白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secure resource authorization for external identities using remote principal objects

專利號
US11888856B2
公開日期
2024-01-30
申請人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Charles Prakash Rao Dasari; Maksym Yaryn; Debashis Choudhury; Jeffrey A Staiman
IPC分類
H04L9/40
技術(shù)領(lǐng)域
domain,principal,remote,tenant,resource,rpo,access,in,directory,data
地域: WA WA Redmond

摘要

Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.

說明書

Additionally, if issues arise during the performance of a task, the owners of data resources on which tasks are performed are enabled to determine specific information regarding the task performance in order track and/or resolve issues via logs/audit reports without being required to maintain a list of group members from a remote domain that have access to the data resource. That is, in some scenarios, the data resource owner may not want to include remote domain users in its directory, of which there may be many in embodiments, because maintaining lists of remote domain users requires additional memory and processing usage, additional administration/overhead, and remote domain user access may only be required for a limited period of time (e.g., to perform a task related to the data resource). Furthermore, the group membership list for access to a data resource for performing a task may include many more members than will actually participate in task performance. As an example, a group can include ten members who are granted access to a data resource, but only a single member may be involved to complete a given task associated with the data resource. Over time, considering that different tasks may also have different corresponding groups with different memberships, a large number of remote domain users, many of which never accessed a data resource in performance of a task, could be maintained by the domain of the data resource owner. The described RPO embodiments, however, allow for the transient access permissions associated with RPOs to have little persisting impact on the domain of the resource owner as the lists of remote domain users are not required to be persisted.

權(quán)利要求

1
微信群二維碼
意見反饋