Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

108 results about "Multi-factor authentication" patented technology

Multi-factor authentication (MFA) is an authentication method in which a computer user is granted access only after successfully presenting two or more pieces of evidence (or factors) to an authentication mechanism: knowledge (something the user and only the user knows), possession (something the user and only the user has), and inherence (something the user and only the user is).

Method and system for preventing identity spoofing using artificial intelligence driven pattern recognition

The invention provides a method and system for preventing identity spoofing during digital authentication processes using artificial intelligence (AI)-driven pattern recognition. The system receives an input data stream from a user attempting to authenticate, which may include biometric data, device behavior data, or user interaction data. An AI-based pattern recognition model processes this data to analyze user behavior patterns and detect any anomalies that may indicate potential spoofing attempts. The system compares the processed data against a pre-established user profile to generate an authentication decision. If anomalies are detected, the system can flag the authentication for further review or trigger additional verification steps, such as multi-factor authentication (MFA) or one-time password (OTP) prompts. The system continuously learns from user interaction data and dynamically updates the user profile to improve the accuracy of identity verification.
Owner:SIVAKUMAR NITHYA REKHA +14

A system for securing cloud-based large language models through cyber threat defense and compliance monitoring

A system (100) for securing cloud-based large language models through cyber threat defense and compliance monitoring, comprising: (a) an access control and authentication module configured to authenticate users and applications using role-based access control (RBAC) and multi-factor authentication (MFA); (b) a data protection and encryption module configured to encrypt data in transit and at rest and to anonymize sensitive input / output data using cryptographic techniques; (c) a threat detection and behavior monitoring module employing machine learning algorithms to identify anomalies and detect potential cyber threats in real time;(d) a regulatory compliance monitoring module configured to continuously assess system operations against applicable regulatory frameworks and generate alerts in the event of deviations from the regulations; (e) an incident response and mitigation module configured to automatically execute predefined response actions upon detection of threats or regulatory violations; (f) a logging, auditing, and forensic analysis module configured to securely log system activities, interactions, and threat events with cryptographic integrity protection; and (g) a governance and policy management module configured to define, update, and enforce organizational AI usage and compliance policies via the cloud-based LLM infrastructure.
Owner:ULAGANATHAN ILAKIYA

Digital identity verification method and device based on zero-trust architecture, terminal equipment and storage medium

The invention discloses a digital identity verification method and device based on a zero-trust architecture, terminal equipment and a storage medium, and belongs to the field of network security, and the method comprises the steps: obtaining an identity verification result according to user information and multi-factor identity verification information; according to the identity verification result, generating a session token and creating a session; collecting behavior data, equipment fingerprint data and geographic position data of the user during the session in real time, and dynamically adjusting the access authority stored by the session token according to the behavior data, the equipment fingerprint data and the geographic position data; each time a request sent by a client is received, the zero-trust architecture gateway determines the current session state of the server by verifying the current session token. Therefore, through the implementation of the invention, various identity authentication technologies can be organically integrated, continuous identity authentication under a zero-trust architecture is realized, and the security of digital identity authentication is improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD

Architectural design dynamic process management system based on Internet

The invention relates to the technical field of building design, and discloses an Internet-based building design dynamic process management system, which comprises a multi-factor identity verification module, a distributed data storage module, a process dynamic optimization engine, a behavior evaluation and intervention module and an intelligent audit tracking system. According to the building design dynamic process management system based on the Internet, through cooperative work of the process dynamic optimization engine and the behavior evaluation and intervention module, the problem that task optimization of a traditional process management system depends on a preset rule is solved; the flow dynamic optimization engine dynamically adjusts the task priority and resource allocation by using an improved ant colony algorithm based on the real-time task progress and the executor behavior data; meanwhile, the behavior evaluation and intervention module quantitatively evaluates the behavior of the executor according to a weighted scoring model, triggers an automatic intervention process when necessary, and can quickly adapt to sudden changes, so that the resource allocation efficiency is improved, and human errors are reduced.
Owner:王彧

Contactless card and personal identification system

For multifactor authentication, a transaction device can receive encrypted data from a contactless card within a communication range of a short-range communication antenna, communicate the encrypted data to an authenticating device, solicit a user PIN in response to authentication of the encrypted data by the authenticating device, receive an input PIN, communicate the input PIN to a separate device storing a record PIN for the contactless card, and authorize a transaction initiated in connection with the contactless card in response to matching of the input PIN with the record PIN by the separate device. The input PIN can be received from the contactless card itself or a user interface, and the separate device can include the authenticating device or the contactless card itself. In different embodiments, the input PIN or the record PIN can include an EMV PIN stored in an EMV applet on the contactless card.
Owner:CAPITAL ONE SERVICES LLC

Enterprise production safety operation and maintenance operation listing and locking intelligent management system

The invention discloses an enterprise production safety operation and maintenance operation listing and locking intelligent management system. The system is composed of a management platform, a mobile terminal, an intelligent lock set and an evidence storage module. The management platform is responsible for creating an isolation job task, tracking the state and removing the right after timeout; the mobile terminal sequentially implements face, fingerprint and voiceprint multi-factor identity verification, and generates a locking or unlocking instruction after completing geo-fence verification; the intelligent lock group comprises a Bluetooth lock, a fingerprint lock and a mechanical lock, and is used for executing unlocking and locking operations and collecting operation logs and on-site images; and the evidence storage module performs hash abstract on the event data during task creation, lock operation and exception repair and asynchronously writes the event data into the block chain. Intelligent monitoring and management of three risk factors of users, equipment and operation environment in the whole process of production operation and maintenance operation are realized, and the method is suitable for safety management and control of high-risk production operation places, so that the safety, compliance and management efficiency of production and maintenance operation are remarkably improved.
Owner:JOB SAFETY SOLUTIONS

Systems and processes for multifactor authentication and identification

A system can include a server having a processor configured to receive, from a first computing device, first data associated with at least one historical data attack. The processor can encode the first data into at least one fixed-size representation. The processor can generate at least one anonymized vector representation based on the at least one fixed-size representation. The processor can receive, from a second computing device, second data associated with a potential attacker. The processor can encode the second data into at least one additional fixed-size representation. The processor can generate a second anonymized vector representation based on the at least one additional fixed-size representation. The processor can generate a confidence measure of the potential attacker as an attacker based on a comparison between the at least one anonymized vector representation and the second anonymized vector representation.
Owner:T STAMP INC

Zero-trust cybersecurity enforcement in operational technology systems

In one embodiment, a method may implement a multi-layer cybersecurity model for a multi-layer distributed computer system which comprises a sensitive data resource, such as a computing environment with an operational technology (OT) layer with multiple zones, an information technology (IT) layer, a DMZ, and a cloud layer. The method can assess a policy based on a zero-trust model for the sensitive data resource. The method can receive one or more requests, at any layer of a multi-layer distributed computing system, to access the sensitive data resource and acquire identity information for a user account specified in the first request. The method can perform a multi-layer multi-factor authentication of the user account using the identity information and the multi-layer cybersecurity model. In response to authenticating the identity information, the method can acquire sensitive access data corresponding to the identity information. The method can determine a sensitive resource access value using the sensitive access data and the zero trust model. In response to determining the sensitive resource access value is above a predetermined threshold, the method can authenticate the user account.
Owner:XAGE SECURITY INC

Multifactor authentication via bifurcated passcode and non-fungible token

Multifactor user authentication leveraging secure tokenization, such as a Non-Fungible Token (NFT) and multiple passkeys (e.g., bifurcated passkey). One or more authentication NFTs are generated that use some form of a user's authentication credentials as the seed input for the NFT encryption / hash algorithm(s). In addition, passkeys are distributed to and / or made accessible to multiple passkey holders. In response to an event that requests multifactor authentication of the user, a plurality passkeys are requested, received and verified. Each of the passkeys being requested and received from, or at the directive of, one of the multiple passkey holders. In response to verifying the plurality of passkeys, at least one of the authentication NFTs is accessed and the cryptographic hash algorithm(s) is implemented to decrypt the authentication NFT(s) and identify the one or more user credentials. In response, the user is authenticated based at least on the user credentials that formed the basis for the authentication NFT(s).
Owner:BANK OF AMERICA CORP

Systems and methods of cloud-based multifactor authentication

A method may include receiving, by a multifactor authentication (MFA) service instantiated on a computing system, a token generated by a cloud services provider and associated with a user device. The MFA service may be instantiated within a tenancy of the cloud services provider. The method may include determining, by the computing system, an authorized cloud service instantiated within the tenancy. The method may include receiving, by the computing system, a request to access the authorized cloud service by the user device, where the request may include a multi-factor authentication request. The method may include generating, by the MFA service instantiated on the computing system, a one-time pad (OTP). The method may include providing, by the MFA service instantiated on the computing system, the OTP to the user device such that the user device accesses the authorized cloud service.
Owner:MCMILLEN HOLDINGS INC DBA RYANTECH

Multi-factor authentication with device and carrier validation

The invention provides systems, methods, and computer-readable media for multi-factor authentication (MFA) using device and carrier validation. A user device generates an attested blob containing cryptographic keys and a Universal Integrated Circuit Card (UICC)-originated International Mobile Subscriber Identity (IMSI), which is transmitted to a cloud-based MFA service. The service validates the attested blob, coordinates with an Original Equipment Manufacturer (OEM) service, and executes an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) process with the carrier network to establish mutual trust. Authentication data, including a validated phone number independent of the device's stored number, is securely stored in a cloud wallet. The invention enhances security by mitigating risks such as spoofing, replay attacks, and SIM swapping, providing a novel authentication framework compatible with modern networks.
Owner:SYNIVERSE TECHNOLOGIES LLC

Multifactor authentication from messaging systems

A user is assigned an initial risk score during a session with a messaging platform. During the session, the user attempts an operation with an external service. One or more additional authentication factors are requested from the user to dynamically lower the initial risk score. The lowered risk score is processed with the external service to perform the operation on behalf of the user during the session.
Owner:NCR VOYIX CORP

Methods, devices, and systems for facilitating firearms safety

Methods, systems, and devices for facilitating firearms safety are provided. A multi-factor authentication is performed to verify an identity of a user trying to access a secure firearm. Presence of a user contact with the secure firearm is detected, the secure firearm being in a locked state. Upon detecting the presence of the user contact with the firearm, the user is prompted to enter a passcode via a keypad on the secure firearm. Also, a biometric attribute of the user is obtained by a biometric sensor on the secure firearm. It is determined, if the user is an authorized user based on the passcode entered by the user and the biometric attribute of the user. In response to determining that the user is the authorized user, the secure firearm is unlocked.
Owner:BROOKS-MALLORY BETTY CAROL

Limiting discovery of a protected resource in a zero trust access model

According to an embodiment, a system comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations. The operations comprise determining that an endpoint device has requested to discover a location of a protected resource that is protected by a gateway, determining whether the endpoint device has provided a token that is valid, and permitting the endpoint device to discover the location of the protected resource based on determining that the endpoint device has provided the token that is valid. The token indicates that the endpoint device successfully completed a first multi-factor authentication procedure in connection with accessing an authentication enforcement resource.
Owner:CISCO TECHNOLOGY INC

System and method for securing and facilitating access to a digital legacy

A system for securely storing personal information and memories of a user, such as through a software application, is disclosed. In particular, the system may utilize the application to transition the personal information and memories from cloud storage to cold storage and / or to an air-gapped data storage system. The personal information and memories of the user may be secured by the system using blockchain technology, multi-factor authentication, and / or other security technologies. The system may ensure that the information is highly secured until the user has passed and a next of kin of the user and / or other intended recipient of the user's information successfully authenticates with the system, such as by presenting a valid death certificate and / or acceptable credential. If the intended recipient of the data successfully provides a valid death certificate and / or credential, the intended recipient may be provided with access to the data associated with the user.
Owner:DIGITAL LEGACY AI INC

Multi-factor authentication based on audio message

Techniques are described for accessing an account on a public device. In some implementations, an audio message is received from a portable computing device, requesting to establish an account access session between the portable computing device and the public device. A first communication based on the audio message is sent from the public device to a backend server. The backend server analyzes the first communication to determine whether the portable computing device is authorized to establish the account access session. A second communication is received from the backend server, indicating that the portable computing device is authorized. In response, the account access session is established between the portable computing device and the public device, wherein the account access session is employed by an application executing on the portable computing device to access account information associated with an account of a user of the portable computing device.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Multi-factor authentication using wearable devices

According to one aspect, a method includes receiving, by a head-mounted display device, an authentication code associated with multi-factor authentication; receiving image data from an image camera on the head-mounted display device; detecting, by the head-mounted display device, that the image data includes an interface for receiving the authentication code; and displaying, by the head-mounted display device, the authentication code in a location corresponding to the interface.
Owner:GOOGLE LLC

Dynamic multi-factor authentication for premises access

Systems, methods, and devices are described herein. An example system is disclosed. The system includes at least one computing device configured to communicate with a premises monitoring system located at a premises. The at least one computing device is further configured to determine that a plurality of authentication factors associated with a person at the premises monitoring system have been satisfied, determine a respective weight of a plurality of weights for each of the plurality of authentication factors, determine a security factor for the premises monitoring system, calculate an authentication value for the person based on the security factor and the plurality of weights for the plurality of authentication factors, determine that the authentication value meets a predefined authentication threshold, and in response to determining that the authentication value meets the predefined authentication threshold, deem the person authenticated.
Owner:THE ADT SECURITY CORPORATION

System and method for providing location-based access in 5g

In one embodiment, a method includes transmitting, to a multi-factor authentication (MFA) agent running on a user device, a request for a location of the user device, receiving, from the MFA agent, the location of the user device, wherein the location is determined by the MFA agent to be a most common location indicated by a plurality of location indicators, receiving, from a policy server, a location-based access policy, appending, to the location-based access policy, the location of the user device and determining, based on the location of the user device and the location-based access policy, whether to allow the user device to access one or more of: a remote service, a remote database, and a remote device.
Owner:CISCO TECHNOLOGY INC

Limiting discovery of a protected resource in a zero trust access model

According to an embodiment, a system comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations. The operations comprise determining that an endpoint device has requested to discover a location of a protected resource that is protected by a gateway, determining whether the endpoint device has provided a token that is valid, and permitting the endpoint device to discover the location of the protected resource based on determining that the endpoint device has provided the token that is valid. The token indicates that the endpoint device successfully completed a first multi-factor authentication procedure in connection with accessing an authentication enforcement resource.
Owner:CISCO TECHNOLOGY INC

Authentication hardening with proof of proximity over local connection

A device may receive, from a computing device, a request for a two-factor authentication of a user. A device may transmit, from a server to the computing device and based on the request, multi-factor authentication data to the computing device. A device may establish a short-distance wireless communication link between the computing device and a registered mobile device. A device may transmit, from the computing device and via the short-distance wireless communication link, encrypted data which is encrypted based on the multi-factor authentication data, to the registered mobile device. A device may receive, at the server and from the registered mobile device, a confirmation that corrected data was decrypted from the encrypted data. A device may provide, based on the confirmation, the user with access to a service via the computing device.
Owner:CISCO TECHNOLOGY INC

Remote control wake-up method, device, equipment and storage medium

The present application relates to the technical field of remote control wake-up, and discloses a remote control wake-up method, apparatus, device and storage medium. The method includes: performing multi-concatenated encoding processing on a key signal of the remote control to obtain multi-concatenated encoded data and generate a session key; performing adaptive carrier modulation to obtain a dynamic modulation signal; performing multi-band transmission control processing and adaptive power control to obtain a transmission control signal; performing low-power management on the remote control system, creating a multi-level sleep strategy and a dynamic power consumption control scheme, and controlling a signal processor to receive multi-band optical signals; performing parallel processing and adaptive decoding on the multi-band optical signals to obtain decoded multi-concatenated encoded data; performing multi-factor authentication processing on the decoded multi-concatenated encoded data based on the session key to obtain a secure wake-up instruction, thereby improving the reliability and security of the wake-up, optimizing the power consumption management strategy, and enhancing the signal processing capability.
Owner:SHENZHEN JIALIAN ELECTRONIC TECH DEV CO LTD

System and method for enhancing multi-factor authentication

A system for enhancing multi-factor authentication comprises a processor associated with a server. The processor receives a first request with user identity data to access an application service from a user device. The processor generates a multi-factor authentication code to verify a user identity and a user device. The processor implements a customized operation rule with the multi-factor authentication code and a customized security code to generate an enhanced multi-factor authentication code. The processor presents the multi-factor authentication code to the user device with a response for the user to provide the enhanced multi-factor authentication code. The processor determines whether a user input code matches the enhanced multi-factor authentication code. In response to determining that the user input code matches the enhanced multi-factor authentication code, the processor authorizes the user device associated with the user to interact with the entity, such as, for example, to implement the application service.
Owner:BANK OF AMERICA CORP

Multiple-factor authentication

One example involves a method for providing communications services to remotely-situated client entities, wherein each client entity is associated with users and each user is associated with a communication device. For providing the services verification may be realized by using authentication factors, and a communication request generated with at least one of the authentication factors. The generated communication request may include a first portion specifying at least one target endpoint associated with the user and a second portion associated with or indicating the security code and that includes a set of instructions which: are specific to the user, which specify how to communicate the security code for the user, and which specify different security codes for different types of communications. The security code is sent to the user according to the set of instructions, and verified via a second authentication factor is implemented.
Owner:8X8 INC

Multi-factor authentication door access control system

A multi-factor authentication access control system is described for permitting access to secured locations. Types of authentication factors include property or physical-based items and biometric-based information. Optionally, the biometric information presented by the person is evaluated for being a presentation attack. Exemplary embodiments are directed to controlling door access.
Owner:ASSA ABLOY GLOBAL SOLUTIONS AB

Multi-Factor Authentication and Post-Authentication Processing System

An end-user computing device may utilize a device to capture input from an electronic tag of a physical asset. The end-user computing device may generate supplemental digital data associated with the input. The end-user computing device may transmit the input and the supplemental digital data to an authentication and digital assets server. The authentication and digital assets server may authenticate the physical asset and transmit the authentication results to the end-user computing device, which may display the authentication results. If the authentication of the physical asset is successful, the authentication and digital assets server may select one or more digital assets and transmit the one or more digital assets to the end-user computing device. The end-user computing device may display the one or more digital assets.
Owner:NIKE INC

Multi factor authentication using different devices

Customizing an application on a mobile device includes storing at least a portion of customization data in a customization server that is independent of the mobile device, a user of the mobile device accessing the customization server independently of the mobile device, receiving authorization data from the customization server that enables the mobile device to securely receive customization data from the customization server, and the mobile device using the authorization data to cause the customization server to provide the customization data to the mobile device. The authorization data may be provided by postal message, email message, an SMS text message, and / or a visual code provided on a screen of a computer used to access the customization server. The user may use a computer to provide credential information to access the customization server. Customizing the application may allow the mobile device to access a user service on behalf of the user.
Owner:ASSA ABLOY AB

Biometric Multi-Account Transaction Card

PendingUS20260252837A1MicrocontrollerBiometric data
A biometric multi-account transaction card and associated transaction system. The card includes a card body conforming to ISO / IEC 7810 ID-1, a fingerprint sensor configured to capture user biometric data, an optical element for facial-recognition or optical sensing, and an integrated circuit contact module for EMV communication is disclosed. A secure element stores a non-reversible biometric template and multiple tokenized payment credentials organized in credential slots. A microcontroller executes biometric-matching algorithms, account-selection logic, and generates EMV-compliant cryptograms, while an NFC antenna enables contactless operation. A cooperating point-of-sale terminal displays account options received from the card and can perform facial recognition for multi-factor authentication. Upon successful authentication, the card transmits a tokenized payment credential corresponding to a selected account.
Owner:WOODLEY TYWANA

Multi-factor authentication system for property management

A multi-factor authentication system for property management may provide user a convenient and safe property management service via enrolling with service for multi-factor authentication via an application. The user may log in the multi-factor authentication service platform during the enrollment phase via the application to acquire an account and obtain authority for use, thereby to access the service provided by the multi-factor authentication service platform via a property management station system. In addition, during the property management service, the user may acquire the property management service in fewer steps and a more secure manner during an authentication phase with the multi-factor authentication service platform, thereby to enforce security for identity authentication.
Owner:WANG CHIH CHUN