发明名称 METHODS AND SYSTEMS FOR AUTHORIZING WEB SERVICE REQUESTS
摘要 Systems and methods for authorizing web service requests. In some embodiments, a computer-implemented method includes receiving a web service request having an authorization header and business code, authenticating a Security Assertion Markup Language (SAML) token included in the authorization header and constructing a security context based on attributes of the SAML token. The process also includes passing the security context to an authorization interceptor to interact with a policy information point (PIP) and a policy decision point (PDP), receiving a permit response, and then authorizing the web services request. In some implementations, the requested web service is then transmitted to the client computer that requested the web service.
申请公布号 US2015350212(A1) 申请公布日期 2015.12.03
申请号 US201414290492 申请日期 2014.05.29
申请人 General Electric Company 发明人 Amiri Dariush Mario
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A computer-implemented method, comprising: receiving a web service request comprising an authorization header and business code; passing the web services request to an authentication interceptor to authenticate a Security Assertion Markup Language (SAML) token included in the authorization header; receiving an authentication indication; constructing a security context based on attributes of the SAML token; passing the security context to an authorization interceptor to interact with a policy information point (PIP) and a policy decision point (PDP); receiving a permit response; and authorizing the web services request.
地址 Schenectady NY US