Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

156 results about "Single sign-on" patented technology

Single sign-on (SSO) is a property of access control of multiple related, yet independent, software systems. With this property, a user logs in with a single ID and password to gain access to any of several related systems. It is often accomplished by using the Lightweight Directory Access Protocol (LDAP) and stored LDAP databases on (directory) servers. A simple version of single sign-on can be achieved over IP networks using cookies but only if the sites share a common DNS parent domain.

Methods and systems for facilitating single sign-on and passwordless sign-on

Computer-implemented methods and systems for facilitating single sign-on (SSO) and passwordless sign-on to a web service provider are provided. A client device authorized for SSO or passwordless sign-on generates and stores a device-specific key that it uses to encrypt a credential bundle containing key(s) necessary to access a cryptographically protected resource provided by the web service provider. The encrypted credential bundle is stored by the web service provider and provided to the authorized client device upon a successful authentication via SSO or passwordless sign-on. The authorized device uses the locally stored device-specific key to decrypt the encrypted credential bundle received from the web service provider to obtain the key(s) necessary to access the cryptographically protected resource.
Owner:AGILEBITS INC DBA 1PASSWORD

Multi-tenant data pushing method

The invention provides a multi-tenant data pushing method, and relates to the technical field of computer software and information, and the method comprises the steps: achieving unified identity authentication through single sign-on, and dynamically distributing a pushing authority based on an authority strategy; defining conversion rules and tasks by utilizing a visual interface of the low-code configuration center, and generating a standardized data packet; and centralized scheduling is carried out in a multi-tenant management and control center, and the stability of the system is guaranteed by combining a current limiting and dynamic retry mechanism. Source system data are collected in real time, and format conversion is completed through a rule engine after grammar, permission and event state verification. And pushing in an asynchronous mode, and recording full-link information including a tracking ID, a timestamp, a data fingerprint and a response state. And when pushing fails, a compensation mechanism is triggered, degradation or retry is carried out according to a preset rule, final consistency of data is ensured, and the reliability and maintainability of the system are improved.
Owner:SHENZHEN INSPUR HAIYUE HUMAN RESOURCES TECHNOLOGY CO LTD

Single sign-on method based on flow interception and voucher injection

The invention discloses a single sign-on method and system based on flow interception and credential injection, and the method comprises the steps: a user completes UKey authentication through a gateway client, a gateway generates a session bound with the client and stores the session in a Redis cluster, and a dynamic TTL mechanism renews the session according to the operation of the user; when a user accesses an application system, a gateway captures traffic through a kernel layer, and a quintuple rule and a Bloom filter are adopted to intercept malicious requests; for a logged-in user, after the gateway queries the session state, an encrypted user certificate is called and a signature is added, and a request header is injected by a zero-copy technology and then forwarded to an application server. The system comprises a gateway client, an authentication gateway, a database and an application server. According to the invention, through a cryptographic algorithm, hardware-level key management and kernel layer flow optimization, the problems of complex integration, low security and performance bottleneck of a traditional single sign-on system are solved, and zero transformation access, microsecond-level delay and financial-level security compliance are realized.
Owner:ZHONGAN WANGMAI (BEIJING) TECH CO LTD

Local account access conditioned on SSO availability

A managed device may include multiple techniques to login and use resources. One example may include a single sign-on (SSO) login procedure that utilizes an identity provider that may authenticate the user. Another example may include a local account, which may allow access by the user inputting credentials, such as a login ID and a password. The managed device may condition access to the local account based on whether the identity provider is available. If the identity provider is available, then the managed device may disallow access through the local account. However, if the identity provider is unavailable, then the managed device may allow access through the local account.
Owner:DELL PROD LP

Universal privileged access for web applications through remote browser isolation

Methods and systems of providing a universal privileged access management solution to enable users to securely share web applications through remote browser isolation (RBI). The web applications may be hosted in a SAAS (Software As A Services) cloud or in a private network. For privileged access of web applications that do not support SSO, the universal privileged access management solution implements cloud-based software services including Remote Browser Isolation (RBI), Zero Trust Network Access (ZTNA) and password vault. For privileged access of web applications that support SSO, the universal privileged access management solution implements cloud-based software services including Remote Browser Isolation (RBI) and ID brokers. In the access authentication process, by leveraging the data loss prevention (DLP) feature of RBI, the actual access credentials for accessing web applications are not disclosed to the user for mitigating security risks.
Owner:SPLASHTOP INC

Intelligent management system and method for vocational skill training

The invention discloses an intelligent management system and method for vocational skill training, and relates to the technical field of vocational skill training management systems. The system comprises a student information management subsystem which integrates biological feature recognition, a dynamic password and SSO single sign-on to realize cross-platform secure access; a personal ability graph is constructed based on behavior logs and psychological assessment data, and attribute tags of unmarked nodes are automatically expanded by using a graph neural network. According to the system, attribute tags of unmarked nodes are automatically expanded through a graph neural network, a dynamic personal ability graph is constructed in combination with behavior logs and psychological assessment data, and accurate user portraits and personalized recommendation are supported; modeling time series data by using an LSTM neural network, and quantifying an attention concentration score; and student grades are divided based on a K-means clustering algorithm, and differentiated resource packages are pushed, so that individualized teaching is realized.
Owner:SHENZHEN QINGGAN EDUCATION TECHNOLOGY CO LTD

Unified account management method and device under multi-cloud architecture

The invention provides a unified account management method and device under a multi-cloud architecture, and the method comprises the steps: constructing a globally unified account management system at a multi-cloud management platform layer, carrying out the butt joint with a plurality of heterogeneous cloud platforms through a standardized interface, building the dynamic bidirectional mapping of a cloud management layer account and a local account through an account mapping engine, and carrying out the dynamic bidirectional mapping of a cloud management layer account and a local account. A unified permission strategy is converted into a specific format of each platform through a permission converter, and atomicity of account life cycle operation is ensured through a distributed transaction coordinator. The method is also integrated with a unified authentication gateway, supports single sign-on, and realizes centralized identity authentication and access control of a plurality of cloud platforms. The method has the beneficial effects that account unified management and resource scheduling in a multi-cloud environment are realized, the resource visualization coverage rate is improved, the operation and maintenance complexity is reduced, and the management efficiency is improved.
Owner:JINAN INSPUR DATA TECH CO LTD

Method and system for expanding operator mobile phone number identification in multi-identification network system

The invention provides a method and system for expanding operator mobile phone number identification in a multi-identification network system, and the method comprises the following steps: S1, the authentication of a mobile phone number is realized through an MIN client, the mobile phone number is accessed to an MIN network, the MIN client refers to a multi-identification network system client, the MIN network refers to a multi-identification network system client, and the MIN network refers to a multi-identification network system; the network is called MIN network for short; step S2, single sign-on of the mobile phone number is realized through an MIN-SDK toolkit, wherein the MIN-SDK toolkit refers to a multi-identifier network system toolkit; s3, performing identity signature and signature verification in the MIN network; and S4, network grouping addressing is carried out in the MIN network through the mobile phone number. According to the invention, through combination of the operator mobile phone number and the MIN network, identification expansion of the operator mobile phone number can be realized, cross-domain unified identity authentication is realized, and cross-physical-space and cross-virtual-space identity and data intercommunication requirements of the mobile phone number are met.
Owner:PEKING UNIV SHENZHEN GRADUATE SCHOOL +1

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Single sign-on between 2 independent states

Systems and methods for single sign-on between two independent systems are disclosed herein. The method can include receiving a request to access a first application of a first system having a first login protocol. The method can include receiving user login credentials and authenticating the user login credentials. The method can include logging the user in to the first system and a second system based on the received login credentials. The second system can have a second login protocol independent of the first login protocol.
Owner:ORACLE INT CORP

Cross-application login, authentication and information synchronization method and system

The invention provides a cross-application login, authentication and information synchronization method and system. The method comprises the following steps: synchronizing user information to a plurality of target applications at regular time by utilizing a timer; setting a unified authentication interface and sharing the authentication information of the user to provide a single sign-on function; and providing a password-free login function through an encryption algorithm based on the authentication information of the user. According to the method, multiple authentication protocols can be integrated, unified management and login functions are realized, and an information synchronization mode is provided, so that information leakage and hostile attack are avoided, and convenience and security are improved.
Owner:SICHUAN DETUO INFORMATION TECHNOLOGY CO LTD

Single sign-on proxy

Embodiments of the present disclosure relate to single sign-on proxies. In certain examples, a method includes obtaining, at a single sign-on (SSO) proxy, an identity event associated with a user of a private cloud; requesting, by the SSO proxy in response to obtaining the identity event, a set of user information corresponding to the user from a private cloud platform corresponding to the private cloud; providing the set of user information to an identity access management (IAM) tool of the SSO proxy; and updating a realm of the IAM tool based on the set of user information to reflect the identity event.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Robot login control method and device

The invention provides a robot login control method and device, and relates to the technical field of artificial intelligence and safety. The method comprises the following steps: firstly, receiving a login URL obtaining request sent by a robot, generating a corresponding secret key for the robot, then obtaining a corresponding robot virtual job number and a business system URL based on a robot identifier and a business system identifier, generating a token obtaining request based on the robot virtual job number and the secret key, and sending the token obtaining request to a single sign-on system, the method comprises the steps of receiving a service system identifier and a service system URL, then receiving an identity token returned by a single sign-on system, generating a login URL based on the identity token, the service system identifier and the service system URL, sending the login URL to a robot, finally receiving a login verification request sent by the single sign-on system, verifying the login behavior of the robot, obtaining a verification result and sending the verification result to the single sign-on system.
Owner:PEOPLE'S INSURANCE COMPANY OF CHINA

A network security detection method, system, device and medium

The application discloses a network security detection method, system and device and a medium, relates to the field of network security, and is used for solving the problem of network risks existing in a third-party platform. The scheme receives user identity information through the third-party platform, creates a single sign-on account on a cloud platform and configures operation permissions, detects the corresponding networks of the third-party platform and the cloud platform, determines whether there is a security risk, and limits the operation permissions of the account on the cloud platform when a security risk is found, thereby reducing the influence range of the security risk. It can be seen that the application can solve the problem of network risks existing in the third-party platform, thereby improving the network security when the user logs in to the cloud platform through the third-party platform.
Owner:JINAN INSPUR DATA TECH CO LTD

Methods, systems, and apparatus, for steering traffic on a per-flow basis

Techniques for using a single sign-on (SSO) service as a software-defined networking (SDN) controller for a virtual private network environment. The techniques disclosed herein can include receiving, at a first authentication service, first data comprising a first request to authenticate a user of a client device to access an application. The techniques can also include sending, to the client device, second data representing a second request configured to prompt a second authentication service to authenticate the user of the client device. Additionally, the first authentication service can receive an indication that the user is authenticated by the second authentication service, and determine whether the client device is to access the application using a non-secure connection or, instead, using a secure connection based at least in part on attributes associated with at least one of the client device or the application.
Owner:CISCO TECHNOLOGY INC

Double Encryption Single Sign-On Method, System, Device and Medium

The present invention discloses a dual - encryption single sign - on method, system, device and medium, belonging to the field of network security and encryption technology. The technical problem to be solved by the present invention is how to improve the security of the single sign - on system, ensure the security of data transmission and the secure storage of data. The adopted technical solution is as follows: This method generates a dynamic key and uses RSA public - key encryption technology for data transmission to ensure the security of data transmission; at the same time, it uses the AES symmetric encryption algorithm to encrypt sensitive data to ensure the secure storage of data. The system includes a user client, an authentication server, a data server and a key automatic generation system. The user client, the authentication server, the data server and the key automatic generation system communicate through encrypted data transmission.
Owner:INSPUR ZHUOSHU BIG DATA IND DEV CO LTD

Single Sign-On Verification and Coordinated Management Method and Device Based on PAM Framework

The present application discloses a single sign-on verification and overall management method and device based on the PAM framework. Among them, the method includes: first determining the single sign-on type of the administrator user, and then calling the single sign-on interface corresponding to the target single sign-on type from the set of login interfaces provided by the PAM framework. The single sign-on process can be broken down into: 1. Establishing a trust relationship between the administrator user and the integrated management platform; 2. Establishing a trust relationship between the integrated management platform and the network security device; 3. Establishing a trust relationship between the administrator user and the network security device. This process is uniformly implemented using the PAM framework, and solutions such as the CAS server, certificate, independent password, TOKEN, etc. can be selected. Resource unified allocation is carried out based on the SSO type library, docking platform library, and user library, and the processing and verification functions are completed based on the service provider interface SPI of the PAM framework, solving the technical problem that it is difficult for the prior art to provide compatibility verification for multi-type single sign-on SSO solutions.
Owner:HILLSTONE NETWORKS CO LTD

Single Sign-On Method, Device, Non-Volatile Storage Medium, and Processor

The present application discloses a single sign-on method, device, non-volatile storage medium, and processor. Among them, the method includes: receiving a single sign-on request of a target object, where the single sign-on request carries a single-point ciphertext and a key identifier, the single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; querying a target key indicated by the key identifier in a first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key; decrypting the single-point ciphertext based on the target key to obtain a single-point ticket; performing a uniqueness verification on the single-point ticket, where if the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request. The present application solves the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service.
Owner:CHINA TELECOM CORP LTD

Single sign-on method and system for shared terminal equipment

The invention relates to the field of network communication, and provides a single sign-on method and system for shared terminal equipment. The method comprises the following steps: performing security packaging on first equipment identity data of terminal equipment through a national secret encryption algorithm to generate a dynamic authentication code; identifying and analyzing the dynamic authentication code through a user side application, executing password-free verification on the identity of the user side, and establishing secure binding between the terminal equipment and the identity of the user; reporting second equipment identity data of the terminal equipment to a cloud authority control center, and constructing a network environment feature library; when it is detected that the network environment feature change exceeds a preset security threshold, performing multi-factor identity authentication on the identity of the user side; and when the verification is passed, embedding the session security identifier into the transmission protocol extension field through the gateway service, and establishing an end-to-end trusted transmission link. According to the invention, the convenience of single sign-on is improved, and the user experience and safety are improved.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

Transformed link for automatically providing access of a protected resource accessible to a different instance

In the present application, improved techniques of a provider instance providing a customer instance access to resources on an ITSM platform are disclosed. A link to a protected resource is generated by a first instance. In response to determining that the link is being transmitted to a user of a second instance different from the first instance, the link is converted into a transformed link comprising an application programming interface (API) call. In response to the user of the second instance interacting with the transformed link, the API call is received. Based on the API call, it is determined that the user is authorized to access the protected resource. In response to determining that the user is authorized to access the protected resource, the user of the second instance is provided a uniform resource locator (URL) to access a time-based single sign-on (SSO) page for accessing the protected resource.
Owner:SERVICENOW INC

Systems and methods for single sign on (SSO) redirecting in the presence of multiple service providers for a cloud service

The present disclosure relates to systems and methods for SSO redirecting. More particularly, for identifying and authenticating a user via the user's specific service provider. A user intending to establish a connection between two cloud services, where the user is subscribed to a specific service provider in one cloud service, must provide identity authentication and consent to the cloud service. The processes described herein provide the user with an authentication token supplied by the user's specific service provider associated with a first cloud service. Utilizing the authentication token, the token being entered into a URL opened within the second cloud service, the first cloud service can identify the service provider with which the user is associated, and provide the user with means of identification authentication. Further, the URL provides the first cloud service with information for the connection to the second cloud service.
Owner:PLUME DESIGN INC

Single sign-on method for heterogeneous system, heterogeneous system and computing device cluster

The invention belongs to the technical field of distributed system security, particularly relates to a single sign-on method for a heterogeneous system, the heterogeneous system and a computing device cluster, and aims to solve the problem of improving the single sign-on operation convenience and security of the heterogeneous system. The method comprises the following steps that: a subsystem obtains a mobile phone number input by a user through primary login, associates the mobile phone number with a local account registered in the subsystem by the user, and synchronizes the mobile phone number to a single sign-on system; the single sign-on system generates a globally unique single sign-on identifier according to the mobile phone number, binds the single sign-on identifier with the mobile phone number, associates the single sign-on identifier with a local account of the subsystem and a code of the subsystem, and synchronizes the single sign-on identifier to the subsystem; and the subsystem receives the synchronized single sign-on identifier, establishes a mapping relation between the single sign-on identifier and the local account and stores the mapping relation. Therefore, decentralized authentication and unified authentication of the heterogeneous system are realized, and the user experience and security of the heterogeneous system are improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Unified workspace for thin, remote, and SAAS applications

Application-manager software authenticates a user of a client device over a channel. The authentication operation is performed using a directory service. The application-manager software presents a plurality of applications in a GUI displayed by the client device. The plurality of applications depends on the authentication, the client device, and the channel. And the plurality of applications includes a thin application and a software-as-a-service (SaaS) application. The application-manager software receives a selection as to an application from the user. If the selection is for the SaaS application, the application-manager software provisions the SaaS application. The provision includes automatically logging the user onto an account with a provider of the SaaS application using a single sign-on and connecting the user to the account so that the user can interact with the SaaS application. If the selection is for the thin application, the application manager software launches the thin application.
Owner:OMNISSA LLC

A single sign-on authentication method supporting cross-platform and multi-host operation

This invention relates to a single sign-on authentication method supporting cross-platform, multi-host operation, belonging to the field of computer security. This invention connects multiple terminal computers in the same location to an authentication device via USB interfaces, enabling synchronous authentication and locking of multiple computers and sharing authentication information. After a user completes authentication with an authentication server on one host, the authentication information generated by the server is encrypted and stored in the authentication device. Other computers complete operating system authentication by reading the authentication information from the authentication device, thus ensuring the consistency and continuity of the authentication process between the host and backup machines. Furthermore, once one computer is locked, other computers are locked simultaneously. When the host machine fails, the backup machine can continue to process business without requiring re-authentication, ensuring system continuity and availability.
Owner:BEIJING INST OF COMP TECH & APPL

Single sign-on method and system and storage medium

The invention provides a single sign-on method and system and a storage medium. An OIDC service, a first micro-service and a second micro-service are deployed at a management node where a target platform is located; in response to a received unified authentication instruction that the user triggers the target platform, the OIDC service obtains login information input by the user through the target login page, and verifies the login information; when the verification is passed, the OIDC service feeds back account information and first role information of the user; the first micro-service reads a role mapping relation from the second micro-service and determines second role information corresponding to the first role information based on the role mapping relation, and the second role information is used for indicating a role of the user in the target platform; and logging in the target platform based on the account information and the second role information. The method supports automatic mapping of the platform role and the system role, facilitates butt joint of the client system and the target platform, is convenient for users to use, and improves the working efficiency.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Plug and play OAuth2 single sign-on authentication service system and method

ActiveCN121530766BStable and reliable background supportAchieve seamless interactionUser identity/authority verificationEngineeringAccess token
The application relates to the technical field of single sign-on, in particular to a plug-and-play OAuth2 single sign-on authentication service system and method, which comprises the following steps: redirecting to a client according to a login address carrying an authorization code preset by the client; after receiving the authorization code, automatically calling a token interface of an authentication center system to obtain an OAuth2 token, calling a token generation interface provided by an original system by a plug-in client jar package, and obtaining an original system token based on user information in the OAuth2 token; the plug-in client jar package establishes a bidirectional mapping relationship between an OAuth2 access token and an original system access token and between an OAuth2 refresh token and an original system refresh token, and stores the tokens in Redis; and when the OAuth2 token state changes, synchronously updating the original system token state based on the mapping relationship in Redis. The method does not need to make large-scale modification on an existing business system, and reduces integration cost and development difficulty.
Owner:NORTH CHINA DIGITAL HEALTH TECHNOLOGY CO LTD

Single sign-on authentication for API invokers in CAPIF

Single sign-on authentication of application programming interface invokers in a CAPIF system. using a Resource Owner Function (ROF), and an API Exposing Function. The methods allow an API invoker to
Owner:NOKIA TECHNOLOGIES OY

Security analysis of diverse identity provider and single sign-on configurations

The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC

A mobile terminal single sign-on method, device, storage medium, equipment and product

The application relates to the technical field of single sign-on, and particularly provides a mobile terminal single sign-on method, device, storage medium, equipment and product. The method is applied to an identity authentication terminal and comprises the following steps: receiving authorization application information sent by a client, wherein the authorization application information comprises login token ciphertext, a business identifier of a third-party business system and an interface input parameter signature value; generating authorization information after confirming that the authorization application information passes verification, wherein the authorization information comprises an address of the third-party business system and an authorization code; and sending the authorization information to the client, so that the client accesses the third-party business system through the address and the authorization code, and the third-party business system acquires user information through the authorization code. The embodiment of the application solves the problem that a user needs to repeatedly log in when logging in to a third-party business system due to the fact that a mobile terminal does not have cached data.
Owner:BEIJING BIG DATA CENT

Single sign-on method, device and equipment based on browser and storage medium

The invention discloses a single sign-on method and device based on a browser, equipment and a storage medium, and relates to the technical field of data security. The method is applied to an identity authentication module in a browser login system. The browser login system further comprises a user login module and a service management module. The method comprises the following steps: when user authentication data sent by a user login module is received, performing user identity verification on the user authentication data; determining user authorization data of the user according to the user authentication data under the condition of identifying that the user identity verification is passed; and sending the user authorization data to the service management module, so that the service management module determines accessible data of the user according to the user authorization data, and feeds back the accessible data to the user login module. According to the technical scheme, through automatic identification and authentication of the identity authentication module, non-perceptual access of the user to the service system is realized, and the security of the service system is improved.
Owner:BEIJING JUHARD TECHNOLOGY CO LTD