Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

260 results about "Identity management" patented technology

Identity management (IdM), also known as identity and access management (IAM or IdAM), is a framework of policies and technologies for ensuring that the proper people in an enterprise have the appropriate access to technology resources. IdM systems fall under the overarching umbrella of IT security and Data Management . Identity and access management systems not only identify, authenticate and authorize individuals who will be utilizing IT resources, but also the hardware and applications employees need to access. Identity and Access Management solutions have become more prevalent and critical in recent years as regulatory compliance requirements have become increasingly more rigorous and complex. It addresses the need to ensure appropriate access to resources across increasingly heterogeneous technology environments and to meet increasingly rigorous compliance requirements.

Distributed vehicle-mounted advertisement node encryption communication and tamper-proof system

The invention relates to the technical field of encryption communication, in particular to a distributed vehicle-mounted advertisement node encryption communication and tamper-proofing system. Comprising a vehicle-mounted advertisement node layer, an edge computing layer, a block chain layer and a cloud platform layer, the vehicle-mounted advertisement node layer is composed of a plurality of vehicle-mounted advertisement nodes and is responsible for collecting vehicle sensor data, playing advertisement content and performing local encryption. The edge computing layer is composed of edge computing nodes distributed in a regional base station or a road side unit and is responsible for dynamic key distribution, lightweight data verification and node state monitoring; the block chain layer comprises an advertisement evidence storage module and an identity management module, adopts an alliance chain, stores advertisement content hash, node identity certificates and operation logs, and ensures that data cannot be tampered; the cloud platform layer comprises an advertisement distribution module, a secret key life cycle module and an anomaly analysis module, and is responsible for global advertisement content distribution, secret key life cycle management and anomaly detection analysis.
Owner:JIANGSU XUNYO NEW MEDIA CO LTD

Patient-empowered data management having a secure blockchain architecture with decentralized ownership

A blockchain-based system and method for secure and auditable sharing of medical image studies between providers, patients, and authorized recipients. The system has modules for verifying identities of trusted healthcare providers as issuers of medical data, managing secure storage of medical images and metadata, minting non-fungible tokens (NFTs) representing patient ownership of studies, authenticating patient consent for data sharing, and controlling access to shared data by authorized parties. Issuer registration authenticates healthcare providers permitted to submit studies by verifying credentials against authoritative sources. Secure data management employs cryptographic wallets and smart contracts to ensure only verified issuers can create new medical data NFTs on the blockchain. Automated processing extracts medical data such as image files and metadata upon upload for separate secure storage, with metadata references encrypted in the associated NFT. The system generates patient-controlled wallets for managing ownership of their medical NFTs without separate identity verification. Patient consent for sharing data is authenticated through multi-signature wallets requiring patient approval before minting study NFTs. Controlled access for other parties is gated by cryptographic proofs of authorization without exposing data. The immutable blockchain ledger records all sharing transactions initiated through patient and provider wallets, providing transparency and an auditable trail of how and when medical data is shared or accessed and by whom. The decentralized architecture promotes patient control, security, and accountability in managing sensitive healthcare information.
Owner:MEDIMINT LLC

Cross-domain authentication method based on block chain

The invention relates to a cross-domain authentication method based on a block chain, and the method comprises the steps: obtaining distributed identity data, carrying out the coding through employing a preset hash function, and obtaining a coded identity; recording an identity verification log based on the encoded identity label, and retrieving label consistency data from an account book according to the verification request to obtain a legality verification result; obtaining a dynamic permission allocation strategy through a legality verification result, generating a temporary access credential meeting the access requirement, and determining the content of the dynamic credential; extracting a permission range based on the dynamic voucher content, encrypting the permission range by adopting a zero-knowledge proof protocol, acquiring proof data, distributing the proof data to a cross-domain access target domain, and if the target domain feeds back a verification request, checking credibility according to the proof data, and obtaining an access permission validity result, extracting an access demand matching degree for comparison verification, and determining a cross-domain access passing state. According to the method, the trusted identity management requirement in a complex heterogeneous network environment can be met.
Owner:SHAANXI SCI TECH UNIV

Decentralized identity management method based on trusted execution environment

PendingCN121098518AUser identity/authority verificationAccess structureComputer network
The invention discloses a decentralized identity management method based on a trusted execution environment, and the method comprises the steps: generating, isolating and storing a user decentralized identity in the trusted execution environment of equipment, carrying out the Hash signature of a decentralized identity document, and recording an uplink; the block chain consensus node verifies the decentralized document uplink transaction through a Byzantine fault-tolerant consensus mechanism and achieves consistency, and writes the metadata of the decentralized identity into the block; encrypting and storing the voucher in a trusted execution environment of the equipment by adopting a Pearson commitment, and supporting voucher Hash uplink and commitment uplink; and introducing a multilevel access structure based on a binary tree, and verifying the and / or logic combination voucher by adopting a depth-first search algorithm. According to the method, decentralized autonomy of the user identity and hardware security isolation are supported, and the reliability and privacy protection capability of user identity management are improved.
Owner:SOUTHEAST UNIV

Dynamic security authentication method for cross-platform information system integration

The invention discloses a dynamic security authentication method for cross-platform information system integration, and relates to the technical field of cross-platform dynamic authentication. A non-tampering identity trust chain is established through a block chain consensus algorithm, the problems of single-point fault and expansibility of centralized identity management are solved, cross-platform unified identity verification is realized, the problem that multi-factor authentication lacks intelligent risk assessment is solved through intelligent contract automatic verification and user behavior analysis, threats can be dynamically responded, and the user experience is improved. The authority is dynamically adjusted based on the risk level, and a real-time access control decision engine is combined, so that the problem of response lag of traditional access control is solved, accurate authority control is realized, and finally, a continuously optimized security authentication mechanism and a unified and coordinated cross-platform security protection system are formed.
Owner:TIBET JINHUI TECHNOLOGY CO LTD

Multi-tenant-based centralized authentication and authorization system, method, equipment and medium

The invention provides a multi-tenant-based centralized authentication and authorization method, system, device and medium, and belongs to the technical field of security and identity management, and the system comprises a unified portal layer, an authentication layer, an authorization layer, a strategy center and an audit monitoring layer. The unified portal layer receives a user request, identifies and injects a tenant identifier, and executes WAF rule verification, JWT signature verification and Token blacklist check; the authentication layer performs user or client credential verification on different accessed identity sources, generates and issues a JWT, and monitors the life cycle of a token; the authorization layer extracts an authority statement in the JWT and a locally cached strategy snapshot; the strategy center provides centralized storage, version management and visual editing of multi-tenant strategies; through cooperative work of each layer, accurate identification, unified authentication, centralized strategy management and comprehensive audit monitoring of tenants are realized. And the security, the expandability and the management efficiency of the system are effectively improved.
Owner:QINGDAO PORT INT CO LTD +1

Implementation method for constructing unified user authentication center based on OIDC framework

The invention discloses an implementation method for constructing a unified user authentication center based on an OIDC framework, and the method comprises the steps: S1, integrating user data sources, and constructing a unified science and technology management user information base; s2, constructing a unified user authentication center of the science and technology management industry; s3, related functions of each business platform system in the science and technology management industry are upgraded, OIDC unified user authentication service docking is completed, and unified identity management is realized; and S4, system interfaces of all service platforms in the science and technology management industry are comprehensively and jointly debugged, and seamless cooperation of all the service platforms in the science and technology management industry and the OIDC unified user authentication center is ensured. The method has the advantages that the problems of informatization cross-system and cross-platform identity management and authority control in the science and technology management industry are solved, efficient and safe user identity management is realized, the system safety is enhanced, the system convenience is improved, the system integration complexity is reduced, and the informatization system management efficiency is improved.
Owner:INST OF SCI & TECHN INFORMATION OF CHINA

Multi-chain collaborative central node switching method for ensuring authentication efficiency and data reliability

The invention discloses a multi-chain collaborative center node switching method for ensuring authentication efficiency and data reliability, which is applied to a system comprising an identity chain, an authentication chain, an edge computing center, a key generation center, a plurality of unmanned aerial vehicle clusters and at least two aerial directors, and is characterized in that the identity chain is used for identity management of all the unmanned aerial vehicle clusters; the authentication chain is jointly maintained by all the unmanned aerial vehicle clusters and all the air directors. According to the multi-chain collaborative central node switching method for ensuring the authentication efficiency and the data reliability provided by the invention, the secure communication between the clusters can be quickly established in the authentication process of the unmanned aerial vehicle clusters, and the switching of the central nodes can be quickly carried out when the central nodes are threatened and attacked in a multi-chain manner; the new central node continues to execute the flight task, and the forward and backward security is ensured in the switching process, so that the problems of low authentication efficiency of the unmanned aerial vehicle cluster, strong dependency of the central node and insufficient security in the switching process of the central node are solved.
Owner:XIAN TECH UNIV

Intelligent Cognitive AI Based Secure Protocol Channel to Create and Deploy Projects on Demand in Real Time Leveraging Unikernels

ActiveUS20250310352A1Securing communicationConfidentialityUnikernel
This invention introduces a sophisticated system for deploying projects on cloud platforms, combining Unikernels, Cyber Security Mesh Architecture (CSMA), MQTT protocol with SHA256 encryption, an Unikernel Orchestration Rules Engine (UORE), generative AI, and an innovative caching mechanism. Unikernels offer a secure, isolated environment for applications, reducing overhead and boosting performance. CSMA provides extensive security through analytics, identity management, and policy enforcement. The MQTT protocol, secured with SHA256, ensures the integrity and confidentiality of communications. UORE automates deployment, integrating a TLS terminator and data management for streamlined operation. Generative AI proactively resolves deployment challenges, particularly for complex applications, while the caching mechanism enhances performance and efficiency by minimizing latency. This integrated approach automates and secures the deployment process, enabling scalable, efficient, and real-time project creation and deployment in the cloud, thereby addressing the key challenges of cloud application hosting.
Owner:BANK OF AMERICA CORP

Extensible system for credible management of academic / educational certificate

The invention relates to an extensible system for credible management of academic / educational credentials, and belongs to the field of block chain technology and credible management of academic / educational credentials. The system comprises a user layer, an application layer, a contract layer, an under-chain storage layer, a block chain bottom layer and a management layer. The user layer supports a user to perform user registration, identity verification, certificate service and identity management; the application layer provides a certificate management operation function, an intelligent contract operation function, role and authority management and an API interface; the block chain bottom layer is based on an FISCO-BCOS platform, an alliance chain architecture is adopted, and a z-PBFT consensus mechanism is used; the management layer relates to monitoring and management of nodes in the block chain network, dynamic adding or exiting of the nodes and log management. According to the method, the block chain storage cost is effectively reduced, the expansibility and performance of the system are improved, the credibility and integrity of the data are considered, and the method is suitable for a large-scale distributed academic / educational certificate credibility management scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Transparent, on-demand route determination and delegated authorization in a large-scale, decentralized service mesh

A system can execute a containerized application that comprises a microservice in a decentralized service mesh architecture, and a sidecar. The system can intercept, by the containerized application, a call from the microservice that is directed to a remote endpoint, and direct the call to the sidecar. The system can communicate, by the sidecar to an identity manager, service account credentials associated with the microservice, resulting in receiving an identity token associated with the microservice. The system can determine, by the sidecar, connectivity information of the remote endpoint based on a virtual address of the remote endpoint identified in the call. The system can communicate, by the sidecar to a token exchanger, the identity token and the connectivity information, resulting in receiving an access token and a network route to the remote endpoint. The system can relay, by the sidecar, network traffic between the microservice and the remote endpoint.
Owner:DELL PROD LP

Internet of Things identity management method and system based on block chain

The invention discloses an Internet of Things identity management method and system based on a block chain, and relates to the technical field of fusion block chains, the method comprises identity prefabrication, dynamic authorization, security interaction and identity management and control, and in the identity prefabrication stage, a unique security seed is injected into equipment, a key pair is generated, an identifier is decentralized, and an access credential is decentralized. After verification of a block chain smart contract, writing the data into an alliance chain main chain to complete identity anchoring; dynamically authorizing through an attribute-based access control model, and setting a fine-grained permission boundary according to an access credential; the security interaction adopts a DID bidirectional authentication and batch signature verification technology to process a high-concurrency request, an instruction is verified and executed through a security module after being signed and packaged, and an audit triple is synchronously constructed for storage; and identity management and control triggers key rotation through an intelligent contract rule engine, so that the full-life-cycle safety of the identity is ensured, and the safety risk caused by permission abuse is effectively reduced.
Owner:南京傲拓智能控制技术有限公司

System for active participation and improvement of school security

A device, system and method to log a communication device into services using a device identifier is provided. An identity management (IM) computing device receives, from a certificate authority, a first digital certificate, and further receives from a given communication device, a second digital certificate and a device identifier associated with the given communication device. The IM computing device successfully validates the second digital certificate using the first digital certificate, obtains a user identifier associated with the device identifier, and issues, to the given communication device, one or more tokens that include the user identifier, the one or more tokens enabling the given communication device to log into one or more services using the user identifier.
Owner:MOTOROLA SOLUTIONS INC

Access control method and device based on smart contract

The invention provides an access control method and device based on a smart contract, and the method comprises the steps: receiving a data request packet through a block chain, carrying out the matching of a request data index and at least one storage data index, and determining a successfully matched data owning device as a matching device; checking whether the current reputation value of the data request equipment is higher than the preset minimum reputation value of the matching equipment or not through the block chain based on the identity management contract according to the pseudonym of the request equipment; verifying whether the request equipment attribute set accords with the access control strategy through the block chain; generating a one-time authorization token based on the data sharing contract under the condition that the request equipment attribute set conforms to the access control strategy; sending the extracted data packet to a data request device through the block chain according to the one-time authorization token; and a multi-dimensional security foundation is laid for data sharing.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System for Cross-Domain Identity Management (SCIM) Proxy Service

A system for cross-domain identity management (SCIM) proxy service is described. A first SCIM endpoint receives, from a first SCIM client, a first message that includes a SCIM resource. The first SCIM endpoint is associated with a customer of the SCIM proxy service. The SCIM proxy service is configured as a first SCIM service provider for the first SCIM client. The first message is validated. The first SCIM proxy service determines that a third-party application is in scope for the SCIM resource, where the SCIM proxy service is configured as a second SCIM client for the third-party application. The SCIM proxy service transmits a second message to a second SCIM endpoint of the third-party application, the second message including the SCIM resource.
Owner:CLOUDFLARE INC

Universal method for realizing multiple conditions and search based on LDAP (Lightweight Directory Access Point)

The invention provides a universal method for realizing multi-condition and search based on LDAP, and belongs to the technical field of data retrieval of directory service and identity management. A user defines query conditions including attributes, values and logical relationships through a configuration file, a visual interface or an interface; the system parses the query condition model into a query condition model supporting nested combination of AND, OR and NOT by using a parser, and performs legality check and error prompt; and then a generator dynamically generates a filtering statement conforming to the LDAP grammar specification according to the model, and query is executed through an LDAP client. In order to improve the performance, common condition caching and high-frequency statement pre-compiling optimization are introduced, and an asynchronous query mode is supported. And the query result is returned in the form of structured data, and is matched with a display interface to support screening, sorting and exporting, so that the flexibility and maintainability of multi-condition query are improved.
Owner:UNICLOUD TECH CO LTD

Online entropy estimation method based on parallel technology

The invention discloses an online entropy estimation method based on a parallel technology, and aims to solve the problem that a conventional random number entropy estimation method is slow in speed and cannot meet the detection requirements of a modern high-speed random number generator, the parallel technology is applied to entropy estimation, and the speed of entropy estimation is greatly improved by utilizing the parallel computing capability of a GPU (Graphic Processing Unit). The method and the device can meet the requirement of rapid detection of key security in the information interaction process of identity management. Besides, by means of the post-processing method of the entropy estimation result, the reliable entropy estimation result can be reserved and inaccurate values can be eliminated regardless of sudden change data or gradual change data. Besides, in the entropy estimation process, the calculation formula of the statistical entropy is improved according to the size change of the sample size, the accuracy of random number entropy estimation is improved, and therefore the requirement for accurate detection of key security in the information interaction process of identity management is met.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY +1

Unmanned aerial vehicle cross-domain service function link accessing method based on alliance chain

The invention discloses an alliance chain-based unmanned aerial vehicle cross-domain service function link accessing method, which comprises the following steps of: 1, initializing a system and configuring an alliance chain, generating a global password parameter and a root key by a trusted mechanism, and finishing domain registration and certificate chain storage by each management domain edge server; 2, blockchain-driven identity management is carried out, and the unmanned aerial vehicle completes chain registration and anti-counterfeiting registration certificate acquisition through a domain edge server to which the unmanned aerial vehicle belongs; 3, deploying a flexible threshold signature algorithm to realize multi-domain joint signature and Byzantine fault tolerance; 4, executing a cross-domain SFC security authentication protocol, including SFC pre-verification and security authorization certificate issuing, first node verification starting, hop-by-hop key negotiation and handover certificate transmission, and on-chain auditing; and 5, based on the topology centrality and the path coverage, dynamically electing an orchestrator to realize load balancing. According to the invention, safe access and identity authentication of the cross-domain service function chain of the unmanned aerial vehicle are realized, safety, efficiency and expandability are balanced, and reliable guarantee is provided for cross-domain cooperation of the unmanned aerial vehicle.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Intelligent security method and device for industrial park, electronic equipment and storage medium

The invention relates to the technical field of Internet of Things, and provides an intelligent security method and device for an industrial park, electronic equipment and a storage medium. The method comprises the following steps: carrying out space-time alignment and feature fusion on sensor data to obtain environmental perception data, carrying out face feature recognition and hierarchical authorization processing on the environmental perception data to obtain character data in a region, and carrying out disaster prediction coupling on the character data in the region and the environmental perception data to obtain risk evolution data. And performing evacuation path planning on the risk evolution data and the data of the persons in the region to obtain evacuation navigation data, and performing emergency response processing on the evacuation navigation data and the real-time position coordinates of the persons to obtain an equipment control instruction set. According to the invention, refinement, real-time performance and automation are realized in links of environment perception, identity management, risk prediction, evacuation navigation and emergency response, and the safety protection capability of the industrial park is improved.
Owner:SHENZHEN KEAN DIGITAL CO LTD

Identity authentication method and system, electronic equipment and storage medium

The invention discloses an identity authentication method and system, electronic equipment and a storage medium. The method comprises a password authentication login stage and a certificate authentication login stage, in a password authentication login stage, after an authentication client receives identity identification information and password information sent by a user terminal and generates a password hash value, an authentication server receives the password hash value, a random salt value and the identity identification information from the authentication client and sends the password hash value to the user terminal; the authentication server verifies the legality of the received password hash value; in a certificate authentication login stage, the authentication server sends a first random value and timestamp information to the user terminal, and after a digital signature is generated by the user terminal according to the identity identification information, the first random value, a second random value selected by a user and the timestamp information, the first random value and the second random value are sent to the user terminal. And the authentication server receives the digital signature and the authorization certificate from the user terminal, and verifies the legality of the digital signature and the authorization certificate. By adopting the technical scheme provided by the invention, the security of terminal identity management is improved by the two-factor identity authentication method fusing the dynamic verification password and the certificate.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER

Photovoltaic module decommissioning prediction method and system

The invention discloses a photovoltaic module decommissioning prediction and cyclic utilization management system and method, and belongs to the technical field of photovoltaic module life cycle management and prediction.The system comprises a central processing unit and a memorizer, and the memorizer stores computer programs; during execution, the component identity management module, the dynamic prediction analysis module and the full-chain tracing module are realized; the component identity management module distributes a unique identity code for the photovoltaic component and manages static attribute data and dynamic operation data; the dynamic prediction analysis module dynamically predicts the decommissioning time and scale of the component through a decommissioning analysis model based on the data; the full-chain tracing module records circulation information of the components in links of collection, transportation, storage and resource utilization by scanning codes after the components are decommissioned, so that full-chain tracing is realized; according to the invention, the problems of difficult management tracing and insufficient prediction precision in the prior art are solved, and fine management, intelligent prediction and efficient resource utilization of the photovoltaic module are realized.
Owner:CECEP SOLAR ENERGY TECH (ZHENJIANG) CO LTD

Method and device for managing multiple system accounts and permissions in enterprise and medium

The invention discloses a method and equipment for managing multiple system accounts and permissions in an enterprise and a medium, and relates to the technical field of enterprise user management. The method comprises the following steps: switching an interface of a central identity management platform corresponding to an administrator account to a system interface corresponding to a first system environment based on a first system environment switching request sent by the administrator account; receiving a user account allocation request sent by the administrator account; wherein the user account allocation request comprises account allocation information of at least one user and system permission information of an allocated account; and creating a target user account for the user based on the account allocation information, and determining a first operation authority of the target user account in the first system environment based on the system authority information. According to the invention, on the premise of ensuring the security of account and authority management, the rapid integration of the central identity management platform and each self-developed system is realized, the management efficiency is improved, and the operation complexity is reduced.
Owner:AULTON NEW ENERGY AUTOMOBILE TECHNOLOGY CO LTD

Intelligent building method and system for future community member architecture

The invention relates to the technical field of intelligent community data governance and main identity normalization management, and discloses a future community member architecture intelligent building method and system, and the method comprises the steps: carrying out the field semantic standardization of structured resident data; fusing the unstructured data; generating a ciphertext identifier; executing cross-system identity matching in combination with a field similarity function; and generating a unique main identity file. Compared with the prior art, the technical problems that data of multiple departments are independently managed, field structures are heterogeneous, a unified identity primary key is lacked, and particularly, high-precision identity fusion and normalization management cannot be realized under the complex data conditions of name duplication, different address expressions, field missing or untrusted sources and the like of residents are solved. According to the method, cross-system multi-source data fusion and identity uniqueness determination are realized through semantic hash slot construction, image-text joint recognition, multi-source fuzzy matching and a credible main file generation mechanism, and the uniqueness and credibility of future community resident identity data are improved.
Owner:ZHEJIANG THIRDNET TECH

Method and system for scaling blockchains via secure chain division

A method for secure chain division of a satellite chain by a validator node of a permission-based blockchain system includes executing, by communicating with a set of validator nodes of an original satellite chain of the blockchain system, a validator assignment scheme that splits the set of validator nodes of the original satellite chain into subsets of validator nodes of child chains of the original satellite chain, and running, by communicating with the validator nodes of the respective subsets, a reconfiguration protocol to set up the respective child chains and sending, to an identity management component that maintains identity information of all members of the blockchain system in a registry, a configuration update to record the division of the original satellite chain and corresponding creation of the child chains.
Owner:NEC CORP

Permission topological structure construction method and device based on minimum permission

The embodiment of the invention provides a permission topological structure construction method and device based on the lowest permission, and the method comprises the steps: carrying out the structural analysis and classification of request data from an identity management platform, carrying out the parameterized replacement, obtaining an unpublished interface path template, and storing the unpublished interface path template in a database; establishing a mapping relationship between the unpublished interface path template and a preset identity management platform permission model to obtain an unpublished interface parameter structure, and fusing the unpublished interface parameter structure with the existing interface parameter structure to obtain a centralized interface parameter structure; under the lowest permission role, starting from an initial node of the centralized interface parameter structure according to a task scheduling engine and a graph operation model, performing multi-hop breadth traversal along a member relationship, role binding and a permission operation path, determining a corresponding permission map, performing fine-grained dependency extraction on the permission map, and updating the permission map according to the dependency relationship, according to the method and the device, the security and the management efficiency of the identity and access management platform can be improved.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Remote medical identity management method and system based on multi-factor authentication and dynamic trust evaluation

The invention discloses a telemedicine identity management method and system based on multi-factor authentication and dynamic trust evaluation in the technical field of computer data processing. The method comprises the steps that a data sharing platform based on a block chain preprocesses identity information of telemedicine users and information of medical entities; registering a medical service center and performing user registration and medical sensor registration through the medical service center; and authenticating the information of the electronic smart card of the telemedicine patient and updating the data and access authority of the three-factor authentication. Through a three-factor authentication system integrating the iris, the intelligent card and the static password, different scenes and user requirements are adapted, the authentication safety and convenience are improved, meanwhile, the system can automatically adjust the authentication mode according to the risk level of the user, the authentication safety and efficiency are balanced, the problem that user authentication is complex in telemedicine is solved, and the user experience is improved. The convenience and safety of biological characteristic factor authentication can be balanced.
Owner:WUXI HUACAN INTELLIGENT TECHNOLOGY CO LTD

Methods and systems for point-of-use token validation with a core access network element

A method comprises performing, by a core access network element in a core network, a registration of a first client with the IMS core network based on an identifier of the first client and an access token associated with the first client, maintaining, by the core access network element, the registration of the first client with the IMS core network, receiving, by the core access network element, an access request from the first client, wherein the access request comprises the access token of the first client and the identifier of the first client, authenticating, by an authorization server, the access token in association with the first client, verifying, by an identity management server, a permission associated with the first client to use the access token to access the core network.
Owner:T MOBILE INNOVATIONS LLC

User identity generation and account processing systems and methods

Systems and methods which generate and use user identities are described. A user account processing method comprises: receiving a connection request from a user device, the connection request comprising a user identifier of a user, a subscriber identity module number associated with the user, and a device identifier of a device associated with the user; sending a user identity generation request to a user identity management server; receiving a user identity for the user from the user identity management server; requesting payment card details associated with the user identity from a payment card management system; receiving payment card details associated with the user identity from the payment card management system; generating a payment request comprising the payment card details associated with the user identity; and receiving payment confirmation in response to the payment request.
Owner:MASTERCARD ASIAPACIFIC PTE LTD

Personal credit information management method and system based on block chain

The invention discloses an individual credit investigation information management method and system based on a block chain, and relates to the technical field of individual credit investigation. The personal credit information management system based on the block chain comprises an identity management module, an authorization application module, a data encryption and decryption module, a data sharing module and a credit report module. According to the method, data is stored in a decentralization mode, a third-party mechanism does not need to participate in data storage, the problem of data sharing is solved, personal credit investigation management is performed by using the block chain, information judgment is performed on the data storage process by using the smart contract, the security of data storage is ensured, and the user experience is improved. By applying for authorization and storing the applied authorization in the block chain, the information authorization security of the user is ensured.
Owner:SHENZHEN HONGTAI HEXIN TECHNOLOGY CO LTD

Identity management method and apparatus

An identity management method, wherein the method includes: A trusted authority (TA) device determines a pseudonymous identity (PID) of a terminal device i, and sends a first parameter to the terminal device i, where the first parameter indicates the PID of the terminal device i, and the PID of the terminal device i is determined based on a real identity (RID) of the terminal device i. Based on this, the TA device may determine the PID for the terminal device, to protect the RID of the terminal device. In addition, the PID of the terminal device is associated with the RID of the terminal device, so that the TA device can determine the RID of the terminal device based on the PID of the terminal device, and can determine the real identity of the terminal device when the terminal device performs a malicious operation or an unauthorized operation.
Owner:HUAWEI TECH CO LTD