首页> 外国专利> SYSTEM AND METHOD FOR HARDENING SECURITY BETWEEN WEB SERVICES USING PROTECTED FORWARDED ACCESS TOKENS

SYSTEM AND METHOD FOR HARDENING SECURITY BETWEEN WEB SERVICES USING PROTECTED FORWARDED ACCESS TOKENS

机译:使用保护的正向访问令牌来增强Web服务之间的安全性的系统和方法

摘要

Methods for hardening security between web services using protected forwarded access tokens are implemented via systems and devices. User applications receive user tokens with user information from an identity provider and provide the user tokens to first services with data requests. Each first service extracts and transforms a portion of a user token to validate a user token signature, and determines a target service for the data request. The first services acquire actor tokens from the identity provider that uniquely identify the first services using public keys, and then generate authentication tokens, signed with corresponding private keys, that encapsulate the actor tokens and the transformed user tokens. The signed authentication tokens are provided to target services which validate the authentication tokens as well as the encapsulated tokens and their respective signatures. Upon validation, requested data is retrieved and provided back for the user applications from the target services.
机译:使用受保护的转发访问令牌来增强Web服务之间安全性的方法是通过系统和设备实现的。用户应用程序从身份提供者接收带有用户信息的用户令牌,并通过数据请求将用户令牌提供给第一服务。每个第一服务提取并转换用户令牌的一部分以验证用户令牌签名,并确定数据请求的目标服务。第一服务从身份提供者获取参与者令牌,该身份提供者使用公共密钥唯一地标识第一服务,然后生成用对应的私有密钥签名的身份验证令牌,该身份验证令牌封装了参与者令牌和转换后的用户令牌。将签名的身份验证令牌提供给目标服务,以验证身份验证令牌以及封装的令牌及其相应的签名。验证后,就从目标服务中检索请求的数据并将其提供给用户应用程序。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号