Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

36 results about "Conditional access" patented technology

Conditional access (abbreviated CA) or conditional access system (abbreviated CAS) is the protection of content by requiring certain criteria to be met before granting access to the content. The term is commonly used in relation to digital television systems and to software.

Conditional access control policy finding generation

ActiveUS12363168B1Securing communicationConditional accessData mining
Techniques for more precise access control policy findings, use a conditional injection of policy constraints into a findings analysis. The injection of a policy constraint of a policy being analyzed into the findings analysis is conditioned on the policy itself. In particular, the injection is conditioned on whether the policy constraint is trusted in the context of the policy (e.g., unlikely to be spoofed or manipulated in the policy context). As a result, where a policy constraint can be trusted in the context of a given policy, a more precise (e.g., more specific) findings analysis of the policy based on the policy constraint can be conducted than if the policy constraint were not included in the policy finding analysis (e.g., because the policy constraint is not trusted in other policy contexts).
Owner:AMAZON TECH INC

Concept for providing conditional access to an online service

The present disclosure is related to a concept for providing conditional access to an online service. A smart contract deployed on a blockchain network is used to lock a predetermined amount of digital assets of a user for a predetermined locking duration. A proof is provided to the online service that the user has locked an amount of digital assets meeting or exceeding a threshold specified by the online service. The proof is verified and access for the user to the online service may be granted in case the verification is successful.
Owner:SONY GROUP CORP +1

Secure cross-tenant access

In a cloud computing environment, cross-tenant access security measures include monitoring a change or addition of conditional access policies that impedes or is at risk to impede authorized access to a focal tenant from a secondary tenant user. In some cases, cross-tenant access security includes tracking a role assignment list to detect malicious roles, or to detect hindered role changes such as role deletion, or both. In some cases, focus tenant events and auxiliary tenant events are associated in the audit. In some cases, the authorized access is an access when zero persistently limited. In some cases, authorized access is constrained to an IP address range, or to a login from a managed device, or both. In short, security measures are described that aim to mitigate accidental or secret role or policy changes that may interrupt or obstruct authorized cross-tenant access.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Intelligent secure user access to private resources

Methods, systems and computer program products are provided for intelligent secure access to private resources. A security service (e.g., SASE ZTNA) may maintain the same or similar security posture for users who work remotely and / or locally by providing authentication, authorization, and / or ongoing conditional access via a security service (e.g., private or public SASE) while intelligently routing remote client traffic to private resources through the security service and routing local client traffic to private resources locally. A traffic routing determination may be made by a security client and / or security server. A traffic routing determination may be based on the location of a client computing device, such as a trusted network detection for a private / trusted network. Traffic routing determinations may be based on conditions alternative or in addition to location, such as the type of private resource or information being accessed by a client computing device.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Control integrated circuit for maintaining video output to conditional access module with aid of reference clock regeneration, associated television receiver and associated method

A control integrated circuit (IC) for maintaining video output to a conditional access module (CAM) with aid of reference clock regeneration, an associated television receiver and an associated method are provided. The control IC may include an input control circuit, a frame processing circuit, a clock control circuit, and an output control circuit. The input control circuit receives a transport stream (TS) data signal from a demodulator circuit, the frame processing circuit performs frame processing operations on the TS data signal to prepare a plurality of frames, the clock control circuit generates a second reference clock signal according to the TS valid signal to be a replacement for a first reference clock signal, and the output control circuit outputs the plurality of frames to the CAM according to the second reference clock signal, to allow the CAM to perform conditional access (CA) control for the television receiver.
Owner:REALTEK SEMICON CORP

Method, communication devices and a server for controlling content

A method at a first communication device for providing a second communication device access to content, the method comprising: providing an offer to the second communication device, offering the second communication device conditional access to the content, wherein access to the content at the second communication device is adaptable based on sensor data of at least one of the first and the second communication device; acquiring sensor data of at least one of the first and the second communication device; providing the second communication device full access to the content in case it is that the sensor data of at least one of the first and the second communication device indicates that the second communication device shall be grated full access to the content, or determining that access to the content is to be restricted at the second communication device, and providing the second communication device restricted access to the content, in case it is determined that sensor data of at least one of the first and the second communication device is indicating that access to the content is to be restricted at the second communication device.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Issuance of a fungible token for a conditional access to a service

The invention provides a method of enabling a conditional access to a service delivered by a service provider. The method comprises receiving (209) by an issuer entity, a fungible token request from a user device, the fungible token request comprising a public key of the service provider, a public key of a secure element associated with the user device and requested information to be incorporated in a fungible token. A fungible token is computed (210) based on the requested information comprised in the fungible token request, and encrypted (211) using the public key of the service provider, to obtain a first encrypted fungible token. The first encrypted fungible token is further encrypted using the public key of the secure element to obtain a second encrypted fungible token, which is transmitted (212) to the user device.
Owner:THALES DIS FRANCE SA

System for decrypting and rendering content

The invention relates to a system for rendering content, the rendering of which is subject to conditional access security conditions. A system is described comprising a host device and a detachable security device, the security device being arranged to decrypt encrypted content, re-encrypt it under a local key and deliver the re-encrypted content to the host device while ensuring that the host device is compliant or otherwise implements any conditions associated with rendering the content.
Owner:NAGRAVISION SA

Cryptography

A pairing method between a user device (1) and an operator device (2), the user device (1) being intended to receive conditional access data from the operator device (2), the user device having a user device identifier (UID), the operator having an operator device identifier (OID). The method comprises receiving, by the user device, a user device key (KUID) derived from a first cryptographically secure function and receiving, by the operator device, an operator key (KOID) derived from a second cryptographically secure function. The user device comprises a user device bilinear mathematical function (e(KUID, OID)) and the operator device comprises an operator bilinear mathematical function (e(UID, KOID)) which each define a pairing over an elliptic curve. The method includes generating, by the operator device (2), a pairing key (KD=e(UID, KOID)) between the user device (1) and the operator device (2), using the operator key (KOID) and the device identifier (UID) as variables of the operator mathematical function (e(UID, KOID)). The user device (1) generates the same pairing key (KD=e(KUID, OID)) using the user device key (KUID) and the operator device identifier (UID) as variables of the user device mathematical function e(KUID, OID).
Owner:NAGRAVISION SA

Data processing method, target working node in distributed system and distributed system

The embodiment of the invention provides a data processing method, a target working node in a distributed system and the distributed system.The data processing method is applied to the target working node in the distributed system and comprises the steps that under the condition that an access instruction for a target partition is received, a to-be-verified access label of the target partition is obtained; a condition access request of the target partition is generated according to the to-be-verified access label, the target partition is accessed based on the condition access request, the to-be-verified access label is used for being matched with a target access label, and whether the target working node has the access permission of the target partition or not is determined based on a matching result; the target access tag is an access tag currently stored in the file system, and the conditional access request is used for indicating that access is allowed under the condition that the target working node has the access permission of the target partition. And whether the target working node has the access permission of the target partition is verified by using the to-be-verified access label, so that the partition data consistency is ensured.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Method to revoke a receiving device among a population of receiving devices having access to conditional access data, corresponding computer program products and devices.

PCT designated stageWO2026109482A1Key distribution for secure communicationPathPingConditional access
Method to revoke a receiving device among a population of receiving devices having access to conditional access data, corresponding computer program products and devices A method is proposed to revoke a receiving device among a group of receiving devices having access to conditional access data. The group is organized in a hierarchical tree structure starting by a root, represented by a root key, down to the leaves associated to the receiving devices, a leaf being represented by a key which is unique to the receiving device associated to the leaf, a path starting from the root and terminating by a leaf having multiple nodes represented by group keys. According to such method, new keys are populated only in the receiving devices using group keys representing nodes along the path starting from the root and terminating by a leaf associated to the revoked receiving device. The new root key is thus only present in the authorized receiving devices at the end. The revoked device cannot any more access to the new root key.
Owner:NAGRAVISION SA

Control integrated circuit, television receiver and method

The present disclosure relates to control integrated circuits, television receivers, and methods. The present invention provides a control integrated circuit, a related television receiver, and a method for maintaining control of video output to a conditional access module by reference clock regeneration. The control integrated circuit can include an input control circuit, a frame processing circuit, a clock control circuit, and an output control circuit. The input control circuit receives a transport stream (TS) data signal from a demodulator circuit, the frame processing circuit performs frame processing operations on the TS data signal to prepare a plurality of frames, the clock control circuit generates a second reference clock signal from a TS active signal as a substitute for a first reference clock signal, and the output control circuit outputs the plurality of frames to the conditional access module in accordance with the second reference clock signal to allow the conditional access module to perform conditional access control for the television receiver.
Owner:REALTEK SEMICON CORP

Conditional access

An apparatus comprising means for receiving secondary radio link failure information, wherein the secondary radio link failure information indicates a situation of a failure in a secondary radio link between the user equipment and at least one source secondary node when the user equipment is configured to conditionally access at least one target secondary node, the user equipment is in dual connectivity with a source main node and a source auxiliary node; determining at least one target primary cell in a secondary cell group of the target secondary node based at least in part on the received secondary radio link failure information, where the determined at least one target primary cell in the secondary cell group is to be included in information indicating at least one suggested target primary cell in the secondary cell group, the at least one suggested target primary cell is to be prepared by the target secondary node for conditional access by the user equipment; and transmitting information indicating the determined at least one target primary cell in the secondary cell group of the target secondary node.
Owner:NOKIA TECHNOLOGIES OY

Blockchain-implemented systems and methods for secure access control

Methods and systems for enabling conditional access to a resource, where the condition is the performance of a task. This task can be executed by one party on behalf of another. The entity controlling access creates a task that includes broadcasting a transaction on the blockchain, with multiple outputs, including a locking-output. Additional transactions ensure access to the resource only upon task completion. Access is achieved by initially broadcasting the resource, conditionally available, then broadcasting the transaction that fulfills the condition. Multi-signatures and a refund mechanism are used to lock access, with multi-signatures spread across transactions. Initial deposit broadcast makes the resource available but locked by a first multi-signature and tied to a refund mechanism. The task and transaction have a locking-output secured by a second multi-signature linked to the refund mechanism. Access requires both multi-signatures of the refund mechanism to be signed and the main transaction to be broadcast.
Owner:NCHAIN LICENSING AG

System and method for providing conditional access to virtual gaming items

ActiveUS12420202B2Video gamesConditional accessEngineering
The present specification describes a system and method for providing conditional access to a virtual gaming item possessed by a first player of a video game to a second player. The method includes: creating a database of conditionally accessible virtual items, wherein said accessibility is determined based on at least one predefined condition; modifying an attribute of the virtual item for making the second player aware that said item is available for conditional access for a predefined period of time; fulfilling, by the second player, at least one access condition; and providing accessibility to the item to the second player for the predefined period of time.
Owner:ACTIVISION PUBLISHING INC

Adaptive protection mechanisms loop

Some embodiments operationally connect a risk score with cybersecurity protection mechanisms and user interactions data in a feedback loop. The risk score guides protection activities by the protection mechanisms, thereby prompting or preventing various user interactions. The protection activities and the user interactions are recorded in audit logs, and curated data based on the audit logs is fed to a risk scoring model as input. The risk scoring model then updates the risk score, and the loop repeats as the protection mechanisms alter their protection activities based on the updated risk score, thereby providing adaptive protection. Security tools for insider risk management, data leak prevention, and conditional access are enhanced to provide adaptive protection, by recording protection activities and user interactions for use as risk model input, and by checking regularly for risk score updates and modifying their protection activities accordingly.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Test suite for digital television host and conditional access module

ActiveCN223957597UTelevision systemsTest suiteConditional access
The utility model discloses a test suite for a digital television host and a conditional access module, which comprises a main controller, an interface bus, a digital television host interface adaptation unit, a conditional access module interface adaptation unit, a modulation-demodulation interface unit, a storage unit and a network interface unit, the main controller is respectively connected with the storage unit, the modulation-demodulation interface unit and the network interface unit, and is also respectively connected with the digital television host interface adaptation unit and the conditional access module interface adaptation unit through the interface bus; and the digital television host interface adaptation unit is respectively connected with the conditional access module interface adaptation unit and the modulation-demodulation interface unit. The test suite provided by the utility model can be compatible with tests of the digital television host and the conditional access module.
Owner:SHENZHEN STATE MICRO TECH CO LTD

Handling of Conditional Access Policies

PendingUS20250385942A1Securing communicationConditional accessEngineering
A conditional access policy management system which enables organizations' administrators to manage conditional access policies controlling user access to respective organizational assets, e.g., apps which respective organizations may store on a cloud, the system comprising a user interface enabling an administrator to select a policy, to define a selected policy; and / or a processor which may be configured to display a timeline along which a sequence of plural time-points may be arranged wherein changes were made in said selected policy at each of the plural time-points.
Owner:PRO-VISION SOFTWARE SOLUTIONS LTD

Digital TV Host and Conditional Access Module Test Component

ActiveCN309409646STelecommunicationsConditional access
1. Name of the Design Product: Digital TV Host and Conditional Access Module Test Component. 2. Use of the Design Product: Used to test digital TV hosts and conditional access modules. 3. Design Key Points of the Design Product: Lies in the shape. 4. Picture or Photograph that Best Illustrates the Design Key Points: Perspective View 1.
Owner:SHENZHEN STATE MICRO TECH CO LTD

Secure conditional domain name system operation

Some embodiments enhance the security of domain name resolution and other DNS operations by automatically intercepting DNS operations, determining an associated device identity, or ascertaining an associated user identity, and enforcing security policies based at least on the DNS operations and based on at least one of the identities. Some protectable DNS operations include request resolution, reverse lookup from an IP address to a domain name, DNS record access, mail server mapping, redirection, forwarding, and DNS record caching operations. Implementing the policy includes, for example, blocking a result requested by the DNS operation, permitting computation progress towards the requested result, permitting different results, modifying the DNS record, or flushing the DNS record from a cache. In some embodiments, a DNS operation security function utilizes or implements a conditional access security function, providing, for example, secure conditional domain name resolution.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Situationally conditional electronic access control system and method

An electronic access control system and method that enables conditional access to electronic locking systems according to user-based and situation-based safety parameters. Aspects of the present disclosure provide for a mobile access interface whereby the network operations center can assess a safety risk for a service site based on a combination of user-generated inputs, sensor inputs and / or external data inputs. The system may comprise a dynamic rules engine configured to dynamically determine safety and compliance associated with an access-restricted area. If the access-restricted area is safe, the system may enable access according to one or more access protocols. If the access-restricted area is unsafe, or the user requesting access is not in compliance with one or more static or dynamic safety parameters, the system may disable standard access protocols and deny access to the requesting party.
Owner:TYCO FIRE & SECURITY GMBH

Intelligent secure user access to private resources

Methods, systems and computer program products are provided for intelligent secure access to private resources. A security service (e.g., SASE ZTNA) may maintain the same or similar security posture for users who work remotely and / or locally by providing authentication, authorization, and / or ongoing conditional access via a security service (e.g., private or public SASE) while intelligently routing remote client traffic to private resources through the security service and routing local client traffic to private resources locally. A traffic routing determination may be made by a security client and / or security server. A traffic routing determination may be based on the location of a client computing device, such as a trusted network detection for a private / trusted network. Traffic routing determinations may be based on conditions alternative or in addition to location, such as the type of private resource or information being accessed by a client computing device.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Enforcing conditional access to network services based on authorization statuses associated with network flows

ActiveUS12401644B2Securing communicationAuthorization ModeConditional access
This disclosure describes techniques for enforcing conditional access to network services. In an example method, a first computing device detects a second device operating in a per-flow authorization mode. The first device receives a first request from a second computing device to communicate with a third computing device using a first network flow and determines that the first flow is authorized (e.g., because of an active past authentication and / or the third device's authentication exemption). Data associated with the first request is transmitted to the third device. The first device then receives a second request to communicate with a fourth computing device using a second network flow and determines that the second flow is not authorized (e.g., because it is not associated with an active past authentication and / or the fourth device is not exempt from authentication). Data associated with the second request is not transmitted to the fourth device.
Owner:CISCO TECHNOLOGY INC

Issuance of a fungible token for a conditional access to a service

The invention provides a method of enabling a conditional access to a service delivered by a service provider. The method comprises receiving (209) by an issuer entity, a fungible token request from a user device, the fungible token request comprising a public key of the service provider, a public key of a secure element associated with the user device and requested information to be incorporated in a fungible token. A fungible token is computed (210) based on the requested information comprised in the fungible token request, and encrypted (211) using the public key of the service provider, to obtain a first encrypted fungible token. The first encrypted fungible token is further encrypted using the public key of the secure element to obtain a second encrypted fungible token, which is transmitted (212) to the user device.
Owner:THALES DIS FRANCE SA

Conditional access

A user equipment comprises means for sending information indicating that a target secondary node is accessed conditionally since the user equipment is configured to access conditionally, and before a secondary radio link failure occurs, the target secondary node is not accessed conditionally. Whether at least one measurement report for at least one target primary cell in a secondary cell group of the target secondary node has been sent by the user equipment, the at least one target primary cell is a target primary cell detectable by the user equipment when the secondary radio link failure occurs at the user equipment when the user equipment is configured to conditionally access a target secondary node.
Owner:NOKIA TECHNOLOGIES OY

Enforcing conditional access to network services based on authorization statuses associated with network flows

PendingUS20250373582A1Securing communicationAuthorization ModeConditional access
This disclosure describes techniques for enforcing conditional access to network services. In an example method, a first computing device detects a second device operating in a per-flow authorization mode. The first device receives a first request from a second computing device to communicate with a third computing device using a first network flow and determines that the first flow is authorized (e.g., because of an active past authentication and / or the third device's authentication exemption). Data associated with the first request is transmitted to the third device. The first device then receives a second request to communicate with a fourth computing device using a second network flow and determines that the second flow is not authorized (e.g., because it is not associated with an active past authentication and / or the fourth device is not exempt from authentication). Data associated with the second request is not transmitted to the fourth device.
Owner:CISCO TECHNOLOGY INC

Secure cross-tenant access

In a cloud computing environment, a cross-tenant access security measure includes monitoring conditional access policies for changes or additions that hamper or threaten to hamper an authorized access from an assistant tenant user to a focus tenant. In some cases, cross-tenant access security includes tracking a role assignment list to detect rogue roles, or to detect hampering role changes such as role deletions, or both. In some cases, focus tenant events and assistant tenant events are correlated in an audit. In some cases, the authorized access is a zero standing time bound access. In some cases, the authorized access is constrained to an IP address range, or constrained to login from a managed device, or both. In short, security measures are described that mitigate accidental or surreptitious role or policy changes that would shut down or hinder authorized cross-tenant access.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Conditional access

An apparatus comprising means for: receiving secondary radio link failure information, wherein the secondary radio link failure information is indicative of circumstances of a failure in a secondary radio link between a user equipment and at least one source secondary node while the user equipment was configured to conditionally access a target secondary node, and the user equipment is having dual connectivity with a source master node and a source secondary node; determining based, at least in part, on the received secondary radio link failure information at least one target primary cell of a secondary cell group, of the target secondary node, wherein the determined at least one target primary cell of a secondary cell group is to be included in information indicating at least one suggested target primary cell of a secondary cell group to be prepared by the target secondary node for conditional access by a user equipment; and transmitting information indicative of the determined at least one target primary cell of a secondary cell group, of the target secondary node.
Owner:NOKIA TECHNOLOGIES OY