白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secure resource authorization for external identities using remote principal objects

專利號
US11888856B2
公開日期
2024-01-30
申請人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Charles Prakash Rao Dasari; Maksym Yaryn; Debashis Choudhury; Jeffrey A Staiman
IPC分類
H04L9/40
技術(shù)領(lǐng)域
domain,principal,remote,tenant,resource,rpo,access,in,directory,data
地域: WA WA Redmond

摘要

Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.

說明書

Flow diagram 400 begins at step 402 in which a user device 470 associated with tenant A 226 is authenticated to tenant 226. Authentication is performed with user credentials associated with the domain of tenant 226, and in embodiments, is performed via a tenant portal of portals 216. Step 402 is optional in embodiments for which the user of user device 470 authenticates via a different tenant portal (e.g., of tenant B/P 228) or via a system portal, i.e., an alternate portal, of portals 216 related to task creation in step 404, e.g., for a support task related to an identity problem in directory A 468 and requested to tenant B/P 228 as a support service. This alternate portal is configured to authorize the user of user device 470 to a limited space in the domain of tenant B/P 228 for creation of the task, e.g., a support task, based on user-domain credentials from tenant B/P 228, in step 404. That is, the IdP for tenant B/P 228, or for system 200, is configured to recognize the user of user device 470 for the purposes of generating task requests via portals 216. A reply indicating task creation is provided back in step 406.

權(quán)利要求

1
微信群二維碼
意見反饋