Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

271 results about "Access token" patented technology

In computer systems, an access token contains the security credentials for a login session and identifies the user, the user's groups, the user's privileges, and, in some cases, a particular application. Typically one may be asked to enter the access token (for example a 40 character long gibberish) rather than the usual password (it therefore should be kept secret just like a password).

Heterogeneous database security access and report generation method based on MCP and agent

The invention relates to the technical field of database security, and discloses an MCP and agent-based heterogeneous database security access and report generation method, which comprises the following steps of: receiving a task request, acquiring a task context, synchronizing capability declarations from a plurality of database adapters according to the MCP, generating a capability graph and determining a capability version identifier; performing semantic mapping to obtain a strategy inline rewriting rule and a rewriting abstract fingerprint; the method comprises the following steps: signing and issuing a minimum permission access token, generating cross-source query, performing forced rewriting according to a strategy inline rewriting rule in a compilation stage, verifying consistency, processing an original result to obtain a purified result, only allowing to read a generated report from a buffer area of the purified result under the constraint of a structured mode template, and calculating a report fingerprint at the same time. And writing a chained audit log, fixing the audit log, and verifying report reproduction based on the audit log. According to the method and the system, minimum access, unauthorized prevention and control, compliance audibility and result reproducibility are realized.
Owner:BEIJING HEALTH ONLINE TECH CO LTD

Secure access control method and device of MCP protocol, storage medium and program product

The invention relates to the field of artificial intelligence, and discloses a security access control method and device of an MCP protocol, a storage medium and a program product. The method comprises the following steps: in a tool registration stage, performing digital signature on tool metadata registered in an MCP server, and signing and issuing an access token containing a client identity attribute to complete bidirectional identity authentication of a client and an external tool; a tool calling request initiated by the MCP client is acquired and intercepted, context information of the request is collected, the context information comprises at least one of a main body attribute, a resource attribute, an operation attribute and an environment attribute, and the tool calling request carries an access token; the context information is submitted to a strategy decision point, dynamic evaluation is carried out based on a preset attribute-based access control strategy rule, an authorization decision is generated, and the authorization decision comprises permission and rejection; and executing releasing or blocking operation on the tool calling request according to the authorization decision.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Resource classification layer for constant request verification in zero trust systems

A method is disclosed for managing access in a telecommunications network by utilizing a resource classification layer. The method involves receiving a request at a resource classification layer from a sender to obtain an access token for a receiver service. The sender is associated with a user role that has specific permissions and access rights corresponding to a data sensitivity threshold. The request includes a data payload. A classification value for the data payload is assigned using one or more resource classification models, which are trained on a log of past data payloads. A data sensitivity score is generated by comparing the classification value to a scale of classification values. The method then indicates whether the access token can be granted to the sender by comparing the data sensitivity score against the data sensitivity threshold to verify authorization.
Owner:T MOBILE US INC

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Industrial AI model security management and control system

The invention discloses an industrial AI model security management and control system, and the system comprises a permission granularity control module which is used for declaring a required minimum permission set when an AI model is registered, and generating a dynamic access token containing a permission list for the model; wherein the identifier is a resource operation authority identifier; the permission mapping table module is used for maintaining a mapping relation from the resource operation permission identifier to the actual resource address; the access verification module is used for verifying the validity and the permission range of the dynamic access token when the model requests the system resources, and refusing the non-permission access; and the dynamic permission recovery module is used for removing the target permission identifier in the authorized permission set of the model in real time to update the permission set, marking that the old token is invalid, and generating a new token containing a timestamp based on the new permission set. According to the method, the industrial AI model can be effectively prevented from abusing the authority, and the system security is improved.
Owner:QKM TECH (DONG GUAN) CO LTD

Transparent, on-demand route determination and delegated authorization in a large-scale, decentralized service mesh

A system can execute a containerized application that comprises a microservice in a decentralized service mesh architecture, and a sidecar. The system can intercept, by the containerized application, a call from the microservice that is directed to a remote endpoint, and direct the call to the sidecar. The system can communicate, by the sidecar to an identity manager, service account credentials associated with the microservice, resulting in receiving an identity token associated with the microservice. The system can determine, by the sidecar, connectivity information of the remote endpoint based on a virtual address of the remote endpoint identified in the call. The system can communicate, by the sidecar to a token exchanger, the identity token and the connectivity information, resulting in receiving an access token and a network route to the remote endpoint. The system can relay, by the sidecar, network traffic between the microservice and the remote endpoint.
Owner:DELL PROD LP

System and method for implementing an edge queuing platform

This application relates to a system, method, and non-transitory computer readable medium for implementing a queuing platform. In some embodiments, a user request is received and it determined whether the user request matches predetermined criteria. Embodiments can include assigning the user request to an item queue and issuing a ticket. In further embodiments, the ticket is validated and an access token is transmitted to the user device based on the validation of the ticket. A checkout request corresponding to the at least one user request is received and validated. In some embodiments, the user request is transmitted from the item queue to a checkout engine to complete a purchase of the item based on the validation of the access token received in the checkout request.
Owner:WALMART APOLLO LLC

Network management authorization security management method and system for electric power communication network

The invention discloses a network management authorization security management method and system for an electric power communication network, and relates to the technical field of network security management. The method comprises the following steps: constructing a layered block chain network architecture; a user request is received, dynamic risk assessment is performed, a multi-factor identity authentication process is triggered, and after identity authentication is passed, an intelligent contract verifies the permission and generates a minimum permission access token; and the client accesses the token by means of the minimum authority, establishes an under-chain state channel, exchanges operation instructions and logs under the chain during the session, submits the aggregated hash values and the final states of all the operation logs to the slave block chains for evidence storage when the session is ended, and regularly anchors the state abstract of each slave block chain by the master block chain, so that the state abstract of each slave block chain is obtained. And completing global auditing traceability. The technical problem that in the prior art, network management operation authorization management of an electric power communication network lacks safety and traceability is solved, and the technical effects of improving the safety and credibility of network management operation authorization and achieving traceability of the whole operation process are achieved.
Owner:BENXI POWER SUPPLY COMPANY OF STATE GRID LIAONINGELECTRIC POWER SUPPLY

Personal electronic archive and genealogy management system based on block chain

The invention discloses a personal electronic archive and genealogy management system based on a block chain, and the system comprises an archive generation module which is used for building a personal electronic archive; the genealogy application module is used for receiving a genealogy construction request initiated by a user and forming a candidate block set according to information in a user starting block; the genealogy generation module is used for calculating genetic relationship and a time sequence among the candidate blocks, and generating a topologically balanced religious pedigree diagram according to a calculation result and hash reference information among the candidate blocks; the automatic updating module is used for automatically updating the religious pedigree diagram; the access application module is used for generating an access token containing the permission range and the effective duration according to the access application; and the access evidence storage module is used for completing access and storing an access behavior. According to the method, efficient construction and dynamic management of personal archives and genealogy structures are realized by fusing block chain authentication and an intelligent retrieval modeling algorithm.
Owner:ANHUI HANGTIAN INFORMATION CO LTD

Decoupled gift cards and process for activation and validation

PendingUS20260087484A1Debit schemesPre-payment schemesEngineeringRemote computer
Disclosed are systems, methods, and techniques for purchasing and activating a decoupled gift card. A system can include: a first gift card component of a first type having a first identifier, a second gift card component of a second type separate from the first component and having a second identifier, the second component being configured to attach to the first component to form a decoupled gift card purchasable during a checkout process, a point of sale (POS) terminal that scans the first and second identifiers during checkout, and a remote computer system that can activate the decoupled gift card while the checkout process is performed. The remote system can receive the scanned identifiers, identify a gift card number corresponding to the first scanned identifier, identify an access token corresponding to the second scanned identifier, and associate the gift card number with the access token to activate the decoupled gift card.
Owner:TARGET BRANDS INC

Multi-user equipment access and control method based on smart cloud platform

The invention relates to the technical field of Internet of Things, and discloses a multi-user equipment access and control method based on a smart cloud platform. The method comprises the following steps: the Internet of Things equipment sends an access request to a smart cloud platform through a network, distributes an access token after verification, and stores equipment information to a cloud database; after the user logs in for the first time, the platform loads a device list according to user account information and a device binding relation, and creates an independent account space; a user sends a control instruction through the terminal, and the platform verifies user permission and converts the instruction into a protocol format which can be recognized by target equipment; the target device executes an operation and feeds back a result, and the platform updates and pushes the result to the user terminal in real time; and the platform continuously monitors the state of the equipment, analyzes and evaluates the state, triggers an early warning mechanism when an abnormity occurs, notifies a user and provides a solution, and the overall efficiency and safety of the system are improved, and the compatibility of multi-user control and the user experience are improved.
Owner:HENAN ZHONGAN ELECTRONIC DETECTION TECH CO LTD

Dynamic key derivation method for bidirectional authentication between Internet of Things equipment and cloud

The invention relates to the technical field of Internet of Things security, in particular to an Internet of Things equipment and cloud bidirectional authentication dynamic key derivation method, which comprises the following steps of: distributing a unique identity label, an initial key and an equipment serial number for equipment, and encrypting and storing the initial key; the device obtains a current timestamp, calculates a time quantum factor, and performs cascade processing on the initial key, the identity label, the device serial number and the time quantum factor by adopting a multi-stage cascade key derivation structure to obtain an intermediate key; the equipment encrypts the registration request by using the intermediate key and then sends the encrypted registration request to the gateway, the gateway carries out decryption verification and generates a random number, and the equipment and the gateway derive an access token based on the intermediate key and the random number; the equipment generates a request signature identifier by using the access token, and sends the service parameters, the request signature identifier and the request serial number to the gateway; and the device and the cloud carry out bidirectional identity verification. According to the technical scheme of the invention, high-strength bidirectional authentication and key dynamic generation of the equipment and the cloud are realized.
Owner:LICHU BUSINESS

Resource owner authorization for API invoker

Example embodiments of the disclosure relate to methods, devices, apparatuses and computer readable storage medium for resource owner(s) authorization for an Application Programming Interface (API) invoker in Communication API Framework (CAPIF) Resource owner-aware Northbound API Access (RNAA) context. In a method, a first apparatus transmits, to a second apparatus, an access token request for authorization from one or more resource owners. The access token request comprises first information for accessing resources of the one or more resource owners, each of the one or more resource owners being different from a further resource owner associated with the first apparatus; and receive. Then, the first apparatus receives, from the second apparatus, an access token response comprising second information indicating a result of the authorization for accessing the resources of the one or more resource owners.
Owner:NOKIA TECHNOLOGIES OY

Access token verification

Example embodiments of the present disclosure relate to access token verification. In example embodiments, a method is provided. The method comprises, at a first service communication proxy, receiving, from a second service communication proxy, a first request for a service from a first network function, the first request originating from a second network function and comprising a token to access the first network function, the token comprising a delegation domain list to which token verification is delegated by the first network function, the token being generated by a network repository function based on registration information from the first network function, the registration information comprising at least one of: an indication of whether a delegation of the token verification is allowed or the delegation domain list: alternatively the first service communication proxy may obtain whether a delegation of the token verification is allowed and the delegation domain list from the network repository function and in accordance with a determination that the first service communication proxy belongs to the delegation domain list, verifying the token. In this way, the verification of the access token can be improved.
Owner:NOKIA TECHNOLOGIES OY

AI large model access data security control method

This invention discloses a method for controlling access security of large AI models, relating to the field of data security technology. The invention includes the following steps: Step S1: Data classification and grading preprocessing: Multi-dimensional feature extraction is performed on the original data to be accessed by the large AI model. Based on a preset classification and grading rule base, the data security level value is calculated using the analytic hierarchy process (AHP). The specific formula is: where n is the number of data feature dimensions, w i The weight is the i-th feature dimension. This invention has the function of multi-dimensional and accurate data security management. Through multi-dimensional feature extraction, such as data sensitivity and importance, the security level is calculated using the analytic hierarchy process, making data classification and grading more accurate. At the same time, it combines natural language processing to parse access requests and generate an initial access token with multiple parameters, laying the foundation for subsequent security control.
Owner:GUANGZHOU PRINCIPAL DATA CO LTD

Ledger-based cookie management with non-fungible token integration

In various embodiments, systems and methods for ledger-based cookie management are provided. Rather than store cookie data as text files on the local device drive, cookie data is recorded to a blockchain technology cookie ledger store on a network resource. When a client application (e.g., a browser) on the UE is directed to a cloud-based service, and that cloud-based service calls for access to a cookie, that call is processed by a cookie gateway executing on the UE. The cookie gateway may verify authenticity of the user and generate a cookie access token that it transmits to the cloud-based service. The cloud-based service may use the cookie access token to locate the cookie ledger and access one or more records storing cookie data used by the cloud-based service. The cookie access token may expire upon termination of the session between the user equipment and the cloud-based service.
Owner:T MOBILE INNOVATIONS LLC

Method and system for completing project development through task panel-agent client pre-installed with AI model in container

The invention discloses a method and system for completing project development through a task panel, relates to the crossing field of project development and artificial intelligence technology, and is suitable for various development scenes needing team cooperation and intelligent assistance. The core of the method is to construct an integrated process of task submission, container creation, environment initialization, AI interaction and result submission depending on a container mirror image of a pre-installed AI proxy client: a user submits a task description and a project anchor point through an operation table, and a remote server matches a corresponding container mirror image and creates an isolation container; dynamically injecting a security key and a warehouse access token to activate an AI proxy client; after the container loads project basic resources, the AI proxy client and the AI model module establish an exclusive interaction link, a development scheme is generated based on task requirements, and preliminary modification is completed; in the development process, real-time two-way interaction between a user and the AI is supported, and finally, the AI proxy client completes project resource verification, packaging and direct connection with a project warehouse for submission, so that efficient combination of a lightweight operating end and a high-computing-power server is realized. According to the scheme, the problems that hardware adaptation is difficult, the environment is not isolated, the cooperation process is tedious, AI interaction is not smooth and the like in traditional development are solved, the development efficiency and safety are greatly improved, and environment consistency and configuration standardization are guaranteed.
Owner:赖金燕

Metaverse integrated authentication method and system

Provided is a metaverse integrated authentication method. The metaverse integrated authentication method includes: transmitting, by a user terminal, an IDP login request; when the IDP login request is received, extracting, by a first ID provider, subscription information associated with a user of the user terminal from a first ID database; providing, by the first ID provider, the user terminal with an access token based on the extracted subscription information; transmitting, by the user terminal, a first login request for a public metaverse based on the provided access token; extracting, by a first server associated with the public metaverse, account information associated with the first login request from an account database; and performing, by the first server, authentication of the user terminal for the public metaverse based on the extracted account information.
Owner:CATALYSTER CORP

Method for authenticating a mobile device of a vehicle occupant to a backend service of a vehicle manufacturer, computer-readable medium, system, and vehicle

The invention relates to a method for authenticating a mobile device of a vehicle occupant to a backend service of a vehicle manufacturer, the method comprising: establishing an encrypted communication connection between the vehicle occupant's mobile device and the vehicle; generating a temporary access token for the occupant's mobile device by the vehicle after establishing the encrypted communication connection between the vehicle occupant's mobile device and the vehicle; and authenticating a request from the vehicle occupant's mobile device to the vehicle manufacturer's backend service with the generated temporary access token of the vehicle.
Owner:BAYERISCHE MOTOREN WERKE AG

Object authentication

Machines, devices, and other objects are configured to use authorization tokens to verify object identities without human input. In examples, the object uses a password to validate the object's identity to an authorization server to obtain an access token for use in multiple applications. In another example, the object uses a certificate to validate the object's identity to an authorization server to obtain an access token. In other examples, any other suitable identifying data may be used to validate the object's identity to an authorization server to obtain an access token. The process of using passwords, certificates, or other validation processes to obtain tokens or other authorization mechanisms allows the object to authenticate themselves without human interaction and to use a single identity to access services from multiple service providers that trust a central authorization server.
Owner:CITIGROUP TECHNOLOGY INC

Composite identity for accessing network-based services

Access management in a network-based service involves identifying an action involving a first account and determining if an account policy forbids the action. If forbidden, the system identifies an identity data structure linking the first account with a second account of a different type. The system determines if the second account allows the action, sends a transmission to the user's device identifying the second account, and receives an access token. If the token is valid, the system performs the action. The system may also create a new account if policies allow.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Robot safety communication method and device and storage medium

The invention discloses a robot safety communication method and device and a storage medium. The method comprises the following steps: acquiring an equipment identity credential from a hardware security environment of a robot, and establishing a security channel with a cloud service based on the equipment identity credential; obtaining an access token with a validity period from the cloud service through the secure channel; under the condition that the secure channel receives the control instruction from the cloud service, the control instruction is set in a temporary storage state; an execution authorization request for the control instruction is initiated to the cloud service, and the execution authorization request carries the access token; receiving a response to the execution authorization request from the cloud service; and under the condition that the response is authorization, the control instruction in the temporary storage state is sent to an execution mechanism of the robot to be executed.
Owner:ZHONGKE YUNGU TECH

Safety interaction control method of smart electric energy meter, smart electric energy meter and interaction system

PendingCN122372227AInteraction controlPayment
This application proposes a secure interactive control method for smart meters, a smart meter, and an interactive system, relating to the field of smart grid technology. The secure interactive control method includes: generating a one-time access token based on the smart meter's identity, dynamic factor, and key information; generating a dynamic identification code based on the one-time access token; refreshing the dynamic identification code according to the validity period of the one-time access token; receiving a near-field communication connection request, the connection request carrying a token to be verified parsed from the dynamic identification code; verifying whether the token to be verified matches the locally stored one-time access token; and, after successful verification, signing the current electricity consumption data and sending the signed current electricity consumption data to an external terminal via a near-field communication link; receiving business processing information and performing local billing status updates and / or power on / off control based on the business processing information. The dynamic identification code in this application ensures the security of the payment instruction source.
Owner:SHENZHEN CLOU ELECTRONICS +1

Security for ai / ML models

Various aspects of the present disclosure relate to security for artificial intelligence / machine learning (AI / ML) models. An apparatus, such as a user equipment (UE) or a network equipment (NE), transmits a first message including a request for an access token, wherein the first message includes first AI / ML model information. The apparatus receives a second message including the access token, wherein the access token includes second AI / ML model information. The access token can be used, along with other authorization information, to perform different AI / ML model management tasks.
Owner:LENOVO UNITED STATES INC

Data security management method and system based on block chain

The invention relates to the technical field of data security, and discloses a data security management method and system based on a block chain. The method comprises the following steps: acquiring and standardizing encrypted data and main body request information; extracting identity attributes and access requirements, and matching data paragraph attributes to generate permission vectors; synchronizing to a block chain and screening an adaptation rule combination; planning a conversion path to adjust an encryption key; verifying the identity authority, and calculating the matching degree to generate a temporary access token; the verification token obtains the data and re-encrypts the data; isolating the unauthorized content to obtain an isolated data packet; and after secure transmission, recording the log, updating the permission vector and synchronizing the permission vector to the block chain. And dynamic accurate authority management and secure sharing of encrypted data are realized. According to the method, dynamic accurate authority management and secure sharing of encrypted data can be realized, and dual requirements of data privacy protection and efficient circulation in a complex scene are met.
Owner:ZHONG YI DING SHENG JIAN SHE JI TUAN YOU XIAN GONG SI

Quantum-resistant security enhancement method for openid connect

The present application discloses a quantum-resistant security enhancement method for OpenID Connect in a communication network. The method comprises: when communication preprocessing is completed, receiving quantum-resistant token request information sent by a client; generating an access token and an identity token on the basis of the quantum-resistant token request information; generating a temporary key pair associated with the client; acquiring a quantum key identifier; processing the access token to generate a quantum-resistant access token; obtaining a quantum-resistant identity token on the basis of the temporary key pair, the quantum key identifier, post-quantum cryptography and the identity token; sending the quantum-resistant access token and the quantum-resistant identity token to the client; and receiving a resource access request generated on the basis of the quantum-resistant access token and the quantum-resistant identity token, and confirming an access permission to a corresponding resource, such that the client performs resource access on a server. The server and the client encrypt communications by means of post-quantum cryptography and quantum key distribution, thereby significantly enhancing the ability to resist quantum computing attacks.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Quantum secure infrastructure system and user terminal access method based on the system

The application discloses a quantum security infrastructure system and a user terminal access method based on the system, belongs to the field of quantum security communication and cryptography, and comprises the following steps: a cryptographic management service platform (CMSP) responds to an access request of a user terminal, determines an identity and access management system (IAM) and a key management system (KMS) that need to be accessed by the user terminal; if the IAM and the KMS belong to the same region, the CMSP sends IAM information of the IAM to the user terminal; the user terminal accesses the IAM based on the IAM information; if the IAM and the KMS do not belong to the same region, the IAM performs a key relay process through the CMSP, generates a service authentication token and access token ciphertext, and sends the service authentication token and the access token ciphertext to the user terminal; and the user terminal accesses the IAM based on the service authentication token and the access token ciphertext. The application improves the resistance to quantum attacks and the security of the system.
Owner:中电信量子信息科技集团有限公司

Passwordless wireless authentication

First, multiple access tokens can be received from various identity provider services. Each of these access tokens can be associated with a user. Then, the multiple access tokens can be stored in a profile associated with the user. Next, user policies associated with the use of the multiple access tokens can be assigned. A device token can then be provided to the user device associated with the user. The device token can be associated with a profile. A device token and a network policy can be received, and it can then be determined that the user policy and the network policy are consistent. In response to determining that the user policy and the network policy are consistent, authentication can be performed on at least one of the multiple identity provider services.
Owner:CISCO TECHNOLOGY INC

Apparatus, computer program and method

An apparatus comprising means for: receiving, from a first Application Programming Interface, API, Exposing Function, AEF, a request to access a second AEF, wherein the request comprises a Client Credentials Assertion, CCA, token signed by an API invoker and a first access token of the API invoker for the first AEF; authenticating the API invoker using the CCA token; generating a second access token for the first AEF to access a service of the second AEF.
Owner:NOKIA TECHNOLOGIES OY