Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

67 results about "Identity management system" patented technology

An identity management system refers to an information system, or to a set of technologies that can be used for enterprise or cross-network identity management...

Authority management method and system for double-token decoupling and dynamic token mapping

The invention discloses an authority management method and system for double-token decoupling and dynamic token mapping, and relates to the technical field of information security. According to the method, a user identity is verified in a unified identity management system; receiving the user identity identifier in the target subsystem and generating a local permission token based on the permission model; in the token mapping service, when it is detected that a mapping relation is not established, the user identity identifier, the target subsystem identifier and the time slice identifier are combined according to a preset sequence, a one-time random factor is inserted, and a mapping key is generated through two-time abstract calculation of different secure hash functions and key parameters; determining a unified expiration time based on a smaller value of the validity period of the double tokens, generating a mapping value by using the exclusive key of the target subsystem in an encryption manner, and storing the mapping value, the mapping key and the expiration time in a distributed cache in an association manner; and the validity of the identity token is verified and the corresponding local permission token is obtained during user access, so that cross-system security access is realized, permission data migration is reduced, and compatibility and security are improved.
Owner:NANJING HUADUN ELECTRIC POWER INFORMATION SAFETY EVALUATION CO LTD

Techniques for managing artificial intelligence agents using user-controlled authorization network tokens

A user of an identity management system may configure a software agent with a set of parameters within one or more user interfaces of an agent management service. The set of parameters may include an identifier of an application programming interface (API) endpoint of a first service that the software agent is authorized to query and one or more permissions associated with queries to the API endpoint by the software agent. Further, the user may receive an authentication token for the software agent from the agent management service. The software agent may use the authentication token for accessing resources of the service via the API endpoint in accordance with the one or more permissions. Thus, the user may configure the first software agent with the authentication token to enable the software agent to perform the queries to the API endpoint of the first service.
Owner:OKTA INC

Dynamic policy and network security zone generation

An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.
Owner:OKTA INC

Version control integration in cross-domain-based authentication systems

A system, method, and computer-program product includes receiving, from a third-party identity management system, an authentication response indicating a set of login attributes; obtaining, from an identity resolution service, a set of identity and authorization attributes using the set of login attributes, the set of identity and authorization attributes including a unique user identifier (UID); granting, by the identity resolution service, a session initiation token when the set of identity and authorization attributes satisfy predefined authorization criteria; in response to the identity resolution service granting the session initiation token: allocating a compute session and a persistent storage resource to the unique UID; executing, via the compute session, an operation that modifies files stored in the persistent storage resource; and transmitting, to a version control system, a version control operation that records the files modified in the persistent storage resource to a code repository using the unique UID or group identifiers.
Owner:SAS INSTITUTE INC

Identity management system, identity management method, and program

An identity management system with a circuity which causes a memory to store a prescribed plurality of pieces of qualification information in association with an information storage medium owned by a user, the plurality of pieces of qualification information being at least one of one or more pieces of qualification information that are assigned to an identity serving as the user existing in a physical space and that indicate that the user has a prescribed qualification, and one or more pieces of qualification information that are assigned to an identity serving as an avatar that corresponds to the user existing in a metaverse.
Owner:TOPPAN HOLDINGS INC

Risk and anomaly detection using a large language model

Methods, systems, devices, and computer-readable media for risk and anomaly detection using one or more large language model (LLMs) are described. An identity management system may use an LLM to generate a predicted next system event or sequence of next system events associated with a user of the identity management system. A detected system event associated with the user may be compared to a predicted next system event of the sequence of predicted next system events. Based on a difference between the detected system event and the predicted next system event, a risk level associated with the detected system event may be determined. Based on determining that the risk level satisfies a threat threshold and based on policy information associated with the identity management system a remediation action may be performed.
Owner:OKTA INC

Continuous tag identification method and system based on COTS RFID

The invention provides a continuous tag identification method and system based on COTS RFID, and relates to the technical field of RFID. According to the method, a label identity management system is established by pre-distributing static identifiers to a label user storage area, and accurate screening and grouping of labels are realized by matching a standard selection instruction with specific mask parameters; an optimized filtering mechanism is adopted to distinguish known tags from unknown tags, and the tag state is confirmed and updated step by step through a staged polling strategy; wherein a static identification pre-storage mechanism obviously reduces performance requirements on label hardware, a selective polling method based on mask matching improves processing efficiency, a multi-stage fingerprint filtering structure ensures identification accuracy, and the design completely following a C1G2 protocol specification enables a system to be directly deployed in an existing RFID infrastructure.
Owner:ANHUI UNIVERSITY OF TECHNOLOGY

Techniques for generating policy recommendations and insights using generative AI

ActiveUS12647461B2Securing communicationEngineeringClient organization
Methods, systems, devices, and computer-readable media for generating authentication policy recommendations and insights using generative AI are described. An authentication policy recommendation system associated with an identity management system may receive a request from a client organization for an authentication policy configuration recommendation for an application associated with the client organization. One or more recommended authentication policy rules may be generated for the application using a machine learning model (such as a large-learning model). The model may output the authentication policy rules in a machine-readable format. Based on an analysis of applying information about the client organization to the model-generated recommended authentication policy rule to generate a context-specific recommended authentication policy rule, an impact of implementing the context-specific recommended authentication policy rule may be determined and output. The impact of implementing the context-specific recommended authentication policy rule may be determined in advance of implementing the recommended authentication policy rule.
Owner:OKTA INC

Passwordless vault access through secure vault enrollment

Methods, systems, and devices are described. A client may perform a sign-in or registration process to register a user with an application of an identity management system. The sign-in or registration process may include receiving an indication of at least one credential associated with an identity of the user. The client may perform a vault enrollment process to configure a secure vault for the user of the application. The client may upload data to the identity management system. The data may be associated with the secure vault configured for the user of the application. The client may perform a device pairing operation to transfer a Recovery Key from the first client device to a second client device of the user. The client may use one or more keys stored in the vault to access the application of the identity management system via the second client device of the user.
Owner:OKTA INC

Using contextual security challenges to prevent bot attacks

Computer-implemented methods, systems, and devices for generating security challenges are described. An identity management system may obtain image descriptions. The image descriptions may include a first image description set that corresponds to a sequence of events and a second image description set that is unassociated with the sequence of events. The identity management system may obtain images based on the image descriptions. The images may include a first image set that corresponds to the sequence of events and a second image set that is unassociated with the sequence of events. The identity management system may generate a security challenge using the images. The security challenge may request for a user to identify the sequence of events from the images. Identification of the sequence of events may be based on each image of the first image set being contextually relevant to the sequence of events.
Owner:OKTA INC

Server authenticity verification using a chain of nested proofs

An identity management system may support an authentication server. According to techniques described herein, a client device may receive an authentication challenge from the authentication server. The authentication challenge may include an indication of a first public key of a first keypair, a first signature of a first private key of the first keypair, and second signatures of second private keys of second keypairs. The client device may determine whether the first public key is a trusted key that is pinned by the client device. The client device may determine, based on determining that the first public key is not the trusted key that is pinned by the client device, whether at least one signature of the second signatures can be validated by the trusted key. The client device may validate the authentication challenge based on determining that the at least one signature can be validated by the trusted key.
Owner:OKTA INC

Extra-organizational application management

An identity management system may receive one or more signals associated with a sign-in to a first application via a first user profile of an organization of the identity management system. The first application may be disassociated with first applications having been authorized access by an administrator of the organization via the identity management system. The identity management system may generate a report indicative of second applications accessed via user profiles of the organization, user profiles that accessed the second applications, and a timestamp of access to the second applications by each of the user profiles, where the second applications include the first application, and where the user profiles include the first user profile. The identity management system may perform an application management operation associated with an application of the second applications, a user profile of the user profiles, or both based on generating the report.
Owner:OKTA INC

Methods and systems for secure and reliable identity-based computing

The embodiments herein provide a secure computing resource set identification, evaluation, and management arrangement, employing in various embodiments some or all of the following highly reliable identity related means to establish, register, publish and securely employ user computing arrangement resources in satisfaction of user set target contextual purposes. Systems and methods may include, as applicable, software and hardware implementations for Identity Firewalls; Awareness Managers; Contextual Purpose Firewall Frameworks for situationally germane resource usage related security, provisioning, isolation, constraining, and operational management; liveness biometric, and assiduous environmental, evaluation and authentication techniques; Repute systems and methods assertion and fact ecosphere; standardized and interoperable contextual purpose related expression systems and methods; purpose related computing arrangement resource and related information management systems and methods, including situational contextual identity management systems and methods; and / or the like.
Owner:ADVANCED ELEMENTAL TECHNOLOGIES INC

Application association risk detection using association rule learning

PendingUS20260111559A1Platform integrity maintainanceEngineeringAssociation rule learning
An authentication and authorization system associated with an identity management system may receive a set of access patterns from two or more applications that are associated with a set of users and may indicate which of the two or more applications a respective user has access to. The system may generate association rules that are based on the set of access patterns to indicate associations between the two or more applications and the set of users. Moreover, for each respective user, the system may generate an indication of a likelihood that the respective user is associated with a security risk by accessing the two or more applications that is based on the association rules and one or more parameters associated with the respective user. The system may then generate an indication of actions for the system to execute in response to a respective user being associated with the security risk.
Owner:OKTA INC

Fiducial mark document sharing

In an example implementation according to aspects of the present disclosure, a system, method, and storage medium comprising a processor, memory, and instructions to receive a fiducial mark, wherein the fiducial mark encodes a user identity, a face descriptor, a background descriptor, and a signature block. The system decodes the fiducial mark and validates the signature block against a public key repository system. The system validates the user identity against an identity management system and validates the face descriptor against a face descriptor repository. The system validates the background descriptor against a background descriptor repository and responsive to successful validation, allows a document to be shared in an online conference.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Systems, methods, and storage media for administration of identity management systems within an identity infrastructure

Systems, methods, and storage media for controlling access to an application in an identity infrastructure are disclosed. The method comprises requesting to access the application, wherein the application is associated with an identity system, determining a status of the identity system, the status comprising one of an available status and unavailable status. When the status comprises the unavailable status, transmitting a request for additional information, receiving the additional information, and verifying the additional information by referencing an identity cache associated with the identity system. In some cases, the method comprises authenticating a user to access the application when the status comprises the available status and / or the additional information has been verified, and in response to authenticating the user at the application, sending a communication from the application to the user, granting the user access to the application.
Owner:STRATA IDENTITY INC

System and method for SQL server resources and permissions analysis in identity management systems

Embodiments as disclosed allow identity management with respect to SQL database by discovering substantially database objects and their entitlements and associating them with corresponding identities within the identity management system, thus providing insights into such SQL server entitlements and their associated identities, even across multiple SQL servers within an enterprise environment.
Owner:SAILPOINT TECH ISRAEL LTD

Systems and methods for distributed ledger-based identity management

Systems and methods for distributed ledger-based identity management are disclosed. In one embodiment, a computer-based method for managing attestations may include: (1) receiving, by a computer program executed by an electronic device for an identity consumer and from an identity provider, a notification from an identity provider server that an attestation is available, wherein the attestation may be generated by the identity provider based on authorization from a system operator and may include a chain of trust comprising an identification of the system operator and the identity provider; (2) requesting, by the computer program, the attestation from the identity provider; and (3) downloading, by the computer program, the attestation to an identity consumer electronic wallet for the identity consumer. The identity provider may commit the downloading of the attestation to a distributed ledger, wherein the distributed ledger maintains a current status for the attestation.
Owner:JPMORGAN CHASE BANK NA

Computer-implemented method for controlling access in a network

Proposed is a computer-implemented method for controlling access in a network having at least two users, having the following steps: - a first identity corresponding to a first user (11) of the at least two users is created and stored in an encrypted form in an identity management system (15), - a second identity corresponding to a second user of the at least two users is created and stored in an encrypted form in the identity management system (15), - a first right of access to a first information or to a first software function or to a first product is assigned to the first identity, - the second user requests access to the information or software function or product from the first user (11) by sending a request to the identity management system (15), - the identity management system (15) checks the authentication of the second user on the basis of the second identity, - the identity management system sends the request to the first user (11), - the first user (11) rejects or approves the request by responding to the identity management system (15), - the identity management system (15) checks the authentication of the first user (11) on the basis of the first identity, - depending on the check, a secret information stored in an encrypted form is shared with the second user, which secret information allows the second user to access the information, software function or product, - the second user accesses the first information or the first software function or the product.
Owner:ROBERT BOSCH GMBH

Dynamic policy and network security zone generation

An authentication server of an identity management system may establish an authentication policy for a tenant of a multi-tenant system and receive device access signals from one or more network identifiers. In some examples, the authentication server may receive an indication from machine learning (ML) models to update the authentication policy of a tenant based on a set of authentication rules of one or more second tenants that are for one or more applications common between the tenant and the one or more second tenants. In some other examples, the ML model may monitor a set of device access signals received at the authentication server to obtain a set of assurance scores for associated network identifiers. The authentication server may then update the authentication policy for a tenant, generate a set of network zones, or both based on the ML model outputs.
Owner:OKTA INC

Ground truth establishment and labeling techniques using signal aggregation

An identity management system may perform ground truth establishment and labeling techniques using signal aggregation. The identity management system may obtain, from multiple data sources, multiple data signals associated with a user of a set of multiple users of the identity management system. The identity management system may store the multiple data signals in a database. In some examples, the identity management system may aggregate the multiple data signals in the database. The identity management system may assign a label to the user based on the database. The label may indicate whether the user is malicious or benign. The identity management system may calculate a confidence level for a risk assessment product based on a comparison between the label and one or more outputs of the risk assessment product. The confidence level may indicate a confidence of the risk assessment product to classify the user as malicious or benign.
Owner:OKTA INC

Agent dynamic address and identity management system based on cache capability

The invention discloses a proxy dynamic address and identity management system based on cache capability, and the system comprises a capability feature extraction module which is used for obtaining a capability attribute set of a proxy in real time, carrying out the denoising and normalization of the capability attribute set, and generating a standardized capability feature set; and a high-dimensional semantic coding module connected with the capability feature extraction module and used for mapping the standardized capability feature set to a high-dimensional feature space by using a preset semantic coding model to generate a high-dimensional feature vector. Perfect balance is achieved between data timeliness and resource efficiency through the system, the updating strategy periodically scans capacity change through a fixed time window, and the passive updating strategy can respond to model upgrading or hardware recovery emergency state events. The combination of the two ensures that the data in the edge node cache is always kept synchronous with the proxy body state of the physical world, and the storage space is prevented from being fully occupied by invalid historical data through a first-in first-out strategy.
Owner:SHENZHEN JUDAO STAR MAP OVERSEAS INFORMATION TECHNOLOGY CO LTD

Identification management system and identification management method

To provide: an identity management system that individually manages design, manufacturing, use, and discard of a product that is a molded body; and an identity management method.SOLUTION: An identity management system that manages traceability of a molded body includes: a molded body information acquisition part 1 that acquires imaging information about a molded body; an identification information conversion part 2 that converts a random pattern in a predetermined region of the imaging information to identification information; and an information control part 8 that performs processing of storing manufacturing information and lifecycle information about the molded body in a molded body management DB 3 for each of identification information.SELECTED DRAWING: Figure 3
Owner:HITACHI LTD

Malicious actor model training using threat intelligence recommendations

In some identity management systems, to train a machine learning (ML) model to detect malicious actors, a model training service may receive a set of training data that is automatically labeled with a first label and a second label in response to an authentication challenge. The model training service may use a subset of the training data (e.g., that is labeled with the first label) and label the subset with the second label based on respective training data elements satisfying a threshold to obtain a set of updated training data. Moreover, the model training service may receive a set of pre-labeled data that is labeled as being associated with a respective malicious actor. The model training service may then train an ML model using both the set of updated training data and the set of pre-labeled data to obtain an indication that a respective user is a malicious actor.
Owner:OKTA INC

System and method for SQL server resources and permissions analysis in identity management systems

Embodiments as disclosed allow identity management with respect to SQL database by discovering substantially database objects and their entitlements and associating them with corresponding identities within the identity management system, thus providing insights into such SQL server entitlements and their associated identities, even across multiple SQL servers within an enterprise environment.
Owner:SAILPOINT TECH ISRAEL LTD

Method and device for processing account information

The present invention discloses a method and apparatus for processing account information, relating to the field of digital wallet technology. A specific implementation of the method includes: sending an identity credential issuance request to a first financial institution, the identity credential issuance request carrying the binding relationship between a first digital wallet account and a first digital wallet distributed identity account; receiving a first digital wallet institution identity credential issued by the first financial institution; signing the binding relationship between the first digital wallet account and the first digital wallet distributed identity account using the first digital wallet issuance private key to obtain a first digital wallet self-signed identity credential; and submitting the first digital wallet issuance public key and the first digital wallet self-signed identity credential to the blockchain identity management system. This implementation can address the technical issue of user account information being easily leaked.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST +1