白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secure resource authorization for external identities using remote principal objects

專利號
US11888856B2
公開日期
2024-01-30
申請人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Charles Prakash Rao Dasari; Maksym Yaryn; Debashis Choudhury; Jeffrey A Staiman
IPC分類
H04L9/40
技術(shù)領(lǐng)域
domain,principal,remote,tenant,resource,rpo,access,in,directory,data
地域: WA WA Redmond

摘要

Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.

說明書

Group information 804 includes one or more of a group ID that identifies the group, a group domain ID that identifies the domain associated with the group, a task ID that identifies the task associated with the data resource, and a data resource ID that identifies the data resource itself. In embodiments, more or fewer of the listed information entries illustrated for group information 804 may be included.

Group members 806 includes a first group member with identifier “Member1” and a second group member with identifier “Member2,” although more or fewer of the listed member entries illustrated for group members 806 may be included, in addition to an empty set of members, in embodiments. Each entry of group members 806 may include an identifier as a member name, an alias, and/or any other type of identifier. As shown, group members 806 is a set or list of members, e.g., users/remote principals of a domain for which access to a data resource of another domain is sought in performance of a task. Additional information associated with entries of group members 806 is also contemplated herein, such as but not limited to, credential information, member roles, and/or the like, in embodiments. As noted above, group members include applications and/or services, according to embodiments.

權(quán)利要求

1
微信群二維碼
意見反饋