Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

27 results about "Strong authentication" patented technology

Strong authentication is a notion with several definitions.

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Systems and methods for use in synchronizing keys for enhanced authentication availability

Systems and methods are provided for use in consent-based synchronization of keys for enhanced authentication availability. One example computer-implemented method includes receiving, by a first fast identity online (FIDO) server, from a second FIDO server, a signed consent token, which is signed by a first private key specific to a mobile device of a user; retrieving a user profile for a user; verifying the signed consent token based on a first public key included in the user profile; based on the successful verification of the consent token, generating a response token, which includes the first public key; signing the response token with a second private key unique to the first FIDO server; and transmitting the signed response token to the second FIDO server.
Owner:MASTERCARD INT INC

Three-weight quantum hybrid security chip based on quantum random source, equipment fingerprint and biological characteristics and identity authentication method

The invention discloses a quantum random source, equipment fingerprint and biological characteristic-based three-quantum hybrid security chip and an identity authentication method. The three-quantum hybrid security chip comprises a quantum random number generation unit; the system comprises an equipment safety processing unit, a biological characteristic processing unit, a triple mixing processing unit and a key derivation and identity management unit. The chip is integrated with a biological characteristic processing unit with living body detection and quantum fuzzy commitment functions, quantum randomness, equipment physical fingerprints and living body biological characteristics are subjected to deep cryptographic fusion through a triple hybrid processing unit, a unique hybrid result binding'equipment-user 'is generated, and a joint authentication key is derived according to the hybrid result; according to the invention, the method achieves the jump from equipment authentication to human-machine integrated strong authentication, thoroughly solves the risk of equipment embezzlement while inheriting the anti-quantum and anti-cloning advantages, and is suitable for scenes with the highest security level.
Owner:ANHUI YUNXI TECH CO LTD

Dynamic authorization method based on software defined boundary and user behavior baseline

The invention relates to a dynamic authorization method based on a software defined boundary and a user behavior baseline, and belongs to the field of network security. According to the method, initial strong authentication of a software defined boundary SDP is combined with continuous monitoring based on a user behavior baseline, and a dynamic authorization system throughout the full life cycle of a session is constructed; the abnormal risk is identified by comparing the current operation of a user with a dynamically updated behavior baseline in real time, and an authorization engine is triggered to automatically execute a complete method flow of authority adjustment according to the risk alarm, so that the fundamental conversion from'one-time authorization 'to'continuous self-adaptive authorization' is realized. According to the method, on the basis of a controlled channel established by the SDP, continuous learning and risk assessment of behaviors in a user session are introduced, and the access authority is automatically adjusted in real time according to an assessment result, so that a self-adaptive security closed loop integrating perception, analysis, decision making and execution is formed.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 32003

Strong authentication of a user of a communication terminal

The invention relates to a method for authenticating a user of a service on a communication terminal, comprising what follows, performed by the communication terminal: - transmitting (S23) to a server a request to access said server, said request comprising an identifier associated with the communication terminal and an identifier associated with a required service in said server, - receiving (S25), from an authentication device, an authentication request asking the user to pronounce at least one word, - communicating (S26) said at least one word pronounced by the user to the device, - said at least one pronounced word corresponding to a voiceprint of the user stored beforehand in association with the identifier of said communication terminal, accessing (S30a) the service or receiving (S29b) from the device a complementary user authentication request.
Owner:ORANGE SA

Multi-factor authentication system for property management

A multi-factor authentication system for property management may provide user a convenient and safe property management service via enrolling with service for multi-factor authentication via an application. The user may log in the multi-factor authentication service platform during the enrollment phase via the application to acquire an account and obtain authority for use, thereby to access the service provided by the multi-factor authentication service platform via a property management station system. In addition, during the property management service, the user may acquire the property management service in fewer steps and a more secure manner during an authentication phase with the multi-factor authentication service platform, thereby to enforce security for identity authentication.
Owner:WANG CHIH CHUN

Strong headless authentication without user involvement

A service installed on a user's device identifies a user that has logged into an account associated with an organization that has provided the service for installment. When the service determines that the user has successfully authenticated with an identity provider used by the organization, the service determines information about the session with the identity provider that was created to strongly authenticate the user. The service sends an authentication request to the identity provider as part of the same session with the identity provider that was created when the user was strongly authenticated. The authentication request generated by the service includes a parameter value for configuring authentication without user involvement, such as a parameter value for configuring passive or no prompt authentication. The user thus can be strongly authenticated to the service.
Owner:PALO ALTO NETWORKS INC

Global digital authentication terminal device supporting eSIM and credit service method

The invention discloses a global digital authentication terminal device supporting an eSIM, and the device comprises a password security chip which is used for executing global digital identity authentication, credit evidence storage and secure communication control, and a security module, an SM9 identification password algorithm module, an electronic seal engine, a multi-platform digital certificate management unit and a trusted execution environment are built in the password security chip; the eSIM module conforms to the standard of the global system for mobile communication (SGP). 22 and supports the switching of configuration files of a multi-operator subscriber identity module; wherein the eSIM module and the password security chip cooperatively operate, when a user initiates a security service, the password security chip generates a dynamic digital identity identifier based on an SM9 identifier cryptographic algorithm, and binds the dynamic digital identity identifier with an international mobile subscriber identity code in an eSIM configuration file; therefore, two-factor authentication of the communication identity and the digital identity is realized. The terminal device has the advantages of strong authentication and high compliance.
Owner:胡金钱 +1

Using machine-learning models to determine graduated levels of access to secured data for remote devices

ActiveUS12717940B2EngineeringData mining
Aspects of the disclosure relate to using machine-learning models to determine graduated levels of access to secured data for remote devices. In some embodiments, a computing platform may establish a connection with a mobile device. Subsequently, based on establishing the connection, the platform may identify initial device information, device features, and user information. The platform may input the identified information into an authentication model to compute a baseline authentication score and then may identify an initial level of access to secured resources for the mobile device. Thereafter, the platform may receive from the mobile device, AR / VR device information captured by the mobile device. The platform may input the AR / VR device information into the authentication model to compute an augmented authentication score. Based on the augmented score, the platform may identify an augmented level of access to secured resources for the mobile device.
Owner:BANK OF AMERICA CORP

Intelligent substation security communication method and system based on edge computing

The application discloses an intelligent substation security communication method and system based on edge computing, proposes an intelligent substation security communication strategy based on edge computing, provides shared proxy computing services for resource-limited terminal devices, greatly reduces the time for the terminal devices to process security messages, and can well meet the high-specification delay requirements of communication messages. In view of the access risk control problems of the edge server and the terminal device, a lightweight two-way identity authentication protocol is proposed, which is low in security risk, high in real-time authentication efficiency and light in weight, and is more suitable for real-time interaction of the substation transceiving time-sensitive business subject and the edge server. Moreover, considering that the server is low in risk level and high in performance, and the terminal device is high in risk level and low in performance, an asymmetric two-way authentication mode of weak authentication for the server and strong authentication for the terminal device is proposed, so that the calculation burden of the terminal device is reduced, and the authentication efficiency is improved.
Owner:STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED +2

Multi-terminal equipment biological recognition method and system

The invention discloses a multi-terminal device biological recognition method and device, and the method comprises the steps: enabling a first terminal device to respond to a first verification information input operation of a user, and carrying out the unlocking verification of the device and the login verification of a target APP; in response to the transaction amount input and confirmation operation, sending a first enhanced identity verification request to the second terminal device; the second terminal device displays an information collection page used for receiving first biological information input by a user; transmitting the encrypted biological information template to a first terminal device through a near-field secure communication channel; matching with standard biological information; if the matching is successful, generating a first authentication token; the first terminal device displays a payment verification interface; and after the payment verification succeeds, performing payment operation. According to the scheme, the biological information of the user is stored on the first terminal equipment, so that the risk that the biological data is leaked and abused at the cloud is eliminated; multiple verification factors are introduced outside a single biological feature, and multi-factor enhanced safety is achieved.
Owner:TAIEN IND (SHENZHEN) CO LTD

Strong authentication via distributed stations

In various embodiments, authentication stations are distributed within a facility, particularly in spaces where mobile devices are predominantly used—e.g., a hospital's emergency department. Each such station includes a series of authentication devices. Mobile device may run applications for locating the nearest such station and, in some embodiments, pair wirelessly with the station so that authentication thereon will accord a user access to the desired resource via a mobile device.
Owner:IMPRIVATA

BDSBAS hybrid authentication method fusing domestic cryptographic algorithm and TESLA protocol

The invention provides a BDSBAS hybrid authentication method fusing a domestic cryptographic algorithm and a TESLA protocol. According to the method, strong authentication of terrestrial broadcast node identities and generation of message digests are realized by introducing an SM3 hash algorithm, and efficient broadcast authentication of enhanced messages is realized by combining a time window delay release mechanism based on a symmetric key chain construction mode of a TESLA protocol. In the aspect of key management, the system generates a root key through a key management center, constructs a TESLA authentication chain through a Hash function, supports regular rotation, and ensures the security and traceability of the key. In the aspect of protocol design, compatible expansion and low-overhead receiving verification of a telegraph text structure are realized. The mechanism has the advantages of low calculation complexity, good broadcast adaptability and high security, is suitable for a large-range broadcast scene of the BDSBAS in civil aviation navigation enhancement, and effectively defends attacks such as data forgery and the like.
Owner:CIVIL AVIATION UNIV OF CHINA

Systems and methods for context-switching authentication over short range wireless communication

Systems and methods is provided for implementing a strong user authentication across a public network. One operational aspect of the disclosed systems and methods involves the integration of a browser functionality to communicate with processes and hardware elements on a device initiating the network connection to implement a context-switching authentication scheme. Disclosed system and process further involves an implementation of a two-factor strong authentication based on a single authentication input from a user involving an NFC read of a contactless card by a mobile device within Bluetooth proximity of the device initiating the network connection.
Owner:CAPITAL ONE SERVICES LLC

Strong authentication of a user of a communication terminal

A method for authenticating a user of a service on a communication terminal is performed by the communication terminal. The method includes transmitting to a server a request to access the server, the request comprising an identifier associated with the communication terminal and an identifier associated with a required service in the server, receiving, from an authentication device, an authentication request asking the user to pronounce at least one word, and communicating the at least one word pronounced by the user to the device. When the at least one pronounced word corresponds to a voiceprint of the user stored beforehand in association with the identifier of said communication terminal, the terminal then accesses the service or or receives from the device an additional user authentication request.
Owner:ORANGE SA

Displaying representations of a virtual card within a virtual wallet application to enhance authentication security and to provide Anti-phishing methods

Systems and methods are described herein for updating a representation of a virtual payment card in response to a virtual transaction between a first device (e.g., a user device) and a second device (e.g., a merchant point-of-sale device). The systems and methods may be used to authenticate user identity with an additional layer of security and / or combat phishing attempts intended to dupe users into disclosing confidential profile information. In response to a completed transaction, the second device delivers interactivity data (e.g., animation data, card image data, contextual data, notification sound data, etc.) to the first device, which actuates a distinct representation (e.g., an animation, a graphic image, a notification sound, etc.) of the card image of the virtual payment card used in the completed transaction.
Owner:ADEIA GUIDES INC

Certificate-based socks5 mutual authentication method, device and equipment

The application relates to a certificate-based SOCKS5 bidirectional authentication method, device and equipment. The method comprises the following steps: based on an established transmission layer connection, an authentication method request containing a certificate authentication method identifier is sent, the certificate authentication method identifier selected by a server is acquired, an authentication request carrying a user certificate is sent according to the certificate authentication method identifier selected by the server, the user certificate is verified by the server, the server certificate is acquired after a response of the server to the user certificate verification is received, the server certificate is verified according to the acquired server certificate, an authentication success message is sent after the verification is passed, and a business data transmission channel is established. The application expands the SOCKS5 protocol, defines a certificate authentication identifier, realizes identity strong authentication based on asymmetric cryptography through bidirectional certificate exchange and verification, replaces traditional passwords and automatically establishes a secure data transmission channel.
Owner:CBC TECH CO LTD

Strong authentication of a user of a communication terminal

The invention relates to a method of authenticating a user of a service on a communication terminal, the method comprising the following operations performed on the communication terminal: - sending (S23) to a server a request to access said server, said request comprising an identifier associated with the communication terminal and an identifier associated with a service requested in said server, - receiving (S25) from an authentication device an authentication request requiring the user to pronounce at least one word, - transmitting (S26) to the device said at least one word pronounced by the user, - said pronounced at least one word corresponding to a voice print of the user recorded in advance in association with the identifier of said communication terminal, accessing (S30a) the service or receiving (S29b) from the device an additional authentication request for additional authentication of the user.
Owner:ORANGE SA

An aircraft anonymous authentication method based on pseudonym aggregation index

The application discloses an aircraft anonymous authentication method based on pseudonym aggregation index, and the method constructs a hierarchical collaborative architecture of a trusted authority center, a regional management agency, a low-altitude base station and an unmanned aircraft, completes system initialization, strong authentication and key negotiation based on an elliptic curve cryptography system, generates an aircraft pseudonym by the regional management agency, and generates a unique index through aggregation operation, and the index is chained together with a certificate, and the trusted authority center stores the mapping relationship between the index and the real identity. The aircraft initiates an anonymous authentication request through additive homomorphic encryption, and the index level fast authentication is completed by a calculation node after verification by the base station; in a malicious scene, the ciphertext pseudonym is aggregated, and the real identity is traced back by controlled decryption of the trusted authority center, and the whole life cycle management of the certificate is realized, forming a 'one-time strong authentication and multiple fast authentication' mode. The method reduces authentication complexity and time delay, improves high-concurrency processing capacity, and realizes privacy protection and security supervision.
Owner:JIANGSU UNIV OF TECH

system

We provide the system. [Solution] Information gathering means for collecting and integrating biomedical information, An information analysis means for extracting biomedical patterns by applying a machine learning algorithm to the integrated information, Access management means to enhance the authentication process based on the extracted pattern, A repositioning method that explores applicability from multiple information resources, A decision-making support tool that proposes the optimal treatment method based on individual subject information, A system that includes this.
Owner:SOFTBANK GROUP CORP

Systems and methods for use in synchronizing keys for enhanced authentication availability

Systems and methods are provided for use in consent-based synchronization of keys for enhanced authentication availability. One example computer-implemented method includes receiving, by a first fast identity online (FIDO) server, from a second FIDO server, a signed consent token, which is signed by a first private key specific to a mobile device of a user; retrieving a user profile for a user; verifying the signed consent token based on a first public key included in the user profile; based on the successful verification of the consent token, generating a response token, which includes the first public key; signing the response token with a second private key unique to the first FIDO server; and transmitting the signed response token to the second FIDO server.
Owner:MASTERCARD INT INC

802.1x authentication method for ship network access control

Proposed is an 802.1x authentication method for ship network access control, which provides strong authentication by supporting various authentication mechanisms to enhance network security of a ship and increase management and operation efficiency.
Owner:HANWHA OCEAN CO LTD (KR) +1

Cloud edge collaborative operation and maintenance method and system

PendingCN121864432ASecuring communicationPathPingStrong authentication
The invention provides a cloud edge collaborative operation and maintenance method and system, which can realize high-efficiency encryption of a large-volume troubleshooting script in a full path of pre-diagnosis, troubleshooting script, accompanying issuing and customer receipt. Client identity and script integrity strong authentication; the compliance requirement that the trusteeship does not see the client content is met, and the safety and troubleshooting efficiency of remote operation and maintenance are improved.
Owner:ZHEJIANG DETACENT DATA TECH CO LTD

Bluetooth network distribution method and system, and intelligent device

The invention provides a Bluetooth network distribution method and system and intelligent equipment, and the method comprises the steps: generating an authentication code in a network distribution mode, the authentication code at least comprising a unique identifier and a Bluetooth MAC address of the intelligent equipment; in response to a Bluetooth connection request sent by the intelligent terminal based on identification of the authentication code, establishing a Bluetooth data channel connected with the intelligent terminal; performing TLS handshake negotiation with the intelligent terminal on the Bluetooth data channel, and establishing a TLS data channel connected with the intelligent terminal; and receiving target network information sent by the intelligent terminal through the TLS data channel, and performing networking of a target network based on the target network information. According to the scheme, bidirectional strong authentication can be realized, a standardized secure channel is constructed, high-strength and standardized protection is provided for transmission of sensitive data such as WiFi passwords, and eavesdropping, tampering and counterfeit attacks are effectively defended.
Owner:SHANGHAI SUMI TECH CO LTD +1

Identity service and blockchain

Systems and methods relating to an identity service and blockchain. An individual's sensitive data is anonymized using a one-way function. The anonymized sensitive data can be stored on a. blockchain and validated by an identity service without comn-promising the privacy of the individual's data. The authentication systems and methods that both (i) provide strong authentication of the identity of online personalities to prevent fraud, theft, scalping, etc. and (ii) respect the privacy of the individual's sensitive personal information.
Owner:C3N TECHNOLOGIES INC