Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "Federated identity" patented technology

A federated identity in information technology is the means of linking a person's electronic identity and attributes, stored across multiple distinct identity management systems. Federated identity is related to single sign-on (SSO), in which a user's single authentication ticket, or token, is trusted across multiple IT systems or even organizations. SSO is a subset of federated identity management, as it relates only to authentication and is understood on the level of technical interoperability and it would not be possible without some sort of federation.

Intelligent Attack Vector Analysis and Mitigation System

An intelligent attack vector analysis and mitigation system incorporates an intelligent process to analyze potential attack vectors from a suspicious attacker. The intelligent attack vector analysis and mitigation system leverages a generative artificial intelligence (AI)-enabled simulation environment to isolate and / or simulate attackers using federated identity and a hypermedia application programming interface (API). The system analyzes actual and / or potential attack vectors by leveraging the generative AI simulation and provides behavioral analysis with a specific focus on federated identity and / or hypermedia API components. As such, the system provides insights into novel attack vectors, vulnerabilities, and effective mitigation strategies that may then be automatically incorporated and / or implemented on the enterprise network by the intelligent attack vector analysis and mitigation system. The process utilizes continuous improvement, adaptation to evolving threats, and a holistic understanding of the system's security posture to improve and enable the enterprise organization's network security system.
Owner:BANK OF AMERICA CORP

Federal identity authentication method fusing mouse behavior modeling and adaptive differential privacy

The invention relates to the technical field of identity authentication, in particular to a federated identity authentication method fusing mouse behavior modeling and self-adaptive differential privacy, which comprises the following steps: building a federated learning framework; an authentication problem is converted into a time sequence behavior modeling task; updating model parameters by each client, and calculating local gradient information of the current round; cutting the local gradient information; the privacy budget is dynamically distributed; gaussian noise is added to the cut local gradient information; the central server aggregates the disturbed local model parameters to obtain new global model parameters; when the model reaches the preset convergence standard or the maximum round limit after multiple communication rounds, training is ended, a global model terminal is deployed, mouse behavior modeling and a federal learning mechanism are combined, the collection requirement for original user data is avoided, the leakage risk of sensitive data in the transmission and storage process is fundamentally reduced, and the user experience is improved. And the data security and the privacy protection capability are improved.
Owner:GUILIN UNIV OF ELECTRONIC TECH +2

Data Encryption Communication Method and System Applied to Intelligent Cash Registers

The present invention relates to the field of encrypted communication technologies, and particularly to a data encryption communication method and system applied to an intelligent cash register. The method includes the following steps: collecting user touch data and device hardware fingerprints, and performing high-dimensional feature fusion encoding to obtain a combined identity credential; obtaining the original key negotiation protocol and transmission metadata of the peer server, and performing multi-logical path mapping and channel encryption configuration to obtain distributed ciphertext channel parameters; encrypting the distributed ciphertext channel parameters and the corresponding transmission metadata, and then performing block content packaging and node hash calculation to obtain an audit chain hash block; performing homomorphic encryption processing on the obtained real-time transaction data to obtain a homomorphic ciphertext to be transmitted; performing communication transmission anomaly detection on the information transmission data collected in real time, and triggering dynamic key renegotiation to improve the communication feedback ability. The present invention helps to improve the overall security and stability of data encryption communication between the cash register and the backend server.
Owner:SHENZHEN DODONEW TECH CO LTD

A gateway access system and method for smart door locks in campus dormitories

This invention relates to the field of gateway access and discloses a gateway access system and method for smart door locks in campus dormitories. The system includes: continuously scanning the entry area by deploying multi-source sensing units to generate an event priority queue; triggering a multi-person joint identity verification process based on events in the event priority queue whose risk levels meet preset conditions, generating a joint risk probability distribution matrix; uploading the matrix to the dormitory building gateway, and forming a candidate protection event set by combining the operating status and time node characteristics of the door lock node and monitoring node; generating door lock control commands based on the candidate protection event set and the corresponding time node joint risk probabilities through a door lock dynamic access control mechanism and a multi-level policy mapping algorithm; and forming a protection policy set by combining the risk changes of the candidate protection event set at different time nodes and updating protection parameters, sensing frame rate, and multi-factor verification rules through algorithms. This invention has the advantage of improving security.
Owner:HANGZHOU REFORMER HLDG CO LTD

Data verification methods, apparatus, equipment, media and program products

This application provides a data verification method, apparatus, device, medium, and program product, relating to the field of computer technology, for improving the data verification security of AIGC. The specific technical solution is as follows: obtaining a first AIGC generated by at least one generating device; obtaining metadata information corresponding to the first AIGC; wherein, the metadata information includes: the identity information of the generating device and the flow path log corresponding to the first AIGC; the identity information of the generating device includes at least one of the following: hardware root of trust information of each generating device, and a joint identity identifier of the at least one generating device; the hardware root of trust information is used to characterize the hardware information of the chip of the generating device, and the computing power characteristic information of the generating device when generating the first AIGC; based on the metadata information, performing data verification on the first AIGC, the data verification including: verifying whether the first AIGC has been tampered with, and verifying whether the generating device corresponding to the first AIGC is a trusted device. This application is applied to scenarios involving data verification of AIGC.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Identity authentication method, device and related equipment

The embodiment of the present application provides an identity authentication method, apparatus and related equipment, wherein the method includes: the service provider's server receives a message that the user's user identity has been authenticated by the identity provider's server, and the message includes the user's bound verification method information; the service provider's server sends a verification request to the user terminal according to the verification method information; the service provider's server receives the verification code sent by the user terminal and verifies the verification code; when the service provider's server verifies the verification code, the service provider's server generates an access credential corresponding to the user and sends the access credential to the user terminal, and the access credential indicates that the user has the right to access the service provider's server. By implementing the above method, in the process of realizing federated identity authentication, the user's identity is confirmed through multi-factor authentication to prevent the risk of user data security caused by the leakage of identity credentials of a single system.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Authentication process for facilitating secure access to voice-enabled applications

A system can be provided for providing access for internal client devices to a voice-enabled application. For example, the system can detect a selection of the voice-enabled application by an internal client device. The voice-enabled application can generate metadata related to a secure interaction between entities for preventing an adverse event. In response to detecting the selection of the voice-enabled application, the system can further transmit an access request to a federated identity provider. The access request can include an authentication credential associated with the internal client device and an identity indicator associated with the voice-enabled application. The system can receive, from the federated identity provider, an authentication of the internal client device based on the authentication credential and the identity indicator. Moreover, in response to receiving the authentication of the client device, the system can provide access for the internal client device to the voice-enabled application.
Owner:TRUIST BANK

Identity verification and remote operation control method and equipment for charging cabin

PendingCN121864390ASecuring communicationFederated identityAuthorization
The invention relates to the technical field of charging cabin control, in particular to an identity verification and remote operation control method and device for a charging cabin. The method comprises the following steps: receiving a charging request of a charging cabin, and collecting user identity information associated with the charging request, equipment identity information of equipment to be charged and cabin space identification information of the currently occupied charging cabin to form an original identity information set; constructing the original identity information set into joint identity binding information according to a preset identity combination rule, judging the validity of the joint identity binding information, and determining joint identity authorization state data; and taking the combined identity authorization state data as a charging authorization basis for limiting a power supply enabling condition of the corresponding shipping space to form power supply authorization associated data. According to the invention, by constructing the joint identity binding of the user, the equipment and the cabin space and combining the multi-layer verification, the accurate authorization, dynamic response and safe controllable management of the charging cabin in the multi-user and multi-equipment environment are realized.
Owner:SHENZHEN DELTA EXPLOSION PROOF ELECTRIC VEHICLE CO LTD

A commodity exchange method, device, equipment and program product

This application discloses a method, apparatus, device, and program product for exchanging goods. The method includes: determining whether identity information meets preset user exchange conditions and whether first product information meets preset product exchange conditions; if both are met, extracting the identity features to be verified and the product features to be verified from a relationship proof image, and performing identity consistency verification and product consistency verification by combining the identity information and the first product information. If both consistency verifications pass, an exchange voucher is issued to the user. This application uses preset user exchange conditions and preset product exchange conditions to perform preliminary verification of identity information and the first product, preventing users from making duplicate exchanges. It determines whether the user corresponding to the identity information is consistent with the user corresponding to the identity features to be verified, and whether the product to be exchanged is consistent with the product corresponding to the product features to be verified. If any consistency verification fails, it indicates that there may be a fraudulent exchange.
Owner:CHINA UNIONPAY

Second-Factor-Based Realm Selection for Federated Authentication

ActiveJP7769454B2Digital data authenticationTransmissionEngineeringFederated identity
In an approach for authenticating a username, a processor maintains a mapping of usernames and realms. The processor receives a username and a time-based one-time password code (TOTP code) for the username based on an authentication application. Upon receiving the TOTP code, the processor determines a realm from the mapping based on the received username and the received TOTP; and requests input of credentials associated with the username into the realm. Upon receiving the requested credentials, the processor authenticates the username by determining that the received credentials match expected credentials for the realm.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Federated Security Orchestration System for codified security

A Federated Security Orchestration System (FSOS) (100) for codified security management, including: a) a federated control plane configured to coordinate policy orchestration across multiple infrastructure environments; b) a unified policy engine that can be operated to normalise and translate high-level enterprise security intent into domain-specific policies across the Infrastructure as Code (IaC), Policy as Code (PaC), Application Security as Code (AppSec-as-Code), Configuration as Code (CaC) and Security Orchestration, Automation and Response (SOAR) domains; c) a cross-domain policy mapper that transforms normalized policies into vendor-specific executable formats; d) a policy drift detection engine integrated with a feedback loop to monitor deviations between codified configurations and runtime states; (e) a security-as-code registry for storing, versioning and validating codified security artifacts; (f) a dynamic enforcement layer embedded in DevSecOps workflows to enable real-time enforcement during development, deployment, and runtime; and g) a federated identity and role mapping module that enables context-aware, identity-based policy enforcement in hybrid and multi-cloud environments.
Owner:BANDARU LALITH CHANDRA CHARLOTTE +4

Federated identity verification and access control for public service entities

A processing system including at least one processor associated with a second public service entity may obtain a notification of at least a first guest user to access at least one network-based resource of the second public service entity, where the at least the first guest user is associated with a first public service entity, and may obtain a request from a first device of the at least the first guest user to access the at least one network-based resource of the second public service entity. The processing system may then query an attribute provider to obtain one or more attributes of the first guest user and grant the first device an access to the at least one network-based resource of the second public service entity in accordance with at least one policy based on the one or more attributes.
Owner:AT&T INTELLECTUAL PROPERTY I L P

A method for processing cloud services in a cloud system and related apparatuses

The application provides a method for processing cloud services in a cloud system, the cloud system comprising a first cloud platform and a second cloud platform, the first cloud platform and the second cloud platform being partner clouds, the first cloud platform being provided with a first operation device and a first partner management device, and the second cloud platform being provided with a second operation device and a second partner management device, the method comprising the following steps: the second partner management device receiving a local identity credential acquisition request sent by the second operation device, acquiring a federated identity credential of a first user from the first partner management device according to an identity credential of the first user in the first cloud platform, converting the federated identity credential of the first user into an identity credential of the first user in the second cloud platform, and returning the identity credential of the first user in the second cloud platform to the second operation device, so that a client of the first user obtains the identity credential, and generates an API calling request according to the identity credential, thereby realizing process cooperation of the API calling request between the cloud platforms.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD