Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

57 results about "Single sign-on" patented technology

Single sign-on (SSO) is a property of access control of multiple related, yet independent, software systems. With this property, a user logs in with a single ID and password to gain access to any of several related systems. It is often accomplished by using the Lightweight Directory Access Protocol (LDAP) and stored LDAP databases on (directory) servers. A simple version of single sign-on can be achieved over IP networks using cookies but only if the sites share a common DNS parent domain.

Intelligent management system and method for vocational skill training

The invention discloses an intelligent management system and method for vocational skill training, and relates to the technical field of vocational skill training management systems. The system comprises a student information management subsystem which integrates biological feature recognition, a dynamic password and SSO single sign-on to realize cross-platform secure access; a personal ability graph is constructed based on behavior logs and psychological assessment data, and attribute tags of unmarked nodes are automatically expanded by using a graph neural network. According to the system, attribute tags of unmarked nodes are automatically expanded through a graph neural network, a dynamic personal ability graph is constructed in combination with behavior logs and psychological assessment data, and accurate user portraits and personalized recommendation are supported; modeling time series data by using an LSTM neural network, and quantifying an attention concentration score; and student grades are divided based on a K-means clustering algorithm, and differentiated resource packages are pushed, so that individualized teaching is realized.
Owner:SHENZHEN QINGGAN EDUCATION TECHNOLOGY CO LTD

System and method for using client-based login certificates for remote applications

A system and method for providing a single sign-on for connecting a client device to a virtual infrastructure. The virtual infrastructure includes a server, an enterprise connector and a certificate authority. The client device receives an identity provider (IdP) token obtained from an IdP on authenticating a user of the client device. On authentication of the user, a desktop client application on the client device sends a request through the enterprise authority for a login certificate. A login certificate generated by the certificate authority is received by the client device. The login certificate to the client device is sent to the virtual infrastructure to allow the client device a connection to a virtual machine of the virtual infrastructure.
Owner:WORKSPOT INC

Single sign-on proxy

Embodiments of the present disclosure relate to single sign-on proxies. In certain examples, a method includes obtaining, at a single sign-on (SSO) proxy, an identity event associated with a user of a private cloud; requesting, by the SSO proxy in response to obtaining the identity event, a set of user information corresponding to the user from a private cloud platform corresponding to the private cloud; providing the set of user information to an identity access management (IAM) tool of the SSO proxy; and updating a realm of the IAM tool based on the set of user information to reflect the identity event.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Robot login control method and device

The invention provides a robot login control method and device, and relates to the technical field of artificial intelligence and safety. The method comprises the following steps: firstly, receiving a login URL obtaining request sent by a robot, generating a corresponding secret key for the robot, then obtaining a corresponding robot virtual job number and a business system URL based on a robot identifier and a business system identifier, generating a token obtaining request based on the robot virtual job number and the secret key, and sending the token obtaining request to a single sign-on system, the method comprises the steps of receiving a service system identifier and a service system URL, then receiving an identity token returned by a single sign-on system, generating a login URL based on the identity token, the service system identifier and the service system URL, sending the login URL to a robot, finally receiving a login verification request sent by the single sign-on system, verifying the login behavior of the robot, obtaining a verification result and sending the verification result to the single sign-on system.
Owner:PEOPLE'S INSURANCE COMPANY OF CHINA

Methods, systems, and apparatus, for steering traffic on a per-flow basis

Techniques for using a single sign-on (SSO) service as a software-defined networking (SDN) controller for a virtual private network environment. The techniques disclosed herein can include receiving, at a first authentication service, first data comprising a first request to authenticate a user of a client device to access an application. The techniques can also include sending, to the client device, second data representing a second request configured to prompt a second authentication service to authenticate the user of the client device. Additionally, the first authentication service can receive an indication that the user is authenticated by the second authentication service, and determine whether the client device is to access the application using a non-secure connection or, instead, using a secure connection based at least in part on attributes associated with at least one of the client device or the application.
Owner:CISCO TECHNOLOGY INC

Systems and methods for single sign on (SSO) redirecting in the presence of multiple service providers for a cloud service

The present disclosure relates to systems and methods for SSO redirecting. More particularly, for identifying and authenticating a user via the user's specific service provider. A user intending to establish a connection between two cloud services, where the user is subscribed to a specific service provider in one cloud service, must provide identity authentication and consent to the cloud service. The processes described herein provide the user with an authentication token supplied by the user's specific service provider associated with a first cloud service. Utilizing the authentication token, the token being entered into a URL opened within the second cloud service, the first cloud service can identify the service provider with which the user is associated, and provide the user with means of identification authentication. Further, the URL provides the first cloud service with information for the connection to the second cloud service.
Owner:PLUME DESIGN INC

Unified workspace for thin, remote, and SAAS applications

Application-manager software authenticates a user of a client device over a channel. The authentication operation is performed using a directory service. The application-manager software presents a plurality of applications in a GUI displayed by the client device. The plurality of applications depends on the authentication, the client device, and the channel. And the plurality of applications includes a thin application and a software-as-a-service (SaaS) application. The application-manager software receives a selection as to an application from the user. If the selection is for the SaaS application, the application-manager software provisions the SaaS application. The provision includes automatically logging the user onto an account with a provider of the SaaS application using a single sign-on and connecting the user to the account so that the user can interact with the SaaS application. If the selection is for the thin application, the application manager software launches the thin application.
Owner:OMNISSA LLC

Plug and play OAuth2 single sign-on authentication service system and method

ActiveCN121530766BStable and reliable background supportAchieve seamless interactionUser identity/authority verificationEngineeringAccess token
The application relates to the technical field of single sign-on, in particular to a plug-and-play OAuth2 single sign-on authentication service system and method, which comprises the following steps: redirecting to a client according to a login address carrying an authorization code preset by the client; after receiving the authorization code, automatically calling a token interface of an authentication center system to obtain an OAuth2 token, calling a token generation interface provided by an original system by a plug-in client jar package, and obtaining an original system token based on user information in the OAuth2 token; the plug-in client jar package establishes a bidirectional mapping relationship between an OAuth2 access token and an original system access token and between an OAuth2 refresh token and an original system refresh token, and stores the tokens in Redis; and when the OAuth2 token state changes, synchronously updating the original system token state based on the mapping relationship in Redis. The method does not need to make large-scale modification on an existing business system, and reduces integration cost and development difficulty.
Owner:NORTH CHINA DIGITAL HEALTH TECHNOLOGY CO LTD

Single sign-on authentication for API invokers in CAPIF

Single sign-on authentication of application programming interface invokers in a CAPIF system. using a Resource Owner Function (ROF), and an API Exposing Function. The methods allow an API invoker to
Owner:NOKIA TECHNOLOGIES OY

Security analysis of diverse identity provider and single sign-on configurations

The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC

Single sign-on method and device, medium and product

PendingCN121509063ASecuring communicationEngineeringLogin Name
The invention provides a single sign-on method and device, a medium and a product. The method comprises the following steps: receiving a query request sent by a target end; the query request comprises a source end identifier of a source end, a source end user login name and a target end identifier of a target end; querying an adjacency list based on the source end identifier, the source end user login name and the target end identifier to obtain a target end user login name; the adjacency list comprises a user mapping relation between a source end user of the source end and a target end user of the target end; sending the user login name of the target end to the target end; the target end user login name is used for the source end user to complete single sign-on to the target end.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Service access method and device based on single sign-on, equipment and storage medium

The invention relates to a service access method and device based on single sign-on, equipment and a storage medium. The method comprises the following steps: receiving an access request of a user terminal for a target service, wherein the access request comprises a URL parameter corresponding to the target service; when it is detected that the user terminal is in a non-login state, generating a login authentication request according to the URL parameter and the SAML request message; obtaining a login authentication result in response to the login authentication request; and after the validity verification of the login authentication result is passed, generating a one-time voucher, so that the user terminal accesses the target service based on the one-time voucher. According to the scheme provided by the invention, safe and seamless service access can be realized in a distributed SSO environment.
Owner:GUANGDONG ESHORE TECH

System single sign-on method, device, equipment and medium

The invention discloses a system single sign-on method and device, equipment and a medium, relates to the technical field of computers, is applied to a front-end page, and comprises the following steps: receiving initial configuration information sent by an operation end; encrypting a user name and a password in the initial configuration information to obtain target configuration information, and storing the target configuration information to a database; the target configuration information comprises a protocol, a port, a login address suffix, an encrypted user name, an encrypted password and each CSS selector; obtaining target configuration information of the target system from the database, and decrypting the encrypted user name and the encrypted password in the target configuration information through the target browser plug-in to obtain decrypted information; and determining a user name input box, a password input box and a login button corresponding to the login page of the target system through the CSS selector, and completing automatic login of the target system based on the decrypted information, the user name input box, the password input box and the login button. And single sign-on of the target system is realized.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Cross-platform single sign-on seamless migration method

The invention relates to a cross-platform single sign-on seamless migration method. The method comprises the following steps: S1, a client application initiates a sign-on request to an authentication center; s2, after receiving the request, the authentication center firstly verifies the identity of the user, and meanwhile, the authentication center creates an initial session and binds the initial session; s3, the client persists part of session data to the cloud for caching in real time through a Session synchronization service; s4, the user selects cross-terminal non-inductive login to call the migration process at the new terminal, and the new terminal submits the obtained migration voucher to the authentication center to initiate a session takeover application; s5, the authentication center verifies the legality of the migration voucher, after verification is passed, a new group of Access Token and Refresh Token is generated, the original session state is synchronized to the new end, and a new session and the original session are bound or coexist in parallel; and S6, after the APP end receives the new Token information, a local Session environment is automatically reconstructed, original end session data is pulled at the same time, and the operation process is seamlessly continued. According to the invention, cross-platform seamless migration of the user session and the service state is realized.
Owner:SICHUAN ZHONGDIAN AOSTAR INFORMATION TECHNOLOGIES CO LTD

Fund sales ecological platform based on four-party collaborative operation

The invention discloses a fund sales ecological platform based on four-party collaborative operation, belongs to the field of financial services, and aims to solve the problem that information of an existing fund sales ecological platform cannot be synchronized. Through the supervisor module, the institution module, the financial planner module, the customer module, the sales management module and the dynamic management module, single sign-on, full-process run-through and data seamless circulation are realized through one-stop resource integration aiming at the long-standing system splitting and low-efficiency operation pain points in the fund industry, and the system is convenient to use. A traditional mode that a user needs to repeatedly switch multiple systems and an operation path is broken is thoroughly changed, multiple fund product data of multiple trusteeship institutions are pulled at regular time through an FSP platform for unified cleaning and collection, and a standardized data asset management specification is established; structured and unstructured storage and processing are supported, the problem of data islands is solved, data are stored in different platform media according to the data value and the cold and hot degree, and the cost is optimized.
Owner:BEIJING JIADING TIANMING INFORMATION SERVICE CO LTD

Browser switching method combined with single sign-on

The invention discloses a browser switching method combined with single sign-on, which relates to the technical field of browser switching, and comprises the following steps: judging a user login state of an initial application, performing login authentication processing by utilizing single sign-on verification to obtain a session identifier of the initial application, and writing the session identifier into a session credential of an initial browser; transmitting a target application access parameter according to a click result, performing browser jump judgment by utilizing single sign-on, and generating a session token, anti-opening equipment multiplexing relational data and a browser switching front-end page; starting a target browser, generating an optimized target address, generating a synchronous session front-end page, and calling a session setting interface of single sign-on to transmit a session token; and establishing a target browser session, and redirecting to the optimized target address for target application login. According to the cross-browser login-free switching method and the cross-browser login-free switching device, the problem that the traditional single sign-on cannot share the login state in a cross-browser manner is solved by synchronizing the front-end page of the session, and the safe and seamless cross-browser login-free switching is realized.
Owner:BANK OF NANJING CO LTD

Single sign-on clinical trial management platform

A method includes ingesting, by a clinical trial management platform, data from multiple clinical trial site systems associated with multiple clinical trials, responsive to authentication of user credentials of a user, providing the user with access to the clinical trial management platform, based on the user credentials, identifying a particular clinical trial associated with the user, through the clinical trial management platform, providing the user with access to multiple clinical trial software services based on the authenticated user credentials, based on the ingested data for the particular clinical trial associated with the user, presenting to the user a user-specific task list for user tasks related to the particular clinical trial; and through the clinical trial management platform, establishing a communication link between the user and another user, the communication link enabling direct, real-time messaging via the clinical trial management platform between the user and the other user.
Owner:IQVIA INC

Security product login method and device

The invention provides a security product login method and device, and the method comprises the steps: enabling a browser to respond to the single sign-on operation of a terminal user on a target security product, and transmitting a single sign-on request to a service management system; then the service management system returns a target URL pointing to a background single sign-on interface of the security management platform and encryption parameters to the browser; when the browser carries encryption parameters to initiate a request to a target URL, the security management platform completes user identity verification and simulation login in the background, generates a session voucher, writes the session voucher into a browser Cookie, and returns a redirection response pointing to a proxy page to the browser; and when the browser requests the proxy page, the security management platform returns proxy page content to the browser, so that the browser executes initialization logic of the proxy page. According to the method, one-key single sign-on of the terminal user from the service management system to the target security product is realized, and interaction between the terminal user and a security management platform page is effectively avoided.
Owner:NEW H3C SECURITY TECH CO LTD

Hash power resource transaction processing method and system based on multi-level account system and medium

This invention relates to a method, system, and medium for processing computing power resource transactions based on a multi-level account system. The method includes: pre-constructing a multi-level account permission mapping model, which includes preset role groups in the trading platform and preset user accounts in the supplier platform that are mapped to the trading platform; upon receiving a cross-platform access request generated by a user, the trading platform sends a service request to the supplier platform according to the determined business role and user account; the supplier platform generates an encrypted redirection credential encapsulated with a unique identifier of the target resource, a time-sensitive signature, and specific operation permissions based on the service request, and forwards it to the user; the user redirects to the supplier platform based on the encrypted redirection credential, and after verification by the supplier platform, a control connection is established between the user and the corresponding computing power resource in the supplier platform. Compared with the prior art, this invention achieves single sign-on and fast access between resources.
Owner:INESA (GRP) CO LTD

Methods and systems for facilitating single sign-on and passwordless sign-on

Computer-implemented methods and systems for facilitating single sign-on (SSO) and passwordless sign-on to a web service provider are provided. A client device authorized for SSO or passwordless sign-on generates and stores a device-specific key that it uses to encrypt a credential bundle containing key(s) necessary to access a cryptographically protected resource provided by the web service provider. The encrypted credential bundle is stored by the web service provider and provided to the authorized client device upon a successful authentication via SSO or passwordless sign-on. The authorized device uses the locally stored device-specific key to decrypt the encrypted credential bundle received from the web service provider to obtain the key(s) necessary to access the cryptographically protected resource.
Owner:AGILEBITS INC DBA 1PASSWORD

Agentless single sign-on techniques

Described herein are methods, systems, and computer-readable storage media for using a network identity. Techniques may include obtaining and encrypting a first data element using an encryption key and storing the encrypted first data element mapped to a network identity. Techniques may further include receiving a request from the network identity to perform an action on a resource and authenticating the network identity using an existing protocol, decrypting the first data element using a second data element calculated based on standard fields of the existing protocol, and enabling the action on the resource using the first data element.
Owner:CYBER ARK SOFTWARE LTD

A unified identity authentication system and method for scientific research collaboration

The application discloses a kind of unified identity authentication system and method for scientific research cooperation, belong to permission control and identity authentication technical field.The application access module provides visual template to support the quick access and life cycle management of different protocol applications;Gateway module realizes non-invasive request interception through DNS and IP mapping, and calls unified authentication endpoint to execute strategy;Protocol support module realizes the accurate mapping of user attributes across protocols through standardized directory and mapping engine;Unified authentication and authorization module adopts pipeline process, integrates identity linker, risk control engine and token service, realizes single sign-on and adaptive control;Dynamic permission allocation module combines reinforcement learning, and issues optimal permission strategy according to trust score and context environment;Data storage module guarantees account unified governance and log traceability.The application realizes unified authentication and zero-trust dynamic authorization under heterogeneous scientific research platform.
Owner:INST OF HIGH ENERGY PHYSICS CHINESE ACAD OF SCI +1

A single sign-on system, method and medium based on user permission synchronization

This invention discloses a single sign-on system, method, and medium based on user permission synchronization. The system includes an authentication center, an application console, a message middleware, and application systems. The authentication center provides user management, authentication, authorization, and authorization functions. The application console provides links for users to access applications. The message middleware receives messages from the authentication center and distributes them to application systems that have subscribed to the messages. The application system is the business platform where users perform actual business processing. The authentication center does not immediately synchronize users to the application system upon registration; it only notifies the application system of user changes when a user requests access. This approach avoids the generation of a large number of invalid dormant users and solves the user permission synchronization and access authorization problems of single sign-on systems.
Owner:GUANGDONG AIB POLYTECHNIC COLLEGE

Single sign-on authentication for API invokers in CAPIF

Single sign-on authentication of application programming interface invokers in a CAPIF system. using a Resource Owner Function (ROF), and an API Exposing Function. The methods allow an API invoker to
Owner:NOKIA TECHNOLOGIES OY

Single sign-on method and device, electronic equipment and storage medium

The invention provides a single sign-on method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining an access request for a first application which runs on a first browser on terminal equipment, and deploying a local Web service on the terminal equipment; in response to the existence of historical login operation for a second application, generating a cross-browser bill, the second application running in a second browser on the terminal device; sending the cross-browser bill to a local Web service, so that the local Web service generates a bill authentication request based on the cross-browser bill; authenticating the cross-browser bill in the bill authentication request; and in response to the cross-browser bill passing the authentication, sending a first login credential associated with the historical login operation to the first application, so that the first application logs in based on the first login credential.
Owner:CHINA MOBILE INTERNET CO LTD +1

Single sign-on method, system and device for terminal equipment, equipment, product and medium

The invention relates to the technical field of single sign-on, and provides a terminal equipment single sign-on method, system and device, equipment, a product and a medium. The method comprises the following steps: a service server receives a resource access request sent by terminal equipment; performing offline verification on the legality of the authentication server of the terminal equipment; under the condition that the legality verification of the authentication server is passed, offline verification is carried out on the legality of the terminal equipment; under the condition that the validity verification of the terminal equipment is passed, offline verification is carried out on the integrity of the service data; and returning a resource access result to the terminal equipment under the condition that the integrity verification of the service data is passed. The decentralized authentication chain architecture is adopted, and the service server does not depend on real-time online interaction with the authentication server, so that the single-point fault risk, the security risk and the architecture complexity can be effectively reduced, and the applicability in the resource-limited Internet of Things environment is improved.
Owner:CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1

Single sign-on (SSO) authentication system for enabling digital communication between multiple entities

A system and a method for a single sign-on (SSO) authentication process that enables digital communication between multiple entities. The system includes a server with one or more processors. These processors receive a first authentication request from a first entity to access a second entity, which employs a first authentication process. Based on the request, the processors generate a second authentication request corresponding to the second authentication process used by the second entity. The second authentication request is then communicated to the second entity. After receiving a first response from the second entity, the processors generate a second response corresponding to that first response. This second response is communicated back to the first entity. Upon validating the second response, the processors allow communication between the first and second entities.
Owner:LUMENORE INC

Client device information for controlling access to web applications

The described technology provides for plural application processes including at least one application in a browser to reliably acquire device information that can be used by other processes to accurately determine whether the plural applications are running on the same client device and / or are associated with aspects of the same client device. The more reliable determination of the devices associated with respective application processes can be used for various purposes such as, for example, user access management capabilities such as improved single sign-on (SSO) capability and / or improved multiple login prevention (MLP) capability.
Owner:NASDAQ INC

Security analysis of diverse identity provider and single sign-on configurations

PendingUS20260052165A1Securing communicationIdentity providerSecurity analysis
The present application relates to devices and components including apparatus, systems, and methods to perform risk analysis of authentication systems and presenting results of the risk analysis. The approaches can transform configuration data indicating authentication operations to a data format representation for performing risk analysis of the authentication systems.
Owner:BEYOND IDENTITY INC