Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1075 results about "User authentication" patented technology

User authentication is the verification of an active human-to-machine transfer of credentials required for confirmation of a user’s authenticity; the term contrasts with machine authentication, which involves automated processes that do not require user input.

Multi-role grading access control method, system and device for segment sliding electric door

The invention discloses a multi-role grading access control method, system and device for a segment sliding electric door, and relates to the technical field of access control. The multi-role hierarchical access control method, system and device for the segment sliding electric door comprises the following steps: S1, collecting user access control data in the user identity verification and passing operation process, and carrying out data cleaning and normalization processing on the user access control data; s2, slicing the user behavior data in different time periods, extracting statistical characteristics, identifying abnormal modes, and carrying out quantitative analysis on the behavior state of the user; s3, collecting access control data in real time to construct a behavior sequence, evaluating the risk fluctuation amplitude and trend, judging the risk level and carrying out risk response; and S4, carrying out quantitative evaluation on risk response effects in different operation periods, dynamically adjusting safety response measures and regularly generating strategy optimization suggestions. The problem that in the prior art, traffic abnormal behaviors cannot be effectively recognized, and consequently a safety blind area exists is solved.
Owner:WUXI JIANGUO INTELLIGENT TECH CO LTD

Electric vehicle interconnection, intercommunication and sharing charging operation method and device and storage medium

The invention relates to the field of new energy automobile power supply, and provides an electric automobile interconnection sharing charging operation method and device and a storage medium, the method comprises the following steps: realizing heterogeneous system interconnection of a multi-source charging platform and a supervision platform through a standardized interface protocol, and establishing a cross-platform data channel; a dynamic user authentication system is constructed based on a cross-platform data channel, user registration and authority distribution of the electric vehicle are completed in a multi-mode identity authentication mode to obtain a user authority level, and an authentication result is fed back to the supervision platform; performing intelligent charging pile matching based on the real-time multi-dimensional charging resource atlas according to the user permission level, and generating a dynamic service instruction containing a navigation path and charging parameters; and in a charging service execution process, a bidirectional supervision data flow is created through a cross-platform data channel, full-life-cycle supervision of the charging process is executed in real time, and a service strategy is dynamically adjusted based on a feedback instruction of a supervision platform. According to the technical scheme, the electric vehicle can be cooperatively charged.
Owner:深圳市友电物联科技有限公司

Identity authentication and control method and device based on block chain

The invention discloses an identity authentication and control method and device based on a block chain. According to the method, biological features are collected through edge nodes to generate feature vectors, a combined hash value is generated in combination with a device scene label and a service role label, the combined hash value is uploaded to a cloud server after encrypted signature, and the combined hash value is written into a block chain through an intelligent contract; and during user authentication, the edge node calculates a real-time risk level, dynamically selects an authentication mode, calls an intelligent contract for verification after verification of the cloud server, and adjusts the risk level according to a verification result to implement management and control. According to the method, the edge cloud collaborative architecture is adopted, and the dynamic multi-factor authentication mechanism and the block chain consensus technology are combined, so that high-security privacy protection authentication is realized, the security requirements of different service scenes can be met, data leakage and replay attacks are effectively prevented, and the authentication efficiency and reliability are improved.
Owner:BEIJING BOSHI YUANXIN TECH CO LTD

Systems, methods, and protocols for zero knowledge proof user authentication

Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and / or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.
Owner:T STAMP INC

Real-time data desensitization method and system based on context awareness

The invention relates to the technical field of data security, and particularly discloses a real-time data desensitization method and system based on context awareness, and the method comprises the steps: intercepting an HTTP / HTTPS request through a gateway, and extracting a user authentication token, URL parameters, an IP address, a timestamp and request body data in a request header; analyzing user role information based on the user authentication token, extracting access environment characteristics based on an IP address and a timestamp, and performing sensitive field identification and grading on request volume data to determine a data sensitive level; according to the user role information, the access environment characteristics and the data sensitivity level, matching a predefined desensitization strategy template through a rule engine, and generating a real-time desensitization strategy containing a field-level desensitization instruction; verifying the access authority based on the user authentication token, and dynamically adjusting the desensitization degree in combination with the access environment characteristics; and according to the real-time desensitization strategy and the desensitization strength, performing real-time desensitization processing on the sensitive fields in the corresponding data.
Owner:BEIJING JIANGRONGXIN TECH CO LTD

Dynamic function menu generation method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a dynamic function menu generation method, device, equipment and medium, which comprises the following steps: acquiring an access request containing equipment type information sent by a user terminal, analyzing an authentication state of a user account and an associated license state, and sending the access request to the user terminal; and generating a dynamic session context defining function access qualification and an interface rendering strategy, loading a function menu strategy model containing function item set and permission mapping, determining a target permission level, matching a target function item subset with a rendering strategy, and generating and sending a function menu instance to the user terminal. The dynamic session context is generated in real time in combination with the user authentication state and the license state, linkage of permission judgment and interface rendering is driven, the function menu has the capacity of dynamic switching according to the session state, menu generation and accurate issuing based on actual authorization and the equipment environment are achieved, and unauthorized access is effectively avoided.
Owner:PING AN TECH (SHENZHEN) CO LTD

Security protection method for power mobile application based on swan-gap microkernel

The invention relates to an electric power mobile application security protection method based on a swan gap microkernel, which comprises the following steps of: S1, establishing a hardware trust root, and storing a device root key and a certificate chain by utilizing a non-tampering storage area built in a chip; s2, establishing a complete trusted boot chain based on a hardware root of trust, and verifying the integrity and credibility of the next layer by each layer from Bootloader to a swan microkernel and then to an application program; s3, constructing a triple authentication system based on user identity, equipment identity and biological characteristics, and performing user authentication; s4, according to a user authentication result, realizing fine-grained authority control based on an RBAC model and ABAC, and ensuring that authority check can be executed during resource access every time by utilizing an IPC security mechanism of a swan micro kernel; and S5, creating an independent execution environment for each power application according to the process isolation capability of the swan microkernel, and ensuring that memories among the applications cannot be mutually accessed through virtual address space isolation. The reliability of power mobile application safety protection is effectively improved.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

User Authentication, Spoofing and Replay Attack Prevention, Liveness Detection, and User-and-Document Verification using a Live Video Stream with Spatial Challenges

User authentication, spoofing and replay attack prevention, liveness detection, and user-and-document verification using a live video stream with spatial challenges. A camera of an electronic device captures and transmit a live selfie user-facing video, as part of a user registration process. The user is instructed to spatially move his body or face, such that his face would appear within a first particular on-screen shape; and to also, concurrently or simultaneously, spatially hold in his hand or move a particular an identification document such that it would appear within a second on-screen shape. Optionally, the on-screen shape moves on the screen, and the user is required to spatially move the relevant item to keep it within the boundaries of the moving on-screen shape. The system then analyzes the video via computerized vision, to determine whether the user complied with the spatial manipulation challenges.
Owner:IRONVEST INC

Decentralized Digital Identity Exchange for Fraud Detection

A decentralized digital identity exchange (IDX) is provided. In response to receiving a request for identity verification of a user, the IDX transmits, to a digital wallet associated with the user, a request for current biometric data. The current biometric data is received from the digital wallet and a biometric liveness check is performed. In response to the biometric liveness check succeeding, the IDX generates a verification transaction ID (VTID) and a verifiable credential for the user. The VTID is a unique identifier that comprises a representation of when the identity of the user was verified by the IDX. The verifiable credential and VTID are transmitted to the digital wallet which sends them to a relying party computing system to verify the identity of the user to the relying party computing system.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems and methods for user authentication using subject identifier and / or subject identifier documents

In some instances, a method is provided. The method comprises: generating a first subject identifier for the first domain, wherein the first subject identifier comprises a plurality of elements, wherein at least one of the plurality of elements comprises a subject identifier fragment indicating a unique identifier string for the user; based on a second user request to access second content for a second domain from the user device associated with the user, determining whether the user is enrolled into the subject identifier authentication; in response to determining that the user is enrolled into the subject identifier authentication for the first domain, generating a second subject identifier for the user for the second domain based on the subject identifier fragment from the first subject identifier for the first domain; and granting access to the second content for the second domain based on generating the second subject identifier.
Owner:AETNA INC

Systems and methods for counter-reconnaissance in cloud infrastructure to disrupt adversarial targeting

The present invention relates to a cybersecurity system for preventing adversarial reconnaissance in cloud, hybrid, and multi-cloud environments by dynamically modifying user authentication identifiers, hostnames and fully qualified domain names. The system updates login usernames in real time using randomized, non-repeating values generated from a configurable dictionary. Updates occur at scheduled, random, coordinated, or event-triggered intervals to disrupt profiling and targeting attempts. When identifiers are changed, associated sessions and tokens are invalidated to prevent reuse. The system monitors expired credential usage to detect potential reconnaissance, generating alerts with intelligence such as IP addresses, timestamps, and affected resources. By eliminating predictable identity patterns, the system defends against reconnaissance-based attacks, unauthorized access attempts, and other credential-driven threats, thereby improving organizational security across cloud platforms.
Owner:FRENETIK LLC

Systems and methods facilitating user to user authentication and authorization

Aspects of the subject disclosure may include, for example, transmitting a request to generate an authorization object; receiving a first confirmation that authenticates a primary user device from a service provider system; generating the authorization object that meets a predetermined standard and contains audio visual representation of a primary user associated with the primary user device; receiving a second confirmation that authenticates a matching between the authorization object and the primary user; uploading the authorization object to a storage of a trusted server; and executing an access mechanism to access the stored authorization object on the trusted server. Other embodiments are disclosed.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Decentralized terminal user login management system and method in ad hoc network environment

The invention discloses a decentralized terminal user login management system in an ad hoc network environment, which is embedded in each terminal of the whole network, and each terminal comprises a user login module used for a user to input a user name and a password in the ad hoc network environment to initiate login; the local offline user management module is used for user information authentication of a user in an ad hoc network environment; and the user authentication broadcast confirmation module is used for synchronizing authentication information to other terminals after the user is successfully authenticated in the ad hoc network environment. The invention further discloses a method of the decentralized terminal user login management system in the ad hoc network environment. According to the method, the problems of single-point failure, poor dynamic topology adaptability, incapability of authenticating an offline scene, low synchronization efficiency and the like caused by centralized authentication in a traditional ad hoc network user management system are effectively solved.
Owner:XIAOTANG TECH (SHANGHAI) CO LTD

Television terminal education application multi-mode user authentication method and system

The invention relates to the technical field of data processing, and discloses a television terminal education application multi-mode user authentication method and system. The method comprises the following steps: monitoring a user face orientation offset degree and a voice interaction frequency through an IPTV set top box to obtain a learning participation degree index, comparing the index with a preset threshold 0.7 to execute a concentrated learning or distraction state authentication process, and dynamically adjusting through an authentication severity regulator to obtain a high-sensitivity or low-sensitivity authentication parameter, and performing weighted fusion calculation on the multi-modal biological characteristics of the user to obtain an identity confidence score associated with a learning state, and performing matching verification on the identity confidence score and a dynamic authentication threshold to obtain a user identity authentication result based on the learning concentration degree. According to the method and the device, the problem that a user authentication strategy in television terminal education application cannot adapt to dynamic change of a learning state is solved, and the accuracy of multi-modal user identity authentication based on learning concentration and the adaptability of user learning experience are improved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD +1

Multifactor authentication via bifurcated passcode and non-fungible token

Multifactor user authentication leveraging secure tokenization, such as a Non-Fungible Token (NFT) and multiple passkeys (e.g., bifurcated passkey). One or more authentication NFTs are generated that use some form of a user's authentication credentials as the seed input for the NFT encryption / hash algorithm(s). In addition, passkeys are distributed to and / or made accessible to multiple passkey holders. In response to an event that requests multifactor authentication of the user, a plurality passkeys are requested, received and verified. Each of the passkeys being requested and received from, or at the directive of, one of the multiple passkey holders. In response to verifying the plurality of passkeys, at least one of the authentication NFTs is accessed and the cryptographic hash algorithm(s) is implemented to decrypt the authentication NFT(s) and identify the one or more user credentials. In response, the user is authenticated based at least on the user credentials that formed the basis for the authentication NFT(s).
Owner:BANK OF AMERICA CORP

System and Method for Securing Multiregional Interactions Utilizing Quantum Computing

A system includes a memory configured to store instances of a software application and a quantum processor operably coupled to the memory and configured to receive, from an instance of the software application, a user request to initiate an execution of multiregional interactions. The quantum processor is further configured to determine, based on the user request, structured data items configured to be completed by the user in order to satisfy the user request, identify, based one or more data fields within the structured data items, an input of first user identity verification data for satisfying the user request, extract, based on quantum sensor data obtained from quantum sensors, second user identity verification data, execute one or more quantum machine-learning (QML) models trained to identify whether the second user identity verification data matches to the first user identity verification data, and initiate the execution of the one or more multiregional interactions.
Owner:BANK OF AMERICA CORP

Mobile application to expedite activation of contactless cards

A method, a system and a computer program product for expediting activation of contactless cards. An application on a computing device is executed upon the computing device detecting a contactless card to be located within a predetermined distance of the computing device. The computing device stores one or more computing device activation keys. The contactless card is an inactive contactless card. The stored computing device activation keys are accessed upon verifying one or more user authentication keys received in response to the executing. One or more contactless card activation keys are received. The contactless card activation keys are stored by the contactless card. The contactless card is activated based on a determination that the received contactless card activation keys match the stored computing device activation keys.
Owner:CAPITAL ONE SERVICES LLC

Lightweight multi-factor authentication method and system oriented to multiple modes

The invention relates to the technical field of identity authentication, in particular to a multi-mode-oriented lightweight multi-factor authentication method and a multi-mode-oriented lightweight multi-factor authentication system. The method comprises the following steps: taking a real voice sample as input to realize lightweight voice deception detection, synchronously acquiring voiceprint modal data and auxiliary modal data of a user through terminal equipment, extracting modal feature vectors and performing dimension reduction processing; distributing a weight for the modal feature vector, and calculating a fusion feature vector; inputting a password by a user, performing AES encryption on the password by the system, and performing local comparison with the ciphertext in the database; homomorphic encryption is carried out on the fusion feature vector by using an ASPE homomorphic encryption algorithm based on chaotic scrambling and semi-tensor product optimization, and the fusion feature vector is compared with a stored voiceprint ciphertext vector; and when both the password comparison authentication and the voiceprint recognition authentication are passed, determining that the user authentication is successful. According to the method, key technologies such as voice deception detection, multi-modal fusion and knowledge distillation are fused, and low overhead and high safety in the safety certification process are ensured.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System and method for enforcing PII segregation in a distributed data 1 processing system for Privacy-preserving AI corpus generation

A system and method are disclosed for generating a privacy-preserving data corpus for Artificial Intelligence (AI) training. The system comprises a relying partner (RP) computing environment and a trusted, independent identity provider (IdP) computing system. Upon a user authentication request, the IdP provides the RP with only a PII-free, persistent pseudonymous identifier (gUserID) for the user. Any authentication artifacts containing Personally Identifiable Information (PII), such as an OAuth token, are programmatically neutralized by the IdP. This is achieved by generating a transient public-private encryption key pair, immediately destroying the private key, and encrypting the PII-laden artifact with the remaining public key, rendering the PII therein permanently irrecoverable. This enforcement of “PII unknowability” at the RP enables the aggregation of pseudonymous user data, linked by the persistent gUserID, from multiple independent RPs into a rich, cross-organizational corpus for AI training, without ever exposing user PII to the RP.
Owner:NEMA WALEED S

Vehicle remote control driving system and method

The invention discloses a vehicle remote control driving system and method. The system comprises a cloud remote control platform and a vehicle-mounted control terminal, wherein the cloud remote control platform is used for sending a communication connection request to the vehicle-mounted control terminal after the identity verification of a target user is passed; the vehicle-mounted control terminal is used for carrying out identity verification on the cloud remote control platform and establishing encrypted communication connection; the cloud remote control platform is used for generating a remote control mode starting instruction; the vehicle-mounted control terminal is used for decrypting the encrypted remote control mode starting instruction and entering a remote control driving mode; the cloud remote control platform is used for generating a remote control driving interface, generating a driving control instruction and sending the driving control instruction to the vehicle-mounted control terminal; and the vehicle-mounted control terminal is used for decrypting the encrypted driving control instruction and performing driving control on the target vehicle. According to the invention, remote control driving of the vehicle can be realized, and the system can adapt to a complex vehicle environment, so that the stability and reliability of the vehicle in the remote control driving process are ensured.
Owner:FAW JIEFANG AUTOMOTIVE CO

Authority management device and method adaptive to heterogeneous access controller

The invention provides an authority management device and method adaptive to a heterogeneous access controller. The device consists of the heterogeneous access controller, an access management system and a user terminal, the heterogeneous access controller is provided with a calculation main control module, a communication module, an identity verification module, a permission execution module, a state acquisition module, a storage module and a power supply module; the access control management system is provided with a protocol adaptation management module, an authority engine detection module, a data storage management module and a user authentication management module; the user terminal is provided with a man-machine interaction module, an authority configuration module, an access control state monitoring display module and an alarm receiving module; the use method of the device comprises the following steps: installing the heterogeneous access controller, accessing other access controllers, performing authority configuration, communication debugging, controlling and managing the heterogeneous access controller and displaying and checking the working state of the heterogeneous access controller through the user terminal, so that the requirement of unified and centralized management of various different access controllers is met, and the system integration and maintenance cost is reduced.
Owner:ZHEJIANG NINGHANG ENERGY TECHNOLOGY CO LTD

Gesture-Based User Authentication

A computerized method is provided for user authentication using hand gestures. Multiple points on a user's hand can be tracked using cameras or various sensors and the motion of those points in space and relative to each other can used to create gesture-based passwords. Such user authentication techniques have advantages in augmented and virtual reality applications where traditional text-based passwords may be difficult. Gesture-based user authentication can be augmented with physical characteristics of the specific user's fingers and hands including size, shape, and distinguishing marks to enhance security.
Owner:FMR CORP

Identifying a context of a user authentication

Systems and methods for identifying a context of a user authentication are provided. In one example, during a user authentication to a web service by a web browser, one or more updates to a state of the web browser are determined. The one or more updates to the state of the web browser are reported to an assessment entity, which may be implemented within an agent external to the web browser. The assessment entity then identifies a context of the user authentication based on the one or more updates to the state of the web browser.
Owner:FORTINET INC

User authentication on a web resource using a browser fingerprint-based identifier

The invention relates to methods for authenticating users by generating web browser identifiers. The present method includes the steps of receiving, on a server, data about a user connection to a web resource; collecting¸ from the client device, parameters of the user's web browser, including a web browser performance parameter, audio processing interface parameters and 2D and 3D graphic rendering parameters; determining parameters of the web browser connection to the server, including the HTTP headers received in the browser request, and the IP address of the client device; generating SSL and TCP fingerprints on the server on the basis of the obtained client device web browser parameters; generating an identifier of the web browser fingerprint by vectorizing the collected web browser parameters; using the obtained identifier to train a machine learning model; using the machine learning model for the subsequent authorization of users on the web resource. The technical result is an increase in the reliability of user authentication.
Owner:PUBLICHNOE AKTSIONERNOE OBSHCHESTVO SBERBANK ROSSII (PAO SBERBANK)

Safety control method and system for RFID (Radio Frequency Identification) digital information read-write tag

The invention discloses an RFID digital information read-write tag security control method and system, and relates to the technical field of Internet of Things information security, and the method comprises the steps: receiving a user authentication request, generating a communication random number in combination with a trusted tag archive back-end program, and obtaining an authentication task package after common packaging; the authentication task package is sent to an RFID digital information read-write tag, a reconstructed stable key and real-time environment parameters are obtained, and a tag encryption response voucher is obtained by combining cryptographic signature calculation; according to the label encryption response voucher, cryptographic verification of a back-end program is executed, and credible physical state data is identified; and based on the credible physical state data, executing business strategy verification of a back-end program, obtaining an authorization decision result, and performing dynamic data reading and writing. According to the method, the physical identity of the tag and the real-time environment parameters are bound on the cryptographic level, so that the authenticity and non-tampering property of the physical state data in subsequent verification are ensured.
Owner:CENTURY ZHONGKE (BEIJING) TECHNOLOGY CO LTD

Techniques for Device Authentication

Techniques are disclosed relating to user authentication. In some embodiments, a first device includes an authentication system configured to store an identity of a user of the first device and detect a visual indication presented on a display of a second device in response to a successful biometric authentication of a user of the second device. Based on the visual indication, the authentication system determines that the authenticated user of the second device corresponds to the identity of the user of the first device. In some embodiments, the second device includes a display with a lenticular lens and, in response the user has been authenticated, displays a plurality of visual indications including a first visual indication visible from a first viewing angle and a second visual indication visible from a second viewing angle.
Owner:APPLE INC

Method, user device, verifier device, server and system for authenticating user data while preserving user privacy

A method comprises:receiving, by a user device, from a verifier device, a request for user data;retrieving a first cryptogram and a decryption key;sending and, to a server, the first cryptogram;retrieving a random and a second cryptogram generated using reference user authentication data concatenated with the random;sending, to the verifier device, the second cryptogram and the random;storing the reference random;sending, to the user device, the second cryptogram;decrypting the second cryptogram using the decryption key;extracting the reference user authentication data and the random;providing, the user device, with user authentication data;verifying that it matches the reference user authentication data;providing, the verifier device, with the random;verifying that it matches the reference random; andauthenticating the user data.
Owner:THALES DIS CZECH REPUBLIC SRO +1

Method of verifying user identity and electronic device

The application relates to the field of electronic equipment. The application provides a method for verifying the identity of a user. The method can be performed by a device for collecting identity information to be verified of a user and a device for verifying the identity information to be verified. The device for collecting the identity information to be verified or the device for verifying the identity information to be verified can determine a target identity verification mode suitable for a non-self device from multiple identity verification modes according to device information of the non-self device, so that the target user identity verification mode can be suitable for two different devices at the same time and can be more matched with a current scene, and personalized services can be provided for the user.
Owner:HUAWEI TECH CO LTD