-
公开(公告)号:US11503012B1
公开(公告)日:2022-11-15
申请号:US16456770
申请日:2019-06-28
Applicant: Amazon Technologies, Inc.
Inventor: Justin Paul Yancey , Jack A. Drooger , Beau Jared Hunter , Harvir Singh
IPC: H04L9/40
Abstract: A service or load balancer may use the techniques herein to perform client authentication using a certificate-based identity provider. A client may send a request for access to a service of the provider network. In response, the service or a load balancer may redirect the request to a certificate-based identity provider in accordance with a standard identity protocol (e.g., a federated identity protocol such as the protocol for OpenID Connect (OIDC)). The certificate-based identity provider may obtain a client certificate and validate the client certificate. The identity provider may also obtain and verify other credentials. In response to validating the client certificate (and in some cases authenticating the credentials), the certificate-based identity provider may generate and sign an identity token and redirect the client back to the service in accordance with the identity protocol.