Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

93 results about "Identity management system" patented technology

An identity management system refers to an information system, or to a set of technologies that can be used for enterprise or cross-network identity management...

Software-defined vehicle and ai-convergence system of systems

The present disclosure relates to transportation and related methods and systems including software-defined vehicles, vehicle operating states, an identity management system, an intelligent digital twin system that creates, manages, and provides digital twins for transportation systems using sensor and other data, and the integration of a transportation system with an AI convergence system of systems, providing a multi-layered system for intelligent automation and data-driven decision making across operational aspects of a transportation system.
Owner:STRONG FORCE TP PORTFOLIO 2022 LLC

Techniques for managing artificial intelligence agents using user-controlled authorization network tokens

A user of an identity management system may configure a software agent with a set of parameters within one or more user interfaces of an agent management service. The set of parameters may include an identifier of an application programming interface (API) endpoint of a first service that the software agent is authorized to query and one or more permissions associated with queries to the API endpoint by the software agent. Further, the user may receive an authentication token for the software agent from the agent management service. The software agent may use the authentication token for accessing resources of the service via the API endpoint in accordance with the one or more permissions. Thus, the user may configure the first software agent with the authentication token to enable the software agent to perform the queries to the API endpoint of the first service.
Owner:OKTA INC

Authority management method and system for double-token decoupling and dynamic token mapping

The invention discloses an authority management method and system for double-token decoupling and dynamic token mapping, and relates to the technical field of information security. According to the method, a user identity is verified in a unified identity management system; receiving the user identity identifier in the target subsystem and generating a local permission token based on the permission model; in the token mapping service, when it is detected that a mapping relation is not established, the user identity identifier, the target subsystem identifier and the time slice identifier are combined according to a preset sequence, a one-time random factor is inserted, and a mapping key is generated through two-time abstract calculation of different secure hash functions and key parameters; determining a unified expiration time based on a smaller value of the validity period of the double tokens, generating a mapping value by using the exclusive key of the target subsystem in an encryption manner, and storing the mapping value, the mapping key and the expiration time in a distributed cache in an association manner; and the validity of the identity token is verified and the corresponding local permission token is obtained during user access, so that cross-system security access is realized, permission data migration is reduced, and compatibility and security are improved.
Owner:NANJING HUADUN ELECTRIC POWER INFORMATION SAFETY EVALUATION CO LTD

Systems and Methods for Data Correlation and Artifact Matching in Identity Management Artificial Intelligence Systems

Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may support the correlation of identities from authoritative source systems and accounts from non-authoritative source systems using artificial intelligence techniques.
Owner:SAILPOINT TECHNOLOGIES INC

Techniques for managing artificial intelligence agents using user-controlled authorization network tokens

A user of an identity management system may configure a software agent with a set of parameters within one or more user interfaces of an agent management service. The set of parameters may include an identifier of an application programming interface (API) endpoint of a first service that the software agent is authorized to query and one or more permissions associated with queries to the API endpoint by the software agent. Further, the user may receive an authentication token for the software agent from the agent management service. The software agent may use the authentication token for accessing resources of the service via the API endpoint in accordance with the one or more permissions. Thus, the user may configure the first software agent with the authentication token to enable the software agent to perform the queries to the API endpoint of the first service.
Owner:OKTA INC

Establishing sessions via a proxy service

A method for managing sessions with an application server via an identity management system is described. The method may include receiving, via an application protocol interface (API) of a cloud service of the identity management system, a first request associated with a first user for user access to an account of the application server. The API may transmit a second request for a secrets service to encrypt a password associated with the first user to a public key of a keypair. The API may receive a message including the encrypted password and forward the encrypted password to an end-client. The identity management system may establish a session on behalf of the first user for the account of the application server based on the end-client having access to a private key of the keypair.
Owner:OKTA INC

System and method for predictive platforms in identity management artificial intelligence systems using analysis of network identity graphs

Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize artificial intelligence approaches for determining health indicators for the identity management state of an enterprise. Specifically, in certain embodiments, an artificial intelligence based identity management systems may utilize one or more components to generate signals associated with the identity management state of an enterprise based on a network identity graph and evaluate feature spaces of these input signals from these components based on a global objective function or the like.
Owner:SAILPOINT TECHNOLOGIES INC

Privacy protection autonomous identity management system and method based on block chain under scene of Internet of Things

The invention relates to the technical field of block chain application, in particular to a privacy protection autonomous identity management system and method based on a block chain in an Internet of Things scene, each identity issuer and an identity verification party form an alliance chain, the identity issuer generates system parameters and registers, uploads and revokes an equipment identity, and the identity verification party verifies the equipment identity. The verification party retrieves equipment identity verification and revocation information uploaded to the block chain by the issuer, and constructs a distributed management framework of the Internet of Things equipment identity based on the block chain; an identity issuer generates a plurality of unassociated anonymous identities for equipment based on a one-way hash chain, privacy protection certificateless signature is realized, and one-time anonymous identities are added into leaf nodes based on a Merkle Tree structure to generate verifiable declarations so as to protect association among a plurality of verifiable declarations of the equipment and realize attribute selective disclosure; and the on-chain node realizes management of device identity registration, authentication, tracking and revocation and updating of a full life cycle by using an intelligent contract. According to the invention, the privacy requirement of the Internet of Things equipment can be met.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Dynamic policy and network security zone generation

An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.
Owner:OKTA INC

Trusted identity management system and method for unmanned aerial vehicle

The invention discloses a trusted identity management system and method for an unmanned aerial vehicle based on a trust score and a Merkel tree structure. Unmanned aerial vehicle identity management is involved; the objective of the invention is to provide a trusted identity management system and method for an unmanned aerial vehicle for identity verification and trust evaluation scenes in a dynamic environment. On the basis of the existing trust scoring mechanism technology, the method is improved, the influence of node behavior change is considered in unmanned aerial vehicle group cooperation based on dynamic trust scoring and a Merkel tree structure, the historical performance and real-time information of nodes are comprehensively considered in the identity management process, and the identity management efficiency is improved. The risk of network paralysis caused by a single-point fault is reduced, and a safe and efficient identity management method suitable for a complex task environment is provided.
Owner:CIVIL AVIATION FLIGHT UNIV OF CHINA

Lightweight Internet of Things equipment identity management system based on block chain

The invention provides a lightweight Internet of Things equipment identity management system based on a block chain, which comprises a system initial module, an identity registration module, a lightweight identity verification module, an identity updating module, an identity revocation module and a light node information maintenance module, and realizes functions of identity registration, verification, revocation, updating and the like based on a block chain environment. The equipment identity credibility is ensured; a block chain light node is deployed on the Internet of Things node to reduce resource consumption; a revocation scheme based on a Bloom filter and a cryptographic accumulator is used to realize light weight of identity verification so as to adapt to the environment of the Internet of Things. The method has the advantages that the problem of inaccurate identity bidirectional verification of the Internet of Things equipment under the condition of poor network is solved, the cost of identity verification of the Internet of Things equipment is reduced, and the judgment performance of the Internet of Things on the identity state is improved.
Owner:XINJIANG DIGITAL CERTIFICATE CERTIFICATION CENT (CO LTD)

Version control integration in cross-domain-based authentication systems

A system, method, and computer-program product includes receiving, from a third-party identity management system, an authentication response indicating a set of login attributes; obtaining, from an identity resolution service, a set of identity and authorization attributes using the set of login attributes, the set of identity and authorization attributes including a unique user identifier (UID); granting, by the identity resolution service, a session initiation token when the set of identity and authorization attributes satisfy predefined authorization criteria; in response to the identity resolution service granting the session initiation token: allocating a compute session and a persistent storage resource to the unique UID; executing, via the compute session, an operation that modifies files stored in the persistent storage resource; and transmitting, to a version control system, a version control operation that records the files modified in the persistent storage resource to a code repository using the unique UID or group identifiers.
Owner:SAS INSTITUTE INC

Identity management system, identity management method, and program

An identity management system with a circuity which causes a memory to store a prescribed plurality of pieces of qualification information in association with an information storage medium owned by a user, the plurality of pieces of qualification information being at least one of one or more pieces of qualification information that are assigned to an identity serving as the user existing in a physical space and that indicate that the user has a prescribed qualification, and one or more pieces of qualification information that are assigned to an identity serving as an avatar that corresponds to the user existing in a metaverse.
Owner:TOPPAN HOLDINGS INC

Risk and anomaly detection using a large language model

Methods, systems, devices, and computer-readable media for risk and anomaly detection using one or more large language model (LLMs) are described. An identity management system may use an LLM to generate a predicted next system event or sequence of next system events associated with a user of the identity management system. A detected system event associated with the user may be compared to a predicted next system event of the sequence of predicted next system events. Based on a difference between the detected system event and the predicted next system event, a risk level associated with the detected system event may be determined. Based on determining that the risk level satisfies a threat threshold and based on policy information associated with the identity management system a remediation action may be performed.
Owner:OKTA INC

Authenticated firmware transmittal upgrade system

The invention relates to a method of uploading firmware (FW) to a device comprising an end node (EN), applying an authentication tag (AT) to the firmware released, the releasing and end node side share a digital key, and utilize an identical MAC-algorithm for calculating a message authentication tag (AT), utilized by the end node device (EN) for authenticating the firmware received. A MAC algorithm (THAMC) included secure token (INT) calculates the message authentication tag (AT) in the end node (EN), the token (INT) incorporating a unique identity (TID), and the method further comprising a secure identity management system (CS) for authenticating an identity (ID) of end node devices, and an end node configuration management module (CMS) releasing firmware to an end node (EN) upon receipt of an identity authentication (IDAUR) of the end node (EN) from the secure identity management system (CS).
Owner:SANDGRAIN BV

Continuous tag identification method and system based on COTS RFID

The invention provides a continuous tag identification method and system based on COTS RFID, and relates to the technical field of RFID. According to the method, a label identity management system is established by pre-distributing static identifiers to a label user storage area, and accurate screening and grouping of labels are realized by matching a standard selection instruction with specific mask parameters; an optimized filtering mechanism is adopted to distinguish known tags from unknown tags, and the tag state is confirmed and updated step by step through a staged polling strategy; wherein a static identification pre-storage mechanism obviously reduces performance requirements on label hardware, a selective polling method based on mask matching improves processing efficiency, a multi-stage fingerprint filtering structure ensures identification accuracy, and the design completely following a C1G2 protocol specification enables a system to be directly deployed in an existing RFID infrastructure.
Owner:ANHUI UNIVERSITY OF TECHNOLOGY

Techniques for generating policy recommendations and insights using generative AI

ActiveUS12647461B2Securing communicationEngineeringClient organization
Methods, systems, devices, and computer-readable media for generating authentication policy recommendations and insights using generative AI are described. An authentication policy recommendation system associated with an identity management system may receive a request from a client organization for an authentication policy configuration recommendation for an application associated with the client organization. One or more recommended authentication policy rules may be generated for the application using a machine learning model (such as a large-learning model). The model may output the authentication policy rules in a machine-readable format. Based on an analysis of applying information about the client organization to the model-generated recommended authentication policy rule to generate a context-specific recommended authentication policy rule, an impact of implementing the context-specific recommended authentication policy rule may be determined and output. The impact of implementing the context-specific recommended authentication policy rule may be determined in advance of implementing the recommended authentication policy rule.
Owner:OKTA INC

Passwordless vault access through secure vault enrollment

Methods, systems, and devices are described. A client may perform a sign-in or registration process to register a user with an application of an identity management system. The sign-in or registration process may include receiving an indication of at least one credential associated with an identity of the user. The client may perform a vault enrollment process to configure a secure vault for the user of the application. The client may upload data to the identity management system. The data may be associated with the secure vault configured for the user of the application. The client may perform a device pairing operation to transfer a Recovery Key from the first client device to a second client device of the user. The client may use one or more keys stored in the vault to access the application of the identity management system via the second client device of the user.
Owner:OKTA INC

Using contextual security challenges to prevent bot attacks

Computer-implemented methods, systems, and devices for generating security challenges are described. An identity management system may obtain image descriptions. The image descriptions may include a first image description set that corresponds to a sequence of events and a second image description set that is unassociated with the sequence of events. The identity management system may obtain images based on the image descriptions. The images may include a first image set that corresponds to the sequence of events and a second image set that is unassociated with the sequence of events. The identity management system may generate a security challenge using the images. The security challenge may request for a user to identify the sequence of events from the images. Identification of the sequence of events may be based on each image of the first image set being contextually relevant to the sequence of events.
Owner:OKTA INC

Server authenticity verification using a chain of nested proofs

An identity management system may support an authentication server. According to techniques described herein, a client device may receive an authentication challenge from the authentication server. The authentication challenge may include an indication of a first public key of a first keypair, a first signature of a first private key of the first keypair, and second signatures of second private keys of second keypairs. The client device may determine whether the first public key is a trusted key that is pinned by the client device. The client device may determine, based on determining that the first public key is not the trusted key that is pinned by the client device, whether at least one signature of the second signatures can be validated by the trusted key. The client device may validate the authentication challenge based on determining that the at least one signature can be validated by the trusted key.
Owner:OKTA INC

Extra-organizational application management

An identity management system may receive one or more signals associated with a sign-in to a first application via a first user profile of an organization of the identity management system. The first application may be disassociated with first applications having been authorized access by an administrator of the organization via the identity management system. The identity management system may generate a report indicative of second applications accessed via user profiles of the organization, user profiles that accessed the second applications, and a timestamp of access to the second applications by each of the user profiles, where the second applications include the first application, and where the user profiles include the first user profile. The identity management system may perform an application management operation associated with an application of the second applications, a user profile of the user profiles, or both based on generating the report.
Owner:OKTA INC

Methods and systems for secure and reliable identity-based computing

The embodiments herein provide a secure computing resource set identification, evaluation, and management arrangement, employing in various embodiments some or all of the following highly reliable identity related means to establish, register, publish and securely employ user computing arrangement resources in satisfaction of user set target contextual purposes. Systems and methods may include, as applicable, software and hardware implementations for Identity Firewalls; Awareness Managers; Contextual Purpose Firewall Frameworks for situationally germane resource usage related security, provisioning, isolation, constraining, and operational management; liveness biometric, and assiduous environmental, evaluation and authentication techniques; Repute systems and methods assertion and fact ecosphere; standardized and interoperable contextual purpose related expression systems and methods; purpose related computing arrangement resource and related information management systems and methods, including situational contextual identity management systems and methods; and / or the like.
Owner:ADVANCED ELEMENTAL TECHNOLOGIES INC

Application association risk detection using association rule learning

PendingUS20260111559A1Platform integrity maintainanceEngineeringAssociation rule learning
An authentication and authorization system associated with an identity management system may receive a set of access patterns from two or more applications that are associated with a set of users and may indicate which of the two or more applications a respective user has access to. The system may generate association rules that are based on the set of access patterns to indicate associations between the two or more applications and the set of users. Moreover, for each respective user, the system may generate an indication of a likelihood that the respective user is associated with a security risk by accessing the two or more applications that is based on the association rules and one or more parameters associated with the respective user. The system may then generate an indication of actions for the system to execute in response to a respective user being associated with the security risk.
Owner:OKTA INC

Techniques for simplifying identity management implementations related to application subscription management

PCT designated stage expiredWO2025117303A1Version controlDigital data protectionFeature setEngineering
A data management system may receive a subscription schema for a version of an application associated with the data management system. The subscription schema may include a set of feature sets for a set of plans of the version of the application. The data management system may then configure an integration between the application and a transaction processing platform. Further, the data management system may configure one or more pipelines for the application via an identity management system and based on the subscription schema. Additionally, the data management system may generate an entitlement setup for the version of the application to be used by an entitlement management system. The data management system may then receive data via a request about a subscription plan for an account associated with the user. The entitlement management system may then authorize or deny the request based on the entitlement setup.
Owner:OKTA INC

Fiducial mark document sharing

In an example implementation according to aspects of the present disclosure, a system, method, and storage medium comprising a processor, memory, and instructions to receive a fiducial mark, wherein the fiducial mark encodes a user identity, a face descriptor, a background descriptor, and a signature block. The system decodes the fiducial mark and validates the signature block against a public key repository system. The system validates the user identity against an identity management system and validates the face descriptor against a face descriptor repository. The system validates the background descriptor against a background descriptor repository and responsive to successful validation, allows a document to be shared in an online conference.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Systems, methods, and storage media for administration of identity management systems within an identity infrastructure

Systems, methods, and storage media for controlling access to an application in an identity infrastructure are disclosed. The method comprises requesting to access the application, wherein the application is associated with an identity system, determining a status of the identity system, the status comprising one of an available status and unavailable status. When the status comprises the unavailable status, transmitting a request for additional information, receiving the additional information, and verifying the additional information by referencing an identity cache associated with the identity system. In some cases, the method comprises authenticating a user to access the application when the status comprises the available status and / or the additional information has been verified, and in response to authenticating the user at the application, sending a communication from the application to the user, granting the user access to the application.
Owner:STRATA IDENTITY INC