Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Server authentication" patented technology

Fingerprint lock dynamic encryption authentication method and system and medium

The invention relates to a fingerprint lock dynamic encryption authentication method and system and a medium. The method comprises a registration stage and an authentication stage. Wherein in the registration stage, lock body environment real-time physical parameters are collected, and a dynamic environment secret key is generated through a chaotic mapping function; acquiring a user fingerprint, identifying core and non-core feature regions, and encrypting the two types of regions by combining a dynamic environment key and a user key to generate registration encrypted fingerprint data; and dividing the data into two data fragments by using a quantum noise source true random sequence, storing the first data fragment in a local security chip, and encrypting the second data fragment and storing the encrypted second data fragment in a cloud server. In the authentication stage, environment parameters are collected in real time to generate a verification key, and the verification key is compared with a registration key; and when the two fragments are consistent, recombining the two fragments to restore the encrypted fingerprint data, authenticating the fingerprint input by the user, unlocking if the authentication succeeds, and triggering risk grading processing if the continuous failure reaches a threshold value. The overall safety and reliability of the fingerprint lock system are improved.
Owner:BEIJING HUAZHONG CHUANGSHI TECH DEV CO LTD

Authenticating data across distinct remote game servers in a game streaming environment

PendingUS20260081779A1User identity/authority verificationVideo gamesEngineeringServer authentication
Systems and methods that determine whether data determined by a first remote game server in association with a play of a wagering game displayed by a streaming device is authentic data. If so, the systems and methods cause a communication of the authentic data to a second remote game server operating with a client device. On the other hand, if the data is not authentic, the systems and methods store the data as unauthentic data without communicating any data to the second remote game server operating with the client device.
Owner:INTERNATIONAL GAME TECHNOLOGY INC

Device authentication through proxy

A software-based authentication protocol enables a client to be authenticated by a server through a host. The authentication protocol involves using mutable authentication data that changes to deter counterfeiters from making clones of authentic clients. The host requests a token from the client as proof of authenticity. The client establishes a communication channel to the server using the host as a communication proxy. The client presents mutable authentication data to the server. If the server determines that the mutable authentication data is outdated, then the client is deemed a counterfeit. If the server determined that the mutable authentication data is the latest version, then the client is deemed authentic and a token is issued to the client. Depending on a set of policies, the server changes the mutable authentication data and sends the new mutable authentication data to the client but not to counterfeit clients.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

IoT device authenticated based on dynamically reconfigurable PUF and server and method for authenticating the same

An Internet of Thing (IoT) device generates a first response value corresponding to a previously registered first challenge value by using a WPUF, generates a current session key based on the first response value, transmits the current session key to an authentication server by encrypting the current session key into a first random number, receives, from the authentication server, some of a previously registered CRP transmitted by the authentication server as the authentication server authenticates the IoT device based on the first random number and the session key and a second random number, generates a second response value corresponding to a second challenge value, among the some of the CRP, by using an RPUF, authenticates the authentication server by comparing the second response value with the some of the CRP, and then updates the session key, the second challenge value, and the second response value for a next session.
Owner:ELECTRONICS & TELECOMM RES INST

Lightweight digital signature method and electronic equipment

The invention discloses a lightweight digital signature method, which is applied to a system comprising a first terminal and a second terminal, and comprises the following steps: the first terminal and the second terminal are mutually registered in a safe environment, and a first challenge response pair and a second challenge response pair which are paired are generated based on a physical unclonable function; a first challenge response pair is stored in the first terminal, and a second challenge response pair is stored in the second terminal; the first terminal constructs a signature message according to the first challenge in the first challenge response pair, and sends the signature message to the second terminal; the second terminal calculates a second verification value according to the signature message and a physical unclonable function of the second terminal, and sends the second verification value to the first terminal; and the first terminal judges whether the second verification value is consistent with the first response in the first challenge response pair, and if yes, the identity verification of the second terminal is successful. While the signature security is ensured, the calculation complexity is reduced, and direct authentication between the terminal devices is realized without server authentication.
Owner:福建福链科技有限公司

Login authentication management method and device, processor and machine readable storage medium

ActiveCN114417303BDigital data authenticationEngineeringServer authentication
The embodiment of the application provides a login authentication management method, device, processor and machine readable storage medium, and relates to the technical field of information security. The method comprises the following steps: in response to a connection request of a user terminal, obtaining a first authentication parameter and a first connection target of the user terminal; calling a server authentication file to obtain a second authentication parameter of the server authentication file; in the case that the first authentication parameter and the second authentication parameter satisfy a matching condition, obtaining login information of the first connection target and transmitting the login information to the user terminal, and the user terminal can establish a connection with the first connection target through the login information. In the application, the user terminal cannot directly obtain the login information of the connection target, so that the data security can be effectively improved, and when the login information of the connection target changes, the user terminal does not need to modify the connection code or the configuration file, and only needs to modify the login information in the configuration file on the server side.
Owner:CHINA CONSTRUCTION BANK

System and method for authentication control for content delivery

The present disclosure provides systems and methods for authentication control of content delivery. The method includes receiving a request for a content item from a computing device, the request including a security token associated with the computing device and an identifier of a domain group, identifying the domain group from the identifier, and retrieving a security key associated with the domain group. The method also includes decrypting a signature of the security token, identifying an authentication string, determining that the authentication string matches a server authentication string, and identifying a characteristic of the security token. The characteristic of the security token includes a confidence score. The method further includes comparing the confidence score of the security token to a threshold, determining that the confidence score does not exceed the threshold, and preventing the content from being sent to the computing device.
Owner:GOOGLE LLC

Authentication server, authentication system, authentication device, authentication method, and authentication program

This invention provides an authentication server, authentication system, authentication device, authentication method, and authentication program that can reduce processing load while ensuring security. [Solution] The authentication server 2 includes a processor 11 that acquires captured images and performs authentication processing. Based on processing instruction information 42, the processor selectively executes, for each frame constituting the captured image, a biometric information matching process that compares it with registered biometric information and determines whether the person to be authenticated is a registered person, a body expression matching process that determines whether the body expression of the person to be authenticated satisfies the conditions, and a liveness determination process that confirms whether it is a living being, thereby authenticating the person to be authenticated. The processing instruction information indicates whether or not the biometric information matching process, body expression matching process, and liveness determination process should be executed for each frame, and each process is set to be executed in at least one frame.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Authentication using an intermediary

Technology related to authentication using an intermediary is disclosed. In one example, a method for authentication can include intercepting a first authentication response destined for a server. The first authentication response identifies a server authentication service and is digitally signed by an identity service provider. The first authentication response can be authenticated using a cryptographic key of the identity service provider to validate an identity service provider signature included in the first authentication response. In response to validating the identity service provider signature, a second authentication response can be sent to the server that identifies the server authentication service.
Owner:F5 NETWORKS INC

Rapid privacy protection biological characteristic authentication method based on lattice password

The invention discloses a quick privacy protection biological characteristic authentication method based on a lattice password, the method comprises the steps of system initialization, key generation, user registration, user authentication and server authentication, the lattice password technology is combined with local sensitive hashing (LSH), the anti-quantum characteristic of the lattice password is utilized to guarantee data security, and the security of the system is improved. The comparison range is reduced in combination with the LSH, the authentication efficiency is improved, the problems of high privacy leakage risk, weak quantum attack resistance and low large-scale authentication efficiency in traditional biological feature authentication are solved, and the method is suitable for scenes with high requirements for privacy protection and authentication speed.
Owner:GUIZHOU DATABAO NETWORK TECH CO LTD

Online authentication for medical devices

A medical device includes a QR generator and a user access / activity log. The QR generator generates a QR code at least from a username of a user and at least one OTP (one-time password) for the user and enables access of the user to the medical device upon receiving an OTP from the user. The user sends the QR code to an online authorization server for the medical device for decryption upon authentication of the user. The log lists user activity once the user is authenticated by the server. The server receives the QR code, which includes at least an encrypted text containing at least the OTP and a user identification, and decrypts the encrypted text using a private key associated with the medical device. The authorization server enables the user to log in for authentication and, if authenticated, displays the at least one OTP to the user.
Owner:BIOSENSE WEBSTER (ISRAEL) LTD

A method for automatic IP allocation of service packets in an OpenVPN environment

This invention discloses a method for automatically allocating service packets IP addresses based on an OpenVPN environment in the field of Virtual Private Network (VPN) technology. The method includes configuring multiple first IP address pools for first ID groups based on the OpenVPN server's management interface, associating each first IP address pool with a corresponding filter ID, setting the IP range for each first IP address pool, authenticating a second ID using server authentication, and obtaining the attributes of the filter ID corresponding to the second ID after successful authentication. Based on these attributes, the method matches the corresponding IP address pool within the first IP address pools to obtain the second IP address pool. This invention achieves non-overlapping IP address allocation by developing automated CCD files as configuration scripts and combining this with matching IP addresses to the attributes of the filter IDs used for authenticated user access. This avoids conflicts and allows for the allocation of different IP segments based on the user's service packet status, effectively improving the efficiency of IP address allocation management.
Owner:SHANGHAI HENGXIANG NETWORK TECH CO LTD

Device authentication through proxy

A software-based authentication protocol enables a client to be authenticated by a server through a host. The authentication protocol involves using mutable authentication data that changes to deter counterfeiters from making clones of authentic clients. The host requests a token from the client as proof of authenticity. The client establishes a communication channel to the server using the host as a communication proxy. The client presents mutable authentication data to the server. If the server determines that the mutable authentication data is outdated, then the client is deemed a counterfeit. If the server determined that the mutable authentication data is the latest version, then the client is deemed authentic and a token is issued to the client. Depending on a set of policies, the server changes the mutable authentication data and sends the new mutable authentication data to the client but not to counterfeit clients.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A dynamic encryption authentication method and system for a fingerprint lock and a medium

The application relates to a dynamic encryption authentication method and system of a fingerprint lock and a medium, and the method comprises a registration and authentication stage. In the registration stage, real-time physical parameters of a lock body environment are collected, a dynamic environment key is generated through a chaotic mapping function, user fingerprints are obtained, core and non-core feature areas are identified, two types of areas are respectively encrypted in combination with the dynamic environment key and a user key, and registered encrypted fingerprint data is generated. The data is segmented into two data fragments by using a quantum noise source true random sequence, the first data fragment is stored in a local secure chip, and the second data fragment is stored in a cloud server after encryption. In the authentication stage, environment parameters are collected in real time to generate a verification key, which is compared with the registration key. When the two are consistent, the two fragments are recombined to restore the encrypted fingerprint data, which is authenticated with the user input fingerprint. If the authentication is successful, the lock is opened. If the authentication fails continuously and reaches a threshold value, a risk grading process is triggered. The application improves the overall security and reliability of the fingerprint lock system.
Owner:BEIJING HUAZHONG CHUANGSHI TECH DEV CO LTD

Server authentication method, electronic equipment and system

PendingCN121727855ASecuring communicationEngineeringServer authentication
The invention provides a server authentication method, electronic equipment and a server authentication system, and relates to the technical field of network security. In view of the problem that potential safety hazards are easily caused when network configuration is carried out on a client traditionally, the server authentication method provided by the invention comprises the steps that a first discovery message is broadcasted to a server in a network, the first discovery message comprises preset first authentication information, and the first authentication information is used for indicating identity information of electronic equipment; receiving a first offer message returned by the at least one server after verifying the first authentication information of the first discovery message; analyzing the first offer message, and if the first offer message contains second authentication information in a preset format, taking the server as a trusted server; wherein the intermediate device is used for sending a message to the trusted server in a unicast form and forwarding configuration parameters issued by the trusted server to the client in a unicast form, and the configuration parameters are used for performing network configuration on the client. According to the embodiment of the invention, the network security can be improved.
Owner:TP-LINK

A blockchain-based identity authentication method and system

The application discloses a kind of identity authentication method and system based on blockchain, specifically related to identity authentication security technical field, including step S01: user login request verification, step S02: user identity detection enhancement check, step S03: user identity authentication exception control, step S04: user access security evaluation data acquisition, step S05: user access security analysis, step S06: user access security evaluation, the present application collects face recognition confidence, iris matching degree, user face video stream in user login page, verifies user identity compliance, is conducive to improving the security of identity verification, improves authentication accuracy, collects the security evaluation data of authentication server in blockchain network, calculates user authentication access risk evaluation coefficient, monitors server authentication access risk, is conducive to real-time monitoring the change of server authentication access risk, effectively prevent the occurrence of security event, improve user information management efficiency.
Owner:HEZHENG TECHNOLOGY (YUNNAN) CO LTD

Systems and methods for generating a one-time use token for item purchase

Systems and methods are disclosed for payment system that uses one-time use tokens for securely facilitating and controlling user purchases using company funds. A user (e.g., driver) may generate a request to make a purchase using a user application. The request may be sent to a server running a payment system that may generate a one-time use token for the purchase of an item (e.g., fuel). The one-time use token may have an expiration time and may only be redeemable at certain locations (e.g., fueling stations) that have been preapproved. The system may send the user application running on the user device the token for purchasing fuel and approved locations. The user may input the token to a controller at an approved location which may request that the server authenticate the token and approve the purchase. Once authenticated and approved, the controller may permit the purchase of the desired item.
Owner:RELAY PAYMENTS INC

Online authentication for medical devices

A medical device includes a QR generator and a user access / activity log. The QR generator generates a QR code at least from a username of a user and at least one OTP (one-time password) for the user and enables access of the user to the medical device upon receiving an OTP from the user. The user sends the QR code to an online authorization server for the medical device for decryption upon authentication of the user. The log lists user activity once the user is authenticated by the server. The server receives the QR code, which includes at least an encrypted text containing at least the OTP and a user identification, and decrypts the encrypted text using a private key associated with the medical device. The authorization server enables the user to log in for authentication and, if authenticated, displays the at least one OTP to the user.
Owner:BIOSENSE WEBSTER (ISRAEL) LTD

Method for Registering a Mobile Device, an Embedded Universal Integrated Circuit Card, eUICC, and a Mobile Network Server

A method for registering a mobile device including an embedded Universal Integrated Circuit Card (eUICC) at a mobile network server includes determining subscriber identification information and deriving a first key. Then a registration request is sent to the mobile network server. The eUICC signs first random data with the first key and sends it to the mobile network server. The server produces a server authentication key and authenticates the eUICC, and if successful, grants limited access. The eUICC signs first or second random data with a second key and sends a registration message comprising the signed first or second random data to the mobile network server, which determines the validity of the signed first or second random data, and if valid, grants regular access to the eUICC. Further an embedded Universal Integrated Circuit Card, a mobile network server and a computer program product are disclosed.
Owner:NXP BV

Method for registering device, embedded universal integrated circuit card and server

A method for registering a mobile device including an embedded universal integrated circuit card (eUICC) at a mobile network server is disclosed. The method includes determining subscriber identification information and deriving a first key. Then, a registration request is sent to the mobile network server. And the eUICC signs first random data by using the first secret key and sends the first random data to the mobile network server. The server generates a server authentication key and authenticates the eUICC, and if successful, grants restricted access. The eUICC signs the first or second random data with a second key and sends a registration message comprising the signed first or second random data to the mobile network server, the mobile network server determines validity of the signed first or second random data, and if valid, the mobile network server sends a registration message comprising the signed first or second random data to the eUICC. And if so, granting regular access to the eUICC. Further disclosed herein are an embedded universal integrated circuit card, a mobile network server and a computer program product.
Owner:NXP BV

Home gateway anti-theft method based on PPPoE server authentication and home gateway equipment

The invention provides a home gateway anti-theft method based on PPPoE server authentication and home gateway equipment, and the method comprises the steps: embedding a two-stage verification mechanism in a PPPoE dialing process, and carrying out the matching with a legal identifier set pre-stored in a gateway based on AC Name and Service Name information in a PPPoE server reply message; the server is judged to be illegal if any level of verification fails, so that the use of the equipment in an unauthorized network is effectively prevented, the physical security of the equipment is improved, the controllability and transparency of network operation management can be enhanced, and the effect of improving the efficiency without changing the existing PPPoE protocol and server architecture is realized. The authentication can be completed only by adding identification verification and state control logic on the gateway side, and the problem that in existing PPPoE authentication, only one-way authentication can be conducted on the gateway through a server, and the gateway equipment cannot be prevented from being illegally used in an unauthorized network is solved.
Owner:CHENGDU CHANGHONG NETWORK TECH CO LTD

Authentication method and recording medium

An authentication method is performed by a device to authenticate a license of software that is installed on the device and managed by a server. The authentication method includes: presenting unique authentication information that is unique to the software; receiving input of server authentication information generated by the server based on: license information of the software managed by the server in association with the unique authentication information; and the unique authentication information; and authenticating the license of the software based on the unique authentication information and the inputted server authentication information.
Owner:PANASONIC PROJECTOR & DISPLAY CORPORATION

Server authentication method based on biometric and dynamic token

The application discloses a server authentication method based on biological characteristics and dynamic tokens, relates to the technical field of server authentication, and comprises the following steps: S1, biological characteristics and dynamic tokens are fused and registered; S2, two-way verification and authentication are performed; S3, scene-based dynamic adaptation is performed; S4, biological characteristic matching threshold time effectiveness is adjusted; S5, biological characteristics and dynamic tokens are synchronously refreshed; and S6, decay correlation permission management is performed. According to the application, biological characteristics are split into characteristic factors, and the characteristic factors are hierarchically embedded with characteristic segments of dynamic token basic keys according to weights, a unique biological characteristic and dynamic token fusion root key is generated, and the root key sub-segments are encrypted and stored in a terminal, a server and a third party by using a multi-party secret sharing mechanism, so that deep confusion fusion and distributed fault-tolerant storage of biological characteristic templates and key data are realized, and the problems that a static biological characteristic library is centralized, storage is vulnerable to library segment matching attacks, and a token key has a security risk when being stored at a single point can be solved.
Owner:BEIJING AEROSPACE LEGIONE TECH CO LTD

Identity authentication method and device in smart power grid, and storage medium

The invention discloses an identity authentication method and device in a smart power grid, and a storage medium, and relates to smart power grid terminal equipment, a power grid server and a trusted center node. The scheme comprises three stages of initialization, registration and authentication: initializing to determine hash, MAC and symmetric encryption and decryption algorithms, and establishing block chain configuration; during registration, the terminal and the server respectively generate a public key and a private key, and the {n, time, id} and the {N, time, ID} are registered to the block chain; during authentication, the server sends a public key, the terminal selects a random number and takes a timestamp after checking the validity period, calculates four modular square roots corresponding to a hash result, determines the minimum square root, and encrypts by using a shared session key to form an authentication message to be sent; the server calculates a master key according to the private key, decrypts and verifies a timestamp and on-chain registration, authenticates the terminal through a square relationship of a minimum square root and returns a response; and the terminal authenticates the server accordingly, and the two parties obtain an equal shared session key. The scheme is light in weight and efficient, and has correctness, confidentiality and integrity.
Owner:BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +2

Beacon and device location verification using broadcast location data

PCT designated stageWO2026117229A1Individual entry/exit registersAuthentication serverServer authentication
A physical access control (PAC) system includes a reader device configured to receive credential information from a credential device; a beacon transmitting device configured to transmit a beacon signal detectable by the credential device; and an mauthentication server. The authentication server includes a first communication channel configured to communicate information with the credential device; a second communication channel configured to communicate information with the reader device; and server processing circuitry. The server processing circuitry is configured to receive beacon signal information from the credential device and send beacon signal authentication information to the credential device; receive credential information from the reader device when the beacon signal is authenticated; and initiate access to a physical access portal conditional on authentication of the credential information.
Owner:ASSA ABLOY AB

Server authentication method based on biological characteristics and dynamic token

The invention discloses a server authentication method based on biological characteristics and dynamic tokens, and relates to the technical field of server authentication, and the method comprises the steps: S1, carrying out the fusion registration of the biological characteristics and the dynamic tokens; s2, bidirectional verification authentication; s3, scene-based dynamic adaptation is carried out; s4, adjusting the timeliness of a biological characteristic matching threshold value; s5, synchronously refreshing the biological characteristics and the dynamic token; and S6, controlling the attenuation association authority. According to the method, the biological characteristics are split into the characteristic factors, the characteristic factors and the characteristic fragments of the basic key of the dynamic token are layered and embedded according to the weight, the unique fusion root key of the biological characteristics and the dynamic token is generated, and the sub-fragments of the root key are encrypted and stored in the terminal, the server and the third party by adopting a multi-party secret sharing mechanism. According to the method, deep confusion and distributed fault-tolerant storage of the biological feature template and the key data are realized, and the problems that a static biological feature library is concentrated, storage is easily attacked by library segment matching, and potential safety hazards exist when token keys are stored at a single point can be solved.
Owner:BEIJING AEROSPACE LEGIONE TECH CO LTD

Subscription concealed identifier

A method performed by an authentication server (14) in a home network (3) of a user equipment (1), UE, for obtaining a subscription permanent identifier, SUPI. The method comprises: - receiving a subscription concealed identifier, SUCI, which comprises an encrypted part in which at least a part of the SUPI is encrypted, and a clear-text part which comprises a home network identifier and an encryption scheme identifier that identifies an encryption scheme used by the UE to encrypt the SUPI in the SUCI, - determining a de-concealing server (19) to use to decrypt the encrypted part of the SUCI; - sending the SUCI to the de-concealing server (19), and - receiving the SUPI in response. Methods performed by a UE and a de-concealing server are also disclosed. Furthermore, UEs, de-concealing servers, authentication servers, computer program (133) and a memory circuitry (12) are also disclosed.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Information processing system, information processing device, and information processing method

To prevent an incorrect signature in electronic signature.SOLUTION: A signature application server 40 displays a signature instruction screen including a document ID corresponding to signature target data on a signer operation terminal 13, receives a signature instruction from the signer operation terminal 13, and transmits a signature approval request including information on the document ID to an authentication and approval server 20. The authentication and approval server 20 displays a signature intention confirmation screen including the document ID on a signer approval terminal 11 upon receiving the signature approval request from the signature application server 40, and generates a token to permit use of a signature key and transmits the token to the signature application server 40 when a signature intention confirmation result is received from the signer approval terminal 11.SELECTED DRAWING: Figure 12
Owner:HITACHI LTD

Authentication method and device, storage medium and program product

The embodiment of the invention discloses an authentication method and device, a storage medium and a program product. The method is applied to a server, and comprises the steps that the server receives an authentication request from terminal equipment, the authentication request comprises an identifier of the terminal equipment and a first authentication value, and the first authentication value is generated by the terminal equipment based on the identifier and a first illumination value collected by the terminal equipment; and the server responds to the authentication request, queries a second illumination value of the geographic position registered by the terminal equipment based on the identifier, and generates a second authentication value based on the identifier and the second illumination value. Under the condition that the first authentication value is equal to the second authentication value, the server sends an authentication response to the terminal equipment, and the authentication response comprises information used for indicating that authentication of the terminal equipment is passed. The method is beneficial to improving the security of the server authentication terminal equipment.
Owner:FIBOCOM TECHNOLOGY CO LTD

System and method for automatic connection and interaction of multiple devices in local area network

The invention belongs to the technical field of communication, and discloses a system and a method for automatic connection and interaction of multiple devices in a local area network, and the method comprises the steps of device registration and identity management, active interaction trigger mechanism, server authentication and content distribution, multi-device collaborative display, state management and exception handling. Compared with other methods, the automatic connection and interaction method has the advantages that efficient and anthropomorphic interaction cooperation among multiple devices is realized through labels, service self-discovery temporary groups and server central control, and the method is applicable to scenes such as smart home, Internet of Things and games.
Owner:XIAN MURPHYS TECHNOLOGY CO LTD