Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

35 results about "Client certificate" patented technology

In cryptography, a client certificate is a type of digital certificate that is used by client systems to make authenticated requests to a remote server. Client certificates play a key role in many mutual authentication designs, providing strong assurances of a requester's identity.

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

Secure provisioning and rotation of certificates for edge devices

A certificate management service (CMS) may securely provision and rotate certificates for edge devices. The CMS may pre-register a unique device ID of an edge device (e.g., provided by the device manufacturer). When the edge device is installed at the client's remote network, it is provisioned with a common bootstrap certificate that allows the edge device to initially establish a secure to connection to a local hub device and to request a client certificate. The CMS receives the request for the client certificate, which includes the unique device ID. Since the unique device ID was pre-registered at the CMS, the CMS authenticates the request for the client certificate. The CMS causes a signed client certificate to be delivered back to the edge device, which may be used by the edge device to establish subsequent secure connections.
Owner:AMAZON TECH INC

Customized network interface card oriented to intranet security access and design method thereof

The invention discloses a network interface card with autonomous access authentication, and provides an integrated hardware authentication mechanism. The EAP-TLS client protocol stack is integrated on the bottom layer of the network card, so that the defect that an authentication module depends on a host system, manual intervention and the like in the existing scheme is overcome, TLS handshake and certificate verification are independently completed on the network card side, and authentication interaction is automatically initiated. The network interface card serves as a unique identity certificate of an access network, a client certificate and a corresponding private key are embedded in the network interface card and are stored in a protected nonvolatile area, and data confidentiality is effectively enhanced. The network card is used as an identity certificate and network access equipment at the same time, and the integrated design reduces the dependence on the service capability of management personnel. A traditional physical network card and an automatic authentication protocol are fused, and the method is suitable for application environments with high requirements for access control and authentication safety, such as an enterprise intranet and a government affair private network.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Certificate generation and access authentication method based on host fingerprint

The invention provides a certificate generation and access authentication method based on host fingerprints, and aims to improve authentication security by combining hardware fingerprints and certificate management. In the traditional EAP-TLS authentication, the user identity completely depends on a client certificate and a private key, is easy to copy or leak and has potential safety hazards, and when the private key is captured, an attacker can disguise as a user to access an intranet. According to the method, hardware fingerprints are dynamically calculated at a client side (an SHA256 Hash value is generated based on information of a network card, a hard disk, an SMBIOS, a mainboard and the like) to verify a certificate, and the certificate is sent to an authentication server. Meanwhile, on the basis of EAP-TLS bidirectional authentication, the matching condition of the certificate fingerprint and the client host is additionally checked, strong binding of the certificate and the host is achieved, and the related certificate can only be used on the corresponding host. In order to further enhance the protection of the certificate, the client stores the certificate and the private key as EFI variables. The method is widely applicable to various wireless network authentication scenes, and has wide applicability and remarkable economic benefits.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Certificate authority verification system, certificate authority verification method, and program

PCT designated stageWO2026176551A1Self-signed certificateInternet privacy
This certificate authority verification system includes: a verification device; a local certificate authority device that operates under an isolated execution environment; a certificate presenter device that serves as a server or a client and uses a server certificate or a client certificate; and a certificate verifier device that serves as a server or a client and verifies a presented certificate. The certificate authority device includes a self-certificate generation unit that generates a self-certificate which is a certificate of the certificate authority device itself, an evidence generation unit that generates evidence of the self-certificate, and a reference value registration request unit that executes a reference value registration request together with a reference value of the self-certificate. The verification device includes a reference value registration unit that registers the reference value of the self-certificate.
Owner:NT T INC

System and methods for agentless managed device identification as part of setting a security policy for a device

Systems, methods, and apparatuses directed to efficiently determining whether a device making a request to access an application or service is a managed device and using that information to set an appropriate security policy for the device or the request to access the application or service. In some embodiments, a service or server (referred to as a Managed Device Identification Service) is configured to request a client certificate from a device that is requesting access to a cloud-based application or service as part of a protocol handshake. If a certificate is received, it is compared to a stored certificate to determine if the device is a managed device and as a result, the appropriate security policy.
Owner:GOLDMAN SACHS BANK USA

BMC login method, system and device and computer readable storage medium

The invention discloses a BMC login method, system and device and a computer readable storage medium. The BMC login method comprises the steps that a user name, a login password and a client certificate uploaded by a login terminal are received; verifying whether the user name, the login password and the client certificate are all valid or not, and obtaining a verification result; and if the verification result is all valid, allowing the login terminal to log in the BMC system. According to the BMC login method provided by the embodiment of the invention, the login terminal is allowed to log in the BMC system only by verifying that the user name, the login password and the client certificate are all valid, and compared with the prior art that login is allowed only after the user name is verified to be matched with the password, a process of verifying the client certificate is added during login, so that the login efficiency is improved, and the user experience is improved. Meanwhile, compared with an operation mode of verifying login by using a user name, a password and a dynamic code, the method disclosed by the invention is simpler and more convenient, and login can be carried out without downloading and installing an identity verifier by the login terminal.
Owner:TONG TAIYI INFORMATION TECHNOLOGY (FUJIAN) CO LTD

Methods and systems for client certificate extraction in device authentication

Embodiments of a device and method are disclosed. In an embodiment, a method of communications involves at a network device, receiving an authentication message from a client, at the network device, extracting a payload from the authentication message, and sending a copy of the payload to a Transport Layer Security (TLS) microserver of the network device for client certificate extraction, where the TLS microserver is implemented in a side signal channel.
Owner:NILE GLOBAL INC

Connection management device and common API

A connection management device may be used to with a common API to allow a host device of a client to securely connect to a remote provider network. The host device may only be able to use a connection management device by using a defined set of commands of a common API. A hardware root of trust may be pre-provisioned with security data (e.g., client certificate, encryption keys). A connection command may be used that is not specific to any particular communication protocol (e.g., WiFi, cellular, wired protocol). In response to receiving the connection command from a host device, the connection management device may perform commands specific to the communication protocol of the connection management device to connect to a remote provider network, use the security data for authentication, and establish a connection in accordance with the communication protocol based on the authentication.
Owner:AMAZON TECH INC

Access authentication method for binding switch port and host

The invention provides an access authentication method for binding a switch port and a host, which is used for solving the problems that a server is difficult to judge the correctness of the port and the management complexity is high when a multi-port client is accessed. According to the method, switch port information (a switch identifier and a port number) is aggregated into a logic user, and the logic user is bound with a client certificate, so that unified authentication is realized. A client can obtain current port information through a link layer discovery protocol, and submits an authentication request in the form of'switch identifier-port number '; and the authentication server carries out verification according to the stored port information, the logic user and the certificate public key, and if the connection port does not accord with the binding relationship, the access is refused. The authentication request carries the network port MAC information of the first accessed switch so as to prevent the switch from being counterfeited. According to the technology, the security and flexibility of authentication are effectively improved, and when the network configuration is changed, only the binding relationship needs to be updated at the server without modifying the configuration of the client, so that the management burden is remarkably reduced.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Role-based authorization for wireless network management services

Technology for mesh network management including role-based authorization for wireless network management services is described. In one embodiment, a wireless mesh device receives, from a requesting device, a request to establish a secure communication session, authenticates the client certificate and establishes the secure communication session. The wireless mesh device further receives, from the requesting device via the secure communication session, a request directed to a service of a plurality of services provided by the wireless mesh device, where the request comprises the client certificate associated with the requesting device, identifies a root certificate used to cryptographically sign the client certificate, wherein the root certificate is associated with a role assigned to the requesting device, identifies role information associated with the requesting device and the client certificate, and responsive to determining that the role information indicates that the requesting device has permission to access the service, forwards the request to the service.
Owner:AMAZON TECH INC

General-purpose device identifiers and signal exchange integration

In certain aspects of this disclosure, a computer implementation method includes registering at least one managed device in a mobile device management service. This method includes receiving a client certificate on at least one managed device. This method includes integrating a generic device identifier SDK via a trusted ecosystem vendor app on at least one managed device. This method includes obtaining a pre-salted device identifier address associated with at least one managed device by the generic device identifier SDK based on a request from the trusted ecosystem vendor app. This method includes at least one managed device sending the pre-salted device identifier address to a security vendor service via a trusted ecosystem vendor to generate a generic device identifier address. This method includes at least one managed device receiving a generic device identifier address from the security vendor service via a trusted ecosystem vendor.
Owner:JAMF SOFTWARE LLC

Automatic OpenVPN account management method based on approval linkage

The invention provides an automatic OpenVPN account management method based on examination and approval linkage, and relates to the technical field of network communication, and the method comprises the steps: checking VPN application information filled by an applicant, and generating an examination and approval form based on the VPN application information passing the examination and approval; calling a Python API (Application Program Interface), and mapping parameters in the approval form into OpenVPN (Open Virtual Private Network) configuration parameters; a client certificate and a private key are generated based on an EasyRSA component, and certificate generation is completed through non-interactive password input; according to the authority level, dynamically updating an authority rule in an OpenVPN configuration directory, and distributing a main IP address and a standby IP address from a preset IP address pool; and forming VPN information by the certificate, the authority rule, the main IP rule and the standby IP rule, and sending the VPN information to the applicant.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Intelligent mobile terminal digital certificate issuing method and system based on ACME specification

The invention discloses an intelligent mobile terminal digital certificate issuing method based on an ACME specification, and the method comprises the steps: S1, enabling a client to request to create an order, and enabling the identification type to be a mobile phone number; s2, the server generates an order and returns the order to an authorized object list; s3, the client accesses the authorized object and obtains access URLs of two challenge objects of short message authentication and voice dialing authentication; s4, the client selects one authentication mode to access the corresponding challenge object; s5, the server side sends an authentication token value through a short message or voice dialing according to the selection of the client side; s6, the client calculates an authentication information value based on the token and the account key and returns the authentication information value; s7, the server verifies the authentication information, and waits for the client certificate application if the verification is passed; and S8, executing a certificate application and downloading process by the client. According to the invention, an automatic digital certificate issuing service can be provided for the intelligent mobile terminal, the number changing software is effectively prevented from counterfeiting a mobile phone number, and the security is improved.
Owner:GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD

A method for secure communication based on quantum keys

The application provides a kind of quantum key-based secure communication method, it is related to cryptographic application technical field.The method comprises: obtaining the serial number of target refilling key from the security chip in the communication module, and generating client handshake information;Client handshake information is sent to gateway device, so that gateway device obtains target refilling key from quantum cryptography management service platform according to the serial number of target refilling key, and generates server handshake message, receives the server handshake message and server certificate sent by gateway device;Call security chip to authenticate server certificate, generate first working key, send the client certificate of communication module to gateway device, so that gateway device authenticates client certificate through quantum cryptography management service platform, and generates second working key;Finally, according to the first working key and the second working key, VPN tunnel between communication module and gateway device is established, which is used for service data packet transmission.
Owner:中电信量子信息科技集团有限公司

Integrated trust platform modules, device attestation, and device management for live zero trust network access

Systems, apparatus, and methods for device attestation are disclosed. An example apparatus includes communication circuitry to obtain a request to access an organization resource and a client certificate including a device identifier and a certificate authority issuer, at least one memory storing machine readable instructions, and programmable circuitry to execute the machine readable instructions to determine that the certificate authority issuer is a trusted issuer, compare the device identifier against device identifiers in a database storing trusted device identifiers of an organization protecting the organization resource, in response to determining that an instance of the device identifier exists in the database, determine that a client device associated with the device identifier is authorized to access the organization resource based on checking a policy of the organization, and grant the client device access to the organization resource.
Owner:JAMF SOFTWARE LLC

Multi-protocol compatible communication method and related devices

This application provides a multi-protocol compatible communication method and related equipment. The multi-protocol compatible communication method includes: obtaining a target client certificate; determining the encryption algorithm of the target client certificate; determining a target communication protocol based on the encryption algorithm of the target client certificate; and establishing a connection with a server using the target communication protocol. The technical solution of this application automatically selects a suitable protocol through certificate analysis, eliminating compatibility issues that may occur in traditional protocol selection. The client and server can automatically adjust the communication protocol they use based on the encryption algorithm information contained in the client certificate, ensuring that both the client and server use compatible protocols in the same communication, effectively avoiding authentication failures or connection problems caused by mismatched protocols. Automated protocol selection ensures that both parties can use a matching protocol for authentication, reducing the chance of configuration errors and improving overall communication security.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

A data interaction method and device

The application provides a data interaction method and device, and relates to the technical field of cloud computing. A data interaction method is applied to a client and includes the following steps: obtaining a CA certificate and a client certificate issued by a private cloud; performing handshake information verification with a public cloud according to the CA certificate and the client certificate; and performing data interaction with the public cloud after the handshake information verification is successful. According to the embodiment of the application, the client can perform handshake with the public cloud through the certificate issued by the private cloud, and the private cloud can perform identity verification on the client through the handshake process.
Owner:HANGZHOU TUYA INFORMATION TECH CO LTD

Secure provisioning of an edge device using a fiducical marker

An update deployment service performs secure provisioning of an edge device using a fiducial marker. A client registers an edge device with a provisioning service of a remote service provider network by providing a unique device ID. When the edge device is turned on, the edge device detects, based on input from a camera of the device, a fiducial marker that was generated by the provisioning service. The edge device decodes a network address (URL) and security credentials represented by the fiducial marker. The edge device sends the device ID and credentials to the provisioning service. The provisioning service authenticates the credentials and sends, to the edge device, a client certificate that can be used by the edge device for authentication by one or more other services of the provider network.
Owner:AMAZON TECH INC

Communication configuration method, device and medium based on DPU centralized service mesh

The application relates to a communication configuration method and device based on a DPU centralized service grid and a medium, in particular to the technical field of centralized service grids. The application is applied to a client node, the client node comprises a client host and a client data processing unit (DPU), the client host deploys a client preset adaptation component, and the client DPU deploys a client data plane agent; the method comprises the following steps: the client preset adaptation component receives a key discovery service request sent by the client data plane agent, generates a certificate signature request and sends the certificate signature request to a server control plane component, so that the server control plane component issues a client certificate; the client preset adaptation component receives the client certificate; and after the client preset adaptation component performs format conversion on the client certificate, the client preset adaptation component sends the client certificate to the client data plane agent, so that the client data plane agent performs bidirectional transport layer security communication by using the client certificate.
Owner:YUSUR TECH CO LTD

A virtual machine migration method, device, equipment and medium

The application discloses a virtual machine migration method, device, equipment and medium, and belongs to the technical field of servers. The method comprises the following steps: when OpenStack is required to perform a virtual machine migration operation, a target libvirt container image is acquired; a target computing node for deploying the target libvirt container image is specified in the OpenStack, and it is judged whether the target libvirt container image needs to perform the migration operation by using a national secret algorithm according to a global configuration file; if yes, a central certificate is generated according to the national secret algorithm, and a corresponding relationship between the target computing node and the central certificate is stored into a libvirt pod; a client certificate and a server certificate are generated according to the central certificate, and each certificate is stored into a specified directory, so as to deploy the target libvirt container image on the target computing node. By the method, the safety and reliability of the virtual machine in the migration process can be further ensured.
Owner:JINAN INSPUR DATA TECH CO LTD

Secure method of bi-directional inline exchange of cryptographic certificates for data transfers

Embodiments for securely exchanging Certificate Authority (CA) certificates inline and bi-directionally to make it easier for client-server transmissions to use certificate-based authentication. The client certificate is transferred securely through encryption with a pre-shared key based on certain parameters, and the server certificate is transferred securely through encryption with a pre-shared key based on the parameters. The process reduces the burden from applications to maintain and save the CA certificate. It also reduces the burden from server to maintain and save the CA certificate of the client so that server can select it to be used during authentication. This helps enable large scale deployments where the server can maintain the CA certificate and send it to client.
Owner:DELL PROD LP

MySQL public network encryption transmission method and system based on X.509 certificate and Stunnel

The invention discloses a MySQL public network encryption transmission method and system based on an X.509 certificate and Srunnel, and relates to the technical field of network security and database communication, secure communication of a MySQL database in a public network environment is realized by deploying a Srunnel encryption agent module at a client and a server and establishing a bidirectional authentication TLS encryption tunnel based on the X.509 digital certificate, and the security of the MySQL database in the public network environment is improved. The method comprises the steps that a certificate issuing mechanism root certificate is generated, a server certificate and a client certificate are signed and issued, a Srunnel server agent module and a client agent module are configured, a certificate path and a verification level are set, a MySQL client carries out TLS handshake and two-way certificate verification through a local Srunnel agent and a server Srunnel agent, after an encryption tunnel is established, data are transmitted in an encrypted mode, and the data are transmitted to the server Srunnel agent. The method supports an RSA and SM2 dual-certificate system, end-to-end encryption and strong identity authentication are realized, man-in-the-middle attack and data leakage risks are effectively defended, and the method is suitable for the fields of finance, government affairs and the like which have strict requirements on data security.
Owner:SHANGHAI TERRESTRIAL INFORMATION NETWORK CO LTD

Terminal verification method and system, electronic equipment and storage medium

The invention provides a terminal verification method and system, electronic equipment and a storage medium, and the method comprises the steps: obtaining the environment information of a current client when the client responds to a user entering a target application; determining that environmental security exists based on the environmental information, responding to user identity information input by a user, and obtaining a target identifier and a client certificate; the user identity information, the target identifier, the client certificate and the environment information are packaged to generate a data packet, and the data packet is sent to credit processing equipment; the credit data device determines whether the user can access the target environment through the client based on the user identity information, the target identifier, the client certificate, the identity credential and the environment information in the data packet; and if it is determined that the client can access the target environment, determining that the client logs in successfully. According to the invention, bidirectional authentication is carried out on the user identity and the client identity through the client and the credit processing equipment, so that the network security problem in the industrial control network is solved by controlling the user permission and the terminal permission.
Owner:SUPCON TECH CO LTD +1

Access authentication method that binds switch ports to hosts

ActiveCN121396666Beasy to integrateReduce migration costsPublic key for secure communicationUser identity/authority verificationEngineeringLink Layer Discovery Protocol
This invention proposes an access authentication method that binds switch ports to hosts, addressing the challenges of server-side port verification and high management complexity when multiple clients access the network. This method aggregates switch port information (switch identifier + port number) into logical users and binds them to client certificates for unified authentication. Clients can obtain current port information via a link-layer discovery protocol and submit authentication requests in the form of "switch identifier - port number." The authentication server verifies the connection based on stored port information, logical users, and certificate public keys. If the connection port does not match the binding relationship, access is rejected. The authentication request includes the MAC address of the first connected switch to prevent switch spoofing. This technology effectively improves authentication security and flexibility. When network configuration changes, only the binding relationship needs to be updated on the server side, without modifying client configurations, thus significantly reducing the management burden.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Operation data reporting method, device, equipment and system of VR project and medium

The invention relates to an operation data reporting method, device, equipment and system based on a VR project and a medium. In the application, before a central control system deployed by a store main control device operates a VR project, authentication information needs to be sent to a cloud authentication system; only when the authentication result shows that the authentication is successful, TLS bidirectional authentication with a project server with a first MQTT client certificate can be carried out through the MQTT server certificate in the authentication result, so that after the authentication is successful, the VR project is operated through the project server and the project client; through the mode, only the central control system which is successfully authenticated can obtain the MQTT server certificate and run the VR project, and the illegally copied VR project is effectively prevented from running in unauthorized equipment; moreover, after the central control system and the project server side carry out TLS bidirectional authentication, the project server side can send the operation data through an MQTTS protocol, and the safety of the operation data is ensured.
Owner:BEIJING QIYI CENTURY SCI & TECH CO LTD

A distributed node unified identity authentication method and system based on a QUIC protocol

The application relates to a distributed node unified identity authentication method and system based on a QUIC protocol, belongs to the technical field of network security, and is applied to a client. The identity authentication method comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and prestoring a server certificate chain; generating a QUIC initial data packet according to a target server domain name identifier and the client certificate and sending the QUIC initial data packet to a server; receiving a QUIC handshake data packet returned by the server; verifying the legality of a server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to a client DH private key and a server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to the server; and synchronously encrypting application layer data with the 1-RTT session key with the server, and transmitting data to the server in a 1-RTT encryption space of the QUIC protocol. The application ensures the reliability of node identity and the confidentiality of data.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

A V2X communication method and system

This application proposes a V2X communication method and system, comprising: a client sending a ClientHello message in SPDU format to a server, the ClientHello message including the client's communication cipher suite and a signature message, the signature message including the client's certificate and client data signature value; the server responding to the client with a ServerHello message in SPDU format based on the ClientHello message, the ServerHello message including a target communication cipher suite determined by the server and the server certificate; the server verifying the client's identity based on the signature message and determining the server's communication transmission key based on the target communication cipher suite; the client determining its own communication transmission key based on the ServerHello message; and the client and server communicating with each other based on the client's communication transmission key and the server's communication transmission key, respectively.
Owner:VANJEE TECHNOLOGY CO LTD

A client authentication method, apparatus, device, and storage medium

The application provides a client authentication method and device, equipment and a storage medium. The client authentication method comprises the following steps: obtaining a client multi-certificate chain from a client certificate message sent by a client, wherein the client multi-certificate chain comprises a plurality of client certificate chains, and each client certificate chain comprises a plurality of certificates; checking the client multi-certificate chain to obtain a checking result; if the checking result is that the checking is passed, obtaining an authentication result according to a certificate public key corresponding to the client multi-certificate chain, an encrypted hash value sent by the client and a hash value calculated locally, wherein the encrypted hash value is obtained by encrypting a private key by the client.
Owner:HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3