Systems and methods for authentication brokering
In some aspects, the techniques described herein relate to a method including: receiving, at a credential broker, a request including a unique identifier of a client application, wherein the request is from a token software development kit; querying, by the credential broker, an application attestation datastore using the unique identifier of the client application as a lookup key; receiving, at the credential broker and as a result of the querying, a service identifier for a network service; requesting a service ticket from a key distribution center, wherein the service ticket facilitates authentication with the network service; and responding to the token software development kit with a return communication, wherein the return communication includes the service ticket.
1 . A method comprising:
receiving, at a credential broker, a request for a service ticket comprising a unique identifier for a client application, wherein the request is from a token software development kit included in the client application;
querying, by the credential broker, an application attestation datastore for network services that the client application is authorized to make service requests to using the unique identifier of the client application as a lookup key;
receiving, at the credential broker and as a result of the querying, a service identifier for one of the network services;
requesting, by the credential broker, a ticket granting ticket from a key distribution center;
receiving, by the credential broker, the ticket granting ticket from the key distribution center, wherein the ticket granting ticket is encrypted;
requesting, by the credential broker, a service ticket from the key distribution center, wherein the service ticket facilitates authentication with the network service;
receiving, by the credential broker, the service ticket from the key distribution center; and
generating, by the credential broker, a response to the token software development kit comprising the service ticket;
wherein the token software development kit is configured to instantiate in-memory objects context object;
wherein the client application is configured to use context object to connect and authenticate to the network service.
2 . The method of claim 1 , wherein the service ticket is Kerberos service ticket.
3 . The method of claim 2 , wherein the key distribution center comprises a ticket granting service.
4 . The method of claim 3 , wherein the service ticket is provided by the ticket granting service.
5 . The method of claim 1 , comprising:
returning, by the key distribution center, a payload to the credential broker.
6 . The method of claim 5 , comprising:
paring, by the credential broker, data from the payload resulting in pared data.
7 . The method of claim 6 , wherein the pared data includes the service ticket.
8 . The method of claim 1 , comprising:
generating, by the credential broker, a binary representation of the service ticket.
9 . The method of claim 8 , wherein the binary representation of the service ticket comprises a byte array.
10 . The method of claim 1 , wherein the unique identifier is a workload identifier.
11 . The method of claim 10 , wherein the workload identifier comprises a plurality of identifying components.
12 . The method of claim 1 , comprising:
receiving, at a service registration processor, the service identifier.
13 . The method of claim 12 , comprising:
persisting, by the service registration processor, the service identifier in the application attestation datastore.