Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Active directory" patented technology

Active Directory Federation Services (AD FS) is a single sign-on service. With an AD FS infrastructure in place, users may use several web-based services (e.g. internet forum, blog, online shopping, webmail) or network resources using only one set of credentials stored at a central location, as opposed to having to be granted a dedicated set of credentials for each service.

Green financial transformation field judgment system based on keyword library and scoring algorithm

The invention discloses a green financial transformation field judgment system based on a keyword library and a scoring algorithm. The green financial transformation field judgment system is characterized by comprising a keyword library construction module, a data uploading module, a scoring module, a core phrase extraction module and a field judgment module, the keyword library construction module is used for analyzing and arranging the content of the transition finance support economic activity catalog to form a keyword library; the data uploading module is used for receiving enterprise data; the core phrase extraction module is used for extracting core phrases from enterprise data; the scoring module is used for matching and scoring the extracted core phrases according to the importance weight of each keyword in the keyword library, and calculating to obtain a comprehensive score of each field; and the field judgment module is used for comparing the comprehensive scores of the fields calculated by the scoring module, and selecting the field with the highest comprehensive score as the green financial transformation field to which the target enterprise belongs. The method has the advantages that the green financial transformation field to which the enterprise belongs can be automatically, efficiently and accurately judged.
Owner:CHONGQING CREDIT INFORMATION CO LTD

Agentless active directory granular level restore from virtual machine level backups

A method for managing data protection includes obtaining, by a backup server, a restoration request for a virtual machine (VM) that includes an active directory (AD) application, and wherein the AD application comprises a set of AD objects and a directory service for managing the set of AD objects, parsing a VM backup corresponding to the VM, stored in a backup storage system, to identify an AD application backup of the AD application using metadata stored in an index and search microservice of the backup server, mounting, using an AD recovery microservice, backups of the set of AD objects of the AD application backup to the production environment, and providing browse and restoration services to the production environment based on the mounting of the AD objects and using the AD recovery microservice.
Owner:DELL PROD LLC

Ciphertext Header-Based Data Security

Methods for landing encrypted data in a column, requesting access to decrypted data, and storing multiple data sets in a single column with different encryption schemes based on utilizing cryptographic key and algorithm identifiers in ciphertext headers. The methods comprise an application of a storage system receiving an access request to encrypt data to or decrypt data from (respectively) a database of the storage system. Next, the application determines whether the external source is permitted to encrypt to or decrypt from the database based on external source identifiers and permissions specified in an active directory of the storage system. When the external source is authenticated (i.e., permitted), performing the appropriate steps to write encrypted data by adding to ciphertext headers cryptographic key and algorithm identifiers or read decrypted data by obtaining cryptographic key and algorithm identifiers from ciphertext headers.
Owner:T MOBILE INNOVATIONS LLC

System and methods for minimizing organization risk from users associated with a password breach

System and methods are disclosed for organizations to run a test against an active directory list to see if any user-provided passwords have been part of an existing data breach. Utilizing information from such a test identifies users that have weak passwords, reused passwords or shared passwords that have been associated with an earlier breach. With this information, the organization can seek to reduce risk by training staff for this specific issue in a timely and appropriate manner to significantly reduce the risk of a future breach by those identified users. Training can be customized and targeted at those users who attempt to use passwords that have been associated with a breach (either of their own account or of another account on the same or related domain.
Owner:KNOWBE4 INC

Online conference cooperation system and method

The invention relates to the technical field of online conferences, and discloses a collaboration system and method for an online conference, and the method comprises the following steps: a user logs in the system through authentication, the authentication comprises AzureActiveDirect-based login and secondary verification, and the secondary verification is realized through a mobile phone short message code or a security verification code; the user creates a new conference and submits conference information, wherein the conference information comprises a conference theme, a conference date, a conference owner and a remark; the user uploads a video file to the new conference, wherein the video file supports multiple formats; and performing translation analysis on the uploaded video file. The efficient multi-language speech recognition and translation system is constructed by integrating the acoustic model, the language model and the neural machine translation model with the attention mechanism, accurate speech recognition and real-time translation can be automatically carried out on conference videos including Cantonese, Mandarin and English, synchronous subtitles are generated, and the speech recognition and translation efficiency is improved. And the language barrier in the multi-language conference scene is effectively eliminated.
Owner:ZHUHAI AIPUJING SOFTWARE TECH CO LTD

Systems and methods for role-based computer security configurations

ActiveCA3054609CSoftware engineeringAssociative processor
An apparatus includes a processor operatively coupled to a memory. The processor detects a software application installed on a client computing device, and / or usage data. Detected usage data is associated with a current user of the client computing device and with the software application. The processor identifies a user role for the current user based on the software application and / or usage data. The processor applies a security configuration to the client computing device based on the user role. The security configuration limits access by the current user to a portion of the software application. The processor sends an identifier of the user role to an administrative server for storage in an Active Directory (AD) database.
Owner:IVANTI INC

Active directory data protection by leveraging virtual machine backup with change notification-based active directory backup

A method for managing data protection includes initiating, by a backup server, discovery for a new virtual machine (VM) in a production environment, performing, using an active directory listener (AD), listening on active directory (AD) applications in the production environment, wherein the new VM executes one of the AD applications, and wherein the one of the AD applications comprises a set of AD objects and a directory service for managing the set of AD objects, storing, based on the listening, monitored changes to obtain stored changes in the AD applications, generating a change report based on the stored changes, and using the change report to perform an incremental backup of the new VM and store a VM backup of the new VM and an AD application backup of the one of the AD applications in a backup storage system.
Owner:DELL PROD LP

Identity threat detection and response

Systems and methods are provided for protecting identity information in a directory, such as Active Directory. A method, according to one implementation, include the step of conducting a scan of a directory of a network domain to gain visibility of one or more vulnerabilities of the directory. The one or more vulnerabilities define a potential security risk that would allow an attacker to leverage identity-related information from the directory. The method further includes the step of guiding an administrator regarding management of the directory to reduce the potential security risk. Also, the method includes the step of monitoring the directory for one or more attacks to leverage the identity-related information.
Owner:ZSCALER INC

A vehicle networking cross-domain identity authentication method based on master-slave multi-chain architecture

This invention proposes a cross-domain identity authentication method for the Internet of Vehicles (IoV) based on a master-slave multi-chain architecture, comprising six stages: system initialization, OBU registration, certificate storage, cross-domain identity authentication, certificate update, and certificate revocation. Considering that traditional IoV uses a single-chain blockchain structure, it cannot effectively isolate vehicle information across cities, posing risks of privacy leaks and low query efficiency. Therefore, this invention proposes a master-slave multi-chain architecture, where slave chains in each city build a secure cross-domain communication channel through the master chain, achieving secure isolation of cross-domain vehicle information. For data storage, a Merkle tree hash mechanism is used to process vehicle information to ensure data integrity and immutability. A prefix tree is used to compress the common parts in the hash path, constructing an MPT-based storage structure to improve the query efficiency of vehicle information. Furthermore, Active Directory (AD) is used to monitor malicious vehicle behavior in real time, thereby achieving secure and efficient cross-domain identity authentication.
Owner:BAOTOU NORMAL UNIV OF INNER MONGOLIA UNIV OF SCI & TECH

Domain environment ADCS deception trapping method based on attack and defense game

The invention relates to a domain environment ADCS deception trapping method based on an attack and defense game, and belongs to the technical field of network security. Aiming at the problems that strategy fingerprints are easy to expose and attack chains are difficult to trace in Active Directory certificate service defense, the system decodes attacks by deploying simulation honey point clusters, adopts a Stackelberg-Markov game model as the core to perform intelligent decision making, dynamically simulates TameMyCerts strategy fingerprints to hide real defense features, and embeds hidden identifiers in cheating certificates by using a certificate staining tracking technology, so that the real defense features are hidden. And capturing and tracing from attack detection to certificate utilization full link are realized. And finally, the system is linked with the existing security equipment through a collaborative interface to form an active defense closed loop, so that the security protection capability of the Active Direct certificate service is improved.
Owner:GUANGZHOU UNIVERSITY +1

Process control systems using active directory to manage user access of field devices

Process control systems using active directory to manage user access of field devices are disclosed herein. An example process control system includes a user management system including an active directory of user names and group names assigned to respective ones of the user names, a computer to communicate with the user management system over a network, and a field device to communicate with the user management system and the computer over the network. The computer is to be operated by a user to connect to and access information on the field device. The user has a first user name. The field device is to determine a first permission configuration associated with a first group name assigned to the first user name, and establish a working session with the computer and allow access and communications between the field device and the computer based on the first permission configuration.
Owner:BRISTOL INC

Authentication process for facilitating secure access to voice-enabled applications

A system can be provided for providing access for internal client devices to a voice-enabled application. For example, the system can receive an access request with an authentication credential associated with an internal client device. The access request can be a request to access the voice-enabled application. In response to receiving the access request, system can verify the internal client device by accessing an active directory with authentication credentials authorized to access the voice-enabled application and by determining that the authentication credential is included the authentication credentials of the active directory. Then, in response to verifying the internal client device, the system can transmit an indication of the verification of the internal client device to the authentication system to cause the authentication system to provide access for the internal client device to the voice-enabled application.
Owner:TRUIST BANK

Data analytics systems with effective access permission monitoring

Data analytics methods are described herein which may provide permission management to one or more file servers in a virtualized file system. Example methods may include receiving, at an analytics system, an access control list of a storage item in a file server responsive to a change to data in the storage item, the access control list including access control entries; evaluating effective access of the access control list based on an active directory; detecting a change in either one or more permissions or one or more memberships of the storage item in the active directory; re-evaluating, at the analytics system, the effective permission of the access control list upon detecting the change; storing the effective permission in a data repository of the analytics system; and accessing the effective permission at the data repository during a time the file server is unavailable to the analytics system.
Owner:NUTANIX INC

Fine-grained recovery method and device of activity directory, computer equipment and medium

The invention relates to a fine-grained recovery method and device of an activity directory, computer equipment, a computer readable storage medium and a computer program product, and can be used in the technical field of computers. The method comprises the following steps: receiving identification information of a to-be-recovered target object aiming at an active directory; acquiring data in a recycle bin of the active directory, and matching the identification information with the data in the recycle bin to obtain a matching result; under the condition that the matching result shows that the matching is successful, recovering the target object from the recycle bin; comparing the attribute information of the target object with backup attribute information corresponding to the target object in a backup set of the active directory to obtain a comparison result; under the condition that the comparison result shows that the difference exists, the target object is updated according to the backup attribute information, and a recovery object of the active directory is obtained. By adopting the method, the object recovery efficiency can be improved.
Owner:GUANGZHOU DINGJIA COMPUTER TECHNOLOGY CO LTD

Process control systems using active directory to manage user access of field devices

Process control systems using active directory to manage user access of field devices are disclosed herein. An example process control system includes a user management system including an active directory of user names and group names assigned to respective ones of the user names, a computer to communicate with the user management system over a network, and a field device to communicate with the user management system and the computer over the network. The computer is to be operated by a user to connect to and access information on the field device. The user has a first user name. The field device is to determine a first permission configuration associated with a first group name assigned to the first user name, and establish a working session with the computer and allow access and communications between the field device and the computer based on the first permission configuration.
Owner:BRISTOL INC

Risk factors for an organization network

A method for determining risks associated with an identity in an organization network, including scanning an active directory for a network including a plurality of identities, to extract a plurality of attributes of the identities and their corresponding values. analyzing the extracted attribute values for an identity in the network to identify one or more risks associated with that identity, which an attacker can exploit, assigning a score to each risk identified by said analyzing, and further assigning a score to the identity based on the scores of the one or more risks associated with the identity.
Owner:GOLDMAN SACHS BANK USA

Automated lightweight active directory protocol (LDAP) consolidation via LDAP discovery

PendingUS20260189530A1Domain nameData transport
Methods and systems for automatically discovering and consolidating lightweight active directory protocol (LDAP) servers into a centralized-LDAP (C-LDAP) are described. A method includes initiating, by an orchestration engine, automated discovery of LDAP systems deployed across an entity, establishing, by the orchestration engine, secure connections between a centralized LDAP (C-LDAP) system and identified LDAP systems, forming, by the orchestration engine, a partitioned directory database in response to data from the identified LDAP systems, requesting, by the orchestration engine, each directory database associated with the identified LDAP systems to transfer directory data to the partitioned directory database, instructing, by the orchestration engine, one or more domain name system (DNS) servers to resolve requests directed to the identified LDAP systems to the C-LDAP system, and repurposing one or more of the identified LDAP systems.
Owner:CHARTER COMM OPERATING LLC