Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

691 results about "Access token" patented technology

In computer systems, an access token contains the security credentials for a login session and identifies the user, the user's groups, the user's privileges, and, in some cases, a particular application. Typically one may be asked to enter the access token (for example a 40 character long gibberish) rather than the usual password (it therefore should be kept secret just like a password).

Container mirror image security management method and system

The invention relates to the technical field of data access security, and discloses a container mirror image security management method and system, and the method comprises the steps: constructing a container mirror image, generating a differential encryption key through a strategy center, carrying out the encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an environmental risk score, verifying access authority and an access scene matching degree through attribute-based encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer verification is passed, generating a temporary access token; according to the method, access request authority is verified, a temporary access token is matched, key fragments are synthesized, a master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-attack ability of container mirror image transmission is improved, and man-in-the-middle attack and data tampering are effectively coped with.
Owner:NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD

Method and system for safely sharing traffic edge computing data

The invention relates to the technical field of traffic data processing, and discloses a traffic edge computing data security sharing method and system, and the method comprises the steps: collecting traffic edge computing network multi-source heterogeneous data, and carrying out the classification standardization processing to generate a structured data set; designing a dynamic data sharing security protocol based on a multi-party security computing protocol and a homomorphic encryption algorithm; verifying the authority of a requester in a multi-level manner by using an attribute-based access control model and a zero-knowledge proof mechanism, and generating a dynamic access token; storing data by adopting a fragmentation storage and redundancy encryption strategy, and recording storage information through a hash chain; and dynamically adjusting the encryption strength and the sharing strategy according to the network threat level and the data sensitivity. The method effectively guarantees safe sharing of traffic data, accurately controls access authority, improves storage and sharing efficiency, adapts to complex network environment changes, and provides powerful support for development of an intelligent traffic system.
Owner:ZHENGZHOU UNIV +1

Data privacy protection method for data governance system

The invention provides a data privacy protection method for a data governance system, and belongs to the technical field of data governance, and the method comprises the steps: carrying out the cross verification of multi-source feature data and the unique identification information of an object collected on site, generating an original data set, carrying out the sensitive information recognition and grading, and generating the preprocessing data with a sensitive grade label; core identification information in the preprocessed data is disassembled to generate standardized desensitized data conforming to privacy protection, a bidirectional encryption mapping relation is established between object unique identification information collected on site and the standardized desensitized data, an encryption index is formed, the encryption index and preset multi-dimensional compliance data are fused, and a data fusion result is obtained; generating standardized fusion data; and based on the access token, generating a differential authorization data set divided according to permission granularity, performing privacy disclosure risk assessment, generating a risk level, performing privacy processing on the risk level, and outputting the risk level to a risk control system. And the data management efficiency is improved.
Owner:BEIJING GUOXINDA DATA TECH CO LTD

Intelligent warehouse login verification method and system based on dynamic living body detection

The invention relates to the technical field of information security, provides an intelligent warehouse login verification method and system based on dynamic living body detection, and is used for realizing accurate generation of an identity label vector, enhanced authentication of a dynamic password and automatic matching of warehouse authority while accurately performing living body detection. And the security and convenience of warehousing system login are comprehensively improved. The method comprises the following steps: collecting real-time interaction action data of a warehousing system login user, calling a preset living body detection algorithm to carry out dynamic biological characteristic analysis on the real-time interaction action data, and generating a living body verification confidence coefficient and a user identity identification vector; performing dynamic password enhanced authentication according to the living body verification confidence coefficient and a preset security authentication threshold value, and generating a dynamic access token containing multiple layers of encryption identifiers; and based on the user identity identification vector and the dynamic access token, executing storage permission automatic matching processing, and outputting a login verification result associated with the user permission level to the storage system according to the permission matching label.
Owner:SHANDONG LUNENG SOFTWARE TECH

Permission-based ai system responses

A method and apparatus are disclosed for generating permission-based large language model responses by using a query received from a user to identify a plurality of documents that are semantically similar to the query, using an access token received from the user to identify user accessible documents from the plurality of documents that the user is permitted to access, processing the user accessible documents to define a context of user accessible documents that is associated with the query, and then submitting the query and the context of user accessible documents to a large language model (AI system) to generate an AI system response to the query.
Owner:JIVE SOFTWARE LLC

Cloud deployment automation system with integrated resource orchestration and customizable deployment workflows

A cloud deployment automation system consisting of: a deployment automation device housed in a rack-mountable enclosure, the device comprising: a multi-core orchestration processor configured to execute deployment logic as compiled execution graphs; a storage module operatively coupled to the orchestration processor, the storage storing a set of deployment templates, real-time execution states, telemetry logs, and policy configurations; a secure credential management processing unit embedded in the device, configured to generate, store, and rotate cloud access tokens, API keys, and user-specific credentials, and to provide encrypted access to those credentials during deployment execution; an in-memory workflow execution engine executed by the orchestration processor, configured to analyze a user-defined deployment configuration that includes a declarative specification of infrastructure resources and compile that configuration into a directed acyclic graph (DAG) that represents the resource deployment order, dependency mapping, and rollback relationships, a cloud provider interface subsystem communicatively connected to multiple heterogeneous cloud platforms via appropriate API adapters, the subsystem enabling the orchestration processor to send provisioning requests and receive status events from the platforms; a customizable workflow compiler unit configured to convert graphical workflow definitions or domain-specific language (DSL) scripts into execution sequences that can be used by the workflow execution engine, where the workflow compiler unit supports conditional branching, asynchronous operations, and runtime variable resolution; and A policy enforcement control unit integrated into the deployment automation device, with the policy engine configured to apply organization-specific compliance rules, tagging conventions, security group configurations, and runtime resource limits to all deployment actions in a context-aware manner prior to execution.
Owner:THASON JUSTIN RAJAKUMAR MARIA FAIRFAX

Systems and methods for scheduling actions in remote networking environments while minimizing exposure of secured access credentials

Systems and methods for scheduling actions in remote networking environments while minimizing exposure of secured access credentials using a bifurcated security approach. The system may receive confirmation of a first verification that the first user is authorized to access the remote server. The system may, after providing access to the remote server, receive and schedule a first action. The system may generate a first access token for the remote server, wherein the first access token is specific to the first user. The system may authorize, via a second verification, the first action based on determining that the first access token is currently valid.
Owner:CAPITAL ONE SERVICES LLC

Server-to-device secure data exchange transactions

Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. In an embodiment, a smart device receives, from a requestor entity provided to the smart device, an account data provisioning request for an account. Based on the account data provisioning request, an account identifier for the account is determined. In some arrangements, the account identifier comprises or is associated with a device access token. Based on the device access token, a data element associated with the account is determined. In some embodiments, the data element is accessible to the requestor entity only if it is not access-restricted based on the device access token. Based on the data element, an executable graphic rendering instruction is generated. The executable graphic rendering instruction is executed, which includes generating and displaying, on a user interface of the smart device, a dynamic account status indicator relating to the account.
Owner:WELLS FARGO BANK NA

Identity authentication and access control method and device for low-altitude aircraft

The invention provides an identity authentication and access control method and device for a low-altitude aircraft, and the method comprises the steps: obtaining environment data, equipment state data and a historical authentication log of the low-altitude aircraft, and obtaining collection data; inputting the collected data into an AI decision engine, and generating an authentication factor combination through a pre-trained deep reinforcement learning model to obtain a main factor and a standby factor; performing identity authentication of the aircraft by using the main factor, and when the matching degree of the identity authentication of the main factor is in a preset interval, triggering a standby factor to perform secondary identity authentication to obtain an authentication result; and an access token is generated according to the authentication result and the risk assessment model, and the aircraft performs access control according to the access token. The invention relates to the field of low-altitude security management and control, and solves the technical problems that the identity authentication security of a low-altitude aircraft is insufficient and the low-altitude aircraft cannot dynamically adapt to a complex airspace environment in the prior art.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Heterogeneous database security access and report generation method based on MCP and agent

The invention relates to the technical field of database security, and discloses an MCP and agent-based heterogeneous database security access and report generation method, which comprises the following steps of: receiving a task request, acquiring a task context, synchronizing capability declarations from a plurality of database adapters according to the MCP, generating a capability graph and determining a capability version identifier; performing semantic mapping to obtain a strategy inline rewriting rule and a rewriting abstract fingerprint; the method comprises the following steps: signing and issuing a minimum permission access token, generating cross-source query, performing forced rewriting according to a strategy inline rewriting rule in a compilation stage, verifying consistency, processing an original result to obtain a purified result, only allowing to read a generated report from a buffer area of the purified result under the constraint of a structured mode template, and calculating a report fingerprint at the same time. And writing a chained audit log, fixing the audit log, and verifying report reproduction based on the audit log. According to the method and the system, minimum access, unauthorized prevention and control, compliance audibility and result reproducibility are realized.
Owner:BEIJING HEALTH ONLINE TECH CO LTD

Energy big data right confirmation method, system and device based on hierarchical hash tree and dynamic authorization and storage medium

The invention discloses an energy big data right confirmation method and system based on a hierarchical hash tree and dynamic authorization, and belongs to the field of energy big data management and information security, and the method comprises the steps: obtaining and standardizing original data in an energy scene, and dividing the original data into a data block set according to equipment and time; constructing a hierarchical hash tree and generating root hash; writing the root hash and the associated metadata into the block chain to realize right confirmation and evidence storage; executing proxy re-encryption according to the access token, and converting the ciphertext into a decryptable format; verifying the data consistency through the Hash path and the root Hash, and completing the access; and recording the access behavior and distributing transaction earnings by the smart contract based on the contribution degree. Hash calculation and local path updating of a data block level are supported through a layered Hash tree structure, so that when large-scale energy data is frequently updated, a new root Hash value can be quickly generated and right confirmation updating can be completed only by carrying out local Hash recalculation on a changed path.
Owner:GUIZHOU POWER GRID CO LTD

Front-end multi-tenant management method and device, electronic equipment and storage medium

The invention relates to the field of front-end technology, can be applied to the field of digital medical / financial science and technology, and discloses a front-end multi-tenant management method and device, electronic equipment and a storage medium. The method comprises the following steps: returning a security access token corresponding to a target tenant by using an authentication mechanism based on a token or third-party authorization according to a tenant registration request; when registration succeeds, role configuration data and permission configuration data of the target tenant are generated; when it is monitored that login is successful by using the security access token, creating a micro-front-end application and different micro-front-end modules of the target tenant according to the role configuration data and the authority configuration data; starting a micro-front-end application, and dynamically loading a micro-front-end module according to the role configuration data and the authority configuration data; and executing mixed mode rendering on the front-end module at the server side and the tenant side through the integrated front-end framework to obtain a front-end rendering page of the target tenant. According to the method, multi-tenant security isolation is realized, resources are loaded as required, and system performance and expansibility are guaranteed.
Owner:PING AN HEALTH INSURANCE CO LTD

Block chain-based gynaecology and obstetrics emergency medical data security sharing system

The invention discloses a gynaecology and obstetrics emergency medical data security sharing system based on a block chain, and relates to the technical field of medical information processing. The method is used for solving the security and timeliness problems of multi-mechanism data sharing in an emergency scene. The method comprises the following steps: firstly, performing grading processing and desensitization on personal identifiers and medical data of patients through a data grading and desensitization module, and outputting data which can be safely shared; then, an on-chain evidence storage module performs windowing processing on the continuous monitoring data flow, extracts key physiological features, generates feature value Hash, constructs data feature descriptors and submits the data feature descriptors to a block chain network; the emergency access token management module realizes dynamic authorization through a smart contract, and generates a temporary access token associated with the data feature descriptor; and finally, the secure decryption and data sharing module verifies the authority based on the hierarchical decryption key, decrypts the data and compares the eigenvalue hash, and shares and records an operation log with an authorization party after ensuring the data integrity, thereby realizing efficient, secure and traceable data sharing.
Owner:NORTHWEST WOMEN & CHILDREN HOSPITAL

Intelligent terminal identity authentication and data security management method, system and device based on block chain, and medium

The invention relates to the technical field of Internet of Things data management, in particular to an intelligent terminal identity authentication and data security management method, system and device based on a block chain and a medium, and the method comprises the steps: generating a unique identity label and a public and private key pair of an intelligent terminal device, a fog node and a user, packaging a digital certificate, and writing the digital certificate into a block chain network; the intelligent terminal equipment initiates a registration request, and the blockchain network distributes a hosting fog node to the intelligent terminal equipment after verification is passed; the intelligent terminal device generates data, constructs a data fingerprint, sends the data fingerprint to the block chain network for storage, encrypts the data, and sends the data to the hosting fog node for storage; a user initiates an authentication request, and a temporary access token is generated after verification is passed; and establishing a secure communication channel by using the temporary access token, obtaining the required encrypted data stored by the fog node, decrypting to obtain the required data, and verifying the integrity of the required data by using the data fingerprint. According to the invention, the overall security and reliability of data management of the Internet of Things system can be significantly improved.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Security authentication method and device, computer equipment, readable storage medium and program product

The invention relates to a security authentication method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: receiving a key generation request sent by target equipment; if it is determined that the key generation request is legal, generating a trust identifier and a security certificate of the target device, obtaining an identifier verification request through the trust identifier, and sending the identifier verification request to an authentication server, so that the authentication server verifies the trust identifier to obtain an access token corresponding to the target device; receiving a message returned by the authentication server, and processing an access token carried by the message to obtain a trust identifier; and writing the security certificate into the target protection area, and sending the trust identifier and the security certificate to the target equipment, so that the target equipment is registered in the authentication server. By adopting the method, the identity verification of the equipment and the control of an encryption communication mechanism are realized, and the safety protection performance in a communication system is further improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Generating access tokens for direct data plane requests

A data analytics system receives a data access request from a client device at a control plane. The data access request is a request to access a set of target data files stored by the data analytics system. The data analytics system identifies a data plane that stores the set of target data files and generates an access token for the client device based on the request and the identified data plane. The access token is a token that contains authorization information for the client device to request the target data files directly from identified data plane. The client device can transmit the access token to the data plane to request the target data files. The data plane receives the data file request with the access token, collects the target data files, and transmits them to the client device.
Owner:SSLP LENDING LLC

Permission management method and apparatus, and device and storage medium

The embodiments of the present disclosure relate to a permission management method and apparatus, and a device and a storage medium. The method provided herein comprises: receiving an application request from a proxy service, wherein the application request indicates permission information of a target application regarding a set of resources; sending to the proxy service an access token corresponding to the permission information; receiving from the target application an access request for a target resource, wherein the access request comprises the access token; determining whether the access request matches the permission information corresponding to the access token; and in response to the access request matching the permission information, authorizing the target application to access the target resource. In this way, the embodiments of the present disclosure can improve the security and flexibility of resource access.
Owner:DOUYIN VISION CO LTD

Methods, systems, and computer readable media for detecting and mitigating security attacks on producer network functions

A method for detecting and mitigating security attacks on producer network NFs (202) using access token to non-access-token parameter correlation at a proxy NF (126B) includes receiving an inter-PLMN SBI request message, obtaining, from an access token transmitted with the inter-PLMN SBI request message, at least one network- or service-identifying parameter and obtaining, externally from the access token, at least one network- or service-identifying parameter. The method further includes comparing the at least one network- or service-identifying parameter obtained from the access token and the at least one network- or service-identifying parameter obtained externally from the access token and performing a network security action when the at least one network- or service-identifying parameter obtained from the access token does not match the at least one network- or service-identifying parameter obtained externally from the access token.
Owner:ORACLE INT CORP

Methods, systems, and computer readable media for detecting and mitigating security attacks on producer network functions (NFs) using access token to non-access-token parameter correlation at proxy nf

A method for detecting and mitigating security attacks on producer network NFs using access token to non-access-token parameter correlation at a proxy NF includes receiving an inter-PLMN SBI request message. The method further includes obtaining, from an access token transmitted with the inter-PLMN SBI request message, at least one network- or service-identifying parameter and obtaining, externally from the access token, at least one network- or service-identifying parameter. The method further includes comparing the at least one network- or service-identifying parameter obtained from the access token and the at least one network- or service-identifying parameter obtained externally from the access token and performing a network security action when the at least one network- or service-identifying parameter obtained from the access token does not match the at least one network- or service-identifying parameter obtained externally from the access token.
Owner:ORACLE INT CORP

Power encryption database fine-grained access control method based on quantum key

The embodiment of the invention provides a power encryption database fine-grained access control method based on a quantum key, and relates to the technical field of quantum communication. The access control method comprises the following steps: performing identity authentication on a data user applying for data access; after the data user passes the identity verification, verifying the user attribute of the data user, and issuing a dynamic access token; after identity verification and attribute verification, establishing a QKD channel between the data center and the data user, and generating a quantum key; the data center defines an access strategy according to the user attribute corresponding to the plaintext; encrypting a plaintext and an access strategy through the generated quantum key to obtain a ciphertext; storing the ciphertext in a distributed database of the data center; verifying whether the user attribute of the data user is consistent with the access strategy in the ciphertext according to the access token; under the condition of consistency, the data center distributes the secret key to the data user through the QKD channel; and the data user decrypts the ciphertext according to the distributed key to obtain a plaintext.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD +1

Multi-tenant multi-user login method based on enhanced OAuth2

The invention provides a multi-tenant multi-user login method based on enhanced OAuth2, which relates to the technical field of network security, and comprises the following steps: obtaining a key threshold through a tenant identifier, and executing OAuth2 authentication to obtain an access token; tenant fingerprint information is generated through zero-knowledge proof and homomorphic encryption, and a tenant verification token is generated through secure multi-party calculation; constructing a reinforcement learning access controller in combination with the historical access data, and generating and verifying an authority list; and finally forming a session identifier and storing the session identifier in a distributed cache. According to the invention, the authentication security is improved, cross-tenant fine-grained authority management is realized, and unauthorized access is effectively prevented.
Owner:ZHEJIANG SHUXIN NETWORK CO LTD

Secure access control method and device of MCP protocol, storage medium and program product

The invention relates to the field of artificial intelligence, and discloses a security access control method and device of an MCP protocol, a storage medium and a program product. The method comprises the following steps: in a tool registration stage, performing digital signature on tool metadata registered in an MCP server, and signing and issuing an access token containing a client identity attribute to complete bidirectional identity authentication of a client and an external tool; a tool calling request initiated by the MCP client is acquired and intercepted, context information of the request is collected, the context information comprises at least one of a main body attribute, a resource attribute, an operation attribute and an environment attribute, and the tool calling request carries an access token; the context information is submitted to a strategy decision point, dynamic evaluation is carried out based on a preset attribute-based access control strategy rule, an authorization decision is generated, and the authorization decision comprises permission and rejection; and executing releasing or blocking operation on the tool calling request according to the authorization decision.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Methods and apparatus to access federated resources

Disclosed examples include transmitting a discovery result to a client application, the discovery result including a list of federated data lakes; and after receiving a token request specifying a first data lake of the federated data lakes, transmitting an access token and metadata to the client application. The access token and the metadata corresponding to the first data lake. The metadata specifies services available at the first data lake. The access token grants the client application access to the first data lake of the federated data lakes.
Owner:CLOUDERA INC

Resource classification layer for constant request verification in zero trust systems

A method is disclosed for managing access in a telecommunications network by utilizing a resource classification layer. The method involves receiving a request at a resource classification layer from a sender to obtain an access token for a receiver service. The sender is associated with a user role that has specific permissions and access rights corresponding to a data sensitivity threshold. The request includes a data payload. A classification value for the data payload is assigned using one or more resource classification models, which are trained on a log of past data payloads. A data sensitivity score is generated by comparing the classification value to a scale of classification values. The method then indicates whether the access token can be granted to the sender by comparing the data sensitivity score against the data sensitivity threshold to verify authorization.
Owner:T MOBILE US INC

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Systems and methods for immersive data management in spatial computing

Systems and methods for immersive data management in spatial computing are disclosed. A method may include: (1) requesting from an identity and access management service executed in a cloud environment, an access token; (2) receiving, from an identity and access management service, the access token comprising user entitlements to access a plurality of elements in a plurality of scenes; (3) requesting one of the plurality of scenes from a scene filtering service, the request comprising the access token; (4) identifying the user entitlements from the access token; (5) retrieving the requested scene comprising a subset of the elements; (6) adding the elements that the user is entitled to based on the user entitlements to a scene to be displayed; (7) returning the scene to be displayed to the computer program; and (8) displaying the scene to be displayed.
Owner:JPMORGAN CHASE BANK NA

Open platform management method and system based on dynamic reflection calling

The invention provides an open platform management method and system based on dynamic reflection calling in the technical field of distributed micro-services and gateways. The method comprises the following steps: S1, forwarding an access request to an authentication center; s2, the authentication center executes identity authentication and issues an access token, and the client sends a request message to the open platform based on the access token; s3, the open platform carries out authentication, decryption and signature verification on the request message to obtain message content containing request parameters and a target service subsystem; s4, searching interface metadata and a network address of the target service subsystem; and S5, through a dynamic reflection calling engine, generating a proxy instance based on the interface metadata, mapping the request parameter into a target parameter, and through the proxy instance and the network address, calling the target service subsystem to execute the target parameter. The method has the advantages that the safe, uniform and non-intrusive open service capability is realized, and the maintainability, the safety and the evolution capability of the platform are greatly improved.
Owner:FUJIAN ECAN INFORMATION TECH CO LTD

Personal health related data access method and system based on block chain

The embodiment of the invention discloses a personal health related data access method and system based on a block chain, and the method comprises the steps: receiving a health data access request, and carrying out the access judgment operation: carrying out the identity verification of a request main body of the health data access request through a block chain network digital identity authentication mechanism, performing equipment authentication on the request main body, and performing access condition evaluation through next-generation access control; if the data access is allowed, determining target health data corresponding to the health data access request, and generating a temporary access token through an intelligent contract on a block chain network where the target health data is located, so that the request subject accesses the target health data through the temporary access token; performing data protection operation on the target health data, generating risk tracing information, and storing the risk tracing information and access log information of the target health data in a block chain network; and performing data risk judgment operation according to the access log information, and performing risk management according to the risk tracing information when a risk event is judged.
Owner:PROACTIVE MEDICAL DEVICES LTD +3