Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

266 results about "Authentication server" patented technology

An authentication server provides a network service that applications use to authenticate the credentials, usually account names and passwords, of their users. When a client submits a valid set of credentials, it receives a cryptographic ticket that it can subsequently use to access various services.

Authentication management method for non-3GPP access of a UE device to a 5G network

A core network server for defining authentication credentials and authenticating a wireless communication device according to WIFI communication protocols includes a central processing unit (CPU) and a non-transitory memory comprising executable instructions that when executed by the CPU, causes the core network server to receive an encrypted authentication request from a wireless communication device; send the encrypted authentication request to an authentication server based on one or more attributes in the encrypted authentication request; receive an indicator of a specialized network slice associated with the wireless communication device based on sending the encrypted authentication request; communicate authentication messages to the wireless communication device according to one or more network functions of the specialized network slice; and authenticate the wireless communication device according to the specialized network slice responsive to communicating the authentication messages.
Owner:T MOBILE INNOVATIONS LLC

Computing systems and methods for provisioning privacy-preserving identity-bound passkeys and digital signatures

Systems and methods are provided that allows users to execute a secure digital action that is authenticated by their digital wallet app (or wallet) on a user device or a wallet server. An identity issuer server issues a batch of verification credentials (VCs) for an identity holder to the wallet. The wallet stores the batch of VCs, respectively binds each VC in the batch of VCs with a given passkey from a plurality of passkeys, generates selective disclosures via a content generator server, and transmits the batch of VCs, as a plurality of VC presentations, to an identity verification server. An identity verification server requests and validates the plurality of VC presentations, and, responsive to validating the plurality of VC presentations, registers the plurality of device-bound passkeys respectively bound to the batch of VCs to generate a plurality of registered passkeys. In a secure digital action, after generating the plurality of registered passkeys, the identity verification server is further configured to authenticate the identity holder using one or more of the registered passkeys.
Owner:LOGIN ID INC

System and method for authenticating user of robotaxi

An embodiment system for authenticating a user of a robotaxi includes an authentication server and a robotaxi. The authentication server configured to create a first authentication number, transmit the first authentication number to a smart phone the user, receive a second authentication number from the robotaxi when authenticating the user using a digital key fails, and request unlocking of a door to the robotaxi when the first authentication number and the second authentication number match. The robotaxi configured to receive the second authentication number from the user, transmit the second authentication number to the authentication server, and unlock the door in response to the request from the authentication server.
Owner:HYUNDAI MOTOR CO LTD +1

WAPI intelligent air switch, end-network-cloud security measurement and control method and system thereof, and medium

The invention discloses a wireless authentication and privacy infrastructure (WAPI) intelligent air switch, an end-network-cloud security measurement and control method and system thereof and a medium, and relates to the field of power internet of things security. A closed-loop system consisting of terminal equipment, a WAPI wireless access network, an authentication server and a cloud management platform is constructed; the authentication server verifies a negotiation session key and establishes an encrypted communication link, the terminal collects electric power parameters, encrypts and uploads the electric power parameters to the cloud, the cloud analyzes the electric power parameters and then issues a control signal, the terminal verifies and analyzes the electric power parameters through a trusted execution environment and drives an execution mechanism to operate, meanwhile, a power consumption mode is dynamically switched, and the cloud stores logs in a hash chain mode. According to the invention, through the technologies of hardware encryption, isolation execution and the like, the communication security and the equipment reliability are improved, and the requirements of high security, low power consumption and traceability of an electric power scene are met.
Owner:QUJING BUREAU OF SUPERVOLTAGE POWER TRANSMISSION CHINA SOUTHERN POWER GRID

Secure generation of one-time passcodes using a contactless card

Systems, methods, apparatuses, and computer-readable media for secure generation of one-time passcodes using a contactless card. In one example, an operating system (OS) of a device may receive a uniform resource locator (URL) and a cryptogram from a contactless card. The OS may launch an application associated with the URL. The application may transmit the cryptogram to an authentication server. The application may receive a decryption result from the authentication server indicating the authentication server decrypted the cryptogram. Based on the decryption result, the application may request an OTP. The processor may receive an OTP from an OTP generator. The application may receive an input value and compare the input value to a copy of the OTP. The application may determine that the comparison results in a match, and display, based on the determination that the comparison results in the match, one or more attributes of the account.
Owner:CAPITAL ONE SERVICES LLC

Authentication of users utilizing biometric data in a non-centralized computer system

A system for authenticating a sender of a response to an authentication request includes an authentication server, an identity server configured to receive biometric data of a user, a central ID system configured to create or receive a username and / or password, and a first user device associated with a first user. The first user device is configured to create a first user ID that includes at least a first username and a first biometric data. When an authentication request is sent to a user device by the authentication server the user device responds with a user ID. The authentication server then queries at least one or both of the central ID system and the identity server to certify the accuracy of the user ID to assure it matches the first user ID before (1) accepting the response, or (2) permitting the first user to access confidential information. The systems and methods may also include blockchain authentication or tuple space authentication.
Owner:MITEL CORP

Telecommunication system and method of operating the telecommunications system

PendingCN122319638ATicketTelecommunications
A method (200) for operating a telecommunications system (100), the system comprising: a client device (110); a set of servers (130) for providing services to the client device; and an authentication server (120) for generating authentication tickets for the set of servers to provide services to the client device; the method comprising the steps of: generating at the authentication server: a set of encrypted service levels (220), the set comprising at least two different service levels, each level: including performance requirements; and encrypted with a corresponding encryption key from a set of encryption keys; and an authentication ticket for the client device and services, the ticket comprising the set of encrypted service levels; transmitting the authentication ticket to the set of servers (230); and performing a process comprising the following steps Process: Transmits an encryption key from a set of encryption keys that has not yet been transmitted to the server set (240); The server set processes the authentication ticket using the transmitted encryption key to retrieve the performance requirements within the corresponding service level (250); The server set determines whether to provide service at least according to the retrieved performance requirements (250); and after determination, identifies whether to provide service at least according to the retrieved performance requirements (260): rejected by the server set (260-1), in response to which the process is iterated again (240); or accepted by at least one server (260-2), in response to which one of the servers is selected to provide service at least according to the retrieved performance requirements (280).
Owner:BRITISH TELECOM PLC

Non-inductive continuous authentication anti-stealing-link method

The invention provides a non-inductive continuous authentication anti-stealing-link method, which is applied to an HLS streaming media transmission protocol and comprises the following steps: a client sends an authentication request containing unique authentication information to a service server; the service server obtains a first information identifier based on the authentication request, and the unique authentication information, the first information identifier and the live broadcast resource address are included in authentication information and forwarded to an authentication server; the authentication server generates a permission token based on the authentication information, and returns the permission token to the business server; the service server splices the permission token into the live broadcast resource address to form a parametric address, and returns the parametric address to the client; and the client periodically sends a polling request to the live broadcast resource server based on the parametric address so as to obtain the live broadcast content from the live broadcast resource server. The method has the beneficial effects that non-inductive continuous authentication is realized, and the authentication information is complex in composition and not easy to crack.
Owner:SHANGHAI MEDIA TECH

System and method for device matching during a customer service call

Embodiments are directed to systems and techniques to perform device matching during a customer service call. In some examples, the techniques provided herein include receiving, at a call center system, a communication from a device associated with a user account. The method further includes, in response to receiving the communication, sending a message to the device associated with the user account, the message including a link for a user to interact with on a user interface of the device, wherein interaction with the link by the user causes initiation of an application on the device for receiving encrypted data from a contactless card associated with the user account. The method further includes receiving, by the call center system, from an authentication server, an authorization message indicating whether the user account is authorized to maintain the communication based on an evaluation of the encrypted data by the authentication server.
Owner:CAPITAL ONE SERVICES LLC

Power wireless communication system and smart grid

This invention addresses the problem in existing technologies where WiFi signals are easily interfered with. In complex electromagnetic environments such as substations, electromagnetic interference generated by other electronic devices and power equipment can affect the stable transmission of WiFi signals, leading to data loss or transmission delays. The invention provides a power wireless communication system and a smart grid. It relates to the field of power wireless communication systems. The system includes a sensing layer, a network layer, and an application layer. The sensing layer includes at least one power monitoring terminal for collecting power equipment operation data. The network layer includes a secure access module, a WAPI authentication server, and a communication network architecture. The secure access module connects to both the power monitoring terminal and the WAPI authentication server via a WAPI encrypted channel. The communication network architecture includes a core routing unit and a wireless access unit. The application layer includes a power control center and a security audit module. This invention constructs a secure protection system for data acquisition, transmission, processing, and control.
Owner:SICHUAN ENERGY INVESTMENT YIBIN XUZHOU ELECTRIC POWER CO LTD

Adaptive dynamic identity authentication method and system based on trust evaluation

The application discloses a kind of based on trust evaluation's adaptive dynamic identity authentication method and system, belong to information security field, including steps: S1, access subject initiates identity authentication service request to adaptive dynamic authentication server;S2, adaptive dynamic authentication server parses and identifies personnel information, and requests trust evaluation value to trust evaluation engine;S3, trust evaluation engine continues trust evaluation, calculates trust evaluation value;S4, trust evaluation engine carries out calculation based on multiple trust evaluation values, and evaluates integrated trust evaluation value;S5, trust evaluation engine returns the integrated trust evaluation value of user to adaptive dynamic authentication server;S6, adaptive dynamic authentication server carries out adaptive dynamic authentication;The application constructs an intelligent, feedback type identity authentication mode, can solve the problem that authentication strategy cannot be self-adaptively adjusted once being set in current authentication system, with wide application value.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Identity verification method and system

The invention discloses an identity verification method and system, and the method comprises the steps: generating a verification result through a verification algorithm after an identity verification server receives an identity verification request; when the verification result is successful, generating a legal identity certificate; and when the verification result is failure, generating a counterfeit identity certificate, and generating at least one of counterfeit reasonable data, counterfeit reasonable authority and counterfeit reasonable abnormity. The method has the core advantages that fake reasonable information is returned when verification fails, so that illegal visitors cannot deduce correct identity information by using failure feedback and cannot distinguish the authenticity of acquired data, authority or abnormal prompts, illegal behaviors such as library collision attacks and brute force cracking are effectively avoided, and the safety of the visitors is improved. The defect that key information is leaked due to failure feedback in the traditional identity verification technology is overcome, and the security of system data and functions is remarkably improved.
Owner:要宇轩

Method for processing medical images, program product, readable storage medium and computer system

A medical image processing method, program product, readable storage medium, and computer system are disclosed. The medical image processing method processes a medical image at a medical image device, characterized in that the method includes the following steps: an operation extraction step, which performs a hash operation on medical image data obtained using an imaging system to obtain a hash value and extracts a data packet included in the medical image data; a generation step, which generates the hash value and the data packet obtained in the operation extraction step as request data; a transmission step, which transmits the request data generated in the generation step to an authentication server for time stamp authentication; a reception step, which receives data authenticated using the time stamp authentication from the authentication server; and a writing step, which writes the authenticated data received in the reception step to a designated information field of the medical image.
Owner:BEIJING UNITED TRUST TECH SERVICE CO LTD

Method, device, equipment, storage medium and program product for file transmission

ActiveCN119814766BData transportEngineering
The application discloses a file transmission method, device, equipment, storage medium and program product, and is applied to an authentication server. The specific technical scheme comprises the following steps: receiving an identity authentication request sent by a terminal, wherein the identity authentication request carries user identity information and a to-be-transmitted file; querying authentication information corresponding to the user identity information in a database; calculating a check parameter corresponding to the user identity information based on the authentication information and a preset authentication algorithm; authenticating the terminal based on the check parameter; and transmitting the to-be-transmitted file in the case that the terminal is authenticated successfully. In this way, the data encryption speed can be improved, and thus the data transmission efficiency is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Business real-name authentication method and device, electronic equipment and readable storage medium

The application discloses a business real-name authentication method and device, electronic equipment and a readable storage medium, which are applied to an authentication server, the authentication server is in communication connection with a user terminal, and the method comprises the following steps: acquiring a real-name authentication request sent by the user terminal for a to-be-authenticated business; feeding back a real-name authentication result corresponding to the real-name authentication request to the user terminal, so that the user terminal generates an authentication information lock of the to-be-authenticated business according to the real-name authentication result, and sends the authentication information lock to the authentication server, wherein the authentication information lock carries to-be-authenticated information; and performing real-name authentication on the to-be-authenticated business according to the to-be-authenticated information. The application solves the technical problem of low authentication security of business real-name authentication.
Owner:中国移动通信集团江西有限公司 +1

Code scanning authentication method, system and related device

The application relates to a code scanning authentication method, a system and related equipment. The method adopts scanning a two-dimensional code displayed by a client to obtain a trusted timestamp and a dynamic address; based on the trusted timestamp, a first signature is generated by using a first signature private key of a mobile terminal, the first signature is sent to a co-signing server to trigger the co-signing server to use a second signature private key stored by the co-signing server to perform secondary signing on the first signature; according to the dynamic address, a final signature, a signature certificate of the mobile terminal and the trusted timestamp are submitted to a corresponding authentication server; after authentication succeeds, in response to a login state query request, the client obtains user identity information and automatically completes login, the problems that in the prior art, mobile terminal key single-point storage risk is high, and after a private key is leaked, the private key is easily abused to cause authentication credentials to be impersonated are solved, the technical effect that authentication credentials impersonation risk caused by single-end private key leakage is avoided, and the security and reliability of code scanning authentication are improved.
Owner:BEIJING EETRUST TECH CO LTD

Unified authentication system access method and apparatus, computer device, and storage medium

Embodiments of the present application provide a unified authentication system access method and device, computer equipment, storage medium and computer program product, and relate to the technical field of Internet. The method comprises the following steps: receiving a data access request triggered by an access user through a data access terminal, determining a target access platform corresponding to the data access request according to the data access request; if the user account of the access user meets the regional access permission and the platform access permission of the target access platform, initiating a proxy request for the data access request to the target access platform; the target access platform is used for obtaining a data providing package according to the proxy request, and returning the data providing package to an authentication server; receiving the data providing package sent by the target access platform, and sending the data providing package to the data access terminal; the data access terminal is used for analyzing and displaying the data providing package. The method improves the security and efficiency of data access.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Systems and methods for supporting UE authentication and security

Systems and methods for supporting UE authentication and security are provided. A wireless communication node may send a first message to an authentication server function (AUSF) to request authentication of a wireless communication device. The wireless communication node may receive a second message from the AUSF in response to the first message.
Owner:ZTE CORP

A method for implementing an identification-based authentication mechanism

The application belongs to the technical field of information security, and discloses a kind of based on identification authentication mechanism implementation method, including: after multi-dimensional identification server receives device authentication request, parsing device identification and calculating device public key, then interact with authentication center, carry out identity verification, after authentication center receives authentication request, the public key of device is calculated and the signature in request is verified using the public key, pass the verification, and the authorization code is generated and returned to the authentication server, and the server further forwards it to the device, and the returned signature information is verified by the device to ensure the validity of the authorization code.The application not only simplifies the management process of traditional public key infrastructure, but also improves the efficiency of the authentication process, each device only needs to generate a public-private key pair through its unique identification (EID), avoiding the complexity in traditional key distribution and certificate management, making device authentication more flexible and easy to expand.
Owner:NANJING UNIV OF POSTS & TELECOMM +1

Authentication system, method, client, server, device, medium, and product

Embodiments of the present disclosure disclose authentication system, method, client, server, device, medium, and product. The system comprising a client comprising a first storage, a resource server comprising a second storage, and an authentication server, wherein the client, configured to obtain an access token from the authentication server before determining to access the resource server, store the access token in the first storage, acquire the access token from the first storage when determining to access the resource server, generate a business request carrying the access token, and send the business request; the resource server, configured to obtain a public key from the authentication server before receiving the business request, store the public key in the second storage, receive the business request, acquire the public key from the second storage, and verify the access token based on the public key; the authentication server, configured to provide the access token and the public key. The business processing time of the client and resource server is saved, and the service availability is improved.
Owner:SIEMENS AG +1

Method, device and electronic equipment for identity authentication

The application discloses a kind of identity authentication method, device and electronic equipment.Therein, the method includes: sending key request to secure chip, receiving the first response information returned by secure chip, wherein the first response information at least includes: key;According to application identification, the session identification corresponding to this session is created, and the request for obtaining authentication key is initiated to quantum key management system;Determine the authentication key returned by quantum key management system, at least encrypt login authentication credential according to authentication key to generate login information ciphertext, and generate the message authentication code corresponding to login information ciphertext;Send login information ciphertext, message authentication code and session identification to identity authentication server;Receive the second response information returned by identity authentication server.The application solves the technical problem that the security is poor and data leakage is easy to cause in the related art based on the security verification mode of username and password.
Owner:CHINA TELECOM CORP LTD

Authenticating a device in a communication network of an automation installation

A method authenticates a device in a communication network. The method includes transmitting authentication information which indicates the device to an authentication server, which permits or rejects the device as a subscriber in the communication network on the basis of the authentication information. In order that an authentication of a device can also be carried out in a communication network configured with redundancy, the communication network contains two subnetworks. The device is connected to both subnetworks for redundant data transmission. At the start, the device sends authentication requests to access points arranged in the first subnetworks. The access points send the respective received authentication information to an authentication server, which authentication server in each case carries out a check of the authenticity of the device on the basis of the respective received authentication information and, as the result of the check, permits or rejects the device as a subscriber.
Owner:SIEMENS AG

Multi-factor user authentication

A system for multi-factor user authentication for payment card-based transactions are described. The multifactor authentication may be based on a one-time passcode / password (OTP) as sent by an authentication server. A user device may, based on receiving the OTP, send an authentication code. The authentication code may be generated / determined based on the OTP. The authentication code may be augmented biometric identifier (ID) of a user associated with the user device. The authentication server may validate a transaction based on the authentication code.
Owner:BANK OF AMERICA CORP

A method and apparatus for identity authentication

The application discloses an identity authentication method, which performs secret processing on identity information of a requesting device, prevents the identity information of the requesting device from being exposed in the transmission process, and ensures that an attacker cannot obtain private information of the requesting device. Moreover, by introducing an authentication server, while guaranteeing the confidentiality of entity identity related information, the application realizes real-time two-way identity authentication between the requesting device and an authentication access controller.
Owner:CHINA IWNCOMM

An offline identity authentication and key agreement method comprising biometric features

The application discloses an offline identity authentication and key negotiation method containing biological characteristics, and belongs to the technical field of shared resource network security. The method is completed by three parties of a user intelligent terminal device, an authentication server and a vehicle-mounted device, and contains user registration / vehicle initialization stage, user login / vehicle selection stage, user offline identity authentication and vehicle use stage, user vehicle return stage and user intelligent terminal loss and vehicle use stage. The main purpose of the application is to solve the problem that shared vehicles are scattered in different geographical spaces during use, leading to difficult management of physical vehicle keys. The core idea is to use the user's intelligent terminal as a key substitute for the shared vehicle, and through the introduction of biological characteristics, time stamps, random numbers and the like, the effects of preventing theft of the intelligent terminal attack, preventing replay attack, resisting key manipulation and the like can be achieved, so that the user experience and security are improved.
Owner:SHANDONG UNIV OF SCI & TECH

Electronic system and method for enabling payment of a good or service by means of voice commands

A method and system are disclosed for enabling payment of a good or service by means of voice commands. The method and system comprise a voice assistant, an electronic human language processor connected to the voice assistant, an application for delivering services to be paid connected to the electronic human language processor, an operative server device connected to the application for delivering services to be paid, a first authentication server device connected to the operative server device, a second authentication server device connected to the operative server device, a payment server device connected to the operative server device and an electronic device.
Owner:VOICEME SRL

Server authenticity verification using a chain of nested proofs

An identity management system may support an authentication server. According to techniques described herein, a client device may receive an authentication challenge from the authentication server. The authentication challenge may include an indication of a first public key of a first keypair, a first signature of a first private key of the first keypair, and second signatures of second private keys of second keypairs. The client device may determine whether the first public key is a trusted key that is pinned by the client device. The client device may determine, based on determining that the first public key is not the trusted key that is pinned by the client device, whether at least one signature of the second signatures can be validated by the trusted key. The client device may validate the authentication challenge based on determining that the at least one signature can be validated by the trusted key.
Owner:OKTA INC

AUTOMATED CLIENT PROVISION

The systems and methods disclosed herein are designed for a network to use virtual routing and forwarding (VRF) for tenant provisioning. The network may include a network device and an authentication server or service. The network device may submit an authentication request and a VRF request to the authentication server or service. The authentication server or service may return a VRF reference to the network device. The network device may also, on behalf of a tenant and as part of resource provisioning for the tenant, include the tenant in a VRF associated with the VRF reference.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Method and system for securing information exchange against ai-based network traffic by using client-side execution-based challenge-response mechanisms

A system and method for defending against AI-driven web traffic interference is provided. The system and method include: receiving, by an agent, a secret device ID and a web token provided by an authentication server; receiving an instruction to modify a request to a web service stored in a web server; embedding within a WebAssembly (WASM) component executed by the agent, a first portion of an encryption key and a second portion of the encryption key; transmitting the second portion of the encryption key to the authentication server; assembling, at runtime within the WASM component, an actual encryption key by combining the first portion and the second portion of the encryption key; encrypting, using the actual encryption key, the web token in the WASM component to generate a plurality of authentication tokens; and sending a request with the generated plurality of authentication tokens to the authentication server.
Owner:CO RADWARE LTD