白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Identity experience framework

專(zhuān)利號(hào)
US11997077B2
公開(kāi)日期
2024-05-28
申請(qǐng)人
Microsoft Technology Licensing, LLC(US WA Redmond)
發(fā)明人
Raja Charu Vikram Kakumani; Brandon B. Murdoch; Ronald Bjones; Muhammad Omer Iqbal; Kim Cameron
IPC分類(lèi)
H04L9/00; H04L9/40; G06F3/0484
技術(shù)領(lǐng)域
policy,identity,ui,ief,provider,user,token,journeys,providers,composable
地域: WA WA Redmond

摘要

Methods for composable user journeys for user authentication via an identity experience framework are performed by systems and apparatuses. Initiating a user authentication process for an application triggers application calls for dynamic invocation of a specific identity policy, required by the application, of a number of identity policies managed by a host of the identity experience framework. User interfaces defined by the identity policies are provided from the host to the application for interaction by the user and entry of identity information needed to authenticate the user according to specified verification providers. Identity claims and token requests are provided from the application to the host which then authenticates the identity claims via the verification providers and mints a token that includes the claims required by the application, according to the identity policy. The application consumes the token to complete the token request and allow the user access to the application.

說(shuō)明書(shū)

Child policies may be modified/created by, or have parameters specified by, application service providers including application developers therefor. That is, according to the embodiments and techniques for the IEF described herein, another entity, e.g., associated with the identity policy host, associated with an identity operator, etc., may create or modify child policies for utilization by applications.

By using trustframeworks to conceptualize and capture the requirements of a “community of interest” and then define these requirements in a policy document, policy authors (e.g., identity operators) can build identity workloads of varying complexity, in a manner that aligns with the needs or requirements of the drivers of the community and not the technology. Having a language for articulating the identity needs for workloads fosters collaboration and partnerships between policy authors, identity experts, and business stakeholders.

A trustframework engine is the service that executes the trustframework policy. The trustframework engine may comprise loosely coupled state machine handlers that can invoke specific concrete implementations of identity semantics, and a state machine that instantiates and executes the identity semantics in the context of the user journey and the policy being executed. Each authorization request made to the IEF may be processed in the context of a trustframework policy that defines the user journey. In embodiments, there may be no identity logic outside of what is declared in the policy and implemented by the specific claims providers. This is analogous to the trustframework policy being the identity application and the trustframework engine being an operating system that runs that application, except in this case, the instruction set allowed by the operating system comprises the constructs exposed by the trustframework schema.

權(quán)利要求

1
微信群二維碼
意見(jiàn)反饋