Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

499 results about "Access token" patented technology

In computer systems, an access token contains the security credentials for a login session and identifies the user, the user's groups, the user's privileges, and, in some cases, a particular application. Typically one may be asked to enter the access token (for example a 40 character long gibberish) rather than the usual password (it therefore should be kept secret just like a password).

Data privacy protection method for data governance system

The invention provides a data privacy protection method for a data governance system, and belongs to the technical field of data governance, and the method comprises the steps: carrying out the cross verification of multi-source feature data and the unique identification information of an object collected on site, generating an original data set, carrying out the sensitive information recognition and grading, and generating the preprocessing data with a sensitive grade label; core identification information in the preprocessed data is disassembled to generate standardized desensitized data conforming to privacy protection, a bidirectional encryption mapping relation is established between object unique identification information collected on site and the standardized desensitized data, an encryption index is formed, the encryption index and preset multi-dimensional compliance data are fused, and a data fusion result is obtained; generating standardized fusion data; and based on the access token, generating a differential authorization data set divided according to permission granularity, performing privacy disclosure risk assessment, generating a risk level, performing privacy processing on the risk level, and outputting the risk level to a risk control system. And the data management efficiency is improved.
Owner:BEIJING GUOXINDA DATA TECH CO LTD

Permission-based ai system responses

A method and apparatus are disclosed for generating permission-based large language model responses by using a query received from a user to identify a plurality of documents that are semantically similar to the query, using an access token received from the user to identify user accessible documents from the plurality of documents that the user is permitted to access, processing the user accessible documents to define a context of user accessible documents that is associated with the query, and then submitting the query and the context of user accessible documents to a large language model (AI system) to generate an AI system response to the query.
Owner:JIVE SOFTWARE LLC

Cloud deployment automation system with integrated resource orchestration and customizable deployment workflows

ActiveDE202025104332U1Resource allocationResourcesAsynchronous operationExecution control
A cloud deployment automation system consisting of: a deployment automation device housed in a rack-mountable enclosure, the device comprising: a multi-core orchestration processor configured to execute deployment logic as compiled execution graphs; a storage module operatively coupled to the orchestration processor, the storage storing a set of deployment templates, real-time execution states, telemetry logs, and policy configurations; a secure credential management processing unit embedded in the device, configured to generate, store, and rotate cloud access tokens, API keys, and user-specific credentials, and to provide encrypted access to those credentials during deployment execution; an in-memory workflow execution engine executed by the orchestration processor, configured to analyze a user-defined deployment configuration that includes a declarative specification of infrastructure resources and compile that configuration into a directed acyclic graph (DAG) that represents the resource deployment order, dependency mapping, and rollback relationships, a cloud provider interface subsystem communicatively connected to multiple heterogeneous cloud platforms via appropriate API adapters, the subsystem enabling the orchestration processor to send provisioning requests and receive status events from the platforms; a customizable workflow compiler unit configured to convert graphical workflow definitions or domain-specific language (DSL) scripts into execution sequences that can be used by the workflow execution engine, where the workflow compiler unit supports conditional branching, asynchronous operations, and runtime variable resolution; and A policy enforcement control unit integrated into the deployment automation device, with the policy engine configured to apply organization-specific compliance rules, tagging conventions, security group configurations, and runtime resource limits to all deployment actions in a context-aware manner prior to execution.
Owner:THASON JUSTIN RAJAKUMAR MARIA FAIRFAX

Heterogeneous database security access and report generation method based on MCP and agent

The invention relates to the technical field of database security, and discloses an MCP and agent-based heterogeneous database security access and report generation method, which comprises the following steps of: receiving a task request, acquiring a task context, synchronizing capability declarations from a plurality of database adapters according to the MCP, generating a capability graph and determining a capability version identifier; performing semantic mapping to obtain a strategy inline rewriting rule and a rewriting abstract fingerprint; the method comprises the following steps: signing and issuing a minimum permission access token, generating cross-source query, performing forced rewriting according to a strategy inline rewriting rule in a compilation stage, verifying consistency, processing an original result to obtain a purified result, only allowing to read a generated report from a buffer area of the purified result under the constraint of a structured mode template, and calculating a report fingerprint at the same time. And writing a chained audit log, fixing the audit log, and verifying report reproduction based on the audit log. According to the method and the system, minimum access, unauthorized prevention and control, compliance audibility and result reproducibility are realized.
Owner:BEIJING HEALTH ONLINE TECH CO LTD

Energy big data right confirmation method, system and device based on hierarchical hash tree and dynamic authorization and storage medium

The invention discloses an energy big data right confirmation method and system based on a hierarchical hash tree and dynamic authorization, and belongs to the field of energy big data management and information security, and the method comprises the steps: obtaining and standardizing original data in an energy scene, and dividing the original data into a data block set according to equipment and time; constructing a hierarchical hash tree and generating root hash; writing the root hash and the associated metadata into the block chain to realize right confirmation and evidence storage; executing proxy re-encryption according to the access token, and converting the ciphertext into a decryptable format; verifying the data consistency through the Hash path and the root Hash, and completing the access; and recording the access behavior and distributing transaction earnings by the smart contract based on the contribution degree. Hash calculation and local path updating of a data block level are supported through a layered Hash tree structure, so that when large-scale energy data is frequently updated, a new root Hash value can be quickly generated and right confirmation updating can be completed only by carrying out local Hash recalculation on a changed path.
Owner:GUIZHOU POWER GRID CO LTD

Block chain-based gynaecology and obstetrics emergency medical data security sharing system

The invention discloses a gynaecology and obstetrics emergency medical data security sharing system based on a block chain, and relates to the technical field of medical information processing. The method is used for solving the security and timeliness problems of multi-mechanism data sharing in an emergency scene. The method comprises the following steps: firstly, performing grading processing and desensitization on personal identifiers and medical data of patients through a data grading and desensitization module, and outputting data which can be safely shared; then, an on-chain evidence storage module performs windowing processing on the continuous monitoring data flow, extracts key physiological features, generates feature value Hash, constructs data feature descriptors and submits the data feature descriptors to a block chain network; the emergency access token management module realizes dynamic authorization through a smart contract, and generates a temporary access token associated with the data feature descriptor; and finally, the secure decryption and data sharing module verifies the authority based on the hierarchical decryption key, decrypts the data and compares the eigenvalue hash, and shares and records an operation log with an authorization party after ensuring the data integrity, thereby realizing efficient, secure and traceable data sharing.
Owner:NORTHWEST WOMEN & CHILDREN HOSPITAL

Intelligent terminal identity authentication and data security management method, system and device based on block chain, and medium

The invention relates to the technical field of Internet of Things data management, in particular to an intelligent terminal identity authentication and data security management method, system and device based on a block chain and a medium, and the method comprises the steps: generating a unique identity label and a public and private key pair of an intelligent terminal device, a fog node and a user, packaging a digital certificate, and writing the digital certificate into a block chain network; the intelligent terminal equipment initiates a registration request, and the blockchain network distributes a hosting fog node to the intelligent terminal equipment after verification is passed; the intelligent terminal device generates data, constructs a data fingerprint, sends the data fingerprint to the block chain network for storage, encrypts the data, and sends the data to the hosting fog node for storage; a user initiates an authentication request, and a temporary access token is generated after verification is passed; and establishing a secure communication channel by using the temporary access token, obtaining the required encrypted data stored by the fog node, decrypting to obtain the required data, and verifying the integrity of the required data by using the data fingerprint. According to the invention, the overall security and reliability of data management of the Internet of Things system can be significantly improved.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Security authentication method and device, computer equipment, readable storage medium and program product

The invention relates to a security authentication method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: receiving a key generation request sent by target equipment; if it is determined that the key generation request is legal, generating a trust identifier and a security certificate of the target device, obtaining an identifier verification request through the trust identifier, and sending the identifier verification request to an authentication server, so that the authentication server verifies the trust identifier to obtain an access token corresponding to the target device; receiving a message returned by the authentication server, and processing an access token carried by the message to obtain a trust identifier; and writing the security certificate into the target protection area, and sending the trust identifier and the security certificate to the target equipment, so that the target equipment is registered in the authentication server. By adopting the method, the identity verification of the equipment and the control of an encryption communication mechanism are realized, and the safety protection performance in a communication system is further improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Methods, systems, and computer readable media for detecting and mitigating security attacks on producer network functions (NFs) using access token to non-access-token parameter correlation at proxy nf

A method for detecting and mitigating security attacks on producer network NFs using access token to non-access-token parameter correlation at a proxy NF includes receiving an inter-PLMN SBI request message. The method further includes obtaining, from an access token transmitted with the inter-PLMN SBI request message, at least one network- or service-identifying parameter and obtaining, externally from the access token, at least one network- or service-identifying parameter. The method further includes comparing the at least one network- or service-identifying parameter obtained from the access token and the at least one network- or service-identifying parameter obtained externally from the access token and performing a network security action when the at least one network- or service-identifying parameter obtained from the access token does not match the at least one network- or service-identifying parameter obtained externally from the access token.
Owner:ORACLE INT CORP

Power encryption database fine-grained access control method based on quantum key

The embodiment of the invention provides a power encryption database fine-grained access control method based on a quantum key, and relates to the technical field of quantum communication. The access control method comprises the following steps: performing identity authentication on a data user applying for data access; after the data user passes the identity verification, verifying the user attribute of the data user, and issuing a dynamic access token; after identity verification and attribute verification, establishing a QKD channel between the data center and the data user, and generating a quantum key; the data center defines an access strategy according to the user attribute corresponding to the plaintext; encrypting a plaintext and an access strategy through the generated quantum key to obtain a ciphertext; storing the ciphertext in a distributed database of the data center; verifying whether the user attribute of the data user is consistent with the access strategy in the ciphertext according to the access token; under the condition of consistency, the data center distributes the secret key to the data user through the QKD channel; and the data user decrypts the ciphertext according to the distributed key to obtain a plaintext.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +1

Multi-tenant multi-user login method based on enhanced OAuth2

The invention provides a multi-tenant multi-user login method based on enhanced OAuth2, which relates to the technical field of network security, and comprises the following steps: obtaining a key threshold through a tenant identifier, and executing OAuth2 authentication to obtain an access token; tenant fingerprint information is generated through zero-knowledge proof and homomorphic encryption, and a tenant verification token is generated through secure multi-party calculation; constructing a reinforcement learning access controller in combination with the historical access data, and generating and verifying an authority list; and finally forming a session identifier and storing the session identifier in a distributed cache. According to the invention, the authentication security is improved, cross-tenant fine-grained authority management is realized, and unauthorized access is effectively prevented.
Owner:ZHEJIANG SHUXIN NETWORK CO LTD

Secure access control method and device of MCP protocol, storage medium and program product

The invention relates to the field of artificial intelligence, and discloses a security access control method and device of an MCP protocol, a storage medium and a program product. The method comprises the following steps: in a tool registration stage, performing digital signature on tool metadata registered in an MCP server, and signing and issuing an access token containing a client identity attribute to complete bidirectional identity authentication of a client and an external tool; a tool calling request initiated by the MCP client is acquired and intercepted, context information of the request is collected, the context information comprises at least one of a main body attribute, a resource attribute, an operation attribute and an environment attribute, and the tool calling request carries an access token; the context information is submitted to a strategy decision point, dynamic evaluation is carried out based on a preset attribute-based access control strategy rule, an authorization decision is generated, and the authorization decision comprises permission and rejection; and executing releasing or blocking operation on the tool calling request according to the authorization decision.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Methods and apparatus to access federated resources

Disclosed examples include transmitting a discovery result to a client application, the discovery result including a list of federated data lakes; and after receiving a token request specifying a first data lake of the federated data lakes, transmitting an access token and metadata to the client application. The access token and the metadata corresponding to the first data lake. The metadata specifies services available at the first data lake. The access token grants the client application access to the first data lake of the federated data lakes.
Owner:CLOUDERA INC

Resource classification layer for constant request verification in zero trust systems

A method is disclosed for managing access in a telecommunications network by utilizing a resource classification layer. The method involves receiving a request at a resource classification layer from a sender to obtain an access token for a receiver service. The sender is associated with a user role that has specific permissions and access rights corresponding to a data sensitivity threshold. The request includes a data payload. A classification value for the data payload is assigned using one or more resource classification models, which are trained on a log of past data payloads. A data sensitivity score is generated by comparing the classification value to a scale of classification values. The method then indicates whether the access token can be granted to the sender by comparing the data sensitivity score against the data sensitivity threshold to verify authorization.
Owner:T MOBILE US INC

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Systems and methods for immersive data management in spatial computing

Systems and methods for immersive data management in spatial computing are disclosed. A method may include: (1) requesting from an identity and access management service executed in a cloud environment, an access token; (2) receiving, from an identity and access management service, the access token comprising user entitlements to access a plurality of elements in a plurality of scenes; (3) requesting one of the plurality of scenes from a scene filtering service, the request comprising the access token; (4) identifying the user entitlements from the access token; (5) retrieving the requested scene comprising a subset of the elements; (6) adding the elements that the user is entitled to based on the user entitlements to a scene to be displayed; (7) returning the scene to be displayed to the computer program; and (8) displaying the scene to be displayed.
Owner:JPMORGAN CHASE BANK NA

Open platform management method and system based on dynamic reflection calling

The invention provides an open platform management method and system based on dynamic reflection calling in the technical field of distributed micro-services and gateways. The method comprises the following steps: S1, forwarding an access request to an authentication center; s2, the authentication center executes identity authentication and issues an access token, and the client sends a request message to the open platform based on the access token; s3, the open platform carries out authentication, decryption and signature verification on the request message to obtain message content containing request parameters and a target service subsystem; s4, searching interface metadata and a network address of the target service subsystem; and S5, through a dynamic reflection calling engine, generating a proxy instance based on the interface metadata, mapping the request parameter into a target parameter, and through the proxy instance and the network address, calling the target service subsystem to execute the target parameter. The method has the advantages that the safe, uniform and non-intrusive open service capability is realized, and the maintainability, the safety and the evolution capability of the platform are greatly improved.
Owner:FUJIAN ECAN INFORMATION TECH CO LTD

Construction method of trusted industrial data space

The invention discloses a credible industrial data space construction method, and particularly relates to the technical field of industrial data credible management and sharing. Collecting identity feature data and behavior data of an industrial subject, and establishing a behavior data pool; generating a behavior view map based on the behavior ontology model; constructing a behavior consensus index model, and evaluating historical behavior credibility; performing semantic alignment on the behavior credibility index and the current access intention, constructing a credibility mapping function in combination with a multi-source decision factor, and generating a credibility rating value of the access behavior; a one-time pass token is generated or access is denied according to a rating result, behavior feedback is used for model optimization and graph evolution, and finally an extensible trusted industrial data space is constructed; according to the method, dynamic trust judgment, behavior semantic understanding and cross-domain cooperative control of industrial data access are realized, and the credibility, the adaptive capability and the structure treatment capability of a data space are improved.
Owner:NINGBO WOLS SOFTWARE CO LTD

Industrial AI model security management and control system

The invention discloses an industrial AI model security management and control system, and the system comprises a permission granularity control module which is used for declaring a required minimum permission set when an AI model is registered, and generating a dynamic access token containing a permission list for the model; wherein the identifier is a resource operation authority identifier; the permission mapping table module is used for maintaining a mapping relation from the resource operation permission identifier to the actual resource address; the access verification module is used for verifying the validity and the permission range of the dynamic access token when the model requests the system resources, and refusing the non-permission access; and the dynamic permission recovery module is used for removing the target permission identifier in the authorized permission set of the model in real time to update the permission set, marking that the old token is invalid, and generating a new token containing a timestamp based on the new permission set. According to the method, the industrial AI model can be effectively prevented from abusing the authority, and the system security is improved.
Owner:QKM TECH (DONG GUAN) CO LTD

Transparent, on-demand route determination and delegated authorization in a large-scale, decentralized service mesh

A system can execute a containerized application that comprises a microservice in a decentralized service mesh architecture, and a sidecar. The system can intercept, by the containerized application, a call from the microservice that is directed to a remote endpoint, and direct the call to the sidecar. The system can communicate, by the sidecar to an identity manager, service account credentials associated with the microservice, resulting in receiving an identity token associated with the microservice. The system can determine, by the sidecar, connectivity information of the remote endpoint based on a virtual address of the remote endpoint identified in the call. The system can communicate, by the sidecar to a token exchanger, the identity token and the connectivity information, resulting in receiving an access token and a network route to the remote endpoint. The system can relay, by the sidecar, network traffic between the microservice and the remote endpoint.
Owner:DELL PROD LP

Data transaction system

The invention provides a data transaction system, and relates to the technical field of block chains, and the data transaction system comprises a data providing device, a data purchasing device, a transaction device, a block chain device and an interstellar file system. The data providing device sends encrypted data to the interstellar file system and issues an intelligent contract to the block chain device; the data purchasing equipment sends a payment request and a payment transaction fund to the transaction equipment; the transaction device generates a payment voucher and sends the payment voucher to the data purchasing device; the data purchasing device generates a payment statement and sends a data access application to the data providing device; the data providing device generates a temporary key, generates a data access credential and sends the data access credential to the transaction device; the transaction device pays transaction money to the data providing device, generates a data access statement and sends the data access statement to the data purchasing device; and the data purchasing device obtains the access token, obtains the encrypted data, and decrypts the encrypted data by using the temporary key to obtain the to-be-transacted data.
Owner:CHINA MOBILE ZIJIN INNOVATION INST CO LTD +3

Multi-system micro-front-end dynamic integration method and device, electronic equipment and storage medium

The invention relates to the technical field of computers, can be applied to the field of science and technology finance, and discloses a multi-system micro-front-end dynamic integration method and device, electronic equipment and a storage medium. The method comprises the following steps: deploying a base application, configuring a sandbox mechanism and a front-end plug-in of the base application, initializing a cache strategy of the base application, acquiring a target system as a sub-application, and opening a state refreshing interface of the sub-application; when a user accesses the sub-application after logging in the base application, calling the unified authentication service to generate a user token; the access token is obtained from the unified authentication service through the sub-application according to the user information and the key pair, the validity of the access token and the user token is verified through the unified authentication service, the user information is user data stored after successful login, and the key pair is obtained from the unified authentication service in advance; and if the access token is valid, loading the sub-application on the base application by using a sandbox mechanism and a front-end plug-in. According to the method, efficient integration and stable operation of the multi-system micro front end are realized.
Owner:ZHUHAI CHINA RESOURCES BANK CO LTD

API gateway multi-service aggregation arrangement method and system based on dynamic rule engine

The invention provides an API gateway multi-service aggregation arrangement method and system based on a dynamic rule engine, and relates to the technical field of distributed system architecture.The method comprises the steps that an API gateway layer intercepts a service scene interface calling request initiated by a client side, and the request carries a service scene unique identifier identity certificate and analyzes the service scene unique identifier identity certificate to obtain a request parameter; retrieving a preset aggregation arrangement rule topology from a rule engine through the business scene unique identifier to obtain a target micro-service set; based on the identity credential and the target micro-service set, initiating a token joint request to an authentication center, and obtaining an access token set; and mapping predicate logic according to the request parameter and the target micro-service set parameter, analyzing a client request load through a regular expression engine, and generating a parameter key value pair set for each micro-service. The method is used for solving the problem of poor multi-service dynamic arrangement adaptability in the micro-service architecture.
Owner:SHAANXI YILAN TECH CO LTD

System and method for implementing an edge queuing platform

This application relates to a system, method, and non-transitory computer readable medium for implementing a queuing platform. In some embodiments, a user request is received and it determined whether the user request matches predetermined criteria. Embodiments can include assigning the user request to an item queue and issuing a ticket. In further embodiments, the ticket is validated and an access token is transmitted to the user device based on the validation of the ticket. A checkout request corresponding to the at least one user request is received and validated. In some embodiments, the user request is transmitted from the item queue to a checkout engine to complete a purchase of the item based on the validation of the access token received in the checkout request.
Owner:WALMART APOLLO LLC

Service provision system and method which use user access token

Disclosed is a service provision system using a user access token including a user terminal used for a user to request a service and use the service provided from a service server, an access control server configured to provide a one-time user access token including information necessary for the user to use the service and allowing the user terminal to access the service server for a unit session, and a gateway configured to provide data provided from the service server to the user terminal between the user terminal and the service server, and a service is provided without exposing an address of the service server.
Owner:AWESOMEBLY INC

Multi-party controlled transient user credentialing for interaction with secure data

Apparatus and associated methods relate to provide transient access rights to entities for creating, accessing, and / or sharing digital health content (DHC). In an illustrative example, a health content distribution system (HCDS) may generate a time-limited access token (TLAT) for authenticated users to access DHC. The TLAT, for example, may be generated based on a predetermined association of a corresponding DHC with a patient, a predetermined association of a requestor with the patient, a predetermined role of the requestor with relation to the patient, and a predetermined association between the requestor and a creator of the content. The TLAT may be further generated based on a predetermined association between the requestor and an organization associated with the patient. The HCDS may, for example, upon receiving the TLAT, transmit the corresponding DHC to be displayed at the requestor's device. Various embodiments may advantageously provide a secure on-demand health content access system.
Owner:PLAYBACK HEALTH INC

Network management authorization security management method and system for electric power communication network

The invention discloses a network management authorization security management method and system for an electric power communication network, and relates to the technical field of network security management. The method comprises the following steps: constructing a layered block chain network architecture; a user request is received, dynamic risk assessment is performed, a multi-factor identity authentication process is triggered, and after identity authentication is passed, an intelligent contract verifies the permission and generates a minimum permission access token; and the client accesses the token by means of the minimum authority, establishes an under-chain state channel, exchanges operation instructions and logs under the chain during the session, submits the aggregated hash values and the final states of all the operation logs to the slave block chains for evidence storage when the session is ended, and regularly anchors the state abstract of each slave block chain by the master block chain, so that the state abstract of each slave block chain is obtained. And completing global auditing traceability. The technical problem that in the prior art, network management operation authorization management of an electric power communication network lacks safety and traceability is solved, and the technical effects of improving the safety and credibility of network management operation authorization and achieving traceability of the whole operation process are achieved.
Owner:BENXI POWER SUPPLY COMPANY OF STATE GRID LIAONINGELECTRIC POWER SUPPLY

Document management method and device supporting API integration, equipment and storage medium

The invention relates to the technical field of information processing, in particular to a document management method and device supporting API integration, equipment and a storage medium. Role permissions to which different users belong are distributed, API access tokens are issued for the users with API calling permissions by using a token bucket algorithm, an API interface is called according to the API access tokens, and the user access permission is called according to the API interface. Interface access can be controlled based on permissions of different user roles, the flexibility and expansibility of the document management system are improved, the document management system adapts to diversified business scenes, a task scheduler is utilized to trigger an API interface according to preset time to pull timing synchronization data from an external system, document events of the external system are monitored in real time based on a message queue, and the user experience is improved. According to a document event, an API interface is triggered to pull real-time synchronization data, timing synchronization and real-time synchronization with external system data are achieved, the integration level of the system is improved, format conversion is conducted on the timing synchronization data or the real-time synchronization data, a document library is updated based on standard format synchronization data, and the reliability of document management is improved.
Owner:SHANGHAI DONGPU INFORMATION TECH CO LTD