Automated Virtual Machine Domain Join via Pre-configured Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The process of manually joining a virtual machine instance to a managed directory is labor-intensive, prone to errors, and exposes credentials, especially when dealing with alternative networks.

Innovation Solution

An automated system where a virtual machine instance is automatically joined to a managed directory through a virtual computer system service, using an agent that requests and obtains necessary network address information and temporary credentials to create a computer account, facilitating secure and efficient domain joining.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual domain join process is used, then administrator can join virtual machine instance to managed directory, but the process is labor intensive and time consuming

Engineering Contradiction:
Improvedomain join speedVSAvoidtime for domain join process
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring the virtual machine image with domain join capabilities and credentials before deployment. The agent is pre-installed on the virtual machine image, and domain join parameters are prepared in advance, allowing the actual domain join to execute automatically without manual intervention during deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The virtual machine instance performs self-service by automatically joining the managed directory using the pre-configured agent and credentials. The system enables the virtual machine to autonomously complete the domain join process without requiring administrator intervention, thereby improving productivity and reducing time loss.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual domain join process is used, then administrator can authenticate and join virtual machine instance, but the process is prone to errors

Engineering Contradiction:
Improveaccuracy of domain joinVSAvoidsimplicity of domain join process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by enabling the virtual machine instance to automatically perform domain join operations using pre-configured credentials and parameters. This eliminates manual authentication steps that are prone to human error, thereby improving reliability while maintaining ease of operation through automated processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The agent provides feedback mechanisms to verify successful domain join and report any errors. This automated feedback loop ensures accurate execution of the domain join process and allows for immediate correction of any issues, improving reliability without complicating the operation.

Inventive Principle:
Principle #23Feedback

3Reliability

If administrator credentials are used for domain join, then virtual machine instance can be joined to managed directory, but credentials are exposed especially in alternative networks

Engineering Contradiction:
Improvesecurity of credentialsVSAvoidlevel of automated domain join
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The system extracts administrator credentials from the manual process and embeds them securely within the pre-configured virtual machine image. The credentials are taken out of the administrator's direct control and integrated into the automated agent, which manages them securely during the domain join process, reducing credential exposure risk.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The agent acts as an intermediary between the virtual machine instance and the managed directory service. It handles credential management and authentication processes automatically, preventing direct exposure of administrator credentials while enabling automated domain join. The intermediary securely manages the credentials without requiring administrator intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If automated domain join is implemented, then deployment speed is improved, but system complexity increases

Engineering Contradiction:
Improvedeployment speedVSAvoidcomplexity of domain join system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system applies preliminary action by pre-configuring the virtual machine image with the domain join agent and necessary parameters before deployment. This upfront preparation simplifies the actual deployment process, enabling fast automated domain join without requiring complex runtime configurations or manual interventions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The agent is designed as a universal component that can be integrated into different virtual machine images and work with various managed directory services. This multi-functionality reduces system complexity by using a single standardized approach for domain join across different scenarios, rather than requiring specialized solutions for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12061920B2Automatic domain join for virtual machine instances
Publication Date: 2024.08.13 AMAZON TECH INC
  • US12061920B2 patent drawing
  • US12061920B2 patent drawing
  • US12061920B2 patent drawing

AI summary

A customer submits a request to a virtual computer system service to launch a virtual machine instance and to join this instance to a managed directory. The service may obtain, from the customer, a domain name and Internet Protocol addresses for the selected directory, which is then stored within a systems management server. When launched, the instance may initiate an agent, which may communicate with the systems management server to obtain the configuration information. The agent may use this configuration information to establish a communications channel with the managed directory and create a temporary set of computer credentials that may be used to verify that the customer is authorized to join the virtual machine instance to the managed directory. If the credentials are valid, the managed directory may generate a computer account within the managed directory, which may be used to join the virtual machine instance to the managed directory.