Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

106 results about "Identity management" patented technology

Identity management (IdM), also known as identity and access management (IAM or IdAM), is a framework of policies and technologies for ensuring that the proper people in an enterprise have the appropriate access to technology resources. IdM systems fall under the overarching umbrella of IT security and Data Management . Identity and access management systems not only identify, authenticate and authorize individuals who will be utilizing IT resources, but also the hardware and applications employees need to access. Identity and Access Management solutions have become more prevalent and critical in recent years as regulatory compliance requirements have become increasingly more rigorous and complex. It addresses the need to ensure appropriate access to resources across increasingly heterogeneous technology environments and to meet increasingly rigorous compliance requirements.

Transparent, on-demand route determination and delegated authorization in a large-scale, decentralized service mesh

A system can execute a containerized application that comprises a microservice in a decentralized service mesh architecture, and a sidecar. The system can intercept, by the containerized application, a call from the microservice that is directed to a remote endpoint, and direct the call to the sidecar. The system can communicate, by the sidecar to an identity manager, service account credentials associated with the microservice, resulting in receiving an identity token associated with the microservice. The system can determine, by the sidecar, connectivity information of the remote endpoint based on a virtual address of the remote endpoint identified in the call. The system can communicate, by the sidecar to a token exchanger, the identity token and the connectivity information, resulting in receiving an access token and a network route to the remote endpoint. The system can relay, by the sidecar, network traffic between the microservice and the remote endpoint.
Owner:DELL PROD LP

Internet of Things identity management method and system based on block chain

The invention discloses an Internet of Things identity management method and system based on a block chain, and relates to the technical field of fusion block chains, the method comprises identity prefabrication, dynamic authorization, security interaction and identity management and control, and in the identity prefabrication stage, a unique security seed is injected into equipment, a key pair is generated, an identifier is decentralized, and an access credential is decentralized. After verification of a block chain smart contract, writing the data into an alliance chain main chain to complete identity anchoring; dynamically authorizing through an attribute-based access control model, and setting a fine-grained permission boundary according to an access credential; the security interaction adopts a DID bidirectional authentication and batch signature verification technology to process a high-concurrency request, an instruction is verified and executed through a security module after being signed and packaged, and an audit triple is synchronously constructed for storage; and identity management and control triggers key rotation through an intelligent contract rule engine, so that the full-life-cycle safety of the identity is ensured, and the safety risk caused by permission abuse is effectively reduced.
Owner:南京傲拓智能控制技术有限公司

System for Cross-Domain Identity Management (SCIM) Proxy Service

A system for cross-domain identity management (SCIM) proxy service is described. A first SCIM endpoint receives, from a first SCIM client, a first message that includes a SCIM resource. The first SCIM endpoint is associated with a customer of the SCIM proxy service. The SCIM proxy service is configured as a first SCIM service provider for the first SCIM client. The first message is validated. The first SCIM proxy service determines that a third-party application is in scope for the SCIM resource, where the SCIM proxy service is configured as a second SCIM client for the third-party application. The SCIM proxy service transmits a second message to a second SCIM endpoint of the third-party application, the second message including the SCIM resource.
Owner:CLOUDFLARE INC

Universal method for realizing multiple conditions and search based on LDAP (Lightweight Directory Access Point)

The invention provides a universal method for realizing multi-condition and search based on LDAP, and belongs to the technical field of data retrieval of directory service and identity management. A user defines query conditions including attributes, values and logical relationships through a configuration file, a visual interface or an interface; the system parses the query condition model into a query condition model supporting nested combination of AND, OR and NOT by using a parser, and performs legality check and error prompt; and then a generator dynamically generates a filtering statement conforming to the LDAP grammar specification according to the model, and query is executed through an LDAP client. In order to improve the performance, common condition caching and high-frequency statement pre-compiling optimization are introduced, and an asynchronous query mode is supported. And the query result is returned in the form of structured data, and is matched with a display interface to support screening, sorting and exporting, so that the flexibility and maintainability of multi-condition query are improved.
Owner:UNICLOUD TECH CO LTD

Unmanned aerial vehicle cross-domain service function link accessing method based on alliance chain

The invention discloses an alliance chain-based unmanned aerial vehicle cross-domain service function link accessing method, which comprises the following steps of: 1, initializing a system and configuring an alliance chain, generating a global password parameter and a root key by a trusted mechanism, and finishing domain registration and certificate chain storage by each management domain edge server; 2, blockchain-driven identity management is carried out, and the unmanned aerial vehicle completes chain registration and anti-counterfeiting registration certificate acquisition through a domain edge server to which the unmanned aerial vehicle belongs; 3, deploying a flexible threshold signature algorithm to realize multi-domain joint signature and Byzantine fault tolerance; 4, executing a cross-domain SFC security authentication protocol, including SFC pre-verification and security authorization certificate issuing, first node verification starting, hop-by-hop key negotiation and handover certificate transmission, and on-chain auditing; and 5, based on the topology centrality and the path coverage, dynamically electing an orchestrator to realize load balancing. According to the invention, safe access and identity authentication of the cross-domain service function chain of the unmanned aerial vehicle are realized, safety, efficiency and expandability are balanced, and reliable guarantee is provided for cross-domain cooperation of the unmanned aerial vehicle.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Photovoltaic module decommissioning prediction method and system

The invention discloses a photovoltaic module decommissioning prediction and cyclic utilization management system and method, and belongs to the technical field of photovoltaic module life cycle management and prediction.The system comprises a central processing unit and a memorizer, and the memorizer stores computer programs; during execution, the component identity management module, the dynamic prediction analysis module and the full-chain tracing module are realized; the component identity management module distributes a unique identity code for the photovoltaic component and manages static attribute data and dynamic operation data; the dynamic prediction analysis module dynamically predicts the decommissioning time and scale of the component through a decommissioning analysis model based on the data; the full-chain tracing module records circulation information of the components in links of collection, transportation, storage and resource utilization by scanning codes after the components are decommissioned, so that full-chain tracing is realized; according to the invention, the problems of difficult management tracing and insufficient prediction precision in the prior art are solved, and fine management, intelligent prediction and efficient resource utilization of the photovoltaic module are realized.
Owner:CECEP SOLAR ENERGY TECH (ZHENJIANG) CO LTD

Secure data through a decentralized blockchain platform for enhanced security through virtual machines (VM) using VM management through asymmetric encryption for digital signature

An enhanced blockchain data computing platform for node-based core operations and trust data asset management provides a package-built solution using a blockchain platform for core banking and data asset management. Identity Management and Asset Management are constructed as coordinated extensions of inherent blockchain capabilities. Queries against a Master Data Asset World State provide interactive views into the “lives” of Trust Data Assets (TDAs) and a full-provenance historical view of Trust Data Asset transactions recorded in a Master Ledger. This ledger is then automatically shared as Distributed Ledger copies across the blockchain network to other Network Node applications thereby providing access to the same TDA objects and improving source data quality and TDA analytical results over time as the Network Nodes synchronize on a single trusted TDA Source of Record.
Owner:TRUIST BANK

Systems and methods for enhancing operational efficiency through standardized communication and automation

Systems and methods for automating and optimizing cross-institutional Request for Information (RFI) processing are described including generating and applying a RFI template, identity management, and multi-modal communication channels. A dynamic channel selection engine routes RFIs based on real-time analytics and compliance needs, while adaptive privacy controls protect sensitive data. Machine learning-driven workflow optimization predicts efficient processing steps and automates routine tasks. A plug-and-play integration layer enables seamless adoption with existing systems, and a unified audit framework ensures regulatory compliance.
Owner:JPMORGAN CHASE BANK NA

Identity Management in a Heterogeneous Cloud Computing System

A method for managing credentials in a heterogeneous cloud computing system, includes receiving, at a local computing system, a request to access a cloud resource on behalf of an end user, the request including a unique identifier associated with the end user and a resource identifier associated with the cloud resource, identifying, using the resource identifier, a predefined procedure for obtaining credentials for accessing the cloud resource, performing the predefined procedure to obtain the credentials for accessing the cloud resource, and accessing the cloud resource on behalf of the end user using the credentials.
Owner:AB INITIO TECHNOLOGY LLC

Three-weight quantum hybrid security chip based on quantum random source, equipment fingerprint and biological characteristics and identity authentication method

The invention discloses a quantum random source, equipment fingerprint and biological characteristic-based three-quantum hybrid security chip and an identity authentication method. The three-quantum hybrid security chip comprises a quantum random number generation unit; the system comprises an equipment safety processing unit, a biological characteristic processing unit, a triple mixing processing unit and a key derivation and identity management unit. The chip is integrated with a biological characteristic processing unit with living body detection and quantum fuzzy commitment functions, quantum randomness, equipment physical fingerprints and living body biological characteristics are subjected to deep cryptographic fusion through a triple hybrid processing unit, a unique hybrid result binding'equipment-user 'is generated, and a joint authentication key is derived according to the hybrid result; according to the invention, the method achieves the jump from equipment authentication to human-machine integrated strong authentication, thoroughly solves the risk of equipment embezzlement while inheriting the anti-quantum and anti-cloning advantages, and is suitable for scenes with the highest security level.
Owner:ANHUI YUNXI TECH CO LTD

Method and apparatus for constructing a permission topology structure based on least privilege

ActiveCN120850316BDigital data protectionOther databases indexingGraph operationsPublic interface
This application provides a method and apparatus for constructing a permission topology structure based on the lowest privilege level. The method includes: obtaining a non-public interface path template by structured parsing and classifying request data from an identity management platform and performing parameterized substitution; establishing a mapping relationship between the non-public interface path template and a preset identity management platform permission model to obtain a non-public interface parameter structure; merging the non-public interface parameter structure with an existing interface parameter structure to obtain a centralized interface parameter structure; under the lowest privilege role, starting from the initial node of the centralized interface parameter structure according to the task scheduling engine and graph operation model, performing a multi-hop breadth traversal along member relationships, role bindings, and permission operation paths to determine the corresponding permission graph; performing fine-grained dependency extraction on the permission graph; updating the permission graph according to the dependency relationships; and determining the corresponding permission topology structure. This application can improve the security and management efficiency of the identity and access management platform.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Positioning coordinate conversion system and method suitable for unmanned formation

The invention discloses a positioning coordinate conversion system and method suitable for an unmanned formation, and relates to the technical field of unmanned driving, geographic information engineering and Internet of Vehicles cooperative control crossing. The positioning coordinate conversion system suitable for the unmanned formation mainly comprises a vehicle-mounted sensing and computing terminal, a Mercator projection conversion unit and a vehicle-vehicle cooperative control unit, wherein the vehicle-mounted sensing and computing terminal realizes data interaction through a vehicle-mounted bus and a vehicle-vehicle communication network; the vehicle-mounted sensing and calculating terminal is used for positioning data acquisition, projection calculation and reference parameter storage; the Mercator projection conversion unit is used for coordinate conversion; and the vehicle-vehicle cooperative control unit is used for performing identity management of the master and slave nodes in the formation, reference point synchronization and calibration process control. By implementing the positioning coordinate conversion system and method suitable for the unmanned formation provided by the invention, the positioning precision and reliability of a local area can be improved, cooperative calibration of reference points in the formation is realized, and a scene is flexibly adapted.
Owner:SUZHOU YANXING CHANGKONG TECHNOLOGY CO LTD

Data security system asset and user identity management

Methods, systems, and devices for data security system computing asset and user identity management are described. For example, the data security system may obtain input records from multiple event information sources. The data security system may manage multiple assets for a client that may be associated with multiple user accounts. The multiple event information sources may provide computing asset identifiers (IDs) and / or user IDs in different formats. The data security system may determine linkages between different computing asset IDs between different user IDs in event records. For example, the data security system may use machine learning models to identify linkages between different computing asset IDs, between different user IDs in event logs, and / or between data records obtained from multiple event information sources. Accordingly, the data security system may provide a holistic view of events associated with the same computing asset and / or the same user account.
Owner:LUCIDUM INC

Identity management in a heterogeneous cloud computing system

A method for managing credentials in a heterogeneous cloud computing system, includes receiving, at a local computing system, a request to access a cloud resource on behalf of an end user, the request including a unique identifier associated with the end user and a resource identifier associated with the cloud resource, identifying, using the resource identifier, a predefined procedure for obtaining credentials for accessing the cloud resource, performing the predefined procedure to obtain the credentials for accessing the cloud resource, and accessing the cloud resource on behalf of the end user using the credentials.
Owner:AB INITIO TECHNOLOGY LLC

Active authorization control scheme for splitting learning model copyright and user dual verification

PendingCN121723442ADigital data protectionBiological modelsInference attackEngineering
The invention discloses an active authorization control scheme for splitting learning model copyright and user dual verification, and relates to the field of artificial intelligence. For a split learning model, dual verification of the model and a user identity is realized by constructing a fingerprint and embedding the user identity (ID). In the training stage, the fingerprints participate in a low proportion, so that the model can generate specific classification behaviors for the fingerprints while learning normal tasks. In the verification link, the model conducts reasoning on the fingerprint set, and the model copyright can be verified. And the client matches the extracted ID with the label output by the server to verify the identity of the user. The method supports active authorization control, and a normal model can be accessed when user identity verification is passed; and if not, the server is automatically switched to the shadow model added with the noise, so that high performance cannot be obtained. The method has high robustness and can resist pruning, fine tuning and label reasoning attacks. And a technical means is provided for copyright verification and user identity management of the split learning model.
Owner:EAST CHINA NORMAL UNIV

Nested resource identity management of cloud resources

A system is disclosed that includes the ability to enable nested sub-resources residing in a service lease to access resources owned by a customer residing in a customer lease without using a cross-lease policy. The disclosed system provides the ability to cause nested sub-resources residing in a service lease to obtain a resource subject identity of a higher level resource residing in a customer lease and use the identity of the higher level resource to access resources owned by a customer residing in the customer lease. Using the resource subject identity of its higher level of resource, the sub-resource can access the customer owned resource residing in the customer lease in a seamless manner without writing a cross-lease policy statement that provides permission to the sub-resource to access the customer owned resource.
Owner:ORACLE INT CORP

Identity-based digital signature encryption method and system in Internet of Things environment

The invention discloses an identity-based digital signature encryption method and system in an Internet of Things environment, and belongs to the technical field of Internet of Things security. The method comprises the following steps that: a key generation center KGC generates system parameters which comprise a bilinear mapping parameter, a hash function and a master key, and publishes a public parameter; receiving registration information submitted by a user or equipment to the KGC by using own identity information, and calculating and distributing a corresponding private key by the KGC according to the identity information; the sender encrypts the message by using the identity information of the receiver and signs the message by using a private key of the sender; and the receiver verifies the validity of the signature by using the identity information of the sender, and decrypts the message by using a private key of the receiver. According to the invention, the identity-based digital signature encryption is introduced into the communication of the Internet of Things, and through the design of the identity, namely the public key, the lightweight, efficient and flexible communication security guarantee of the Internet of Things is realized, the key and identity management is simplified, the efficient equipment authentication and dynamic access are realized, and the security and mutual trust of cross-scene communication are ensured.
Owner:BEIJING SANSEC TECH DEV

Revocable Internet of Vehicles authentication method based on alliance chain

The invention discloses a revocable Internet of Vehicles authentication method based on an alliance chain. The method comprises the following steps: initializing a system to establish a trust basis; the vehicle and road side unit registers to a trusted mechanism, the pseudo identity and PUF information are subjected to uplink storage, and an intelligent contract is deployed; after the vehicle initiates authentication, the road side unit verifies information from the chain and generates a new pseudo identity and a PUF challenge value; the vehicle generates a PUF response based on the challenge and calculates a session key, and the road side unit calls an on-chain contract to verify the response, completes bidirectional authentication and updates an on-chain identity state; and if the malicious vehicle is detected, the road side unit submits the chain revocation transaction, and the whole network refuses the authentication after consensus synchronization. According to the invention, a lightweight password technology, a physical unclonable function, an alliance block chain distributed account book and a dynamic identity management mechanism are integrated to construct an Internet of Vehicles authentication scheme considering high efficiency, safety, reliability and privacy protection, and effective support is provided for safe and reliable operation of an intelligent traffic system.
Owner:ANQING NORMAL UNIV

A cross-chain and DID-based efficient and reliable identity authentication method for Internet of Vehicles

PendingCN122119880ADetermine the legality of access in a timely mannerImplement cross-domain queryKey distribution for secure communicationEncryption apparatus with shift registers/memoriesInternet privacyEngineering
The application discloses a kind of based on cross-chain and DID's high-efficiency trusted identity authentication method of Internet of Vehicles, comprising: in key generation stage, identity management entity generates decentralized identity based on the registration request of target vehicle and issues verifiable identity credential, generates the digest or index mark corresponding to verifiable identity credential;In cross-domain identity authentication stage, when target vehicle v enters second trust domain, cross-domain authentication request is sent to second roadside unit, and cross-domain authentication request at least includes: the digest or index mark of verifiable identity credential, session-related temporary identification or pseudonym identification and the privacy proof information used to prove that target vehicle meets cross-domain access condition;Second roadside unit obtains the certificate state corresponding to digest or index mark;And when certificate state is valid, privacy proof information is verified, and cross-domain authentication is completed accordingly.The application realizes high-efficiency trusted authentication without revealing real identity and credential.
Owner:BEIJING JIAOTONG UNIV

Access authentication system for cloud side-end collaborative equipment based on selective disclosure DID

The invention relates to a selective disclosure DID-based access authentication system for cloud side end collaborative equipment, and belongs to the technical field of distributed authentication in a cloud side end collaborative scene. The system comprises a cloud side layer, an edge side layer and an end side layer, the cloud side is used as a distributed root of trust and a full-amount evidence storage layer, the side side is used as a localized authentication agent and a light-weight evidence storage layer, and the end side is used as a DID autonomous management and privacy protection execution layer; the cloud side comprises a block chain total node cluster, a root trust service module, a VC global verification engine and a data synchronization module; the side comprises a block chain lightweight client, an edge authentication agent module, a pre-verification engine and a cache module; the end side comprises a lightweight DID SDK, a VC management module, a selective disclosure engine and an EDHOC key exchange module. According to the invention, a safe, efficient and privacy-protecting solution is provided for identity management in the fields of the Internet of Things, the Internet of Vehicles and the like in the future.
Owner:BEIJING INST OF COMP TECH & APPL

Apparatus, method, and system for resource provider identity management and resource attestation and provisioning

PendingUS20260093548A1Resource allocationDigital data authenticationPhysical infrastructureUnique identifier
An approach is provided for resource provider identity management and resource attestation and provisioning. The approach involves, for example, determining a request to initiate a pre-provisioning of a resource component to an infrastructure network (e.g., Decentralized Physical Infrastructure Networks (DePIN). The request includes a specification label that advertises one or more capabilities of the resource. The approach also involves reading of a specification table and a unique identifier from the resource component. The approach further involves verification of the specification label based, at least in part, on the specification table. The approach further involves generating a bundle based, at least in part, on the specification table and the unique identifier. The bundle represents the verification of the specification label. The approach further involves associating the bundle with the resource component.
Owner:NOKIA SOLUTIONS & NETWORKS OY

Enhanced paging service with identity management for wireless networks

Apparatus, methods, and computer-readable media for performing wireless communication are disclosed. For example, a process for wireless communication may include sending a service registration request to an identity and routing service, where the service registration request includes a service identifier for a network service, where the network service is independent of the identity and routing service; receiving a first temporary service identifier (TSID) for the network service from the identity and routing service; assigning a first temporary device identifier (TUID) to the device; and sending the first TSID and the first TUID to the device for the first security context.
Owner:QUALCOMM INC

Identity management platform-based undisclosed interface structure induction method and device

The embodiment of the application provides a kind of based on identity management platform's undisclosed interface structure induction method and device, method includes: by the request data of parsing to oneself identity management platform obtains undisclosed interface data set, including request method and request path;Interface data belonging to identity management platform is classified by service type, by regular expression to the request path of each service category interface data set is dynamically variable matching and parameterized replacement, obtains standardized interface path, according to the path key field in standardized interface path carries out permission matching and obtains permission mapping table, the request method in permission mapping table is divided by semantics, determine corresponding operation type, according to the resource type in key field, operation type and standardized interface path are inducted and aggregated, determine the interface structure under each resource type, the structured display of undisclosed interface is carried out, and the application can improve the management efficiency and security of identity and access management platform.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Enabling coordinated identity management between an operator-managed mobile-edge platform and an external network

An edge processing platform in a communications network is configured to communicate with at least one edge application. The edge processing platform comprises at least one processor configured to receive a registration request, from the at least one edge application. The registration request is a request to register a token. The token represents a wireless transmit / receive unit (WTRU) and the token is used to associate at least one traffic filter to the token. The at least one processor is configured to register the token in response to the received registration request. The at least one processor is configured to activate, in response to registering the token, the at least one traffic filter based on the token for routing traffic for the WTRU between the communications network and a local network.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Kerberos identity authentication system and method based on SM9 and biological characteristic fuzzy extraction

The invention belongs to the technical field of network security, and relates to a Kerberos identity authentication system and method based on SM9 and biological characteristic fuzzy extraction. The system comprises a biological characteristic key generation module used for extracting a stable cryptographic key from biological characteristics of a user; the SM9 digital identity management module is used for performing identity management based on a cryptographic key; the Kerberos protocol enhancement module is used for enhancing the security of the Kerberos protocol; and the safety fusing and managing module is used for monitoring an authentication process and executing a fusing mechanism. According to the invention, the SM9 digital signature of the timestamp is embedded in the Kerberos authentication request, and the signature verification is used as the precondition of bill signing and issuing, so that an attacker is difficult to forge an effective authentication certificate.
Owner:XIAN UNIV OF POSTS & TELECOMM

Identification information reporting method and device, nonvolatile storage medium and electronic equipment

The invention discloses an identification information reporting method and device, a nonvolatile storage medium and electronic equipment. The method comprises the steps that after the terminal equipment receives an identity management request message, identification collection tasks are generated for card slots in the terminal equipment, and each card slot corresponds to one identification collection task; card slot identification information of the card slot and SIM card identification information of a user equipment module SIM card in the card slot are determined through the identification acquisition task; the identification information of the terminal equipment is reported to the network side, and the identification information comprises the card slot identification information of each card slot in the terminal equipment and the SIM card identification information in each card slot. The technical problems of tedious interaction process and signaling resource waste caused by too many signaling interaction processes when the identification information is reported in related technologies are solved.
Owner:CHINA TELECOM CORP LTD SATELLITE COMMUNICATIONS BRANCH

A task authentication and scheduling method, a task scheduler and a storage medium

The application discloses a task authentication and scheduling method, a task scheduler and a storage medium, relates to the technical field of distributed systems, and realizes identity authentication on an authentication request through container group configuration in the task scheduler. Each container group can flexibly configure resource quotas according to actual needs, maximally avoids unreasonable resource allocation, and has strong expansion capability. Each container group is independent of each other and redundant to each other, avoids single-point dependence of authentication services, improves the reliability of the whole authentication and task scheduling process, guarantees the fault tolerance of the task scheduler, and meanwhile, each container group can adopt different authentication strategies for identity authentication, so that the scheduler can effectively adapt to various types of authentication requests existing in a multi-data center scenario, realizes unified identity management and cross-cluster resource collaborative scheduling, improves authentication efficiency, and realizes more fine-granularity authorization based on request attributes during task scheduling execution, and further improves the security of the authentication and scheduling process.
Owner:JINAN MAIWEI INTELLIGENT TECHNOLOGY CO LTD