白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

System and method for single sign-on technical support access to tenant accounts and data in a multi-tenant platform

專利號
US11888838B2
公開日期
2024-01-30
申請人
Zuora, Inc.(US CA Redwood City)
發(fā)明人
Oleg Mikheev; Joshy Austin; Pushkala Pattabhiraman; Levon Stepanian; Pritesh Parekh
IPC分類
H04L9/40; G06F21/41; H04L67/10; H04W4/60
技術(shù)領(lǐng)域
tenant,account,user,service,idp,platform,access,in,or,tenant's
地域: CA CA Redwood City

摘要

Shown is single sign-on support access to tenant accounts in a multi-tenant service platform involving a proxy user account in an identity provider for a tenant account on the service platform having security metadata associated therewith, mapping in the identity provider maps a support user to a proxy user identifier, a corresponding security endpoint in the service platform and mapping of the proxy user account identifier to the tenant account and security metadata. The identity provider authenticates a request to access the tenant account on the service platform, obtains the security credentials for the proxy user identifier, and sends a security assertion with the proxy user identifier and the security metadata to the security endpoint. The endpoint receives and validates the security assertion against the mapping for the proxy user identifier to the tenant account and the security metadata in the service platform, and permits access by the support user to the tenant account in the service platform.

說明書

The present approach utilizes IDP-initiated SSO. In some examples of IDP initiated SSO, the IDP is configured with links to service providers (SPs), where these links refer to the local IDP's SSO service and pass parameters to the service that identify the remote SP. Instead of visiting the SP directly, a user accesses the IDP site and clicks a link identifying an SP in order to access the remote SP. In one example, this triggers the creation of a SAML assertion or artifact that is sent to the SP using HTTP POST binding. At some point, a user is required to supply their credentials to the IDP, e.g. logon, in order to obtain a valid local security context in the IDP. The user may then request access to a SP, e.g. an SaaS application on a service provider platform, which causes the IDP's SSO service to be called. The SSO service builds a SAML assertion representing the user's logon security context, which is digitally signed and place in an SAML response message. In the case of an HTML context, the SAML response message is placed in an HTML form as a hidden form control, e.g. SAMLResponse. If the convention for identifying a specific application resource at the SP is supported at the IDP and the SP, then the resource URL at the SP can be encoded into the HTML form using a hidden form control, e.g. RelayState. The SSO service sends the HTML form to the SP in the HTTP response, which may include script code to automatically submit the form at the SP.

權(quán)利要求

1
微信群二維碼
意見反饋