Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

151 results about "Security token" patented technology

A security token is a physical device used to gain access to an electronically restricted resource. The token is used in addition to or in place of a password. It acts like an electronic key to access something. Examples include a wireless keycard opening a locked door, or in the case of a customer trying to access their bank account online, the use of a bank-provided token can prove that the customer is who they claim to be.

Document authentication certification with blockchain and distributed ledger techniques

Embodiments are described herein for document authentication certification using information stored on a distributed ledger such as a blockchain. A distributed ledger may securely store document data describing the document. Use of a distributed ledger may provide an immutable, readily auditable record of the history of the document. Each user participating in the system may be assigned a unique identifier to be used for conducting transactions on the distributed ledger network. A user may also be provided with a digital security token such as a cryptographic key that is useable to authenticate the user and enable access to the document data stored on the distributed ledger(s).
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Flow-based secure packet forwarding

Example methods and systems for flow-based secure packet forwarding are described. In one example, a first computer system may assess validity of a security token associated with a flow of one or more packets. In response to determination that the security token is valid, a security association associated with the flow and the security token may be negotiated with a second computer system. The first computer system may process a packet associated with the flow and the security token to generate an encapsulated encrypted packet by performing encryption and encapsulation based on the security association. The encapsulated encrypted packet may be forwarded towards the second computer system to cause the second computer system to perform decapsulation and decryption, and to forward a decapsulated and decrypted packet towards the destination.
Owner:VMWARE INC

Data privacy protection method and system based on zero trust principle

The invention discloses a data privacy protection method and system based on a zero trust principle, and particularly relates to the field of data privacy protection.The method comprises the steps that identity information and biological characteristics are provided when a user registers, and a security token is obtained; during login, the system verifies identity information and inquires role permission to ensure access compliance; a quantum encryption algorithm is adopted for data transmission, and the data security is ensured through quantum state selection, quantum channel transmission and error rate detection; the system continuously monitors user behaviors, equipment states and environment information, dynamically adjusts access authority, divides risk levels based on a risk assessment result and takes corresponding measures; sensitive data are processed through a desensitization technology and an anonymization algorithm, and privacy is protected; and the system collects operation logs and data access logs, analyzes and excavates the logs by using an audit analyzer, identifies abnormal behaviors and generates early warning information.
Owner:NAVAL UNIV OF ENG PLA

Tokenized structured asset states

A system to track to model asset states and access by utilizing non-fungible tokens (NFTs). The system includes a data processing system including memory and one or more processors to receive a stating request for an asset, obtain, based on a plurality of control structures, a plurality of NFTs, each of the plurality of NFTs including a link with a metadata object including metadata of a state of the asset, encapsulate the plurality of NFTs within a container, receive, from the remote device, a state request for an asset state corresponding to a first NFT, the state request including a security token, obtain, from the metadata of the first NFT, one or more recorded security tokens, compare the security token to the one or more security tokens, and, in response to the security token matching the one or more security tokens, transmit the first NFT to the remote device.
Owner:WELLS FARGO BANK NA

AI semantic model and robot interconnection method and system based on MCP protocol, and medium

The invention provides an AI semantic model and robot interconnection method and system based on an MCP protocol and a medium. A natural language instruction is received, and a structured operation sequence is generated through a semantic analysis model; extracting a semantic tag dynamic matching service engine in the sequence, and generating an operation request containing a tool identifier and a parameter template; if the operation authority is verified based on the verification security token, triggering secondary authorization of the user, and if the authority is passed, packaging the operation request into a security instruction according to an encryption rule; a transmission protocol channel is dynamically selected based on the real-time flag bit, an executable instruction stream is generated, and therefore the target tool is driven to execute operation and feed back execution state data; according to the method, the problem of AI and robot instruction heterogeneity is solved through dynamic matching of semantics and robot tools, the unauthorized operation is intercepted based on authority verification, data security is guaranteed through field-level encryption, and a safe and efficient man-machine interaction framework is provided for intelligent manufacturing.
Owner:ZHONGCHUANG (SHENZHEN) INTERNET OF THINGS CO LTD

Dynamic payment authorization system and method

A method of transaction authorization includes receiving, by a payment gateway of a payment platform and from a business support system (BSS), an authorization request for a transaction and a security token corresponding to credential information, determining, by the payment gateway, whether an authorization for the transaction is required, and, based on determining that an authorization for the transaction is not required, generating, by the payment gateway, a capture request for retrieving funds for the transaction, sending, by the payment gateway, the capture request to a card issuer corresponding to the credential information, and transferring, by the payment gateway, the funds for the transaction to an operator of the payment gateway.
Owner:RAKUTEN GROUP INC

Supervisable data security sharing method and device based on three-chain architecture

The invention relates to the technical field of data sharing, and discloses a supervisible data security sharing method and equipment based on a three-chain architecture, and the method comprises the steps that a user submits a data sharing strategy to a strategy contract, the contract generates a strategy verification key and returns the strategy verification key, and the user creates a temporary symmetric key and a data identifier; packaging into a security token and encrypting by using a supervision chain public key to finish strategy registration and key initialization; and the user transmits the encrypted security token to the storage chain through the relay chain, the relay chain verifies the identity of the user and then forwards the token, and the storage chain verifies that the contract decrypts the token by using the private key of the supervision chain. Through a three-chain architecture, zero-knowledge proof and an anti-quantum evidence storage mechanism, data operation compliance can be verified through a non-tampering operation evidence storage chain, the risk of sensitive information leakage caused by opening of supervision authority is reduced, the defect that encrypted data is difficult to audit is overcome, a cross-chain security token fusing mechanism is utilized to resist communication threats, and the safety of the system is improved. And privacy protection and supervision compliance are dynamically balanced.
Owner:ZHEJIANG HEALTH CLOUD CO LTD

Attestable deepfake detection and / or prevention

Implementations are described herein for detecting deepfakes in digital media while preserving the privacy of the source computing device. In various implementations, sensor fingerprints and / or security tokens that signal software-introduced alterations, e.g., introduced by hardware abstraction layers (HALs) or virtual machines (VMs) may be utilized to detect such deepfakes. These signals may be used, separately and / or in combination, for various purposes, such as flagging digital content to a user as being a deepfake, preventing or blocking receipt and / or playback of digital content deemed to be a deepfake, allowing an end user to disable aspect(s) (e.g., layers) of digital content that are determined to be synthetic, etc.
Owner:GDM HOLDING LLC

Utilizing Digital Certificates Generated Based On Security Tokens To Establish Trust For Initiating Secure Connections

A system establishes a secure connection between a first entity and a second entity upon validating a digital signature of a digital certificate. The digital signature is validated utilizing a trust anchor public key corresponding to a security token issued by a trust anchor that is trusted by the first entity and the second entity. In response to a request to establish the secure connection, the system validates the security token issued by the trust anchor to establish trust between the first entity and the second entity. Upon validating the security token, the system validates the digital signature of the digital certificate utilizing an entity public key embedded in the security token. Based on the trust established by the security token, the digital certificate is trusted upon validating the digital signature. Upon validating the digital signature, the system establishes the secure connection between the first entity and the second entity.
Owner:ORACLE INT CORP

Systems and / or methods implementing hybrid approach using JWT token and symmetric hashing

An API gateway receives, from an application, a callback-related request and a registration token including a callback URL usable by an API server to call the callback server and security data for the callback URL. If that token's signature is valid: the callback URL, the security data for the callback URL, and an identifier identifying the API and callback servers are stored; a replacement URL is generated using the identifier; and the replacement URL is registered with the API server. When the API server emits an event regarding a registered request: the security data is retrieved for the associated request; a secure token is generated using that data and event-related content; the callback URL is retrieved for the associated request; and the retrieved callback URL, the secure token, and event-related content are sent to the callback server. The callback server determines whether event-related content is trustworthy using the secure token.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Fine-grained data security access control method and device and storage medium

The invention discloses a fine-grained data security access control method and device and a storage medium, and the method comprises the steps: obtaining terminal information which comprises hardware fingerprint information and a digital certificate; performing terminal information verification processing according to the hardware fingerprint information and the digital certificate to generate a security token; performing user information verification processing according to the security token and the user access request to generate an access request result; according to the access request result, access channel authorization processing is carried out, and a target data access channel state is generated; performing data access record processing according to the target data access channel state to generate a target operation ticket; performing storage and audit processing according to the target operation order to generate an audit report; and performing data clearing processing according to the audit report to generate a visual report. According to the invention, data security access control is realized, and security and adaptability are improved. The method can be widely applied to the technical field of data security access.
Owner:GUANGZHOU KETENG INFORMATION TECH

Safety management

There are proposed methods, devices, and computer program products for safety management. In the method, in response to receiving a first query to a machine learning model, a first response to the first query is obtained by the machine learning model, the first query being represented in a natural language, and the machine learning model being a language model. A second query is determined based on the first query, the first response and a safety token, the safety token triggering a safety check on the second query. A second response to the second query is obtained by the machine learning model based a check result of the safety check.
Owner:BYTEDANCE TECHNOLOGY LTD

Out-of-band (OOB) remote attestation

A computing system includes a baseboard management controller (“BMC”) that receives a security token from a management system. The computing system also executes a firmware that collects measurements from components of the computing system. The measurements include data describing the components for use in attestation. The firmware provides the measurements to the BMC, which generates a digital signature of the measurements and the security token. The BMC provides the measurements and the digital signature to the management system, which attempts to verify the digital signature utilizing a public key associated with the BMC. If the management system can verify the digital signature, then the BMC utilized the correct security key to generate the digital signature and the measurements were not tampered with after collection by the firmware. The measurements can then be utilized to attest the computing system.
Owner:AMERICAN MEGATRENDS

Trusted customer identity systems and methods

Trusted customer identity systems and methods provide secure electronic payment transactions incorporating customer identity verification using cross-referenced multiple data sources. Two distinct authorities provide payment speed, simplicity, and security. A network path-based identity methodology does not require shared information between parties. A first party receives a secure token and has sole access and controls possession of unique data that they append to the token. Before a transaction, a unique identifying characteristic of the party is used to register it on the trusted customer network. Other parties on the network do not possess a copy of the unique data but, based on the registration characteristics of the first party, know when they receive the token that only the first party could have added the unique data to the token. Other parties on the network can trust that the first party is the same party who registered this account to the network.
Owner:SHAZZLE LLC

Caller identification trust

Disclosed are example methods, systems, and devices for allowing caller computing devices to authenticate calls via a service provider computing system. Users may opt to have entities register to contact the user with a positive ID, icon, or other notification on the user's computing device transmitted by the service provider computing system. A caller computing device may use a unique security token of the user to activate the notification on the user's device. The user device may be used to exert control over the security token via a service provider client application running on the user device. The caller computing device may initiate authentication via an API call to the service provider computing system. The caller computing device is able to have items (text, images, documents, etc.) delivered to the user computing device if authenticated.
Owner:WELLS FARGO BANK NA

Authentication of a vehicle occupant for a financial transaction

The invention relates to a method for executing an electronic financial transaction by a user as an occupant of a vehicle (1), wherein the user uses a physical electronically readable identity card (3) or a virtual electronically readable identity card (3) displayed in a mobile device to identify and authenticate themselves to a reader (5) of the vehicle (1), wherein no identification of the vehicle takes place, wherein the reader (5) connects to a central computer (7) via the Internet and receives a security token from it after successful identification and authentication, which is transmitted together with payment data to a payment service provider (9), which then authorizes a financial transaction with reference to the payment data and / or forwards data about it.
Owner:MERCEDES BENZ GROUP AG

Identity authentication method of token based on quantum security

The invention discloses an identity authentication method of a token based on quantum security. The method comprises the following steps: a client executes an initialization operation; the client establishes a session link with the server, the server generates a first token and issues the first token to the client, and the server and the client locally store the first token respectively; when the session link exists, the client negotiates with the authentication server, generates a second token based on the first token, generates a service resource request based on the second token, and initiates the service resource request to the server; the authentication server and the server respectively execute identity authentication operation for the service resource request; and the server responds to the current service resource request of the client based on a result of passing the identity authentication operation. According to the invention, through the dynamic token, the hierarchical key, the pre-negotiation parameter and the quantum encryption technology, an anti-cracking, anti-attack and high-efficiency multi-level security authentication system is constructed.
Owner:MATRICTIME DIGITAL TECH CO LTD

Federal learning privacy protection method for dynamic search hybrid encryption and contribution value perception

The invention relates to the technical field of federated learning and privacy protection, and discloses a federated learning privacy protection method for dynamic search hybrid encryption and contribution value perception, which mainly comprises the following steps of: constructing a privacy protection scheme of a local evaluation and hybrid encryption mechanism combined with contribution degree perception to realize differentiated privacy protection of client privacy data; the calculation time overhead and the communication overhead based on a single homomorphic encryption privacy mechanism are effectively reduced; a central storage server access control and dynamic key rotation mechanism driven by a security token is constructed, and key non-replay and historical data non-revealing are realized by combining a searchable relevance trap door index stored by a ciphertext; according to the method, on the basis of a security aggregation algorithm of contribution perception, the contribution value of each local model in a ciphertext state is evaluated by a joint secrecy calculation protocol, aggregation screening of a global model under the condition that the contribution value plaintext is not revealed is ensured, power dispersion of a central storage server is completed, and the overall efficiency and privacy of the system are remarkably improved.
Owner:KUNMING UNIV OF SCI & TECH

Secure token exchange for automated systems

Secure token exchange for automated systems includes receiving, for validation, an application programming interface (API) token grant request, including an API key, sent by an automated system, and retrieving, from a database, an API key entity corresponding to the API key, wherein the API key entity includes a token receive endpoint. An authentication token is generated. The authentication token is asynchronously pushed to the token receive endpoint for access by the automated system.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

USB key on-line checking method and system combining artificial intelligence and Internet of Things

The invention relates to the technical field of USB key on-line checking, in particular to a USB key on-line checking method and system combining artificial intelligence and the Internet of Things. Establishing a USB key dynamic authority management model, and defining an authority level; performing abnormal behavior analysis according to the permission level, and judging a user risk level; and according to an abnormal behavior analysis result, performing a U shield intelligent response mechanism. Through artificial intelligence, the Internet of Things and a big data analysis technology, intelligent checking and safety management of the USB key are realized, and the system has dynamic authority management, efficient anomaly detection, accurate response mechanism and adaptive adjustment capability, and is widely applied to the fields of finance, government affairs, enterprise information safety and the like.
Owner:YUNNAN POWER GRID CO LTD +1

Secure data processing using data packages generated by edge devices

Disclosed are example methods, systems, and devices that allow for secure data processing using data packages generated by edge devices. The techniques include generating a biometric signature using information captured by a computing device, and encrypting user data obtained via the computing device using the biometric signature and a device identifier of the computing device. A security token can be generated and utilized by the computing device to generate a data package, which is configured such that any change to the data package would cause a validation process of the data package using the security token to fail. The data package can be encrypted using various digital keys and provided to secondary computing systems.
Owner:WELLS FARGO BANK NA

Service ID

Service ID card for analog and digital authentication, characterized in that the service ID card (1) can be attached to a piece of clothing by means of fastening means and has a receptacle (2) for a USB security token, wherein the USB security token is removable and replaceable.
Owner:DIGITRONIC COMPUTERSYSTEME GMBH

Systems and methods for secure tokenized credentials

Systems, devices, methods, and computer readable media are provided in various embodiments having regard to authentication using secure tokens, in accordance with various embodiments. An individual's personal information is encapsulated into transformed digitally signed tokens, which can then be stored in a secure data storage (e.g., a “personal information bank”). The digitally signed tokens can include blended characteristics of the individual (e.g., 2D / 3D facial representation, speech patterns) that are combined with digital signatures obtained from cryptographic keys (e.g., private keys) associated with corroborating trusted entities (e.g., a government, a bank) or organizations of which the individual purports to be a member of (e.g., a dog-walking service).
Owner:ROYAL BANK OF CANADA

Secure token exchange and controls and interfaces therefor

Methods, systems, and computer program products provide direct and in-network provisioning of tokens. A secure token exchange (STE) processor receives a direct token request from a token requestor prior to sending a payment transaction message or request for payment message. In-network token provisioning is performed during a transaction and also involves the STE processor. Data aggregation security is provided by verifying consumer information, tokenizing account data, and forwarding a token and consumer data to a data aggregator.
Owner:CLEARING HOUSE PAYMENTS CO LLC

Secure token exchange and controls and interfaces therefor

Methods, systems, and computer program products provide direct and in-network provisioning of tokens. A secure token exchange (STE) processor receives a direct token request from a token requestor prior to sending a payment transaction message or request for payment message. In-network token provisioning is performed during a transaction and also involves the STE processor. Data aggregation security is provided by verifying consumer information, tokenizing account data, and forwarding a token and consumer data to a data aggregator.
Owner:CLEARING HOUSE PAYMENTS CO LLC

Intelligent access control system

A method, by an intelligent access control system, of implementing access control to a controlled area having a plurality access areas divided by at least one access point includes the following operations. A security token is generated. The security token is transmitted to a client module executing on a client device associated with a first user, and the client module is caused to pair with an access control device associated with the first user. The client module is caused to transfer the security token to the access control device. A physical location of the client device within the controlled area is monitored. A determination is made, by an access control system and based upon the physical location, that the first user is to be revalidated. The client module causes, based upon the determining, the client device to generate an alert.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Intelligent access control system

A method, by an intelligent access control system, of implementing access control to a controlled area having a plurality access areas divided by at least one access point includes the following operations. A security token is generated. The security token is transmitted to a client module executing on a client device associated with a first user, and the client module is caused to pair with an access control device associated with the first user. The client module is caused to transfer the security token to the access control device. A physical location of the client device within the controlled area is monitored. A determination is made, by an access control system and based upon the physical location, that the first user is to be revalidated. The client module causes, based upon the determining, the client device to generate an alert.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Artificial reality encryption and decryption

Embodiments described herein disclose methods and systems for encryption and decryption of data. In some implementations, an encryption and decryption system can protect private information of a user in documents with an artificial reality device. The encryption and decryption system can determine the portion of a document containing private information and encrypt that portion of the document. In some implementations, the encryption and decryption system can receive a document and identify the protected (e.g., encrypted) portion of the document. In some cases, the protected portion of the document can contain a security token that the encryption and decryption system can extract. The system can compare the security token to an authentication token associated with the user and determine whether the security and authentication token match. If the tokens match, the system can decrypt the protected portion of the document and display the decrypted data as a virtual object.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Method and apparatus for performing client credential assertion in wireless communication system

The present disclosure relates to a 5th-Generation (5G) communication system or a 6th-Generation (6G) communication system for supporting higher data rates beyond a 4th-Generation (4G) communication system such as Long Term Evolution (LTE). The present disclosure provides techniques for performing authentication and authorization based on client credential assertion in a wireless communication system. A method performed by a network entity for performing client credential assertion (CCA)-based authentication and authorization of the network entity is provided. In one embodiment, a method includes sending, by a network entity, a first service request to a network repository function (NRF), where sending of the first service request includes encrypting, by the network entity, a CCA token using a Key Encapsulation Mechanism (KEM), where the KEM is based on a predefined post-quantum cryptography (PQC) mechanism, where the KEM is based on the PQC mechanism. The encrypted CCA token is signed by the network entity using a digital signature to generate a quantum-secure CCA token, where the quantum-secure CCA token is a digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism, and sending, by the network entity, the quantum-secure CCA token to the NRF along with the first service request, where the quantum-secure CCA token is the digitally signed encrypted CCA token and the digital signature is based on a predefined PQC mechanism. And receiving, by the network entity, a service response to the first service request from the NRF.
Owner:SAMSUNG ELECTRONICS CO LTD