About: WS-Federation Active Requestor Profile is a research topic. Over the lifetime, 61 publications have been published within this topic receiving 1508 citations.
TL;DR: In this paper, an access control policy engine associated with a resource determines whether to allow a request to access same, and if the request is to be allowed, provides the requestor access to the resource in accordance with the request and the rights of the requestors as determined based on the security claims.
Abstract: An access control policy engine associated with a resource determines whether to allow a request to access same. The engine receives the request with an security token, retrieves the token determines a type thereof, and maps access decision information in the token to a common format as at least one security claim setting forth adequate information to determine a right of the requestor. Thereafter, the engine retrieves a set of rules for accessing the resource, applies the rules to the security claims to determine whether to allow the request from the requestor, and if the request is to be allowed, provides the requestor access to the resource in accordance with the request and the rights of the requestor as determined based on the security claims.
TL;DR: In this paper, the authentication of a process at one node for the use of a service at another node is performed in a facility that is separate from the requestor and service process.
Abstract: In a distributed data processing system, the authentication of a process at one node for the use of a service at another node is performed in a facility that is separate from the requestor and service process. The separate facility is also replaceable, thereby allowing different authentication policies to be implemented within the distributed data processing system. The requesting process and the service process merely pass the authentication information between themselves without attempting to interpret the work of the separate authentication facility. In addition to authenticating the requestor to the service, the service is also authenticated to the requestor.
TL;DR: In this paper, a method for requesting a credential associated with a token in a multiple token layer environment is disclosed, where a tokenization certificate serves to validate the identity of a credential requestor and provide information about the requestor's authorization for de-tokenizing a token.
Abstract: A method for requesting a credential associated with token in a multiple token layer environment is disclosed. A tokenization certificate serves to validate the identity of a credential requestor and provide information about the requestor's authorization for de-tokenizing a token. Also, a public key in the tokenization certificate is used to encrypt the credential for secure transmission to the requestor.
TL;DR: In this article, the authors propose a method for controlling access to a plurality of computing resources in a distributed computing environment can comprise the steps of an application role server, responsive to receiving a certificate request, authenticating the requestor and issuing a digital certificate to the requestors, and an access control node, responsive for receiving a resource access request, granting access to the computing resource to the requested user upon ascertaining the user's access privileges.
Abstract: A method for controlling access to a plurality of computing resources in a distributed computing environment can comprise the steps of: an application role server, responsive to receiving a certificate request, authenticating the requestor and issuing a digital certificate to the requestor; an access control node, responsive to receiving a resource access request, granting access to the computing resource to the requestor upon ascertaining the requestor's access privileges, or forwarding the resource access request to another access control node.
TL;DR: In this article, a data structure comports with a secure application instruction protocol (SIPP) and includes a first application-level request and a second application level request with a signature over at least the application-specific instructions from the intermediary.
Abstract: In an example implementation, a data structure comports with a secure application instruction protocol. The data structure includes a first application- level request and a second application-level request. The first application-level request has application-specific instructions from a requestor and a requestor signature over the application-specific instructions from the requestor. The second application-level request has application-specific instructions from an intermediary and an intermediary signature over at least the application- specific instructions from the intermediary.