Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

42 results about "Passphrase" patented technology

A passphrase is a sequence of words or other text used to control access to a computer system, program or data. A passphrase is similar to a password in usage, but is generally longer for added security. Passphrases are often used to control both access to, and operation of, cryptographic programs and systems, especially those that derive an encryption key from a passphrase. The origin of the term is by analogy with password. The modern concept of passphrases is believed to have been invented by Sigmund N. Porter in 1982.

Securing secrets and their operation

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for providing secure protection of secrets. In some implementations, a passphrase and data corresponding to an authenticatable entity are received. An entropy extender is generated based at least on the data associated with the authenticatable entity. A key pair is generated using the passphrase and the entropy extender, the key pair comprising a public key and a private key. An identifier is generated using data from the public key, wherein the identifier maps to a file for storing content related to the authenticatable entity.
Owner:CHANG MINGTAI +1

Wi-fi protected access 3-compatible authentication using an established binding

In response to an association request associated with an electronic device to a second WLAN that uses a WPA3-compatible authentication protocol, an access point may establish a connection with an electronic device using the second WLAN when a binding between a passphrase associated with the electronic device and the second WLAN exists in a computer system. Alternatively, when the binding does not exist, the access point may reject the association request. Instead, the access point may establish a second connection with the electronic device using a first WLAN that uses a WPA2-compatible authentication protocol, and may establish the binding in a computer system. Next, the access point may perform a BSS transition of the electronic device from the first WLAN to the second WLAN. Furthermore, the access point may perform authentication of the electronic device after the connection or the second connection is established.
Owner:RUCKUS IP HOLDINGS LLC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

End to end encryption with roaming capabilities

Systems and methods relating to end to end encryption. Encrypted data stored on a server or transmitted by way of a server can be accessed from any number of authenticated client devices by storing an encrypted private key on the server. The encrypted data can only be decrypted by the decrypted version of the encrypted private key. The encrypted private key is undecryptable by the server and can only be decrypted using user provided credentials (e.g. a user provided password / passphrase). For the user to access the encrypted data, the client device used by the user downloads the encrypted private key along with the encrypted data. The encrypted private key is then decrypted using user provided credentials and the decrypted private key is used to decrypt the downloaded encrypted data. The decrypted private key never leaves the client device and is never used by the server.
Owner:ENCSTOCOM LLC

Generating usable high entropy passphrases in local language from personalized intersection corpus

PendingUS20250335572A1Semantic analysisDigital data authenticationLocal languagePassphrase
There are technical challenges to address the technical capability limitations of a Basic Emergent User (BEU) to enable and assist in generating high entropy passphrases but are easier for recall. Generation usable high entropy passphrases in local language from personalized intersection corpus for device authentication set up for BEU is provided. A recallable phrase, spoken by the BEU in local language, is converted to a text and Seed List Words (SLWs) are filtered based on a pre-generated personalized intersection corpus. Passphrase distance matrix is generated for the SLWs using the personalized intersection corpus. Words associated with each SLW are arranged in descending order of vector distance or entropy. Words of same order are concatenated in for each SLW to generate passphrase corpus. Randomly selected passphrases are read out and displayed on the user device by positioning the highest entropy based on usability of display screen in context of the user.
Owner:TATA CONSULTANCY SERVICES LTD

Systems and methods for verifying funds transfer

PendingUS20260050926A1Electronic credentialsPassphraseUser device
Disclosed embodiments may include a method for verifying funds transfer. The method may include receiving, from a first user device, a request to complete a transfer from a first account to a second account and generating a passphrase for authentication of the transfer. Next, the method may include transmitting, to the first user device, the passphrase for authentication of the transfer, receiving, from a second user device, a shared passphrase for authentication of the transfer, and determining whether the shared passphrase matches at least a portion of the passphrase. In response to determining that the shared passphrase matches at least a portion of the passphrase, the method may include transferring funds from the first account to the second account.
Owner:CAPITAL ONE SERVICES LLC

Controlling workload execution on trusted execution environments

InactiveGB2640873APlatform integrity maintainancePassphraseWorkload
A computer-implemented method whereby confidential computing control service CCCS 500 automatically controls an execution of workloads on trusted execution environments TEEs 510 while enforcing compliance with constraints required by entities 504. CCCS 500 may be on a server and TEEs may ne n a cloud. The method comprises: receiving constraints for the execution of a workload from the entities; automatically generating an execution requirement (e.g. a contract) for controlling the trusted execution environments using the received constraints, the requirement defining execution parameters of the workload in compliance with the constraints; the generating comprising adding identifiers of the constraints (e.g. checksums of the constraints) to the requirement for an attestation of the constraints being complied with by the trusted executing environments; controlling the trusted execution environments in compliance with the execution requirement, the environments being enabled to provide attestation records for the execution of the workload comprising the identifiers of the constraints. Execution requirements may relate to: sections of a document being encrypted independently; description of the environment to execute an application, e.g. logging, virtual machines; data volumes; seeds for deriving encryption passphrases; cryptographic keys. Constraints are checked for conflicts and detected conflicts are resolved. Each entity 506 relates to developing, managing and deploying services, e.g. KUBERNETES (RTM) K8s for orchestrating workloads in containers.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

System, method, and device for modifying network functionality based on provided passphrase

A method for modifying functionality within a wireless network based on an applied authentication asset is disclosed that includes: defining a first set of network policies and a second set of network policies associated with a first authentication asset and a second authentication asset, respectively, for the wireless network, the second authentication asset being different from the first authentication asset; determining if the applied authentication asset used by a client device while engaging in an authentication process with an authentication server to secure a network connection with the wireless network matches one of the first authentication asset and the second authentication asset; and providing the network connection defined at least in part by the first set or the second set of network policies if the applied authentication asset is the first authentication asset and the second authentication asset, respectively to the client device through a mutable network device.
Owner:SOUNDVISION TECHNOLOGIES LLC

Contactless identification and authentication of a person

A system (1) for identifying and authenticating a person upon entry to an event, comprising a physical terminal (3) at the entrance to the event, a networking unit (5), a computing unit (7), and one or more databases (9) in which at least one data record is stored and assigned to the person, wherein the data record comprises a desired type of authentication of the person selected in advance by the person and authentication information defined and stored in advance by the person in the desired type of authentication, wherein the type of authentication is a voice input, in particular a password or a passphrase, and / or a gesture and / or a facial expression of the person, wherein the physical terminal (3) is designed toto identify the person and, based on the identification, to submit a request to the networking unit (5) for linking the identified person to the data record assigned to the identified person, wherein the networking unit (5) does not store any personal data of the person, but only has a linking table with stored links between persons and an associated virtual address of a data record of a respective person and is designed to transmit at least the stored authentication information to the computing unit (7) by means of a corresponding request to the one or more databases (9) containing the data record associated with the identified person, wherein the physical terminal (3) is designed to sensorily detect an input from the person for authentication and to transmit it to the computing unit (7) in the form of detected authentication information,and wherein the computing unit (7) is designed to compare the acquired authentication information with the authentication information stored in the data record assigned to the identified person and, if the match is positive, to evaluate the identified person as authenticated.
Owner:DEUTSCHES ZENTRUM FÜR LUFT UND RAUMFAHRT E V

Systems and methods for an instant virtual access point

ActiveUS20250274756A1Security arrangementPassphraseStation
Systems and methods for providing instant secured network access for station devices. Multiple sets of SSIDs and passphrases construct different instant virtual access points (iVAPs) by utilizing a hidden virtual access point (VAP); where station devices can connect to the hidden VAP using different iVAP credentials, reducing the security risk as the unique access credentials allow the station devices to access the hidden VAP without other devices decrypting the data; where iVAPs can be created, deleted, and modified without changing the VAP configurations, without disconnections, and without system downtime; and where the iVAP solution includes using hidden SSIDs, sending decoy beacons and probe responses, an association process, and a 4-way handshake.
Owner:ALLIED TELESIS

Visitor management method, visitor inviting method and related equipment

The invention discloses a visitor management method, which belongs to the field of visitor management, and comprises the following steps: receiving visitor invitation information of a first class client; receiving a passing password of the visitor; performing verification processing on the pass password based on the visitor invitation information to obtain a verification result; and performing visitor management on the visitor based on the verification result. According to the method and the system, complex information registration is not needed, contact with the visitor is not needed, after the visitor invitation information and the passing password are received, the passing password can be verified, visitor management is performed on the visitor according to the verification result, and distribution service personnel can safely, effectively and quickly access the visitor.
Owner:SHENZHEN JIESHUN SCI & TECH IND

Protection and encryption of objects, metadata, and encryption keys

A computer implemented method for securely storing data on an object store, comprising: receiving a passphrase and an object at a computing device, wherein metadata is associated with the object; generating a first encryption key based on the passphrase; encrypting the metadata using a second encryption key; encrypting the object using a third encryption key; encrypting the third encryption key using the first encryption key; providing the encrypted object, the encrypted metadata, and the encrypted third encryption key to a processing device for storing in the object store.
Owner:TIGRIS DATA INC

Device-independent authentication based on a passphrase and a policy

An electronic device that selectively approves secure access of a second electronic device to a network is described. This electronic device receives an access request associated with a computer, where the access request includes passphrase parameters associated with a user, and the passphrase parameters include inputs to and an output of a cryptographic calculation. In response, the electronic device calculates one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases. Moreover, when there is a match between one of the one or more second outputs and the output, the electronic device accesses a policy associated with the user. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message to the computer, which includes information for establishing the secure access of the second electronic device.
Owner:RUCKUS IP HOLDINGS LLC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

Communication apparatus, method of controlling communication apparatus, and non-transitory computer-readable storage medium

A communication apparatus accepts an input of a passphrase by a user operation, sets an authentication scheme based on a passphrase length of the passphrase, and performs wireless connection with a partner apparatus using the set authentication scheme, wherein (i) in a case where the passphrase length is within a predetermined range, an authentication scheme of any of WPA (Wi-Fi Protected Access), WPA2, and WPA3, or a combination of at least two of WPA, WPA2, or WPA3, is set, and (ii) otherwise, an authentication scheme of WPA3 is set.
Owner:CANON KK

Automatic periodic pre-shared key update

ActiveUS12418530B2Securing communicationPassphraseEngineering
During operation, the computer may obtain an access acceptance message, where the access acceptance message indicates that the electronic device has been authenticated and allowed to securely access a network, and where the authentication is based at least in part on a passphrase associated with a user of an electronic device. For example, the computer may receive the acceptance message from the computer network device or a second computer (such as a controller). Alternatively, the computer may obtain the access acceptance message while performing the authentication. Then, the computer may automatically provide a second passphrase addressed to a computer network device and the electronic device, where the second passphrase replaces the passphrase during a current session of the electronic device in the network. Moreover, when the current session ends, the computer may automatically revert to the passphrase for subsequent authentication of the user.
Owner:RUCKUS IP HOLDINGS LLC

User or device authorization element in 4-way handshake

The present disclosure provides techniques for device authorization using a per-device identifier. A network device authenticates a client device using simultaneous authentication of equals (SAE) with a shared passphrase. After completing association, the network device sends a first message to the client device, comprising an access point (AP)-generated random value to the client device. The network device receives a second message from the client device, comprising a station (STA)-generated random value and an authorization identifier. The network device decrypts the authorization identifier using a session key. In response to determining that the authorization identifier matches an entry in the authorization database, the network device sends a third message confirming authorization of the client device as a trusted entity. The network device receives a fourth message confirming completion of a security key exchange.
Owner:CISCO TECHNOLOGY INC

Initiating SoftAp mode provisioning of WiFi device via custom data field

One or more examples relate to a method, which includes sending, from a provisioner WiFi device to a provisionee WiFi device in an idle mode, a probe request frame including a random data in a custom data field; powering up the provisionee WiFi device in a SoftAp mode at least partially responsive to receiving the probe request frame; sending, from the provisioner WiFi device to the provisionee WiFi device in the SoftAp mode, a further probe request frame including the random data in a custom data field; sending, from the provisionee WiFi device in the SoftAp mode to the provisioner WiFi device, a probe response frame; establishing a secure WiFi connection between the provisioner WiFi device and the provisionee WiFi device utilizing passphrases respectively generated by the provisioner WiFi device and the provisionee WiFi device; and sending provisioning data, from the provisioner WiFi device to the provisionee WiFi device in SoftAp mode, via the secure WiFi connection.
Owner:MICROCHIP TECHNOLOGY INC

Get key bot for securely maintaining and providing passphrases

Techniques are provided for a get key bot that securely provides access to passphrases. A set key workflow is executed to generate a get key executable binary that is implemented as the get key bot. The get key executable binary is encapsulated with encrypted information that includes a verified user identifier, a passphrase, and / or a bot expiry time. Upon receiving a request for the passphrase from a requestor, the get key executable binary is invoked. The encrypted information is decrypted and compared to a logged-in user identifier and current time for verification. In response to successful verification, the passphrase is provided to the requestor. Otherwise, the requestor is denied access to the passphrase.
Owner:NETAPP INC

system

PendingJP2026070122ASpeech recognitionDigital dataPassphrase
We provide the system. [Solution] A means of receiving voice input from a communication terminal available to the user and converting it into digital data, A means for analyzing the digital data and converting it into text data, A means for analyzing the text data using natural language processing to identify the user's intent, A means of authenticating a user using voice pattern recognition and a passphrase, A means to prevent duplicate actions by referring to the user's past action history, A means of detecting fraud risks and issuing warnings to users and their associates, A system that includes this.
Owner:SOFTBANK GROUP CORP

Get key bot for securely maintaining and providing passphrases

Techniques are provided for a get key bot that securely provides access to passphrases. A set key workflow is executed to generate a get key executable binary that is implemented as the get key bot. The get key executable binary is encapsulated with encrypted information that includes a verified user identifier, a passphrase, and / or a bot expiry time. Upon receiving a request for the passphrase from a requestor, the get key executable binary is invoked. The encrypted information is decrypted and compared to a logged-in user identifier and current time for verification. In response to successful verification, the passphrase is provided to the requestor. Otherwise, the requestor is denied access to the passphrase.
Owner:NETAPP INC

Methods and systems for user authentication

A user device, such as a smartphone or laptop, may be password (passphrase) protected. The user device may combine biometric input analysis, such as facial recognition, with viseme analysis to authenticate a user attempting to use a password (passphrase) to access the user device. Secure authentication methods and systems are described that account for variations in how, based on the user's emotion (e.g., mood, temperament, unique pronunciation, etc. . . . ), a password (passphrase) may be presented to the user device.
Owner:COMCAST CABLE COMM LLC

Method and system for detecting passphrases in plain text

Nowadays, platforms are advocating use of passphrases with aim to provide more secure yet memorable form of authentication as passphrase offer ease of remembering, and improved adaptability to password policies without compromising usability. Existing password detection methods fail to detect passphrases due to distinct nature of passphrases, as it involves use of multiple words, symbols, numbers, and special characters. Present disclosure provides method and system for detecting passphrases in plain text. The system first receives plurality of files. Then, system filters files based on file attributes to obtain potential files. Thereafter, sensitivity analysis of potential file is performed based on sensitivity indicators to obtain sensitivity score for potential file. Further, system generates set of context from text present in each potential file. Finally, system utilizes set of context and sensitivity score of potential file to identify set of potential passphrases present in text using pre-trained machine learning based language model.
Owner:TATA CONSULTANCY SERVICES LTD

Multi-component article with cross-component deterministic values and underlying value protection

A physical multi-component article with cross-component deterministic values and underlying value protection (in some cases without any on-board source of power or computing capabilities) is configured to maintain access information for a digital wallet on a decentralized computing platform, like a blockchain-based decentralized computing platform. Private access information, like private key ciphertext and key or passphrase by which the private key ciphertext may be converted to plaintext, are physically concealed with tamper-evident components such that a user can readily determine by visual inspection of the apparatus whether, and what, private access information was divulged. In some examples, a user is required to activate one or more tamper-evident features, thereby altering a visible state of the apparatus, to access certain functions of a digital wallet corresponding to the apparatus.
Owner:BALLET GLOBAL INC

User or device authorization element in 4-way handshake

PCT designated stageWO2026055506A1Security arrangementSecuring communicationKey exchangePassphrase
The present disclosure provides techniques for device authorization using a per-device identifier. A network device authenticates a client device using simultaneous authentication of equals (SAE) with a shared passphrase. After completing association, the network device sends a first message to the client device, comprising an access point (AP)-generated random value to the client device. The network device receives a second message from the client device, comprising a station (STA)-generated random value and an authorization identifier. The network device decrypts the authorization identifier using a session key. In response to determining that the authorization identifier matches an entry in the authorization database, the network device sends a third message confirming authorization of the client device as a trusted entity. The network device receives a fourth message confirming completion of a security key exchange.
Owner:CISCO TECHNOLOGY INC

An encryption method and system for Ceph block storage based on quantum key

The present application provides an encryption method and system for national secret Ceph block storage based on quantum keys, belonging to the field of storage technology. The present application provides Ceph RBD clients with data encryption-related operation functions based on quantum random number cryptography by setting up a passphrase management system, thereby applying quantum security technology to Ceph's encrypted storage, which can ensure the long-term security of stored data; and adopts an architecture in which the Ceph RBD client and the passphrase management system are deployed separately, which can increase the control capability of data leakage risks and reduce maintenance costs.
Owner:中电信量子信息科技集团有限公司

Authentication using a conversational user interface

A one-time passphrase is transmitted from an authentication system to a personal communication device of a user. The one-time passphrase includes common but incongruous words. The user is prompted to verbalize the one-time passphrase to a processor-implemented, conversational user interface. Utterances from the user are received by a conversational user interface, and the utterances are communicated from the conversational user interface to the authentication system via a trusted communication channel. The authentication system determines, using speech recognition, presence or non-presence of the one-time passphrase within the received utterances. The authentication system authenticates the user in response to detecting presence of the one-time passphrase within the received utterances.
Owner:GENESEE VALLEY INNOVATIONS LLC