Virtual Directory Access Sharing Across Web Services Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based directory services cannot share directory access between web services accounts, leading to increased configuration efforts and costs, as customers need to set up separate instances and establish multiple trusts, which complicates the management of on-premises user credentials and cloud-based resources.

Innovation Solution

A mechanism to share directory access between web services accounts by creating a single directory service instance that can be accessed by multiple accounts, using virtual directories and network interfaces to provide access while maintaining isolation and security, allowing applications from different accounts to share the same directory while keeping application data isolated.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate instance of cloud-based directory service is set up in each web services account, then each account can access its own directory service, but the configuration effort and cost increase significantly

Engineering Contradiction:
Improvedirectory access availabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate directory service instances into a single shared directory service that can be accessed by multiple web services accounts. Instead of provisioning separate AD instances in each account, the system allows accounts to share a common directory service instance through established trust relationships, thereby reducing configuration complexity while maintaining access availability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The directory service instance is designed to serve multiple functions and multiple web services accounts simultaneously. A single directory service can be shared across numerous accounts through trust relationships, making the system universal rather than account-specific, which reduces both configuration effort and operational costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple trusts are established for hundreds of accounts, then each account can access the directory service, but the number of configurations required becomes unmanageable

Engineering Contradiction:
Improvemulti-account access capabilityVSAvoidsetup time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing a template or framework for trust relationships that can be automatically applied to multiple accounts. Rather than manually configuring each trust relationship individually, the system allows for bulk operations or automated provisioning that pre-configures trust relationships across hundreds of accounts, dramatically reducing setup time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The directory service system enables self-service capabilities where accounts can automatically establish or join trust relationships without manual intervention for each individual account. The system handles the complexity of trust management automatically, allowing accounts to access the directory service through automated processes rather than requiring manual configuration of each trust relationship.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If separate directory instances are used in each account, then account isolation is maintained, but the cost and computational resources increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidcomputational resources
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system segments access control and security management at the account level while sharing the underlying directory service infrastructure. Each account maintains its own security policies, access controls, and permissions that are enforced through the trust relationship framework, providing logical isolation without requiring separate physical or virtual directory instances for each account.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of creating separate directory service instances (full copies) for each account, the system creates lightweight reference copies or views of the shared directory service. Each account receives a virtual or logical representation of the directory with appropriate access controls, eliminating the need to duplicate the entire directory service infrastructure while maintaining security isolation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11102214B2Directory access sharing across web services accounts
Publication Date: 2021.08.24 AMAZON TECH INC
  • US11102214B2 patent drawing
  • US11102214B2 patent drawing
  • US11102214B2 patent drawing

AI summary

A method includes determining to share access to a directory between a first web services account and a second web services account that lacks access to the directory, wherein the directory is managed by a directory service that executes within a first on-demand configurable pool of shared computing resources, and wherein the second web services account is associated with a second on-demand configurable pool of shared computing resources. The method includes generating a virtual directory for the second web services account, wherein the virtual directory comprises one or more virtual resources that are representations of resources on the directory, and wherein the virtual directory further comprises a reference to the directory. The method further includes receiving an access request to the directory from the second web services account, wherein the access request is received via the reference from the virtual directory to the directory, and then granting the access request.