Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

759 results about "Authentication server" patented technology

An authentication server provides a network service that applications use to authenticate the credentials, usually account names and passwords, of their users. When a client submits a valid set of credentials, it receives a cryptographic ticket that it can subsequently use to access various services.

Blockchain-based authentication system and method for authenticating electric vehicles or drones in a smart city

The present disclosure relates to a blockchain-based authentication system for electric vehicles and drones, and a method for authenticating electric vehicles or drones in a smart city. The proposed blockchain-based authentication system enhances security, privacy, and scalability for electric vehicles (EVs) and drones in smart city environments. It employs a consortium blockchain managed by city authorities and stakeholders, utilizing smart contracts for identity registration, credential issuance, and access control. Device nodes store cryptographic keys securely, while an optional authentication server facilitates off-chain integration. The authentication operation of the system includes, ensuring tamper-proof identity verification through on-chain validation. Authentication attempts are immutably recorded for auditing and anomaly detection. By eliminating single points of failure and strengthening data privacy, this decentralized authentication framework offers a scalable and secure solution for integrating EVs and drones into smart city infrastructures.
Owner:SHAQRA UNIV

Anti-quantum security identity authentication method, system, medium and equipment

The invention discloses an anti-quantum security identity authentication method and system, a medium and equipment. The method comprises the following steps: S1, a client, a service server and a key distribution center perform key configuration by adopting a digital signature algorithm; s2, the client sends an authentication request to the authentication server, and receives an authentication response with a bill granted bill returned by the authentication server; s3, the client sends a bill request to the bill issuing server, and receives a bill response with the service bill returned by the bill issuing server; s4, the client generates a client key exchange public key by adopting a first key exchange algorithm and sends an access request, the service server calculates a shared key and a ciphertext after receiving the public key, generates an access response comprising the ciphertext and identity information encrypted by using the shared key, and returns the access response to the client; and S5, the client receives the access response and obtains the shared key, and performs encrypted communication with the service server by using the shared key. The method has forward safe quantum attack resistance and strong identity authentication.
Owner:HAINAN HUAMI TECHNOLOGY CO LTD

Equipment access control method and system based on security sandbox

The invention discloses an equipment access control method and system based on a security sandbox, which adopts an advanced virtualization technology, constructs a highly isolated operation environment, combines technologies such as deep packet inspection, system call interception and process operation logic analysis, comprehensively monitors access behaviors of processes in the sandbox to virtual equipment, and improves the access performance of the virtual equipment. And the security and credibility of the equipment are evaluated, and illegal processes are prevented from running on the access terminal, so that the security access control of the equipment is realized. The monitoring comprises data packet content, protocol filtering, threat detection, system call interception, process creation, execution and termination behavior monitoring and the like. In combination with a trust evaluation algorithm, behavior data features are collected and extracted, trust scoring is performed by applying a machine learning model, and the equipment trust level and the access strategy are dynamically adjusted according to the score. According to the invention, the access control strategy is managed in a unified manner and deployed quickly based on the security sandbox management program and the authentication server. After identity authentication of the equipment, real-time monitoring of process dynamic behaviors in the running process of the equipment is added, and the safety of the equipment in the data exchange process is further improved.
Owner:DALIAN PUBLIC SECURITY BUREAU +1

High availability multi-tenant cloud based network access control system

A cloud-based architecture includes a cloud-based network management system (NMS) that provides the management plane and one or more cloud-based NAC systems that provide NAC services, including end-point device authentication. The cloud-based NAC system may have multiple groups of authentication server instances. Each group may have multiple authentication server instances to allow the authentication service provided by the group to serve more client devices than a single authentication server instance alone. Different Groups can be configured differently to serve different tenant sets.
Owner:JUNIPER NETWORKS INC

Anonymous Internet of Things identity authentication method and device based on anti-quantum computing password

The invention provides an anonymous Internet of Things identity authentication method and device based on an anti-quantum computing password. A key generation device sends a public key to a message sending end and a message receiving end, and sends a private key to an authentication server; the authentication server generates a blind parameter based on the private key, and sends the blind parameter to the message sending end; the message sending end performs blind operation based on the blind parameter, the public key and the to-be-transmitted message to obtain a blind message, and sends the blind message to the authentication server; the authentication server performs post-quantum signature on the blind message based on the private key to obtain a to-be-solved blind signature, and sends the to-be-solved blind signature to the message sending end; the message sending end carries out blind resolution operation on the to-be-resolved blind signature to obtain a target signature; the message sending end sends the to-be-transmitted message and the target signature to a message receiving end; and the message receiving end performs post-quantum verification on the target signature based on the public key, and if verification succeeds, processing is performed based on the to-be-transmitted message. Through the scheme of the invention, the user data security can be improved.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Network initiated primary authentication

Various aspects of the present disclosure relate to an authentication server function (AUSF) that receives an authentication request from a security anchor function (SEAF), and transmits a data request for authentication data to unified data management (UDM). The AUSF can receive the authentication data from the UDM for primary authentication, and set an expiration time for security information associated with the primary authentication being successful. The AUSF can then transmit an authentication message of authentication information that includes the security information and the expiration time to an authentication and key management for applications (AKMA) anchor function (AAnF) that registers the expiration time. The AUSF can also initiate reauthentication based at least in part on expiry of the authentication information.
Owner:LENOVO (SINGAPORE) PTE LTD

Using hallucinations from generative ai for challenge-response in secure access

Techniques leveraging hallucinations from generative AI for challenge-response in secure access are described and may be performed at least in part by a generative AI engine. An indication of a memorable event associated with a user is received. Time series sensor data associated with the user for a period of time associated with the memorable event is received from a time series database. Parameters for determining one or more plausible events that are similar to the memorable event are received by an authentication server. The parameters include a level of hallucination for generating the one or more plausible events. One or more plausible events are generated based at least in part on the memorable event, the time series sensor data, and the parameters. A challenge and response to be used as a challenge-response authentication from the user to access a network resource is generated and transmitted to the authentication server.
Owner:CISCO TECHNOLOGY INC

Application login method and system

This application provides an application login method and system, and relates to the field of communication technologies. The system includes a first electronic device and a second electronic device. A cellular communication function of the second electronic device is available. The first electronic device is configured to: display a login interface after an application to be logged in to is started, where the login interface includes a second control, the second control is used to provide a first login manner, and the first login manner is obtaining login information from an authentication server by using the cellular communication function of the second electronic device, to log in to the application based on the login information; and log in to the application in the first login manner after an operation performed by a user on the second control is detected. According to the application login system in embodiments of this application, after detecting the operation performed by the user on the second control, the first electronic device may log in to the application by using the cellular communication function of the second electronic device. This is easy for the user to operate and provides good user experience.
Owner:HUAWEI TECH CO LTD

Security authentication method and device, computer equipment, readable storage medium and program product

The invention relates to a security authentication method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: receiving a key generation request sent by target equipment; if it is determined that the key generation request is legal, generating a trust identifier and a security certificate of the target device, obtaining an identifier verification request through the trust identifier, and sending the identifier verification request to an authentication server, so that the authentication server verifies the trust identifier to obtain an access token corresponding to the target device; receiving a message returned by the authentication server, and processing an access token carried by the message to obtain a trust identifier; and writing the security certificate into the target protection area, and sending the trust identifier and the security certificate to the target equipment, so that the target equipment is registered in the authentication server. By adopting the method, the identity verification of the equipment and the control of an encryption communication mechanism are realized, and the safety protection performance in a communication system is further improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Artwork remote authentication system

Apparatus and associated methods relate to an artwork authenticity owner validation system. In an illustrative example, an artwork remote identification system (ARIS) may include an artwork companion chip (ACC) and a certificate of authenticity (COA). The ACC, for example, may be physically attached to an artwork. The ACC and the COA, for example, may each include a unique identifier. For example, a centralized server may be configured to automatically authenticate an ownership of the artwork attached to the ACC by validating the ACC and the COA. For example, the user may scan the COA and then the ACC within a predetermined time limit to gain access to modify an ownership record in an artwork profile of the artwork. Various embodiments may advantageously allow a modification to the ownership information only when the centralized authentication server validates the COA and the ACC within the predetermined time period.
Owner:BLAIR PRESTON

Identity authentication method and system based on block chain

The invention discloses an identity authentication method and system based on a block chain, and particularly relates to the technical field of identity authentication security. Comprising the steps of S01, user login request verification, S02, user identity detection enhancement verification, S03, user identity authentication abnormity control, S04, user access security assessment data acquisition, S05, user access security analysis and S06, user access security assessment. The face recognition confidence, the iris matching degree and the user face video stream are collected on the user login page, the user identity compliance is verified, the safety of identity verification is improved, the authentication accuracy is improved, the safety evaluation data of the authentication server in the block chain network are collected, the user authentication access risk evaluation coefficient is calculated, and the user authentication access risk evaluation efficiency is improved. And the server authentication access risk is monitored, so that the change of the server authentication access risk can be monitored in real time, the occurrence of security events is effectively prevented, and the user information management efficiency is improved.
Owner:HEZHENG TECHNOLOGY (YUNNAN) CO LTD

Extending EAP for supporting generative ai challenges

Techniques for extending EAP for supporting generative AI challenge-response for secure access are described. The techniques may be performed at least in part by an authentication server. An indication of a request for a user account to access the network resource via a user device is received. A determination that the user device supports generative AI challenge-response authentication id determined. A posture of the user device is determined. Based at least in part on the device posture, parameters for generating a generative AI challenge-response are determined. The parameters include at least one of a level of hallucination for, and a type of, challenge response to generate, and are transmitted to a generative AI engine. The generative AI challenge-response is received from the generative AI engine and caused to be output by the user device.
Owner:CISCO TECHNOLOGY INC

Authentication management method for non-3GPP access of a UE device to a 5G network

A core network server for defining authentication credentials and authenticating a wireless communication device according to WIFI communication protocols includes a central processing unit (CPU) and a non-transitory memory comprising executable instructions that when executed by the CPU, causes the core network server to receive an encrypted authentication request from a wireless communication device; send the encrypted authentication request to an authentication server based on one or more attributes in the encrypted authentication request; receive an indicator of a specialized network slice associated with the wireless communication device based on sending the encrypted authentication request; communicate authentication messages to the wireless communication device according to one or more network functions of the specialized network slice; and authenticate the wireless communication device according to the specialized network slice responsive to communicating the authentication messages.
Owner:T MOBILE INNOVATIONS LLC

Unmanned aerial vehicle cluster authentication method based on certificateless homomorphic network coding signature

The invention discloses an unmanned aerial vehicle cluster authentication method based on a certificateless homomorphic network coding signature, and belongs to the field of cryptography and network security. In an unmanned aerial vehicle network system comprising a KGC, a source node, an intermediate node and an authentication server CS, the following steps are executed: the KGC generates system parameters and a master key; the source node registers to the KGC and requests part of private keys; the source node carries out vector splitting and expansion on the authentication message, randomly selects a message identifier, executes a signature algorithm to respectively calculate the signature of each vector, and sends the vectors and the signatures to the intermediate node; and the intermediate node executes a verification algorithm to judge the validity of the currently received data packet, discards the invalid data packet, calculates to obtain a signature of the combined vector, and forwards the signature to the adjacent intermediate node. When the CS obtains a sufficient number of valid data packets, the original authentication message can be recovered and an authentication success message is sent to the source node unmanned aerial vehicle. According to the invention, the transmission performance and reliability of the unmanned aerial vehicle network are improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Systems and methods for secure user authentication with passkeys on shared computing devices

Embodiments described herein provide systems and methods for secure and efficient user authentication across a variety of computing devices, such as desktops, laptops, smartphones, and tablets across operating systems such as Windows, MacOS, IOS, Android, and iPadOS. The system incorporates an authenticator application configured to communicate with internal or external user identifier scanners, such as RFID / NFC readers, fingerprint scanners, facial recognition cameras, and QR / Barcode scanners, using transport protocols like USB, BLE, or NFC. The authenticator application serves as a third-party passkey provider by interfacing with platform WebAuthn APIs, enabling WebAuthn-based authentication for native applications, browsers, and services, or alternatively as a browser extension, intercepting WebAuthn API calls directly within a browser environment. An authentication server, accessible over a network, verifies user identities by mapping unique identifiers to stored authenticators and requesting additional authentication factors as needed, such as a security PIN. Upon successful authentication, the server transmits passkeys and a session token to the authenticator application, enabling it to handle further authentication requests locally. The system supports advanced session management for shared device environments, allowing configurable passkey storage with options for one-time, time-based, or shift-based expiration, automatically clearing passkeys upon session completion. This design delivers a versatile, secure, and seamless authentication experience across diverse user environments.
Owner:IDMELON TECH INC

ESIM card changing method and related equipment

The embodiment of the invention discloses an embedded subscriber identity module (eSIM) card changing method and related equipment, and the method comprises the steps that an authentication server receives a first card changing request sent by terminal equipment, and the first card changing request comprises a user account, a password, a user number and an eUICC chip identifier; verifying the user identity of the terminal equipment according to the user account and the password; and if the verification is passed, a second card changing request is sent to an operator service support system (BSS), the second card changing request comprises the user number and the eUICC chip identifier, the second card changing request is used for indicating the BSS to complete eSIM card changing, and an eSIM server is notified to generate an eSIM configuration file and associate the eSIM configuration file with the eUICC chip identifier. By adopting the embodiment of the invention, the eSIM card changing process is simplified, and the eSIM card changing efficiency is improved.
Owner:HUAWEI TECH CO LTD

Systems and methods for performing digital authentication

A system for digital authentication may include an authentication server. The system may be configured to receive a login request from a user device associated with a user. The login request may include a user identity data element and a login request data element. The system may be configured to retrieve, based on the login request, a supplemental data element associated with the user from a recording server and determine whether the login request data element matches the supplemental data element and in response to a determination that the login request data element matches the supplemental data element: perform an authentication on the user device; configure the user device as authenticated in response to the authentication; and in response to configure the user device as authenticated: configure a first login mode as an authenticated status; and configure a second login mode as the authenticated status.
Owner:PNC FINANCIAL SERVICES GROUP INC

Microservice system interface authority management and authentication method and related device

The invention provides a micro-service system interface authority management and authentication method and a related device, and belongs to the technical field of software engineering. According to the method, a micro-service plug-in is deployed at each micro-service node, the micro-service plug-in automatically collects interface information of a micro-service system and permission description information corresponding to the interface information, and the interface information of the micro-service system and the permission description information corresponding to the interface information are synchronized to all API gateway nodes through a Nacos configuration management center; starting a role permission configuration server, performing unified management on interface permission information, user role information and permission configuration information of the micro-service system in the role permission configuration server, and performing unified distribution on users, roles and permissions; and starting the single-point authentication server, and verifying the user identity in the single-point authentication server. According to the invention, the problem of low integration efficiency of the micro-service system is solved.
Owner:XIAN TPRI POWER PLANT INFORMATION TECHNOLOGY CO LTD +1

Computing systems and methods for provisioning privacy-preserving identity-bound passkeys and digital signatures

Systems and methods are provided that allows users to execute a secure digital action that is authenticated by their digital wallet app (or wallet) on a user device or a wallet server. An identity issuer server issues a batch of verification credentials (VCs) for an identity holder to the wallet. The wallet stores the batch of VCs, respectively binds each VC in the batch of VCs with a given passkey from a plurality of passkeys, generates selective disclosures via a content generator server, and transmits the batch of VCs, as a plurality of VC presentations, to an identity verification server. An identity verification server requests and validates the plurality of VC presentations, and, responsive to validating the plurality of VC presentations, registers the plurality of device-bound passkeys respectively bound to the batch of VCs to generate a plurality of registered passkeys. In a secure digital action, after generating the plurality of registered passkeys, the identity verification server is further configured to authenticate the identity holder using one or more of the registered passkeys.
Owner:LOGIN ID INC

Computer-implemented system and method for managing authentication between user device and authentication server using private-public key cryptography

A computer-implemented method and system for managing an authentication between user devices and authentication servers, is disclosed. The computer-implemented method includes: obtaining user credentials associated with users; retrieving information associated with device fingerprints corresponding to the user devices; generating cipher messages by at least one of: creating random numbers and encrypting the random numbers with keys derived from at least one of: the first and second index; transmitting the one or more user identities, the first index, the second index, and the cipher messages, to authentication servers; dynamically generating the private keys from private key variables; generating authentication responses by decoding authentication based questions obtained from the authentication servers, using cipher messages and the private keys; and transmitting the authentication responses to the authentication servers for adapting the authentication servers to authenticate the user devices.
Owner:HAWCX INC

System and method for multi-factor authentication

A system and method for authentication a user attempting access to a service is disclosed herein. When a user attempts to gain access, a client associated with the user generates a unique authentication code that is stored at a callback server associated with the client. The user accesses an authentication server associated with the service and provides the authentication server with standard login credentials. The authentication server also obtains the authentication code from the user. If the authentication server successfully verifies the user's credentials, then the authentication server transmits a code validation request to the callback server to validate the authentication code. The callback server verifies that the received code matches a stored code and is current, and then issues a reply message to the authentication server. The authentication server grants or denies the user's access request based on the reply.
Owner:CAPITAL ONE SERVICES LLC

Terminal device, authentication server, authentication method, and non-transitory computer readable storage medium

A terminal device according to the present application includes a sending unit that sends a challenge to an authenticator, a reception unit that receives the challenge with a signature and a public key from the authenticator, a verification unit that performs signature verification using the public key, and a providing unit that provides a verification result of the signature to an authentication server. Further, an authentication server according to the present application includes a sending unit that makes an authentication request to a terminal device, an acquisition unit that receives, from the terminal device, a verification result of a signature generated by an authenticator together with an ID and a password of a user, and a verification unit that determines that FIDO authentication is completed with the verification result of the signature, and verifies the ID and the password of the user.
Owner:YAHOO JAPAN CORP

Authentication server, authentication system, control method of authentication server, and storage medium

An authentication server includes a user registration unit, a service registration unit, and a storage unit. The user registration unit acquires a first ID that uniquely determines a user in a system and first biological information that is used for authentication of the user. The service registration unit processes a service registration request that is transmitted from a service provider of a service that the user wishes to use and that includes the first ID and a second ID that identifies the service provider. The service registration unit generates a third ID that is uniquely determined by a combination of the user and the service provider and transmits the third ID to the service provider. The storage unit stores the first biological information, the first ID, the second ID, and the third ID in association with each other.
Owner:NEC CORP

USB key identity authentication method, system and device based on digital signature trusted chain and medium

The invention discloses a USB key identity authentication method, system and device based on a digital signature trusted chain and a medium, and belongs to the technical field of information security, and the method comprises the following steps: after a receiving terminal accesses a USB key, reading a digital certificate, collecting a device identifier, a network parameter and geographical location information, generating first environment abstract data through abstract processing, and signing; and the authentication server stores the abstract data after passing the signature verification. In the authentication request stage, the server generates random challenge data; the receiving terminal collects the current environment information to generate second environment abstract data, and the second environment abstract data is signed and sent again after being combined with the challenge data. And the server extracts the second abstract data after signature verification, performs similarity comparison with the first abstract data, and confirms that the identity authentication is valid when conditions are met. According to the method, the binding of the environment characteristics and the identity is realized, the protection capability of the U-type shield authentication system on counterfeiting, cloning and replay attacks is remarkably improved, and the credibility and the stability of an authentication result are enhanced.
Owner:YUNNAN POWER GRID CO LTD

Portal system personalized configuration method, system, equipment and medium

The invention discloses a portal system personalized configuration method, system, equipment and medium, and belongs to the technical field of portal systems. The personalized configuration method is applied to a front end and comprises the following steps: in response to a login request of a user, sending an identity authentication request to an identity authentication server; receiving a token returned by the identity authentication server; carrying the token to initiate a request for acquiring user page configuration information to a configuration information management server, so that the configuration information management server returns the user page configuration information to a front end; performing page rendering according to the user page configuration information; carrying the token to initiate a request for acquiring user data loading information to the data server, so that the data server returns the user data loading information to the front end; and displaying the user data loading information in the corresponding page component. Page rendering is performed based on the user page configuration information exclusive to the user, and personalized interface styles and functional layouts can be provided for different users and different tenants.
Owner:AVIC GOLD NETWORK (BEIJING) TECHNOLOGY CO LTD

Method and apparatus for service discovery

Embodiments of the present disclosure provide methods and apparatuses for service discovery. The method comprises determining to initiate an authentication of a user equipment (UE); and sending an authentication request message including an encrypted or unencrypted identity of a subscriber of the UE, a serving network name and routing information of a data management node to an authentication server.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

System and method for authenticating user of robotaxi

An embodiment system for authenticating a user of a robotaxi includes an authentication server and a robotaxi. The authentication server configured to create a first authentication number, transmit the first authentication number to a smart phone the user, receive a second authentication number from the robotaxi when authenticating the user using a digital key fails, and request unlocking of a door to the robotaxi when the first authentication number and the second authentication number match. The robotaxi configured to receive the second authentication number from the user, transmit the second authentication number to the authentication server, and unlock the door in response to the request from the authentication server.
Owner:HYUNDAI MOTOR CO LTD +1

Single sign-on control method and device, electronic equipment and storage medium

The invention provides a single sign-on control method and device, electronic equipment and a storage medium, and is applied to an authentication server, and the method comprises the steps: obtaining and verifying user login information through responding to a login request of a user for a main client, generating an access token, and returning the access token to the main client; when the user uses the access token to access the service system, verifying the validity and granting authority; after the user successfully logs in, if a request for accessing the sub-client is detected, a temporary authorization code is generated, and the main client jumps to the sub-client; and after the authorization code is verified, the corresponding user identity information is analyzed and returned to the sub-client. According to the method, unified authentication and session control of multiple data sources and multiple clients can be supported, and cross-system password-free login and session synchronous logout can be realized on the premise of ensuring security, so that the user experience is improved, the system integration cost is reduced, and the overall security is enhanced.
Owner:北京领雁科技股份有限公司

Communication method and communication apparatus

This application provides a communication method and a communication apparatus. The method includes: An authentication server function receives an authentication request message of a terminal device, where the authentication request message includes a subscription concealed identifier of the terminal device. The authentication server function sends a first request message to a unified data management function based on the authentication request message, where the first request message is used to obtain a subscription permanent identifier of the terminal device, and the first request message carries a certificate of the UE or carries information in the certificate of the UE. The authentication server function receives a response message from the unified data management function, where the response message includes the subscription permanent identifier corresponding to the information in the certificate of the terminal device. The authentication server function determines a security anchor function key based on the subscription permanent identifier.
Owner:HUAWEI TECH CO LTD

Secure generation of one-time passcodes using a contactless card

Systems, methods, apparatuses, and computer-readable media for secure generation of one-time passcodes using a contactless card. In one example, an operating system (OS) of a device may receive a uniform resource locator (URL) and a cryptogram from a contactless card. The OS may launch an application associated with the URL. The application may transmit the cryptogram to an authentication server. The application may receive a decryption result from the authentication server indicating the authentication server decrypted the cryptogram. Based on the decryption result, the application may request an OTP. The processor may receive an OTP from an OTP generator. The application may receive an input value and compare the input value to a copy of the OTP. The application may determine that the comparison results in a match, and display, based on the determination that the comparison results in the match, one or more attributes of the account.
Owner:CAPITAL ONE SERVICES LLC