首页> 外国专利> Apparatus and method for using a directory service for authentication and authorization to access resources outside of the directory service

Apparatus and method for using a directory service for authentication and authorization to access resources outside of the directory service

机译:使用目录服务进行身份验证和授权以访问目录服务之外的资源的设备和方法

摘要

An apparatus and method use the built-in authentication and authorization functions of a directory service to perform authentication and authorization for resources that are external to the directory service. A Lightweight Directory Access Protocol (LDAP) service is used in the preferred embodiments. The LDAP directory includes built-in functions for authenticating a user that requests access to an entry. Each resource that needs to be protected is mapped to an entry in the LDAP directory. These entries that correspond to protected resources external to the LDAP directory are called proxy entries. Proxy entries contain the authorization information for the corresponding protected resource in the form of an access control list for each entry that specifies the authorized users of the entry. When a user needs to access a protected resource, the user or an application uses the LDAP directory to determine whether the user is authenticated and authorized to access the proxy entry in the directory that corresponds to the resource. If the user is authenticated and authorized to access the proxy entry, the user may then access the corresponding external protected resource. The present invention thus allows the use of the internal LDAP authentication and authorization functions to determine which users are allowed to access protected resources that are external to the LDAP directory.
机译:一种设备和方法使用目录服务的内置认证和授权功能来对目录服务外部的资源执行认证和授权。在优选实施例中使用轻量目录访问协议(LDAP)服务。 LDAP目录包括内置功能,用于对请求访问条目的用户进行身份验证。每个需要保护的资源都映射到LDAP目录中的一个条目。这些与LDAP目录外部的受保护资源相对应的条目称为代理条目。代理条目以指定每个条目的授权用户的每个条目的访问控制列表的形式包含相应受保护资源的授权信息。当用户需要访问受保护的资源时,该用户或应用程序将使用LDAP目录来确定该用户是否已通过身份验证和授权,以访问与该资源相对应的目录中的代理条目。如果用户通过了身份验证并有权访问代理条目,则用户可以访问相应的外部受保护资源。因此,本发明允许使用内部LDAP认证和授权功能来确定允许哪些用户访问LDAP目录外部的受保护资源。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号