IP Library › Granted Patent US 10,530,742
Granted Patent B2
US 10,530,742 · App. 14/098,445 · Granted Jan 7, 2020

Managed directory service

Inventors: Shon Kiran Shah (Redmond, WA); Guruprakash Bangalore Rao (Bellevue, WA); Gaurang Pankaj Mehta (Seattle, WA); Thomas Christopher Rizzo (Sammamish, WA); Sameer Palande (Seattle, WA); Krithi Rai (Redmond, WA)
Assignee: Amazon Technologies Inc.
H04L61/1547G06F9/455G06F9/45558G06F21/604H04L41/5009H04L63/08H04L63/102H04L67/10H04L67/1095H04L67/16G06F2009/45562G06F2009/45587G06F2009/45595G06F2221/2141H04L41/5041H04L41/5058H04L41/5083H04L61/1541H04L61/2007H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,530,742
App. No.
14/098,445
Filed
Dec 5, 2013
Granted
Jan 7, 2020
Kind
B2
Art Unit
2454
USPC
709/223
Abstract

Techniques for connecting computer system entities to remote computer system resources are described herein. A computer system entity that requests access to a remote computer system resource has that request fulfilled by a managed directory service which receives the request and connects the computer system entity to the remote computer system resource. While connected, the managed directory service receives commands to perform operations on the remote computer system resource and, if the computer system entity is authorized to perform the operations on the remote computer system resource, the managed directory service performs the operation on the remote computer system resource.

Claims (38)

1. A computer-implemented method, comprising:

receiving, at a managed directory service, an application programming interface call from a customer of a computing resource service provider, the application programming interface call at least including a request to create a computer system directory within an isolated virtual network of the customer, the isolated virtual network of the customer hosted in a computing environment of the computing resource service provider;

creating, in response to the request, the computer system directory in the isolated virtual network of the customer, the computing system directory being inaccessible to computing resources of the computing resource service provider outside the isolated virtual network without provision of access by the managed directory service, the computer system directory configured to at least join virtual machines within the isolated virtual network to a domain of the computer system directory; and

managing, using the managed directory service, the computer system directory on behalf of the customer, wherein the managed directory service is configured to access the computer system directory.

2. The computer-implemented method of claim 1 , wherein managing the computer system directory includes:

creating a replica of the computer system directory to be usable in an event of unavailability of the computer system directory; and

synchronizing the replica of the computer system directory and the computer system directory in accordance with changes made to the computer system directory.

3. The computer-implemented method of claim 1 , wherein:

the customer hosts one or more customer computer systems in a computing environment of the customer;

the computing environment of the customer is configured to communicate with the isolated virtual network via a virtual private network connection; and

the computer system directory is further configured to join one or more customer computer systems in the computing environment of the customer to the computer system directory.

4. The computer-implemented method of claim 1 , wherein managing the computer system directory includes obtaining one or more snapshots of the computer system directory.

5. The computer-implemented method of claim 4 , further comprising:

receiving a request to obtain a snapshot of the computer system directory; and

obtaining at least one of the one or more snapshots as a result of receiving the request to obtain the snapshot.

6. A system, comprising:

one or more processors; and

memory including executable instructions that, when executed by the one or more processors, cause the system to:

receive, at a managed directory service, from a customer of a computing resource service provider, a request using an application programming interface call to create a computer system directory in a computing environment of the computing resource service provider in accordance with one or more parameters specified by the customer;

fulfill the request by at least creating the computer system directory in the computing environment of the computing resource service provider so that the computer system directory is configured to join, to the computer system directory, computing resources from the computing resource service provider, the computer system directory being created in a virtual network hosted by the computing resource service provider in the computing environment of the computing resource service provider, the virtual network being inaccessible by entities of the computing resource service provider outside the virtual network without provision of access by the managed directory service; and

manage, using the managed directory service, the computer system directory on behalf of the customer, wherein the managed directory service is configured to access the computer system directory.

7. The system of claim 6 , wherein the one or more parameters specify the virtual network of the customer where the computer system directory is created.

8. The system of claim 6 , wherein the instructions that cause the system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the system to maintain a replica of the computer system directory in accordance with changes made to the computer system directory over time.

9. The system of claim 6 , wherein the computer system directory is created to at least join computer system instances to the computer system directory, the computer instances located in a computing environment outside of the computing environment of the computing resource service provider.

10. The system of claim 9 , wherein the computing environment outside of the computing environment of the computing resource service provider is hosted on premises of the customer.

11. The system of claim 6 , wherein the instructions that cause the system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the system to patch executable code for operating the computer system directory.

12. The system of claim 6 , wherein the instructions that cause the system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the system to obtain one or more snapshots of the computer system directory.

13. The system of claim 12 , wherein the instructions that cause the system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the system to instantiate a version of the computer system directory from an obtained snapshot of the one or more snapshots.

14. A non-transitory computer-readable storage medium comprising executable instructions that, if executed by one or more processors of a computer system, cause the computer system to at least:

receive, at a managed directory service, from a customer of a computing resource service provider, a request using an application programming interface call to create a computer system directory in a computing environment of the computing resource service provider in accordance with one or more parameters specified by the customer;

fulfill the received request by at least creating the computer system directory in the computing environment of the computing resource service provider so that the computer system directory is configured to join, to the computer system directory, computing resources of the computing resource service provider, the computer system directory being created in a virtual network of the computing resource service provider where the computing resources are inaccessible to entities of the computing resource service provider outside the virtual network without provision of access by the managed directory service; and

manage, using the managed directory service, the computer system directory on behalf of the customer, wherein the managed directory service is configured to access the computer system directory.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the one or more parameters specify the virtual network of the customer, the virtual network of the customer hosted by the computing resource service provider in the computing environment of the computing resource service provider.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the one or more parameters specify a sub-network of the virtual network of the customer in which the computer system directory is to be created.

17. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions that cause the computer system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the computer system to receive and fulfill application programming interface calls to perform management operations on the computer system directory.

18. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions that cause the computer system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the computer system to synchronize a replica of the computer system directory for use in a failover event.

19. The non-transitory computer-readable storage medium of claim 14 , wherein the computer system directory is created to at least join computer system instances to the computer system directory, the computer system instances located in a computing environment hosted by an entity different from the computing resource service provider.

20. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions that cause the computer system to manage the computer system directory include instructions that, when executed by the one or more processors, cause the computer system to perform updates to executable code used to operate the computer system directory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2014
From: SHAH, SHON KIRAN; RAO, GURUPRAKASH BANGALORE; MEHTA, GAURANG PANKAJ; RIZZO, THOMAS CHRISTOPHER; PALANDE, SAMEER; RAI, KRITHI
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 034197/0598 →
Continuity (2)
Provisional Application 61902790 · Nov 11, 2013
Related Publication 20150134800A1 · May 14, 2015
Cited By (21)
US 12,189,499 US 12,197,398 US 12,217,039 US 12,242,455 US 12,248,434 US 12,248,435 US 12,307,238 US 12,367,108 US 12,400,015 US 12,461,832 US 12,517,874 US 12,541,431 US 12,568,160 US 12,572,503 US 12,591,700 US 12,619,754 US 12,627,681 US 12,641,166 US 12,688,312 US 12,699,560 US 12,711,107