The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 06, 2024

Filed:

Jan. 28, 2021
Applicant:

Amazon Technologies, Inc., Seattle, WA (US);

Inventors:

Gokul Ramanan Subramanian, Cambridge, GB;

Sayantan Chakravorty, Sammamish, WA (US);

Dennis Tighe, Seattle, WA (US);

Carlos Alessandro Chiconato, Seattle, WA (US);

Damian Wylie, Preston, WA (US);

Assignee:

Amazon Technologies, Inc., Seattle, WA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/40 (2022.01);
U.S. Cl.
CPC ...
H04L 63/20 (2013.01); H04L 63/0807 (2013.01); H04L 63/0876 (2013.01); H04L 63/1483 (2013.01);
Abstract

A connection-based service impersonates request-based security for requests from clients that do not include credentials for the requests (e.g., data plane requests made via a connection-oriented security). A connection between a client and a connection-based service is established based on connection credentials that are based on security credentials from a request-based security service. The credentials are sent by a security component of the service to a local agent of the remote security service to be authenticated by the security service. An impersonation token is returned by the security service and cached by the local agent. Requests from the client to perform operations do not include credentials. For each request, the service passes an identifier for the client and the operation to a local authorization component that calls the agent for authorization of the requested operation. The agent uses the impersonation token to obtain authorization for the requested operation.


Find Patent Forward Citations

Loading…