REGION-BASED AUTHENTICATION AND ACCESS POLICIES FOR SERVICES

Embodiment described herein enable region-based authentication and/or access policies for services implemented in a cloud computing platform. For example, an authentication request is received from a service, the authentication request including a credential that includes region information that ind...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: PANASYUK, Anatoliy, ROUSKOV, Yordan I
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Embodiment described herein enable region-based authentication and/or access policies for services implemented in a cloud computing platform. For example, an authentication request is received from a service, the authentication request including a credential that includes region information that indicates a region the service is assigned to. An identity system authenticates the service and provides an access token that includes the region information. In another embodiment, the identity system determines a level of access to be provided to the service based on whether a criterion of an access policy is satisfied based on the region information and generates an access token indicating the level of access. In another embodiment, the identity system denies issuance of an access token if a criterion of an authentication policy is not satisfied based on the region information. In another embodiment, the identity system obtains region information stored in association with an identifier of the service.