Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

64 results about "Credential management" patented technology

Credential Management. Credential Management is the set of practices that an organization uses to issue, track, update, and revoke credentials for identities within their context. A CREDENTIAL is authoritative evidence of an individual’s claimed identity.

Credential management and use in a distributed system

A method of provisioning a credential for a transaction between a payment device of a user and a transaction processing device is described. The method is implemented a third-party server remote from the payment device and the transaction processing device. The method comprises assigning the credential to the transaction and the user and provisioning the credential into the payment device for subsequent retrieval by the payment device. Assigning the credential to the transaction comprises: determining unique identifying information of the user; allocating a first user-identifying portion of the credential to correspond to the unique identifying information; determining a plurality of properties intrinsic to the transaction and encoding the plurality of properties into transaction-identifying information; and allocating a second transaction-identifying portion of the credential to correspond to the transaction-identifying information. The credential is associated with encrypted authentication data that is generated by the payment device during the transaction, and used for subsequent authentication of the transaction by the remote third-party server.
Owner:MASTERCARD INT INC

A distributed, verifiable, revocable, and scalable credential management method and system

This invention provides a distributed, verifiable, revocable, and scalable credential management method and system. The method includes: maintaining and managing verifiable credentials using a grouped hierarchical tree-structured RSA accumulator; registering a service center and publishing source computing services and root computing services corresponding to the grouped hierarchical tree-structured RSA accumulator through an entry service; and managing verifiable credentials through the source computing services and root computing services. This invention extends the application of traditional RSA accumulators by designing a grouped hierarchical tree-structured RSA accumulator, breaking down large-scale credential services into smaller, manageable parts, reducing single-point computing resources, and enabling flexible expansion of service capabilities, thus facilitating the large-scale application of verifiable credential services.
Owner:METERTEK TECH INC

Credential management method, and device

The embodiments of the present application relate to the technical field of electronic devices. Provided are a credential management method, and a device. The method is applied to a first device, and comprises: a first device determining that a user account is to be used to associate a target credential, wherein the target credential is used for encrypting user data managed by the first device; the first device further acquiring identity verification information of a user on the basis of the determination that the user account is to be used to associate the target credential; and the first device further sending the target credential to a third device when determining, on the basis of the identity verification information, that the identity verification of the user is successful. Therefore, it is not necessary for a user to manually save a target credential, thereby improving the convenience of credential management. Furthermore, the user can subsequently acquire the target credential only upon successful identity verification, such that the flexibility and security of credential management are improved.
Owner:HUAWEI TECH CO LTD

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Proxy FIDO authentication with signed identity tokens

The present disclosure is directed to a managed cloud-based FIDO authenticator implemented with a distributed switchboard system. The disclosed switchboard implementation enables proxy automation and management of FIDO-related service, including registration and / or access operations, between FIDO service requesting and relying parties. The described process is based on generation of a single pre-validated and personalized identity token, based on validation, tokenization and identity mapping of an identification record associated with a FIDO service-requesting entity (SRE). The generated FIDO identity token can be used as a validity signature for streamlined resolution of identity for generation of FIDO access credentials. The managed FIDO authenticator further provides a FIDO credential management and recovery features for user and / or client applications reliant upon FIDO-authenticated services. The distributed switchboard implementation further enables implementation of a federated FIDO services for a distributed application whereby various FIDO-reliant application components can perform their own FIDO authentication via the distributed switchboard.
Owner:CAPITAL ONE SERVICES LLC

Encoded identifiers for credential access and distribution

Systems and methods described herein relate to workforce credential management. A request is assigned to a first profile identified by a first identifier. The first profile includes worker credentials. An association between the first profile and a second profile identified by a second identifier in the request is stored. The first identifier is encoded into a digital code that is presentable by a first device associated with the first profile. Capturing of the digital code by a second device associated with the second profile is detected. In response to detecting the capturing of the digital code by the second device, the association between the first profile and the second profile is identified and at least a subset of the worker credentials is transmitted to the second device.
Owner:SAP SE

Identity verification middleware applied to PaaS platform

The invention relates to identity authentication middleware applied to a PaaS platform, and belongs to the field of data processing, and the identity authentication middleware comprises a user interface which is used for providing a task creation interface, a data uploading interface and an application configuration interface for a user; the identity verification module is used for verifying the identity of the user based on a bilinear pairing technology; the application program interface server is used for receiving an API request of a user; the composer is used for screening user requests initiated by the users passing the identity verification and determining resource scheduling schemes for all the user requests; the workflow engine is used for converting the resource scheduling scheme into a workflow; the execution adapter is used for converting the task description in the workflow into a specific operation command; the application directory module is used for storing all scientific applications supported by the PaaS platform and parameter templates of the scientific applications; the credential management module is used for managing keys of the user and the cloud service provider; and the message system is used for asynchronous communication among the components in the identity authentication middleware.
Owner:CHINA DATACOM CORP LTD

User identifier and credential management for wireless mobile networks

In one or more methods, devices, and / or systems, solutions are provided for managing wireless communication. For example, managing wireless communication may include a trust enabler client registration process implemented by one or more devices. For example, managing wireless communication may include a distributed user identifier registration process implemented by one or more devices (e.g., mobile device(s) initiated, network device(s) initiated, for multiple mobile devices, etc.). For example, managing wireless communication may include a distributed verifiable user credential generation process implemented by one or more devices (e.g., mobile device(s) initiated, network device(s) initiated, etc.).
Owner:INTERDIGITAL PATENT HOLDINGS INC

Intelligent credential management cabinet

1. The name of the design product: intelligent certificate management cabinet. 2. The use of the design product: for the storage and retrieval of identity cards, passports and other certificates. 3. The design points of the design product: in shape. 4. The picture or photo that best indicates the design points: perspective view 1.
Owner:CHANGCHUN PUKE TECHNOLOGY CO LTD

Techniques for container registry credentials management

Methods, systems, and devices to support techniques for container registry credentials management are described. An operator executed across a set of clusters may manage credentials for multiple namespaces distributed across multiple clusters. For example, the operator may identify a configuration of a namespace (e.g., detect a creation of a configuration, detect an update to a configuration) and may provision the namespace within the container image registry using an application programming interface (API) call transmitted to the registry. The operator may retrieve one or more credentials associated with the namespace from the container image registry based on an operational mode (e.g., an application mode, an infrastructure mode). The operator may store the one or more credentials to a database associated with the cluster.
Owner:ALLY FINANCIAL INC

Dynamic collaborative access credential security management method and system

The invention provides a dynamic collaborative access credential security management method and system, belongs to the technical field of network security, and aims to solve the problems of isolation and response lag of a security credential management module. The method comprises the following steps: establishing a normal use behavior baseline model of the security credential; analyzing the current use behavior in real time to generate a risk index; in response to the risk index meeting the risk condition or receiving an external management event, automatically executing a corresponding security policy; after the restrictive strategy is executed, when the risk meets the recovery condition, the restriction is automatically released. Through linkage behavior analysis, permission configuration and gateway management and control, cooperative defense is realized, the security and management efficiency are improved, and the service influence is reduced.
Owner:SHENZHEN SNOWBALL TECHNOLOGY CO LTD

MQTT voucher management method, device and equipment of embedded Internet of Things system and medium

The invention discloses an MQTT voucher management method and device of an embedded Internet of Things system, equipment and a medium, and relates to the field of Internet of Things, and the method comprises the steps: reading and decrypting encrypted MQTT voucher data corresponding to a voucher obtaining request needed by MQTT connection from a local storage of the equipment; if the preset triggering condition is met, obtaining new MQTT voucher data from the target server; encrypting the new MQTT voucher data to obtain new encrypted MQTT voucher data, storing the new encrypted MQTT voucher data in a local storage, and returning the new MQTT voucher data to the requester; and when it is detected that the MQTT connection is interrupted due to the fact that the voucher has a problem, clearing the corresponding encrypted MQTT voucher data in the local storage, obtaining new MQTT voucher data, and establishing a new MQTT connection according to the new MQTT voucher data. According to the invention, the security and reliability of MQTT communication of the embedded Internet of Things equipment are improved.
Owner:HANGZHOU MAITANG TECH CO LTD

System and method for managing data processing systems and hosted devices

Methods and systems for managing operation of data processing systems are disclosed. To manage operation of the data processing systems, the data processing systems may present a communication and credential management system. The communication and credential management system may be used to manage the operation of any number of devices hosted by the data processing systems. The communication and credential management system may include a device provisioning, validity, and removal process.
Owner:DELL PROD LP

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Cryptographic privacy-preserving transactions with verified credentials and ergonomic cryptography key infrastructure

A cryptographic secure transaction system comprising first and second cryptographic storage devices, each having a master key pair and a public key. A computer server maintains a list of globally unique names and associated public keys. The devices communicate via various signaling pathways, including centralized, decentralized, and broadcast-based pathways, using notification addresses derived from their public keys. A shared secret key generation algorithm generates a shared secret key using the devices' keys, and a distributed ledger records transactions using an address derived from the shared secret key. The system includes methods for managing verified credentials, recovering signals, and reconstructing transaction history using the shared secret keys and distributed ledger. The signaling pathways enable secure communication between devices, facilitating efficient credential management and transaction history reconstruction.
Owner:MATTERFI

Identity credential management method and apparatus, electronic device, and readable storage medium

The application provides an identity credential management method and device, electronic equipment and readable storage medium, and belongs to the technical field of communication. In the case that a target application requests upgrading, the application obtains upgrading information corresponding to the target application, wherein the upgrading information comprises upgrading data and an upgrading mode; controls the target application to generate a corresponding authorization file based on the upgrading mode; after generating the authorization file, upgrades the target application based on the upgrading data; and controls the upgraded target application to request a corresponding identity credential from a corresponding application background based on the authorization file. Through the present solution, the upgraded target application can request a corresponding identity credential from the application background based on the authorization file generated by the target application before upgrading. Thus, the application program can intelligently obtain an identity credential after updating and upgrading, thereby improving the efficiency of obtaining an identity credential.
Owner:WEIWEI SHANGHAI NETWORK TECH CO LTD

Smart home device direct connection communication method and apparatus

PendingCN122475965ANetwork keyTrunking
The present disclosure relates to the technical field of smart home communication, in particular to a smart home device direct connection communication method and device, by pre-storing network configuration information in the local storage of the device, the first device does not need to request network credentials from the gateway when initiating communication, eliminating the dependence of the communication initiation process on the real-time availability of the gateway, and normal communication between devices can still be maintained in scenarios such as gateway offline or network interruption; by encrypting the payload with a network key and carrying a network identifier in the data frame, the second device can independently complete the legality verification and content decryption of the frame based on the same credentials stored locally, without the gateway having to bear the responsibility of credential management or relay, completely decoupling the forwarding path of the gateway for both parties of the communication. By directly sending data frames on the radio frequency channel corresponding to the network configuration information, the control instruction reaches the target device via a single wireless path between devices, reducing the instruction transmission delay.
Owner:HANGZHOU LIFESMART TECH

System and method for securely retrieving from a secrets manager security credentials for migration of password protected data from a password protected data repository

An information handling system operating a security credential retrieval system may comprise a processor executing code instructions for a graphical user interface (GUI) to model, with visual integration elements, a flow diagram of a password protected data integration process for transmitting a keychain password to the security credential management system to retrieve security credentials for password protected data repositories, for supplying the security credentials to the password protected data repositories, and for migrating password protected data sets from the password protected data repositories to destination data repositories. The processor may execute connector code instructions for each of the visual integration elements, including data required for electronic communication in accordance with the security credential management system, the password protected data repositories, and the password protected data repositories, and to display any security credentials in the execution log recording the execution of the connector code instructions in encrypted ciphertext.
Owner:BOOMI LP

Service invocation system, method and trusted secure environment

This invention provides a service invocation system, method, and trusted security environment, belonging to the field of information security technology. The system includes a trusted security environment, a user side, and a service side. The trusted security environment stores target service invocation credentials in a secure storage area. The user side sends an authentication data generation request to the trusted security environment. The trusted security environment also generates corresponding authentication data based on the target service invocation credentials using a preset target authentication mechanism and returns it to the user side, wherein the authentication data does not contain the plaintext data of the target service invocation credentials. The user side also sends a service invocation request to the service side, the service invocation request carrying the authentication data. The service side authenticates the authentication data using the aforementioned target authentication mechanism, determines the corresponding service invocation result upon successful authentication, and returns it to the user side. Using this invention can improve the security of credential management.
Owner:SHENZHEN GOODIX TECH CO LTD

Protective deactivation of GDPR wallet

A credential management system stores GDPR wallets of individuals who consent to share their private data with various consumers, and constructs GDPR directories for the consumers allowing access to the wallet records. If an individual decides they no longer want to share their records with a specific consumer, the system deactivates access to the specific consumer for compliance with privacy laws. However, the consumer may have a legitimate need to retain the information in which case the system will still allow access to records that were available prior to deactivation, but will block access to any newly added records in the individual's wallet. An individual may also automatically deactivate all current consumer connections; if this global deactivation happens after a specific consumer has been already been deactivated, the system will use two different deactivation dates for the access filter depending on which consumer is attempting to view the wallet.
Owner:HEALTHCAREPOINT COM CORP

Systems and methods for credential holder support using AAA in non-3GPP access

ActiveUS12677148B1Internet privacyEngineering
A method is provided for accessing a non-public network (NPN) by a communication device utilizing a credential management system, including steps of (a) receiving, from the device through non-3GPP access means, a first authentication request at an authentication server function (AUSF) of a 5G core (5GC) in communication with the NPN, (b) sending a second authentication request from the AUSF to a network slice-specific authentication and authorization function (NSSAAF) of the 5GC, (c) transmitting, from the NSSAAF, an EAP response / identity message to an AAA server in communication with the credential management system, (d) performing, based on the transmitted EAP response / identity message, EAP-based authentication between the AAA server and the communications device, (e) receiving, at the NSSAAF from the AAA server, and EAP success message, (f) receiving, at the AUSF from the NSSAAF, a first authentication response, and (g) authenticating the communication device with the NPN.
Owner:CABLE TELEVISION LAB INC

Intelligent Password Management and Secure Login Methods under Dynamic Credential Control

This invention relates to the field of data security technology and proposes an intelligent password management and secure login method under dynamic credential control. The steps include: creating a high-strength password using a built-in password generator; dynamically calculating an account security trust score based on a neural network model trained from multi-dimensional behavioral data; and triggering a risk-based targeted password update when the trust score is too low. During the login process, a pre-built user behavior knowledge graph and a heterogeneous graph attention network model are used to calculate the context deviation of login events in real time, identify complex attack behaviors, and execute tiered protection responses. After the account is locked, a real-time risk score is initialized and dynamically adjusted based on multi-source risk signals and a nonlinear decay model to achieve intelligent risk unlocking. This invention realizes a transformation of credential management from static rules to dynamic cognition, significantly improving the defense capabilities against advanced threats such as credential stuffing and credential collision attacks, while optimizing user experience and operational efficiency.
Owner:BEIJING HONGSHAN INFORMATION TECH RES CO LTD

Credential management method and device, credential management system and related equipment

The invention discloses a credential management method and device, a credential management system and related equipment, relates to the technical field of information technology support, and aims to solve the problem that the storage security of credentials is low due to the fact that the security of a storage mode of existing server equipment is low. The method comprises: a server device sends a task calling request to a credential management system, the task calling request carrying target encrypted data and a task identifier, the task identifier being used for identifying a to-be-called task, and the target encrypted data being encrypted data obtained by the credential management system performing encryption processing on a vehicle-mounted credential; the credential management system receives a task calling request sent by the server-side equipment, and decrypts the target encrypted data to obtain a vehicle-mounted credential; a task call is then initiated to the vehicle device based on the on-board credential and the task identification. According to the embodiment of the invention, the safety of the vehicle-mounted credential storage and transmission process can be improved.
Owner:CHINA MOBILE SHANGHAI ICT CO LTD +2

Multi-trusted services manager (TSM) credential management

Aspects of the subject technology include receiving a first script from a first server associated with the first entity, wherein the first script is provided by the first server responsive to a first request from a non-native application process, providing the first script for provisioning a domain for a digital credential on the secure element, receiving a second script from the non-native application process, wherein the second script is provided to the non-native application process by a second server responsive to a second request from the non-native application process and the second server is associated with a second entity that is separate and independent from the first entity, providing the second script for provisioning the digital credential in the domain on the secure element, and providing an indication that the digital credential has been provisioned on the secure element.
Owner:APPLE INC

Wireless access credential system

An access control system and methods according to at least one embodiment leverage wireless access credentials to allow a user to securely gain access to a secured area using his or her mobile device. As such, a credentialed mobile device may permit access to the secured area without requiring a real-time connection to a credential management system and / or an administrative system.
Owner:SCHLAGE LOCK CO LLC

Systems and Methods for Countering Co-Existence Attack

Embodiments described herein provide systems and methods to prevent, or provide a countermeasure, to a co-existence attack, for example, that may occur in a Security Credential Management System (SCMS) where both regular butterfly key (RBK) protocol and unified butterfly key (UBK) protocol are supported. Embodiments described herein provide, support, employ, or implement hardware acceleration for a Hardware Security Module (HSM), for example, for cryptographic operations (e.g., block ciphers, digital signature schemes, and key exchange protocols).
Owner:LG ELECTRONICS INC +1

Relay chain-based cross-chain entity dynamic reputation and attribute voucher management method and system

The invention provides a cross-chain entity dynamic reputation and attribute voucher management method and system based on a relay chain, belongs to the technical field of block chain trusted computing, and aims to calculate and update a reputation value in real time on the basis of a cold start mechanism in combination with historical behavior data of a user cross-chain entity so as to improve the credibility of the block chain trusted computing. And dynamic layering is carried out according to Pareto distribution and a justice value principle, so that the problem of stiffness caused by a fixed upper limit is avoided. A high-reputation entity can obtain excitation such as high-authority access, service charge reduction and guarantee fund return, and a low-reputation entity faces constraints such as authority degradation and additional verification, so that a bidirectional driving mechanism giving consideration to fairness and constraint force is formed in a global range. According to the method, the problem that the reputation is difficult to establish in a distributed scene is solved, and the risks of identity resetting and reputation refreshing are further solved in a cross-chain scene, so that dynamic updating, cross-chain sharing and credible inheritance of the reputation are realized, and a safe and reliable basic support is provided for resource cooperation and value circulation in a Web3.0 detrusted environment.
Owner:BEIJING JIAOTONG UNIV +1

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Method and system for performing task in access control device

Embodiments herein disclose a mobile access control system (1000) and method. The system (1000) comprises a mobile device (200), an access control device (300) and a credential management server (100). The mobile device (200) sends an access credential request message for the user to a credential management server (100), receives the credential data and a wireless communication range based on the user from the server (100), verifies the user based on a match between the credential data received from the server (100) and the credential data of the user stored in the mobile device (200), activates an access control application in the mobile device (200), and encrypts the received data. The access control device (300) establishes a connection with the mobile device (200) and receives the encrypted data from the mobile device (200) using the short-range wireless communication, decrypts the encrypted data, and controls the access to the secured area.
Owner:ARMATURA LLC