Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Hardware authentication" patented technology

The term "hardware authentication" refers to a security system that uses a hardware device to grant access to users. Hardware authentication is used most commonly for computer systems and networks to protect sensitive data.

Desktop cloud security access control method based on multi-factor authentication

ActiveCN120474797ASecuring communicationRisk levelHardware authentication
The invention belongs to the technical field of computer security, and relates to a desktop cloud security access control method based on multi-factor authentication, which comprises the following steps: acquiring hardware authentication information submitted by a user; collecting behavior characteristic data when a user operates and inputs; detecting an environment safety state of the access terminal; generating an authentication confidence level, wherein the authentication confidence level is divided into a high risk level, a medium risk level and a low risk level; assigning an initial access right based on the authentication confidence level; after the initial access authority is obtained, continuously comparing the current behavior characteristic data with the initial behavior characteristic data, and updating the authentication confidence level in a mechanical operation mode; and dynamically adjusting the access permission according to the updated authentication confidence level, and triggering an automatic permission degradation mechanism when a continuous non-operation state is detected. The problem that permission change depends on manual intervention in a traditional mode is solved.
Owner:CHN ENERGY YUEYANG POWER GENERATION CO LTD

Customized network interface card oriented to intranet security access and design method thereof

The invention discloses a network interface card with autonomous access authentication, and provides an integrated hardware authentication mechanism. The EAP-TLS client protocol stack is integrated on the bottom layer of the network card, so that the defect that an authentication module depends on a host system, manual intervention and the like in the existing scheme is overcome, TLS handshake and certificate verification are independently completed on the network card side, and authentication interaction is automatically initiated. The network interface card serves as a unique identity certificate of an access network, a client certificate and a corresponding private key are embedded in the network interface card and are stored in a protected nonvolatile area, and data confidentiality is effectively enhanced. The network card is used as an identity certificate and network access equipment at the same time, and the integrated design reduces the dependence on the service capability of management personnel. A traditional physical network card and an automatic authentication protocol are fused, and the method is suitable for application environments with high requirements for access control and authentication safety, such as an enterprise intranet and a government affair private network.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Systems and methods supporting composable system architectures

The invention provides a platform for evaluating and distributing packaged software capabilities. The packaged software capabilities described herein may be discrete pieces of software designed to perform a specific task and multiple packaged software capabilities may be combined to create larger functionality, such as an application. Packaged software capabilities may be analyzed using a variety of techniques to evaluate interoperability based on standard(s) to determine whether the packaged software capabilities support desired hardware, authentication, authorization, and the like. A catalog of packaged software capabilities satisfying the standard(s) may be created and the platform may provide a variety of techniques for searching the catalog based on search parameters to identify best fit packaged software capabilities meeting a user's needs.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Android SoftPOS trusted application method and application system

The invention discloses an Android SoftPOS (Point Of Sale) trusted application method and an Android SoftPOS trusted application system. The method comprises the following steps: an application end initiates an authentication request to an application proof server, and obtains verification data and a plurality of random numbers; carrying out equipment and application integrity verification, generating an integrity proof and a hardware authentication certificate, and submitting the integrity proof and the hardware authentication certificate to a server; after the server passes the verification, signing and issuing a specific safety communication certificate of the equipment to the application end; and the application end establishes a secure communication channel with the server according to the certificate. Through multi-stage verification and a random number mechanism, it is ensured that only trusted equipment and applications can complete authentication, end-to-end secure communication is achieved by combining dynamic certificate signing and issuing, the confidentiality and integrity of payment data are remarkably improved, and the security risk is reduced.
Owner:SHENZHEN TOPWISE COMM CO LTD

Hardware-anchored liquidity containment and capital reserve enforcement engine with attestation-bound real-time settlement controls

PendingUS20260187726A1Flip-flopTerm memory
A hardware-anchored Liquidity Containment and Capital Reserve Enforcement Engine executes real-time reserve validation, liquidity sufficiency computation, and deterministic settlement gating entirely within trusted execution environments (TEEs) comprising Intel SGX enclaves, AMD SEV-SNP protected VMs, or ARM TrustZone secure worlds, materially altering processor states to isolate all reserve computation. Liquidity Integrity Vectors are computed using the reserve adequacy function h(alpha, beta, gamma) from hardware-attested inputs anchored to TEE-resident hardware mechanisms comprising enclave-sealed monitoring registers, memory encryption engine integrity states, or attestation-based recalibration triggers. A Liquidity Containment Gate enforces a non-bypassable hardware execution barrier requiring all LIV computation, Capital Reserve Monitor validation, and ZKP proof generation to complete within a single attested TEE execution instance before settlement authorization is released. A ZKP Verification Engine generates Groth16 arithmetic-circuit proofs of approximately 192 bytes verifiable in under 10 milliseconds, enabling External Counterparty verification of reserve sufficiency without disclosure of proprietary balance sheet data. A Provenance Ledger stores append-only cryptographic hash chains with each entry bound to a TEE attestation report. A Settlement Attestation Binder cryptographically binds settlement authorizations to specific TEE attestation report identifiers, enabling independent verification of both settlement outcomes and the hardware environments that authorized them.
Owner:BICKERSTAFF III GEORGE WILLIAM

Hardware-Attested Influence-Weighted Oracle Resolution System with TEE-Sealed Provenance Tokens

PendingUS20260254654A1Tamper resistanceHardware authentication
A system for resolving prediction market outcomes using secure hardware and trust-based scorer selection. The system scores each resolver based on their track record of accuracy, governance participation, and integrity alignment rather than token holdings. Resolution computations execute inside a tamper-resistant hardware enclave that prevents manipulation by platform operators or external attackers. Upon resolution, the system produces a sealed Provenance Token containing six cryptographic fields that bind the decision to its inputs, scoring model, enclave identity, and a non-replayable counter value, enabling anyone to independently verify resolution integrity. Anomalous resolver submissions are detected and quarantined before consensus using dual machine-learning algorithms running inside the enclave. The system generates regulatory compliance reports within the secure hardware and delivers results through authenticated API endpoints. Settlement automatically distributes payouts to holders of winning outcome shares.
Owner:BICKERSTAFF III GEORGE WILLIAM

Systems and methods for terminal device attestation for contactless payments

A method and apparatus validating integrity of an environment of a terminal device remote to a commerce platform system are described. The method can include receiving, from the terminal device, a device provisioning request that comprises data indicative of an instance of an application installed on the terminal device, a first public key, a second public key, and a hardware attestation key, the first public key, the second public key, and the hardware attestation key generated within a trusted execution environment of the terminal device, and the first public key and the second public key having a corresponding first private key and second private key stored within the trusted execution environment. The method may also include verifying the first public key and the second public key as being generated by the trusted execution environment of the terminal device using the hardware attestation key, the hardware attestation key generated at least in part using the first public key, the second public key, and the data indicative of the instance of the application.
Owner:STRIPE LLC

System and method for authentication as a service

A computing system includes a server. The server is communicatively coupled to a data repository and is configured to store a data in the data repository. The server is further configured to receive a first authentication information, the first authentication information comprising a login and a password for an entity, and to receive a second authentication information, the second authentication information comprising at least one identifying information generated by a hardware authentication device. The server is further configured to execute a hardware-based authentication as a service process, the authentication as a service process configured to use the first and the second authentication information as input to authenticate the entity, and to provide computing resources to the entity if the entity is successfully authenticated.
Owner:SERVICENOW INC

Android softpos trusted application method and application system

The application discloses an Android SoftPOS trusted application method and system. The method comprises the following steps: an application end initiates an authentication request to an application proof server, obtains verification data and a plurality of random numbers; then, device and application integrity verification is performed, integrity proof and hardware authentication certificates are generated, and the generated integrity proof and hardware authentication certificates are submitted to the server; after the server verifies the integrity proof and the hardware authentication certificates, the server issues a device-specific secure communication certificate for the application end; and the application end establishes a secure communication channel with the server by using the certificate. Through multi-stage verification and a random number mechanism, only trusted devices and applications can complete authentication, dynamic certificate issuance is combined, end-to-end secure communication is realized, the confidentiality and integrity of payment data are significantly improved, and security risks are reduced.
Owner:SHENZHEN TOPWISE COMM CO LTD

Zero terminal system

The invention discloses a zero terminal system, relates to the technical field of electronic information, thoroughly cuts a central processing unit (CPU) and an operating system of a terminal, and improves the end side security of a desktop cloud system. The system specifically comprises the following modules: a network PHY module used for connecting a network cable and receiving and transmitting a network data packet; and the network TCP / IP module is based on a network TCP / IP protocol stack realized by hardware, is internally provided with a hardware authentication private key ID, and is used for packing and unpacking the TCP / IP protocol of the network data. And the encryption and decryption module is used for encrypting and decrypting the transmission data. And the PS / 2 keyboard and mouse module is used for connecting a PS / 2 keyboard and mouse and analyzing the input of the PS / 2 keyboard and mouse. And the decoding module is used for decoding the received display coding data. And the display module is used for processing display data. And the HDMI PHY / VGA interface module is used for being externally connected with a display. All the modules transmit data by sharing a static random access memory (SRAM).
Owner:BEIJING PKUNITY MICROSYST TECH

Charging and discharging relay device

To provide a charging and discharging relay device that can prove that an appropriately configured electric vehicle is connected to a grid.SOLUTION: A charging and discharging relay device 20 includes a relay side memory unit 35 that stores authentication information about hardware of an authenticated electric vehicle 40, and when the relay circuit unit 21 is electrically connected to the inverter 42 of the electric vehicle 40, the relay side control unit 33 acquires information about the hardware from the electric vehicle 40 and performs a vehicle determination process to determine whether the hardware of the electric vehicle 40 is the same as that which has been authenticated on the basis of the authentication information stored in the relay side memory unit 35, and when it is determined that the hardware is the same as that which has been authenticated, it allows the inverter 42 to supply power to the relay circuit unit 21, and when it is determined that the hardware is not the same as that which has been authenticated, it prohibits the inverter 42 from supplying power to the relay circuit unit 21.SELECTED DRAWING: Figure 1
Owner:OSAKA GAS CO LTD

Monitoring system and method based on hierarchical agent architecture and dual hardware confirmation

The invention discloses a monitoring system and method based on hierarchical agent architecture and two-stage hardware confirmation, and belongs to the technical field of Internet of Things and artificial intelligence. The system comprises a bracelet end which is provided with a main key and a touch key and is internally provided with a security chip for generating a digital signature; the mobile phone end deploys a private agent and an encryption sandbox and only responds to the instruction confirmed by the hardware; and the cloud end is used for processing non-sensitive tasks by adopting a Manager / Worker multi-tenant architecture. The method comprises the steps that the bracelet collects a voice instruction, a mobile phone end analyzes an intention, and sensitive operation is issued to the bracelet; the old person selects through the main key and confirms through the touch key, and the security chip generates a signature and returns the signature; after verifying the signature, the mobile phone decrypts the certificate and calls the API to execute operation; and broadcasting and feeding back a result, and performing key operation on a chain for evidence storage. Through cooperation of two-stage hardware confirmation and the layered intelligent agent, hardware right confirmation of sensitive operation and local isolation of privacy data are achieved, full thinking time is given to old people while operation authenticity is guaranteed, and misoperation is avoided.
Owner:SHENBIZILIANG (GUANGDONG) TECHNOLOGY SERVICE CO LTD

Method for secure access control of desktop cloud based on multi-factor authentication

ActiveCN120474797BSecuring communicationHardware authenticationReliability engineering
The application belongs to the technical field of computer security, and relates to a desktop cloud security access control method based on multi-factor authentication, which comprises the following steps: obtaining hardware authentication information submitted by a user; collecting behavior characteristic data when the user operates input; detecting the environment security state of an access terminal; generating an authentication confidence level, which is divided into a high-risk level, a medium-risk level and a low-risk level; distributing initial access rights based on the authentication confidence level; after obtaining the initial access rights, continuously comparing current behavior characteristic data with initial behavior characteristic data, and updating the authentication confidence level when in a mechanical operation mode; dynamically adjusting access rights according to the updated authentication confidence level, and triggering an automatic right downgrade mechanism when a continuous non-operation state is detected. The application solves the problem that traditional methods rely on manual intervention for right change.
Owner:CHN ENERGY YUEYANG POWER GENERATION CO LTD

Universal Internet of Things security encryption gateway equipment based on meteorological industry

The utility model provides universal Internet of Things security encryption gateway equipment based on meteorological industry, which is applied to the technical field of Internet of Things gateway equipment and comprises an RK3568J processor, a communication unit, a memory unit, a clock unit and a power supply unit, the communication unit comprises a data encryption module, a data transmission module, a data acquisition module and an identity authentication module. A hardware authentication algorithm is combined with a TLS encryption technology to realize transmission channel encryption, a device and observation data cloud management and service platform point-to-point encryption transmission channel is constructed, data is ensured not to be stolen or tampered in a transmission process, a digital signature technology and a central CA unified authentication platform are organically combined to form an up-and-down linkage signature authentication system, and the security and reliability of the system are improved. The automatic digital identity verification of the equipment is realized, and the identity legality, validity and credibility of the accessed detection equipment are ensured by means of automatically issuing a credit certificate and the like.
Owner:CMA METEOROLOGICAL OBSERVATION CENT