Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

29 results about "Passphrase" patented technology

A passphrase is a sequence of words or other text used to control access to a computer system, program or data. A passphrase is similar to a password in usage, but is generally longer for added security. Passphrases are often used to control both access to, and operation of, cryptographic programs and systems, especially those that derive an encryption key from a passphrase. The origin of the term is by analogy with password. The modern concept of passphrases is believed to have been invented by Sigmund N. Porter in 1982.

Wi-fi protected access 3-compatible authentication using an established binding

In response to an association request associated with an electronic device to a second WLAN that uses a WPA3-compatible authentication protocol, an access point may establish a connection with an electronic device using the second WLAN when a binding between a passphrase associated with the electronic device and the second WLAN exists in a computer system. Alternatively, when the binding does not exist, the access point may reject the association request. Instead, the access point may establish a second connection with the electronic device using a first WLAN that uses a WPA2-compatible authentication protocol, and may establish the binding in a computer system. Next, the access point may perform a BSS transition of the electronic device from the first WLAN to the second WLAN. Furthermore, the access point may perform authentication of the electronic device after the connection or the second connection is established.
Owner:RUCKUS IP HOLDINGS LLC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

Generating usable high entropy passphrases in local language from personalized intersection corpus

PendingUS20250335572A1Semantic analysisDigital data authenticationLocal languagePassphrase
There are technical challenges to address the technical capability limitations of a Basic Emergent User (BEU) to enable and assist in generating high entropy passphrases but are easier for recall. Generation usable high entropy passphrases in local language from personalized intersection corpus for device authentication set up for BEU is provided. A recallable phrase, spoken by the BEU in local language, is converted to a text and Seed List Words (SLWs) are filtered based on a pre-generated personalized intersection corpus. Passphrase distance matrix is generated for the SLWs using the personalized intersection corpus. Words associated with each SLW are arranged in descending order of vector distance or entropy. Words of same order are concatenated in for each SLW to generate passphrase corpus. Randomly selected passphrases are read out and displayed on the user device by positioning the highest entropy based on usability of display screen in context of the user.
Owner:TATA CONSULTANCY SERVICES LTD

Systems and methods for verifying funds transfer

PendingUS20260050926A1Electronic credentialsPassphraseUser device
Disclosed embodiments may include a method for verifying funds transfer. The method may include receiving, from a first user device, a request to complete a transfer from a first account to a second account and generating a passphrase for authentication of the transfer. Next, the method may include transmitting, to the first user device, the passphrase for authentication of the transfer, receiving, from a second user device, a shared passphrase for authentication of the transfer, and determining whether the shared passphrase matches at least a portion of the passphrase. In response to determining that the shared passphrase matches at least a portion of the passphrase, the method may include transferring funds from the first account to the second account.
Owner:CAPITAL ONE SERVICES LLC

Controlling workload execution on trusted execution environments

InactiveGB2640873APlatform integrity maintainancePassphraseWorkload
A computer-implemented method whereby confidential computing control service CCCS 500 automatically controls an execution of workloads on trusted execution environments TEEs 510 while enforcing compliance with constraints required by entities 504. CCCS 500 may be on a server and TEEs may ne n a cloud. The method comprises: receiving constraints for the execution of a workload from the entities; automatically generating an execution requirement (e.g. a contract) for controlling the trusted execution environments using the received constraints, the requirement defining execution parameters of the workload in compliance with the constraints; the generating comprising adding identifiers of the constraints (e.g. checksums of the constraints) to the requirement for an attestation of the constraints being complied with by the trusted executing environments; controlling the trusted execution environments in compliance with the execution requirement, the environments being enabled to provide attestation records for the execution of the workload comprising the identifiers of the constraints. Execution requirements may relate to: sections of a document being encrypted independently; description of the environment to execute an application, e.g. logging, virtual machines; data volumes; seeds for deriving encryption passphrases; cryptographic keys. Constraints are checked for conflicts and detected conflicts are resolved. Each entity 506 relates to developing, managing and deploying services, e.g. KUBERNETES (RTM) K8s for orchestrating workloads in containers.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Protection and encryption of objects, metadata, and encryption keys

A computer implemented method for securely storing data on an object store, comprising: receiving a passphrase and an object at a computing device, wherein metadata is associated with the object; generating a first encryption key based on the passphrase; encrypting the metadata using a second encryption key; encrypting the object using a third encryption key; encrypting the third encryption key using the first encryption key; providing the encrypted object, the encrypted metadata, and the encrypted third encryption key to a processing device for storing in the object store.
Owner:TIGRIS DATA INC

Device-independent authentication based on a passphrase and a policy

An electronic device that selectively approves secure access of a second electronic device to a network is described. This electronic device receives an access request associated with a computer, where the access request includes passphrase parameters associated with a user, and the passphrase parameters include inputs to and an output of a cryptographic calculation. In response, the electronic device calculates one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases. Moreover, when there is a match between one of the one or more second outputs and the output, the electronic device accesses a policy associated with the user. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message to the computer, which includes information for establishing the secure access of the second electronic device.
Owner:RUCKUS IP HOLDINGS LLC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

User or device authorization element in 4-way handshake

The present disclosure provides techniques for device authorization using a per-device identifier. A network device authenticates a client device using simultaneous authentication of equals (SAE) with a shared passphrase. After completing association, the network device sends a first message to the client device, comprising an access point (AP)-generated random value to the client device. The network device receives a second message from the client device, comprising a station (STA)-generated random value and an authorization identifier. The network device decrypts the authorization identifier using a session key. In response to determining that the authorization identifier matches an entry in the authorization database, the network device sends a third message confirming authorization of the client device as a trusted entity. The network device receives a fourth message confirming completion of a security key exchange.
Owner:CISCO TECHNOLOGY INC

Initiating SoftAp mode provisioning of WiFi device via custom data field

One or more examples relate to a method, which includes sending, from a provisioner WiFi device to a provisionee WiFi device in an idle mode, a probe request frame including a random data in a custom data field; powering up the provisionee WiFi device in a SoftAp mode at least partially responsive to receiving the probe request frame; sending, from the provisioner WiFi device to the provisionee WiFi device in the SoftAp mode, a further probe request frame including the random data in a custom data field; sending, from the provisionee WiFi device in the SoftAp mode to the provisioner WiFi device, a probe response frame; establishing a secure WiFi connection between the provisioner WiFi device and the provisionee WiFi device utilizing passphrases respectively generated by the provisioner WiFi device and the provisionee WiFi device; and sending provisioning data, from the provisioner WiFi device to the provisionee WiFi device in SoftAp mode, via the secure WiFi connection.
Owner:MICROCHIP TECHNOLOGY INC

Get key bot for securely maintaining and providing passphrases

Techniques are provided for a get key bot that securely provides access to passphrases. A set key workflow is executed to generate a get key executable binary that is implemented as the get key bot. The get key executable binary is encapsulated with encrypted information that includes a verified user identifier, a passphrase, and / or a bot expiry time. Upon receiving a request for the passphrase from a requestor, the get key executable binary is invoked. The encrypted information is decrypted and compared to a logged-in user identifier and current time for verification. In response to successful verification, the passphrase is provided to the requestor. Otherwise, the requestor is denied access to the passphrase.
Owner:NETAPP INC

system

PendingJP2026070122ASpeech recognitionDigital dataPassphrase
We provide the system. [Solution] A means of receiving voice input from a communication terminal available to the user and converting it into digital data, A means for analyzing the digital data and converting it into text data, A means for analyzing the text data using natural language processing to identify the user's intent, A means of authenticating a user using voice pattern recognition and a passphrase, A means to prevent duplicate actions by referring to the user's past action history, A means of detecting fraud risks and issuing warnings to users and their associates, A system that includes this.
Owner:SOFTBANK GROUP CORP

Get key bot for securely maintaining and providing passphrases

Techniques are provided for a get key bot that securely provides access to passphrases. A set key workflow is executed to generate a get key executable binary that is implemented as the get key bot. The get key executable binary is encapsulated with encrypted information that includes a verified user identifier, a passphrase, and / or a bot expiry time. Upon receiving a request for the passphrase from a requestor, the get key executable binary is invoked. The encrypted information is decrypted and compared to a logged-in user identifier and current time for verification. In response to successful verification, the passphrase is provided to the requestor. Otherwise, the requestor is denied access to the passphrase.
Owner:NETAPP INC

Method and system for detecting passphrases in plain text

Nowadays, platforms are advocating use of passphrases with aim to provide more secure yet memorable form of authentication as passphrase offer ease of remembering, and improved adaptability to password policies without compromising usability. Existing password detection methods fail to detect passphrases due to distinct nature of passphrases, as it involves use of multiple words, symbols, numbers, and special characters. Present disclosure provides method and system for detecting passphrases in plain text. The system first receives plurality of files. Then, system filters files based on file attributes to obtain potential files. Thereafter, sensitivity analysis of potential file is performed based on sensitivity indicators to obtain sensitivity score for potential file. Further, system generates set of context from text present in each potential file. Finally, system utilizes set of context and sensitivity score of potential file to identify set of potential passphrases present in text using pre-trained machine learning based language model.
Owner:TATA CONSULTANCY SERVICES LTD

User or device authorization element in 4-way handshake

PCT designated stageWO2026055506A1Security arrangementSecuring communicationKey exchangePassphrase
The present disclosure provides techniques for device authorization using a per-device identifier. A network device authenticates a client device using simultaneous authentication of equals (SAE) with a shared passphrase. After completing association, the network device sends a first message to the client device, comprising an access point (AP)-generated random value to the client device. The network device receives a second message from the client device, comprising a station (STA)-generated random value and an authorization identifier. The network device decrypts the authorization identifier using a session key. In response to determining that the authorization identifier matches an entry in the authorization database, the network device sends a third message confirming authorization of the client device as a trusted entity. The network device receives a fourth message confirming completion of a security key exchange.
Owner:CISCO TECHNOLOGY INC

Authentication using a conversational user interface

A one-time passphrase is transmitted from an authentication system to a personal communication device of a user. The one-time passphrase includes common but incongruous words. The user is prompted to verbalize the one-time passphrase to a processor-implemented, conversational user interface. Utterances from the user are received by a conversational user interface, and the utterances are communicated from the conversational user interface to the authentication system via a trusted communication channel. The authentication system determines, using speech recognition, presence or non-presence of the one-time passphrase within the received utterances. The authentication system authenticates the user in response to detecting presence of the one-time passphrase within the received utterances.
Owner:GENESEE VALLEY INNOVATIONS LLC

End to end encryption with roaming capabilities

Systems and methods relating to end to end encryption. Encrypted data stored on a server or transmitted by way of a server can be accessed from any number of authenticated client devices by storing an encrypted private key on the server. The encrypted data can only be decrypted by the decrypted version of the encrypted private key. The encrypted private key is undecryptable by the server and can only be decrypted using user provided credentials (e.g. a user provided password / passphrase). For the user to access the encrypted data, the client device used by the user downloads the encrypted private key along with the encrypted data. The encrypted private key is then decrypted using user provided credentials and the decrypted private key is used to decrypt the downloaded encrypted data. The decrypted private key never leaves the client device and is never used by the server.
Owner:ENCSTOCOM LLC

Access-point passphrase identification using key matching

PendingUS20260052020A1User identity/authority verificationPassphraseEngineering
A computer network device that performs key matching is described. While attempting to establish a secure connection with an electronic device, the computer network device may receive a connection-request message associated with the electronic device. In response, the computer network device may provide a context message addressed to a computer, where the context message requests stored passphrase information associated with the electronic device. Then, the computer network device may receive, associated with the computer, a context response. When the context response indicates that there is no stored passphrase information associated with the electronic device, the computer network device may perform the key matching to identify the passphrase associated with the electronic device. Next, the computer network device may provide, addressed to the computer, the identified passphrase associated with the electronic device or an encryption key corresponding to the identified passphrase for storage by the computer.
Owner:RUCKUS IP HOLDINGS LLC

Using a passphrase with Wi-Fi protected access 3

ActiveUS12532174B2Network topologiesTransmissionPassphraseEngineering
During operation, an access point may provide a first WLAN and a second WLAN, where the first WLAN uses a WPA2-compatible authentication protocol and the second WLAN uses a WPA3-compatible authentication protocol. In response to an association request or a probe request associated with (or from) an electronic device, the access point may establish a connection with the electronic device using the first WLAN. Then, the access point may confirm, with a computer system, that a binding between a passphrase associated with the electronic device and the second WLAN exists. Alternatively, when the binding does not exist, the access point may establish the binding in the computer system. Next, the access point may perform a BSS transition of the electronic device from the first WLAN to the second WLAN.
Owner:RUCKUS IP HOLDINGS LLC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

Methods and systems for training a machine learning model and authenticating a user with the model

A method of training a machine learning model to conduct authentication transactions is provided that includes the steps of obtaining, by an electronic device, a training dataset of audio signals. Each audio signal includes voice biometric data of a user and information for a passphrase spoken by the respective user and belongs to a same or different data class. Each data class includes a user identity and a passphrase identifier. Moreover, the method includes the steps of creating, using a machine learning model being trained, at least one embedding for each audio signal. The machine learning model includes parameters. Furthermore, the method includes calculating, by a machine learning algorithm using the embeddings, a loss, and updating parameters of the machine learning model based on the calculated loss. In response to determining criteria defining an end of training have been satisfied, deeming the machine learning model to be operable for use in simultaneously successfully verifying the identity of a user based on voice biometric data and verifying a passphrase spoken by the user matches a secret passphrase during authentication transactions.
Owner:DAON TECH

Systems and methods for an instant virtual access point

ActiveUS12671992B2PassphraseStation
Systems and methods for providing instant secured network access for station devices. Multiple sets of SSIDs and passphrases construct different instant virtual access points (iVAPs) by utilizing a hidden virtual access point (VAP); where station devices can connect to the hidden VAP using different iVAP credentials, reducing the security risk as the unique access credentials allow the station devices to access the hidden VAP without other devices decrypting the data; where iVAPs can be created, deleted, and modified without changing the VAP configurations, without disconnections, and without system downtime; and where the iVAP solution includes using hidden SSIDs, sending decoy beacons and probe responses, an association process, and a 4-way handshake.
Owner:ALLIED TELESIS

Secure decentralized social media communication system

PendingUS20250379843A1Securing communicationPassphraseSocial media
Provided is a method including nominating a prospective peer for addition to a group of peers communicating via a peer to peer communications system (P2PCS). The nominating includes an active peer within the group sending to the prospective peer, via the P2PCS, a nomination request using email as a primary transport mechanism. The nomination request includes an encrypted payload including instructions and the encryption is performed (i) via the P2PCS and (ii) responsive to a prearranged passphrase.
Owner:KINGDOM PARTNERS LLC

Computing systems and methods for facilitating engagement via direct mail

A computing platform is configured to: (i) obtain a pool of available words for use in generating four-word passphrases, (ii) generate a candidate batch of four-word passphrases using the pool of available words, (iii) identify one or more duplicate four-word passphrases in the candidate batch and then filter the identified one or more duplicate four-word passphrases out of the candidate set; (iv) based on the filtered candidate batch of four-word passphrases, generate a new batch of four-word passphrases for use on direct mail; and (v) release the new batch of four-word passphrases for use on direct mail.
Owner:CAPITAL ONE FINANCIAL CORP

Access-point passphrase identification using key matching

A computer network device that performs key matching is described. While attempting to establish a secure connection with an electronic device, the computer network device may receive a connection-request message associated with the electronic device. In response, the computer network device may provide a context message addressed to a computer, where the context message requests stored passphrase information associated with the electronic device. Then, the computer network device may receive, associated with the computer, a context response. When the context response indicates that there is no stored passphrase information associated with the electronic device, the computer network device may perform the key matching to identify the passphrase associated with the electronic device. Next, the computer network device may provide, addressed to the computer, the identified passphrase associated with the electronic device or an encryption key corresponding to the identified passphrase for storage by the computer.
Owner:RUCKUS IP HOLDINGS LLC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

A method and system for implementing a secure and easy-to-use file vault based on eCryptfs

ActiveCN119227103BDigital data protectionPassphrasePassword
This application discloses a secure and easy-to-use file vault implementation method and system based on eCryptfs. The user inputs a first string as the input password (bPassword); a random password (ePassword) is generated, which is used for encrypting or decrypting files using eCryptfs; ePassword and bPassword are concatenated to form "ePassword+bPassword"; bPassword is used as a key to encrypt "ePassword+bPassword" and stored in a database; and a random passphrase is generated and used as a key to encrypt bPassword and stored in the database. In this application, passwords and passphrases are controlled in the form of keys, and plaintext passwords and keys are not stored in the database, ensuring security.
Owner:HUNAN KYLIN XINAN TECH CO LTD