Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Authorization Mode" patented technology

Change the authentication mode to Windows. Windows Authentication mode provides the developer to authenticate a user based on Windows user accounts. This is the default authentication mode provided by ASP.Net. You can easily get the Identity of the user by using User.Identity.Name.

Multi-domain, multi-tenant authentication method, system and medium based on distributed structure

The application provides a multi-network domain and multi-tenant authentication method and system based on a distributed structure, and a medium. The method comprises the following steps: respectively deploying controller clusters in different network domains, wherein the controller cluster comprises a controller pool and a plurality of controllers, and the controller pool provides tenant request proxy services for the plurality of controllers; deploying a control center in an area in network communication with each network domain, wherein the controller pool provides access proxy services for the corresponding plurality of controllers to the control center; in response to the controller cluster receiving a tenant request, the controller pool forwards the tenant request to the corresponding controller, the controller generates login information, and accesses the control center through the pushing of the controller pool to perform authentication. The application realizes permission isolation and mutual trust and authentication between self-defined differentiated multi-network domain and multi-tenant, and improves the flexibility and adaptability of the authentication and authorization mode.
Owner:XIAMEN ANSCEN NETWORK TECH CO LTD

Authority management method and system for equipment flash, chip and intelligent terminal

The invention discloses an authority management method and system for equipment flashing, a chip and an intelligent terminal.The method comprises the steps that when an authorization mode for equipment flashing is a quick start authorization mode, a boot loader is started; the client application initiates a first authorization authentication request via the first trusted execution environment client interface; the trusted execution environment core driver receives the first authorization authentication request and switches the operating environment of the processor from a common world to a secure world; the trusted operating system receives and analyzes the first authorization authentication request, and schedules an early trusted application to obtain equipment fingerprint information from the first storage partition; when the equipment fingerprint information passes verification, modifying the first authorization mark, and correspondingly modifying the second authorization mark stored in the second storage partition; and the intelligent terminal is switched into the factory mode. According to the method and the device, the original flashing port can be controllably opened, so that the risk of illegal flashing is avoided, and meanwhile, legal flashing operation is guaranteed.
Owner:SHANGHAI SUMI TECH CO LTD +1

A method and system for visitor self-service door opening of an intelligent lock

This specification provides one or more embodiments of a method and system for self-service visitor unlocking of a smart lock. The method includes: responding to a visitor's access operation by sending an authorization request corresponding to the access operation to a terminal; receiving authorization information from the terminal, the authorization information including an authorization method; if it is determined that the authorization method instructs unlocking based on a password set by the visitor, then performing a password setting operation to obtain the unlock password entered by the visitor and the visitor's facial information; binding the unlock password, the facial information, and the authorization information, and recording them in a personnel information table. This enhances security and traceability, avoiding the problems of easily forgotten and leaked passwords in existing technologies.
Owner:HANGZHOU DIANZI UNIV +2

Image forming apparatus

The present invention provides an image processing device, etc., that can reduce the risk of the approval process being hindered due to the applicable approval method. [Solution] The authorization server comprises a control unit capable of performing authorization processing using multiple authorization methods, a storage unit for storing connection information to the authorization server, and an output unit for outputting screen information related to the authorization processing. When the user selects the authorization processing based on one authorization method using the connection information, the control unit determines whether the authorization server supports that authorization method. If the authorization server determines that it does not support the authorization method, it restricts the execution of the authorization processing using that authorization method. The output unit outputs a notification prompting the user to select an authorization method different from the authorization method.
Owner:SHARP KK

FDEP interaction system and method based on double-authorization mode

PendingCN121037358ATransmissionAuthorization ModeEngineering
The invention provides an FDEP interaction method and system based on a dual-authorization mode. The method comprises the following steps: realizing dual-authorization account data transmission between a fund sales end and a trusteeship bank end through an FDEP transmission mode; in the data sending process, a file repushing mechanism and a file polling mechanism are configured; the file repushing mechanism comprises the steps that when file transmission is interrupted, a transmitted progress point is recorded, and after connection is recovered, the remaining part is automatically transmitted from the interruption point; or when an abnormal condition including transmission failure or reception refusal of the receiving end is detected, automatically triggering a re-pushing process according to a preset rule; the file polling mechanism comprises the steps that high-throughput transmission is achieved through scanning and dynamic load balancing, and low-delay and high-reliability file exchange service of the fund sales end and the trusteeship bank end is achieved in combination with failover and priority control.
Owner:上海秉玉软件技术服务有限公司

Authorization authentication method and device, equipment and storage medium

PendingCN121125289AUser identity/authority verificationTicketAuthorization Mode
The invention discloses an authorization authentication method, device and equipment and a storage medium, a distributed authorization mode is adopted, a Redis cache is taken as a core support, an authority strategy and bill metadata are uniformly stored in a Redis cluster, each node can directly read the Redis cache to independently complete authority verification and authorization decision, and dependence on concentrated nodes is not needed. And meanwhile, real-time synchronization and consistent updating of the authority data in the nodes of the whole network are ensured by relying on a master-slave synchronization and persistence mechanism of Redis. Even if part of the nodes fail or are attacked, other nodes can still obtain complete permission information through the Redis cache to operate normally, and the risk of system paralysis or permission out-of-control caused by a single-point problem is effectively reduced.
Owner:SHENZHEN COMTOP INFORMATION TECH

Client-free single packet authorization system and method with active trapping function

PendingCN121367914ASecurity arrangementSecuring communicationAuthorization ModeEngineering
The invention discloses a client-free single packet authorization system and method with an active trapping function. The system comprises an authentication subsystem, an SPA gateway, a firewall and a honeypot. In an initial state, the firewall prohibits an external terminal from accessing all business systems in the firewall, and the authentication subsystem is deployed outside the firewall and issues an authentication service IP, an authentication service port and a trapping port function port to the outside; the external terminal firstly logs in the authentication subsystem to access the service system, and the SPA gateway dynamically adjusts the firewall strategy according to the authentication condition; opening a honeypot system IP and a port for a terminal which does not pass SPA knock packet verification; and after the cumulative time of no access request of the terminal exceeds the time limit, the firewall automatically closes the opened IP and port. By adopting the method, malicious scanning is easy to find, and the traceability countering capability is greatly improved; the method has the convenience of a client-free single packet authorization mode and the universality of a client single packet authorization mode.
Owner:HUANENG POWER INT INC +1

A dynamic renewal system and method for non-permanent term permissions

PendingCN122365530AAuthorization ModeVerification
This invention discloses a dynamic renewal system and method for permissions without fixed time limits, relating to the field of permission management technology. The system includes a business gateway, a permission database, a renewal decision engine, and an approval adaptation module. The business gateway is communicatively connected to the permission database, the renewal decision engine, and the approval adaptation module, respectively. The renewal decision engine is communicatively connected to the approval adaptation module. This system replaces the traditional static authorization mode by establishing dynamic renewal and continuous verification triggered upon access for permissions without fixed time limits. It can trigger risk assessment and status control of permissions in real time based on user access behavior, ensuring that permission status dynamically matches the user's actual business access needs. This fundamentally avoids the problem of permission drift leading to ghost accounts, achieving precise adaptation between business permissions and actual needs. It prevents the long-term disconnect between permissions and business needs in the traditional mode, making permission management closely aligned with actual business usage scenarios.
Owner:SHANGHAI BEIRUI INFORMATION TECH CO LTD

Authentication model construction method and device, task processing method and device

ActiveCN116170438BSecuring communicationAuthorization ModeTrust level
The embodiment of the present specification provides an authentication model construction method and device, a task processing method and device. The authentication model construction method comprises determining a distributed call link corresponding to a target service; analyzing the distributed call link to determine an authentication and authorization mode of a service node in the distributed call link and an association relationship between the service nodes; and constructing an authentication and authorization model of the distributed call link according to the authentication and authorization mode of the service node and the association relationship between the service nodes. The method analyzes the distributed call link corresponding to the target service, determines the authentication and authorization mode of each service node in the distributed call link, and according to the association relationship between each service node and other service nodes, an authentication and authorization model with a directed acyclic structure is made. Subsequently, the authentication and authorization model can be used to form a trusted level security authentication of the service link, and the security of the service is systematically improved.
Owner:ZHEJIANG E COMMERCE BANK CO LTD

Dynamic access control method and device based on multi-dimensional fusion analysis

The invention relates to the technical field of high-level information security and secrecy, in particular to a dynamic access control method and device based on multi-dimensional fusion analysis. The method comprises the following steps: receiving a computer access event, extracting a source IP address and an inherent risk score, matching a user ID based on the source IP address, and taking a user corresponding to the user ID as a target user; acquiring a plurality of original events associated with the user ID, and performing fusion analysis on the plurality of original events to generate a physical confidence coefficient; performing behavior analysis on the computer access event to obtain a behavior matching degree conforming to the normal behavior of the target user; bayesian fusion reasoning is carried out on the inherent risk score, the physical confidence degree and the behavior matching degree, and the dynamic credibility of the target user making the normal behavior at the correct position is obtained; and generating and executing an access control instruction according to a comparison result of the dynamic credibility and a trust threshold. The method can ensure that the authority moves along with the personnel, and eliminates the contradiction between a static authorization mode and dynamic physical reality.
Owner:WUHAN GREENET INFORMATION SERVICE

Authorization license detection method and system applied to industrial host software

The invention relates to the technical field of industrial host software, and provides an authorization permission detection method applied to industrial host software, which comprises the following steps: S1, finishing authorization system deployment on a host running the industrial software; s2, when the industrial software is triggered to run according to a preset time interval, the industrial software calls an authorization SDK interface function to initiate an authorization state verification request and an authorization SDK packaging request and then transmits the authorization state verification request and the authorization SDK packaging request to a kernel layer drive program; s3, the driving program calls a process protection module to detect the safety of a software operation environment, initiates an encryption calling request to the safety encryption hardware through the USB bus after confirming that no abnormity exists, and then returns a result to the driving program; s4, the drive program transmits the encryption result to the authorization SDK in a transparent manner, the SDK decrypts the encryption result to obtain a plaintext result and feeds the plaintext result back to the industrial software for operation, and the industrial software modifies an internal authorization flag bit according to the result; and S5, safety monitoring and connection verification are maintained in the whole detection process. The problem that a traditional industrial software authorization mode is prone to being counterfeited or cracked is solved.
Owner:SUPCON TECH CO LTD

User identity authentication method, device, equipment, medium and program product

PendingCN121508905AUser identity/authority verificationAuthorization ModeInternet privacy
The invention discloses a user identity authentication method, device and equipment, a medium and a program product. An authentication server side receives a user identity authentication request and user data sent by a service side; wherein the user data comprises equipment fingerprint information, network environment information, user behavior information and WebAuthn information; in response to the user identity authentication request, performing risk assessment according to the user data, and generating a risk assessment result; generating a corresponding user identity authentication strategy according to the risk assessment result; wherein the user identity authentication strategy comprises a user authorization mode and whether WebAuthn verification is carried out or not; and performing user identity authentication according to the user identity authentication strategy. According to the invention, through multi-dimensional risk assessment and dynamic selection of the matched user identity authentication strategy, the contradiction between security defense flexibility and user experience is solved, and the security of overall authentication and the user experience are improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Intelligent anti-photographing monitoring, blocking and terminal security sensing system

The invention discloses an intelligent anti-photographing monitoring, blocking and terminal security sensing system, which comprises the following modules: a camera authorization and watermark control module, which is used for configuring a camera use authorization mode and desktop watermark prompt information display according to a security policy; the environment image acquisition and mode selection module is used for acquiring image data of the surrounding environment of the display screen of the terminal and selecting an identification mode; the AI behavior recognition engine module is used for extracting visual features, positioning shooting related equipment and generating shooting behavior judgment data and abnormal behavior confirmation data; the abnormal behavior handling module is used for executing handling operation when an abnormal behavior is detected; and the unlocking control and security audit module is used for unlocking the terminal after the exception is eliminated and generating an audit log and alarm information. According to the invention, an integrated processing flow of intelligent sensing, active blocking and safety auditing for preventing the photographing risk of the terminal is realized.
Owner:JIANGSU AGILE TECH CO LTD

Authorization method, device, non-volatile storage medium and electronic device

ActiveCN119814448BSecuring communicationVirtualizationAuthorization Mode
This application discloses an authorization method, apparatus, non-volatile storage medium, and electronic device. The method includes: obtaining a unique identifier for an authorization service container in a private network, wherein the authorization service container includes an authorization service instance to be authorized and verified; generating an authorization file based on the unique identifier and configuration information of the target object; encrypting the authorization file; and sending the encrypted authorization file to the authorization service container, wherein the authorization service instance reads and verifies the authorization file, and activates the authorization service instance if the authorization file verification is successful. This application solves the technical problem that traditional authorization methods, which rely on hardware information such as media access control addresses for verification, cannot perform authorization verification in a virtualized environment.
Owner:CHINA TELECOM ARTIFICIAL INTELLIGENCE TECHNOLOGY (BEIJING) CO LTD

Password authorization mode improvement method and system based on big data and intelligent algorithm

The application provides a password authorization mode improvement method and system based on big data and intelligent algorithms, relates to the technical field of big data, and comprises the following steps: extracting a behavior characteristic sequence of an object to be authorized, performing time sequence correlation analysis by using a dynamic trust evaluation model to obtain a trust measurement value, and generating a temporary authorization voucher bound with an identity label according to the trust measurement value. In the access process, the behavior deviation is compared in real time, and when the deviation exceeds the limit, the model is fed back to update the weight and the key strength is adaptively adjusted. The application realizes the dynamic and intelligent of the authorization process, and improves the security and adaptability of the access control.
Owner:BEIJING ZBX SOFTWARE TECH CO LTD

Cerebral disease prevention information pushing system

PendingCN121690678APsychotechnic devicesSensorsData streamAuthorization Mode
The invention discloses a brain disease prevention information pushing system, and relates to the technical field of medical health information, and the system comprises the following steps: S1, collecting authorization; s2, the data flow direction is visible; s3, the user autonomously sets the authority; s4, setting data privacy; s5, evaluating a result; and S6, emotion monitoring. According to the brain disease prevention information pushing system, data transmission lines and destination node types are clearly presented in a visual mode, and in combination with line new and old distinguishing and node safety level marking, a user visually masters the data flow direction and eliminates authorized data destination blind areas; a differential authorization rule is set according to a historical security record of a destination node, a user is supported to flexibly adjust an authorization mode, data transmission of a low-security node is defaulted and limited, and the user is endowed with an absolute control right for data transmission; unique sensitive information such as an identity card number and a photo is encrypted, privacy security in the data storage and transmission process is ensured, and the risk of sensitive information leakage is avoided.
Owner:SUZHOU KUYUE NETWORK TECH CO LTD

Enforcing conditional access to network services based on authorization statuses associated with network flows

PendingUS20250373582A1Securing communicationAuthorization ModeConditional access
This disclosure describes techniques for enforcing conditional access to network services. In an example method, a first computing device detects a second device operating in a per-flow authorization mode. The first device receives a first request from a second computing device to communicate with a third computing device using a first network flow and determines that the first flow is authorized (e.g., because of an active past authentication and / or the third device's authentication exemption). Data associated with the first request is transmitted to the third device. The first device then receives a second request to communicate with a fourth computing device using a second network flow and determines that the second flow is not authorized (e.g., because it is not associated with an active past authentication and / or the fourth device is not exempt from authentication). Data associated with the second request is not transmitted to the fourth device.
Owner:CISCO TECHNOLOGY INC

Authorization methods, apparatuses, computing devices, and storage media

ActiveCN115733690BAuthorization ModeData acquisition
The application discloses an authorization method and device, a computing device and a storage medium. The method comprises the following steps: assigning, to a user in a first application, identification information required by the user for using a second application; receiving a target data acquisition request initiated by the second application; the target data acquisition request comprises to-be-verified identification information and application information of the second application; verifying whether a binding relationship exists between the to-be-verified identification information and the application information of the second application; and if it is verified that the binding relationship exists, authorizing the second application to use target data in the first application. In the above manner, the authorization method is easy to implement and has low development difficulty, and the time for verifying application permissions can be saved.
Owner:SHANGHAI BILIBILI TECH CO LTD

Digital asset protection method, device, equipment, medium and product

PendingCN122020683ADigital data protectionSecuring communicationAuthorization ModeMetadata
The invention discloses a digital asset protection method and device, equipment, a medium and a product, and the method comprises the steps: obtaining authorization metadata corresponding to a target digital asset based on a mixed authorization mode which is an authorization mode combining a physical lock with soft authorization; the target resource in the authorization metadata is verified; and if the verification is passed, loading the target digital assets in a target loading mode. According to the invention, through the authorization mode of combining the physical lock and the soft authorization, the flexible adjustment of the authorization strategy is realized, the business change can be responded without replacing the hardware, and the flexibility of authorization management is greatly improved while the safety base line is ensured.
Owner:IFLYTEK CO LTD +1

Feed flow mixed diffusion method and device based on railway CMS derivative application scenarios

The application relates to a Feed flow mixed diffusion method and device based on a railway CMS derivative application scene, and the method comprises the following steps: acquiring a multi-level authorization information storage structure, wherein the multi-level authorization information storage structure comprises a user table, a unit table, a Feed table and a column table; generating a diffusion mode judgment rule based on the column table and a user activity model; performing composite authorization calculation on a Feed flow source according to the multi-level authorization information storage structure and the diffusion mode judgment rule, and performing aggregation calculation on the result of the first authorization calculation to generate a Feed flow weighting table of authorized source users; and based on the request information of the Feed flow, sequentially passing through the dynamic and static request separation of a dynamic and static separation gateway, the read-write diffusion separation of a user authorized Feed flow calling module and then entering a write diffusion acquisition path to obtain Json data of the Feed flow. The application distinguishes the read-write diffusion scenes in the mixed diffusion mode, simplifies the authorization mode and the authentication calculation amount of the read diffusion, and facilitates the requirement of actual use.
Owner:INST OF COMPUTING TECH CHINA ACAD OF RAILWAY SCI +2

User data processing method and device based on user portrait and computer equipment

The invention discloses a user data processing method and device based on a user portrait and computer equipment. The method comprises the following steps: acquiring target user data of a target user; based on a preset feature extraction strategy, obtaining current user features corresponding to the preset feature extraction strategy; obtaining a user tag corresponding to the current user feature, and forming a current user portrait; obtaining a target user portrait having the maximum user portrait similarity with the current user portrait in a user portrait library; and obtaining target user associated data of the target user portrait, and sending the target user associated data to a user terminal corresponding to the target user data. According to the embodiment of the invention, after a part of user data which the user terminal agrees to send is obtained from the user terminal in a user authorization mode, feature extraction and label conversion are carried out to obtain the user portrait, the user portrait and the user portrait library are compared and matched to obtain the target user portrait with the maximum similarity, and related data are obtained; and the acquisition efficiency of the target user portrait and the related data thereof is improved.
Owner:GUANGZHOU FEIQUAN SMALL LOAN CO LTD

Off-line software license tamper-proof verification system and method based on first networking activation

PendingCN121256752AProgram/content distribution protectionPathPingAuthorization Mode
The invention belongs to the technical field of computer software security and digital rights management, and particularly relates to an offline software license tamper-proofing verification system and method based on first networking activation. The multi-NTP server time synchronization module is used for acquiring trusted network time from a plurality of NTP servers; a license signature verification module; the local timestamp encryption storage module is used for encrypting credible time and hardware fingerprints and then storing the credible time and the hardware fingerprints into a plurality of hidden paths; the off-line time integrity verification module is used for verifying system time integrity in an off-line environment; the hardware fault-tolerant module is used for generating a device fingerprint and processing a hardware change scene; and the version compatibility module is used for providing a flexible version matching strategy. According to the invention, an authorization mode that only first networking activation is needed and subsequent complete offline work is needed is realized, and the problems of continuous networking dependence, easy tampering, time rollback, hardware change mistaken killing and the like in the prior art are effectively solved.
Owner:KUNTAI VEHICLE SYST CHANGZHOU CO LTD

Systems, methods, apparatuses, processors, and storage media for enabling trusted transmission and reverse authorization processing of multi-party interactive data.

This invention relates to a system for trusted transmission and reverse authorization processing of multi-party interactive data. The system includes a data sender that configures a security policy list based on the data receiver's access request and assigns a temporary key with an attached permission tag to the data receiver. The data receiver configures the data sender's hardware and software environment as a trusted execution environment. The data receiver and data sender jointly construct a trusted transmission channel based on the feasible execution environment and share a communication key. This invention also relates to a method, apparatus, processor, and computer-readable storage medium for trusted transmission and reverse authorization processing of multi-party interactive data. By employing the system, method, apparatus, processor, and computer-readable storage medium of this invention for trusted transmission and reverse authorization processing of multi-party interactive data, trusted transmission and reverse authorization of multi-party interactive data are achieved, ensuring trusted data transmission at the system security level and refining data access and usage permissions under the reverse authorization mode.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Image forming apparatus

The present invention provides an image processing device, etc., that can reduce the risk of the approval process being hindered due to the applicable approval method. [Solution] The authorization server comprises a control unit capable of performing authorization processing using multiple authorization methods, a storage unit for storing connection information to the authorization server, and an output unit for outputting screen information related to the authorization processing. When the user selects the authorization processing based on one authorization method using the connection information, the control unit determines whether the authorization server supports that authorization method. If the authorization server determines that it does not support the authorization method, it restricts the execution of the authorization processing using that authorization method. The output unit outputs a notification prompting the user to select an authorization method different from the authorization method.
Owner:SHARP KK

A software and dynamic library oriented unified authorization and security verification system and method

The application provides a kind of unified authorization and security verification system and method for software and dynamic library, belongs to software copyright protection and network security technical field.The system includes authorization management center, multi-dimensional fingerprint generation module, secure storage construction module, dual-mode authorization execution module and unified verification engine, by generating software fingerprint, hardware fingerprint and company data fingerprint to constitute multiple binding information, using embedded or independent file mode to securely store encryption certificate, support local and remote two authorization modes, and in software runtime, decryption, certificate chain verification and multi-dimensional fingerprint matching check are carried out.The application realizes unified authorization management for different forms of software, improves hardware binding strength and software tamper resistance ability, while taking into account production batch and on-site remote operation and maintenance needs, suitable for full life cycle security management and control in complex scenarios such as Internet of Things.
Owner:SHAANXI ROCKTECH ELECTRONICS INFORMATION TECH CO LTD