×

Self-describing authorization policy for accessing cloud-based resources

  • US 8,196,175 B2
  • Filed: 03/05/2008
  • Issued: 06/05/2012
  • Est. Priority Date: 03/05/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method for implementing a self-describing authorization policy for resources provided by a cloud service, the method comprising:

  • exposing resources provided by the cloud service as one of a plurality of resource meshes, each resource mesh including a plurality of resources that require authenticating credentials associated with a particular client device to access the resources;

    providing a principal ticket including a link to a particular resource in a mesh and credentials for authenticating a client device to the particular resource in the mesh associated with the client device to permit the client device to access the resource;

    annotating the link to the particular resource with authorization credentials required by at least one other resource in the resource mesh associated with the particular client device to permit the client device to access the other resource, the authorization credentials for the other resource comprising a claim ticket containing at least one assertion providing access to the other resource; and

    accessing the particular resource by using the principal ticket included in the link to the particular resource, the link being annotated with at least one claim ticket required by another resource to permit the client device to directly access the other resource when accessing the particular resource.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×