Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

53 results about "Directory service" patented technology

In computing, directory service or name service maps the names of network resources to their respective network addresses. It is a shared information infrastructure for locating, managing, administering and organizing everyday items and network resources, which can include volumes, folders, files, printers, users, groups, devices, telephone numbers and other objects. A directory service is a critical component of a network operating system. A directory server or name server is a server which provides such a service. Each resource on the network is considered an object by the directory server. Information about a particular resource is stored as a collection of attributes associated with that resource or object.

Privilege assurance of computer network environments

A system and method for privilege assurance protection of computer networks that remedies the deficiencies of the current directory service structure. The system uses a software agent to collect and store snapshots of all network resources on a computer network by identifying network domains, searching the directory service of each domain for network resources, and periodically querying the network resources for changes. The software agent communicates with a backend server which provides searching, querying, storage, administrative and other functionality to the agent via remote procedure calls.
Owner:QOMPLX INC

Universal method for realizing multiple conditions and search based on LDAP (Lightweight Directory Access Point)

The invention provides a universal method for realizing multi-condition and search based on LDAP, and belongs to the technical field of data retrieval of directory service and identity management. A user defines query conditions including attributes, values and logical relationships through a configuration file, a visual interface or an interface; the system parses the query condition model into a query condition model supporting nested combination of AND, OR and NOT by using a parser, and performs legality check and error prompt; and then a generator dynamically generates a filtering statement conforming to the LDAP grammar specification according to the model, and query is executed through an LDAP client. In order to improve the performance, common condition caching and high-frequency statement pre-compiling optimization are introduced, and an asynchronous query mode is supported. And the query result is returned in the form of structured data, and is matched with a display interface to support screening, sorting and exporting, so that the flexibility and maintainability of multi-condition query are improved.
Owner:UNICLOUD TECH CO LTD

Multi-system single sign-on security management method and system, storage medium and equipment

The invention relates to the technical field of information security, and discloses a multi-system single sign-on security management method and system, a storage medium and equipment, and the method comprises the steps: building a deep integration architecture between a directory service and an identity management server, and achieving the bidirectional synchronization of user attributes and security policies; a unified multi-factor authentication process and a security defense strategy are configured in the identity management server; by implementing password expiration risk assessment, multi-channel reminding and password self-service modification service, intelligent password life cycle active management is realized; intelligent account locking and self-adaptive unlocking based on multiple factors are implemented, and differentiated locking duration is dynamically calculated and executed; a cross-system unified session management and cooperative control mechanism is established, session anomaly real-time detection and scoring are performed through multi-dimensional feature fusion, one-point logout of global failure is realized, cross-system unified authentication, active security protection and cooperative management and control are realized, and the security and operation and maintenance efficiency of enterprise identity management are remarkably improved.
Owner:LINKPLAY TECHNOLOGY INC NANJING

Agentless active directory granular level restore from virtual machine level backups

A method for managing data protection includes obtaining, by a backup server, a restoration request for a virtual machine (VM) that includes an active directory (AD) application, and wherein the AD application comprises a set of AD objects and a directory service for managing the set of AD objects, parsing a VM backup corresponding to the VM, stored in a backup storage system, to identify an AD application backup of the AD application using metadata stored in an index and search microservice of the backup server, mounting, using an AD recovery microservice, backups of the set of AD objects of the AD application backup to the production environment, and providing browse and restoration services to the production environment based on the mounting of the AD objects and using the AD recovery microservice.
Owner:DELL PROD LLC

Unified workspace for thin, remote, and SAAS applications

Application-manager software authenticates a user of a client device over a channel. The authentication operation is performed using a directory service. The application-manager software presents a plurality of applications in a GUI displayed by the client device. The plurality of applications depends on the authentication, the client device, and the channel. And the plurality of applications includes a thin application and a software-as-a-service (SaaS) application. The application-manager software receives a selection as to an application from the user. If the selection is for the SaaS application, the application-manager software provisions the SaaS application. The provision includes automatically logging the user onto an account with a provider of the SaaS application using a single sign-on and connecting the user to the account so that the user can interact with the SaaS application. If the selection is for the thin application, the application manager software launches the thin application.
Owner:OMNISSA LLC

A trusted business card call system and method

ActiveCN120301975BInterconnection arrangementsCalling susbscriber number recording/indicationBusiness cardInternet privacy
The application discloses a trusted business card calling system and method, comprising: an electronic authentication module, which is used for issuing a digital certificate for an enterprise or an institution with a first user; a business card issuing module, which is used for editing and exporting a vCard format file of the first user's business card information, and signing the business card of the first user's vCard format file by using a private key of the digital certificate to obtain a trusted business card, and publishing the trusted business card to a directory server for a calling terminal to download; the calling terminal and the called terminal; the directory server, which is used for authenticating other system structures, and providing specified access rights for the calling terminal and the called terminal, and is used for the calling terminal to download the trusted business card and the called terminal to verify the trusted business card; the calling terminal downloads the trusted business card of the first user from the directory server, and transmits the trusted business card to the called terminal for display. The application has the advantages of independent issuing by the enterprise or the institution, guaranteeing the authenticity of work role information, relatively low implementation cost, better compatibility with existing systems and applications, and the like.
Owner:GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD

Security policy framework for cloud environments

ActiveUS12676892B2Data sourceEngineering
The present disclosure includes systems and methods for a security policy framework. Various embodiments include responsive to receiving a trigger, fetching one or more policies from a policy catalog service; compiling the one or more policies into a query, wherein the one or more policies can be compiled into a plurality of different query languages; executing the query over customer data, the customer data being located in one or more data sources; and persisting results of the query.
Owner:ZSCALER INC

Routing digital messages via authentication networks

A system and method for routing digital messages via authentication networks are provided. The method may include, at a first directory server, maintaining a routing data structure with routing information. The routing information may include first and second destination endpoint identifiers. The method may include updating a first source endpoint with configuration to transmit messages to a first destination endpoint and messages to a second destination endpoint, associated with respective endpoint identifiers. The method may include, in response to receiving a first message associated with a first destination endpoint identifier, routing the first message to a first destination endpoint and, in response to receiving a second message associated with a second destination endpoint identifier, routing the second message to a destination interface of a hosted system. The system may include a first directory server and a hosted system for performing the method.
Owner:ENTERSECT INT

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Secure directory services

Secure directory services are disclosed. A cryptographic hash of a foreign identifier associated with a potential user is received. A determination is made that the received cryptographic hash of the foreign identifier matches a representation of a stored entry. In response to the determination, a transmission of a representation of a native identifier associated with the stored entry is transmitted to the sender of the cryptographic hash of the foreign identifier.
Owner:WICKR INC +1

Multi-resolution grid data real-time online visualization method and device

The invention provides a real-time online visualization method and device for multi-resolution grid data, and belongs to the technical field of data processing and visualizing.The method comprises the steps that firstly, grid data are merged into sequence columns in the Z direction to form a multi-resolution stacked grid model, the multi-resolution stacked grid model is stored in an HDF5 file according to resolution levels, and parallel I / O is achieved in combination with MinIO distributed object storage; secondly, a Z-Order index and directory server strategy is designed, and the data scheduling and transmission efficiency is improved; a browser end adopts a virtual quadtree structure to organize data, and realizes multi-thread real-time data receiving in combination with WebWorker and WebSocket, so that the blockage of a main thread is avoided; finally, the LOD level is dynamically selected based on the viewpoint distance, and efficient volume rendering is achieved through a GPU texture array and LOD InfoTexture. According to the method, online real-time updating is supported, the loading delay is remarkably reduced, and the visual frame rate is improved.
Owner:齐鲁空天信息研究院

A cross-domain sharing system and method for earth data resources

The application discloses a cross-domain sharing system and method for earth data resources, an earth data resource directory service, structural analysis of earth data resources of different sources and different types, extraction of core meta information of the earth data resources, establishment of a unified earth data resource model, instantiation of the earth data resource model, correlation and integration of earth resource data in each domain and the whole domain, construction of an earth data resource directory, establishment of a unique data identifier by using data types, spatial ranges, spatial levels and time ranges; a cross-domain resource acquisition module dynamically positions the earth data resources under the premise of balancing resources and efficiency, realizes efficient acquisition of the earth data resources across domains based on reverse proxy technology, restricts cross-domain acquisition behaviors of users from two aspects of permission hierarchical control and risk behavior limitation, intercepts user acquisition beyond the permission definition, and implements acquisition limitation for acquisition behaviors with potential risks; and a mixed backup mechanism of the earth data resources comprehensively considers acquisition efficiency and security factors in the backup process of the earth data resources, and provides mixed earth data resource division strategies and copy migration strategies. The application improves resource utilization efficiency by establishing a cross-region coordination mechanism, and promotes deep sharing of the earth data resources.
Owner:SUZHOU AEROSPACE INFORMATION RES INST

A method and apparatus for real-time online visualization of multi-resolution grid data

This invention provides a method and apparatus for real-time online visualization of multi-resolution grid data, belonging to the field of data processing and visualization technology. First, the grid data is merged into hierarchical columns along the Z-axis to form a multi-resolution stacked grid model, which is then stored in HDF5 files according to resolution levels. Parallel I / O is achieved using MinIO distributed object storage. Second, a Z-Order index and directory server strategy are designed to improve data scheduling and transmission efficiency. On the browser side, a virtual quadtree structure is used to organize the data, and WebWorker and WebSocket are used to achieve multi-threaded real-time data reception, avoiding main thread blocking. Finally, the LOD level is dynamically selected based on the viewpoint distance, and efficient volume rendering is achieved using GPU texture arrays and LODInfoTexture. This method supports online real-time updates, significantly reduces loading latency, and improves the visualization frame rate.
Owner:齐鲁空天信息研究院

Hybrid directory management method and system for automobile industry trusted data space

The invention discloses a mixed directory management method and system for a trusted data space in the automobile industry, and aims to solve the contradiction between sovereignty protection and query efficiency of pure centralized and pure federated directory architecture. The method is based on a hybrid architecture of participating nodes, centralized directory services and data consumers, and through metadata acquisition preprocessing and automatic grading, public layer metadata is desensitized and differentially synchronized to a central directory; and completing query request verification and standardization in combination with DID identity authentication, intelligently selecting a query path by a routing engine according to multi-dimensional cost, executing distributed fine-grained authorization on business / sensitive layer metadata, and finally aggregating multi-source result feedback. Experiments prove that the query efficiency of the method is improved by 1-2 orders of magnitude compared with a pure federation mode, the synchronization bandwidth is reduced by 97% compared with a pure centralization mode, the balance of efficient global discovery and strict sovereign protection of data resources in the automobile industry is realized, and the method adapts to large-scale collaboration scenes such as supply chain collaboration.
Owner:AUTOMOTIVE DATA OF CHINA (TIANJIN) CO LTD

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Connector for private certificate authority and directory service

A method includes receiving, by a service operating in a provider network comprising a plurality of tenants, a request from a user device of one or more user devices in a user VPC of a first tenant of the plurality of tenants, wherein the request includes service identity information and authentication information. The method also includes providing, by the service, the request to an intermediary service operating in the provider network, wherein the intermediary service associates the service identity information with information maintained by the intermediary service associated with the tenants, and authenticating, by the intermediary service and with a domain controller, the request based on the authentication information. The method further includes, after the request is successfully authenticated, generating, by a private certificate authority (PCA) in a service VPC separate from the user VPC, a certificate based on the request, and providing the certificate to the user device.
Owner:AMAZON TECH INC

Data directory management system and method based on metadata driving

The invention discloses a data directory management system and method based on metadata driving, and the system comprises a metadata collection module which is used for automatically collecting the metadata information of structured and unstructured data from a plurality of business data sources, and a metadata analysis and classification module which is used for analyzing the collected metadata and classifying the metadata information of the structured and unstructured data. The metadata analysis module is used for analyzing metadata and classifying the analyzed metadata according to a predefined classification rule, the data directory generation module is used for automatically constructing and updating a multi-level data directory structure according to the classified metadata, and the directory service interface module is used for providing a standardized data directory retrieval and access interface. Through automatic metadata acquisition and real-time processing, the problems of update lag and poor consistency caused by manual maintenance are solved, intelligent data classification and dynamic directory construction are realized by means of a configurable rule engine, the intelligibility and management flexibility of data assets are improved, and through a unified service interface and refined authority control, the method is simple and convenient to operate and high in practicability.
Owner:商飞软件有限公司 +1

Efficient and secure authentication system

A system and method of establishing a resource provider as a trusted list entry is disclosed. The method includes receiving, by a directory server computer, an indication from a user that a resource provider is trusted. The directory server computer is programmed to provide a first level of authentication. The method then includes storing data representing the indication from the user that the resource provider is trusted in a database. The method then includes receiving, from the user, an authentication request message to interact at the resource provider computer and determining that the data representing the indication from the user that the resource provider is trusted is present. In response to the determination, the method includes providing a second level of authentication to the user before the user is allowed to complete the interaction. The second level of authentication is lower than the first level.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Device social media integration with cloud solutions for issue resolutions

A computer system receives a request from a device to join a device social network supported by an enterprise device social media cloud. The request comprises a user packet that includes a network social name, enterprise credentials of the device, and device information metadata. The computer system validates the user packet. When the validation is successful, the computer system calls a directory service to create a directory service user entry corresponding to the device in the directory service. When the creation of the directory service user entry is successful, the computer system creates a device social network user corresponding to the device in the enterprise device social media cloud.
Owner:AMERICAN MEGATRENDS

Metadata management method and device for AI data lake, medium and electronic equipment

A metadata management method and device of an AI data lake, a medium, and an electronic device, relating to the technical field of computers, the method comprising: in response to a first operation request for first metadata, parsing the first operation request to obtain first request information; a preset directory structure comprising at least a tenant domain, a directory domain, and an object domain nested in stages; in response to logical addressing information pointing to a first directory service of the plurality of metadata directory services, routing the first operation request to a first connector corresponding to the first directory service, the connectors corresponding to different metadata directory services having mutually isolated runtime environments, or the connectors corresponding to different types of metadata directory services having mutually isolated runtime environments; and executing the first operation on the first metadata in the first directory service through the first connector to obtain an execution result. Thus, tenant-level isolation and fine-grained access control of metadata are achieved, and dependency conflicts between different connectors are avoided.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Directory Service Recommender Assessment & Scoring

A cybersecurity service assesses, scores, and / or prioritizes activities associated with a directory service. When the directory service is requested to change a directory service assignment, the directory service may first request a verdict from the cybersecurity service. The cybersecurity service may use profiling and / or machine learning to predict directory service assignments. The cybersecurity service may then score and prioritize requests to change / update directory service assignments. Small deviations from predicted directory service assignments, for example, may indicate harmless / normal directory service activity. Larger deviations, though, may indicate abnormal directory service activity. Larger deviations may even indicate malicious directory service activity, such as permission escalation and cyberbreaches. Scoring and prioritization allows for resource allocation and timely mitigations by human experts.
Owner:CROWDSTRIKE

Method and system for providing time-critical services

ActiveCN116210215BTransmissionCommunication interfaceTime critical
In order to provide time-critical services, the services are each assigned at least one server component (111, 121), which is formed by a software container that can be loaded into a process control environment (102) and executed there. A virtual IP stack is provided for each server component, which is connected to a virtual switch (104) included in the process control environment. The services also each include a directory service component (112, 122) for determining the services provided within the process control environment. The directory service components are connected to each other via a communication interface (105) that is separate from the virtual switch and the virtual IP stack of the server components. An aggregator component (131) formed by a further software container is connected to the separate communication interface and makes comparative information about the services provided by the server components available outside the process control environment.
Owner:SIEMENS AG

Active directory data protection by leveraging virtual machine backup with change notification-based active directory backup

A method for managing data protection includes initiating, by a backup server, discovery for a new virtual machine (VM) in a production environment, performing, using an active directory listener (AD), listening on active directory (AD) applications in the production environment, wherein the new VM executes one of the AD applications, and wherein the one of the AD applications comprises a set of AD objects and a directory service for managing the set of AD objects, storing, based on the listening, monitored changes to obtain stored changes in the AD applications, generating a change report based on the stored changes, and using the change report to perform an incremental backup of the new VM and store a VM backup of the new VM and an AD application backup of the one of the AD applications in a backup storage system.
Owner:DELL PROD LP

Device social media integration with cloud solutions for issue resolutions

A computer system receives a request from a device to join a device social network supported by an enterprise device social media cloud. The request comprises a user packet that includes a network social name, enterprise credentials of the device, and device information metadata. The computer system validates the user packet. When the validation is successful, the computer system calls a directory service to create a directory service user entry corresponding to the device in the directory service. When the creation of the directory service user entry is successful, the computer system creates a device social network user corresponding to the device in the enterprise device social media cloud.
Owner:AMERICAN MEGATRENDS

Method and system for managing heterogeneous directory

The invention relates to the technical field of data sharing, in particular to a method and system for managing heterogeneous directories, comprising the following steps: constructing a reference directory management system and a government affair data reference directory library, the reference directory library being used for storing and managing directory data from different sources and different data structures and providing a full-range directory service, fusion, deduplication and association functions of directory data generated in multiple modes and multiple stages are achieved; the method has the beneficial effects that directory data with different sources and different data structures are stored, managed, treated, circulated and used by constructing the reference directory management system and the reference directory library. An ideal representation model is established according to the essence, correlation, development and evolution process and other information of the catalogue, and catalogue data life cycle management process links are supplemented, perfected and established.
Owner:BEIJING INSPUR CLOUD COMPUTING CO LTD

Converged communication server resource scheduling method and system

The invention relates to the field of network communication, and discloses a converged communication server resource scheduling method and system, and the method comprises the steps: receiving a user communication request, and converting a heterogeneous protocol into a standard format in a unified manner through a protocol conversion layer; identifying a target service module based on the request type, wherein the service module comprises at least two of a local regeneration service, a boundary service, a multi-point control unit service and an address book service; querying real-time resource monitoring data, and dynamically allocating CPU cores, memories and network bandwidth resources according to a preset priority strategy; starting a target service instance in a containerized environment, and performing communication between instances through the service grid; and executing the service logic and returning a result, and recording resource consumption data to the performance database. According to the invention, the resource utilization rate of a single server can be improved, and the service quality of multiple services is guaranteed.
Owner:CHINA YANGTZE POWER

Api request data sharing method and apparatus, electronic device, and storage medium

This invention provides an API request data sharing method, apparatus, electronic device, and storage medium. The method includes: calling a data exchange service to verify the API interface based on an application programming interface (API) request initiated by a data consumer; if the API interface verification is successful, obtaining target data from a data provider based on the API interface request; matching the target data with data on a first blockchain; and if the target data and the first blockchain data are successfully matched, feeding the target data back to the data consumer through a directory service. API interface verification facilitates subsequent accountability and improves the security of data sharing.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +2

Intake pipeline for augmented reality content generator

The subject technology receives information about a product. The subject technology generates a 3D model file of the product in a first format. The subject technology converts the 3D model file into a 3D object file in a second format. The subject technology associates the 3D object file with the product in a product catalog service. The subject technology publishes an augmented reality (AR) content generator corresponding to the product.
Owner:SNAP INC

Integrating a wallet client with federated directory services

PendingUS20250315880A1Payment architectureCommerceMerchant servicesComputer network
Systems and methods provide for integrating a wallet client with federated directory services are disclosed herein. By integrating merchant services, such as directory services with a wallet service provider, wallet clients on mobile devices can have access to all merchant listings without having to manually add each directory service. The system disclosed herein integrates Chamber of Commerce directory service listings with the wallet client, such that when a request for a merchant directory service is received from a device associated with the wallet client, the request is forwarded to a federated directory service wallet system interface operated by a Chamber of Commerce site. Supply chain data that matches the request, and location information that is included in the request, is then fetched from the federated directory service wallet system interface and forwarded to the device that sent the request.
Owner:WELLS FARGO BANK NA