首页> 外国专利> Multi-domain applications with authorization and authentication in cloud environment

Multi-domain applications with authorization and authentication in cloud environment

机译:云环境中具有授权和认证的多域应用程序

摘要

A multi-domain application requiring SSO and SLO operations in cloud environment is presented. The computing system of the multi-domain application includes a multi-domain service (MDS) to redirect the calls for the multi-domain application to an identity provider to authenticate the user or to invoke the single logout services (SLOs) on the domains of the multi-domain application and to invalidate the user sessions on the domains. A cookie that includes the multi-domain application URL is generated to reach the assertion consumer service (ASC) and the single logout service (SLO) that receive an identity assertion response from the identity provider. Domain specific SLOs are provided. A trust between these domain specific SLOs and the SLO is provided based on service provider keys. The SAML mechanism for a logout scenario is reused for communication between the SLO and the domain specific SLOs, where the SLO plays a role of a local IDP.
机译:提出了一种需要在云环境中进行SSO和SLO操作的多域应用程序。多域应用程序的计算系统包括一个多域服务(MDS),用于将对多域应用程序的调用重定向到身份提供商,以认证用户或调用以下域中的单个注销服务(SLO):多域应用程序,并使域上的用户会话无效。生成包含多域应用程序URL的cookie,以到达声明接收方服务(ASC)和单个注销服务(SLO),它们从身份提供者处接收身份声明响应。提供了特定于域的SLO。这些特定于域的SLO与SLO之间的信任关系是基于服务提供商密钥提供的。注销场景的SAML机制被重新用于SLO和特定于域的SLO之间的通信,其中SLO充当本地IDP。

著录项

  • 公开/公告号US10015157B2

    专利类型

  • 公开/公告日2018-07-03

    原文格式PDF

  • 申请/专利权人 SAP SE;

    申请/专利号US201615169841

  • 发明设计人 MILEN MANOV;STEFAN PETROV;JASEN MINOV;

    申请日2016-06-01

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:04:27

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号