Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Identity management system" patented technology

An identity management system refers to an information system, or to a set of technologies that can be used for enterprise or cross-network identity management...

Version control integration in cross-domain-based authentication systems

A system, method, and computer-program product includes receiving, from a third-party identity management system, an authentication response indicating a set of login attributes; obtaining, from an identity resolution service, a set of identity and authorization attributes using the set of login attributes, the set of identity and authorization attributes including a unique user identifier (UID); granting, by the identity resolution service, a session initiation token when the set of identity and authorization attributes satisfy predefined authorization criteria; in response to the identity resolution service granting the session initiation token: allocating a compute session and a persistent storage resource to the unique UID; executing, via the compute session, an operation that modifies files stored in the persistent storage resource; and transmitting, to a version control system, a version control operation that records the files modified in the persistent storage resource to a code repository using the unique UID or group identifiers.
Owner:SAS INSTITUTE INC

Identity management system, identity management method, and program

An identity management system with a circuity which causes a memory to store a prescribed plurality of pieces of qualification information in association with an information storage medium owned by a user, the plurality of pieces of qualification information being at least one of one or more pieces of qualification information that are assigned to an identity serving as the user existing in a physical space and that indicate that the user has a prescribed qualification, and one or more pieces of qualification information that are assigned to an identity serving as an avatar that corresponds to the user existing in a metaverse.
Owner:TOPPAN HOLDINGS INC

Risk and anomaly detection using a large language model

Methods, systems, devices, and computer-readable media for risk and anomaly detection using one or more large language model (LLMs) are described. An identity management system may use an LLM to generate a predicted next system event or sequence of next system events associated with a user of the identity management system. A detected system event associated with the user may be compared to a predicted next system event of the sequence of predicted next system events. Based on a difference between the detected system event and the predicted next system event, a risk level associated with the detected system event may be determined. Based on determining that the risk level satisfies a threat threshold and based on policy information associated with the identity management system a remediation action may be performed.
Owner:OKTA INC

Techniques for generating policy recommendations and insights using generative AI

ActiveUS12647461B2Securing communicationEngineeringClient organization
Methods, systems, devices, and computer-readable media for generating authentication policy recommendations and insights using generative AI are described. An authentication policy recommendation system associated with an identity management system may receive a request from a client organization for an authentication policy configuration recommendation for an application associated with the client organization. One or more recommended authentication policy rules may be generated for the application using a machine learning model (such as a large-learning model). The model may output the authentication policy rules in a machine-readable format. Based on an analysis of applying information about the client organization to the model-generated recommended authentication policy rule to generate a context-specific recommended authentication policy rule, an impact of implementing the context-specific recommended authentication policy rule may be determined and output. The impact of implementing the context-specific recommended authentication policy rule may be determined in advance of implementing the recommended authentication policy rule.
Owner:OKTA INC

Passwordless vault access through secure vault enrollment

Methods, systems, and devices are described. A client may perform a sign-in or registration process to register a user with an application of an identity management system. The sign-in or registration process may include receiving an indication of at least one credential associated with an identity of the user. The client may perform a vault enrollment process to configure a secure vault for the user of the application. The client may upload data to the identity management system. The data may be associated with the secure vault configured for the user of the application. The client may perform a device pairing operation to transfer a Recovery Key from the first client device to a second client device of the user. The client may use one or more keys stored in the vault to access the application of the identity management system via the second client device of the user.
Owner:OKTA INC

Server authenticity verification using a chain of nested proofs

An identity management system may support an authentication server. According to techniques described herein, a client device may receive an authentication challenge from the authentication server. The authentication challenge may include an indication of a first public key of a first keypair, a first signature of a first private key of the first keypair, and second signatures of second private keys of second keypairs. The client device may determine whether the first public key is a trusted key that is pinned by the client device. The client device may determine, based on determining that the first public key is not the trusted key that is pinned by the client device, whether at least one signature of the second signatures can be validated by the trusted key. The client device may validate the authentication challenge based on determining that the at least one signature can be validated by the trusted key.
Owner:OKTA INC

Extra-organizational application management

An identity management system may receive one or more signals associated with a sign-in to a first application via a first user profile of an organization of the identity management system. The first application may be disassociated with first applications having been authorized access by an administrator of the organization via the identity management system. The identity management system may generate a report indicative of second applications accessed via user profiles of the organization, user profiles that accessed the second applications, and a timestamp of access to the second applications by each of the user profiles, where the second applications include the first application, and where the user profiles include the first user profile. The identity management system may perform an application management operation associated with an application of the second applications, a user profile of the user profiles, or both based on generating the report.
Owner:OKTA INC

Methods and systems for secure and reliable identity-based computing

PendingUS20260080062A1Digital data protectionDigital data authenticationSoftware engineeringIdentity management system
The embodiments herein provide a secure computing resource set identification, evaluation, and management arrangement, employing in various embodiments some or all of the following highly reliable identity related means to establish, register, publish and securely employ user computing arrangement resources in satisfaction of user set target contextual purposes. Systems and methods may include, as applicable, software and hardware implementations for Identity Firewalls; Awareness Managers; Contextual Purpose Firewall Frameworks for situationally germane resource usage related security, provisioning, isolation, constraining, and operational management; liveness biometric, and assiduous environmental, evaluation and authentication techniques; Repute systems and methods assertion and fact ecosphere; standardized and interoperable contextual purpose related expression systems and methods; purpose related computing arrangement resource and related information management systems and methods, including situational contextual identity management systems and methods; and / or the like.
Owner:ADVANCED ELEMENTAL TECHNOLOGIES INC

Application association risk detection using association rule learning

PendingUS20260111559A1Platform integrity maintainanceEngineeringAssociation rule learning
An authentication and authorization system associated with an identity management system may receive a set of access patterns from two or more applications that are associated with a set of users and may indicate which of the two or more applications a respective user has access to. The system may generate association rules that are based on the set of access patterns to indicate associations between the two or more applications and the set of users. Moreover, for each respective user, the system may generate an indication of a likelihood that the respective user is associated with a security risk by accessing the two or more applications that is based on the association rules and one or more parameters associated with the respective user. The system may then generate an indication of actions for the system to execute in response to a respective user being associated with the security risk.
Owner:OKTA INC

Fiducial mark document sharing

In an example implementation according to aspects of the present disclosure, a system, method, and storage medium comprising a processor, memory, and instructions to receive a fiducial mark, wherein the fiducial mark encodes a user identity, a face descriptor, a background descriptor, and a signature block. The system decodes the fiducial mark and validates the signature block against a public key repository system. The system validates the user identity against an identity management system and validates the face descriptor against a face descriptor repository. The system validates the background descriptor against a background descriptor repository and responsive to successful validation, allows a document to be shared in an online conference.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Systems, methods, and storage media for administration of identity management systems within an identity infrastructure

Systems, methods, and storage media for controlling access to an application in an identity infrastructure are disclosed. The method comprises requesting to access the application, wherein the application is associated with an identity system, determining a status of the identity system, the status comprising one of an available status and unavailable status. When the status comprises the unavailable status, transmitting a request for additional information, receiving the additional information, and verifying the additional information by referencing an identity cache associated with the identity system. In some cases, the method comprises authenticating a user to access the application when the status comprises the available status and / or the additional information has been verified, and in response to authenticating the user at the application, sending a communication from the application to the user, granting the user access to the application.
Owner:STRATA IDENTITY INC

Systems and methods for distributed ledger-based identity management

Systems and methods for distributed ledger-based identity management are disclosed. In one embodiment, a computer-based method for managing attestations may include: (1) receiving, by a computer program executed by an electronic device for an identity consumer and from an identity provider, a notification from an identity provider server that an attestation is available, wherein the attestation may be generated by the identity provider based on authorization from a system operator and may include a chain of trust comprising an identification of the system operator and the identity provider; (2) requesting, by the computer program, the attestation from the identity provider; and (3) downloading, by the computer program, the attestation to an identity consumer electronic wallet for the identity consumer. The identity provider may commit the downloading of the attestation to a distributed ledger, wherein the distributed ledger maintains a current status for the attestation.
Owner:JPMORGAN CHASE BANK NA

Computer-implemented method for controlling access in a network

Proposed is a computer-implemented method for controlling access in a network having at least two users, having the following steps: - a first identity corresponding to a first user (11) of the at least two users is created and stored in an encrypted form in an identity management system (15), - a second identity corresponding to a second user of the at least two users is created and stored in an encrypted form in the identity management system (15), - a first right of access to a first information or to a first software function or to a first product is assigned to the first identity, - the second user requests access to the information or software function or product from the first user (11) by sending a request to the identity management system (15), - the identity management system (15) checks the authentication of the second user on the basis of the second identity, - the identity management system sends the request to the first user (11), - the first user (11) rejects or approves the request by responding to the identity management system (15), - the identity management system (15) checks the authentication of the first user (11) on the basis of the first identity, - depending on the check, a secret information stored in an encrypted form is shared with the second user, which secret information allows the second user to access the information, software function or product, - the second user accesses the first information or the first software function or the product.
Owner:ROBERT BOSCH GMBH

Dynamic policy and network security zone generation

An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.
Owner:OKTA INC

Agent dynamic address and identity management system based on cache capability

The invention discloses a proxy dynamic address and identity management system based on cache capability, and the system comprises a capability feature extraction module which is used for obtaining a capability attribute set of a proxy in real time, carrying out the denoising and normalization of the capability attribute set, and generating a standardized capability feature set; and a high-dimensional semantic coding module connected with the capability feature extraction module and used for mapping the standardized capability feature set to a high-dimensional feature space by using a preset semantic coding model to generate a high-dimensional feature vector. Perfect balance is achieved between data timeliness and resource efficiency through the system, the updating strategy periodically scans capacity change through a fixed time window, and the passive updating strategy can respond to model upgrading or hardware recovery emergency state events. The combination of the two ensures that the data in the edge node cache is always kept synchronous with the proxy body state of the physical world, and the storage space is prevented from being fully occupied by invalid historical data through a first-in first-out strategy.
Owner:SHENZHEN JUDAO STAR MAP OVERSEAS INFORMATION TECHNOLOGY CO LTD

Identification management system and identification management method

To provide: an identity management system that individually manages design, manufacturing, use, and discard of a product that is a molded body; and an identity management method.SOLUTION: An identity management system that manages traceability of a molded body includes: a molded body information acquisition part 1 that acquires imaging information about a molded body; an identification information conversion part 2 that converts a random pattern in a predetermined region of the imaging information to identification information; and an information control part 8 that performs processing of storing manufacturing information and lifecycle information about the molded body in a molded body management DB 3 for each of identification information.SELECTED DRAWING: Figure 3
Owner:HITACHI LTD

Malicious actor model training using threat intelligence recommendations

In some identity management systems, to train a machine learning (ML) model to detect malicious actors, a model training service may receive a set of training data that is automatically labeled with a first label and a second label in response to an authentication challenge. The model training service may use a subset of the training data (e.g., that is labeled with the first label) and label the subset with the second label based on respective training data elements satisfying a threshold to obtain a set of updated training data. Moreover, the model training service may receive a set of pre-labeled data that is labeled as being associated with a respective malicious actor. The model training service may then train an ML model using both the set of updated training data and the set of pre-labeled data to obtain an indication that a respective user is a malicious actor.
Owner:OKTA INC

System and method for SQL server resources and permissions analysis in identity management systems

Embodiments as disclosed allow identity management with respect to SQL database by discovering substantially database objects and their entitlements and associating them with corresponding identities within the identity management system, thus providing insights into such SQL server entitlements and their associated identities, even across multiple SQL servers within an enterprise environment.
Owner:SAILPOINT TECH ISRAEL LTD

Automatic website input detection

An identity management system may be associated with a software plug-in for input detection of a website. In some examples, the plug-in may obtain, via an image capturing system, an image of the website that includes a set of inputs, where the set of inputs includes an interactive interface element. Using the obtained image, a set of location predictions for the set of inputs of the website may be generated via a machine learning (ML) model. Further, the plug-in may obtain a set of locations of the set of inputs based on generating the set of location predictions. Thus, the plug-in may automatically, and in response to obtaining the set of locations of the set of inputs of the website, input content into the set of inputs of the website, select an interactive interface element on the website, or both, on the behalf of the user.
Owner:OKTA INC

Loop8 quorum access system and method

ActiveUS12699787B2Software engineeringIdentity management system
A method of providing secure access to a software object including generating quorum voting requirements for the software object and storing the quorum voting requirements for the software object in a quorum requirements table, wherein the quorum requirements table is resident in quorum access software; receiving a request for a user account and establishing the user account with user parameters for a user; generating a QR code for the user and communicating the QR code to the user computing device; scanning the QR code on the user computing device that the user is utilizing to access the software object; logging into, by the user computing device, a software application including the software object, and transmitting, by the user computing device, an access request with respect to the software object; receiving the access request at the identity management system software, and transmitting the received access request to the quorum access software.
Owner:L8P8 INC

Techniques for managing artificial intelligence agents using user-controlled authorization network tokens

A user of an identity management system may configure a software agent with a set of parameters within one or more user interfaces of an agent management service. The set of parameters may include an identifier of an application programming interface (API) endpoint of a first service that the software agent is authorized to query and one or more permissions associated with queries to the API endpoint by the software agent. Further, the user may receive an authentication token for the software agent from the agent management service. The software agent may use the authentication token for accessing resources of the service via the API endpoint in accordance with the one or more permissions. Thus, the user may configure the first software agent with the authentication token to enable the software agent to perform the queries to the API endpoint of the first service.
Owner:OKTA INC

Systems and methods for identity management

Disclosed is a computer-implemented method for correlating user information can include receiving, from a user device, a login log associated with a user; receiving an intrusion detection system (IDS) log; receiving a domain name system (DNS) log; receiving, from a computing device, a log; enriching at least one of the login log, the IDS log, or the DNS log; and correlating an identity with one or more of the login log, the IDS log, and the DNS log. In some embodiments, correlating the identity with one or more of the login log, the IDS log, and the DNS log can include generating a graph representation and saving the graph representation as a sparse graph representation.
Owner:CYBEREASON INC

Intensive care identity intelligent management system

The invention belongs to the technical field of computers, particularly relates to an intensive care identity intelligent management system, and aims to solve the problems of disordered patient identity management, multi-device data disjunction and misrecognition risk in intensive care. The system generates a unique identity key by fusing a three-dimensional face point cloud and an electrocardio R-wave sequence, and realizes full-time-domain identity tracking by combining a real-time sensing unit and a dual-channel matching engine; dynamic context modeling and a three-dimensional authorization mechanism are introduced, so that the identity maintenance robustness and the operation safety are improved; and the linkage execution module ensures that each medical equipment data flow is bound with an effective identity tag to form closed-loop verification.
Owner:THE UNIVERSITY-TOWN HOSPITAL AFFILIATED TO CHONGQING MEDICAL UNIVERSITY

Efficient and dynamic cross-block chain anonymous identity management system and method

The invention discloses an efficient and dynamic cross-block chain anonymous identity management system and method, relates to the technical field of block chains and distributed systems, and strongly couples the issuing process of a cross-chain identity certificate with the dynamic state of a global malicious behavior log, so that a new user can directly synchronize the log from the registration time point of the new user. An iteration hidden increment verifiable computing technology is applied to continuous certification of cross-chain identity validity so as to construct a complete end-to-end authorization framework, CCVP is used as private input and is embedded into a customized zero-knowledge certification (zkSNARK) circuit, so that an intelligent contract on a target block chain only needs to execute zkSNARK verification of constant time for one time, and the verification efficiency of the intelligent contract on the target block chain is improved. And the whole authorization process can be completed. According to the method, the leading edge cryptography theory is successfully converted into a key technology for supporting the next generation Web3 infrastructure, and the core problem which cannot be overcome in a cross-chain scene in the prior art is solved.
Owner:SHANDONG RUNYI INTELLIGENT TECH CO LTD

Identity management system, identity management method, and program

The invention relates to an identity management system which is provided with a qualification management part. The qualification management unit assigns one or more pieces of qualification information to the identity of a real user present in a real space and indicates that the real user has a predetermined qualification. And storing in a storage unit a prescribed plurality of pieces of qualification information among one or more pieces of qualification information assigned to the identity of the virtual image that corresponds to the real user and can exist in the meta universe, in association with one information storage medium owned by the real user.
Owner:TOPPAN HOLDINGS INC

Multi-account security in cloud-based 5G network

ActiveUS12719879B2Data cloudCloud resources
Systems, methods, and devices manage security controls associated with cloud accounts in a virtual private cloud. An example process includes retrieving native data and nonnative data for the cloud accounts. The cloud accounts comprise cloud roles that have access to cloud resources. Data for identities mapped to the cloud roles is retrieved. The identities are mapped in an identity management system. The retrieved native data for the cloud accounts, the retrieved nonnative data for the cloud accounts, and the retrieved data for the identities mapped to the cloud roles are compared to a security policy to identify a deviation in a cloud account from the cloud accounts. The cloud account is modified to remediate the deviation from the security policy.
Owner:BOOST SUBSCRIBERCO LLC

Tenant-specific user management within multi-tenant applications

An application may establish a connection between a first identity provider (IdP) that is associated with an identity management system and an authentication system associated with the application. Further, the application may receive, from a developer associated with the application, an indication of a mapping between a first set of attributes associated with the first IdP and a second set of attributes associated with the authentication system. The application may then transmit the indication of the mapping to the authentication system. The authentication system may further receive, from a tenant associated with the first IdP, a request message that includes data in the first set of attributes. As such, the authentication system may map the set of data of the request message to the second set of attributes in accordance with the received mapping and store the set of data within a tenant-specific data store based on the mapping.
Owner:OKTA INC