白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

System and method for single sign-on technical support access to tenant accounts and data in a multi-tenant platform

專利號(hào)
US11888838B2
公開日期
2024-01-30
申請人
Zuora, Inc.(US CA Redwood City)
發(fā)明人
Oleg Mikheev; Joshy Austin; Pushkala Pattabhiraman; Levon Stepanian; Pritesh Parekh
IPC分類
H04L9/40; G06F21/41; H04L67/10; H04W4/60
技術(shù)領(lǐng)域
tenant,account,user,service,idp,platform,access,in,or,tenant's
地域: CA CA Redwood City

摘要

Shown is single sign-on support access to tenant accounts in a multi-tenant service platform involving a proxy user account in an identity provider for a tenant account on the service platform having security metadata associated therewith, mapping in the identity provider maps a support user to a proxy user identifier, a corresponding security endpoint in the service platform and mapping of the proxy user account identifier to the tenant account and security metadata. The identity provider authenticates a request to access the tenant account on the service platform, obtains the security credentials for the proxy user identifier, and sends a security assertion with the proxy user identifier and the security metadata to the security endpoint. The endpoint receives and validates the security assertion against the mapping for the proxy user identifier to the tenant account and the security metadata in the service platform, and permits access by the support user to the tenant account in the service platform.

說明書

FIG. 2 is a block diagram illustrating a conventional architecture 200 for enabling a technician or customer service representative of a multi-tenant service provider to access a tenant's account on Mufti-Tenant SaaS Application Platform 210. FIG. 2 illustrates aspects of an example mufti-tenant architecture that includes the use of credentials for purposes of authenticating each user desiring access to a tenant's account. As shown in the figure, a set of user credentials 222 are stored and referred to by an authentication process 226 to permit service representatives of the platform operator to obtain access to the accounts of individual tenants (shown as “Internal Support Access to Tenants” 220) via Service UI 218. Each tenant may have access to one or more applications, which may be provided by the mufti-tenant platform, typically (although not required) in a Mufti-Tenant Software-as-a-Service (SaaS) application mod& 210 and typically has a separate Tenant Data Store 212A, 212B and 212n. The tenant's users (employees and/or customers) 202 may access the data 212A, 212B and 212n and applications resident on platform 210 remotely through Tenant User Interface 217A, 217B and 217n using a suitable client device and communications network. Data used in service and support may be maintained in Service Store 225.

權(quán)利要求

1
微信群二維碼
意見反饋