白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Secure resource authorization for external identities using remote principal objects

專利號
US11888856B2
公開日期
2024-01-30
申請人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Charles Prakash Rao Dasari; Maksym Yaryn; Debashis Choudhury; Jeffrey A Staiman
IPC分類
H04L9/40
技術(shù)領(lǐng)域
domain,principal,remote,tenant,resource,rpo,access,in,directory,data
地域: WA WA Redmond

摘要

Methods of secure resource authorization for external identities using remote principal objects are performed by systems and devices. An external entity creates a user group and defines entitlements to an owning entity's secure resource as a set of permissions for the group. An immutable access template with the permissions and an access policy for the secure resource are provided to the owning entity for approval. On approval, a remote principal object is created in the owner directory according to the permissions and access policy. A remote principal that is a group member requests access via an interface to the owner domain using external domain credentials. The identity of the remote principal is verified against the remote principal object by a token service. Verification causes generation and issuance of a token, with the enumerated entitlements, to the remote principal interface affecting a redirect for access to the secure resource.

說明書

In an embodiment of the system, generating the remote principal object is performed based on an acceptance within the first domain of an access permission approval request for the secure data resource that is initiated in and provided on behalf of the second domain.

In an embodiment of the system, generating the remote principal object includes determining a temporal validity period associated therewith, and the method includes performing at the domain host, and subsequent to an expiration of the temporal validity period, at least one of removing the remote principal object from the directory or removing the set of permissions and the at least one associated access policy from the directory.

In an embodiment of the system, the method includes generating, subsequent to said providing the access token, an audit report including at least one of one or more entries for operations performed by the remote principal on the secure data resource that exclude a personal identifier of the remote principal or indicia of the set of permissions with which the remote principal object is associated.

In an embodiment, the system includes a cloud-based services platform that includes a secure token service configured to generate the access token, and the domain host comprises a first tenancy of the cloud-based services platform, and the second domain comprises a second tenancy of the cloud-based services platform.

In an embodiment of the system, the method includes verifying that an entry of the identity of the remote principal is absent from the directory in the first domain and is present in a directory of the second domain subsequent to said receiving, and performing said determining responsive to said verifying.

權(quán)利要求

1
微信群二維碼
意見反饋