Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

92 results about "Web authentication" patented technology

Web service authentication is the verification of a user’s identity before allowing access to a network or website. Certificates verify the identity of a Web server to users.

Unmanned aerial vehicle group mutual authentication and key agreement method based on PUF (Physical Unclonable Function)

The invention discloses an unmanned aerial vehicle group mutual authentication and key agreement method based on PUF, and relates to the technical field of unmanned aerial vehicle group communication security and network authentication, and the method comprises the steps: S1, obtaining change data through monitoring unmanned aerial vehicle node position coordinate tracking and connection signal intensity in real time, the method comprises the following steps: S1, carrying out state change detection on a node moving speed by adopting position deviation calculation and connection interruption records to obtain a position coordinate tracking sequence after data synchronization update, S2, carrying out data point clustering on the position coordinate tracking sequence by adopting a K-Means clustering algorithm, processing the connection interruption record groups through central point iteration and distance measurement calculation to obtain change vector groups under group number setting; the PUF-based unmanned aerial vehicle group mutual authentication and key agreement method not only effectively solves the problems of slow response, easy communication interruption, unstable key agreement and the like of a traditional unmanned aerial vehicle group authentication mechanism, but also realizes comprehensive improvement in the aspects of safety, robustness and intelligence.
Owner:GUANGZHOU YOUFEI INTELLIGENT EQUIP CO LTD

Network authentication and authorization issue detection

Techniques are disclosed that enable a system to determine whether an error associated with a cloud-based authentication, authorization, and accounting (AAA) service has occurred. The techniques include obtaining, for a plurality of network access service (NAS) devices at a site, data indicative of authentication attempts for client devices with a cloud-based AAA service. The techniques include identifying, based on the data, whether one or more errors occurred for the authentication attempts; and correlating the one or more errors across the plurality of NAS devices at the site to determine whether the one or more errors are indicative of an issue associated with the AAA service. The techniques further include determining at least one remediation action for the issue associated with the AAA service.
Owner:JUNIPER NETWORKS INC

Method and system for transferring funds between a financial institution and an e-wallet within an interbank network

There is provided a method to transfer funds from a user's financial institution account to an electronic wallet (e-wallet). The e-wallet is provided by an e-wallet provider. The method includes obtaining a message addressed to an email address from an interbank network. The message includes the email address and a transaction identifier (ID). The method further includes obtaining an e-wallet ID associated with the e-wallet. The transaction ID is provided to the interbank network and a hash salt of a security question is obtained from the interbank network. The hash salt of the security question, the security answer and the e-wallet ID are provided to cause the interbank network to authenticate the transaction and the amount of funds is transferred from the account at the financial institution to the e-wallet provider and an e-wallet balance of the e-wallet is updated.
Owner:ZHU ZHAOYU +2

Network authentication with cryptographic corpocessors

Disclosed are various embodiments for authentication with network connected computing resources using a cryptographic coprocessor installed on a client device. A request can be sent to the client device to provision an asymmetric encryption key-pair using a cryptographic coprocessor installed on the client device, wherein the request comprises a key-authorization credential for the asymmetric encryption key-pair and the asymmetric encryption key-pair comprises a public key and a private key. The public key of the asymmetric encryption key-pair and an identity public key for the cryptographic coprocessor can be received. The public key, key-authorization credential, and the identity public key can then be stored in association with each other.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Network authentication toxicity assessment

A system and method for scoring and enforcing authentication standards that actually enable zero trust network security principles when combined with stateful authentication object tracking, authentication object manipulation and forgery detection, and assessment of authentication and identity attack surface. The methodology involves gathering all authentication objects issued by a network, storing the authentication objects in a centralized location for use in stateful deterministic authentication object tracking, scoring the completeness of the authentication observations, assessing the quality of the authentication observations, and assigning organization-specific penalty functions.
Owner:QOMPLX INC

Information access handover

A computerized method of information access handover between a first device and a second device of a user is presented. The method comprises displaying, on the first device, a QR code generated by a synchronizer. The method further comprises capturing the QR code with the second device for displaying the data record and providing a registration option for associating the data record with the user at a relying party. The method further comprises performing a web authentication registration and, in response to that the web authentication registration flow has been performed successfully, performing an information access handover and securing process. The information access handover and securing process comprises sharing, by the second device, the unique user identifier and the device identifier with the first device, storing them at the first device, and securing access to the data record. A corresponding system and computer program are provided, too.
Owner:AMADEUS SAS

Methods and apparatus for storing and forwarding authentication of user equipment registration

Techniques for authenticating user equipment (UE) to a network are provided. For example, a method performed by a non-terrestrial node in a network includes: receiving a registration request from the UE for authenticating to the network; in response to the unavailability of a link between the non-terrestrial node and a terrestrial node of the network for forwarding the registration request; storing the registration request and assigning binding information associated with the non-terrestrial node to the UE; and sending a message to the UE including the binding information to be used by the UE.
Owner:NOKIA TECHNOLOGIES OY

System and method for forwarding authentication requests to a nearby authenticator

Systems and methods that involve receiving an authentication request initiated by a relying party application on a computing device via Web Authentication (WebAuthn) interface; connecting to a nearby companion device; forwarding the authentication request to the authenticator on the companion device; receiving a response to that authentication request from the authenticator on the companion device; and transmitting the authentication response back to the sender application on the computing device for authentication purposes.
Owner:IDMELON TECH INC

Enterprise-level gateway authentication methods and systems

This invention provides an enterprise-level gateway authentication method and system, comprising: Step S1: managing and authorizing published APIs; Step S2: the gateway uniformly calls the APIs to determine whether authentication is required for each API access request; if authentication is required for each API access request, proceed to Step S3; if authentication is not required for each API access request, proceed to Step S4; Step S3: if authentication is required for each API access request, perform pass-through authentication or TOKEN authentication; Step S4: if authentication is not required for each API access request, perform WEB authentication, and the gateway forwards the request to the backend microservice, where the microservice performs authentication. This invention, by designing three authentication modes, satisfies the needs of different scenarios, solves the problem of unified authentication and authorization at the gateway, and effectively protects backend service resources.
Owner:IND BANK CO +1

Systems and methods for orchestrating web authentication requests

In one embodiment, a method uses a web browser to receive an authentication request for an application from an authentication prompt of a client device. The method identifies an authentication protocol associated with web browser of the client device and use the authentication prompt to fetch a first challenge from an authentication service associated with the client device. The method uses the authentication prompt to communicate a subscribe to the authentication service and use a localhost to communicate to the application to provide the first challenge. In response to receiving the first challenge, the method uses one or more native Application Programming Interfaces (APIs) to determine an assertion associated with the authentication request and the authentication protocol. The method validates the assertion associated with the authentication request. In response to determining the assertion is valid, the method approves the authentication request.
Owner:CISCO TECHNOLOGY INC

4G Cat.1 passive Internet of Things monitoring system and method based on Vsim

PendingCN121547835APower managementSecurity arrangementPassive infrared sensorWeb authentication
The invention relates to the technical field of Internet of Things monitoring, in particular to a 4G Cat.1 passive Internet of Things monitoring system and method based on Vsim. The method comprises the following steps: pre-storing network authentication information of at least two operators through a VSim software unit; establishing low-power-consumption network connection between the 4G Cat.1 communication unit and a preset cloud management platform according to the network authentication information in a terminal dormant state; the method comprises the following steps: continuously monitoring heat radiation change in a target monitoring area through a passive infrared sensor, and when an effective moving event is detected, generating a hardware interruption wake-up signal; and waking up the terminal according to the hardware interrupt wakeup signal, and obtaining compressed audio and video data of the target monitoring area through the terminal. According to the method, millisecond-level wakeup and optimal link maintenance under permanent endurance of the passive camera are realized through a VSim multi-operator dynamic switching and electric quantity self-adaption strategy.
Owner:SHENZHEN YIYI IOT CO LTD

SRv6-based network cloud authentication method, storage medium and device

The invention belongs to the technical field of network cloud authentication, and relates to an SRv6-based network cloud authentication method, storage medium and device, and the method comprises the steps that a network client sends an SRv6-based network authentication request message to a network management cloud through a basic network; after receiving the SRv6-based network authentication request message, the network management cloud replies an SRv6 path packet to the network client initiating the request message; after receiving the SRv6 path packet, the network client processes the identity authentication information and sends the processed identity authentication information to the network service cloud; the network service cloud authenticates the identity authentication information, if the authentication succeeds, the network client accesses the network service cloud, and if the authentication fails, the network client does not access the network service cloud; according to the method provided by the invention, the identity authentication information of the network client is divided into a plurality of parts and is sent to the network service cloud through a plurality of paths, so that the sub-identity authentication information is forwarded according to different paths, and line repetition is effectively avoided.
Owner:SOUTHWEST UNIV

System and method for network authentication using device level authentication control

A system and method for network authentication with device level authentication control. The method includes receiving a first payment transaction request from a user device. In response to receiving agreement, the method comprises: enabling an authentication mode for the user to perform authentication using a selected authentication mode; and generating a key pair for linking with the enabled authentication mode to further authenticate the user device in one or more other transaction requests. The method further includes generating an enrollment completion message and executing the first payment transaction request upon successful signature using the linked key pair. In this way, the present disclosure may be configured to use device authentication data as part of a network authentication risk check, thereby providing a safer way to complete transactions.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

A chain-based BFT consensus method for unmanned aerial vehicle ad hoc network

The present application relates to the technical field of unmanned aerial vehicle swarm technology and blockchain technology, and particularly relates to a chain BFT consensus method for unmanned aerial vehicle ad hoc network. The present application selects a plurality of unmanned aerial vehicles for network authentication, constructs an unmanned aerial vehicle ad hoc network, constructs an ad hoc network topology structure, selects consensus nodes based on flight requirements, constructs a consensus network topology structure, assembles a consensus network based on a chain BFT protocol, divides the consensus nodes into a plurality of chain nodes and a plurality of backup chain nodes, optimizes the consensus network using a PSO algorithm to determine the chain sequence of each chain node in the consensus network, transmits information according to the chain sequence, and updates the topology structure in the consensus network based on a sudden situation to redetermine the chain sequence of each chain node. The present application guarantees the timing of information transmission, effectively determines the optimal chain sequence quickly and accurately, effectively guarantees the data transmission efficiency, effectively reduces the communication complexity, and effectively improves the consensus efficiency of the unmanned aerial vehicle group in the consensus network.
Owner:BEIHANG UNIV

Relay communication system and method of satellite terminal and authentication charging system

The invention relates to a relay communication system and method of a satellite terminal and an authentication and charging system, the satellite terminal is arranged to provide network access, charging request and account control functions, a relay server module and an authentication and charging server are arranged on the basis, and the relay server module is arranged between the satellite terminal and the authentication and charging server. The remote user dial-in authentication protocol interface communicates with the satellite terminal, so that data of the satellite terminal can be received, reported and analyzed. And the network is protected from being interfered by unauthorized visitors, so that high-security network authentication, authorization and charging service levels are provided.
Owner:DITAI (ZHEJIANG) COMM TECH CO LTD

Network service debugging method and device

The present application relates to the field of network communication technology, and provides a network service debugging method and device. The method includes: being applied to a terminal device, including: according to the selected operating mode, exchanging information between the virtual switch deployed by the terminal device and the target device determined according to the operating mode in each network device, and monitoring the data message of the target device; according to the data message, obtaining the debugging result of the network service corresponding to the target device; wherein each network device includes a client device to be connected to the network, and an authentication server for performing network access authentication of the client device; the network service corresponding to the client device includes a network access service, and the network service corresponding to the authentication server includes a network authentication service. The network service debugging method provided in the embodiment of the present application can improve the reliability of network services.
Owner:HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3

Network authentication of user equipment access to edge data networks

A network can authenticate a user equipment (UE) to access an edge data network. The network generates a first credential based on a second credential generated for a procedure between the UE and a cellular network corresponding to a network component; receives, in response to the UE transmitting an application registration request to a server associated with the edge data network, an identifier associated with the first credential from another network component; and retrieves the first credential based on the identifier. The network also receives a multi-access edge computing (MEC) authorization parameter, verifies the MEC authorization parameter, and transmits an authentication verification response to the second network component.
Owner:APPLE INC

Wireless network authentication method, device, equipment and storage medium

The present application discloses a wireless network authentication method, apparatus, device and storage medium, which relates to the field of Internet of Things application technology, including: obtaining a wireless network usage request sent by a mobile terminal of a wireless network user, and sending a first preset portal page to the mobile terminal based on the wireless network request and collecting the attribute information of the mobile terminal, and obtaining the identity authentication method selected by the wireless network user for social media identity authentication; if the verification is passed, determining whether the wireless network user has followed the preset social media account; if the wireless network user has followed the account, sending the attribute information to the preset wireless network device through a preset information sending channel, so that the wireless network user can use the wireless network usage service. In this way, it is possible to guide traffic for the wireless network provider while simplifying the access steps of the network user.
Owner:CHENGDU SKSPRUCE TECH

Behavior of user equipment when emergency bearer service connection fails due to network authentication failure

In one aspect of the disclosure, a method, a computer readable medium, and an apparatus are provided. The device may be a user equipment (UE). A user equipment receives an AUHENTICATION REJECT message from a network during an attempt to establish an emergency service through a first procedure. The user equipment performs a generic operation of authentication rejection. And the user equipment informs the upper layer of failure of the first process. Alternatively, the user equipment attempts to perform a second process.
Owner:MEDIATEK SINGAPORE PTE LTD

Identity authentication method based on dynamic graph network and related device

The invention belongs to the field of identity authentication, and discloses an identity authentication method based on a dynamic graph network and a related device, and the method comprises the steps: collecting interaction data of a plurality of touch screen sliding events of a user, constructing a single-event sliding graph of each touch screen sliding event of the user according to the interaction data, and combining the single-event sliding graphs according to a time sequence to obtain a sliding graph sequence; inputting the sliding graph sequence into a pre-trained dynamic graph network authentication model to obtain a user identity authentication result; wherein the dynamic graph network authentication model comprises a feature extraction part used for extracting feature vectors of a sliding graph sequence and a classification authentication part used for carrying out identity classification according to the feature vectors; the feature extraction part comprises a graph convolutional network and a long-short-term memory network which are connected in sequence, and the classification authentication part is constructed based on a full-connection module. The whole-process identity authentication can be completed only through interaction data generated when the user interacts with the touch screen, and compared with an existing identity authentication method, an authentication mode better in performance and higher in generalization is provided.
Owner:XI AN JIAOTONG UNIV

Distributed network architecture and authentication method

The invention provides a distributed network architecture and an authentication method, and relates to the technical field of network information security, and the distributed network architecture comprises a plurality of subnetworks. Wherein a first network element is deployed in each subnet; wherein in the distributed network authentication, the first network element is used for representing the identity of a subnet where the first network element is located; and / or the first network element has a security protection function. Thus, authentication of the subnet where the first network element is located can be realized through authentication of the first network element, and / or the first network element performs security protection on the subnet where the first network element is located, so that secure communication between different network resources can be ensured.
Owner:CHINA MOBILE COMM LTD RES INST +1

Network authentication service security

Some embodiments provide or utilize technology which increases the security of network authentication operations, such as Kerberos operations, New Technology LAN Manager operations, or other network authentication operations which utilize security tickets or security tokens or both. In some embodiments, a user machine (also known as a client machine) receives an authentication data structure (ADS) which includes one or more security tickets or security tokens or both. Embodiments constrain the ADS according to at least one security requirement, such as a volatile-memory-only constraint, a secured-memory-only constraint, or a multilayer encryption constraint. Embodiments also transmit the ADS from the machine as a part of performing the network authentication service. Some embodiments inhibit virtual memory, or memory dumping, or both. Some embodiments bind the ADS to the user machine, and some embodiments limit ADS usage counts.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network authentication method, device, system, electronic device and storage medium

This disclosure provides a network authentication method, apparatus, system, electronic device, and storage medium. The main technical features include: generating a set of authentication vectors based on a root key; sending the set of authentication vectors to an on-board network device, so that the on-board network device can perform authentication interaction with the user terminal when receiving an authentication request from the user terminal. By pre-generating and sending a set of authentication vectors to the on-board network device, the on-board network device can complete the authentication interaction based on the set of authentication vectors, reducing the reliance of the authentication process on real-time satellite-to-ground communication, effectively avoiding the impact of power supply link interruptions or delays on the authentication process, and ensuring the smooth progress of user terminal authentication.
Owner:CHINA MOBILE COMM LTD RES INST +1

A multi-purpose network password service system

The application relates to the field of network password technology, and provides a multi-purpose network password service system, wherein a Web authentication service flow and a virtual machine access service flow of an Untrust domain are connected to a vLB in a DMZ domain and a vAG in the DMZ domain through SSLVPN and WAF; the vLB is connected to a login server through a firewall by the Web authentication service flow, and then connected to a desktop controller; the desktop controller is connected to a password service center through the Web authentication service flow; the password service center is connected to a user active directory AD through the firewall by the Web authentication service flow; the vAG is connected to the desktop controller through the virtual machine access service flow, and the vAG is connected to a user desktop through the firewall by the virtual machine access service flow; the user desktop is connected to the user active directory AD through the firewall by the virtual machine access service flow; and the password service center realizes the assistance of the cloud desktop of a customer in the password evaluation, and solves the problem of the password evaluation of the cloud desktop of the customer.
Owner:BEIJING HUIQUAN CHUANGAN TECHNOLOGY CO LTD

Policy based multi-link operation access for devices

Methods to restrict the number of multi-link operation (MLO) links while Layer 3 (web) authentication is in progress and permit additional links only after the web authentication is completed. The methods involve obtaining an MLO policy for establishing a multi-link connection to a wireless network and performing an MLO association for establishing the multi-link connection to the wireless network based on the MLO policy in which the MLO association is restricted to a single link during a web authentication for access to the wireless network.
Owner:CISCO TECHNOLOGY INC

System, method, storage medium and equipment for mobile network access

The disclosure relates to a System, Method, Storage medium and Equipment for Mobile Network Access. The system includes: a first certificate authority node located in a block chain network, configured to authorize a first authentication certificate indicating an identity of the first network authentication service node to the first network authentication service node, authorize a first UE certificate indicating an identity of user equipment to the user equipment of the first operator, and store first UE certificate revocation information and a first CA certificate indicating an identity of the first certificate authority node to a block chain, and a first network authentication service node, configured to obtain the first UE certificate revocation information and the first CA certificate from the block chain, perform mutual identity authentication with the user equipment when receiving a first access authentication message, make the user equipment access a mobile network when completing the authentication.
Owner:CHONGQING XINGJIE SHUXING TECHNOLOGY PARTNERSHIP ENTERPRISE (LLP)

Iot security authentication method based on communication network

This invention relates to the field of IoT security authentication technology, specifically to an IoT security authentication method based on a communication network. The method includes: when an IoT device connects to the network, it collects its own multi-dimensional physical fingerprint information, including the device's hardware signature, firmware version hash value, and current operating environment signal feature profile. This information is then encapsulated as a component of an identity credential and combined with a dynamic temporary identifier to construct an initial authentication request message, which is then sent. The network authentication entity parses the message, queries the device's legitimate fingerprint feature database based on the dynamic temporary identifier to obtain a registered physical fingerprint template, and calculates a comprehensive similarity by performing multi-level matching between the real-time fingerprint and the template. When the similarity exceeds a threshold, a session key seed with a time-limited window is generated, deriving a pair of temporary communication keys. This method improves the authenticity and security of IoT device access authentication through multi-dimensional physical fingerprint fusion and dynamic key derivation.
Owner:CHINA TELECOM CONSTR 4TH ENG

Space-ground integrated network authentication method, apparatus and device, and medium

The embodiment of the invention provides a space-ground integrated network authentication method and device, equipment and a medium, and relates to the technical field of satellite communication. The method comprises the steps that a terminal sends an authentication request to a satellite; the authentication request at least comprises a terminal identifier, a terminal public key and authentication information; in response to the fact that the satellite passes verification according to the authentication information, the satellite stores the terminal identifier and forwards the terminal public key to the ground station; the ground station generates a session key and a ciphertext based on the terminal public key, and returns the ciphertext to the satellite; the satellite returns authentication response information to the terminal; the authentication response information at least comprises a ciphertext; and the terminal decrypts the ciphertext based on the terminal private key to obtain the session key. According to the method, the authentication process is transferred to satellite processing, the terminal authentication process is simplified, the single-point bottleneck of high-concurrency access is eliminated, the bidirectional identity authentication of the satellite and the user is realized through the PQC algorithm, and the network security is improved.
Owner:CHINA TELECOM CORP LTD +1

Method and system for exchanging web authentication protocols for public cloud migrations

A system and a method for authenticating user access to a service that is hosted on a public cloud platform are provided. The method includes: receiving an access request from a user that relates to a service that is hosted on a public cloud platform; preliminarily authenticating the access request by using a legacy authentication protocol that is not sufficiently secure for accessing the first service via the public cloud platform; generating and validating, based on a result of the preliminary authentication, a legacy protocol certification; retrieving roles that are associated with the user; obtaining, based on the user roles, a token that is usable for controlling access to the service via the public cloud platform; and augmenting the access request with the token and a signature to facilitate an authentication of the access request by the public cloud platform, while excluding the legacy protocol certification.
Owner:JPMORGAN CHASE BANK NA

Web authentication enhancement method and system based on user behavior analysis

The invention relates to the technical field of network security, in particular to a Web authentication enhancement method and system based on user behavior analysis, and the method comprises the following steps: collecting multi-dimensional behavior data of a user, including login behavior data, access behavior data, operation behavior data and equipment fingerprint data; predefining a behavior rule base comprising a login time limit rule, an equipment fingerprint matching rule, an access frequency threshold rule and an operation path compliance rule; the method has the beneficial effects that the system can timely discover and prevent potential security threats, such as cross-site script attack, SQL injection attack, unauthorized access and the like, through predefined behavior rules and real-time comparison of user behaviors. The collection and analysis of the multi-dimensional behavior data enable the system to more comprehensively understand the behavior characteristics of the user, thereby improving the accuracy of authentication.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD