白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secure resource authorization for external identities using remote principal objects

專利號
US11888856B2
公開日期
2024-01-30
申請人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Charles Prakash Rao Dasari; Maksym Yaryn; Debashis Choudhury; Jeffrey A Staiman
IPC分類
H04L9/40
技術(shù)領(lǐng)域
domain,principal,remote,tenant,resource,rpo,access,in,directory,data
地域: WA WA Redmond

摘要

Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.

說明書

In step 710, an access permission approval request for the secure data resource is provided to the first domain on behalf of the remote principal, as a member of the group, causing generation in a directory of the first domain at the domain host of a remote principal object based at least on an indication of an approval of the access permission approval request from the first domain, the remote principal object linking the group to the at least one entitlement for the secure data resource as enumerated in the set of permissions and specified by the access policy. For instance, a secure data resource owner or representative (e.g., an authorized member of the domain for tenant A 226) approves access permission to the secure data resource based on the permissions and the access policy provided in step 708 (e.g., via lock box 222 of system 200) from ELM 214 on behalf of a user/remote principal of tenant B/P 228. When an indication of the approval is received by ELM 214, ELM 214 is configured to cause the creation/generation of an RPO in directory A 468. As described herein, such as with respect to RPO 308 of system 300 in FIG. 3, the RPO includes links to group for entitles to a secure data resource(s) based on the access packages/permissions and/or access policy provided by ELM 214. The RPO is stored in directory A 468 against an access attempt by a user/remote principal of the group from tenant B/P 228.

權(quán)利要求

1
微信群二維碼
意見反饋