白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secure resource authorization for external identities using remote principal objects

專利號
US11888856B2
公開日期
2024-01-30
申請人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Charles Prakash Rao Dasari; Maksym Yaryn; Debashis Choudhury; Jeffrey A Staiman
IPC分類
H04L9/40
技術(shù)領(lǐng)域
domain,principal,remote,tenant,resource,rpo,access,in,directory,data
地域: WA WA Redmond

摘要

Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.

說明書

In embodiments, the telemetry processing pipeline of STS 232 that generates token 600 incorporates the RPO modeling/requirements noted herein, and is configured to emit sign-in logs or audit reports in both the domain of the user/remote principal and the domain of the data resource owner. As similarly noted above for token generation in flow diagram 400, embodiments provide for the logs/audit reports provided to the domain of the data resource owner to be exclusive of any user-/remote principal-specific information, while the logs/audit reports that are emitted into the domain of the user/remote principal are permitted to include the actual user/remote principal information. In other embodiments, however, portions of principal-specific/identifying information may be included in logs/audit reports based on an agreement therefor between data resource owners and accessors.

Accessing secure data resources, such as directory data, via remote principals is a sensitive operation. Because there are at least two different organizations involved in setting up the access controls, and one organization obtaining the ability to read data of another organization, embodiments herein provide for the sign-in/authentication and all task activity, which are important data for audits, to be tracked to prevent abuse and further reduce the risk of using the described embodiments for conducting tasks and operations on data resources.

權(quán)利要求

1
微信群二維碼
意見反饋