Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Login session" patented technology

In computing, a login session is the period of activity between a user logging in and logging out of a (multi-user) system.

Dynamic authentication revocation utilizing privilege assurance

ActiveUS12500888B2Securing communicationInternet privacyEnterprise computing
A system and method for the dynamic authentication revocation using privilege assurance of enterprise computer network environments using lateral movement detection and prevention. The system uses local session monitors to monitor logon sessions within a network, generating and verifying event logs and authentication records to ensure the legitimacy of authenticated user sessions and to revoke credentials when an illicit session is detected and further removing potentially compromised network components from the network, halting lateral movement in real-time.
Owner:QOMPLX INC

Secure collection of sensitive data on computer devices

ActiveUS20260006008A1Securing communicationIdenticonLogin session
A method for secure collection of sensitive data at a computer device includes receiving a request for sensitive data. The request indicates a set of parameters and a dynamic encryption key. The dynamic encryption key is generated by an authorized data requester based on a login session identifier. The method includes creating a user interface for collecting the set of parameters by an artificial intelligence (AI) software of the computer device. The method includes providing the user interface for collecting the set of parameters. Responsive to collecting the set of parameters from the user, the method includes encrypting the set of parameters using the dynamic encryption key and an encryption algorithm associated with the authorized data requester. The method includes transmitting the encrypted set of parameters to the authorized data requester to be decrypted.
Owner:T MOBILE US INC

Remote login resource access control using a container

PendingUS20250330469A1Securing communicationUser deviceShell (computing)
A system can be used to control access to protected resources with respect to remote access of a computing environment. The system can execute a service file to generate a container in a host system based on user input received from a user device to initiate a login session. The service file can correspond to the user input. Subsequent to generating the container, the system can execute a user shell associated with the container to assign the user device to the container. The container can restrict the user device to access a set of predefined resources indicated in the service file. In response to detecting that the login session has ended, the system can remove the container associated with the user device from the host system.
Owner:RED HAT INC

Secure storing and retrieval of sensitive data from a server system

ActiveUS20260003516A1Input/output to record carriersLogin sessionKey generation
A method includes receiving a request from a data requester device by a server system to retrieve sensitive data associated with a customer. Decryption of the sensitive data can require a composite decryption key specific for the encrypted sensitive data. The method can include retrieving the encrypted sensitive data, a login session identifier associated with the encrypted sensitive data, at least one attribute associated with the data requester, and a decryption algorithm. The login session identifier, the at least one attribute associated with the data requester, and the decryption algorithm are required for generating the composite decryption key for decrypting the encrypted sensitive data. The method includes generating the composite decryption key and decrypting the encrypted sensitive data by the server system based on the composite decryption key. The method can include providing the decrypted sensitive data to the data requester device to be revealed.
Owner:T MOBILE US INC

Session data processing method, session system, electronic device and program product

The invention provides a session data processing method, a session system, electronic equipment and a program product, and the method comprises the steps: generating a first equipment session comprising a first session identifier, a first equipment token and a first session object when a first non-login session request sent by a client on first equipment is received; transmitting the first session identifier and the first equipment token to the client, receiving a first login request sent by the client, generating a first user session comprising the first user token and first client login information, binding a user identifier of a target user with a first session object, and sending the first session object to the client; and storing the first client login information in the first session object, and transmitting the first user token to the client, thereby realizing a parallel support capability of simultaneously supporting an anonymous session (i.e., a first device session) and an authentication session (i.e., a first user session), and allowing a target user to carry out authentication according to actual demands. And the client is operated in a non-login state or a login state flexibly.
Owner:北京理房通支付科技有限公司

Ssh lineage table-based tracking of user login sessions

An illustrative system includes a processor configured to: determine that a first user login session and a second user login session have a parent-child relationship that indicates that a particular user is associated with both the first and second user login sessions; link first user login activity performed during the first user login session and second user login activity performed during the second user login session to the user; and identify, at least in part by using an ssh lineage table, an original login session associated with a subsequent chain of login sessions; and a memory coupled to the processor and configured to provide the processor with instructions.
Owner:FORTINET INC

Host-level ticket forgery detection and extension to network endpoints

A system and method for detection and prevention of ticket forgery cyberattacks by improving host-level analytics and monitoring and extending the improved host-level analytics and monitoring to endpoints of a network. The methodology described herein comprises the use of a ticket-granting log extension utility which stores every logon session on a network, queries the local ticket cache, and generates additional custom data as a part of an event log stream such as a start time, end time, renew time, and related session data. This comprehensive log extension data can be used to identify certain types of ticket forgery cyberattacks by comparing the user session name with the client name identified in the ticket presented for access to network resources and other means. This host-level ticket forgery detection can be extended to network endpoints for additional security.
Owner:QOMPLX INC

Data transmission method and device, electronic equipment and storage medium

The invention discloses a data transmission method and device, electronic equipment and a storage medium. Comprising the following steps: in response to a login request which is initiated by a client and is successfully verified, creating a login session, and generating a corresponding dynamic symmetric key and corresponding first time information; constructing a digital envelope corresponding to the dynamic symmetric key based on the dynamic symmetric key and the first time information, generating a digital signature corresponding to the digital envelope based on a preset private key, and transmitting the digital envelope and the digital signature to the client, the client extracts the dynamic symmetric key based on the digital envelope and the digital signature to encrypt the target service data and construct a service request; and verifying the service request according to a preset service verification rule, if verification succeeds, updating the first time information of the dynamic symmetric key into second time information, repackaging the dynamic symmetric key with the updated second time information into a digital envelope, signing the digital envelope, and feeding back the digital envelope to the client for subsequent data transmission. And the data transmission security is improved.
Owner:SHENZHEN COMTOP INFORMATION TECH

A BMC system with multi-level user remote authentication mechanism

The present invention proposes a BMC system with a multi-level user remote authentication mechanism, comprising a business server cluster, an authentication server, and a switch. Each business server is provided with a BMC management unit. A client connects to the authentication server via the Internet to perform user identity and authority authentication. The authentication server includes a session management module for generating, updating, and destroying login sessions for users to log into the BMC system based on user login information; a VLAN management module for establishing a session VLAN subnet for each user login session to the BMC system, so that the user can manage the hardware resources of the business servers in the session VLAN subnet; and a permission configuration module for configuring the permission level for users to manage the hardware resources of the business servers in the session VLAN subnet. This system can improve authentication efficiency while providing higher security.
Owner:FUXI SEMICON (SHENZHEN) CO LTD

Implementation method and device of audit playback of a bastion

The present disclosure provides an implementation method and device for audit playback of a bastion host, wherein the method comprises: obtaining a pseudo login shell script for calling screen recording software; configuring a user login session to be bound to the pseudo login shell script; and automatically creating a directory and recording a monitoring record file through the pseudo login shell script. The present disclosure can highly restore the user operation site, ensure the integrity of each file and record, and improve the flexibility of file organization mode and the positioning efficiency.
Owner:BEIJING TTSF TECH

Secure shell (SSH) remote connection process management method and computing device

Embodiments of the present application relate to the technical field of server, and specifically provide a secure shell (SSH) remote connection process management method and a computing device, wherein the method comprises: obtaining a login session identifier of a user; determining whether the login session identifier is in a blacklist; in response to the login session identifier being in the blacklist, adding an SSH process of the user into a cgroup resource control group; and in response to the login session identifier not being in the blacklist, monitoring resource usage of the SSH process of the user. Embodiments of the present application can achieve dynamic, real-time and fine resource management for remote connection sessions.
Owner:XFUSION DIGITAL TECH CO LTD

Bidirectional identity authentication method and system for client and lower computer

The invention discloses a bidirectional identity authentication method and system for a client and a lower computer, and relates to the technical field of user identity authentication. The bidirectional identity authentication method comprises the following steps: a client generates a first challenge code, derives a temporary key based on a current timestamp and a public identifier of a lower computer, and encrypts an authentication data block comprising user authentication data and the first challenge code by using the temporary key; and the lower computer receives the authentication data block, verifies the validity of the timestamp and decrypts the data, and then generates a response value based on the hardware unique identifier and the local secret key. And meanwhile, generating a second challenge code, and returning the response value and the second challenge code to the client. And the client verifies whether the response value is matched with an expected response. And if so, encrypting the second challenge code by using the temporary key to generate a confirmation signal, and sending the confirmation signal to the lower computer. And the lower computer decrypts the confirmation signal and verifies the consistency of the decrypted data and the second challenge code. And if the verification is passed, opening the login session and destroying the temporary key.
Owner:XIAMEN HANIN CO LTD

Host-level ticket forgery detection and extension to network endpoints

A system and method for detection and prevention of ticket forgery cyberattacks by improving host-level analytics and monitoring and extending the improved host-level analytics and monitoring to endpoints of a network. The methodology described herein comprises the use of a ticket-granting log extension utility which stores every logon session on a network, queries the local ticket cache, and generates additional custom data as a part of an event log stream such as a start time, end time, renew time, and related session data. This comprehensive log extension data can be used to identify certain types of ticket forgery cyberattacks by comparing the user session name with the client name identified in the ticket presented for access to network resources and other means. This host-level ticket forgery detection can be extended to network endpoints for additional security.
Owner:QOMPLX INC

Secure storing and retrieval of sensitive data from a server system

ActiveUS12561075B2Input/output to record carriersLogin sessionDatabase
A method includes receiving a request from a data requester device by a server system to retrieve sensitive data associated with a customer. Decryption of the sensitive data can require a composite decryption key specific for the encrypted sensitive data. The method can include retrieving the encrypted sensitive data, a login session identifier associated with the encrypted sensitive data, at least one attribute associated with the data requester, and a decryption algorithm. The login session identifier, the at least one attribute associated with the data requester, and the decryption algorithm are required for generating the composite decryption key for decrypting the encrypted sensitive data. The method includes generating the composite decryption key and decrypting the encrypted sensitive data by the server system based on the composite decryption key. The method can include providing the decrypted sensitive data to the data requester device to be revealed.
Owner:T MOBILE US INC

SYSTEMS AND METHODS FOR BIOMETRIC AUTHENTICATION

An authentication screen, which prevents access to at least one application via the computer device, can be displayed on a computer device's screen. The computer device can scan a physical medium located externally and independently of the computer device to capture challenge data for a user from the physical medium, and the computer device can capture response data from the user. Upon a successful match between the challenge data and the response data, the authentication screen can be removed from the screen, and access to the at least one application can be granted. Once the user is granted access to the computer device, the computer device can identify the user and manage the challenge data, response data, SSO sessions, and / or personalized device configurations.
Owner:ZEBRA TECHNOLOGIES CORP

Platform login method and device, back-end server and storage medium

The embodiment of the invention discloses a platform login method and device, a back-end server and a storage medium, and the method comprises the steps: receiving a user identifier fed back by a platform to which a platform applet belongs according to a call instruction, and determining historical login session information from a plurality of data tables of a platform database according to the user identifier; generating user session association information according to the user identifier and the historical login session information, and feeding back the user session association information to the gateway, so that the gateway sends session information in the user identifier and the user session association information to the platform applet; and when a user performs third-party login authentication based on the platform applet, receiving a login state request sent after the gateway verifies that session information is valid, updating login state information according to the login state request and an authentication type of the user during login authentication, feeding back first login-free expiration time to the gateway according to the updated login state information, and sending the first login-free expiration time to the gateway. And the gateway feeds back the login result to the platform applet based on the first login-free expiration time, so that the silent login is accurate and rapid.
Owner:DIGITAL GUANGDONG NETWORK CONSTR CO LTD

Unified identity authentication and collaborative office workbench access platform and method

This invention provides a unified identity authentication and collaborative workbench access platform and method, belonging to the field of user identity software authentication technology. The collaborative workbench module receives a user-initiated access request for a business system containing the identifier of the target business system and sends it to the unified access orchestration module. The unified access orchestration module queries the authentication routing policy from the access policy library based on the target business system identifier, then calls the unified identity authentication platform module to complete user authentication and obtain unified identity token information. Based on the authentication routing policy, it generates authentication data recognizable by the target business system from the unified identity token, verifies the user's access permissions, and forwards the authentication data to the target business system if the permission verification passes. The target business system establishes a login session based on the received authentication data and returns the access result to the unified access orchestration module. This invention achieves unified access control for multiple business systems.
Owner:ANHUI CONCH IT ENG CO LTD

Single sign-on method, system and electronic device

The application discloses a single sign-on method, system and electronic equipment. The method comprises the following steps: a user terminal acquires login information and initiates a login session for requesting to log in a target application in a first server according to the login information; then, the first server checks whether the login session of a user account in the login information about the target application is expired; if not, the first server can log in the target application again after logging out other applications of the user account; if yes, the first server can request a second server to update the login session; then, the second server updates the login session and logs out other applications of the user account on the second server; and finally, the user terminal logs in the target application according to the updated login session. The application can improve the security of logging in a ship system and a shore system, and can be widely applied in the technical field of communication.
Owner:GUANGZHOU MARINE GEOLOGICAL SURVEY

Secure collection of sensitive data on computer devices

ActiveUS12563020B2Securing communicationIdenticonLogin session
A method for secure collection of sensitive data at a computer device includes receiving a request for sensitive data. The request indicates a set of parameters and a dynamic encryption key. The dynamic encryption key is generated by an authorized data requester based on a login session identifier. The method includes creating a user interface for collecting the set of parameters by an artificial intelligence (AI) software of the computer device. The method includes providing the user interface for collecting the set of parameters. Responsive to collecting the set of parameters from the user, the method includes encrypting the set of parameters using the dynamic encryption key and an encryption algorithm associated with the authorized data requester. The method includes transmitting the encrypted set of parameters to the authorized data requester to be decrypted.
Owner:T MOBILE US INC

Secure collection of sensitive data on computer devices

PendingUS20260189540A1IdenticonLogin session
A method for secure collection of sensitive data at a computer device includes receiving a request for sensitive data. The request indicates a set of parameters and a dynamic encryption key. The dynamic encryption key is generated by an authorized data requester based on a login session identifier. The method includes creating a user interface for collecting the set of parameters by an artificial intelligence (AI) software of the computer device. The method includes providing the user interface for collecting the set of parameters. Responsive to collecting the set of parameters from the user, the method includes encrypting the set of parameters using the dynamic encryption key and an encryption algorithm associated with the authorized data requester. The method includes transmitting the encrypted set of parameters to the authorized data requester to be decrypted.
Owner:T MOBILE US INC

Computer network information security management method and system based on data processing

PendingCN122160137ASecuring communicationInformation security managementInformation security
The present application relates to the technical field of information security, in particular to a computer network information security management method and system based on data processing, the method comprising: collecting key security data and historical security data of the current login session of a user, and preprocessing the key security data to form a current login behavior feature vector; constructing a login time probability distribution model, a login space position clustering center model and a historical device fingerprint model for each user based on the historical security data, and forming a user behavior baseline vector; comparing the current login behavior feature vector with the user behavior baseline vector within 1 second after the user completes login, and calculating the time deviation, the space deviation and the device abnormality degree. The present application introduces a dynamic device fingerprint technology based on multiple fractal spectrum analysis and hardware aging drift model, effectively overcoming the problems of traditional static fingerprint being easily forged and high false alarm rate caused by natural hardware aging.
Owner:LIHE TECHNOLOGY CO LTD

Access authorization for report data in a multi-tenancy data management system

Methods, systems, and devices for data management are described. A multi-tenancy data management system (DMS) may include multiple computing objects organized as a hierarchy of computing objects. The DMS may receive a request for report data associated with a first set of computing objects of the DMS. The DMS may identify context information for a log-in session associated with the request. The context information may include a tenant identifier (ID) for a tenant associated with the request. The DMS may apply a filter to the first set of computing objects. The filter may be based on a second set of computing objects to which the tenant has access within the hierarchy of computing objects. The DMS may output the report data for at least one computing object of the first set based on the at least one computing object being included in the second set of computing objects.
Owner:RUBRIK INC

Login management method and device

The embodiment of the invention provides a login management method and device, and the method comprises the steps: receiving the login information of a client, loading an interface permission set of the current login information, which is granted with an access permission in a current client type, from a database based on a current user and a role to which the user belongs in the login information, loading the interface permission set into a server memory so as to determine an access permission interface range of the current login session based on the interface permission set; generating a corresponding access token, and enabling the client to register a long connection session with the server based on the access token; and receiving an interface access request sent by the client through the long connection session, verifying a target interface of the interface access request, verifying an authority state of the target interface, and executing service logic of the target interface and returning an execution result to the client when the authority state is an access authority granting state. According to the method, the defect of difficulty in performing permission isolation on different client types and the like is effectively overcome, and the permission vertical management of multiple client types is remarkably improved.
Owner:富盛科技股份有限公司