Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

115 results about "Single sign-on" patented technology

Single sign-on (SSO) is a property of access control of multiple related, yet independent, software systems. With this property, a user logs in with a single ID and password to gain access to any of several related systems. It is often accomplished by using the Lightweight Directory Access Protocol (LDAP) and stored LDAP databases on (directory) servers. A simple version of single sign-on can be achieved over IP networks using cookies but only if the sites share a common DNS parent domain.

Multi-tenant data pushing method

The invention provides a multi-tenant data pushing method, and relates to the technical field of computer software and information, and the method comprises the steps: achieving unified identity authentication through single sign-on, and dynamically distributing a pushing authority based on an authority strategy; defining conversion rules and tasks by utilizing a visual interface of the low-code configuration center, and generating a standardized data packet; and centralized scheduling is carried out in a multi-tenant management and control center, and the stability of the system is guaranteed by combining a current limiting and dynamic retry mechanism. Source system data are collected in real time, and format conversion is completed through a rule engine after grammar, permission and event state verification. And pushing in an asynchronous mode, and recording full-link information including a tracking ID, a timestamp, a data fingerprint and a response state. And when pushing fails, a compensation mechanism is triggered, degradation or retry is carried out according to a preset rule, final consistency of data is ensured, and the reliability and maintainability of the system are improved.
Owner:SHENZHEN INSPUR HAIYUE HUMAN RESOURCES TECHNOLOGY CO LTD

Intelligent management system and method for vocational skill training

The invention discloses an intelligent management system and method for vocational skill training, and relates to the technical field of vocational skill training management systems. The system comprises a student information management subsystem which integrates biological feature recognition, a dynamic password and SSO single sign-on to realize cross-platform secure access; a personal ability graph is constructed based on behavior logs and psychological assessment data, and attribute tags of unmarked nodes are automatically expanded by using a graph neural network. According to the system, attribute tags of unmarked nodes are automatically expanded through a graph neural network, a dynamic personal ability graph is constructed in combination with behavior logs and psychological assessment data, and accurate user portraits and personalized recommendation are supported; modeling time series data by using an LSTM neural network, and quantifying an attention concentration score; and student grades are divided based on a K-means clustering algorithm, and differentiated resource packages are pushed, so that individualized teaching is realized.
Owner:SHENZHEN QINGGAN EDUCATION TECHNOLOGY CO LTD

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Cross-application login, authentication and information synchronization method and system

The invention provides a cross-application login, authentication and information synchronization method and system. The method comprises the following steps: synchronizing user information to a plurality of target applications at regular time by utilizing a timer; setting a unified authentication interface and sharing the authentication information of the user to provide a single sign-on function; and providing a password-free login function through an encryption algorithm based on the authentication information of the user. According to the method, multiple authentication protocols can be integrated, unified management and login functions are realized, and an information synchronization mode is provided, so that information leakage and hostile attack are avoided, and convenience and security are improved.
Owner:SICHUAN DETUO INFORMATION TECHNOLOGY CO LTD

Single sign-on proxy

Embodiments of the present disclosure relate to single sign-on proxies. In certain examples, a method includes obtaining, at a single sign-on (SSO) proxy, an identity event associated with a user of a private cloud; requesting, by the SSO proxy in response to obtaining the identity event, a set of user information corresponding to the user from a private cloud platform corresponding to the private cloud; providing the set of user information to an identity access management (IAM) tool of the SSO proxy; and updating a realm of the IAM tool based on the set of user information to reflect the identity event.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Robot login control method and device

The invention provides a robot login control method and device, and relates to the technical field of artificial intelligence and safety. The method comprises the following steps: firstly, receiving a login URL obtaining request sent by a robot, generating a corresponding secret key for the robot, then obtaining a corresponding robot virtual job number and a business system URL based on a robot identifier and a business system identifier, generating a token obtaining request based on the robot virtual job number and the secret key, and sending the token obtaining request to a single sign-on system, the method comprises the steps of receiving a service system identifier and a service system URL, then receiving an identity token returned by a single sign-on system, generating a login URL based on the identity token, the service system identifier and the service system URL, sending the login URL to a robot, finally receiving a login verification request sent by the single sign-on system, verifying the login behavior of the robot, obtaining a verification result and sending the verification result to the single sign-on system.
Owner:PEOPLE'S INSURANCE COMPANY OF CHINA

A network security detection method, system, device and medium

The application discloses a network security detection method, system and device and a medium, relates to the field of network security, and is used for solving the problem of network risks existing in a third-party platform. The scheme receives user identity information through the third-party platform, creates a single sign-on account on a cloud platform and configures operation permissions, detects the corresponding networks of the third-party platform and the cloud platform, determines whether there is a security risk, and limits the operation permissions of the account on the cloud platform when a security risk is found, thereby reducing the influence range of the security risk. It can be seen that the application can solve the problem of network risks existing in the third-party platform, thereby improving the network security when the user logs in to the cloud platform through the third-party platform.
Owner:JINAN INSPUR DATA TECH CO LTD

Methods, systems, and apparatus, for steering traffic on a per-flow basis

Techniques for using a single sign-on (SSO) service as a software-defined networking (SDN) controller for a virtual private network environment. The techniques disclosed herein can include receiving, at a first authentication service, first data comprising a first request to authenticate a user of a client device to access an application. The techniques can also include sending, to the client device, second data representing a second request configured to prompt a second authentication service to authenticate the user of the client device. Additionally, the first authentication service can receive an indication that the user is authenticated by the second authentication service, and determine whether the client device is to access the application using a non-secure connection or, instead, using a secure connection based at least in part on attributes associated with at least one of the client device or the application.
Owner:CISCO TECHNOLOGY INC

Single sign-on method and system for shared terminal equipment

The invention relates to the field of network communication, and provides a single sign-on method and system for shared terminal equipment. The method comprises the following steps: performing security packaging on first equipment identity data of terminal equipment through a national secret encryption algorithm to generate a dynamic authentication code; identifying and analyzing the dynamic authentication code through a user side application, executing password-free verification on the identity of the user side, and establishing secure binding between the terminal equipment and the identity of the user; reporting second equipment identity data of the terminal equipment to a cloud authority control center, and constructing a network environment feature library; when it is detected that the network environment feature change exceeds a preset security threshold, performing multi-factor identity authentication on the identity of the user side; and when the verification is passed, embedding the session security identifier into the transmission protocol extension field through the gateway service, and establishing an end-to-end trusted transmission link. According to the invention, the convenience of single sign-on is improved, and the user experience and safety are improved.
Owner:E-SURFING DIGITAL LIFE TECH CO LTD

Transformed link for automatically providing access of a protected resource accessible to a different instance

In the present application, improved techniques of a provider instance providing a customer instance access to resources on an ITSM platform are disclosed. A link to a protected resource is generated by a first instance. In response to determining that the link is being transmitted to a user of a second instance different from the first instance, the link is converted into a transformed link comprising an application programming interface (API) call. In response to the user of the second instance interacting with the transformed link, the API call is received. Based on the API call, it is determined that the user is authorized to access the protected resource. In response to determining that the user is authorized to access the protected resource, the user of the second instance is provided a uniform resource locator (URL) to access a time-based single sign-on (SSO) page for accessing the protected resource.
Owner:SERVICENOW INC

Systems and methods for single sign on (SSO) redirecting in the presence of multiple service providers for a cloud service

The present disclosure relates to systems and methods for SSO redirecting. More particularly, for identifying and authenticating a user via the user's specific service provider. A user intending to establish a connection between two cloud services, where the user is subscribed to a specific service provider in one cloud service, must provide identity authentication and consent to the cloud service. The processes described herein provide the user with an authentication token supplied by the user's specific service provider associated with a first cloud service. Utilizing the authentication token, the token being entered into a URL opened within the second cloud service, the first cloud service can identify the service provider with which the user is associated, and provide the user with means of identification authentication. Further, the URL provides the first cloud service with information for the connection to the second cloud service.
Owner:PLUME DESIGN INC

Single sign-on method for heterogeneous system, heterogeneous system and computing device cluster

The invention belongs to the technical field of distributed system security, particularly relates to a single sign-on method for a heterogeneous system, the heterogeneous system and a computing device cluster, and aims to solve the problem of improving the single sign-on operation convenience and security of the heterogeneous system. The method comprises the following steps that: a subsystem obtains a mobile phone number input by a user through primary login, associates the mobile phone number with a local account registered in the subsystem by the user, and synchronizes the mobile phone number to a single sign-on system; the single sign-on system generates a globally unique single sign-on identifier according to the mobile phone number, binds the single sign-on identifier with the mobile phone number, associates the single sign-on identifier with a local account of the subsystem and a code of the subsystem, and synchronizes the single sign-on identifier to the subsystem; and the subsystem receives the synchronized single sign-on identifier, establishes a mapping relation between the single sign-on identifier and the local account and stores the mapping relation. Therefore, decentralized authentication and unified authentication of the heterogeneous system are realized, and the user experience and security of the heterogeneous system are improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Unified workspace for thin, remote, and SAAS applications

Application-manager software authenticates a user of a client device over a channel. The authentication operation is performed using a directory service. The application-manager software presents a plurality of applications in a GUI displayed by the client device. The plurality of applications depends on the authentication, the client device, and the channel. And the plurality of applications includes a thin application and a software-as-a-service (SaaS) application. The application-manager software receives a selection as to an application from the user. If the selection is for the SaaS application, the application-manager software provisions the SaaS application. The provision includes automatically logging the user onto an account with a provider of the SaaS application using a single sign-on and connecting the user to the account so that the user can interact with the SaaS application. If the selection is for the thin application, the application manager software launches the thin application.
Owner:OMNISSA LLC

A single sign-on authentication method supporting cross-platform and multi-host operation

This invention relates to a single sign-on authentication method supporting cross-platform, multi-host operation, belonging to the field of computer security. This invention connects multiple terminal computers in the same location to an authentication device via USB interfaces, enabling synchronous authentication and locking of multiple computers and sharing authentication information. After a user completes authentication with an authentication server on one host, the authentication information generated by the server is encrypted and stored in the authentication device. Other computers complete operating system authentication by reading the authentication information from the authentication device, thus ensuring the consistency and continuity of the authentication process between the host and backup machines. Furthermore, once one computer is locked, other computers are locked simultaneously. When the host machine fails, the backup machine can continue to process business without requiring re-authentication, ensuring system continuity and availability.
Owner:BEIJING INST OF COMP TECH & APPL

Plug and play OAuth2 single sign-on authentication service system and method

ActiveCN121530766BStable and reliable background supportAchieve seamless interactionUser identity/authority verificationEngineeringAccess token
The application relates to the technical field of single sign-on, in particular to a plug-and-play OAuth2 single sign-on authentication service system and method, which comprises the following steps: redirecting to a client according to a login address carrying an authorization code preset by the client; after receiving the authorization code, automatically calling a token interface of an authentication center system to obtain an OAuth2 token, calling a token generation interface provided by an original system by a plug-in client jar package, and obtaining an original system token based on user information in the OAuth2 token; the plug-in client jar package establishes a bidirectional mapping relationship between an OAuth2 access token and an original system access token and between an OAuth2 refresh token and an original system refresh token, and stores the tokens in Redis; and when the OAuth2 token state changes, synchronously updating the original system token state based on the mapping relationship in Redis. The method does not need to make large-scale modification on an existing business system, and reduces integration cost and development difficulty.
Owner:NORTH CHINA DIGITAL HEALTH TECHNOLOGY CO LTD

Single sign-on authentication for API invokers in CAPIF

Single sign-on authentication of application programming interface invokers in a CAPIF system. using a Resource Owner Function (ROF), and an API Exposing Function. The methods allow an API invoker to
Owner:NOKIA TECHNOLOGIES OY

Security analysis of diverse identity provider and single sign-on configurations

The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC

A mobile terminal single sign-on method, device, storage medium, equipment and product

The application relates to the technical field of single sign-on, and particularly provides a mobile terminal single sign-on method, device, storage medium, equipment and product. The method is applied to an identity authentication terminal and comprises the following steps: receiving authorization application information sent by a client, wherein the authorization application information comprises login token ciphertext, a business identifier of a third-party business system and an interface input parameter signature value; generating authorization information after confirming that the authorization application information passes verification, wherein the authorization information comprises an address of the third-party business system and an authorization code; and sending the authorization information to the client, so that the client accesses the third-party business system through the address and the authorization code, and the third-party business system acquires user information through the authorization code. The embodiment of the application solves the problem that a user needs to repeatedly log in when logging in to a third-party business system due to the fact that a mobile terminal does not have cached data.
Owner:BEIJING BIG DATA CENT

Authority management system based on cloud workbench

The invention discloses an authority management system based on a cloud workbench. The authority management system comprises an authority management module, a data control module and a single sign-on management module, the authority management module is used for dynamically adjusting and managing the authority used by the user according to the attribute of the user; the data control module is used for encrypting the data, transmitting the data and storing the data; and the single sign-on management module is used for carrying out one-time identification on user sign-on. According to the method, the RBAC and the ABAC are combined, so that dynamic permission allocation based on roles and user attributes is realized, permission management is finer, and enterprises are helped to meet industrial compliance requirements such as GDPR and HIPAA; and detailed authority operation logs are provided, so that safety audit and problem tracking are facilitated.
Owner:QIMING INFORMATION TECH

Blockchain-based multi-warehouse standardized integration management system and control method

The application discloses a kind of based on blockchain's multi-warehouse standardization integrated management system and control method, including the warehouse management subsystem for corresponding different warehouse control hardware of multiple warehouses;For the information standardization subsystem of the unified information standardization of multiple warehouses;For the business data collection of multiple warehouse management subsystem, multi-class statistics, query sharing, cross-library scheduling, inventory check, procurement plan and intelligent scheduling control algorithm Intelligent warehouse collaborative management subsystem;For the distributed blockchain subsystem of the business data cooperation of multiple warehouses;For the single sign-on subsystem of the unified login of multiple warehouse managers;For the central database of the management data collection of multiple warehouses, including user and standard data.The application realizes integrated, standardization, intelligent management and control by the technical trust mechanism of distributed blockchain, can guarantee that the warehouse business of original each warehouse is managed alone, and can realize the collaborative scheduling management of multiple warehouses.
Owner:SOUTHWEST JIAOTONG UNIV

Product scheme generation method and device, equipment, medium and product

The embodiment of the invention provides a product scheme generation method and device, equipment, a medium and a product, and belongs to the technical field of computer application. The method comprises the following steps: calling a domain-driven design model to generate a business process, corresponding to a business scene, of a target product according to the business scene corresponding to the target product; extracting each system function menu required by the target product from the business process; the authority of the system corresponding to each system function menu is broken through through a single sign-on technology, and the system function menus are combined to obtain an integration process of the target product; performing multiple rounds of conversations based on the integration process through the intelligent assistant to obtain a target product scheme of the target product; wherein the intelligent assistant is obtained by training the intelligent large model based on the product field data corresponding to the target product. The method and the device can be applied to business scenes such as financial science and technology, medical health and the like, and can improve the generation efficiency of the product scheme.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD

Safety operation and maintenance method and device

The invention aims to provide a remote security operation and maintenance method and device based on a client. A login user can normally call a target application in a local computer and transmit parameters after clicking a local client button of host operation and maintenance; the single sign-on device can modify a default path for a user to customize and select an application path; meanwhile, the operation and maintenance application installed on the application server can be awakened through the application loader, and application management is simplified; and the operation and maintenance safety and the auditing efficiency can be improved.
Owner:XIAN JIAODA JIEPU NETWORK SCI & TECH CO LTD

Single sign-on method and device, medium and product

PendingCN121509063ASecuring communicationEngineeringLogin Name
The invention provides a single sign-on method and device, a medium and a product. The method comprises the following steps: receiving a query request sent by a target end; the query request comprises a source end identifier of a source end, a source end user login name and a target end identifier of a target end; querying an adjacency list based on the source end identifier, the source end user login name and the target end identifier to obtain a target end user login name; the adjacency list comprises a user mapping relation between a source end user of the source end and a target end user of the target end; sending the user login name of the target end to the target end; the target end user login name is used for the source end user to complete single sign-on to the target end.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Service access method and device based on single sign-on, equipment and storage medium

The invention relates to a service access method and device based on single sign-on, equipment and a storage medium. The method comprises the following steps: receiving an access request of a user terminal for a target service, wherein the access request comprises a URL parameter corresponding to the target service; when it is detected that the user terminal is in a non-login state, generating a login authentication request according to the URL parameter and the SAML request message; obtaining a login authentication result in response to the login authentication request; and after the validity verification of the login authentication result is passed, generating a one-time voucher, so that the user terminal accesses the target service based on the one-time voucher. According to the scheme provided by the invention, safe and seamless service access can be realized in a distributed SSO environment.
Owner:GUANGDONG ESHORE TECH

System single sign-on method, device, equipment and medium

The invention discloses a system single sign-on method and device, equipment and a medium, relates to the technical field of computers, is applied to a front-end page, and comprises the following steps: receiving initial configuration information sent by an operation end; encrypting a user name and a password in the initial configuration information to obtain target configuration information, and storing the target configuration information to a database; the target configuration information comprises a protocol, a port, a login address suffix, an encrypted user name, an encrypted password and each CSS selector; obtaining target configuration information of the target system from the database, and decrypting the encrypted user name and the encrypted password in the target configuration information through the target browser plug-in to obtain decrypted information; and determining a user name input box, a password input box and a login button corresponding to the login page of the target system through the CSS selector, and completing automatic login of the target system based on the decrypted information, the user name input box, the password input box and the login button. And single sign-on of the target system is realized.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Single sign-on method and system based on Micro SaaS form filling

The present disclosure provides a single sign-on method and system based on Micro SaaS form filling, comprising: receiving a login request for a business system, wherein the business system includes several business subsystems, and the login request includes a current user identity identifier; obtaining the current user's account and password information from a unified authentication center based on the user identity identifier; wherein the unified authentication center stores the account and password information of registered users; based on the obtained account and password information, using the Micro SaaS form filling method to realize login to different business subsystems in the business system.
Owner:SHANDONG EVAYINFO TECH CO LTD

Enterprise multi-technology core and subscriber management

A method, system, and computer readable medium are disclosed for providing enterprise multi-technology core and subscriber management. In one embodiment a method includes providing an enterprise network including: at least one Open connect Provider (OP); at least one Access Point (AP) in communication with at least one OP; a locally placed edge core in communication with at least one AP; and using a single sign on service for the edge core to allow different services to be used by different users.
Owner:PARALLEL WIRELESS INC

Integration of identity access management infrastructure with zero-knowledge services

A system and method for protecting user data using a key escrow service. The key escrow service may be hosted by a service provider to integrate Identity Access Management (IAM) solutions, such as Single-Sign-On (SSO) and / or System for Cross-domain Identity Management (SCIM), with a zero-knowledge service, such as a password manager or other service handling sensitive user data. In examples, secure enclave technology may be used to allow the service provider to host and manage the key escrow service without being able to access any cryptographic key used and / or stored within a secure enclave. Accordingly, in some aspects, the service provider may have the ability to store users' secret keys for SSO and sharing keys for SCIM in a trusted, secure storage location without breaking the zero-knowledge principles of the infrastructure.
Owner:DASHLANE

Cross-platform single sign-on seamless migration method

The invention relates to a cross-platform single sign-on seamless migration method. The method comprises the following steps: S1, a client application initiates a sign-on request to an authentication center; s2, after receiving the request, the authentication center firstly verifies the identity of the user, and meanwhile, the authentication center creates an initial session and binds the initial session; s3, the client persists part of session data to the cloud for caching in real time through a Session synchronization service; s4, the user selects cross-terminal non-inductive login to call the migration process at the new terminal, and the new terminal submits the obtained migration voucher to the authentication center to initiate a session takeover application; s5, the authentication center verifies the legality of the migration voucher, after verification is passed, a new group of Access Token and Refresh Token is generated, the original session state is synchronized to the new end, and a new session and the original session are bound or coexist in parallel; and S6, after the APP end receives the new Token information, a local Session environment is automatically reconstructed, original end session data is pulled at the same time, and the operation process is seamlessly continued. According to the invention, cross-platform seamless migration of the user session and the service state is realized.
Owner:SICHUAN ZHONGDIAN AOSTAR INFORMATION TECHNOLOGIES CO LTD

Single sign-on between 2 independent states

Systems and methods for single sign-on between two independent systems are disclosed herein. The method can include receiving a request to access a first application of a first system having a first login protocol. The method can include receiving user login credentials and authenticating the user login credentials. The method can include logging the user in to the first system and a second system based on the received login credentials. The second system can have a second login protocol independent of the first login protocol.
Owner:ORACLE INT CORP