首页> 外国专利> Dynamic security policy consolidation

Dynamic security policy consolidation

机译:动态安全策略整合

摘要

Various embodiments provide for the consolidation of policies across multiple identities that are respectively associated with multiple active directory (AD) groups to which a user belongs. Present embodiments provide for dynamically generating a new identity in the resource provider environment that includes permissions to all of the resources that may otherwise be distributed across multiple identities. Specifically, in accordance with various embodiments, when a user login is detected, the active directory is queried to determine the AD groups to which the user belongs. As mentioned, the user's AD groups are mapped to respective identities in the resource provider environment, in which each identity includes policy defining access to one or more resources. The policies of all the respective identities are consolidated and assigned to a new identity. The user may assume the new identity and access all the resources in tandem.
机译:各种实施例提供跨多个身份的策略的合并,所述多个身份分别与用户所属的多个活动目录(AD)组相关联。本发明的实施例提供了在资源提供者环境中动态生成新身份的过程,该新身份包括对所有资源的许可,否则可能会在多个身份之间进行分配。具体地,根据各种实施例,当检测到用户登录时,查询活动目录以确定用户所属的AD组。如上所述,用户的AD组映射到资源提供者环境中的相应标识,其中每个标识都包含定义对一个或多个资源的访问的策略。所有相应身份的策略将合并并分配给新身份。用户可以采用新的身份并串联访问所有资源。

著录项

  • 公开/公告号US10778691B1

    专利类型

  • 公开/公告日2020-09-15

    原文格式PDF

  • 申请/专利权人 AMAZON TECHNOLOGIES INC.;

    申请/专利号US201715835172

  • 发明设计人 ROBERT W. KISSELL;ERIC ANDREW SCHOLZ;

    申请日2017-12-07

  • 分类号G06F21/62;H04L29/06;G06F16/335;G06F21/60;

  • 国家 US

  • 入库时间 2022-08-21 11:30:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号