Immediate implementation of centrally configured IT policies

The conditional access termination service addresses unauthorized access by allowing resource providers to subscribe to session events, ensuring immediate policy enforcement and scalability without reconfiguring servers, thus reducing security risks and network traffic.

CN114600425BActive Publication Date: 2025-07-15MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080074316.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-10-31
Filing Date
2020-10-23
Publication Date
2025-07-15
Estimated Expiration
2040-10-23

AI Technical Summary

Technical Problem

In the prior art, the problem of unauthorized entities using unexpired access tokens to access resources, and shortening the access token validity time will lead to increased network traffic, affecting system scalability and the reconfiguration costs of resource providers.

Method used

Termination of service through conditional access, informing the resource provider entity of potential access issues in real time, allowing the resource provider to subscribe to related events and evaluate policies to revoke sessions or redirect users to the identity provider for reauthentication.

Benefits of technology

It realizes timely handling of unauthorized access without affecting system scalability, reducing the length of unauthorized access and reducing the cost of reconfiguring resource providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114600425B_ABST
    Figure CN114600425B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the immediate implementation of centrally configured IT policies. Managing an authenticated user session. A method includes a resource provider computer system subscribing a conditional access termination service for an entity configured to obtain resources from the resource provider computer system via a user session. The resource provider computer system receives, from the conditional access termination service, an event related to a resource request for the entity. The resource provider computer system receives a request for a resource from the entity. The resource provider computer system evaluates the request relative to the event. The resource provider computer system responds to the request based on evaluating the request relative to the event.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND OF THE INVENTION

[0001] Computers and computing systems impact almost every aspect of modern life. Computers are generally used for work, entertainment, healthcare, transportation, recreation, household management, and so on.

[0002] In addition, computing system functionality can be enhanced by the ability of a computing system to be interconnected via a network connection to other computing systems. Network connections can include, but are not limited to, connections via wired or wireless Ethernet, cellular connections, and even computer-to-computer connections via serial, parallel, USB, or other connections. These connections allow a computing system to access services at other computing systems and to receive application data from other computing systems quickly and efficiently. For example, an entity can be configured to access resources from a resource provider, where the resource provider is a remote computing system. To obtain access to these resources, the entity will typically authenticate with an identity provider to receive an access token and a refresh token, where the access token can be presented to the resource provider in a request for resources. If the access token is valid, an authenticated session is created between the resource provider and the entity providing the resources.

[0003] In particular, IT management policies for an organization are typically centrally configured on the identity provider used by that organization. Then, when an authentication artifact (e.g., an access token) is issued to confirm a user's identity, the policy is enforced by the identity provider. Before issuing an access token to a user, the identity provider will evaluate the management policy to ensure user compliance. If the user complies with the policy, the access token is issued to the user. The access token is then passed to the resource provider, which grants resource access based on the information in the access token. After an access token is issued, until it expires, the identity provider cannot update the resource provider based on changes to the user's security status. For example, if a user's employment has been terminated, the user will continue to have access to resources until the user's access token expires.

[0004] For example, access tokens are typically issued by an identity provider, where the access token has a validity period of one hour. Thus, when an entity can obtain access to resources, there may be a one-hour time frame during which the entity should not be accessing resources at the resource provider.

[0005] Some solutions are to reduce the access token validity time. However, this only shortens the length of time that an unauthorized entity has access to resources. In addition, this has the negative drawback of causing a sharp increase in network traffic. For example, if the validity period is reduced from 1 hour to 10 minutes, then the network traffic for authentication between the authenticating entity and the identity provider will increase by 600% accordingly.

[0006] The subject matter claimed herein is not limited to embodiments that solve any disadvantages or that operate only in environments such as the ones described above. Rather, this background is provided to illustrate an exemplary technical area where some embodiments described herein may be practiced. Summary of the Invention

[0007] One embodiment shown herein includes a method that includes actions for managing an authenticated user session. The method includes a resource provider computer system subscribing a conditional access termination service for an entity configured to obtain resources from the resource provider computer system via a user session. The resource provider computer system receives an event related to a resource request of the entity from the conditional access termination service. The resource provider computer system receives a request for a resource from the entity. The resource provider computer system evaluates the request relative to the event. The resource provider computer system responds to the request based on evaluating the request relative to the event.

[0008] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter.

[0009] Additional features and advantages will be set forth in the description which follows, and in part will be obvious from the description, or may be learned by the practice of the teachings herein. The features and advantages of the invention may be realized and obtained by means of the instrumentalities and combinations particularly pointed out in the appended claims. The features of the invention will become more apparent from the following description and appended claims, or may be learned by the practice of the invention as set forth hereinafter. Brief Description of the Drawings

[0010] To describe the manner in which the above-recited and other advantages and features can be obtained, a more particular description of the subject matter briefly described above will be rendered by reference to specific embodiments that are illustrated in the appended drawings. Understanding that these drawings depict only typical embodiments and are not therefore to be considered to be limiting in scope, the embodiments will be described and explained with additional specificity and detail through the use of the accompanying drawings, in which:

[0011] Figure 1 Interactions of various computer systems are shown to implement event-driven IT policy enforcement;

[0012] Figure 2 A method for managing an authenticated user session is shown;

[0013] Figure 3A , Figure 3B , Figure 3C and Figure 3DShows various modes for providing consent to a resource provider to subscribe to a conditional access termination service;

[0014] Figure 4 Shows a method for managing an authenticated user session; and

[0015] Figure 5 Shows a computing system in which embodiments may be practiced.

[0016] The specific implementation mode ends here

[0017] The embodiments described herein enable what is referred to as "instant enforcement" of IT policies. That is, there is a technical problem in that the system is vulnerable to unauthorized access due to unauthorized entities using unexpired access tokens to access resources that they should no longer have access to. In addition, there is a technical problem of increased traffic when the system attempts to shorten the access token validity time. Generally, it is not feasible to configure resource providers to enforce policies because doing so affects the scalability of enterprise systems. In particular, reconfiguring resource providers is costly in terms of computing resources and administrator resources at any time there is a policy change or any time there is a change that requires revocation of a user session. As the number of resource providers in such a system increases, the cost of computing resources and administrator resources increases proportionally. Thus, a system that requires reconfiguring each resource provider computer system necessarily needs to limit the number of resource provider computer systems that can be achieved. In addition, requiring reconfiguring each resource provider would require a system that can track and manage all resource providers in a way that allows for reconfiguration. In addition, requiring reconfiguring each resource provider may actually take more time than simply allowing tokens to expire, thus negating any benefits achieved by reconfiguring resource provider computer systems. Therefore, there is a need for a system that allows a highly scalable number of resource providers to be added to an enterprise system while still being able to address the need to invalidate unexpired tokens. This is particularly important in cloud-based systems where resource providers can be added quickly unless external constraints, as shown above, are placed on the system.

[0018] The embodiments shown in this document can implement a technical solution that immediately (or at least very quickly) notifies a resource provider entity of potential access issues to resources. This is achieved in some embodiments by means of a conditional access termination service. Specifically, this means includes allowing the resource provider to receive events related to an entity attempting to receive resources from the resource provider. In some embodiments, this can occur as a result of the resource provider subscribing to the conditional access termination service to receive events. These events can be evaluated at the resource provider based on a request for a resource to determine the action to be taken with respect to the request for the resource from the entity. This allows policy-related information to be provided to the resource provider in a manner that still allows for a scalable system with respect to the resource provider. In particular, there is no need to track and reconfigure individual servers, but rather each resource provider can subscribe to receive events based on policy considerations in those events.

[0019] For example, an embodiment can include a system that can transmit a policy signal to a resource provider, which can then make a decision regarding revoking an existing session and redirecting the user back to the identity provider for policy re-evaluation.

[0020] For example, some embodiments can detect changes that affect the security of a user account. These changes can include, but are not limited to:

[0021] 1. Account state changes: credential changes, account disablement or deletion, policy or group membership changes, increased account risk, etc.

[0022] 2. Device state changes: device non-compliance, virus, etc.

[0023] 3. Session state changes: session revocation, increased session risk, etc.

[0024] Upon detection of such a change, the conditional access termination service (which can be included as part of the identity provider in some embodiments) will publish an event to subscribers. Interested resource providers will subscribe to these events. Upon receiving an event for a user, the resource provider will revoke the user's existing session and redirect the user back to the identity provider.

[0025] In some cases, a resource provider needs to redirect in one situation: for example, if there is a virus on a user's device, only sessions initiated from the infected device will be affected. Thus, the conditions included in the event can be device-based conditions. If an entity requests a resource from the resource provider using the device indicated in the event, the entity will be redirected to the identity provider. In some embodiments, the identity provider will re-evaluate the user's policy and will reissue an access token after re-authenticating the user's identity, show the user remediation steps (e.g., remove the virus from the device) or block the user completely.

[0026] Now refer to Figure 1 , an example is shown. Figure 1 Entity 102 is shown. In the example shown, entity 102 can include a user as well as the device used by the user and the associated client. Entity 102 may need access to resources from resource provider 104. To obtain access to the resources, the entity will first authenticate with identity provider 106. Entity 102 can authenticate with identity provider 106 through any one of a number of different well-known authentication and access token issuance schemes, other less well-known authentication schemes, or even future authentication schemes yet to be developed. It can be said that in Figure 1 the specific example shown, entity 102 receives access token 108 and refresh token 110 from identity provider 106.

[0027] Access token 108 generally includes a timestamp indicating when the access token was issued. Access token 108 may optionally or additionally include information indicating when access token 108 expires. In some embodiments, access token 108 can include information about the authentication process used by entity 102 to authenticate with identity provider 106. For example, access token 108 can indicate that access token 108 was obtained by entity 102 that authenticated with the identity provider using a simple user identity and secret authentication protocol. A common protocol is the Password Authentication Protocol, where the identity is the username and the secret is the password. Optionally or additionally, if entity 102 was authenticated with identity provider 106 using two-factor authentication, this can be indicated in access token 108. Optionally or additionally, if entity 102 was authenticated with the identity provider using a password of a certain strength, such information can be indicated in access token 108 itself. For example, the access token can indicate the minimum length of the password used to authenticate with the identity provider, the use of special characters in the password used to authenticate with the identity provider, the use of uppercase and lowercase letters in the password used to authenticate with the identity provider, the absence of common passwords or other words in the password used to authenticate with the identity provider, etc.

[0028] In some embodiments, the access token 108 will be used for a particular user and the client used by that particular user. Thus, in this example, the entity 102 includes both the user and the client used by the user. For example, a user may use a laptop computer with a corresponding laptop computer client to perform authentication and resource requests. Thus, the access token 108 may include information about the laptop computer client of the entity 102. Optionally, the user may use a smart phone to perform authentication, in which case the corresponding smart phone client is used to perform authentication and perform resource requests, which means that the access token 108 will be used for the entity 102 that includes the user using the smart phone client. As will be explained in more detail below, this additional information may be used by the resource provider 104 to evaluate certain conditions indicated in the event provided by the conditional access termination service.

[0029] Returning again to Figure 1 the example shown, the entity 102 may provide the access token 108 to the resource provider 104 in a request for a resource from the resource provider 104. The resource provider 104 may evaluate the access token to determine that the entity 102 has been properly authenticated to the identity provider 106 and that the access token 108 is otherwise valid. In particular, the access token 108 may have an expiration time, and the resource provider 104 may determine that the access token 108 has not expired. Generally, as long as the evaluation of the access token 108 passes various checks, then the resource 112 will be provided to the entity 102. However, the embodiments shown herein may implement additional checks on the request 111 of the entity 102 to the resource provider 104.

[0030] Specifically, Figure 1 it is shown that the resource provider 104 may subscribe to the conditional access termination service 114. In some embodiments, the conditional access termination service 114 may be included in the identity provider 106. For example, embodiments may be implemented that configure and manage policies in the same central location. Thus, embodiments may include an identity provider 106 that includes the conditional access termination service 114 as part of the identity provider 106.

[0031] In alternative embodiments, the conditional access termination service 114 may be implemented independently of the identity provider 106. For example, embodiments may still be able to implement a centralized conditional access termination service, but the service is separate from the identity provider 106. In some embodiments, the conditional access termination service 114 may be associated with a policy server that includes the policies set and the ability to enforce the policies set. In the example shown, the resource provider 104 sends a subscription request 116 to the conditional access termination service 114. The resource provider subscribes to events related to the entity 102. As Figure 1As shown, event 118 can be published from the conditional access termination service 114 to the resource provider 104 with respect to entity 102.

[0032] As previously mentioned, events can be triggered due to account state changes, device state changes, client state changes, session state changes, etc. For example, the policy service can detect policy-related changes at the policy service.

[0033] Typically, an event will include one or more of the following: entity information, conditions, timestamps, and actions.

[0034] The entity information included in the event can include information identifying a specific user of entity 102, device information of entity 102, client information of entity 102, user role information of entity 102 (e.g., whether the user acts as an administrator or other special authority user), membership information of entity 102, etc.

[0035] The condition information included in the event can include one or more conditions that should be evaluated to determine whether a specific action should be taken.

[0036] The timestamp included in the event can indicate the time when the event was published (or other important times). Optionally or additionally, the event can include a timestamp identifying the time that should be conditionally evaluated.

[0037] The action included in the event indicates the action that should be taken with respect to the event. It should be noted that in some embodiments, the action is conditional, meaning that certain actions should only be taken if certain conditions are met.

[0038] Various examples are now illustrated by way of example.

[0039] As previously mentioned, in some embodiments, event 118 can be published from the conditional access termination service 114 to the resource provider 104 based on a device state change. Specifically, the conditional access termination service 114 can be notified of changes to the device of entity 102. This can be facilitated by entity 102 registering with a specific management service, periodic messages from entity 102, general knowledge that the type of device used by entity 102 has generally changed, or otherwise. Thus, it should be noted that the conditional access termination service 114 can be interconnected to other systems through various means, and these systems can provide information about changes in the device state of entity 102, enabling appropriate event 118 to be published.

[0040] A specific scenario is shown below which illustrates an example of a device state change. In this example, an administrator has configured a policy that requires a device that is compliant (since it conforms to the system policy) and healthy (since it operates within certain predefined functional criteria) as a condition for data access. The identity provider 106 extends the ability to associate an application session with a device ID to the resource provider. The conditional access termination service 114 (in this case, the policy server) learns that the user's device has become non-compliant, has a virus, or otherwise fails to meet the policy. As a result, the policy server issues an event 118 to the subscriber of that user (e.g., the resource provider 104). The event contains the conditional actions that the subscriber needs to perform to comply with the policy. In this example, the condition is the device ID of the non-compliant device.

[0041] As described above, in some embodiments, event 118 can be issued from the conditional access termination service 114 to the resource provider 104 based on a change to the client application. Specifically, a change to the client application can be detected by the policy server (e.g., the conditional access termination 114), and as a result, one or more events can be sent to a resource provider such as resource provider 104. Such a change to the client application can include an update to the client application (e.g., a new version), a configuration change to the client application, a revocation by an administrator, etc.

[0042] A detailed example of a client application change scenario is shown below. In this scenario, an administrator has removed a certain client application from the tenant's list of trusted applications (where in this example, the tenant is entity 102). The policy server (e.g., the policy server implemented as or in conjunction with the conditional access termination service 114) issues one or more events 118 to the subscriber of that entity 102 (e.g., the resource provider 104). At least one of the events 118 contains the actions that the subscriber needs to perform to comply with the policy for the removed application and the client ID.

[0043] As described above, in some embodiments, event 118 can be issued from the conditional access termination service 114 to the resource provider 104 based on a user state change. For example, such a change may be based on a change to the user's attributes. For example, if the password is reset or changed, one or more events 118 can be issued. Optionally or additionally, if the user account is disabled or deleted, one or more events 118 can be issued. Optionally or additionally, if a compromised user is detected, etc., one or more events 118 can be issued.

[0044] As described above, in some embodiments, event 118 can be published from the conditional access termination service 114 to the resource provider 104 based on a change in session state. For example, an administrator can revoke a user session. Optionally or additionally, the policy server can detect an increase in the risk level of a session. For example, this increased risk can be detected due to the device being on a particular network, located in a particular location, unusual input being entered at the device, or simply that risk conditions have generally increased, or based on other detected events.

[0045] As described above, in some embodiments, event 118 can be published from the conditional access termination service 114 to the resource provider 104 based on a change in policy state. For example, an administrator can change a user's membership or role, resulting in the issuance of one or more events 118.

[0046] When an event is to be published (as shown in the examples above, or for other reasons), the policy server (e.g., as represented by the conditional access termination service 114) publishes one or more events 118 to the subscribers of that user (e.g., the resource provider 104). Note that while Figure 1 a single resource provider subscriber is shown, it should be understood that multiple subscribers can subscribe to relevant events for a particular entity. Note that the event can be issued to multiple subscriptions in a selective manner by the subscription publishing service. That is, in some embodiments, subscribers will only receive events relevant to them. Thus, some events will be sent to all subscribers of an entity, while other events will only be sent to relevant subscribers. In other embodiments, all events are sent to all subscribers of an entity, and the burden of determining whether an event is relevant to a resource provider is pushed to the resource provider.

[0047] Event 118 contains actions that the subscriber needs to perform to comply with a particular policy. For example, actions specified in the event can include revoking a session and redirecting the user back to the identity provider 106. Optionally or additionally, actions specified in the event can include blocking access to certain resources (or resource types) or providing limited access (e.g., read-only) to certain resources (or resource types). Optionally or additionally, conditions can be included in the event such that the actions included in the event can include revoking a session and redirecting the user back to the identity provider 106 if the conditions are met, etc.

[0048] In some embodiments, event 118 includes a timestamp. In some embodiments, due to the procedural event handling protocol, conditions implemented either in the event itself or across all events cause the actions in event 118 to be executed only if the access token was issued before the particular event is evaluated. For example, in one embodiment, resource provider 104 compares the timestamp in one or more events 118 with the time the access token 108 was issued and applies the actions in event 118 only if the access token was issued before the timestamp in the event.

[0049] Upon redirection, identity provider 106 may perform various actions according to policy settings, such as displaying an appropriate message to the user, prompting the user for stronger authorization, issuing a new access token to the user with a "restricted access" claim that may be used by resource provider 104 to restrict access to sensitive data, or a combination thereof.

[0050] The following discussion now refers to some methods and method acts that may be performed. Although the method acts may be discussed in a particular order or illustrated in a flowchart as occurring in a particular order, a particular order is not required unless specifically stated, or required because one act depends on another act being completed before that act is performed.

[0051] Now referring Figure 2 to, method 200 is shown. Method 200 includes acts for managing an authenticated user session. The method includes subscribing, by a resource provider computer system configured to obtain resources from a resource provider via a user session, to a conditional access termination service for an entity (act 202). For example, Figure 1 resource provider 104 is shown subscribing to conditional access termination service 114.

[0052] The resource provider computer system receives an event for the entity from the conditional access termination service (act 204). For example, Figure 1 event 118 is shown.

[0053] The resource provider computer system receives a request for a resource from the entity (act 206). For example, Figure 1 request 111 including access token 108 or at least associated with access token 108 is shown.

[0054] The resource provider computer system evaluates the request with respect to the event (act 208).

[0055] The resource provider computer system responds to the request based on evaluating the request with respect to the event (act 210).

[0056] Method 200 may be practiced where the event includes at least one of user information, a condition, a timestamp, or an action.

[0057] Method 200 may be practiced, where the event includes an action indicating an action that should be performed by the resource provider relative to the entity. For example, such an action may include revoking a user session and redirecting the entity to an identity provider for re - authentication. Optionally, the action may include restricting the entity's access to resources. For example, the resource provider may be instructed to block access to all files, block access to certain files, only allow access to certain files, etc.

[0058] In some embodiments, the event identifies one or more conditions to be evaluated for the resource provider computer system to perform the action. For example, the one or more conditions may be based on an authentication level. For example, if an access token has a particular authentication level or does not have a particular authentication level, the event may indicate that the action should occur. For example, the event may specify that if the entity presents an access token obtained using a simple identity and secret authentication process, then the user session should be revoked and the entity should be redirected to the identity provider for re - authentication. Optionally or additionally, the event may indicate that any authentication process used to obtain the access token other than two - factor authentication (or less secure than two - factor authentication) should cause the resource provider to revoke the user session and redirect the entity to the identity provider for re - authentication. Similar conditions may also be indicated for password length, password reuse, or other reasons.

[0059] Optionally or additionally, the one or more conditions may be based on a timestamp. For example, in one embodiment, the resource provider compares the timestamp in one or more events with the time the access token was issued, and applies the action in the event only if the access token was issued before the timestamp in the event. This allows the policy to be implemented at a specific time at the identity provider, and access tokens issued after that specific time will not need to be refreshed as a result of the event.

[0060] Optionally or additionally, the one or more conditions may be based on the client used by the entity. For example, if the policy server determines that the user's desktop client has been compromised, the condition may specify that the action should be taken if the token is for the desktop client. However, if the user uses the token for a mobile client, the action will not be taken. In some embodiments, the event may specify a particular device ID, which may be used as a condition for evaluation.

[0061] Method 200 may be practiced, where the resource provider subscribes the entity to a conditional access termination service based on the entity's consent for the resource provider to subscribe the entity to the conditional access termination service. As Figure 3AAs shown, in some embodiments, consent 118 can be provided directly by an entity 102 that provides consent directly to the conditional access termination service 114. For example, entity 118 can send a message to the conditional access termination service 114 indicating which service providers consent to subscribe to the conditional access termination service 114 with respect to entity 102.

[0062] Optionally or additionally, as Figure 3B shown, an entity can provide consent 118 to an application 120, and the application 120 can notify the conditional access termination service 114 that consent has been provided. For example, in some embodiments, the application 120 can include a user interface that allows a user to provide such consent as part of the configuration of the application 120.

[0063] Optionally or additionally, as Figure 3C shown, consent 118 can be provided by an entity 102 that consents to a first-party application 122 for a different third-party application 124. For example, in a single sign-on scenario, a user can use their Contoso (a fictional company used for illustration herein) credentials, which can be used to authenticate to a third-party application that is not directly controlled by Contoso. The entity consents to the first-party Contoso application for the third-party application, thereby allowing the entity of the third-party application to subscribe. For example, Figure 3C shows that consent 118 can be provided to the first-party application 122. The first-party application can notify the third-party application 124 of the consent (the third-party application 124 can then notify the conditional access termination service 114 of the consent 118) or can directly notify the conditional access termination service 114 of the consent 118.

[0064] In some embodiments, as Figure 3D shown, an administrator can provide consent for an entity group that includes the entity. In the Figure 3D example shown, the administrator 126 provides consent 118' to the conditional access termination service 114 on behalf of a set of entities 102' over which the administrator has control. Although the Figure 3D example shown shows consent provided directly to the conditional access termination service 114, it should be understood that in other embodiments, the consent can be provided to an application or other entity such as Figure 3B and Figure 3C shown.

[0065] Now referring to Figure 4 , a method for managing an authenticated user session is shown. The method includes, in a conditional access termination service, receiving a subscription request from a resource provider computer system that subscribes the conditional access termination service for an entity configured to obtain resources from the resource provider computer system via a user session (act 402).

[0066] Accordingly, method 400 also includes sending an event of an entity related to a resource request to a resource provider computer system, which can be used by the resource provider computer system to evaluate the resource request from the entity relative to the event, in response to the entity's request for resources as a result of evaluating the request (action 404).

[0067] Method 400 can be practiced where the event includes at least one of user information, a condition, a timestamp, and an action.

[0068] Method 400 can be practiced where the event includes an action indicating an action that should be performed by the resource provider computer system relative to the entity. For example, the action can include revoking a user session and redirecting the entity to an identity provider for re-authentication. Optionally or additionally, the action can include restricting the entity's access to resources.

[0069] Method 400 can be practiced where the event identifies one or more conditions to be evaluated by the resource provider computer system to perform an action. In some embodiments, the one or more conditions can be based on an authentication level. Optionally or additionally, the one or more conditions can be based on a timestamp. The one or more conditions can be based on the client used by the entity.

[0070] Method 400 can also include a conditional access termination service that allows for a subscription based on consent provided for the entity, such that the resource provider subscribes the entity to the conditional access termination service. In some embodiments, consent is provided by an administrator for a group of entities that includes the entity.

[0071] After having just described various features and functions of some of the disclosed embodiments, attention will now be turned to Figure 5 , which illustrates an example computer system 500 that can be used to facilitate the operations described herein. A computer system such as system 500 can be used to implement any of the computer systems described above.

[0072] These methods can be practiced by a computer system 500 that includes one or more processors 505 and a computer-readable memory 525 such as computer memory. Specifically, the computer memory can store computer-executable instructions that, when executed by the one or more processors 505, cause various functions to be performed, such as the actions described in the embodiments.

[0073] Embodiments of the present invention may include or utilize a special-purpose or general-purpose computer including computer hardware, as discussed in more detail below. Embodiments within the scope of the present invention also include physical and other computer-readable media for carrying or storing computer-executable instructions, data structures, or combinations thereof, such as memory 525. Such computer-readable media can be any available media accessible by a general-purpose or special-purpose computer system. A computer-readable medium storing computer-executable instructions is a physical storage medium. A computer-readable medium carrying computer-executable instructions is a transmission medium. Thus, by way of example and not limitation, embodiments of the present invention may include at least two distinctly different computer-readable media: physical computer-readable storage media and transmission computer-readable media.

[0074] Physical computer-readable storage media includes RAM, ROM, EEPROM, CD-ROM, or other optical disk storage (such as CDs, DVDs, etc.), magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store the desired program code means in the form of computer-executable instructions or data structures and that is accessible by a general-purpose or special-purpose computer.

[0075] A "network" (e.g., network 535) is defined as one or more data links capable of transmitting electronic data between computer systems, modules, other electronic devices, or combinations thereof. When information is transmitted or provided to a computer (e.g., remote system 540) via a network or another communication connection (wired, wireless, or a combination of wired or wireless), the computer properly views the connection as a transmission medium. The transmission medium can include a network or data link that can be used to carry the desired program code means in the form of computer-executable instructions or data structures and that is accessible by a general-purpose or special-purpose computer. Combinations of the above are also included within the scope of computer-readable media.

[0076] In addition, upon reaching various computer system components, program code means in the form of computer-executable instructions or data structures can automatically transfer from the transmission computer-readable medium to the physical computer-readable storage medium (and vice versa). For example, computer-executable instructions or data structures received via a network or data link can be buffered in RAM within a network interface module (e.g., "NIC") and then ultimately transferred to the computer system RAM, a less volatile computer-readable physical storage medium in the computer system, or a combination thereof. Thus, computer-readable physical storage media can be included in computer system components that also (or even primarily) utilize the transmission medium.

[0077] Computer-executable instructions include, for example, instructions and data that cause a general-purpose computer, special-purpose computer, or special-purpose processing device to perform a certain function or a set of functions. The computer-executable instructions can be, for example, binary files, intermediate format instructions such as assembly language, or even source code. Although the subject matter has been described in a language specific to structural features, method acts, or a combination thereof, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the features or acts described above. Instead, the described features and acts are disclosed as example forms for implementing the claims.

[0078] Those skilled in the art will understand that the present invention can be implemented in a network computing environment having many types of computer system configurations, including personal computers, desktop computers, laptop computers, messaging processors, handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, mobile phones, PDAs, pagers, routers, switches, etc. The present invention can also be implemented in a distributed system environment where local and remote computer systems linked by a network (either through a hardwired data link, a wireless data link, or a combination of hardwired and wireless data links) both perform tasks. In a distributed system environment, program modules can be located in local and remote memory storage devices.

[0079] Optionally, or in addition, the functions described herein can be performed, at least in part, by one or more hardware logic components. By way of example, and not limitation, illustrative types of hardware logic components that can be used include field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip (SOC), complex programmable logic devices (CPLD), etc.

[0080] The present invention can be implemented in other specific forms without departing from its spirit or characteristics. The described embodiments are to be considered in all respects only as illustrative and not restrictive. Thus, the scope of the present invention is indicated by the appended claims rather than by the foregoing description. All changes that come within the meaning and range of equivalency of the claims are to be embraced within their scope.

Claims

1. A method for managing an authenticated user session at a conditional access termination service, the method comprising: Receiving a subscription request from a resource provider computer system to subscribe to one or more events associated with the user session; In response to a first authentication of an entity at an identity provider, establishing a user session that permits the entity to access the resource provider computer system; Determining that at least one of the one or more events has occurred during the user session; And Accordingly, sending the at least one of the one or more events to the resource provider computer system to cause the resource provider computer system to revoke the user session and redirect the entity back to the identity provider for a second authentication, The event identifying one or more conditions to be evaluated for actions to be performed by the resource provider computer system.

2. The method according to claim 1, wherein the event comprises at least one of user information, a condition, a timestamp, or an action.

3. The method according to claim 1, wherein the event comprises an action that indicates an action that should be performed by the resource provider computer system for the entity, the action comprising at least one of: revoking the user session, and redirecting the entity to the identity provider for re - authentication or restricting the entity's access to resources.

4. The method according to claim 3, wherein the one or more conditions are based on at least one of: an authentication level, a timestamp, or the client used by the entity.

5. The method according to claim 1, further comprising the conditional access termination service permitting the subscription based on consent provided for the entity, such that the resource provider subscribes the entity to the conditional access termination service.

6. The method according to claim 5, wherein the consent is provided by an administrator for a group of entities including the entity.

7. A method for managing an authenticated user session at a resource provider computer system, the method comprising: Subscribing to one or more events associated with a user session from a conditional access termination service; In response to a first authentication of an entity at an identity provider, Establishing a user session that permits the entity to access resources provided by the resource provider computer system; In response to determining that at least one of the one or more events has occurred during the user session, Receiving the at least one of the one or more events from the conditional access termination service; Revoking the user session; And Redirecting the entity back to the identity provider for a second authentication, Wherein the event identifies one or more conditions to be evaluated for actions to be performed by the resource provider computer system.

8. The method according to claim 7, wherein the event comprises at least one of: user information, a condition, a timestamp, or an action.

9. The method according to claim 7, wherein the event comprises an action that indicates an action that should be performed by the resource provider computer system for the entity.

10. The method according to claim 9, wherein the action includes revoking the user session and redirecting the entity to an identity provider for re - authentication.

11. The method according to claim 9, wherein the action includes restricting the entity's access to resources.

12. The method according to claim 7, wherein the one or more conditions are based on an authentication level.

13. The method according to claim 7, wherein the one or more conditions are based on a timestamp.

14. The method according to claim 7, wherein the one or more conditions are based on the client used by the entity.

15. The method according to claim 7, wherein the resource provider computer system subscribes the entity to the conditional access termination service based on consent previously provided for the resource provider to subscribe the entity to the conditional access termination service.

16. The method according to claim 15, wherein the consent is provided by an administrator for a group of entities including the entity.

17. The method according to claim 15, wherein the consent is provided by the entity that consents to the first - party application for a third - party application.

18. A computer system, comprising: An identity provider configured to authenticate an entity for access to resources provided by a resource provider computer system; And A conditional access termination service configured to provide events to a resource provider computer system that subscribes to one or more events associated with a user session; Wherein the conditional access termination service is configured to: Detect one or more events associated with a user session established between an authenticated entity and the resource provider computer system; And In response to detecting at least one of the one or more events during a user session in the user session of a particular entity, send the at least one of the one or more events to the resource provider, so that the resource provider computer system revokes the user session and redirects the entity back to the identity provider for a second authentication; Wherein the identity provider is configured to: In response to revoking the user session, Receive an authentication request redirected from the resource provider computer system; And Authenticate the particular entity again to establish a second user session between the particular entity and the resource provider, Wherein the event identifies one or more conditions for evaluating actions to be performed for the resource provider computer system.

19. The computer system according to claim 18, wherein the event includes at least one of user information, a condition, a timestamp, or an action.

Citation Information

Patent Citations

  • Revoking sessions using signaling

    CN106664302A