Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

60 results about "Security token" patented technology

A security token is a physical device used to gain access to an electronically restricted resource. The token is used in addition to or in place of a password. It acts like an electronic key to access something. Examples include a wireless keycard opening a locked door, or in the case of a customer trying to access their bank account online, the use of a bank-provided token can prove that the customer is who they claim to be.

Attestable deepfake detection and / or prevention

Implementations are described herein for detecting deepfakes in digital media while preserving the privacy of the source computing device. In various implementations, sensor fingerprints and / or security tokens that signal software-introduced alterations, e.g., introduced by hardware abstraction layers (HALs) or virtual machines (VMs) may be utilized to detect such deepfakes. These signals may be used, separately and / or in combination, for various purposes, such as flagging digital content to a user as being a deepfake, preventing or blocking receipt and / or playback of digital content deemed to be a deepfake, allowing an end user to disable aspect(s) (e.g., layers) of digital content that are determined to be synthetic, etc.
Owner:GDM HOLDING LLC

Safety management

There are proposed methods, devices, and computer program products for safety management. In the method, in response to receiving a first query to a machine learning model, a first response to the first query is obtained by the machine learning model, the first query being represented in a natural language, and the machine learning model being a language model. A second query is determined based on the first query, the first response and a safety token, the safety token triggering a safety check on the second query. A second response to the second query is obtained by the machine learning model based a check result of the safety check.
Owner:BYTEDANCE TECHNOLOGY LTD

Federal learning privacy protection method for dynamic search hybrid encryption and contribution value perception

The invention relates to the technical field of federated learning and privacy protection, and discloses a federated learning privacy protection method for dynamic search hybrid encryption and contribution value perception, which mainly comprises the following steps of: constructing a privacy protection scheme of a local evaluation and hybrid encryption mechanism combined with contribution degree perception to realize differentiated privacy protection of client privacy data; the calculation time overhead and the communication overhead based on a single homomorphic encryption privacy mechanism are effectively reduced; a central storage server access control and dynamic key rotation mechanism driven by a security token is constructed, and key non-replay and historical data non-revealing are realized by combining a searchable relevance trap door index stored by a ciphertext; according to the method, on the basis of a security aggregation algorithm of contribution perception, the contribution value of each local model in a ciphertext state is evaluated by a joint secrecy calculation protocol, aggregation screening of a global model under the condition that the contribution value plaintext is not revealed is ensured, power dispersion of a central storage server is completed, and the overall efficiency and privacy of the system are remarkably improved.
Owner:KUNMING UNIV OF SCI & TECH

Secure token exchange for automated systems

Secure token exchange for automated systems includes receiving, for validation, an application programming interface (API) token grant request, including an API key, sent by an automated system, and retrieving, from a database, an API key entity corresponding to the API key, wherein the API key entity includes a token receive endpoint. An authentication token is generated. The authentication token is asynchronously pushed to the token receive endpoint for access by the automated system.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

Secure token exchange and controls and interfaces therefor

Methods, systems, and computer program products provide direct and in-network provisioning of tokens. A secure token exchange (STE) processor receives a direct token request from a token requestor prior to sending a payment transaction message or request for payment message. In-network token provisioning is performed during a transaction and also involves the STE processor. Data aggregation security is provided by verifying consumer information, tokenizing account data, and forwarding a token and consumer data to a data aggregator.
Owner:CLEARING HOUSE PAYMENTS CO LLC

Intelligent access control system

A method, by an intelligent access control system, of implementing access control to a controlled area having a plurality access areas divided by at least one access point includes the following operations. A security token is generated. The security token is transmitted to a client module executing on a client device associated with a first user, and the client module is caused to pair with an access control device associated with the first user. The client module is caused to transfer the security token to the access control device. A physical location of the client device within the controlled area is monitored. A determination is made, by an access control system and based upon the physical location, that the first user is to be revalidated. The client module causes, based upon the determining, the client device to generate an alert.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method and apparatus for performing client credential assertion in wireless communication system

The present disclosure relates to a 5th-Generation (5G) communication system or a 6th-Generation (6G) communication system for supporting higher data rates beyond a 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure provides techniques for performing authentication and authorization based on client credential assertion in a wireless communication system. A method performed by a network entity for performing client credential assertion (CCA)-based authentication and authorization of the network entity is provided. In one embodiment, a method includes sending, by a network entity, a first service request to a network repository function (NRF), where sending of the first service request includes encrypting, by the network entity, a CCA token using a Key Encapsulation Mechanism (KEM), where the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, where the KEM is based on the PQC mechanism. The encrypted CCA token is signed by the network entity using a digital signature to generate a quantum-secure CCA token, where the quantum-secure CCA token is a digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-secure CCA token to the NRF along with the first service request, where the quantum-secure CCA token is the digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism. And receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD

Method of determining collateral ratio for liquidity risk management of security token operating investment products, computing device for performing the same, and recording medium

Disclosed are a method, device, and recording medium for determining a collateral ratio for liquidity risk management of a security token offering (STO) investment product. The method of determining a collateral ratio for liquidity risk management of STO investment product according to various embodiments of the present disclosure includes collecting data related to an STO investment product; determining an asset liquidity risk of the investment product based on the collected data; and determining the collateral ratio for the investment product based on the determined asset liquidity risk.
Owner:ONECUP CO LTD

Secure token exchange for automated systems

Secure token exchange for automated systems includes receiving, for validation, an application programming interface (API) token grant request, including an API key, sent by an automated system, and retrieving, from a database, an API key entity corresponding to the API key, wherein the API key entity includes a token receive endpoint. An authentication token is generated. The authentication token is asynchronously pushed to the token receive endpoint for access by the automated system.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Token-based secure database query result sharing

Techniques for sharing query results in a multi-tenant database system are described. The query results can be shared between users of the same account or organization in the multi-tenant network-based database system using security tokens. A first user executes a query, and the results are stored in the network-based database system. The first user can invoke a function to create a security token to provide access to the stored query results to other users in the same account. The first user can share the security token with the other users, who can directly access the stored results in the network-based database system instead of having to download local copies of the query results.
Owner:SNOWFLAKE INC

Method and systems for blocking multi-rail contactless fraud

A system and method for performing a transaction at a software-based POS system of a merchant includes receiving, from the software-based POS system, a payment authorization request message. A processor is programmed to extract a dynamic hashed security token from the payment authorization request message. In addition, the processor is programmed to validate the dynamic hashed security token and, upon validating the dynamic hashed security token, determine that the software-based POS system that transmitted the payment authorization request message is running a mobile POS software application. Furthermore, the processor is programed to extract the hardware identifier and the application identifier from the transaction data and compare them to account registration information stored with a merchant account. The processor then determines that the hardware identifier and the application identifier match with the account registration information and transmits the payment authorization request message to an issuer associated with the transaction card details.
Owner:MASTERCARD INT INC

Cloud service access permission setting method for enclave instance and cloud management platform

A cloud management platform provides an identity and access management (IAM) service and a security token service (STS). The IAM service is used to confirm an enclave instance type input or selected by a first tenant and a conversion rule input or selected by the first tenant. The conversion rule is used to convert, into a tenant-customized attribute, an enclave instance attestation document provided by an enclave instance corresponding to the enclave instance type. The STS is used to receive a token obtaining request sent by an application program in the enclave instance.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

System and method for authentication control for content delivery

The present disclosure provides systems and methods for authentication control of content delivery. The method includes receiving a request for a content item from a computing device, the request including a security token associated with the computing device and an identifier of a domain group, identifying the domain group from the identifier, and retrieving a security key associated with the domain group. The method also includes decrypting a signature of the security token, identifying an authentication string, determining that the authentication string matches a server authentication string, and identifying a characteristic of the security token. The characteristic of the security token includes a confidence score. The method further includes comparing the confidence score of the security token to a threshold, determining that the confidence score does not exceed the threshold, and preventing the content from being sent to the computing device.
Owner:GOOGLE LLC

Methods and systems for hands-free fare validation and gateless transit

A system and method in which a user application on a mobile device facilitates hands-free fare validation and gateless entry / exit at a transit facility like a transit station or a transit vehicle. The user application communicates with a Bluetooth gateway to authenticate the device and provides device-specific information for device identification and location determination. The user application also sends a secure token to the gateway to validate an electronic ticket stored in the device. A positioning unit uses the device-specific information to generate a timestamped location data for the device. A camera monitors the device user's movement and generates another timestamped location data for the device. A controller driver compares two timestamped location data to determine that the user of the device is approaching a gateless entry point and allows the user to avail a transit service through the gateless entry point when the electronic ticket is valid and active.
Owner:SIEMENS MOBILITY INC

Security interceptor for generative artificial intelligence platforms

A method of protecting a generative artificial intelligence (AI) platform can include receiving, at a security interceptor, a plurality of communications from the generative AI platform to one or more sources over a network, wherein each communication of the plurality of communications comprises a source-specific safe-for-AI token (SFAI token) associated with a particular source of the one or more sources appended thereto; checking, by the security interceptor, a safety level of each source-specific SFAI token received with the plurality of communications; for each source-specific SFAI token having a safety level indicating a permitted source, permitting a corresponding communication comprising that source-specific SFAI token to be transmitted to the particular source associated therewith; and for any communication of the plurality of communications comprising a corresponding source-specific SFAI token having a safety level indicating a proscribed source, blocking that communication to be transmitted to the particular source associated therewith.
Owner:MASTERCARD INT INC

5g secure token enrollment using slicing capabilities

The present invention relates to a computer-implemented method for providing secure token enrolment, the method comprising receiving over a communication network (104), at a network selector server (110) associated with a payment network (108), a first token enrolment request message from a user device (102), determining, at the network selector (server 110), a feature of the communication network (104), sending a request message, from the network selector server (110) to the user device (102), based on the determined feature of the communication network (104), instructing the user device (102) to connect to a 5G network slice (106a-c) associated with a 5G Network (106), receiving over the 5G network slice (106a-c), at the network selector server (110), a second token enrolment request message from the user device (102), determining, at the network selector server (110), a feature of the 5G network slice (106a-c), determining, at the network selector server (110), based on the determined feature of the 5G network slice (106a-c), whether to approve the second token enrolment request message.
Owner:MASTERCARD INT INC

Dynamic search hybrid encryption and contribution value-aware federated learning privacy protection method

ActiveCN121581116BPlaintextCiphertext
The application relates to the technical field of federated learning and privacy protection, and discloses a dynamic search hybrid encryption and contribution value perception federated learning privacy protection method, which mainly comprises the following steps: constructing a privacy protection scheme combining a contribution degree perception local evaluation and a hybrid encryption mechanism, realizing differentiated privacy protection of client privacy data, effectively reducing the calculation time cost and communication cost based on a single homomorphic encryption privacy mechanism; constructing a security token driven center storage server access control and dynamic key rotation mechanism, and combining a searchable relevance trapdoor index of ciphertext storage, realizing key non-replayability and historical data non-revealability; and the method is based on a contribution perception security aggregation algorithm, a joint secret computation protocol is used to evaluate contribution values of each local model in a ciphertext state, contribution value plaintext is not revealed, aggregation screening of a global model is ensured, power dispersion of a center storage server is completed, and the overall efficiency and privacy of the system are significantly improved.
Owner:KUNMING UNIV OF SCI & TECH

Data processing method and device based on Internet of Vehicles, electronic equipment and storage medium

The invention provides a data processing method and device based on the Internet of Vehicles, electronic equipment and a storage medium, and the method comprises the steps: obtaining vehicle behavior data corresponding to a vehicle-mounted terminal, and calculating a risk score of the vehicle-mounted terminal according to the vehicle behavior data; determining a session key and a security policy according to the risk score, and generating a dynamic security token containing the session key and the security policy; and the dynamic security token is sent to the vehicle-mounted terminal, so that after the vehicle-mounted terminal verifies the dynamic security token, the original data content is encrypted and transmitted based on the session key and the security policy. According to the mode, a guarantee is provided for establishing low-delay and high-reliability Internet of Vehicles communication.
Owner:CHINA UNICOM SMART CONNECTION TECH LTD

Resource access management and secure authorization systems and methods

Systems and methods for secure user authentication are described. In certain embodiments, a client device such as a smartphone may be provisioned with a secure key and / or other secret information. The client device may be used to generate unique secure tokens and / or other credentials used in connection with an authentication process. A user may provide the generated tokens and / or other credentials to a service provider in connection with a request to access a managed service. The validity of the generated tokens and / or other credentials may be verified by an authentication service in communication with the service provider.
Owner:INTERTRUST TECH CORP

Mcp protocol-based ai semantic model and robot interconnection method, system and medium

This invention provides a method, system, and medium for AI semantic model and robot interconnection based on the MCP protocol. It receives natural language instructions and generates structured operation sequences through a semantic parsing model; extracts semantic tags from the sequences and dynamically matches them with a service engine to generate operation requests containing tool identifiers and parameter templates; verifies operation permissions based on a security token, triggering secondary authorization if unauthorized access is detected, and encapsulating the operation request into a secure instruction according to encryption rules if authorization is granted; dynamically selects the transmission protocol channel based on a real-time flag to generate an executable instruction stream, thereby driving the target tool to perform operations and providing feedback on execution status data. This invention solves the heterogeneity problem between AI and robot instructions through dynamic matching of semantics and robot tools, intercepts unauthorized operations based on permission verification, and ensures data security through field-level encryption, providing a secure and efficient human-machine interaction architecture for intelligent manufacturing.
Owner:ZHONGCHUANG (SHENZHEN) INTERNET OF THINGS CO LTD

Communication method, user equipment, and network node

PCT designated stageWO2026100675A1Security arrangementEngineeringUser equipment
This communication method comprises: user equipment in an RRC connected state in a first cell receiving a MAC PDU from a network node that manages the first cell; and the user equipment deriving a security key to be used in communication with a second cell. The MAC PDU contains: a MAC CE to be used in LTM cell switching from the first cell to the second cell; an NCC to be used in deriving the security key; and at least one of an RRC message in which the NCC is arranged and a security token for confirming the integrity of the NCC.
Owner:KYOCERA CORP

A multi-level security protection system and method for a service-oriented artificial intelligence model

The application relates to the technical field of cross technology of artificial intelligence and information security, and discloses a multi-level security protection system and method of a service-oriented artificial intelligence model. The system comprises a model producer terminal used for enabling a model producer to initiate an identity authentication request to a model security platform and upload an original model file after authentication; a model user terminal used for enabling a model user to initiate an identity authentication request to the model security platform and initiate a model calling request after authentication; and a model security platform used for receiving the original model file uploaded by the model producer terminal, encrypting the original model file, and performing security encapsulation on the model type, model serial number, check value and security token to generate a model security container. A model registration module synchronously generates a globally unique model identity, and the model identity and the model security container are bound and stored after encryption. The application can guarantee the security and credibility of the model from development to retirement.
Owner:IND INFORMATION SECURITY (SICHUAN) INNOVATION CENT CO LTD

Commercial tenant member management system and method based on NFC tag

The invention relates to a merchant member management system and method based on an NFC tag. The method comprises the steps that a user activates equipment through rigid physical confirmation operation; reading a dynamic security token of the NFC tag and collecting environment context data; the cloud verifies the token and carries out non-inductive identity recognition and intention evaluation by fusing multi-modal data; and based on the evaluation result, intelligently deciding and issuing personalized member contents or hierarchical payment instructions. Through the dynamic token, context awareness and hierarchical decision-making mechanism, seamless fusion and intelligent collaboration of payment and membership service are realized on the premise of ensuring safety, and the user experience and the commercial operation efficiency are improved.
Owner:HANGZHOU NIWANG TECHNOLOGY CO LTD

Cloud database resource processing method and device, electronic equipment, and storage medium

The application discloses a cloud database resource processing method and device, electronic equipment and a storage medium, wherein the method comprises: obtaining authentication information of a user and authenticating the authentication information of the user; if the authentication is passed, obtaining a project to which the user has a right from a background database and feeding back to the user, responding to a project selection operation of the user, querying cloud resource information of a target project belonging to a target database type selected by the user from the background database; feeding back the queried cloud resource information to the user; responding to a cloud resource selection operation of the user, obtaining an address corresponding to a target cloud resource selected by the user and cloud account information to which the target cloud resource belongs; sending an authorization request to an authorization server by taking the cloud account information to which the target cloud resource belongs as a parameter item, so as to trigger the authorization server to request and return a security token; splicing the address corresponding to the target cloud resource and the security token to obtain a password-free login address and feed back to the user.
Owner:QINGDAO HAIER TECH +1

Secure data processing using data packages generated by edge devices

Disclosed are example methods, systems, and devices that allow for secure data processing using data packages generated by edge devices. A computing device can generate a biometric signature from a scan of a physical feature of a user and encrypt user data based on the biometric signature and a device identifier to produce encrypted user data decryptable with a first digital key. The first digital key can be transmitted to a first computing system to receive a security token indicating validity of at least part of the user data. The encrypted user data and security token can be stored in a data package such that alterations invalidate the token. A second digital key corresponding to the data package can be generated and transmitted with the data package to a second computing system to provide a service.
Owner:WELLS FARGO BANK NA

Method and apparatus for performing client credential assertion in a wireless communication system

The present disclosure relates to a fifth generation (5G) communication system or a sixth generation (6G) communication system for supporting higher data rates beyond a fourth generation (4G) communication system such as long term evolution (LTE). The present disclosure provides techniques for performing client credential assertion based authentication and authorization in a wireless communication system. A method for performing client credential assertion (CCA) based authentication and authorization of a network entity by a network entity is provided. The method includes sending, by the network entity, a first service request to a network repository function (NRF), wherein the sending of the first service request includes encrypting, by the network entity, a CCA token using a key encapsulation mechanism (KEM), wherein the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, signing, by the network entity, the encrypted CCA token using a digital signature to generate a quantum-safe CCA token, wherein the quantum-safe CCA token is the digitally signed encrypted CCA token, and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-safe CCA token to the NRF along with the first service request, and receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD

Communication between control planes in a virtualized computing system having an autonomous cluster

An example method of establishing trust between a cross-cluster control plane (xCCP) and a cluster control plane (CCP) of an autonomous cluster of hosts in a virtualized computing system includes: providing, by the xCCP, trust data of the xCCP to a hypervisor of a host in the autonomous cluster that is executing the CCP; providing, by the hypervisor, the trust data to the CCP through a volume attached to a virtual machine (VM) that executes the CCP; persisting, by the CCP, the trust data in a database; and accessing, by a security token service (STS) of the CCP, the trust data in the database to authenticate access to the CCP by the xCCP.
Owner:VMWARE INC

Secure token transaction unit, secure token reference register, electronic payment transaction system and method for securing a transaction

A secure token transaction unit is part of an electronic payment system and includes: a secure memory that stores multiple tokens, each representing a monetary value, such as a central bank digital currency token; and a control module configured to generate a first replacement request during a transaction that converts an input token stored in the secure memory into a first intermediate token and a first intermediate partner token. It also creates a token record for this transaction, storing the first intermediate token and the first replacement request. The control module can update the token record for a second transaction by replacing the first replacement request with a second replacement request.
Owner:GIESECKEDEVRIENT ADVANCE52 GMBH