Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

35 results about "Directory service" patented technology

In computing, directory service or name service maps the names of network resources to their respective network addresses. It is a shared information infrastructure for locating, managing, administering and organizing everyday items and network resources, which can include volumes, folders, files, printers, users, groups, devices, telephone numbers and other objects. A directory service is a critical component of a network operating system. A directory server or name server is a server which provides such a service. Each resource on the network is considered an object by the directory server. Information about a particular resource is stored as a collection of attributes associated with that resource or object.

Universal method for realizing multiple conditions and search based on LDAP (Lightweight Directory Access Point)

The invention provides a universal method for realizing multi-condition and search based on LDAP, and belongs to the technical field of data retrieval of directory service and identity management. A user defines query conditions including attributes, values and logical relationships through a configuration file, a visual interface or an interface; the system parses the query condition model into a query condition model supporting nested combination of AND, OR and NOT by using a parser, and performs legality check and error prompt; and then a generator dynamically generates a filtering statement conforming to the LDAP grammar specification according to the model, and query is executed through an LDAP client. In order to improve the performance, common condition caching and high-frequency statement pre-compiling optimization are introduced, and an asynchronous query mode is supported. And the query result is returned in the form of structured data, and is matched with a display interface to support screening, sorting and exporting, so that the flexibility and maintainability of multi-condition query are improved.
Owner:UNICLOUD TECH CO LTD

Multi-system single sign-on security management method and system, storage medium and equipment

The invention relates to the technical field of information security, and discloses a multi-system single sign-on security management method and system, a storage medium and equipment, and the method comprises the steps: building a deep integration architecture between a directory service and an identity management server, and achieving the bidirectional synchronization of user attributes and security policies; a unified multi-factor authentication process and a security defense strategy are configured in the identity management server; by implementing password expiration risk assessment, multi-channel reminding and password self-service modification service, intelligent password life cycle active management is realized; intelligent account locking and self-adaptive unlocking based on multiple factors are implemented, and differentiated locking duration is dynamically calculated and executed; a cross-system unified session management and cooperative control mechanism is established, session anomaly real-time detection and scoring are performed through multi-dimensional feature fusion, one-point logout of global failure is realized, cross-system unified authentication, active security protection and cooperative management and control are realized, and the security and operation and maintenance efficiency of enterprise identity management are remarkably improved.
Owner:LINKPLAY TECHNOLOGY INC NANJING

Agentless active directory granular level restore from virtual machine level backups

A method for managing data protection includes obtaining, by a backup server, a restoration request for a virtual machine (VM) that includes an active directory (AD) application, and wherein the AD application comprises a set of AD objects and a directory service for managing the set of AD objects, parsing a VM backup corresponding to the VM, stored in a backup storage system, to identify an AD application backup of the AD application using metadata stored in an index and search microservice of the backup server, mounting, using an AD recovery microservice, backups of the set of AD objects of the AD application backup to the production environment, and providing browse and restoration services to the production environment based on the mounting of the AD objects and using the AD recovery microservice.
Owner:DELL PROD LLC

Unified workspace for thin, remote, and SAAS applications

Application-manager software authenticates a user of a client device over a channel. The authentication operation is performed using a directory service. The application-manager software presents a plurality of applications in a GUI displayed by the client device. The plurality of applications depends on the authentication, the client device, and the channel. And the plurality of applications includes a thin application and a software-as-a-service (SaaS) application. The application-manager software receives a selection as to an application from the user. If the selection is for the SaaS application, the application-manager software provisions the SaaS application. The provision includes automatically logging the user onto an account with a provider of the SaaS application using a single sign-on and connecting the user to the account so that the user can interact with the SaaS application. If the selection is for the thin application, the application manager software launches the thin application.
Owner:OMNISSA LLC

A trusted business card call system and method

ActiveCN120301975BInterconnection arrangementsCalling susbscriber number recording/indicationBusiness cardInternet privacy
The application discloses a trusted business card calling system and method, comprising: an electronic authentication module, which is used for issuing a digital certificate for an enterprise or an institution with a first user; a business card issuing module, which is used for editing and exporting a vCard format file of the first user's business card information, and signing the business card of the first user's vCard format file by using a private key of the digital certificate to obtain a trusted business card, and publishing the trusted business card to a directory server for a calling terminal to download; the calling terminal and the called terminal; the directory server, which is used for authenticating other system structures, and providing specified access rights for the calling terminal and the called terminal, and is used for the calling terminal to download the trusted business card and the called terminal to verify the trusted business card; the calling terminal downloads the trusted business card of the first user from the directory server, and transmits the trusted business card to the called terminal for display. The application has the advantages of independent issuing by the enterprise or the institution, guaranteeing the authenticity of work role information, relatively low implementation cost, better compatibility with existing systems and applications, and the like.
Owner:GUANGDONG ELECTRONIC CERTIFICATION AUTHORITY CO LTD

Security policy framework for cloud environments

ActiveUS12676892B2Data sourceEngineering
The present disclosure includes systems and methods for a security policy framework. Various embodiments include responsive to receiving a trigger, fetching one or more policies from a policy catalog service; compiling the one or more policies into a query, wherein the one or more policies can be compiled into a plurality of different query languages; executing the query over customer data, the customer data being located in one or more data sources; and persisting results of the query.
Owner:ZSCALER INC

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

A method and apparatus for real-time online visualization of multi-resolution grid data

This invention provides a method and apparatus for real-time online visualization of multi-resolution grid data, belonging to the field of data processing and visualization technology. First, the grid data is merged into hierarchical columns along the Z-axis to form a multi-resolution stacked grid model, which is then stored in HDF5 files according to resolution levels. Parallel I / O is achieved using MinIO distributed object storage. Second, a Z-Order index and directory server strategy are designed to improve data scheduling and transmission efficiency. On the browser side, a virtual quadtree structure is used to organize the data, and WebWorker and WebSocket are used to achieve multi-threaded real-time data reception, avoiding main thread blocking. Finally, the LOD level is dynamically selected based on the viewpoint distance, and efficient volume rendering is achieved using GPU texture arrays and LODInfoTexture. This method supports online real-time updates, significantly reduces loading latency, and improves the visualization frame rate.
Owner:齐鲁空天信息研究院

Hybrid directory management method and system for automobile industry trusted data space

The invention discloses a mixed directory management method and system for a trusted data space in the automobile industry, and aims to solve the contradiction between sovereignty protection and query efficiency of pure centralized and pure federated directory architecture. The method is based on a hybrid architecture of participating nodes, centralized directory services and data consumers, and through metadata acquisition preprocessing and automatic grading, public layer metadata is desensitized and differentially synchronized to a central directory; and completing query request verification and standardization in combination with DID identity authentication, intelligently selecting a query path by a routing engine according to multi-dimensional cost, executing distributed fine-grained authorization on business / sensitive layer metadata, and finally aggregating multi-source result feedback. Experiments prove that the query efficiency of the method is improved by 1-2 orders of magnitude compared with a pure federation mode, the synchronization bandwidth is reduced by 97% compared with a pure centralization mode, the balance of efficient global discovery and strict sovereign protection of data resources in the automobile industry is realized, and the method adapts to large-scale collaboration scenes such as supply chain collaboration.
Owner:AUTOMOTIVE DATA OF CHINA (TIANJIN) CO LTD

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Connector for private certificate authority and directory service

A method includes receiving, by a service operating in a provider network comprising a plurality of tenants, a request from a user device of one or more user devices in a user VPC of a first tenant of the plurality of tenants, wherein the request includes service identity information and authentication information. The method also includes providing, by the service, the request to an intermediary service operating in the provider network, wherein the intermediary service associates the service identity information with information maintained by the intermediary service associated with the tenants, and authenticating, by the intermediary service and with a domain controller, the request based on the authentication information. The method further includes, after the request is successfully authenticated, generating, by a private certificate authority (PCA) in a service VPC separate from the user VPC, a certificate based on the request, and providing the certificate to the user device.
Owner:AMAZON TECH INC

Data directory management system and method based on metadata driving

The invention discloses a data directory management system and method based on metadata driving, and the system comprises a metadata collection module which is used for automatically collecting the metadata information of structured and unstructured data from a plurality of business data sources, and a metadata analysis and classification module which is used for analyzing the collected metadata and classifying the metadata information of the structured and unstructured data. The metadata analysis module is used for analyzing metadata and classifying the analyzed metadata according to a predefined classification rule, the data directory generation module is used for automatically constructing and updating a multi-level data directory structure according to the classified metadata, and the directory service interface module is used for providing a standardized data directory retrieval and access interface. Through automatic metadata acquisition and real-time processing, the problems of update lag and poor consistency caused by manual maintenance are solved, intelligent data classification and dynamic directory construction are realized by means of a configurable rule engine, the intelligibility and management flexibility of data assets are improved, and through a unified service interface and refined authority control, the method is simple and convenient to operate and high in practicability.
Owner:商飞软件有限公司 +1

Metadata management method and device for AI data lake, medium and electronic equipment

A metadata management method and device of an AI data lake, a medium, and an electronic device, relating to the technical field of computers, the method comprising: in response to a first operation request for first metadata, parsing the first operation request to obtain first request information; a preset directory structure comprising at least a tenant domain, a directory domain, and an object domain nested in stages; in response to logical addressing information pointing to a first directory service of the plurality of metadata directory services, routing the first operation request to a first connector corresponding to the first directory service, the connectors corresponding to different metadata directory services having mutually isolated runtime environments, or the connectors corresponding to different types of metadata directory services having mutually isolated runtime environments; and executing the first operation on the first metadata in the first directory service through the first connector to obtain an execution result. Thus, tenant-level isolation and fine-grained access control of metadata are achieved, and dependency conflicts between different connectors are avoided.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Directory Service Recommender Assessment & Scoring

A cybersecurity service assesses, scores, and / or prioritizes activities associated with a directory service. When the directory service is requested to change a directory service assignment, the directory service may first request a verdict from the cybersecurity service. The cybersecurity service may use profiling and / or machine learning to predict directory service assignments. The cybersecurity service may then score and prioritize requests to change / update directory service assignments. Small deviations from predicted directory service assignments, for example, may indicate harmless / normal directory service activity. Larger deviations, though, may indicate abnormal directory service activity. Larger deviations may even indicate malicious directory service activity, such as permission escalation and cyberbreaches. Scoring and prioritization allows for resource allocation and timely mitigations by human experts.
Owner:CROWDSTRIKE

Device social media integration with cloud solutions for issue resolutions

A computer system receives a request from a device to join a device social network supported by an enterprise device social media cloud. The request comprises a user packet that includes a network social name, enterprise credentials of the device, and device information metadata. The computer system validates the user packet. When the validation is successful, the computer system calls a directory service to create a directory service user entry corresponding to the device in the directory service. When the creation of the directory service user entry is successful, the computer system creates a device social network user corresponding to the device in the enterprise device social media cloud.
Owner:AMERICAN MEGATRENDS

Method and system for managing heterogeneous directory

The invention relates to the technical field of data sharing, in particular to a method and system for managing heterogeneous directories, comprising the following steps: constructing a reference directory management system and a government affair data reference directory library, the reference directory library being used for storing and managing directory data from different sources and different data structures and providing a full-range directory service, fusion, deduplication and association functions of directory data generated in multiple modes and multiple stages are achieved; the method has the beneficial effects that directory data with different sources and different data structures are stored, managed, treated, circulated and used by constructing the reference directory management system and the reference directory library. An ideal representation model is established according to the essence, correlation, development and evolution process and other information of the catalogue, and catalogue data life cycle management process links are supplemented, perfected and established.
Owner:BEIJING INSPUR CLOUD COMPUTING CO LTD

Converged communication server resource scheduling method and system

The invention relates to the field of network communication, and discloses a converged communication server resource scheduling method and system, and the method comprises the steps: receiving a user communication request, and converting a heterogeneous protocol into a standard format in a unified manner through a protocol conversion layer; identifying a target service module based on the request type, wherein the service module comprises at least two of a local regeneration service, a boundary service, a multi-point control unit service and an address book service; querying real-time resource monitoring data, and dynamically allocating CPU cores, memories and network bandwidth resources according to a preset priority strategy; starting a target service instance in a containerized environment, and performing communication between instances through the service grid; and executing the service logic and returning a result, and recording resource consumption data to the performance database. According to the invention, the resource utilization rate of a single server can be improved, and the service quality of multiple services is guaranteed.
Owner:CHINA YANGTZE POWER

Api request data sharing method and apparatus, electronic device, and storage medium

This invention provides an API request data sharing method, apparatus, electronic device, and storage medium. The method includes: calling a data exchange service to verify the API interface based on an application programming interface (API) request initiated by a data consumer; if the API interface verification is successful, obtaining target data from a data provider based on the API interface request; matching the target data with data on a first blockchain; and if the target data and the first blockchain data are successfully matched, feeding the target data back to the data consumer through a directory service. API interface verification facilitates subsequent accountability and improves the security of data sharing.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +2

Intake pipeline for augmented reality content generator

The subject technology receives information about a product. The subject technology generates a 3D model file of the product in a first format. The subject technology converts the 3D model file into a 3D object file in a second format. The subject technology associates the 3D object file with the product in a product catalog service. The subject technology publishes an augmented reality (AR) content generator corresponding to the product.
Owner:SNAP INC

An object chain-based data storage method and system

ActiveCN115292678BImprove storage efficiencyimprove concurrencyManagement toolWeb service
The application discloses a kind of data storage method and system based on object chain, which comprises: using N nodes to store data and text;N nodes are linked to form M string chain under the guarantee of security guarantee mechanism;M string chain freely constitutes X object unit;X object unit is linked to form block chain by control library firmware, realize the storage of multiple data and text;The system makes the above-mentioned method carry out data storage and management;System includes support layer, functional layer and interface layer;Wherein, support layer includes: directory service module;Functional layer includes: authentication service module, identity management module, authorization management module, role management module, resource management module and configuration management module;Interface layer includes: API interface module, Web service module and management tool module;Different functional components can be connected through API interface module, can adapt to various different platforms, and the performance is stable and reliable;And data storage efficiency and security are very high, and storage is not limited.
Owner:SHENZHEN LIANWO INFORMATION TECH CO LTD

A database recovery system based on ZFS snapshot cloning and container vertical mounting

PendingCN122346407AEngineeringDatabase services
This invention relates to the field of data storage and disaster recovery backup technology, specifically disclosing a database recovery system based on ZFS snapshot cloning and container vertical mounting. The system includes: a metadata extraction module for extracting the database type and version number from the backup task; a storage cloning module for creating a ZFS snapshot based on the backup set and generating a readable and writable clone volume; a local mounting module for mounting the clone volume to the host machine's local directory; a container orchestration module for starting a database container of the corresponding version according to the database version number and mapping the local directory to the database data directory within the container; a service detection module for detecting the database service status and outputting a success signal; and a resource reclamation module for destroying the container and deleting the clone volume after the task is completed. This invention achieves rapid database recovery and automated verification through ZFS copy-on-write cloning and container vertical mounting technology, and supports the on-demand creation and destruction of the verification environment.
Owner:杭州赢禾科技有限公司

Authentication management method of a server's BMC and related device

The application relates to the field of communication technology, in particular to a BMC authentication management method of a server and related devices. The method comprises the following steps: in response to a login request of a target user to the BMC, calling a Kerberos module through a PAM framework, storing connection parameters of a KDC and a key of the BMC by the BMC; performing service identity authentication based on the key of the BMC, the connection parameters and the KDC; if the service identity authentication is successful, performing user identity authentication based on identity credentials and the KDC; if the user identity authentication is successful, obtaining and using a TGT to request an ST for accessing a directory service from the KDC; querying the directory service by using the ST to obtain group membership information of the target user; and determining access rights of the target user to the BMC according to the group membership information and a predefined mapping rule. The application integrates Kerberos based on the PAM framework, provides a two-way authentication function, and effectively improves security.
Owner:SHENZHEN GOOXI INFORMATION SECURITY CO LTD

Enhanced user authentication system and method

Systems and methods are provided to utilize information from a directory service to determine, at a layer-one network policy server, the appropriate layer-two network policy server to which an authentication request should be routed. For example, a first directory service group may be created that includes all users using a first authentication type, a second directory service group may be created that includes all users using a second authentication type, etc. The layer-one network policy server may periodically synchronize with the directory service to download information about users in the different directory service groups, update a markup language document with that information, and use the markup language document to help route incoming authentication requests to the correct layer-two network policy server for a particular authentication type. In addition, a priority may be set (and changed) by an administrator favoring one or more authentication types in a network.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Method and apparatus for processing multi-level data catalogs in trusted data spaces

This invention discloses a multi-level data directory processing method and apparatus for a trusted data space. The method includes: a client receiving a data query request initiated by a user and sending it to a general data directory node; the general data directory node obtaining an industry code; obtaining an industry data directory service address based on the industry code, and sending the query request to the industry data directory node based on that address; the industry data directory node obtaining metadata and a master data code, obtaining an industry master data service address based on the master data code, and sending the query request to the industry master data service node based on the industry master data service node address; the industry master data service node retrieving the master data and sending it to the industry data directory node; the industry data directory node returning the master data and metadata; and the general data directory node assembling the general data directory, metadata, and master data and returning it to the client. This invention can reduce the load on the general data directory and lower system maintenance pressure.
Owner:BEIJING MATDAO TECH CO LTD

Authorization of mobile OTP based transactions

Embodiments of the present disclosure relate to methods and systems for authenticating and authorizing a mobile one-time password (m-OTP) based transaction. A cardholder (101) can generate the m-OTP in an issuer mobile application (301) and enter in a checkout page for completing the transaction. Once the m-OTP is entered, a merchant system (104) generates a transaction message that includes the m-OTP and a unique identifier indicating that the transaction message includes the m-OTP. Submitted to a directory server (106), the directory server sends the transaction message to an issuer system (107) for authentication and authorization. The issuer system (107) generates a response message that includes a result of the authentication and authorization of the transaction message. The directory server (106) routes the response message to the merchant system (104) via the acquirer system (105).
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Hybrid network directory service

Techniques for a hybrid network directory service are described. Messages forming a request to launch an instance within a cloud provider network are received, the messages including an identifier of a customer virtual network within the cloud provider network, the customer virtual network having connectivity to another network outside of the cloud provider network, the other network outside of the cloud provider network having a directory service. An instance is launched, the instance having connectivity to the customer virtual network. A server of the directory service on the other network outside of the cloud provider network is identified. The identified server is caused to add the instance as a node of the directory service. Directory service data received from the identified server is stored. Directory service requests originating from the customer virtual network are processed.
Owner:AMAZON TECH INC

Managing a resource transfer based on conditions stored in association with a resource handle involved in the resource transfer

A computer-implemented method, system, and non-transitory computer-readable media are provided for managing a resource transfer based on conditions stored in association with a resource handle involved in the resource transfer. The resource transfer may have two-sided anonymity, with resource handles and / or token account identifiers in use on either side of the transaction, while still allowing the parties to directly transact with each other without an intermediary. Anonymity, privacy, and fraud prevention may be further strengthened by secure digital mechanisms such as secure protocols, embedded mechanisms such as QR codes or NFC taps for determining resource handle(s), target validation mechanisms, registration and management of reputation scores for resource handles or directory services that manage the resource handles, and use of transaction metadata and derived keys for additional verification.
Owner:TYFONE INC

Delta anomaly detection for backups of specialized directory service assets

A method for managing access to a file based backup (FBB) includes generating, at a first point-in-time, a first FBB at a first point-in-time, wherein the first FBB comprises a first set of files of an asset at the first point-in-time, generating, at a second point-in-time after the first point-in-time, a second FBB at a second point-in-time, wherein the second FBB comprises a second set of files of the asset at the second point-in-time, performing an asset analysis on the first FBB metadata file and a second FBB metadata file associated with the second FBB to generate a differencing FBB metadata file, performing an anomaly analysis on the second FBB using the differencing FBB metadata file to obtain a anomaly report, and performing a remediation of the second FBB based on the anomaly report.
Owner:DELL PROD LP

File Attribute Setting Method and Apparatus

PendingUS20260093668A1File system administrationFile access structuresNetwork-attached storageFile attribute
A method includes a network attached storage (NAS) server that receives an attribute setting request sent by a client, where the attribute setting request indicates a target directory and a target attribute, the target directory includes a plurality of objects, and the objects are files or subdirectories. The NAS server performs attribute setting on the objects in the target directory based on the target attribute, where the target attribute includes one or more of an owner attribute, a read-only attribute, a hidden attribute, a time attribute, or a permission attribute. The NAS server sends a response message for the attribute setting request to the client.
Owner:HUAWEI TECH CO LTD