发明名称 SELF-DESCRIBING AUTHORIZATION POLICY FOR ACCESSING CLOUD-BASED RESOURCES
摘要 A ticketing system adapted for use with a cloud-based services platform is provided by a ticket-based authorization model in which the authorization requirements for traversing one or more meshes of resources associated with a cloud service are annotated in links included in a resource that refer to other resources. The meshes are thus self-describing with respect to the association among the resources (i.e., the links) as well as the authorization required to access resources. Resource access requires a principal ticket which asserts that a caller at a client (e.g., a security principal representing a device or identity associated with a user) is authenticated, plus zero or more claim tickets. The claim tickets make additional assertions about the caller that the cloud service may use to check that the caller is authorized to access the resource.
申请公布号 US2009228950(A1) 申请公布日期 2009.09.10
申请号 US20080042637 申请日期 2008.03.05
申请人 MICROSOFT CORPORATION 发明人 REED DAVID R.;FLEISCHMAN ERIC S.;GBADEGESIN ABOLADE;SHUKLA DHARMA;SMOLYANSKIY NIKOLAY;GALVIN THOMAS A.
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址