Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

183 results about "Identity provider" patented technology

An identity provider (abbreviated IdP or IDP) is a system entity that creates, maintains, and manages identity information for principals while providing authentication services to relying applications within a federation or distributed network.

Access management for applications using attribute based access control

Systems and methods are described relating to a credential exchange service (service) for providing customizable access to protected resources. A service may receive a user token generated by an identity provider and a resource identifier and determine a set of attributes of the user based on information indicating the user's association with an account associated with the resource. The service may generate a session token for interacting with the resource by: generating a set of tags based on attributes of the user, and attaching the set of tags to the session token. Upon receiving a request to perform a first action with respect to the resource and the session token, the session token may be used to authorize the user to perform the first action by comparing the set of attributes from the set of tags from the session token to an access policy associated with the resource.
Owner:AMAZON TECH INC

Authentication attack detection and mitigation with embedded authentication and delegation

A system and methods for authentication attack detection with embedded authentication and delegation is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object, wherein subsequent access requests accompanied by authentication objects are validated by comparing identifiers for each authentication object to previous identifiers.
Owner:QOMPLX INC

Security for database systems using identity providers for authentication

A system including a processor and a memory is described. The memory is coupled to the processor and configured to provide the processor with instructions. The processor is configured to receive from an identity provider a validation indication for a user as a proxy. The validation indication is for a database, the identity provider, and the user. The processor is also configured to configure a data flow between the database and a client corresponding to the user through the proxy using the validation indication.
Owner:CYRAL INC

Login using QR code

Systems and methods are disclosed herein for a user to use a trusted device to provide sensitive information to an identity provider via QR (Quick Response) code for the identity provider to broker a website login or to collect information for the website. A user may securely transact with the website from unsecured devices by entering sensitive information into the trusted device. The identity provider may generate the QR code for display by the website on an unsecured device. A user running an application from the identity provider on the trusted device may scan the QR code to transmit the QR code to the identity provider. The identity provider may validate the QR code and may receive credential information to authenticate the user or may collect information for the website. Advantageously, the user may perform a safe login to the website from untrusted devices using the trusted device.
Owner:PAYPAL INC

Systems and methods for third party token based authentication

A method is disclosed that includes: receiving, by an identity provider computing system, a user token and user device information from a third-party provider, whereby the user token is associated with a user of the identity provider computing system and the user device information is associated with a user device of the user; identifying, by the identity provider computing system, related user activity based on the user device information; and authenticating, by the identity provider computing system, the user based on the user token and the related user activity indicating that the user used the user device in another authenticated transaction within a past predefined time period.
Owner:WELLS FARGO BANK NA

Zero trust authentication

Systems and methods for zero trust authentication. In certain embodiments, a method may comprise providing, from a client computing system to an identity provider (IdP) authority, an authentication nonce value generated by hashing a random value and a public key of the client computing system, and receiving, at the client computing system from the IdP authority, an authorization token including the authentication nonce value, where the authorization token is signed by a private key of the IdP authority. The method may further comprise providing a message including the authorization token from the client computing system to a target computing system via an intermediary co-signer (ICS) configured to authenticate the message.
Owner:CLOUDFLARE INC

Local account access conditioned on SSO availability

A managed device may include multiple techniques to login and use resources. One example may include a single sign-on (SSO) login procedure that utilizes an identity provider that may authenticate the user. Another example may include a local account, which may allow access by the user inputting credentials, such as a login ID and a password. The managed device may condition access to the local account based on whether the identity provider is available. If the identity provider is available, then the managed device may disallow access through the local account. However, if the identity provider is unavailable, then the managed device may allow access through the local account.
Owner:DELL PROD LP

System and method for enforcing PII segregation in a distributed data 1 processing system for Privacy-preserving AI corpus generation

A system and method are disclosed for generating a privacy-preserving data corpus for Artificial Intelligence (AI) training. The system comprises a relying partner (RP) computing environment and a trusted, independent identity provider (IdP) computing system. Upon a user authentication request, the IdP provides the RP with only a PII-free, persistent pseudonymous identifier (gUserID) for the user. Any authentication artifacts containing Personally Identifiable Information (PII), such as an OAuth token, are programmatically neutralized by the IdP. This is achieved by generating a transient public-private encryption key pair, immediately destroying the private key, and encrypting the PII-laden artifact with the remaining public key, rendering the PII therein permanently irrecoverable. This enforcement of “PII unknowability” at the RP enables the aggregation of pseudonymous user data, linked by the persistent gUserID, from multiple independent RPs into a rich, cross-organizational corpus for AI training, without ever exposing user PII to the RP.
Owner:NEMA WALEED S

Decentralized identity authentication method combining Merkel tree and zero-knowledge proof and related equipment

The invention discloses a decentralized identity authentication method and related equipment in combination with a Merkel tree and zero-knowledge proof. The method comprises the following steps: generating an initial Merkel proof through an identity provider; zero-knowledge proof is generated through a zero-knowledge proof module; requesting to obtain an initial Merkel proof corresponding to a user from an identity provider through an authenticator; the authenticator performs first identity authentication on the user according to the initial Merkel proof, and if the first identity authentication of the user is successful, the authenticator performs second identity authentication on the user according to the zero-knowledge proof; and if the second identity authentication of the user is successful, generating an identity authentication success result, and returning the identity authentication success result to the user. According to the method, the integrity and verifiability of data can be improved, the risks of fraud and identity embezzlement are reduced, a novel attack mode is effectively resisted, higher-level data security characteristics are realized, user privacy protection is greatly enhanced, and the method can be widely applied to the technical field of network security.
Owner:GUANGZHOU UNIVERSITY

Resiliency architecture for identity provisioning and verification

Identity access and management (“IAM”) systems with resiliency features and methods related to the same are provided. An identity proxy is interposed between user systems and each of two or more identity provider (“IDP”) systems. The identity proxy routes authentication requests, challenges, and responses between the user systems and the IDP systems based on availability, and verifies challenge responses to permit access to data or services.
Owner:HUMANA INC

SIM based fido authentication

Systems and techniques for authenticating user sign-on at an online service provider using a subscriber identity module (SIM) based authentication process are discussed herein. A user may request to sign-on an online service provider using a user device. The user device may be requested to provide a response to a challenge sent by the online service provider. The online service provider may interface with an identity provider (IDP) to send the challenge. The challenge may be received at a SIM component associated with the user device. The SIM component may generate a challenge response to the challenge, encrypt the response with a first security key associated with the SIM component, and send the encrypted challenge response to the IDP using the OTA component. The IDP may authenticate the encrypted challenge response using a second security key associated with the IDP.
Owner:T MOBILE US INC

Cross-domain identity authentication system and method capable of bearing certificate entity and agent

The invention relates to the technical field of digital identities, in particular to a cross-domain identity authentication system and method capable of bearing certificate entities and agents, and the system comprises an identity providing module which signs and issues identity certificates in each trust domain; the chain trust registration module is used for maintaining a trust registration table, a voucher state table and a cross-domain trust strategy table of each trust domain identity provider; the trusteeship authorization management module is used for registering trusteeship authorization relationships between the intelligent agent and the trusteeship host platform and between the intelligent agent and the owner; the cross-domain authentication gateway module is used for carrying out identity verification and authorization judgment on the access request and generating an effective access token in the domain; and the audit and responsibility investigation module is used for recording the cross-domain authentication request, the verification result and summary information of the decision basis. According to the invention, the problems of dispersed cross-domain trust, non-uniform voucher states and unverifiable intelligent agent identities are effectively solved, and an identity authentication system with unified cross-domain trust management, trusteeship authorization verification and auditing of the whole access process is realized.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE

Anti-quantum security enhancement method for open identity connection protocol

The invention discloses an anti-quantum security enhancement method for an open identity connection protocol, particularly relates to the technical field of distributed identity authentication, and is used for solving an identity hijacking risk caused by client public key update lag in an anti-quantum cryptography high-frequency key rotation scene of an existing OIDC protocol. A version identification public key fusing a timestamp and Hash is dynamically generated through an identity provider, and change notification broadcast of multicast / fragment routing is realized based on historical response of a client and network topology characteristics; the relying party client accurately requests a new version public key, and updates the local cache after verification; constructing an anomaly detection model in combination with the key version dispersion and the update frequency standard deviation, and triggering a security level adaptive dynamic threshold rollback mechanism; quantum security key synchronization, client cache abnormity real-time self-healing and network resource optimization are realized, and an attack window in a key rotation period is eliminated.
Owner:CHINA NAT INST OF STANDARDIZATION

Method and system for payment device-based access

An access control method comprises: providing access profiles for users, wherein each access profile comprises an access profile identifier and at least one personal identifier mapped to one or more obfuscated payment numbers, and wherein each of the at least one personal identifiers is a non-payment identifier issued by an identity provider;receiving, from a terminal of a service provider, a request to validate permission for a user of a payment device to access a resource made available by the service provider, the request comprising an obfuscated payment number read by the terminal from the payment device; determining whether there is a match of the obfuscated payment number read by the terminal and one of the obfuscated payment numbers of the access profiles; and transmitting at least one of the identifiers of the matched access profile to the service provider for matching to a stored identifier associated with the resource.
Owner:MASTERCARD ASIAPACIFIC PTE LTD

Multi-level authentication for accessing cloud resources

Techniques for a multi-level authentication within a cloud environment are disclosed. A first authentication request is received by an identity and access management (IAM) service from a device associated with a user. The first request is to authenticate the user for accessing one or more cloud resources through a gateway of the cloud environment. Responsive to the first authentication request, a redirection is performed to submit a second authentication request to an identity provider (IdP) to authenticate the user. A first token indicating a first identity for the user based on the first authentical is received by the IAM service, here the first authentication was performed by the IdP. The IAM service performs a second authentication of the user. The IAM service issues a second token indicating a second identity for the user. The device gains access to the one or more cloud resources, based on the second token.
Owner:ORACLE INT CORP

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Identity provider (IDP) agnostic authentication enforcement

An intermediary server operates an application proxy. An access request is received for access to an application, where an access policy is associated with the application that specifies authentication method(s) acceptable for satisfying an authentication requirement enforced by the application proxy. The user agent is redirected to submit an authentication request to an identity provider for identity verification. An authentication response generated by the identity provider is received and includes information that specifies authentication method(s) used during the identity verification. If the authentication method(s) used during the identity verification match the authentication method(s) acceptable for satisfying the authentication requirement, the user will not be prompted to perform those authentication method(s) and the authentication requirement enforced by the application proxy is met. If they do not match, the user will be prompted to perform the authentication method(s) as a condition to access the application.
Owner:CLOUDFLARE INC

System and method for authenticating user of UE for meta-universe service

Embodiments herein disclose a method for authenticating a user of a UE by a network / AF entity (110) for meta-universe / any other service. The method includes receiving a session setup request message from a user of the UE to access the meta-universe service. The session establishment request message includes a UE-ID identifying a UE through which the meta-universe service is accessed, an AF-ID, an external identity provider ID identifying a third party identity service provider of a user through which the service is authenticated to utilize. Further, the method includes identifying the home network based on the UE-ID. Further, the method includes sending a user authentication request to the UAF entity (106) to validate a user of the UE requesting meta universe service based on the identification. Further, the method includes receiving, from the UAF entity, a user authentication response based on the user authentication request. The user authentication response includes a user authentication result and a derived user identity.
Owner:SAMSUNG ELECTRONICS CO LTD

Double blind private wireless local area networking

Techniques are provided for double blind private Wi-Fi wireless networking using an authentication method (e.g., OpenRoaming) that allows the network to authenticate a user identity against an IDP (e.g. Apple ID), without disclosing any identifiable information about that user to the network, or any information about that user's location or behavior to the identity provider, by leveraging a double-blind method.
Owner:CISCO TECHNOLOGY INC

Collaborative cloud identity and credential forgery and abuse defense

A system and method for providing a cloud identity verification exchange service which ingests a plurality of identity assertion data from various Identity Providers and / or Service Providers and aggregates the ingested plurality of data into a master global authentication ledger. The system and method comprise: a data ingestion engine configured for acquiring, extracting, and loading data into the system as well as providing hashing capabilities; a metadata manager for collecting, organizing, and cataloguing ingested data based on collected metadata; and database for storing the master global authentication ledger. The master ledger acts as a central repository that consolidates authentication objects from various Identity Providers, allowing for centralized authentication management, auditing, reporting, and analysis. It provides a comprehensive view of authentication activities across multiple systems and enables the tracking of user authentication events across different identity providers.
Owner:QOMPLX INC

Phishing resistant enrollment via an operating system

An operating system of a first device associated with an identity provider (IdP) may receive an enrollment configuration request from a device management provider for the first device to enroll in an authentication service provided by the IdP. In accordance with the enrollment configuration request, the operating system of the first device may provide the first device that is associated with a first user with a prompt to initiate the enrollment of the first device into the authentication service. The operating system may then transmit an enrollment request message to an authentication server associated with the authentication service. The enrollment request message may also include data associated with the first device that is requesting enrollment in the authentication service where an attestation that the first device is associated with an organization is based on the enrollment request message.
Owner:OKTA INC

Efficient anonymous authentication method and system applied to identity authentication

The invention discloses an efficient anonymous authentication method and system applied to identity authentication, an identity provider performs system initialization, a service provider performs legality check on user service qualification, and a block chain stores and manages identity information associated with a user and a data file of an anonymous certificate. After a delegation request of the user is received, re-proxy verification is completed; a user stores and manages the files through a block chain, the user sends a service request to the block chain when service qualification verification needs to be carried out, a service provider sends materials required by verification to the user and the block chain, and the block chain sends the materials required by verification to the user and the block chain after obtaining a one-time authorization token displayed by an anonymous certificate of the user. And the block chain completes service qualification verification of the user. According to the method, the block chain is integrated, and the proxy zero-knowledge proof scheme is introduced, so that the storage and calculation overhead is outsourced to the block chain, the privacy and the control right of the user are ensured, and seamless and efficient anonymous authentication between the user and the service provider is finally realized.
Owner:ANHUI UNIV

Zero-shot AI workflow engine

ActiveUS12750369B1PathPingPolicy decision
An agent-centric workflow system includes a workflow engine operable to receive a workflow identifier and return a machine-readable response including instructions and success criteria for use by an AI agent. The workflow engine can include a next path generator operable to identify a possible next step in an identified workflow, dependencies between nodes of the identified workflow, and a consequence of the possible next step using a configuration file that corresponds to an API for the identified workflow, as well as an agent context manager operable to use the configuration file to construct the machine-readable response. The system can further include a large language model (LLM) agent operable to receive the machine-readable response and execute the instructions in a zero-shot execution. The system can include a target system including one or more APIs through which the LLM agent communicates with an identity provider or policy decision point.
Owner:THE DOT NET FACTORY LLC

Security for database systems using identity providers for authentication

A system including a processor and a memory is described. The memory is coupled to the processor and configured to provide the processor with instructions. The processor is configured to receive from an identity provider a validation indication for a user as a proxy. The validation indication is for a database, the identity provider, and the user. The processor is also configured to configure a data flow between the database and a client corresponding to the user through the proxy using the validation indication.
Owner:CYRAL INC

Seller autonomous auction system and method with bid privacy and bidder anonymity

The application discloses a kind of seller autonomous auction system and method with bidding anonymity and bid privacy, system includes four entities of seller, bidder, auction platform and anonymous identity provider, and is divided into six stages of initialization, registration, auction release, bidding, winner calculation and transaction.The invention aims at the trade-off between seller autonomy and buyer privacy protection in anonymous auction, and designs a group signature variant-zero-knowledge screenable group signature.The signature combines zero-knowledge proof with group signature, ensuring that the black list screening mechanism defined by the seller does not destroy the anonymity of the bidder.At the same time, by using homomorphic encryption technology, the winning bid calculation of the auction is carried out entirely in ciphertext, realizing the bidding amount and ordering privacy of the bidder.In the final transaction stage, the winner opens the value by presenting the bidding commitment of the winning bid, enabling the seller to correctly identify the winner without revealing their identity, ensuring smooth transaction.
Owner:WUHAN UNIV

Passwordless wireless authentication

First, multiple access tokens can be received from various identity provider services. Each of these access tokens can be associated with a user. Then, the multiple access tokens can be stored in a profile associated with the user. Next, user policies associated with the use of the multiple access tokens can be assigned. A device token can then be provided to the user device associated with the user. The device token can be associated with a profile. A device token and a network policy can be received, and it can then be determined that the user policy and the network policy are consistent. In response to determining that the user policy and the network policy are consistent, authentication can be performed on at least one of the multiple identity provider services.
Owner:CISCO TECHNOLOGY INC

Mechanism to enable a federated onboarding service in an openroaming framework

This disclosure describes systems, methods, and devices related to a mechanism to enable a federated onboarding service in an OpenRoaming™ framework. A device may receive a prompt to initiate onboarding of the device to a framework. The device may the initiate a federated onboarding service process at an access network provider (ANP) that is connected to the device, wherein the federated onboarding service process is configured to onboard the device to the framework. The device may further receive a list of available identity providers (IdPs) configured for the framework and receive a selection of an IdP of the list of available IdPs. The device may then establish a connection between the IdP and the device. The device may receive an IdP-generated user-specific profile, and the device may connect to the framework using the user-specific profile.
Owner:INTEL CORP

A blockchain-based identity authorization method and device

The application discloses a kind of identity authorization methods based on blockchain, it is applied to the service end corresponding to the blockchain of centerless digital identity, blockchain member in the blockchain includes identity provider, identity user and identity verification party;The method comprises: receiving any identity user initiates the authorization request of identity authorization to identity verification party;Wherein, the authorization request includes the authorization information related to the traceable identity certificate stored locally, and the decentralized digital identity of identity provider providing the traceable identity certificate;In response to the authorization request, generate authorization record based on the authorization information and the decentralized digital identity of identity provider, and store the authorization record in blockchain.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Systems and methods for secure online credential authentication

Systems, methods, and non-transitory computer-readable medium are disclosed includes for secure online credential authentication. One method includes receiving, over an electronic network, identification information from an identity provider; accessing, from a database, previously stored hashed identification information stored in association with a previous identity provider; comparing the identification information to previously stored hashed identification information; and storing the identification information in association with the identity provider that provided the identification information in the database when the hashed identification information does not match previously stored hashed identification information.
Owner:ID ME