Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

132 results about "Identity provider" patented technology

An identity provider (abbreviated IdP or IDP) is a system entity that creates, maintains, and manages identity information for principals while providing authentication services to relying applications within a federation or distributed network.

Access management for applications using attribute based access control

Systems and methods are described relating to a credential exchange service (service) for providing customizable access to protected resources. A service may receive a user token generated by an identity provider and a resource identifier and determine a set of attributes of the user based on information indicating the user's association with an account associated with the resource. The service may generate a session token for interacting with the resource by: generating a set of tags based on attributes of the user, and attaching the set of tags to the session token. Upon receiving a request to perform a first action with respect to the resource and the session token, the session token may be used to authorize the user to perform the first action by comparing the set of attributes from the set of tags from the session token to an access policy associated with the resource.
Owner:AMAZON TECH INC

Authentication attack detection and mitigation with embedded authentication and delegation

A system and methods for authentication attack detection with embedded authentication and delegation is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object, wherein subsequent access requests accompanied by authentication objects are validated by comparing identifiers for each authentication object to previous identifiers.
Owner:QOMPLX INC

Security for database systems using identity providers for authentication

A system including a processor and a memory is described. The memory is coupled to the processor and configured to provide the processor with instructions. The processor is configured to receive from an identity provider a validation indication for a user as a proxy. The validation indication is for a database, the identity provider, and the user. The processor is also configured to configure a data flow between the database and a client corresponding to the user through the proxy using the validation indication.
Owner:CYRAL INC

Zero trust authentication

Systems and methods for zero trust authentication. In certain embodiments, a method may comprise providing, from a client computing system to an identity provider (IdP) authority, an authentication nonce value generated by hashing a random value and a public key of the client computing system, and receiving, at the client computing system from the IdP authority, an authorization token including the authentication nonce value, where the authorization token is signed by a private key of the IdP authority. The method may further comprise providing a message including the authorization token from the client computing system to a target computing system via an intermediary co-signer (ICS) configured to authenticate the message.
Owner:CLOUDFLARE INC

System and method for enforcing PII segregation in a distributed data 1 processing system for Privacy-preserving AI corpus generation

A system and method are disclosed for generating a privacy-preserving data corpus for Artificial Intelligence (AI) training. The system comprises a relying partner (RP) computing environment and a trusted, independent identity provider (IdP) computing system. Upon a user authentication request, the IdP provides the RP with only a PII-free, persistent pseudonymous identifier (gUserID) for the user. Any authentication artifacts containing Personally Identifiable Information (PII), such as an OAuth token, are programmatically neutralized by the IdP. This is achieved by generating a transient public-private encryption key pair, immediately destroying the private key, and encrypting the PII-laden artifact with the remaining public key, rendering the PII therein permanently irrecoverable. This enforcement of “PII unknowability” at the RP enables the aggregation of pseudonymous user data, linked by the persistent gUserID, from multiple independent RPs into a rich, cross-organizational corpus for AI training, without ever exposing user PII to the RP.
Owner:NEMA WALEED S

Decentralized identity authentication method combining Merkel tree and zero-knowledge proof and related equipment

The invention discloses a decentralized identity authentication method and related equipment in combination with a Merkel tree and zero-knowledge proof. The method comprises the following steps: generating an initial Merkel proof through an identity provider; zero-knowledge proof is generated through a zero-knowledge proof module; requesting to obtain an initial Merkel proof corresponding to a user from an identity provider through an authenticator; the authenticator performs first identity authentication on the user according to the initial Merkel proof, and if the first identity authentication of the user is successful, the authenticator performs second identity authentication on the user according to the zero-knowledge proof; and if the second identity authentication of the user is successful, generating an identity authentication success result, and returning the identity authentication success result to the user. According to the method, the integrity and verifiability of data can be improved, the risks of fraud and identity embezzlement are reduced, a novel attack mode is effectively resisted, higher-level data security characteristics are realized, user privacy protection is greatly enhanced, and the method can be widely applied to the technical field of network security.
Owner:GUANGZHOU UNIVERSITY

Resiliency architecture for identity provisioning and verification

Identity access and management (“IAM”) systems with resiliency features and methods related to the same are provided. An identity proxy is interposed between user systems and each of two or more identity provider (“IDP”) systems. The identity proxy routes authentication requests, challenges, and responses between the user systems and the IDP systems based on availability, and verifies challenge responses to permit access to data or services.
Owner:HUMANA INC

Cross-domain identity authentication system and method capable of bearing certificate entity and agent

The invention relates to the technical field of digital identities, in particular to a cross-domain identity authentication system and method capable of bearing certificate entities and agents, and the system comprises an identity providing module which signs and issues identity certificates in each trust domain; the chain trust registration module is used for maintaining a trust registration table, a voucher state table and a cross-domain trust strategy table of each trust domain identity provider; the trusteeship authorization management module is used for registering trusteeship authorization relationships between the intelligent agent and the trusteeship host platform and between the intelligent agent and the owner; the cross-domain authentication gateway module is used for carrying out identity verification and authorization judgment on the access request and generating an effective access token in the domain; and the audit and responsibility investigation module is used for recording the cross-domain authentication request, the verification result and summary information of the decision basis. According to the invention, the problems of dispersed cross-domain trust, non-uniform voucher states and unverifiable intelligent agent identities are effectively solved, and an identity authentication system with unified cross-domain trust management, trusteeship authorization verification and auditing of the whole access process is realized.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE

Method and system for payment device-based access

An access control method comprises: providing access profiles for users, wherein each access profile comprises an access profile identifier and at least one personal identifier mapped to one or more obfuscated payment numbers, and wherein each of the at least one personal identifiers is a non-payment identifier issued by an identity provider;receiving, from a terminal of a service provider, a request to validate permission for a user of a payment device to access a resource made available by the service provider, the request comprising an obfuscated payment number read by the terminal from the payment device; determining whether there is a match of the obfuscated payment number read by the terminal and one of the obfuscated payment numbers of the access profiles; and transmitting at least one of the identifiers of the matched access profile to the service provider for matching to a stored identifier associated with the resource.
Owner:MASTERCARD ASIAPACIFIC PTE LTD

Multi-level authentication for accessing cloud resources

Techniques for a multi-level authentication within a cloud environment are disclosed. A first authentication request is received by an identity and access management (IAM) service from a device associated with a user. The first request is to authenticate the user for accessing one or more cloud resources through a gateway of the cloud environment. Responsive to the first authentication request, a redirection is performed to submit a second authentication request to an identity provider (IdP) to authenticate the user. A first token indicating a first identity for the user based on the first authentical is received by the IAM service, here the first authentication was performed by the IdP. The IAM service performs a second authentication of the user. The IAM service issues a second token indicating a second identity for the user. The device gains access to the one or more cloud resources, based on the second token.
Owner:ORACLE INT CORP

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Identity provider (IDP) agnostic authentication enforcement

An intermediary server operates an application proxy. An access request is received for access to an application, where an access policy is associated with the application that specifies authentication method(s) acceptable for satisfying an authentication requirement enforced by the application proxy. The user agent is redirected to submit an authentication request to an identity provider for identity verification. An authentication response generated by the identity provider is received and includes information that specifies authentication method(s) used during the identity verification. If the authentication method(s) used during the identity verification match the authentication method(s) acceptable for satisfying the authentication requirement, the user will not be prompted to perform those authentication method(s) and the authentication requirement enforced by the application proxy is met. If they do not match, the user will be prompted to perform the authentication method(s) as a condition to access the application.
Owner:CLOUDFLARE INC

System and method for authenticating user of UE for meta-universe service

Embodiments herein disclose a method for authenticating a user of a UE by a network / AF entity (110) for meta-universe / any other service. The method includes receiving a session setup request message from a user of the UE to access the meta-universe service. The session establishment request message includes a UE-ID identifying a UE through which the meta-universe service is accessed, an AF-ID, an external identity provider ID identifying a third party identity service provider of a user through which the service is authenticated to utilize. Further, the method includes identifying the home network based on the UE-ID. Further, the method includes sending a user authentication request to the UAF entity (106) to validate a user of the UE requesting meta universe service based on the identification. Further, the method includes receiving, from the UAF entity, a user authentication response based on the user authentication request. The user authentication response includes a user authentication result and a derived user identity.
Owner:SAMSUNG ELECTRONICS CO LTD

Double blind private wireless local area networking

Techniques are provided for double blind private Wi-Fi wireless networking using an authentication method (e.g., OpenRoaming) that allows the network to authenticate a user identity against an IDP (e.g. Apple ID), without disclosing any identifiable information about that user to the network, or any information about that user's location or behavior to the identity provider, by leveraging a double-blind method.
Owner:CISCO TECHNOLOGY INC

Collaborative cloud identity and credential forgery and abuse defense

A system and method for providing a cloud identity verification exchange service which ingests a plurality of identity assertion data from various Identity Providers and / or Service Providers and aggregates the ingested plurality of data into a master global authentication ledger. The system and method comprise: a data ingestion engine configured for acquiring, extracting, and loading data into the system as well as providing hashing capabilities; a metadata manager for collecting, organizing, and cataloguing ingested data based on collected metadata; and database for storing the master global authentication ledger. The master ledger acts as a central repository that consolidates authentication objects from various Identity Providers, allowing for centralized authentication management, auditing, reporting, and analysis. It provides a comprehensive view of authentication activities across multiple systems and enables the tracking of user authentication events across different identity providers.
Owner:QOMPLX INC

Phishing resistant enrollment via an operating system

An operating system of a first device associated with an identity provider (IdP) may receive an enrollment configuration request from a device management provider for the first device to enroll in an authentication service provided by the IdP. In accordance with the enrollment configuration request, the operating system of the first device may provide the first device that is associated with a first user with a prompt to initiate the enrollment of the first device into the authentication service. The operating system may then transmit an enrollment request message to an authentication server associated with the authentication service. The enrollment request message may also include data associated with the first device that is requesting enrollment in the authentication service where an attestation that the first device is associated with an organization is based on the enrollment request message.
Owner:OKTA INC

Efficient anonymous authentication method and system applied to identity authentication

The invention discloses an efficient anonymous authentication method and system applied to identity authentication, an identity provider performs system initialization, a service provider performs legality check on user service qualification, and a block chain stores and manages identity information associated with a user and a data file of an anonymous certificate. After a delegation request of the user is received, re-proxy verification is completed; a user stores and manages the files through a block chain, the user sends a service request to the block chain when service qualification verification needs to be carried out, a service provider sends materials required by verification to the user and the block chain, and the block chain sends the materials required by verification to the user and the block chain after obtaining a one-time authorization token displayed by an anonymous certificate of the user. And the block chain completes service qualification verification of the user. According to the method, the block chain is integrated, and the proxy zero-knowledge proof scheme is introduced, so that the storage and calculation overhead is outsourced to the block chain, the privacy and the control right of the user are ensured, and seamless and efficient anonymous authentication between the user and the service provider is finally realized.
Owner:ANHUI UNIV

Security for database systems using identity providers for authentication

A system including a processor and a memory is described. The memory is coupled to the processor and configured to provide the processor with instructions. The processor is configured to receive from an identity provider a validation indication for a user as a proxy. The validation indication is for a database, the identity provider, and the user. The processor is also configured to configure a data flow between the database and a client corresponding to the user through the proxy using the validation indication.
Owner:CYRAL INC

Seller autonomous auction system and method with bid privacy and bidder anonymity

The application discloses a kind of seller autonomous auction system and method with bidding anonymity and bid privacy, system includes four entities of seller, bidder, auction platform and anonymous identity provider, and is divided into six stages of initialization, registration, auction release, bidding, winner calculation and transaction.The invention aims at the trade-off between seller autonomy and buyer privacy protection in anonymous auction, and designs a group signature variant-zero-knowledge screenable group signature.The signature combines zero-knowledge proof with group signature, ensuring that the black list screening mechanism defined by the seller does not destroy the anonymity of the bidder.At the same time, by using homomorphic encryption technology, the winning bid calculation of the auction is carried out entirely in ciphertext, realizing the bidding amount and ordering privacy of the bidder.In the final transaction stage, the winner opens the value by presenting the bidding commitment of the winning bid, enabling the seller to correctly identify the winner without revealing their identity, ensuring smooth transaction.
Owner:WUHAN UNIV

Passwordless wireless authentication

First, multiple access tokens can be received from various identity provider services. Each of these access tokens can be associated with a user. Then, the multiple access tokens can be stored in a profile associated with the user. Next, user policies associated with the use of the multiple access tokens can be assigned. A device token can then be provided to the user device associated with the user. The device token can be associated with a profile. A device token and a network policy can be received, and it can then be determined that the user policy and the network policy are consistent. In response to determining that the user policy and the network policy are consistent, authentication can be performed on at least one of the multiple identity provider services.
Owner:CISCO TECHNOLOGY INC

Mechanism to enable a federated onboarding service in an openroaming framework

This disclosure describes systems, methods, and devices related to a mechanism to enable a federated onboarding service in an OpenRoaming™ framework. A device may receive a prompt to initiate onboarding of the device to a framework. The device may the initiate a federated onboarding service process at an access network provider (ANP) that is connected to the device, wherein the federated onboarding service process is configured to onboard the device to the framework. The device may further receive a list of available identity providers (IdPs) configured for the framework and receive a selection of an IdP of the list of available IdPs. The device may then establish a connection between the IdP and the device. The device may receive an IdP-generated user-specific profile, and the device may connect to the framework using the user-specific profile.
Owner:INTEL CORP

A blockchain-based identity authorization method and device

The application discloses a kind of identity authorization methods based on blockchain, it is applied to the service end corresponding to the blockchain of centerless digital identity, blockchain member in the blockchain includes identity provider, identity user and identity verification party;The method comprises: receiving any identity user initiates the authorization request of identity authorization to identity verification party;Wherein, the authorization request includes the authorization information related to the traceable identity certificate stored locally, and the decentralized digital identity of identity provider providing the traceable identity certificate;In response to the authorization request, generate authorization record based on the authorization information and the decentralized digital identity of identity provider, and store the authorization record in blockchain.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Systems and methods for secure online credential authentication

Systems, methods, and non-transitory computer-readable medium are disclosed includes for secure online credential authentication. One method includes receiving, over an electronic network, identification information from an identity provider; accessing, from a database, previously stored hashed identification information stored in association with a previous identity provider; comparing the identification information to previously stored hashed identification information; and storing the identification information in association with the identity provider that provided the identification information in the database when the hashed identification information does not match previously stored hashed identification information.
Owner:ID ME

Systems for describing unknown access management events using identity tags and related transaction chains

The technology includes a system to describe access management events. The system monitors transactions performed by layers of an Identity Provider service (IDP). Each layer corresponds to an Application Programming Interface (API). The system captures output from the layers in a dynamic record. The output includes timestamps, names of layers, and principals responsible for calling layers. The system determines related transactions by tagging output with identity tags based on principals, and grouping transactions based on common identity tags. The system chains related transactions into lists by comparing identity tags and timestamps and determining orders based on proximate timestamps. The system determines access management events based on names of layers from lists of chained transactions. The system generates descriptions of these events for display to auditors by using language models which have been provided input from the dynamic record.
Owner:T MOBILE US INC

A key management system with key recovery

The present invention presents a key management system for handling cryptographic keys. The key management system comprises a computer device. The key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers. The IdP servers is configured to send an authentication token to the key management system upon an authentication request from the key management system. The key management system is configured to generate an access ID related to said IdP servers. The key management system is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to the group of computing servers, wherein the group of computing servers is configured to generate a decryption key and sending the decryption key or shares of the decryption key to the computer device or a selected device different from the computer device.
Owner:PARTISIA INFRASTRUCTURE APS

Secure device location sharing

ActiveUS12452679B2TransmissionSecurity arrangementLocation sharingInternet privacy
Secure device location sharing may be provided. Over a secured link, an indication that a peer-to-peer device desires Automated Frequency Coordination (AFC) based location sharing may be received. Then, from the peer-to-peer device over the secured link, an identity provider (IdP) may be received for the peer-to-peer device. Next, validation of the peer-to-peer device may be requested from the IdP. From the IdP in response to requesting validation of the peer-to-peer device from the IdP, authentication for the peer-to-peer device and an indication that the peer-to-peer device needs AFC based location sharing may be received. An indication that the peer-to-peer device is approved for AFC based location sharing may then be sent to the peer-to-peer device over the secured link.
Owner:CISCO TECHNOLOGY INC

Security analysis of diverse identity provider and single sign-on configurations

The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC

Method for carrying out an authentication process on a field device, and corresponding system

The invention discloses a method for carrying out an authentication process on a field device (FG), having the steps of: operating a ticket server (TS), the ticket server (TS) being designed as an identity provider (IDP) and thereby being designed to generate access tokens (JWT) and the ticket server (TS) being designed to generate field-device-specific tickets (T) with at least one transaction for the field device (FG), an access token (JWT) comprising at least one field-device-specific ticket (T); registering an operating unit (BE) on the ticket server (TS), the operating unit (BE) being designed to receive and process access tokens (JWT); logging in a user (BN) on the ticket server (TS) and selecting a transaction for a field device (FG); generating an access token (JWT) for the field device (FG), containing a field-device-specific ticket (T) for the corresponding transaction; transmitting the access token (JWT) to the operating unit (BE) and reading the access token (JWT) containing the field-device-specific ticket (T); transporting the ticket (T) to the field device (FG) via the operating unit (BE); and carrying out the transaction and carrying out the authentication process on the field device (FG). The invention also relates to a system for carrying out the method.
Owner:ENDRESS HAUSER PROCESS SOLUTIONS AG

Authentication system

Methods performed by an identity provider system, a service provider system and a user device are provided. The identity provider system performs an authentication process to confirm an identity of a user. In a case that the identity of the user is confirmed by the authentication process, the identity provider system determines a portion of resources made available at the service provider system that the user is allocated permission to access and generates a permission indication. The permission indication defines a portion of a structure of the resources corresponding to the portion of the resources which the user is permitted to access. The user can access resources made available by the service provider system which are both requested by user device via a resource request and permitted to be accessed by the user according to the permission indication.
Owner:PAYCASSO VERIFY

Audit_Resilient BEI _24HWS Global Sovereign Ecosystem

A fully decentralized, audit-resilient sovereign ecosystem (“BEI×24HWS”) empowering every individual, household, industry, and region to truly own, govern, mint and inherit their time, identity, and digital resources—without reliance on traditional DNS registrars, centralized identity providers, or recurring renewal fees. The system is built upon three Sovereignty Pillars (Time, Identity, Resource) and seventeen modular components, and includes a turnkey “Domain-to-Module” mapping of all registered top-level and second-level names to demonstrate immediate, fee-free deployment across 365 industries and 82 billion global nodes.
Owner:BEI FURONG