Virtual Directory Access Sharing Across Web Services Accounts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud-based directory services cannot share directory access between web services accounts, leading to increased configuration efforts and costs, as customers need to set up separate instances and establish multiple trusts, which complicates the management of on-premises user credentials and cloud-based resources.
Innovation Solution
A mechanism to share directory access between web services accounts by creating a single directory service instance that can be accessed by multiple accounts, using virtual directories and network interfaces to provide access while maintaining isolation and security, allowing applications from different accounts to share the same directory while keeping application data isolated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate instance of cloud-based directory service is set up in each web services account, then each account can access its own directory service, but the configuration effort and cost increase significantly
Solution Approach 1:
The patent merges multiple separate directory service instances into a single shared directory service that can be accessed by multiple web services accounts. Instead of provisioning separate AD instances in each account, the system allows accounts to share a common directory service instance through established trust relationships, thereby reducing configuration complexity while maintaining access availability.
Solution Approach 2:
The directory service instance is designed to serve multiple functions and multiple web services accounts simultaneously. A single directory service can be shared across numerous accounts through trust relationships, making the system universal rather than account-specific, which reduces both configuration effort and operational costs.
2Adaptability or versatility
If multiple trusts are established for hundreds of accounts, then each account can access the directory service, but the number of configurations required becomes unmanageable
Solution Approach 1:
The system performs preliminary actions by establishing a template or framework for trust relationships that can be automatically applied to multiple accounts. Rather than manually configuring each trust relationship individually, the system allows for bulk operations or automated provisioning that pre-configures trust relationships across hundreds of accounts, dramatically reducing setup time.
Solution Approach 2:
The directory service system enables self-service capabilities where accounts can automatically establish or join trust relationships without manual intervention for each individual account. The system handles the complexity of trust management automatically, allowing accounts to access the directory service through automated processes rather than requiring manual configuration of each trust relationship.
3Object-affected harmful factors
If separate directory instances are used in each account, then account isolation is maintained, but the cost and computational resources increase
Solution Approach 1:
The system segments access control and security management at the account level while sharing the underlying directory service infrastructure. Each account maintains its own security policies, access controls, and permissions that are enforced through the trust relationship framework, providing logical isolation without requiring separate physical or virtual directory instances for each account.
Solution Approach 2:
Instead of creating separate directory service instances (full copies) for each account, the system creates lightweight reference copies or views of the shared directory service. Each account receives a virtual or logical representation of the directory with appropriate access controls, eliminating the need to duplicate the entire directory service infrastructure while maintaining security isolation.
Data Source
AI summary
A method includes determining to share access to a directory between a first web services account and a second web services account that lacks access to the directory, wherein the directory is managed by a directory service that executes within a first on-demand configurable pool of shared computing resources, and wherein the second web services account is associated with a second on-demand configurable pool of shared computing resources. The method includes generating a virtual directory for the second web services account, wherein the virtual directory comprises one or more virtual resources that are representations of resources on the directory, and wherein the virtual directory further comprises a reference to the directory. The method further includes receiving an access request to the directory from the second web services account, wherein the access request is received via the reference from the virtual directory to the directory, and then granting the access request.


