IP Library Granted Patent US 10,346,085
Granted Patent B1
US 10,346,085 · App. 16/269,938 · Granted Jul 9, 2019

Distributed restore anywhere for directory services

Inventors: Guy Teverovsky (Kefar Sava, IL); Matan Liberman (Ramat Gan, IL); Michael Bresman (Hoboken, NJ)
Assignee: Semperis
G06F3/065G06F3/067G06F3/0619H04L61/1511H04L61/1523
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,346,085
App. No.
16/269,938
Granted
Jul 9, 2019
Kind
B1
Abstract

Technology for backing up and restoring directory services that have a domain hierarchy (e.g., a domain forest). The technology may analyze operating system level backup data of multiple domain controllers and decouple data of the directory service from the backup data. The decoupled data may be absent executable data and may represent the backed up state of the directory service. The decoupled data may be enriched to include additional information about the computing environment and stored in a storage object (e.g., a forest recovery object). The technology may use the storage object to restore the directory service to the same set of computing devices or to a different set of computing device. This may involve configuring one or more of the computing devices to support directory services and coordinating an update to the configured computing devices to restore the backed up state of the directory service.

Claims (50)

1. A method comprising:

initiating backup operations for a first set of computing devices in a computing environment, wherein the first set of computing devices provides a directory service for the computing environment;

receiving, by a processing device, backup data for one of the computing devices during execution of one of the backup operations;

decoupling data for the directory service from the backup data, wherein the decoupled data represents a first state of the directory service;

storing the decoupled data for the directory service in a storage object;

configuring a second set of computing devices to provide directory services, wherein the directory services comprise a second state; and

updating the second set of computing devices in view of the storage object to replace the second state with the first state of the directory service.

2. The method of claim 1 , wherein the directory service complies with a Lightweight Directory Access Protocol (LDAP) and comprises a hierarchy of domains, wherein the hierarchy of domains comprises a domain forest.

3. The method of claim 1 , wherein the backup data comprises executable data and wherein decoupling the data for the directory service from the backup data causes the decoupled data to be absent the executable data.

4. The method of claim 1 , wherein the first state comprises a state of the directory service at a time when the backup operations are initiated and wherein the second state comprises a default state of the directory services when the directory services are installed on the second set of computing devices.

5. The method of claim 1 , further comprising:

identifying, by the processing device, the directory service for the computing environment, wherein the directory service comprises a hierarchy of domains;

determining a domain controller in the computing environment for each domain of the hierarchy of domains; and

updating the first set of computing devices to include the domain controller for each domain.

6. The method of claim 1 , wherein the storage object comprises domain topology data for the directory service and network mapping data for the computing devices providing the directory service.

7. The method of claim 6 , wherein updating the second set of computing devices comprises using the network mapping data to restore the first state of the directory service to the second set of computing devices in the absence of domain name system (DNS) services.

8. The method of claim 1 , further comprising:

receiving a request to restore the directory service after an adverse event affects the directory service;

determining in view of the storage object that the directory service comprises a hierarchy of domains;

selecting a first computing device from the second set to host a root domain of the hierarchy of domains; and

restoring the first state of the directory service to the second set of computing devise, wherein each computing device of the second set functions as a domain controller for a domain in the hierarchy of domains.

9. The method of claim 1 , wherein configuring the second set of computing devices comprises disabling synchronization of the directory service on at least one of the second set of computing devices.

10. The method of claim 1 , wherein configuring the second set of computing devices comprises:

selecting at least one computing device of the second set of computing devices from a plurality of computing devices that are separate from the first set of computing devices; and

installing directory services on the at least one computing device; and

designating the at least one computing device of the second set of computing devices to function as a domain controller.

11. The method of claim 1 , wherein the first set of computing devices and the second set of computing devices comprise the same set of computing devices.

12. The method of claim 1 , wherein the first set of computing devices and the second set of computing devices comprise a different set of computing devices.

13. A system comprising:

a memory; and

a processing device communicatively coupled to said memory, said processing device configured to:

initiate backup operations for a first set of computing devices in a computing environment, wherein the first set of computing devices provides a directory service for the computing environment;

receive backup data for one of the computing devices during execution of one of the backup operations;

decouple data for the directory service from the backup data, wherein the decoupled data represents a first state of the directory service;

store the decoupled data for the directory service in a storage object;

configure a second set of computing devices to provide directory services, wherein the directory services comprise a second state; and

update the second set of computing devices in view of the storage object to replace the second state with the first state of the directory service.

14. The system of claim 13 , wherein the directory service complies with a Lightweight Directory Access Protocol (LDAP) and comprises a hierarchy of domains, wherein the hierarchy of domains comprises a domain forest.

15. The system of claim 13 , wherein the backup data comprises executable data and wherein to decouple the data for the directory service from the backup data causes the decoupled data to be absent the executable data.

16. The system of claim 13 , wherein the first state comprises a state of the directory service at a time when the backup operations are initiated and wherein the second state comprises a default state of the directory services when the directory services are installed on the second set of computing devices.

17. A non-transitory computer readable storage medium comprising instructions to cause a processor to:

initiate backup operations for a first set of computing devices in a computing environment, wherein the first set of computing devices provides a directory service for the computing environment;

receive backup data for one of the computing devices during execution of one of the backup operations;

decouple data for the directory service from the backup data, wherein the decoupled data represents a first state of the directory service;

store the decoupled data for the directory service in a storage object;

configure a second set of computing devices to provide directory services, wherein the directory services comprise a second state; and

update the second set of computing devices in view of the storage object to replace the second state with the first state of the directory service.

18. The non-transitory computer readable storage medium of claim 17 , wherein the directory service complies with a Lightweight Directory Access Protocol (LDAP) and comprises a hierarchy of domains, wherein the hierarchy of domains comprises a domain forest.

19. The non-transitory computer readable storage medium of claim 17 , wherein the backup data comprises executable data and wherein decoupling the data for the directory service from the backup data causes the decoupled data to be absent the executable data.

20. The non-transitory computer readable storage medium of claim 17 , wherein the first state comprises a state of the directory service at a time when the backup operations are initiated and wherein the second state comprises a default state of the directory services when the directory services are installed on the second set of computing devices.

Assignments (7)
SUPPLEMENT NO. 3 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 9, 2025
From: SEMPERIS LTD.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073057/0979 →
SUPPLEMENT NO. 2 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 8, 2025
From: SEMPERIS LTD
To: HERCULES CAPITAL, INC., AS AGENT
Reel/Frame 073061/0392 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT NUMBER PREVIOUSLY RECORDED AT REEL: 69933 FRAME: 1. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 22, 2025
From: SEMPERIS TECHNOLOGIES INC.
To: SEMPERIS LTD.
Reel/Frame 069990/0061 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 23, 2024
From: SEMPERIS TECHNOLOGIES INC.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 068308/0757 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF ASSIGNEE PREVIOUSLY RECORDED ON REEL 048368 FRAME 0665. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 13, 2023
From: TEVEROVSKY, GUY; LIBERMAN, MATAN; BRESMAN, MICHAEL
To: SEMPERIS TECHNOLOGIES, INC. (US)
Reel/Frame 065969/0001 →
SECURITY INTEREST Recorded Oct 2, 2023
From: SEMPERIS TECHNOLOGIES INC.; SEMPERIS INC.; SEMPERIS GOVERNMENT SOLUTIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065089/0564 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2019
From: TEVEROVSKY, GUY; LIBERMAN, MATAN; BRESMAN, MICHAEL
To: SEMPERIS
Reel/Frame 048368/0665 →
Cited By (3)
US 12,197,467 US 12,229,543 US 12,399,791