Mechanisms to Use Network Session Identifiers for Software-As-A-Service Authentication
    1.
    发明申请
    Mechanisms to Use Network Session Identifiers for Software-As-A-Service Authentication 审中-公开
    使用网络会话标识符进行软件即服务认证的机制

    公开(公告)号:US20150106617A1

    公开(公告)日:2015-04-16

    申请号:US14572075

    申请日:2014-12-16

    CPC classification number: H04L63/0823 H04L63/08

    Abstract: Techniques are provided for authenticating a subject of a client device to access a software-as-a-service (SaaS) server. A network access device receives a request from a client device to establish a network session and transfers identity information of the subject, the client device and the network session to a session directory database. A request is sent to access an application on a SaaS server. If it does not contain an identity assertion that identifies the subject, the request is redirected to an identity provider device, to provide identity assertion services to the subject. A network session identifier is inserted into the request by a network access device and the request is forwarded to the identity provider device. The identity provider device uses the network session identifier to query the session directory database for the identity information to be used for a security assertion of the subject to the SaaS server.

    Abstract translation: 提供了用于验证客户端设备的主体以访问软件即服务(SaaS)服务器的技术。 网络接入设备从客户端设备接收建立网络会话的请求,并将主体,客户端设备和网络会话的身份信息传送到会话目录数据库。 发送请求以访问SaaS服务器上的应用程序。 如果它不包含识别主题的身份断言,则将请求重定向到身份提供者设备,以向主题提供身份声明服务。 网络会话标识符被网络接入设备插入到请求中,该请求被转发给身份提供者设备。 身份提供者设备使用网络会话标识符来查询会话目录数据库,以获得要用于SaaS服务器的对象的安全断言的身份信息。

    Mechanisms to use network session identifiers for software-as-a-service authentication
    2.
    发明授权
    Mechanisms to use network session identifiers for software-as-a-service authentication 有权
    使用网络会话标识符进行软件即服务认证的机制

    公开(公告)号:US09356928B2

    公开(公告)日:2016-05-31

    申请号:US14572075

    申请日:2014-12-16

    CPC classification number: H04L63/0823 H04L63/08

    Abstract: Techniques are provided for authenticating a subject of a client device to access a software-as-a-service (SaaS) server. A network access device receives a request from a client device to establish a network session and transfers identity information of the subject, the client device and the network session to a session directory database. A request is sent to access an application on a SaaS server. If it does not contain an identity assertion that identifies the subject, the request is redirected to an identity provider device, to provide identity assertion services to the subject. A network session identifier is inserted into the request by a network access device and the request is forwarded to the identity provider device. The identity provider device uses the network session identifier to query the session directory database for the identity information to be used for a security assertion of the subject to the SaaS server.

    Abstract translation: 提供了用于验证客户端设备的主体以访问软件即服务(SaaS)服务器的技术。 网络接入设备从客户端设备接收建立网络会话的请求,并将主体,客户端设备和网络会话的身份信息传送到会话目录数据库。 发送请求以访问SaaS服务器上的应用程序。 如果它不包含识别主题的身份断言,则将请求重定向到身份提供者设备,以向主题提供身份声明服务。 网络会话标识符被网络接入设备插入到请求中,该请求被转发给身份提供者设备。 身份提供者设备使用网络会话标识符来查询会话目录数据库,以获得要用于SaaS服务器的对象的安全断言的身份信息。

Patent Agency Ranking