service is designed to be universal, serving multiple functions and locations simultaneously. A single directory service instance can be accessed from on-premises systems and off-premises cloud services, eliminating the need for separate directory services. This multi-functionality allows the same directory to support both on-premises and off-premises data management needs.
2Reliability
If multiple directory services are maintained, then access control for different locations is improved, but credential management complexity increases
Solution Approach 1:
The patent combines multiple credential management systems into a single unified credential store within the directory service. User credentials, authentication mechanisms, and authorization policies are centralized in one directory service that can be accessed from multiple locations, eliminating the need to manage separate credentials for on-premises and off-premises access while maintaining security and access control.
3Reliability
If separate accounts are created for each user in multiple directories, then location-specific access control is improved, but user management complexity increases
Solution Approach 1:
The directory service is designed to provide universal user management that works across multiple locations. A single user account created in the unified directory service automatically provides access control capabilities for both on-premises and off-premises locations. The system maintains location-specific access control policies while managing all users through a single centralized user repository, eliminating the need to create and synchronize separate user accounts in multiple directories.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A user may utilize a set of credentials to access, through a managed directory service, one or more services provided by a computing resource service provider. The managed directory service may be configured to identify one or more policies applicable to the user. These policies may define the level of access to the one or more services provided by the computing resource service provider. Based at least in part on these policies, the managed directory service may transmit a request to an identity management system to obtain a set of temporary credentials that may be used to enable the user to access the one or more services. Accordingly, the managed directory service may be configured to enable the user, based at least in part on the policies and the set of temporary credentials, to access an interface, which can be used to access the one or more services.