Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

13 results about "Credential management" patented technology

Credential Management. Credential Management is the set of practices that an organization uses to issue, track, update, and revoke credentials for identities within their context. A CREDENTIAL is authoritative evidence of an individual’s claimed identity.

Credential management method, and device

PCT designated stageWO2026103528A1Digital data protectionDigital data authenticationEngineeringCredential management
The embodiments of the present application relate to the technical field of electronic devices. Provided are a credential management method, and a device. The method is applied to a first device, and comprises: a first device determining that a user account is to be used to associate a target credential, wherein the target credential is used for encrypting user data managed by the first device; the first device further acquiring identity verification information of a user on the basis of the determination that the user account is to be used to associate the target credential; and the first device further sending the target credential to a third device when determining, on the basis of the identity verification information, that the identity verification of the user is successful. Therefore, it is not necessary for a user to manually save a target credential, thereby improving the convenience of credential management. Furthermore, the user can subsequently acquire the target credential only upon successful identity verification, such that the flexibility and security of credential management are improved.
Owner:HUAWEI TECH CO LTD

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Proxy FIDO authentication with signed identity tokens

The present disclosure is directed to a managed cloud-based FIDO authenticator implemented with a distributed switchboard system. The disclosed switchboard implementation enables proxy automation and management of FIDO-related service, including registration and / or access operations, between FIDO service requesting and relying parties. The described process is based on generation of a single pre-validated and personalized identity token, based on validation, tokenization and identity mapping of an identification record associated with a FIDO service-requesting entity (SRE). The generated FIDO identity token can be used as a validity signature for streamlined resolution of identity for generation of FIDO access credentials. The managed FIDO authenticator further provides a FIDO credential management and recovery features for user and / or client applications reliant upon FIDO-authenticated services. The distributed switchboard implementation further enables implementation of a federated FIDO services for a distributed application whereby various FIDO-reliant application components can perform their own FIDO authentication via the distributed switchboard.
Owner:CAPITAL ONE SERVICES LLC

Identity credential management method and apparatus, electronic device, and readable storage medium

ActiveCN116361765BEngineeringCredential management
The application provides an identity credential management method and device, electronic equipment and readable storage medium, and belongs to the technical field of communication. In the case that a target application requests upgrading, the application obtains upgrading information corresponding to the target application, wherein the upgrading information comprises upgrading data and an upgrading mode; controls the target application to generate a corresponding authorization file based on the upgrading mode; after generating the authorization file, upgrades the target application based on the upgrading data; and controls the upgraded target application to request a corresponding identity credential from a corresponding application background based on the authorization file. Through the present solution, the upgraded target application can request a corresponding identity credential from the application background based on the authorization file generated by the target application before upgrading. Thus, the application program can intelligently obtain an identity credential after updating and upgrading, thereby improving the efficiency of obtaining an identity credential.
Owner:WEIWEI SHANGHAI NETWORK TECH CO LTD

Service invocation system, method and trusted secure environment

PendingCN122372621AEngineeringCredential management
This invention provides a service invocation system, method, and trusted security environment, belonging to the field of information security technology. The system includes a trusted security environment, a user side, and a service side. The trusted security environment stores target service invocation credentials in a secure storage area. The user side sends an authentication data generation request to the trusted security environment. The trusted security environment also generates corresponding authentication data based on the target service invocation credentials using a preset target authentication mechanism and returns it to the user side, wherein the authentication data does not contain the plaintext data of the target service invocation credentials. The user side also sends a service invocation request to the service side, the service invocation request carrying the authentication data. The service side authenticates the authentication data using the aforementioned target authentication mechanism, determines the corresponding service invocation result upon successful authentication, and returns it to the user side. Using this invention can improve the security of credential management.
Owner:SHENZHEN GOODIX TECH CO LTD

Systems and methods for credential holder support using AAA in non-3GPP access

ActiveUS12677148B1Internet privacyEngineering
A method is provided for accessing a non-public network (NPN) by a communication device utilizing a credential management system, including steps of (a) receiving, from the device through non-3GPP access means, a first authentication request at an authentication server function (AUSF) of a 5G core (5GC) in communication with the NPN, (b) sending a second authentication request from the AUSF to a network slice-specific authentication and authorization function (NSSAAF) of the 5GC, (c) transmitting, from the NSSAAF, an EAP response / identity message to an AAA server in communication with the credential management system, (d) performing, based on the transmitted EAP response / identity message, EAP-based authentication between the AAA server and the communications device, (e) receiving, at the NSSAAF from the AAA server, and EAP success message, (f) receiving, at the AUSF from the NSSAAF, a first authentication response, and (g) authenticating the communication device with the NPN.
Owner:CABLE TELEVISION LAB INC

Intelligent Password Management and Secure Login Methods under Dynamic Credential Control

This invention relates to the field of data security technology and proposes an intelligent password management and secure login method under dynamic credential control. The steps include: creating a high-strength password using a built-in password generator; dynamically calculating an account security trust score based on a neural network model trained from multi-dimensional behavioral data; and triggering a risk-based targeted password update when the trust score is too low. During the login process, a pre-built user behavior knowledge graph and a heterogeneous graph attention network model are used to calculate the context deviation of login events in real time, identify complex attack behaviors, and execute tiered protection responses. After the account is locked, a real-time risk score is initialized and dynamically adjusted based on multi-source risk signals and a nonlinear decay model to achieve intelligent risk unlocking. This invention realizes a transformation of credential management from static rules to dynamic cognition, significantly improving the defense capabilities against advanced threats such as credential stuffing and credential collision attacks, while optimizing user experience and operational efficiency.
Owner:BEIJING HONGSHAN INFORMATION TECH RES CO LTD

Proxy FIDO authentication with signed identity tokens

PCT designated stageWO2026136472A1User identity/authority verificationDigital data authenticationEngineeringCredential management
The present disclosure is directed to a managed cloud-based FIDO authenticator implemented with a distributed switchboard system. Exemplary implementations enable proxy automation and management of FIDO-related service, including registration and / or access operations, between FIDO service requesting and relying parties. Exemplary implementations are based on generation of a single pre-validated and personalized identity token, based on validation, tokenization and identity mapping of an identification record associated with a FIDO service-requesting entity. The generated FIDO identity token can be used as a validity signature for streamlined resolution of identity for generation of FIDO access credentials. The managed FIDO authenticator further provides a FIDO credential management and recovery features for user and / or client applications reliant upon FIDO-authenticated services. Exemplary implementations further enable implementation of a federated FIDO services for a distributed application whereby various FIDO-reliant application components can perform their own FIDO authentication via the distributed switchboard.
Owner:CAPITAL ONE SERVICES LLC

A network identity authentication credential management method and system of intelligent security hardware

This invention discloses a method and system for managing network identity authentication credentials for smart security hardware, relating to the field of Internet of Things (IoT) security technology. The method includes: registering a decentralized identity identifier for each smart security hardware device on a blockchain, and storing a public key credential associated with the decentralized identity identifier on the blockchain as an initial identity credential; real-time collection of behavioral data sequences generated by the smart security hardware during operation, inputting them into a pre-trained global anomaly recognition agent, and outputting a behavioral deviation score; dynamically generating a current trust score, uploading the current trust score and corresponding anomaly event information to the blockchain for evidence storage; and monitoring changes in the trust score based on a smart contract, automatically executing the corresponding access control policy when the current trust score falls below a preset trust threshold to adjust the communication permissions of the smart security hardware in the network. This invention effectively improves the reliability and security of network identity authentication for smart security hardware.
Owner:SHENZHEN HOUSELAI TECH CO LTD

A method and system for credential management in a microservice system

ActiveCN113220410BEngineeringCredential management
This invention discloses a credential management method for microservice systems, comprising the following three steps: obtaining token credentials returned by the microservice system; establishing a credential management module to uniformly manage token credentials and obtain real-time token refresh credentials; and distributing the token refresh credentials to clients. This credential management method for microservice systems enables unified management, centralized refreshing, and scheduling of token credentials, avoiding management chaos and reducing the burden on microservices.
Owner:GUANGZHOU TIANGAO SOFTWARE TECH CO LTD

Video Conferencing Systems

A video conferencing system organizes participants into groups based on stored organizational data and displays participants in a graphical interface with visual organization by group. The system maintains a knowledge base containing group-specific information and monitors communications during video conference calls using artificial intelligence. The system automatically provides relevant information from the knowledge base to participants during calls based on monitored communications. The system includes dynamic group reorganization capabilities that automatically reassign participants between groups or subgroups based on real-time analysis of conference data. Additional features include group isolation to virtual waiting rooms during sensitive discussions, permanent user URL login systems that eliminate multiple credential management, and automated post-call summary generation with action item extraction. The system integrates with multiple conference calling applications through a single login interface while providing contextual knowledge base access based on group membership and security permissions.
Owner:MOORE SLOAN

Credential management system and related methods

PCT designated stageWO2026106944A1FinanceUser identity/authority verificationDisplay deviceCredential management
Implementations of credential management methods may include receiving, from a credential-defining organization, a criteria corresponding with a credential. The method may include continually monitoring, through a monitoring module, the recipient organization according to a set of monitored organization actions associated with the criteria. The method may include generating, through a status token module, a credential status token. The method may include generating, through a compliance module, a digital compliance indicator corresponding to the credential status token. The digital compliance indicator may include either a compliance status with a compliance indicator operatively associated therewith or a non-compliance status with a non-compliance indicator operatively associated therewith. The method may include storing the credential status token and the digital compliance indicator in a credential wallet configured to automatically and in real-time synchronize with a digital display. The monitored organization may be dynamically and authoritatively monitored for adherence to the criteria.
Owner:LUCKY BADGER LLC