-
公开(公告)号:US10715514B1
公开(公告)日:2020-07-14
申请号:US15372315
申请日:2016-12-07
Applicant: Amazon Technologies, Inc.
Inventor: Richard Threlkeld
Abstract: One or more clients of a service may obtain access to resources of the service using one or more roles. A role may be used to delegate access to resources that a principal normally would not otherwise have access to. Assuming a role may allow a principal to receive a token that provides access to resources according to permission associated with the role. Upon detecting an event in connection with the invalidation of a token associated with a role, a service may perform a workflow in connection with the principal.
-
公开(公告)号:US10673862B1
公开(公告)日:2020-06-02
申请号:US15372302
申请日:2016-12-07
Applicant: Amazon Technologies, Inc.
Inventor: Richard Threlkeld
Abstract: One or more clients of a service may obtain access to resources of the service using one or more roles. A role may be used to delegate access to resources that a client normally would not otherwise have access to. A system of the service may be used to detect the occurrence of an event associated with a principal that has assumed a role to obtain a token that enables access to a computing resource. The system may prevent one or more principals from use of the token for future access to the resource, and may update permissions associated with the role to prevent one or more principals from assuming the role.
-