Amazon.com, Inc.
Authentication and authorization with remotely managed user directories
Last updated:
Abstract:
Techniques for a service provider network to authenticate client devices and determine authorizations for users by sending requests for information in remotely managed user directories. The service provider network may provide computing infrastructure to service requests from users who have accounts with a subscriber of the service provider network. The subscriber may maintain user information for the various user accounts usable to authenticate client devices and/or determine authorizations of users. The service provider network may receive a request from a client device to execute a workflow for a service of the subscriber that is supported by resources of the service provider network. The service provider network may send a request to a subscriber device for user account information for authentication and determining authorization. For instance, the service provider network may request a public key to authenticate the client device, and/or authorization information indicating permissions granted for a user account.
Utility
28 Dec 2020
30 Aug 2022