Token management in a managed directory service

    公开(公告)号:US11134067B1

    公开(公告)日:2021-09-28

    申请号:US15457273

    申请日:2017-03-13

    Abstract: A centralized policy management may allow for one set of credentials to various applications and services offered by a computing resource service provider or other third-party servers. Systems, methods, and computer readable medium can be configured to receive a request to access a first computing system service provided by the computing resource service provider, generate an encrypted data bundle including at least a user identifier and a data type, and transmit the encrypted data bundle to a recipient, wherein the encrypted data bundle is configured to be returned to the one or more computing devices to facilitate access to the first computing system service provided by the computing resource service provider.

    Multi-factor authentication for managed directories

    公开(公告)号:US10547599B1

    公开(公告)日:2020-01-28

    申请号:US14626843

    申请日:2015-02-19

    Abstract: A user transmits a request to an authentication service to access a managed directory. The request may include a first set of credentials usable by a managed directory service to authenticate the user. As a result of the first set of credentials being valid, the authentication service may prompt the user to provide a multi-factor authentication code, which may be used by an authentication server to further authenticate the user and enable the user to access the managed directory. The authentication service subsequently provides the multi-factor authentication code to the authentication server for validation. If the multi-factor authentication code is valid, the authentication service may enable the user to access the managed directory through an encrypted communications session.

    Management and authentication in hosted directory service
    8.
    发明授权
    Management and authentication in hosted directory service 有权
    托管目录服务中的管理和身份验证

    公开(公告)号:US09596233B1

    公开(公告)日:2017-03-14

    申请号:US15060236

    申请日:2016-03-03

    Abstract: A user, group, and device management and authentication system allows administrators to manage one or more directories with devices that are not associated with a domain of the one or more directories via a set of APIs. The system also allows applications and services that do not have direct access to a list of directory users to access the one or more directories. The user, group, and device management and authentication system may be an add-on system that works in conjunction with a centrally-managed directory service to provide such functionality. For example, the system may generate an access token associated with a particular directory that can be used by a service accessed by an administrator to call an API provided by the system. The API call may be translated into a directory-specific API call that can be used to perform an action in the particular directory.

    Abstract translation: 用户,组和设备管理和认证系统允许管理员通过一组API来管理与一个或多个目录的域不相关联的设备的一个或多个目录。 该系统还允许不能直接访问目录用户列表的应用程序和服务来访问一个或多个目录。 用户,组和设备管理和认证系统可以是与中央管理的目录服务一起工作以提供这样的功能的附加系统。 例如,系统可以生成与特定目录相关联的访问令牌,该目录可由管理员访问的服务使用以调用由系统提供的API。 API调用可能会转换为特定于目录的API调用,该调用可用于在特定目录中执行操作。

    Management and authentication in hosted directory service
    9.
    发明授权
    Management and authentication in hosted directory service 有权
    托管目录服务中的管理和身份验证

    公开(公告)号:US09313193B1

    公开(公告)日:2016-04-12

    申请号:US14500865

    申请日:2014-09-29

    Abstract: A user, group, and device management and authentication system allows administrators to manage one or more directories with devices that are not associated with a domain of the one or more directories via a set of APIs. The system also allows applications and services that do not have direct access to a list of directory users to access the one or more directories. The user, group, and device management and authentication system may be an add-on system that works in conjunction with a centrally-managed directory service to provide such functionality. For example, the system may generate an access token associated with a particular directory that can be used by a service accessed by an administrator to call an API provided by the system. The API call may be translated into a directory-specific API call that can be used to perform an action in the particular directory.

    Abstract translation: 用户,组和设备管理和认证系统允许管理员通过一组API来管理与一个或多个目录的域不相关联的设备的一个或多个目录。 该系统还允许不能直接访问目录用户列表的应用程序和服务来访问一个或多个目录。 用户,组和设备管理和认证系统可以是与中央管理的目录服务一起工作以提供这样的功能的附加系统。 例如,系统可以生成与特定目录相关联的访问令牌,该目录可由管理员访问的服务使用以调用由系统提供的API。 API调用可能会转换为特定于目录的API调用,该调用可用于在特定目录中执行操作。

Patent Agency Ranking