首页> 外国专利> Authored injections of context that are resolved at authentication time

Authored injections of context that are resolved at authentication time

机译:在身份验证时解析的授权上下文注入

摘要

Techniques are described for enabling principals to inject context information into a credential (e.g. session credential). Once the credential has been issued, any arbitrary principal is allowed to inject context information into the existing credential. The injected context is scoped to the principal that made the injection. Subsequently, at authentication time, when the credential is used to request access to a particular resource, the system can verify whether the principal that made the injection is trusted and if the principal is deemed trusted, the context information can be applied to a policy that controls access to one or more resources, or can alternatively be translated into some context residing in a different namespace which can then be applied to the policy. In addition, the system enables arbitrary users to insert additional deny statements into an existing credential, which further restrict the scope of permissions granted by the credential.
机译:描述了用于使委托人能够将上下文信息注入到凭证(例如,会话凭证)中的技术。颁发凭据后,任何任意主体都可以将上下文信息注入到现有凭据中。注入的上下文的范围仅限于进行注入的主体。随后,在身份验证时,当使用凭据请求访问特定资源时,系统可以验证进行注入的主体是否是受信任的,如果该主体被视为受信任的,则可以将上下文信息应用于以下策略:控制对一个或多个资源的访问,或者可以将其转换为驻留在不同名称空间中的某些上下文,然后可以将其应用于策略。另外,该系统使任意用户都可以在现有凭证中插入其他deny语句,这进一步限制了凭证授予的权限范围。

著录项

  • 公开/公告号US9479492B1

    专利类型

  • 公开/公告日2016-10-25

    原文格式PDF

  • 申请/专利权人 AMAZON TECHNOLOGIES INC.;

    申请/专利号US201314145654

  • 发明设计人 KEVIN ROSS ONEILL;GREGORY BRANCHEK ROTH;

    申请日2013-12-31

  • 分类号H04L29/06;G06F21/10;G06F21/31;

  • 国家 US

  • 入库时间 2022-08-21 14:32:46

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号