Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

51 results about "Credential management" patented technology

Credential Management. Credential Management is the set of practices that an organization uses to issue, track, update, and revoke credentials for identities within their context. A CREDENTIAL is authoritative evidence of an individual’s claimed identity.

Credential management and use in a distributed system

A method of provisioning a credential for a transaction between a payment device of a user and a transaction processing device is described. The method is implemented a third-party server remote from the payment device and the transaction processing device. The method comprises assigning the credential to the transaction and the user and provisioning the credential into the payment device for subsequent retrieval by the payment device. Assigning the credential to the transaction comprises: determining unique identifying information of the user; allocating a first user-identifying portion of the credential to correspond to the unique identifying information; determining a plurality of properties intrinsic to the transaction and encoding the plurality of properties into transaction-identifying information; and allocating a second transaction-identifying portion of the credential to correspond to the transaction-identifying information. The credential is associated with encrypted authentication data that is generated by the payment device during the transaction, and used for subsequent authentication of the transaction by the remote third-party server.
Owner:MASTERCARD INT INC

A distributed, verifiable, revocable, and scalable credential management method and system

This invention provides a distributed, verifiable, revocable, and scalable credential management method and system. The method includes: maintaining and managing verifiable credentials using a grouped hierarchical tree-structured RSA accumulator; registering a service center and publishing source computing services and root computing services corresponding to the grouped hierarchical tree-structured RSA accumulator through an entry service; and managing verifiable credentials through the source computing services and root computing services. This invention extends the application of traditional RSA accumulators by designing a grouped hierarchical tree-structured RSA accumulator, breaking down large-scale credential services into smaller, manageable parts, reducing single-point computing resources, and enabling flexible expansion of service capabilities, thus facilitating the large-scale application of verifiable credential services.
Owner:METERTEK TECH INC

Credential management method, and device

The embodiments of the present application relate to the technical field of electronic devices. Provided are a credential management method, and a device. The method is applied to a first device, and comprises: a first device determining that a user account is to be used to associate a target credential, wherein the target credential is used for encrypting user data managed by the first device; the first device further acquiring identity verification information of a user on the basis of the determination that the user account is to be used to associate the target credential; and the first device further sending the target credential to a third device when determining, on the basis of the identity verification information, that the identity verification of the user is successful. Therefore, it is not necessary for a user to manually save a target credential, thereby improving the convenience of credential management. Furthermore, the user can subsequently acquire the target credential only upon successful identity verification, such that the flexibility and security of credential management are improved.
Owner:HUAWEI TECH CO LTD

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Proxy FIDO authentication with signed identity tokens

The present disclosure is directed to a managed cloud-based FIDO authenticator implemented with a distributed switchboard system. The disclosed switchboard implementation enables proxy automation and management of FIDO-related service, including registration and / or access operations, between FIDO service requesting and relying parties. The described process is based on generation of a single pre-validated and personalized identity token, based on validation, tokenization and identity mapping of an identification record associated with a FIDO service-requesting entity (SRE). The generated FIDO identity token can be used as a validity signature for streamlined resolution of identity for generation of FIDO access credentials. The managed FIDO authenticator further provides a FIDO credential management and recovery features for user and / or client applications reliant upon FIDO-authenticated services. The distributed switchboard implementation further enables implementation of a federated FIDO services for a distributed application whereby various FIDO-reliant application components can perform their own FIDO authentication via the distributed switchboard.
Owner:CAPITAL ONE SERVICES LLC

Encoded identifiers for credential access and distribution

Systems and methods described herein relate to workforce credential management. A request is assigned to a first profile identified by a first identifier. The first profile includes worker credentials. An association between the first profile and a second profile identified by a second identifier in the request is stored. The first identifier is encoded into a digital code that is presentable by a first device associated with the first profile. Capturing of the digital code by a second device associated with the second profile is detected. In response to detecting the capturing of the digital code by the second device, the association between the first profile and the second profile is identified and at least a subset of the worker credentials is transmitted to the second device.
Owner:SAP SE

Identity verification middleware applied to PaaS platform

The invention relates to identity authentication middleware applied to a PaaS platform, and belongs to the field of data processing, and the identity authentication middleware comprises a user interface which is used for providing a task creation interface, a data uploading interface and an application configuration interface for a user; the identity verification module is used for verifying the identity of the user based on a bilinear pairing technology; the application program interface server is used for receiving an API request of a user; the composer is used for screening user requests initiated by the users passing the identity verification and determining resource scheduling schemes for all the user requests; the workflow engine is used for converting the resource scheduling scheme into a workflow; the execution adapter is used for converting the task description in the workflow into a specific operation command; the application directory module is used for storing all scientific applications supported by the PaaS platform and parameter templates of the scientific applications; the credential management module is used for managing keys of the user and the cloud service provider; and the message system is used for asynchronous communication among the components in the identity authentication middleware.
Owner:CHINA DATACOM CORP LTD

Intelligent credential management cabinet

1. The name of the design product: intelligent certificate management cabinet. 2. The use of the design product: for the storage and retrieval of identity cards, passports and other certificates. 3. The design points of the design product: in shape. 4. The picture or photo that best indicates the design points: perspective view 1.
Owner:CHANGCHUN PUKE TECHNOLOGY CO LTD

Techniques for container registry credentials management

Methods, systems, and devices to support techniques for container registry credentials management are described. An operator executed across a set of clusters may manage credentials for multiple namespaces distributed across multiple clusters. For example, the operator may identify a configuration of a namespace (e.g., detect a creation of a configuration, detect an update to a configuration) and may provision the namespace within the container image registry using an application programming interface (API) call transmitted to the registry. The operator may retrieve one or more credentials associated with the namespace from the container image registry based on an operational mode (e.g., an application mode, an infrastructure mode). The operator may store the one or more credentials to a database associated with the cluster.
Owner:ALLY FINANCIAL INC

MQTT voucher management method, device and equipment of embedded Internet of Things system and medium

The invention discloses an MQTT voucher management method and device of an embedded Internet of Things system, equipment and a medium, and relates to the field of Internet of Things, and the method comprises the steps: reading and decrypting encrypted MQTT voucher data corresponding to a voucher obtaining request needed by MQTT connection from a local storage of the equipment; if the preset triggering condition is met, obtaining new MQTT voucher data from the target server; encrypting the new MQTT voucher data to obtain new encrypted MQTT voucher data, storing the new encrypted MQTT voucher data in a local storage, and returning the new MQTT voucher data to the requester; and when it is detected that the MQTT connection is interrupted due to the fact that the voucher has a problem, clearing the corresponding encrypted MQTT voucher data in the local storage, obtaining new MQTT voucher data, and establishing a new MQTT connection according to the new MQTT voucher data. According to the invention, the security and reliability of MQTT communication of the embedded Internet of Things equipment are improved.
Owner:HANGZHOU MAITANG TECH CO LTD

System and method for managing data processing systems and hosted devices

Methods and systems for managing operation of data processing systems are disclosed. To manage operation of the data processing systems, the data processing systems may present a communication and credential management system. The communication and credential management system may be used to manage the operation of any number of devices hosted by the data processing systems. The communication and credential management system may include a device provisioning, validity, and removal process.
Owner:DELL PROD LP

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Cryptographic privacy-preserving transactions with verified credentials and ergonomic cryptography key infrastructure

A cryptographic secure transaction system comprising first and second cryptographic storage devices, each having a master key pair and a public key. A computer server maintains a list of globally unique names and associated public keys. The devices communicate via various signaling pathways, including centralized, decentralized, and broadcast-based pathways, using notification addresses derived from their public keys. A shared secret key generation algorithm generates a shared secret key using the devices' keys, and a distributed ledger records transactions using an address derived from the shared secret key. The system includes methods for managing verified credentials, recovering signals, and reconstructing transaction history using the shared secret keys and distributed ledger. The signaling pathways enable secure communication between devices, facilitating efficient credential management and transaction history reconstruction.
Owner:MATTERFI

Identity credential management method and apparatus, electronic device, and readable storage medium

The application provides an identity credential management method and device, electronic equipment and readable storage medium, and belongs to the technical field of communication. In the case that a target application requests upgrading, the application obtains upgrading information corresponding to the target application, wherein the upgrading information comprises upgrading data and an upgrading mode; controls the target application to generate a corresponding authorization file based on the upgrading mode; after generating the authorization file, upgrades the target application based on the upgrading data; and controls the upgraded target application to request a corresponding identity credential from a corresponding application background based on the authorization file. Through the present solution, the upgraded target application can request a corresponding identity credential from the application background based on the authorization file generated by the target application before upgrading. Thus, the application program can intelligently obtain an identity credential after updating and upgrading, thereby improving the efficiency of obtaining an identity credential.
Owner:WEIWEI SHANGHAI NETWORK TECH CO LTD

Smart home device direct connection communication method and apparatus

PendingCN122475965ANetwork keyTrunking
The present disclosure relates to the technical field of smart home communication, in particular to a smart home device direct connection communication method and device, by pre-storing network configuration information in the local storage of the device, the first device does not need to request network credentials from the gateway when initiating communication, eliminating the dependence of the communication initiation process on the real-time availability of the gateway, and normal communication between devices can still be maintained in scenarios such as gateway offline or network interruption; by encrypting the payload with a network key and carrying a network identifier in the data frame, the second device can independently complete the legality verification and content decryption of the frame based on the same credentials stored locally, without the gateway having to bear the responsibility of credential management or relay, completely decoupling the forwarding path of the gateway for both parties of the communication. By directly sending data frames on the radio frequency channel corresponding to the network configuration information, the control instruction reaches the target device via a single wireless path between devices, reducing the instruction transmission delay.
Owner:HANGZHOU LIFESMART TECH

System and method for securely retrieving from a secrets manager security credentials for migration of password protected data from a password protected data repository

An information handling system operating a security credential retrieval system may comprise a processor executing code instructions for a graphical user interface (GUI) to model, with visual integration elements, a flow diagram of a password protected data integration process for transmitting a keychain password to the security credential management system to retrieve security credentials for password protected data repositories, for supplying the security credentials to the password protected data repositories, and for migrating password protected data sets from the password protected data repositories to destination data repositories. The processor may execute connector code instructions for each of the visual integration elements, including data required for electronic communication in accordance with the security credential management system, the password protected data repositories, and the password protected data repositories, and to display any security credentials in the execution log recording the execution of the connector code instructions in encrypted ciphertext.
Owner:BOOMI LP

Service invocation system, method and trusted secure environment

This invention provides a service invocation system, method, and trusted security environment, belonging to the field of information security technology. The system includes a trusted security environment, a user side, and a service side. The trusted security environment stores target service invocation credentials in a secure storage area. The user side sends an authentication data generation request to the trusted security environment. The trusted security environment also generates corresponding authentication data based on the target service invocation credentials using a preset target authentication mechanism and returns it to the user side, wherein the authentication data does not contain the plaintext data of the target service invocation credentials. The user side also sends a service invocation request to the service side, the service invocation request carrying the authentication data. The service side authenticates the authentication data using the aforementioned target authentication mechanism, determines the corresponding service invocation result upon successful authentication, and returns it to the user side. Using this invention can improve the security of credential management.
Owner:SHENZHEN GOODIX TECH CO LTD

Systems and methods for credential holder support using AAA in non-3GPP access

ActiveUS12677148B1Internet privacyEngineering
A method is provided for accessing a non-public network (NPN) by a communication device utilizing a credential management system, including steps of (a) receiving, from the device through non-3GPP access means, a first authentication request at an authentication server function (AUSF) of a 5G core (5GC) in communication with the NPN, (b) sending a second authentication request from the AUSF to a network slice-specific authentication and authorization function (NSSAAF) of the 5GC, (c) transmitting, from the NSSAAF, an EAP response / identity message to an AAA server in communication with the credential management system, (d) performing, based on the transmitted EAP response / identity message, EAP-based authentication between the AAA server and the communications device, (e) receiving, at the NSSAAF from the AAA server, and EAP success message, (f) receiving, at the AUSF from the NSSAAF, a first authentication response, and (g) authenticating the communication device with the NPN.
Owner:CABLE TELEVISION LAB INC

Intelligent Password Management and Secure Login Methods under Dynamic Credential Control

This invention relates to the field of data security technology and proposes an intelligent password management and secure login method under dynamic credential control. The steps include: creating a high-strength password using a built-in password generator; dynamically calculating an account security trust score based on a neural network model trained from multi-dimensional behavioral data; and triggering a risk-based targeted password update when the trust score is too low. During the login process, a pre-built user behavior knowledge graph and a heterogeneous graph attention network model are used to calculate the context deviation of login events in real time, identify complex attack behaviors, and execute tiered protection responses. After the account is locked, a real-time risk score is initialized and dynamically adjusted based on multi-source risk signals and a nonlinear decay model to achieve intelligent risk unlocking. This invention realizes a transformation of credential management from static rules to dynamic cognition, significantly improving the defense capabilities against advanced threats such as credential stuffing and credential collision attacks, while optimizing user experience and operational efficiency.
Owner:BEIJING HONGSHAN INFORMATION TECH RES CO LTD

Credential management method and device, credential management system and related equipment

The invention discloses a credential management method and device, a credential management system and related equipment, relates to the technical field of information technology support, and aims to solve the problem that the storage security of credentials is low due to the fact that the security of a storage mode of existing server equipment is low. The method comprises: a server device sends a task calling request to a credential management system, the task calling request carrying target encrypted data and a task identifier, the task identifier being used for identifying a to-be-called task, and the target encrypted data being encrypted data obtained by the credential management system performing encryption processing on a vehicle-mounted credential; the credential management system receives a task calling request sent by the server-side equipment, and decrypts the target encrypted data to obtain a vehicle-mounted credential; a task call is then initiated to the vehicle device based on the on-board credential and the task identification. According to the embodiment of the invention, the safety of the vehicle-mounted credential storage and transmission process can be improved.
Owner:CHINA MOBILE SHANGHAI ICT CO LTD +2

Multi-trusted services manager (TSM) credential management

Aspects of the subject technology include receiving a first script from a first server associated with the first entity, wherein the first script is provided by the first server responsive to a first request from a non-native application process, providing the first script for provisioning a domain for a digital credential on the secure element, receiving a second script from the non-native application process, wherein the second script is provided to the non-native application process by a second server responsive to a second request from the non-native application process and the second server is associated with a second entity that is separate and independent from the first entity, providing the second script for provisioning the digital credential in the domain on the secure element, and providing an indication that the digital credential has been provisioned on the secure element.
Owner:APPLE INC

Wireless access credential system

An access control system and methods according to at least one embodiment leverage wireless access credentials to allow a user to securely gain access to a secured area using his or her mobile device. As such, a credentialed mobile device may permit access to the secured area without requiring a real-time connection to a credential management system and / or an administrative system.
Owner:SCHLAGE LOCK CO LLC

Relay chain-based cross-chain entity dynamic reputation and attribute voucher management method and system

The invention provides a cross-chain entity dynamic reputation and attribute voucher management method and system based on a relay chain, belongs to the technical field of block chain trusted computing, and aims to calculate and update a reputation value in real time on the basis of a cold start mechanism in combination with historical behavior data of a user cross-chain entity so as to improve the credibility of the block chain trusted computing. And dynamic layering is carried out according to Pareto distribution and a justice value principle, so that the problem of stiffness caused by a fixed upper limit is avoided. A high-reputation entity can obtain excitation such as high-authority access, service charge reduction and guarantee fund return, and a low-reputation entity faces constraints such as authority degradation and additional verification, so that a bidirectional driving mechanism giving consideration to fairness and constraint force is formed in a global range. According to the method, the problem that the reputation is difficult to establish in a distributed scene is solved, and the risks of identity resetting and reputation refreshing are further solved in a cross-chain scene, so that dynamic updating, cross-chain sharing and credible inheritance of the reputation are realized, and a safe and reliable basic support is provided for resource cooperation and value circulation in a Web3.0 detrusted environment.
Owner:BEIJING JIAOTONG UNIV +1

Offline digital asset generation and provisioning

A system for offline generation of digital assets includes: a security credential management system (SCMS) that is operable to generate and conditionally transmit digital assets; and a certificate authority communicatively connected to the SCMS by a communication network, the certificate authority being operable to receive the digital assets from the SCMS. The certificate authority is operable to securely provision a plurality of computerized devices based on the received digital assets, the certificate authority intermittently connects to the SCMS to receive the digital assets, the certificate authority is operable to securely provision the plurality of computerized devices while disconnected from the SCMS, and the provisioning by the certificate authority while disconnected from the SCMS is limited by a policy associated with the certificate authority.
Owner:INTEGRITY SECURITY SERVICES LLC

Method and system for performing task in access control device

Embodiments herein disclose a mobile access control system (1000) and method. The system (1000) comprises a mobile device (200), an access control device (300) and a credential management server (100). The mobile device (200) sends an access credential request message for the user to a credential management server (100), receives the credential data and a wireless communication range based on the user from the server (100), verifies the user based on a match between the credential data received from the server (100) and the credential data of the user stored in the mobile device (200), activates an access control application in the mobile device (200), and encrypts the received data. The access control device (300) establishes a connection with the mobile device (200) and receives the encrypted data from the mobile device (200) using the short-range wireless communication, decrypts the encrypted data, and controls the access to the secured area.
Owner:ARMATURA LLC

End-cloud collaborative large model reasoning method and intelligent device

The invention relates to the technical field of communication, particularly provides an end-cloud collaborative large model reasoning method and intelligent equipment, and aims to solve the problem of insufficient data protection in the existing cross-end model reasoning process. In order to achieve the purpose, the large model reasoning method based on cloud collaboration comprises the steps that a terminal transmits a temporary data key to a voucher management server deployed at the cloud end for storage, encrypts demand information through the temporary data key and then transmits the demand information to a target reasoning server deployed at the cloud end, and sending a key acquisition request to the voucher management server by the target reasoning server, decrypting the encrypted demand information ciphertext after the temporary data key is obtained, and reasoning the decrypted demand information by using the large model. According to the scheme, the demand data can be encrypted in the cross-end transmission process of the terminal and the cloud, and the user data such as demand information is isolated from the temporary data key, so that the security and confidentiality of cross-end data transmission are facilitated, and the leakage risk is reduced.
Owner:NIO TECH ANHUI CO LTD

An identity authentication middleware applied to a PaaS platform

The application relates to an identity authentication middleware applied to a PaaS platform, belonging to the field of data processing, and comprising the following: a user interface used for providing a user with interfaces for task creation, data uploading and application configuration; an identity authentication module used for authenticating the identity of a user based on a bilinear pairing technology; an application program interface server used for receiving an API request of the user; an orchestrator used for screening a user request initiated by the user who passes the identity authentication, and determining a resource scheduling scheme for each user request; a workflow engine used for converting the resource scheduling scheme into a workflow; an execution adapter used for converting a task description in the workflow into a specific job command; an application directory module used for storing all scientific applications and parameter templates supported by the PaaS platform; a credential management module used for managing the keys of the user and a cloud service provider; and a message system used for asynchronous communication between various components in the identity authentication middleware.
Owner:CHINA DATACOM CORP LTD

Business processing method and apparatus, operation and maintenance management platform, and electronic device

The application discloses a business processing method and device, an operation and maintenance management platform and electronic equipment. It relates to the field of cloud computing, and the method comprises the following steps: receiving a business processing request initiated by a target user, obtaining a first credential and a target key pair of the target user from a credential management system; calling a target logical interface in a source code management platform based on the first credential and the interface permission of the target user, and deploying the public key of the target key pair to the source code management platform through the target logical interface; obtaining a second credential from the credential management system, and initiating a target source code calling request to the source code management platform by the pipeline scheduling platform according to the second credential; obtaining the private key of the target key pair, and obtaining the target source code from the source code management platform based on the private key and the target source code calling request; and processing the business in the business processing request through the target source code by the pipeline scheduling platform. Through the application, the problem of low business processing efficiency caused by the lack of credential management in the related art is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Method and apparatus for credential handling

A privilege access management (PAM) appliance can receive an access request from an accessor device to access an endpoint device. The PAM appliance can establish a session via a secure connection between the accessor device and the endpoint device. The PAM appliance can transmit a request for credential information available for the accessor device to access the endpoint device from a credential management device. The credential management device can receive the request for credential information available for the accessor device to access the endpoint device. The credential management device can extract a set of credentials that are available for the accessor device from a plurality of credentials. The credential management device can provide at least one of the set of credentials to the endpoint device for the accessor device for the session.
Owner:BEYONDTRUST CORP