首页> 外国专利> IDENTITY CLOUD SERVICE AUTHORIZATION MODEL WITH DYNAMIC ROLES AND SCOPES

IDENTITY CLOUD SERVICE AUTHORIZATION MODEL WITH DYNAMIC ROLES AND SCOPES

机译:具有动态角色和范围的身份云服务授权模型

摘要

A system for authorizing access to a resource associated with a tenancy in an identity management system that includes a plurality of tenancies receives an access token request for an access token that corresponds to the resource, the request including user information and application information, the user information including roles of a user and the application information including roles of the application. The system evaluates the access token request by computing dynamic roles and corresponding dynamic scopes for the access token including a second intersection between the dynamic roles of the user and the dynamic roles of the application. The system then provides the access token that includes the computed static scopes, where the scopes are based at least on the roles of the user and the roles of the application, and further including the computed dynamic roles and corresponding dynamic scopes.
机译:在包括多个租赁的身份管理系统中用于授权对与租赁相关联的资源的访问的系统接收对与该资源相对应的访问令牌的访问令牌请求,该请求包括用户信息和应用程序信息,该用户信息包括用户的角色以及包括应用程序角色的应用程序信息。该系统通过计算访问令牌的动态角色和相应的动态范围(包括用户的动态角色和应用程序的动态角色之间的第二个交集)来评估访问令牌请求。然后,系统提供包括计算的静态范围的访问令牌,其中范围至少基于用户的角色和应用程序的角色,并且进一步包括计算的动态角色和相应的动态范围。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号