Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

188 results about "Identity management" patented technology

Identity management (IdM), also known as identity and access management (IAM or IdAM), is a framework of policies and technologies for ensuring that the proper people in an enterprise have the appropriate access to technology resources. IdM systems fall under the overarching umbrella of IT security and Data Management . Identity and access management systems not only identify, authenticate and authorize individuals who will be utilizing IT resources, but also the hardware and applications employees need to access. Identity and Access Management solutions have become more prevalent and critical in recent years as regulatory compliance requirements have become increasingly more rigorous and complex. It addresses the need to ensure appropriate access to resources across increasingly heterogeneous technology environments and to meet increasingly rigorous compliance requirements.

Decentralized identity management method based on trusted execution environment

PendingCN121098518AUser identity/authority verificationAccess structureComputer network
The invention discloses a decentralized identity management method based on a trusted execution environment, and the method comprises the steps: generating, isolating and storing a user decentralized identity in the trusted execution environment of equipment, carrying out the Hash signature of a decentralized identity document, and recording an uplink; the block chain consensus node verifies the decentralized document uplink transaction through a Byzantine fault-tolerant consensus mechanism and achieves consistency, and writes the metadata of the decentralized identity into the block; encrypting and storing the voucher in a trusted execution environment of the equipment by adopting a Pearson commitment, and supporting voucher Hash uplink and commitment uplink; and introducing a multilevel access structure based on a binary tree, and verifying the and / or logic combination voucher by adopting a depth-first search algorithm. According to the method, decentralized autonomy of the user identity and hardware security isolation are supported, and the reliability and privacy protection capability of user identity management are improved.
Owner:SOUTHEAST UNIV

Dynamic security authentication method for cross-platform information system integration

The invention discloses a dynamic security authentication method for cross-platform information system integration, and relates to the technical field of cross-platform dynamic authentication. A non-tampering identity trust chain is established through a block chain consensus algorithm, the problems of single-point fault and expansibility of centralized identity management are solved, cross-platform unified identity verification is realized, the problem that multi-factor authentication lacks intelligent risk assessment is solved through intelligent contract automatic verification and user behavior analysis, threats can be dynamically responded, and the user experience is improved. The authority is dynamically adjusted based on the risk level, and a real-time access control decision engine is combined, so that the problem of response lag of traditional access control is solved, accurate authority control is realized, and finally, a continuously optimized security authentication mechanism and a unified and coordinated cross-platform security protection system are formed.
Owner:TIBET JINHUI TECHNOLOGY CO LTD

Multi-tenant-based centralized authentication and authorization system, method, equipment and medium

The invention provides a multi-tenant-based centralized authentication and authorization method, system, device and medium, and belongs to the technical field of security and identity management, and the system comprises a unified portal layer, an authentication layer, an authorization layer, a strategy center and an audit monitoring layer. The unified portal layer receives a user request, identifies and injects a tenant identifier, and executes WAF rule verification, JWT signature verification and Token blacklist check; the authentication layer performs user or client credential verification on different accessed identity sources, generates and issues a JWT, and monitors the life cycle of a token; the authorization layer extracts an authority statement in the JWT and a locally cached strategy snapshot; the strategy center provides centralized storage, version management and visual editing of multi-tenant strategies; through cooperative work of each layer, accurate identification, unified authentication, centralized strategy management and comprehensive audit monitoring of tenants are realized. And the security, the expandability and the management efficiency of the system are effectively improved.
Owner:QINGDAO PORT INT CO LTD +1

Intelligent Cognitive AI Based Secure Protocol Channel to Create and Deploy Projects on Demand in Real Time Leveraging Unikernels

ActiveUS20250310352A1Securing communicationConfidentialityUnikernel
This invention introduces a sophisticated system for deploying projects on cloud platforms, combining Unikernels, Cyber Security Mesh Architecture (CSMA), MQTT protocol with SHA256 encryption, an Unikernel Orchestration Rules Engine (UORE), generative AI, and an innovative caching mechanism. Unikernels offer a secure, isolated environment for applications, reducing overhead and boosting performance. CSMA provides extensive security through analytics, identity management, and policy enforcement. The MQTT protocol, secured with SHA256, ensures the integrity and confidentiality of communications. UORE automates deployment, integrating a TLS terminator and data management for streamlined operation. Generative AI proactively resolves deployment challenges, particularly for complex applications, while the caching mechanism enhances performance and efficiency by minimizing latency. This integrated approach automates and secures the deployment process, enabling scalable, efficient, and real-time project creation and deployment in the cloud, thereby addressing the key challenges of cloud application hosting.
Owner:BANK OF AMERICA CORP

Transparent, on-demand route determination and delegated authorization in a large-scale, decentralized service mesh

A system can execute a containerized application that comprises a microservice in a decentralized service mesh architecture, and a sidecar. The system can intercept, by the containerized application, a call from the microservice that is directed to a remote endpoint, and direct the call to the sidecar. The system can communicate, by the sidecar to an identity manager, service account credentials associated with the microservice, resulting in receiving an identity token associated with the microservice. The system can determine, by the sidecar, connectivity information of the remote endpoint based on a virtual address of the remote endpoint identified in the call. The system can communicate, by the sidecar to a token exchanger, the identity token and the connectivity information, resulting in receiving an access token and a network route to the remote endpoint. The system can relay, by the sidecar, network traffic between the microservice and the remote endpoint.
Owner:DELL PROD LP

Internet of Things identity management method and system based on block chain

The invention discloses an Internet of Things identity management method and system based on a block chain, and relates to the technical field of fusion block chains, the method comprises identity prefabrication, dynamic authorization, security interaction and identity management and control, and in the identity prefabrication stage, a unique security seed is injected into equipment, a key pair is generated, an identifier is decentralized, and an access credential is decentralized. After verification of a block chain smart contract, writing the data into an alliance chain main chain to complete identity anchoring; dynamically authorizing through an attribute-based access control model, and setting a fine-grained permission boundary according to an access credential; the security interaction adopts a DID bidirectional authentication and batch signature verification technology to process a high-concurrency request, an instruction is verified and executed through a security module after being signed and packaged, and an audit triple is synchronously constructed for storage; and identity management and control triggers key rotation through an intelligent contract rule engine, so that the full-life-cycle safety of the identity is ensured, and the safety risk caused by permission abuse is effectively reduced.
Owner:南京傲拓智能控制技术有限公司

Access control method and device based on smart contract

The invention provides an access control method and device based on a smart contract, and the method comprises the steps: receiving a data request packet through a block chain, carrying out the matching of a request data index and at least one storage data index, and determining a successfully matched data owning device as a matching device; checking whether the current reputation value of the data request equipment is higher than the preset minimum reputation value of the matching equipment or not through the block chain based on the identity management contract according to the pseudonym of the request equipment; verifying whether the request equipment attribute set accords with the access control strategy through the block chain; generating a one-time authorization token based on the data sharing contract under the condition that the request equipment attribute set conforms to the access control strategy; sending the extracted data packet to a data request device through the block chain according to the one-time authorization token; and a multi-dimensional security foundation is laid for data sharing.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System for Cross-Domain Identity Management (SCIM) Proxy Service

A system for cross-domain identity management (SCIM) proxy service is described. A first SCIM endpoint receives, from a first SCIM client, a first message that includes a SCIM resource. The first SCIM endpoint is associated with a customer of the SCIM proxy service. The SCIM proxy service is configured as a first SCIM service provider for the first SCIM client. The first message is validated. The first SCIM proxy service determines that a third-party application is in scope for the SCIM resource, where the SCIM proxy service is configured as a second SCIM client for the third-party application. The SCIM proxy service transmits a second message to a second SCIM endpoint of the third-party application, the second message including the SCIM resource.
Owner:CLOUDFLARE INC

Universal method for realizing multiple conditions and search based on LDAP (Lightweight Directory Access Point)

The invention provides a universal method for realizing multi-condition and search based on LDAP, and belongs to the technical field of data retrieval of directory service and identity management. A user defines query conditions including attributes, values and logical relationships through a configuration file, a visual interface or an interface; the system parses the query condition model into a query condition model supporting nested combination of AND, OR and NOT by using a parser, and performs legality check and error prompt; and then a generator dynamically generates a filtering statement conforming to the LDAP grammar specification according to the model, and query is executed through an LDAP client. In order to improve the performance, common condition caching and high-frequency statement pre-compiling optimization are introduced, and an asynchronous query mode is supported. And the query result is returned in the form of structured data, and is matched with a display interface to support screening, sorting and exporting, so that the flexibility and maintainability of multi-condition query are improved.
Owner:UNICLOUD TECH CO LTD

Unmanned aerial vehicle cross-domain service function link accessing method based on alliance chain

The invention discloses an alliance chain-based unmanned aerial vehicle cross-domain service function link accessing method, which comprises the following steps of: 1, initializing a system and configuring an alliance chain, generating a global password parameter and a root key by a trusted mechanism, and finishing domain registration and certificate chain storage by each management domain edge server; 2, blockchain-driven identity management is carried out, and the unmanned aerial vehicle completes chain registration and anti-counterfeiting registration certificate acquisition through a domain edge server to which the unmanned aerial vehicle belongs; 3, deploying a flexible threshold signature algorithm to realize multi-domain joint signature and Byzantine fault tolerance; 4, executing a cross-domain SFC security authentication protocol, including SFC pre-verification and security authorization certificate issuing, first node verification starting, hop-by-hop key negotiation and handover certificate transmission, and on-chain auditing; and 5, based on the topology centrality and the path coverage, dynamically electing an orchestrator to realize load balancing. According to the invention, safe access and identity authentication of the cross-domain service function chain of the unmanned aerial vehicle are realized, safety, efficiency and expandability are balanced, and reliable guarantee is provided for cross-domain cooperation of the unmanned aerial vehicle.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Intelligent security method and device for industrial park, electronic equipment and storage medium

The invention relates to the technical field of Internet of Things, and provides an intelligent security method and device for an industrial park, electronic equipment and a storage medium. The method comprises the following steps: carrying out space-time alignment and feature fusion on sensor data to obtain environmental perception data, carrying out face feature recognition and hierarchical authorization processing on the environmental perception data to obtain character data in a region, and carrying out disaster prediction coupling on the character data in the region and the environmental perception data to obtain risk evolution data. And performing evacuation path planning on the risk evolution data and the data of the persons in the region to obtain evacuation navigation data, and performing emergency response processing on the evacuation navigation data and the real-time position coordinates of the persons to obtain an equipment control instruction set. According to the invention, refinement, real-time performance and automation are realized in links of environment perception, identity management, risk prediction, evacuation navigation and emergency response, and the safety protection capability of the industrial park is improved.
Owner:SHENZHEN KEAN DIGITAL CO LTD

Photovoltaic module decommissioning prediction method and system

The invention discloses a photovoltaic module decommissioning prediction and cyclic utilization management system and method, and belongs to the technical field of photovoltaic module life cycle management and prediction.The system comprises a central processing unit and a memorizer, and the memorizer stores computer programs; during execution, the component identity management module, the dynamic prediction analysis module and the full-chain tracing module are realized; the component identity management module distributes a unique identity code for the photovoltaic component and manages static attribute data and dynamic operation data; the dynamic prediction analysis module dynamically predicts the decommissioning time and scale of the component through a decommissioning analysis model based on the data; the full-chain tracing module records circulation information of the components in links of collection, transportation, storage and resource utilization by scanning codes after the components are decommissioned, so that full-chain tracing is realized; according to the invention, the problems of difficult management tracing and insufficient prediction precision in the prior art are solved, and fine management, intelligent prediction and efficient resource utilization of the photovoltaic module are realized.
Owner:CECEP SOLAR ENERGY TECH (ZHENJIANG) CO LTD

Intelligent building method and system for future community member architecture

The invention relates to the technical field of intelligent community data governance and main identity normalization management, and discloses a future community member architecture intelligent building method and system, and the method comprises the steps: carrying out the field semantic standardization of structured resident data; fusing the unstructured data; generating a ciphertext identifier; executing cross-system identity matching in combination with a field similarity function; and generating a unique main identity file. Compared with the prior art, the technical problems that data of multiple departments are independently managed, field structures are heterogeneous, a unified identity primary key is lacked, and particularly, high-precision identity fusion and normalization management cannot be realized under the complex data conditions of name duplication, different address expressions, field missing or untrusted sources and the like of residents are solved. According to the method, cross-system multi-source data fusion and identity uniqueness determination are realized through semantic hash slot construction, image-text joint recognition, multi-source fuzzy matching and a credible main file generation mechanism, and the uniqueness and credibility of future community resident identity data are improved.
Owner:ZHEJIANG THIRDNET TECH

Method and system for scaling blockchains via secure chain division

A method for secure chain division of a satellite chain by a validator node of a permission-based blockchain system includes executing, by communicating with a set of validator nodes of an original satellite chain of the blockchain system, a validator assignment scheme that splits the set of validator nodes of the original satellite chain into subsets of validator nodes of child chains of the original satellite chain, and running, by communicating with the validator nodes of the respective subsets, a reconfiguration protocol to set up the respective child chains and sending, to an identity management component that maintains identity information of all members of the blockchain system in a registry, a configuration update to record the division of the original satellite chain and corresponding creation of the child chains.
Owner:NEC CORP

Permission topological structure construction method and device based on minimum permission

The embodiment of the invention provides a permission topological structure construction method and device based on the lowest permission, and the method comprises the steps: carrying out the structural analysis and classification of request data from an identity management platform, carrying out the parameterized replacement, obtaining an unpublished interface path template, and storing the unpublished interface path template in a database; establishing a mapping relationship between the unpublished interface path template and a preset identity management platform permission model to obtain an unpublished interface parameter structure, and fusing the unpublished interface parameter structure with the existing interface parameter structure to obtain a centralized interface parameter structure; under the lowest permission role, starting from an initial node of the centralized interface parameter structure according to a task scheduling engine and a graph operation model, performing multi-hop breadth traversal along a member relationship, role binding and a permission operation path, determining a corresponding permission map, performing fine-grained dependency extraction on the permission map, and updating the permission map according to the dependency relationship, according to the method and the device, the security and the management efficiency of the identity and access management platform can be improved.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Methods and systems for point-of-use token validation with a core access network element

A method comprises performing, by a core access network element in a core network, a registration of a first client with the IMS core network based on an identifier of the first client and an access token associated with the first client, maintaining, by the core access network element, the registration of the first client with the IMS core network, receiving, by the core access network element, an access request from the first client, wherein the access request comprises the access token of the first client and the identifier of the first client, authenticating, by an authorization server, the access token in association with the first client, verifying, by an identity management server, a permission associated with the first client to use the access token to access the core network.
Owner:T MOBILE INNOVATIONS LLC

Identity management method and apparatus

An identity management method, wherein the method includes: A trusted authority (TA) device determines a pseudonymous identity (PID) of a terminal device i, and sends a first parameter to the terminal device i, where the first parameter indicates the PID of the terminal device i, and the PID of the terminal device i is determined based on a real identity (RID) of the terminal device i. Based on this, the TA device may determine the PID for the terminal device, to protect the RID of the terminal device. In addition, the PID of the terminal device is associated with the RID of the terminal device, so that the TA device can determine the RID of the terminal device based on the PID of the terminal device, and can determine the real identity of the terminal device when the terminal device performs a malicious operation or an unauthorized operation.
Owner:HUAWEI TECH CO LTD

Shield tunnel limited space safety operation protection early warning system

The utility model provides a shield tunnel limited space safety operation protection early warning system, comprising RFID tags carried by constructors and corresponding to the constructors one by one; an identity management server; the environment monitoring system is provided with a plurality of sensor assemblies and used for monitoring the temperature, humidity and air quality in the limited space of the shield tunnel; the UHF card reader is arranged at the entrance of the shield tunnel and used for preliminarily positioning the identity of a constructor; the face recognition system is used for carrying out face image acquisition and face recognition and registration on the entering constructors and counting the total number of the constructors; the environment safety early warning system is used for receiving the temperature, the humidity and the air quality which are monitored in real time and performing construction early warning according to a safety threshold range; and the monitoring center is connected with the identity management server, the face recognition system and the environment safety early warning system, is provided with a display screen, and is used for displaying data monitored by the environment monitoring system and early warning information.
Owner:JSTI GRP CO LTD +2

Cross-border e-commerce trade autonomous credible identity management method based on smart contract

The invention discloses a cross-border e-commerce trade autonomous and trusted identity management method based on an intelligent contract, and the method comprises the steps: controlling the access authority of an organization member through employing an identity registration contract on the basis of the construction of a cross-border e-commerce trade autonomous and trusted identity management organization, and recording and updating the identity information of the organization member through employing an information management contract, autonomous formulation and updating of an identity management contract are realized by using a decentralized decision-making mode based on proposal and voting, the credibility of identity management is guaranteed from a whole process and multiple levels, and members with governance qualification can promote formulation and updating of the identity management contract through a group decision-making mechanism of proposal and voting at any time, so that the identity management efficiency is improved. And the voting weight of the member depends on the type and number of the obtained qualification token, so that the identity management rule and system can timely and fairly reflect the common opinion of the organization member, and the credibility is guaranteed from the aspects of autonomy and adaptability of the identity management rule formulation.
Owner:霍尔果斯市数字化发展服务中心

Secure data through a decentralized blockchain platform for enhanced security through virtual machines (VM) using VM management through asymmetric encryption for digital signature

An enhanced blockchain data computing platform for node-based core operations and trust data asset management provides a package-built solution using a blockchain platform for core banking and data asset management. Identity Management and Asset Management are constructed as coordinated extensions of inherent blockchain capabilities. Queries against a Master Data Asset World State provide interactive views into the “lives” of Trust Data Assets (TDAs) and a full-provenance historical view of Trust Data Asset transactions recorded in a Master Ledger. This ledger is then automatically shared as Distributed Ledger copies across the blockchain network to other Network Node applications thereby providing access to the same TDA objects and improving source data quality and TDA analytical results over time as the Network Nodes synchronize on a single trusted TDA Source of Record.
Owner:TRUIST BANK

Systems and methods for enhancing operational efficiency through standardized communication and automation

Systems and methods for automating and optimizing cross-institutional Request for Information (RFI) processing are described including generating and applying a RFI template, identity management, and multi-modal communication channels. A dynamic channel selection engine routes RFIs based on real-time analytics and compliance needs, while adaptive privacy controls protect sensitive data. Machine learning-driven workflow optimization predicts efficient processing steps and automates routine tasks. A plug-and-play integration layer enables seamless adoption with existing systems, and a unified audit framework ensures regulatory compliance.
Owner:JPMORGAN CHASE BANK NA

Multi-system single sign-on security management method and system, storage medium and equipment

The invention relates to the technical field of information security, and discloses a multi-system single sign-on security management method and system, a storage medium and equipment, and the method comprises the steps: building a deep integration architecture between a directory service and an identity management server, and achieving the bidirectional synchronization of user attributes and security policies; a unified multi-factor authentication process and a security defense strategy are configured in the identity management server; by implementing password expiration risk assessment, multi-channel reminding and password self-service modification service, intelligent password life cycle active management is realized; intelligent account locking and self-adaptive unlocking based on multiple factors are implemented, and differentiated locking duration is dynamically calculated and executed; a cross-system unified session management and cooperative control mechanism is established, session anomaly real-time detection and scoring are performed through multi-dimensional feature fusion, one-point logout of global failure is realized, cross-system unified authentication, active security protection and cooperative management and control are realized, and the security and operation and maintenance efficiency of enterprise identity management are remarkably improved.
Owner:LINKPLAY TECHNOLOGY INC NANJING

Identity Management in a Heterogeneous Cloud Computing System

A method for managing credentials in a heterogeneous cloud computing system, includes receiving, at a local computing system, a request to access a cloud resource on behalf of an end user, the request including a unique identifier associated with the end user and a resource identifier associated with the cloud resource, identifying, using the resource identifier, a predefined procedure for obtaining credentials for accessing the cloud resource, performing the predefined procedure to obtain the credentials for accessing the cloud resource, and accessing the cloud resource on behalf of the end user using the credentials.
Owner:AB INITIO TECHNOLOGY LLC

Three-weight quantum hybrid security chip based on quantum random source, equipment fingerprint and biological characteristics and identity authentication method

The invention discloses a quantum random source, equipment fingerprint and biological characteristic-based three-quantum hybrid security chip and an identity authentication method. The three-quantum hybrid security chip comprises a quantum random number generation unit; the system comprises an equipment safety processing unit, a biological characteristic processing unit, a triple mixing processing unit and a key derivation and identity management unit. The chip is integrated with a biological characteristic processing unit with living body detection and quantum fuzzy commitment functions, quantum randomness, equipment physical fingerprints and living body biological characteristics are subjected to deep cryptographic fusion through a triple hybrid processing unit, a unique hybrid result binding'equipment-user 'is generated, and a joint authentication key is derived according to the hybrid result; according to the invention, the method achieves the jump from equipment authentication to human-machine integrated strong authentication, thoroughly solves the risk of equipment embezzlement while inheriting the anti-quantum and anti-cloning advantages, and is suitable for scenes with the highest security level.
Owner:ANHUI YUNXI TECH CO LTD

Key management method based on Schuud + algorithm and QKD (quantum key distribution)

The invention discloses a key management method based on an algorithm and a QKD, and relates to the technical field of data security and a system, the method comprises the following steps: a key management center KMC generates global public parameters; after the KMC signs the global public parameters, the global public parameters are published to a block chain network; obtaining an anti-quantum identity certificate sum by a device node; and constructing secure communication; and dynamically updating and generating a session key according to the shared key; and performing communication on the basis; a digital identity certificate signing and issuing mechanism based on a post-quantum signature algorithm ML-DSA is uniformly signed and issued by a key management center, and uplink certificate storage is performed in combination with a block chain network. The mechanism ensures that the certificate cannot be tampered and can be traced, meanwhile, the defense capability for key source counterfeiting and tampering attacks in the quantum computing environment is remarkably improved, the limitation of traditional centralized CA in the aspects of credibility and transparency is broken through, and the mechanism is suitable for a distributed infrastructure environment with high identity management requirements.
Owner:SICHUAN UNIV

Method and apparatus for constructing a permission topology structure based on least privilege

ActiveCN120850316BDigital data protectionOther databases indexingGraph operationsPublic interface
This application provides a method and apparatus for constructing a permission topology structure based on the lowest privilege level. The method includes: obtaining a non-public interface path template by structured parsing and classifying request data from an identity management platform and performing parameterized substitution; establishing a mapping relationship between the non-public interface path template and a preset identity management platform permission model to obtain a non-public interface parameter structure; merging the non-public interface parameter structure with an existing interface parameter structure to obtain a centralized interface parameter structure; under the lowest privilege role, starting from the initial node of the centralized interface parameter structure according to the task scheduling engine and graph operation model, performing a multi-hop breadth traversal along member relationships, role bindings, and permission operation paths to determine the corresponding permission graph; performing fine-grained dependency extraction on the permission graph; updating the permission graph according to the dependency relationships; and determining the corresponding permission topology structure. This application can improve the security and management efficiency of the identity and access management platform.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Positioning coordinate conversion system and method suitable for unmanned formation

The invention discloses a positioning coordinate conversion system and method suitable for an unmanned formation, and relates to the technical field of unmanned driving, geographic information engineering and Internet of Vehicles cooperative control crossing. The positioning coordinate conversion system suitable for the unmanned formation mainly comprises a vehicle-mounted sensing and computing terminal, a Mercator projection conversion unit and a vehicle-vehicle cooperative control unit, wherein the vehicle-mounted sensing and computing terminal realizes data interaction through a vehicle-mounted bus and a vehicle-vehicle communication network; the vehicle-mounted sensing and calculating terminal is used for positioning data acquisition, projection calculation and reference parameter storage; the Mercator projection conversion unit is used for coordinate conversion; and the vehicle-vehicle cooperative control unit is used for performing identity management of the master and slave nodes in the formation, reference point synchronization and calibration process control. By implementing the positioning coordinate conversion system and method suitable for the unmanned formation provided by the invention, the positioning precision and reliability of a local area can be improved, cooperative calibration of reference points in the formation is realized, and a scene is flexibly adapted.
Owner:SUZHOU YANXING CHANGKONG TECHNOLOGY CO LTD

System and method for multiple user authentication and identification in cross-domain communications

PCT designated stageWO2026007278A1Securing communicationInternet privacyEngineering
A method and system for cross-domain authentication of a device of a first domain and one or more users of a second domain are provided. An identity manager of the first domain generates identification information based on temporary IDs of the device and the user IDs of one or more users. The identity information along with credentials or certificates is used for authentication of a user of one or more users and the device via a first authenticator of the first domain and a second authenticator of the second domain, while the real ID of the device is secured with the identity manager.
Owner:HUAWEI TECH CO LTD

Data security system asset and user identity management

Methods, systems, and devices for data security system computing asset and user identity management are described. For example, the data security system may obtain input records from multiple event information sources. The data security system may manage multiple assets for a client that may be associated with multiple user accounts. The multiple event information sources may provide computing asset identifiers (IDs) and / or user IDs in different formats. The data security system may determine linkages between different computing asset IDs between different user IDs in event records. For example, the data security system may use machine learning models to identify linkages between different computing asset IDs, between different user IDs in event logs, and / or between data records obtained from multiple event information sources. Accordingly, the data security system may provide a holistic view of events associated with the same computing asset and / or the same user account.
Owner:LUCIDUM INC

A cross-enterprise identity management and authorization control method, device and medium

A cross-enterprise identity management and authorization control method, device and medium belong to the technical field of permission management. The method comprises the following steps: S1, registering an enterprise space on a platform, and registering a user identity in the enterprise space; S2, defining the permissions of different application roles at the platform level, setting the specific post permissions at the enterprise level, associating the corresponding application roles based on the post of the user's belonging enterprise and allocating the corresponding access permissions, and generating a static permission baseline with multiple levels of constraints; S3, calculating the dynamic controlled range of user permissions based on the context attributes of the user and the space-time access strategy and identity access strategy of the platform resources, wherein the context attributes include time, space and user identity; and S4, combining the static permission baseline and the calculation result of the dynamic controlled range to calculate the real-time resource permission data of the user to perform real-time control of the resource permissions. The application provides a dynamic permission engine and a multi-level identity authentication system to reduce the risk of permission abuse.
Owner:AVIC GOLD NETWORK (BEIJING) TECHNOLOGY CO LTD