Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

57 results about "Server authentication" patented technology

Identity authentication method and system based on block chain

The invention discloses an identity authentication method and system based on a block chain, and particularly relates to the technical field of identity authentication security. Comprising the steps of S01, user login request verification, S02, user identity detection enhancement verification, S03, user identity authentication abnormity control, S04, user access security assessment data acquisition, S05, user access security analysis and S06, user access security assessment. The face recognition confidence, the iris matching degree and the user face video stream are collected on the user login page, the user identity compliance is verified, the safety of identity verification is improved, the authentication accuracy is improved, the safety evaluation data of the authentication server in the block chain network are collected, the user authentication access risk evaluation coefficient is calculated, and the user authentication access risk evaluation efficiency is improved. And the server authentication access risk is monitored, so that the change of the server authentication access risk can be monitored in real time, the occurrence of security events is effectively prevented, and the user information management efficiency is improved.
Owner:HEZHENG TECHNOLOGY (YUNNAN) CO LTD

Fingerprint lock dynamic encryption authentication method and system and medium

The invention relates to a fingerprint lock dynamic encryption authentication method and system and a medium. The method comprises a registration stage and an authentication stage. Wherein in the registration stage, lock body environment real-time physical parameters are collected, and a dynamic environment secret key is generated through a chaotic mapping function; acquiring a user fingerprint, identifying core and non-core feature regions, and encrypting the two types of regions by combining a dynamic environment key and a user key to generate registration encrypted fingerprint data; and dividing the data into two data fragments by using a quantum noise source true random sequence, storing the first data fragment in a local security chip, and encrypting the second data fragment and storing the encrypted second data fragment in a cloud server. In the authentication stage, environment parameters are collected in real time to generate a verification key, and the verification key is compared with a registration key; and when the two fragments are consistent, recombining the two fragments to restore the encrypted fingerprint data, authenticating the fingerprint input by the user, unlocking if the authentication succeeds, and triggering risk grading processing if the continuous failure reaches a threshold value. The overall safety and reliability of the fingerprint lock system are improved.
Owner:BEIJING HUAZHONG CHUANGSHI TECH DEV CO LTD

Authenticating data across distinct remote game servers in a game streaming environment

Systems and methods that determine whether data determined by a first remote game server in association with a play of a wagering game displayed by a streaming device is authentic data. If so, the systems and methods cause a communication of the authentic data to a second remote game server operating with a client device. On the other hand, if the data is not authentic, the systems and methods store the data as unauthentic data without communicating any data to the second remote game server operating with the client device.
Owner:INTERNATIONAL GAME TECHNOLOGY INC

Device authentication through proxy

A software-based authentication protocol enables a client to be authenticated by a server through a host. The authentication protocol involves using mutable authentication data that changes to deter counterfeiters from making clones of authentic clients. The host requests a token from the client as proof of authenticity. The client establishes a communication channel to the server using the host as a communication proxy. The client presents mutable authentication data to the server. If the server determines that the mutable authentication data is outdated, then the client is deemed a counterfeit. If the server determined that the mutable authentication data is the latest version, then the client is deemed authentic and a token is issued to the client. Depending on a set of policies, the server changes the mutable authentication data and sends the new mutable authentication data to the client but not to counterfeit clients.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

IoT device authenticated based on dynamically reconfigurable PUF and server and method for authenticating the same

An Internet of Thing (IoT) device generates a first response value corresponding to a previously registered first challenge value by using a WPUF, generates a current session key based on the first response value, transmits the current session key to an authentication server by encrypting the current session key into a first random number, receives, from the authentication server, some of a previously registered CRP transmitted by the authentication server as the authentication server authenticates the IoT device based on the first random number and the session key and a second random number, generates a second response value corresponding to a second challenge value, among the some of the CRP, by using an RPUF, authenticates the authentication server by comparing the second response value with the some of the CRP, and then updates the session key, the second challenge value, and the second response value for a next session.
Owner:ELECTRONICS & TELECOMM RES INST

Lightweight digital signature method and electronic equipment

The invention discloses a lightweight digital signature method, which is applied to a system comprising a first terminal and a second terminal, and comprises the following steps: the first terminal and the second terminal are mutually registered in a safe environment, and a first challenge response pair and a second challenge response pair which are paired are generated based on a physical unclonable function; a first challenge response pair is stored in the first terminal, and a second challenge response pair is stored in the second terminal; the first terminal constructs a signature message according to the first challenge in the first challenge response pair, and sends the signature message to the second terminal; the second terminal calculates a second verification value according to the signature message and a physical unclonable function of the second terminal, and sends the second verification value to the first terminal; and the first terminal judges whether the second verification value is consistent with the first response in the first challenge response pair, and if yes, the identity verification of the second terminal is successful. While the signature security is ensured, the calculation complexity is reduced, and direct authentication between the terminal devices is realized without server authentication.
Owner:福建福链科技有限公司

Login authentication management method and device, processor and machine readable storage medium

The embodiment of the application provides a login authentication management method, device, processor and machine readable storage medium, and relates to the technical field of information security. The method comprises the following steps: in response to a connection request of a user terminal, obtaining a first authentication parameter and a first connection target of the user terminal; calling a server authentication file to obtain a second authentication parameter of the server authentication file; in the case that the first authentication parameter and the second authentication parameter satisfy a matching condition, obtaining login information of the first connection target and transmitting the login information to the user terminal, and the user terminal can establish a connection with the first connection target through the login information. In the application, the user terminal cannot directly obtain the login information of the connection target, so that the data security can be effectively improved, and when the login information of the connection target changes, the user terminal does not need to modify the connection code or the configuration file, and only needs to modify the login information in the configuration file on the server side.
Owner:CHINA CONSTRUCTION BANK

Identity authentication method for distributed database clusters

The present invention discloses an identity authentication method for distributed database clusters, belonging to the field of database security. The method comprises setting one host in the cluster as an authentication proxy server; the authentication proxy server receives proxy authentication requests from hosts in other clusters; the other hosts transmit the authentication information of the user currently attempting to log in to the authentication proxy server as a proxy authentication request; the authentication proxy server processes the current proxy authentication request through its own authentication system and feeds back the authentication result to the other hosts; after receiving the authentication result, the other hosts determine whether to allow the current user to log in based on the authentication result. Compared with existing database authentication methods, the use of an authentication proxy allows the authentication system to be shared with other systems while retaining the existing authentication process, allowing the distributed database clusters to share the same set of authentication processes. At the same time, the cluster responsible for the authentication proxy can continue to retain the functions of the database itself.
Owner:GUIZHOU ESGYN INFORMATION TECH CO LTD

Personal digital certificate embezzlement identification method based on traffic audit

The invention discloses a personal digital certificate embezzlement identification method based on traffic audit. The method comprises the following steps: S1, deploying a traffic acquisition device in a network path between a user terminal and a server which need to use a personal digital certificate; every time a user terminal uses a digital certificate to authenticate a server, a flow acquisition device acquires communication messages from the same session, extracts three types of information including user personal digital certificate information, a user IP address and a user TCP protocol initial window size from the communication messages and binds the information into a triple elem; s2, establishing a white list (white list) after the learning of the cycle time T; and S3, the traffic acquisition device carries out validity judgment on each newly acquired triple based on the white list white list, compares the valid triple with the legal triple in the white list, updates the white list of the triple, and outputs an alarm record for the digital certificate with an embezzlement risk. Therefore, the purpose of embezzlement identification and alarm can be achieved without the participation of a client.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

A Cross-Scene Anonymous Seamless Identity Authentication Method for the Metaverse Based on Dual Blockchains

The present invention provides a cross-scenario anonymous seamless identity authentication method for the metaverse based on dual blockchains, including: an initialization phase, a scenario server registration phase, a user registration phase, a phase where the user logs in and creates an avatar on the scenario server, and a user cross-scenario server authentication phase. Servers are set up for different application scenarios to reduce the load on the servers, enabling users to experience multiple scenarios without changing devices. The present invention uses a fuzzy extractor and blockchains to protect privacy information such as users' biometric information and avatars. At the same time, in the dual-blockchain mode, the server and user authentication information are stored on the authentication data chain, and users can move among different services. The interactive data chain stores the avatar data of users in multi-scenario servers to achieve data consistency. The dual blockchains achieve the isolation of users' real-world data and virtual data in the metaverse, effectively protecting users' privacy data. Users do not need to enter information again to log in, realizing seamless authentication.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

System and method for authentication control for content delivery

The present disclosure provides systems and methods for authentication control of content delivery. The method includes receiving a request for a content item from a computing device, the request including a security token associated with the computing device and an identifier of a domain group, identifying the domain group from the identifier, and retrieving a security key associated with the domain group. The method also includes decrypting a signature of the security token, identifying an authentication string, determining that the authentication string matches a server authentication string, and identifying a characteristic of the security token. The characteristic of the security token includes a confidence score. The method further includes comparing the confidence score of the security token to a threshold, determining that the confidence score does not exceed the threshold, and preventing the content from being sent to the computing device.
Owner:GOOGLE LLC

System and method for decentralized user controlled social media

A computer system for accessing a decentralized user controlled social media platform receives, from an user computing device, a user authentication token for the decentralized user controlled social media platform. The computer system determines that the user authentication token is valid for access to a user account at the decentralized user controlled social media platform. Additionally, the computer system requests, through a network connection, content from a plurality of remote servers. Each of the plurality of remote servers requires a unique remote server authentication token to access a portion of the content stored at the respective remote server. Further, the computer system communicates, to the user computing device, the content received from the plurality of remote servers.
Owner:TROFIVENTURES LLC

Authentication server, authentication system, authentication device, authentication method, and authentication program

This invention provides an authentication server, authentication system, authentication device, authentication method, and authentication program that can reduce processing load while ensuring security. [Solution] The authentication server 2 includes a processor 11 that acquires captured images and performs authentication processing. Based on processing instruction information 42, the processor selectively executes, for each frame constituting the captured image, a biometric information matching process that compares it with registered biometric information and determines whether the person to be authenticated is a registered person, a body expression matching process that determines whether the body expression of the person to be authenticated satisfies the conditions, and a liveness determination process that confirms whether it is a living being, thereby authenticating the person to be authenticated. The processing instruction information indicates whether or not the biometric information matching process, body expression matching process, and liveness determination process should be executed for each frame, and each process is set to be executed in at least one frame.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Authentication using an intermediary

Technology related to authentication using an intermediary is disclosed. In one example, a method for authentication can include intercepting a first authentication response destined for a server. The first authentication response identifies a server authentication service and is digitally signed by an identity service provider. The first authentication response can be authenticated using a cryptographic key of the identity service provider to validate an identity service provider signature included in the first authentication response. In response to validating the identity service provider signature, a second authentication response can be sent to the server that identifies the server authentication service.
Owner:F5 NETWORKS INC

Rapid privacy protection biological characteristic authentication method based on lattice password

The invention discloses a quick privacy protection biological characteristic authentication method based on a lattice password, the method comprises the steps of system initialization, key generation, user registration, user authentication and server authentication, the lattice password technology is combined with local sensitive hashing (LSH), the anti-quantum characteristic of the lattice password is utilized to guarantee data security, and the security of the system is improved. The comparison range is reduced in combination with the LSH, the authentication efficiency is improved, the problems of high privacy leakage risk, weak quantum attack resistance and low large-scale authentication efficiency in traditional biological feature authentication are solved, and the method is suitable for scenes with high requirements for privacy protection and authentication speed.
Owner:GUIZHOU DATABAO NETWORK TECH CO LTD

Online authentication for medical devices

A medical device includes a QR generator and a user access / activity log. The QR generator generates a QR code at least from a username of a user and at least one OTP (one-time password) for the user and enables access of the user to the medical device upon receiving an OTP from the user. The user sends the QR code to an online authorization server for the medical device for decryption upon authentication of the user. The log lists user activity once the user is authenticated by the server. The server receives the QR code, which includes at least an encrypted text containing at least the OTP and a user identification, and decrypts the encrypted text using a private key associated with the medical device. The authorization server enables the user to log in for authentication and, if authenticated, displays the at least one OTP to the user.
Owner:BIOSENSE WEBSTER (ISRAEL) LTD

Post-quantum identity authentication method and system under multi-server architecture

The invention relates to a post-quantum identity authentication method and system under a multi-server architecture, and the method specifically comprises the steps: transmitting a server identity identifier to a registration center through a secure channel, generating a server authentication secret key by the registration center according to the server identity identifier, and transmitting the server authentication secret key to a server; the user inserts an intelligent card, generates a temporary password and a temporary identity according to the user identity label and the biological characteristics, and sends the temporary password and the temporary identity to the registration center, and the registration center generates verification information when the user logs in by using the temporary password and the temporary identity and by means of the random number; when a user accesses the server, verification information is regenerated according to the identity label and the biological characteristics, if the regenerated verification information is consistent with the verification information generated during registration, the user obtains a temporary message by using central binomial distribution, the server calculates the authentication information and the shared key by using the temporary message, and the user calculates the authentication information again. And if the authentication information is consistent, calculating a shared key, otherwise, terminating the session.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

A method for automatic IP allocation of service packets in an OpenVPN environment

This invention discloses a method for automatically allocating service packets IP addresses based on an OpenVPN environment in the field of Virtual Private Network (VPN) technology. The method includes configuring multiple first IP address pools for first ID groups based on the OpenVPN server's management interface, associating each first IP address pool with a corresponding filter ID, setting the IP range for each first IP address pool, authenticating a second ID using server authentication, and obtaining the attributes of the filter ID corresponding to the second ID after successful authentication. Based on these attributes, the method matches the corresponding IP address pool within the first IP address pools to obtain the second IP address pool. This invention achieves non-overlapping IP address allocation by developing automated CCD files as configuration scripts and combining this with matching IP addresses to the attributes of the filter IDs used for authenticated user access. This avoids conflicts and allows for the allocation of different IP segments based on the user's service packet status, effectively improving the efficiency of IP address allocation management.
Owner:SHANGHAI HENGXIANG NETWORK TECH CO LTD

Device authentication through proxy

A software-based authentication protocol enables a client to be authenticated by a server through a host. The authentication protocol involves using mutable authentication data that changes to deter counterfeiters from making clones of authentic clients. The host requests a token from the client as proof of authenticity. The client establishes a communication channel to the server using the host as a communication proxy. The client presents mutable authentication data to the server. If the server determines that the mutable authentication data is outdated, then the client is deemed a counterfeit. If the server determined that the mutable authentication data is the latest version, then the client is deemed authentic and a token is issued to the client. Depending on a set of policies, the server changes the mutable authentication data and sends the new mutable authentication data to the client but not to counterfeit clients.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Terminal authentication method and device, server and medium

The embodiment of the invention provides a terminal authentication method and device, a server and a medium, relates to the technical field of communication, is applied to a first authentication server in a first cloud management network, and comprises the following steps: receiving a first authentication request message forwarded by a terminal according to an address of the first authentication server carried by the first authentication request message, the first authentication request message is sent by an access device connected with the terminal, and the first authentication request message further carries a management identifier and an authentication template identifier of the access device; and if the management identifier of the access device is not the management identifier in the first cloud management network and the authentication template identifier of the access device corresponds to authentication of a second authentication server in a second cloud management network, sending an address of the second authentication server to the terminal, so that the terminal performs authentication processing by using authentication information in the second authentication server. According to the method, the problem that part of terminals cannot be authenticated after the cloud management network is split can be solved.
Owner:NEW H3C TECH CO LTD

A dynamic encryption authentication method and system for a fingerprint lock and a medium

The application relates to a dynamic encryption authentication method and system of a fingerprint lock and a medium, and the method comprises a registration and authentication stage. In the registration stage, real-time physical parameters of a lock body environment are collected, a dynamic environment key is generated through a chaotic mapping function, user fingerprints are obtained, core and non-core feature areas are identified, two types of areas are respectively encrypted in combination with the dynamic environment key and a user key, and registered encrypted fingerprint data is generated. The data is segmented into two data fragments by using a quantum noise source true random sequence, the first data fragment is stored in a local secure chip, and the second data fragment is stored in a cloud server after encryption. In the authentication stage, environment parameters are collected in real time to generate a verification key, which is compared with the registration key. When the two are consistent, the two fragments are recombined to restore the encrypted fingerprint data, which is authenticated with the user input fingerprint. If the authentication is successful, the lock is opened. If the authentication fails continuously and reaches a threshold value, a risk grading process is triggered. The application improves the overall security and reliability of the fingerprint lock system.
Owner:BEIJING HUAZHONG CHUANGSHI TECH DEV CO LTD

Systems and methods for secure client-server authentication with key recycling

A method may include: sharing, by a client computer program and a server computer program, a set of identification keys, each identification key associated with a key label, and an authentication key; selecting, by the client computer program and the server computer program, one of the key labels; preparing, by the client computer program, quantum systems using a basis, randomly chosen bit values, and intensities; sending, by the client computer program, the quantum systems to the server computer program over a quantum communication channel, wherein the server computer program may be configured to measure the quantum systems using the basis and to announce quantum systems with photon detection; and generating, by the client computer program, a client tag using a shared keyed hash function executed on the authentication key and chosen bit values from the quantum systems with photon detection, and forwarding the client tag to the server computer program.
Owner:JPMORGAN CHASE BANK NA

Campus broadband access management system and method

The invention discloses a campus broadband access management system and method. The system comprises a user terminal, a BRAS server, a Portal prepositive server, an authentication interface server, an RADIUS server, a campus broadband management server and a flow monitoring server, the BRAS server receives an HTTP request sent by the user terminal and redirects the HTTP request to the Portal prepositive server; the Portal prepositive server responds to the request, sends redirection information, and forwards a first authentication request containing user information to an authentication interface server; the authentication interface server generates a second authentication request and sends the second authentication request back to the BRAS server, and the BRAS server transmits the second authentication request to the RADIUS server for authentication; the BRAS server adjusts the user access authority according to the authentication result; and after the campus broadband is accessed, the user terminal and the campus broadband management server execute anti-private connection detection, and the types comprise anti-router, WIFI and virtual environment private connection detection. According to the invention, the technical problems that the authentication security is insufficient and the private access phenomenon is difficult to effectively restrain in the campus broadband technology are solved.
Owner:CHINA TELECOM CORP LTD

Server authentication method, electronic equipment and system

The invention provides a server authentication method, electronic equipment and a server authentication system, and relates to the technical field of network security. In view of the problem that potential safety hazards are easily caused when network configuration is carried out on a client traditionally, the server authentication method provided by the invention comprises the steps that a first discovery message is broadcasted to a server in a network, the first discovery message comprises preset first authentication information, and the first authentication information is used for indicating identity information of electronic equipment; receiving a first offer message returned by the at least one server after verifying the first authentication information of the first discovery message; analyzing the first offer message, and if the first offer message contains second authentication information in a preset format, taking the server as a trusted server; wherein the intermediate device is used for sending a message to the trusted server in a unicast form and forwarding configuration parameters issued by the trusted server to the client in a unicast form, and the configuration parameters are used for performing network configuration on the client. According to the embodiment of the invention, the network security can be improved.
Owner:TP-LINK

A blockchain-based identity authentication method and system

The application discloses a kind of identity authentication method and system based on blockchain, specifically related to identity authentication security technical field, including step S01: user login request verification, step S02: user identity detection enhancement check, step S03: user identity authentication exception control, step S04: user access security evaluation data acquisition, step S05: user access security analysis, step S06: user access security evaluation, the present application collects face recognition confidence, iris matching degree, user face video stream in user login page, verifies user identity compliance, is conducive to improving the security of identity verification, improves authentication accuracy, collects the security evaluation data of authentication server in blockchain network, calculates user authentication access risk evaluation coefficient, monitors server authentication access risk, is conducive to real-time monitoring the change of server authentication access risk, effectively prevent the occurrence of security event, improve user information management efficiency.
Owner:HEZHENG TECHNOLOGY (YUNNAN) CO LTD

Identity authentication method, device and related equipment

The embodiment of the present application provides an identity authentication method, apparatus and related equipment, wherein the method includes: the service provider's server receives a message that the user's user identity has been authenticated by the identity provider's server, and the message includes the user's bound verification method information; the service provider's server sends a verification request to the user terminal according to the verification method information; the service provider's server receives the verification code sent by the user terminal and verifies the verification code; when the service provider's server verifies the verification code, the service provider's server generates an access credential corresponding to the user and sends the access credential to the user terminal, and the access credential indicates that the user has the right to access the service provider's server. By implementing the above method, in the process of realizing federated identity authentication, the user's identity is confirmed through multi-factor authentication to prevent the risk of user data security caused by the leakage of identity credentials of a single system.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Systems and methods for generating a one-time use token for item purchase

Systems and methods are disclosed for payment system that uses one-time use tokens for securely facilitating and controlling user purchases using company funds. A user (e.g., driver) may generate a request to make a purchase using a user application. The request may be sent to a server running a payment system that may generate a one-time use token for the purchase of an item (e.g., fuel). The one-time use token may have an expiration time and may only be redeemable at certain locations (e.g., fueling stations) that have been preapproved. The system may send the user application running on the user device the token for purchasing fuel and approved locations. The user may input the token to a controller at an approved location which may request that the server authenticate the token and approve the purchase. Once authenticated and approved, the controller may permit the purchase of the desired item.
Owner:RELAY PAYMENTS INC

Systems and methods for secure client-server authentication with key recycling

A method may include: sharing, by a client computer program and a server computer program, a set of identification keys, each identification key associated with a key label, and an authentication key; selecting, by the client computer program and the server computer program, one of the key labels; preparing, by the client computer program, quantum systems using a basis, randomly chosen bit values, and intensities; sending, by the client computer program, the quantum systems to the server computer program over a quantum communication channel, wherein the server computer program may be configured to measure the quantum systems using the basis and to announce quantum systems with photon detection; and generating, by the client computer program, a client tag using a shared keyed hash function executed on the authentication key and chosen bit values from the quantum systems with photon detection, and forwarding the client tag to the server computer program.
Owner:JPMORGAN CHASE BANK NA

Online authentication for medical devices

A medical device includes a QR generator and a user access / activity log. The QR generator generates a QR code at least from a username of a user and at least one OTP (one-time password) for the user and enables access of the user to the medical device upon receiving an OTP from the user. The user sends the QR code to an online authorization server for the medical device for decryption upon authentication of the user. The log lists user activity once the user is authenticated by the server. The server receives the QR code, which includes at least an encrypted text containing at least the OTP and a user identification, and decrypts the encrypted text using a private key associated with the medical device. The authorization server enables the user to log in for authentication and, if authenticated, displays the at least one OTP to the user.
Owner:BIOSENSE WEBSTER (ISRAEL) LTD

Method for Registering a Mobile Device, an Embedded Universal Integrated Circuit Card, eUICC, and a Mobile Network Server

A method for registering a mobile device including an embedded Universal Integrated Circuit Card (eUICC) at a mobile network server includes determining subscriber identification information and deriving a first key. Then a registration request is sent to the mobile network server. The eUICC signs first random data with the first key and sends it to the mobile network server. The server produces a server authentication key and authenticates the eUICC, and if successful, grants limited access. The eUICC signs first or second random data with a second key and sends a registration message comprising the signed first or second random data to the mobile network server, which determines the validity of the signed first or second random data, and if valid, grants regular access to the eUICC. Further an embedded Universal Integrated Circuit Card, a mobile network server and a computer program product are disclosed.
Owner:NXP BV