发明名称 ACCESS CONTROL POLICIES ASSOCIATED WITH FREEFORM METADATA
摘要 Approaches are described for security and access control for computing resources. Various embodiments utilize metadata, e.g., tags that can be applied to one or more computing resources (e.g., virtual machines, host computing devices, applications, databases, etc.) to control access to these and/or other computing resources. In various embodiments, the tags and access control policies described herein can be utilized in a multitenant shared resource environment.
申请公布号 US2014207861(A1) 申请公布日期 2014.07.24
申请号 US201313747261 申请日期 2013.01.22
申请人 Amazon Technologies, Inc. 发明人 Brandwine Eric Jason;DeSantis Peter Nicholas;Thrane Léon
分类号 H04L12/58 主分类号 H04L12/58
代理机构 代理人
主权项 1. A computer implemented method for using tags to control access to resources, said method comprising: under the control of one or more computer systems configured with executable instructions, associating a first access control policy and a second access control policy with a metadata tag, the first access control policy identifying which principals are allowed to assign the metadata tag to at least one computing resource, the second access control policy identifying operations that are allowed or not allowed to be performed on resources associated with the metadata tag;receiving, from a user using an application programming interface (API), a request to assign the metadata tag to the at least one computing resource;evaluating the first access control policy and assigning the metadata tag to the computing resource in response to determining that the first access control policy allows the user to assign the metadata tag;receiving a request to perform an operation on the computing resource;evaluating the second access control policy associated with the metadata tag; andauthorizing the request to perform the operation on the computing resource based at least in part on evaluation of the second access control policy.
地址 Reno NV US