Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

74 results about "Identity provider" patented technology

An identity provider (abbreviated IdP or IDP) is a system entity that creates, maintains, and manages identity information for principals while providing authentication services to relying applications within a federation or distributed network.

Authentication attack detection and mitigation with embedded authentication and delegation

A system and methods for authentication attack detection with embedded authentication and delegation is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object, wherein subsequent access requests accompanied by authentication objects are validated by comparing identifiers for each authentication object to previous identifiers.
Owner:QOMPLX INC

System and method for enforcing PII segregation in a distributed data 1 processing system for Privacy-preserving AI corpus generation

A system and method are disclosed for generating a privacy-preserving data corpus for Artificial Intelligence (AI) training. The system comprises a relying partner (RP) computing environment and a trusted, independent identity provider (IdP) computing system. Upon a user authentication request, the IdP provides the RP with only a PII-free, persistent pseudonymous identifier (gUserID) for the user. Any authentication artifacts containing Personally Identifiable Information (PII), such as an OAuth token, are programmatically neutralized by the IdP. This is achieved by generating a transient public-private encryption key pair, immediately destroying the private key, and encrypting the PII-laden artifact with the remaining public key, rendering the PII therein permanently irrecoverable. This enforcement of “PII unknowability” at the RP enables the aggregation of pseudonymous user data, linked by the persistent gUserID, from multiple independent RPs into a rich, cross-organizational corpus for AI training, without ever exposing user PII to the RP.
Owner:NEMA WALEED S

Decentralized identity authentication method combining Merkel tree and zero-knowledge proof and related equipment

The invention discloses a decentralized identity authentication method and related equipment in combination with a Merkel tree and zero-knowledge proof. The method comprises the following steps: generating an initial Merkel proof through an identity provider; zero-knowledge proof is generated through a zero-knowledge proof module; requesting to obtain an initial Merkel proof corresponding to a user from an identity provider through an authenticator; the authenticator performs first identity authentication on the user according to the initial Merkel proof, and if the first identity authentication of the user is successful, the authenticator performs second identity authentication on the user according to the zero-knowledge proof; and if the second identity authentication of the user is successful, generating an identity authentication success result, and returning the identity authentication success result to the user. According to the method, the integrity and verifiability of data can be improved, the risks of fraud and identity embezzlement are reduced, a novel attack mode is effectively resisted, higher-level data security characteristics are realized, user privacy protection is greatly enhanced, and the method can be widely applied to the technical field of network security.
Owner:GUANGZHOU UNIVERSITY

Resiliency architecture for identity provisioning and verification

Identity access and management (“IAM”) systems with resiliency features and methods related to the same are provided. An identity proxy is interposed between user systems and each of two or more identity provider (“IDP”) systems. The identity proxy routes authentication requests, challenges, and responses between the user systems and the IDP systems based on availability, and verifies challenge responses to permit access to data or services.
Owner:HUMANA INC

Cross-domain identity authentication system and method capable of bearing certificate entity and agent

The invention relates to the technical field of digital identities, in particular to a cross-domain identity authentication system and method capable of bearing certificate entities and agents, and the system comprises an identity providing module which signs and issues identity certificates in each trust domain; the chain trust registration module is used for maintaining a trust registration table, a voucher state table and a cross-domain trust strategy table of each trust domain identity provider; the trusteeship authorization management module is used for registering trusteeship authorization relationships between the intelligent agent and the trusteeship host platform and between the intelligent agent and the owner; the cross-domain authentication gateway module is used for carrying out identity verification and authorization judgment on the access request and generating an effective access token in the domain; and the audit and responsibility investigation module is used for recording the cross-domain authentication request, the verification result and summary information of the decision basis. According to the invention, the problems of dispersed cross-domain trust, non-uniform voucher states and unverifiable intelligent agent identities are effectively solved, and an identity authentication system with unified cross-domain trust management, trusteeship authorization verification and auditing of the whole access process is realized.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE

Method and system for payment device-based access

An access control method comprises: providing access profiles for users, wherein each access profile comprises an access profile identifier and at least one personal identifier mapped to one or more obfuscated payment numbers, and wherein each of the at least one personal identifiers is a non-payment identifier issued by an identity provider;receiving, from a terminal of a service provider, a request to validate permission for a user of a payment device to access a resource made available by the service provider, the request comprising an obfuscated payment number read by the terminal from the payment device; determining whether there is a match of the obfuscated payment number read by the terminal and one of the obfuscated payment numbers of the access profiles; and transmitting at least one of the identifiers of the matched access profile to the service provider for matching to a stored identifier associated with the resource.
Owner:MASTERCARD ASIAPACIFIC PTE LTD

Multi-level authentication for accessing cloud resources

Techniques for a multi-level authentication within a cloud environment are disclosed. A first authentication request is received by an identity and access management (IAM) service from a device associated with a user. The first request is to authenticate the user for accessing one or more cloud resources through a gateway of the cloud environment. Responsive to the first authentication request, a redirection is performed to submit a second authentication request to an identity provider (IdP) to authenticate the user. A first token indicating a first identity for the user based on the first authentical is received by the IAM service, here the first authentication was performed by the IdP. The IAM service performs a second authentication of the user. The IAM service issues a second token indicating a second identity for the user. The device gains access to the one or more cloud resources, based on the second token.
Owner:ORACLE INT CORP

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

System and method for authenticating user of UE for meta-universe service

Embodiments herein disclose a method for authenticating a user of a UE by a network / AF entity (110) for meta-universe / any other service. The method includes receiving a session setup request message from a user of the UE to access the meta-universe service. The session establishment request message includes a UE-ID identifying a UE through which the meta-universe service is accessed, an AF-ID, an external identity provider ID identifying a third party identity service provider of a user through which the service is authenticated to utilize. Further, the method includes identifying the home network based on the UE-ID. Further, the method includes sending a user authentication request to the UAF entity (106) to validate a user of the UE requesting meta universe service based on the identification. Further, the method includes receiving, from the UAF entity, a user authentication response based on the user authentication request. The user authentication response includes a user authentication result and a derived user identity.
Owner:SAMSUNG ELECTRONICS CO LTD

Double blind private wireless local area networking

Techniques are provided for double blind private Wi-Fi wireless networking using an authentication method (e.g., OpenRoaming) that allows the network to authenticate a user identity against an IDP (e.g. Apple ID), without disclosing any identifiable information about that user to the network, or any information about that user's location or behavior to the identity provider, by leveraging a double-blind method.
Owner:CISCO TECHNOLOGY INC

Efficient anonymous authentication method and system applied to identity authentication

The invention discloses an efficient anonymous authentication method and system applied to identity authentication, an identity provider performs system initialization, a service provider performs legality check on user service qualification, and a block chain stores and manages identity information associated with a user and a data file of an anonymous certificate. After a delegation request of the user is received, re-proxy verification is completed; a user stores and manages the files through a block chain, the user sends a service request to the block chain when service qualification verification needs to be carried out, a service provider sends materials required by verification to the user and the block chain, and the block chain sends the materials required by verification to the user and the block chain after obtaining a one-time authorization token displayed by an anonymous certificate of the user. And the block chain completes service qualification verification of the user. According to the method, the block chain is integrated, and the proxy zero-knowledge proof scheme is introduced, so that the storage and calculation overhead is outsourced to the block chain, the privacy and the control right of the user are ensured, and seamless and efficient anonymous authentication between the user and the service provider is finally realized.
Owner:ANHUI UNIV

Security for database systems using identity providers for authentication

A system including a processor and a memory is described. The memory is coupled to the processor and configured to provide the processor with instructions. The processor is configured to receive from an identity provider a validation indication for a user as a proxy. The validation indication is for a database, the identity provider, and the user. The processor is also configured to configure a data flow between the database and a client corresponding to the user through the proxy using the validation indication.
Owner:CYRAL INC

Passwordless wireless authentication

First, multiple access tokens can be received from various identity provider services. Each of these access tokens can be associated with a user. Then, the multiple access tokens can be stored in a profile associated with the user. Next, user policies associated with the use of the multiple access tokens can be assigned. A device token can then be provided to the user device associated with the user. The device token can be associated with a profile. A device token and a network policy can be received, and it can then be determined that the user policy and the network policy are consistent. In response to determining that the user policy and the network policy are consistent, authentication can be performed on at least one of the multiple identity provider services.
Owner:CISCO TECHNOLOGY INC

A blockchain-based identity authorization method and device

The application discloses a kind of identity authorization methods based on blockchain, it is applied to the service end corresponding to the blockchain of centerless digital identity, blockchain member in the blockchain includes identity provider, identity user and identity verification party;The method comprises: receiving any identity user initiates the authorization request of identity authorization to identity verification party;Wherein, the authorization request includes the authorization information related to the traceable identity certificate stored locally, and the decentralized digital identity of identity provider providing the traceable identity certificate;In response to the authorization request, generate authorization record based on the authorization information and the decentralized digital identity of identity provider, and store the authorization record in blockchain.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Systems and methods for secure online credential authentication

Systems, methods, and non-transitory computer-readable medium are disclosed includes for secure online credential authentication. One method includes receiving, over an electronic network, identification information from an identity provider; accessing, from a database, previously stored hashed identification information stored in association with a previous identity provider; comparing the identification information to previously stored hashed identification information; and storing the identification information in association with the identity provider that provided the identification information in the database when the hashed identification information does not match previously stored hashed identification information.
Owner:ID ME

Systems for describing unknown access management events using identity tags and related transaction chains

The technology includes a system to describe access management events. The system monitors transactions performed by layers of an Identity Provider service (IDP). Each layer corresponds to an Application Programming Interface (API). The system captures output from the layers in a dynamic record. The output includes timestamps, names of layers, and principals responsible for calling layers. The system determines related transactions by tagging output with identity tags based on principals, and grouping transactions based on common identity tags. The system chains related transactions into lists by comparing identity tags and timestamps and determining orders based on proximate timestamps. The system determines access management events based on names of layers from lists of chained transactions. The system generates descriptions of these events for display to auditors by using language models which have been provided input from the dynamic record.
Owner:T MOBILE US INC

A key management system with key recovery

The present invention presents a key management system for handling cryptographic keys. The key management system comprises a computer device. The key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers. The IdP servers is configured to send an authentication token to the key management system upon an authentication request from the key management system. The key management system is configured to generate an access ID related to said IdP servers. The key management system is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to the group of computing servers, wherein the group of computing servers is configured to generate a decryption key and sending the decryption key or shares of the decryption key to the computer device or a selected device different from the computer device.
Owner:PARTISIA INFRASTRUCTURE APS

Security analysis of diverse identity provider and single sign-on configurations

The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC

Method for carrying out an authentication process on a field device, and corresponding system

The invention discloses a method for carrying out an authentication process on a field device (FG), having the steps of: operating a ticket server (TS), the ticket server (TS) being designed as an identity provider (IDP) and thereby being designed to generate access tokens (JWT) and the ticket server (TS) being designed to generate field-device-specific tickets (T) with at least one transaction for the field device (FG), an access token (JWT) comprising at least one field-device-specific ticket (T); registering an operating unit (BE) on the ticket server (TS), the operating unit (BE) being designed to receive and process access tokens (JWT); logging in a user (BN) on the ticket server (TS) and selecting a transaction for a field device (FG); generating an access token (JWT) for the field device (FG), containing a field-device-specific ticket (T) for the corresponding transaction; transmitting the access token (JWT) to the operating unit (BE) and reading the access token (JWT) containing the field-device-specific ticket (T); transporting the ticket (T) to the field device (FG) via the operating unit (BE); and carrying out the transaction and carrying out the authentication process on the field device (FG). The invention also relates to a system for carrying out the method.
Owner:ENDRESS HAUSER PROCESS SOLUTIONS AG

Delivering identity provider specific configurations and policies

Techniques for wireless communications are disclosed. The techniques include generating a provisioning domain (PVD) identifier by associating a roaming consortium organization identifier (RCOI), relating to an identity federation comprising an identity provider (IDP), with the PVD. The techniques further include providing PVD configuration information from the IDP to a wireless station (STA) associated with the IDP, using the PVD identifier. The techniques further include applying one or more configuration policies at the STA based on the PVD configuration information.
Owner:CISCO TECHNOLOGY INC

Strong headless authentication without user involvement

A service installed on a user's device identifies a user that has logged into an account associated with an organization that has provided the service for installment. When the service determines that the user has successfully authenticated with an identity provider used by the organization, the service determines information about the session with the identity provider that was created to strongly authenticate the user. The service sends an authentication request to the identity provider as part of the same session with the identity provider that was created when the user was strongly authenticated. The authentication request generated by the service includes a parameter value for configuring authentication without user involvement, such as a parameter value for configuring passive or no prompt authentication. The user thus can be strongly authenticated to the service.
Owner:PALO ALTO NETWORKS INC

Multi-level authentication for accessing cloud resources

Techniques for a multi-level authentication within a cloud environment are disclosed. A first authentication request is received by an identity and access management (IAM) service from a device associated with a user. The first request is to authenticate the user for accessing one or more cloud resources through a gateway of the cloud environment. Responsive to the first authentication request, a redirection is performed to submit a second authentication request to an identity provider (IdP) to authenticate the user. A first token indicating a first identity for the user based on the first authentical is received by the IAM service, here the first authentication was performed by the IdP. The IAM service performs a second authentication of the user. The IAM service issues a second token indicating a second identity for the user. The device gains access to the one or more cloud resources, based on the second token.
Owner:ORACLE INT CORP

Single sign-on through customer authentication systems

Described herein is a system, method, and non-transitory computer readable medium related to a service provider using a third party identity provider to authenticate a user with improved security. An authentication token is received from the identity provider, and can be verified against internal configuration information. The internal configuration information includes data that is not included in the authentication token, and therefore, is not vulnerable to some security attacks, such as a man-in-the-middle attack. After the authentication token is verified, the internal configuration information and authentication token may be used to create a custom identifier, referred to as an identity ID. The identity ID may be used by the service provider to verify user access to resources.
Owner:CAPITAL ONE SERVICES LLC

Remote cloud office unified access method, equipment, medium and product

The invention discloses a remote cloud office unified access method and device, a medium and a product. The method comprises the following steps: establishing an encrypted connection channel between a terminal and a cloud access point; receiving an identity authentication request, and forwarding the identity authentication request to an enterprise identity providing service for verification to obtain a main identity authentication result; if yes, acquiring equipment context data of the terminal; intercepting an application access request, extracting a target application identifier, and constructing an authorization judgment request according to a main identity authentication result; evaluating the authorization judgment request based on the strategy matrix, and generating an authorization judgment result; and when the authorization judgment result represents that access is allowed, determining a deployment position type of the target application according to the target application identifier, and creating a session-level encryption tunnel based on the deployment position type. By implementing the technical scheme provided by the invention, the authorization decision can adapt to different risk scenes, and the overall security protection level under the remote access scene is improved.
Owner:BEIJING LIANCHI SYSTEM TECHNOLOGY CO LTD

Digital identity sharing

A method for sharing digital identity data, the method comprising, using an identity network, receiving a sign-up request for a user from a relying party, providing, for display to a user interface of a user device, a list of identity providers, in response to receiving a selection of the identity provider from the list of identity providers, causing the user interface to display a login page associated with the selected identity provider, receiving, from the selected identity provider, a plurality of identity attributes associated with the user, providing, for display to the user interface, the plurality of identity attributes associated with the user, receiving consent from the user to share the plurality of identity attributes associated with the user with the relying party, and redirecting the user interface to a page associated with the relying party.
Owner:EARLY WARNING SERVICES LLC

Apparatus, system, and method of federated authentication service (FAS) for wireless communication roaming

PendingUS20260101185A1Security arrangementWeb authenticationEngineering
For example, a Federated Authentication Service (FAS) server may be configured to register the FAS server with a wireless communication roaming federation service; to authenticate a user of a mobile device according to a network authentication protocol of the wireless communication roaming federation service, e.g., over a Remote Authentication Dial-In User Service (RADIUS) over Transport Layer Security (RADSec) tunnel between the FAS server and an Access Network Provider (ANP); to identify an Identity Provider (IDP) for the user based on user information for the user received from the ANP via the RADSec tunnel; to trigger user authentication of the user with the IDP for the user via an authentication interface between the FAS server and the IDP for the user; and based on a determination that the user is successfully authenticated with the IDP for the user, to send an authentication success message to the ANP via the RADSec tunnel.
Owner:INTEL CORP

Access gateway system for accessing a resource

An access gateway may grant a requestor access to a computer resource. The requestor may receive a credential from an identity provider and calculate a zero-knowledge proof of possession of the credential. The requestor may use the proof to request access to the computer resource. The identity provider may record a policy corresponding to the credential in a distributed ledger. The access gateway may, subject to verifying the proof, retrieve the policy from the distributed ledger. The access gateway may grant the requestor access to the computer resource as indicated by the policy. For example, the access gateway may allow the requestor to transfer data from a classified data storage component to a declassified data storage component. In some cases, the classified data storage component may encrypt data (e.g., using an encryption key provided by the requestor and / or the declassified data storage component) prior to transfer.
Owner:VIA SCIENCE INC

Systems and methods for distributed ledger-based identity management

Systems and methods for distributed ledger-based identity management are disclosed. In one embodiment, a computer-based method for managing attestations may include: (1) receiving, by a computer program executed by an electronic device for an identity consumer and from an identity provider, a notification from an identity provider server that an attestation is available, wherein the attestation may be generated by the identity provider based on authorization from a system operator and may include a chain of trust comprising an identification of the system operator and the identity provider; (2) requesting, by the computer program, the attestation from the identity provider; and (3) downloading, by the computer program, the attestation to an identity consumer electronic wallet for the identity consumer. The identity provider may commit the downloading of the attestation to a distributed ledger, wherein the distributed ledger maintains a current status for the attestation.
Owner:JPMORGAN CHASE BANK NA

Multi-level dynamic smart home privacy authentication method based on verifiable voucher

The invention relates to the field of privacy protection, in particular to a multi-level dynamic smart home privacy authentication method based on verifiable certificates. The method comprises the following steps: S1, receiving an access request of a user; the access request comprises a user decentralized identifier (DID) and a verifiable voucher VC, and the verifiable voucher VC is bound with the user DID and applies for signing and issuing from an identity provider for the user; step S2, executing a DID identity authentication step; step S21, extracting a signer DID, a signature and a to-be-verified message from the verifiable voucher VC, and verifying whether the signature is correct or not; and step S22, if the signature verification is correct, analyzing a DID document according to the user DID and obtaining a public key and a verification path of the DID document, carrying out Hash processing on the user DID and calculating whether the Hash is the same as Merkle root Hash stored on the block chain in advance according to the obtained verification path, and if the Hash is the same as the Merkle root Hash stored on the block chain in advance, the user identity authentication is successful. According to the invention, the problem of privacy leakage caused by malicious behaviors of internal personnel of a service provider in an existing smart home scene can be solved.
Owner:CHANGZHOU UNIV

Methods and Systems for User Authentication and File Access Control

PendingJP2026524985AUniform resource identifierEngineering
This disclosure relates, in general, to methods, systems, devices, and non-temporary computer-readable media for providing access to stored files. These systems can significantly reduce the human capital required to transmit files to customers and other stakeholders across a broad business. Furthermore, these systems can enable the secure transmission of these files without imposing burdensome security requirements on the file recipients. In particular, embodiments of this disclosure may utilize a server to generate a Uniform Resource Identifier (URI) associated with a file. This URI may be transmitted to an end user who uses it to request access to the file. The server may use various pieces of information received from this request to verify the end user's identity locally and using an identity provider. The server may then permit or deny the end user's request based on the results of its verification.
Owner:INKIT WORLDWIDE LLC