Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

63 results about "Web authentication" patented technology

Web service authentication is the verification of a user’s identity before allowing access to a network or website. Certificates verify the identity of a Web server to users.

Unmanned aerial vehicle group mutual authentication and key agreement method based on PUF (Physical Unclonable Function)

The invention discloses an unmanned aerial vehicle group mutual authentication and key agreement method based on PUF, and relates to the technical field of unmanned aerial vehicle group communication security and network authentication, and the method comprises the steps: S1, obtaining change data through monitoring unmanned aerial vehicle node position coordinate tracking and connection signal intensity in real time, the method comprises the following steps: S1, carrying out state change detection on a node moving speed by adopting position deviation calculation and connection interruption records to obtain a position coordinate tracking sequence after data synchronization update, S2, carrying out data point clustering on the position coordinate tracking sequence by adopting a K-Means clustering algorithm, processing the connection interruption record groups through central point iteration and distance measurement calculation to obtain change vector groups under group number setting; the PUF-based unmanned aerial vehicle group mutual authentication and key agreement method not only effectively solves the problems of slow response, easy communication interruption, unstable key agreement and the like of a traditional unmanned aerial vehicle group authentication mechanism, but also realizes comprehensive improvement in the aspects of safety, robustness and intelligence.
Owner:GUANGZHOU YOUFEI INTELLIGENT EQUIP CO LTD

Network authentication and authorization issue detection

Techniques are disclosed that enable a system to determine whether an error associated with a cloud-based authentication, authorization, and accounting (AAA) service has occurred. The techniques include obtaining, for a plurality of network access service (NAS) devices at a site, data indicative of authentication attempts for client devices with a cloud-based AAA service. The techniques include identifying, based on the data, whether one or more errors occurred for the authentication attempts; and correlating the one or more errors across the plurality of NAS devices at the site to determine whether the one or more errors are indicative of an issue associated with the AAA service. The techniques further include determining at least one remediation action for the issue associated with the AAA service.
Owner:JUNIPER NETWORKS INC

Network authentication toxicity assessment

A system and method for scoring and enforcing authentication standards that actually enable zero trust network security principles when combined with stateful authentication object tracking, authentication object manipulation and forgery detection, and assessment of authentication and identity attack surface. The methodology involves gathering all authentication objects issued by a network, storing the authentication objects in a centralized location for use in stateful deterministic authentication object tracking, scoring the completeness of the authentication observations, assessing the quality of the authentication observations, and assigning organization-specific penalty functions.
Owner:QOMPLX INC

Information access handover

A computerized method of information access handover between a first device and a second device of a user is presented. The method comprises displaying, on the first device, a QR code generated by a synchronizer. The method further comprises capturing the QR code with the second device for displaying the data record and providing a registration option for associating the data record with the user at a relying party. The method further comprises performing a web authentication registration and, in response to that the web authentication registration flow has been performed successfully, performing an information access handover and securing process. The information access handover and securing process comprises sharing, by the second device, the unique user identifier and the device identifier with the first device, storing them at the first device, and securing access to the data record. A corresponding system and computer program are provided, too.
Owner:AMADEUS SAS

Methods and apparatus for storing and forwarding authentication of user equipment registration

Techniques for authenticating user equipment (UE) to a network are provided. For example, a method performed by a non-terrestrial node in a network includes: receiving a registration request from the UE for authenticating to the network; in response to the unavailability of a link between the non-terrestrial node and a terrestrial node of the network for forwarding the registration request; storing the registration request and assigning binding information associated with the non-terrestrial node to the UE; and sending a message to the UE including the binding information to be used by the UE.
Owner:NOKIA TECHNOLOGIES OY

Enterprise-level gateway authentication methods and systems

This invention provides an enterprise-level gateway authentication method and system, comprising: Step S1: managing and authorizing published APIs; Step S2: the gateway uniformly calls the APIs to determine whether authentication is required for each API access request; if authentication is required for each API access request, proceed to Step S3; if authentication is not required for each API access request, proceed to Step S4; Step S3: if authentication is required for each API access request, perform pass-through authentication or TOKEN authentication; Step S4: if authentication is not required for each API access request, perform WEB authentication, and the gateway forwards the request to the backend microservice, where the microservice performs authentication. This invention, by designing three authentication modes, satisfies the needs of different scenarios, solves the problem of unified authentication and authorization at the gateway, and effectively protects backend service resources.
Owner:IND BANK CO +1

Systems and methods for orchestrating web authentication requests

In one embodiment, a method uses a web browser to receive an authentication request for an application from an authentication prompt of a client device. The method identifies an authentication protocol associated with web browser of the client device and use the authentication prompt to fetch a first challenge from an authentication service associated with the client device. The method uses the authentication prompt to communicate a subscribe to the authentication service and use a localhost to communicate to the application to provide the first challenge. In response to receiving the first challenge, the method uses one or more native Application Programming Interfaces (APIs) to determine an assertion associated with the authentication request and the authentication protocol. The method validates the assertion associated with the authentication request. In response to determining the assertion is valid, the method approves the authentication request.
Owner:CISCO TECHNOLOGY INC

4G Cat.1 passive Internet of Things monitoring system and method based on Vsim

PendingCN121547835APower managementSecurity arrangementPassive infrared sensorWeb authentication
The invention relates to the technical field of Internet of Things monitoring, in particular to a 4G Cat.1 passive Internet of Things monitoring system and method based on Vsim. The method comprises the following steps: pre-storing network authentication information of at least two operators through a VSim software unit; establishing low-power-consumption network connection between the 4G Cat.1 communication unit and a preset cloud management platform according to the network authentication information in a terminal dormant state; the method comprises the following steps: continuously monitoring heat radiation change in a target monitoring area through a passive infrared sensor, and when an effective moving event is detected, generating a hardware interruption wake-up signal; and waking up the terminal according to the hardware interrupt wakeup signal, and obtaining compressed audio and video data of the target monitoring area through the terminal. According to the method, millisecond-level wakeup and optimal link maintenance under permanent endurance of the passive camera are realized through a VSim multi-operator dynamic switching and electric quantity self-adaption strategy.
Owner:SHENZHEN YIYI IOT CO LTD

SRv6-based network cloud authentication method, storage medium and device

The invention belongs to the technical field of network cloud authentication, and relates to an SRv6-based network cloud authentication method, storage medium and device, and the method comprises the steps that a network client sends an SRv6-based network authentication request message to a network management cloud through a basic network; after receiving the SRv6-based network authentication request message, the network management cloud replies an SRv6 path packet to the network client initiating the request message; after receiving the SRv6 path packet, the network client processes the identity authentication information and sends the processed identity authentication information to the network service cloud; the network service cloud authenticates the identity authentication information, if the authentication succeeds, the network client accesses the network service cloud, and if the authentication fails, the network client does not access the network service cloud; according to the method provided by the invention, the identity authentication information of the network client is divided into a plurality of parts and is sent to the network service cloud through a plurality of paths, so that the sub-identity authentication information is forwarded according to different paths, and line repetition is effectively avoided.
Owner:SOUTHWEST UNIV

A chain-based BFT consensus method for unmanned aerial vehicle ad hoc network

The present application relates to the technical field of unmanned aerial vehicle swarm technology and blockchain technology, and particularly relates to a chain BFT consensus method for unmanned aerial vehicle ad hoc network. The present application selects a plurality of unmanned aerial vehicles for network authentication, constructs an unmanned aerial vehicle ad hoc network, constructs an ad hoc network topology structure, selects consensus nodes based on flight requirements, constructs a consensus network topology structure, assembles a consensus network based on a chain BFT protocol, divides the consensus nodes into a plurality of chain nodes and a plurality of backup chain nodes, optimizes the consensus network using a PSO algorithm to determine the chain sequence of each chain node in the consensus network, transmits information according to the chain sequence, and updates the topology structure in the consensus network based on a sudden situation to redetermine the chain sequence of each chain node. The present application guarantees the timing of information transmission, effectively determines the optimal chain sequence quickly and accurately, effectively guarantees the data transmission efficiency, effectively reduces the communication complexity, and effectively improves the consensus efficiency of the unmanned aerial vehicle group in the consensus network.
Owner:BEIHANG UNIV

Network authentication of user equipment access to edge data networks

A network can authenticate a user equipment (UE) to access an edge data network. The network generates a first credential based on a second credential generated for a procedure between the UE and a cellular network corresponding to a network component; receives, in response to the UE transmitting an application registration request to a server associated with the edge data network, an identifier associated with the first credential from another network component; and retrieves the first credential based on the identifier. The network also receives a multi-access edge computing (MEC) authorization parameter, verifies the MEC authorization parameter, and transmits an authentication verification response to the second network component.
Owner:APPLE INC

Behavior of user equipment when emergency bearer service connection fails due to network authentication failure

In one aspect of the disclosure, a method, a computer readable medium, and an apparatus are provided. The device may be a user equipment (UE). A user equipment receives an AUHENTICATION REJECT message from a network during an attempt to establish an emergency service through a first procedure. The user equipment performs a generic operation of authentication rejection. And the user equipment informs the upper layer of failure of the first process. Alternatively, the user equipment attempts to perform a second process.
Owner:MEDIATEK SINGAPORE PTE LTD

Distributed network architecture and authentication method

The invention provides a distributed network architecture and an authentication method, and relates to the technical field of network information security, and the distributed network architecture comprises a plurality of subnetworks. Wherein a first network element is deployed in each subnet; wherein in the distributed network authentication, the first network element is used for representing the identity of a subnet where the first network element is located; and / or the first network element has a security protection function. Thus, authentication of the subnet where the first network element is located can be realized through authentication of the first network element, and / or the first network element performs security protection on the subnet where the first network element is located, so that secure communication between different network resources can be ensured.
Owner:CHINA MOBILE COMM LTD RES INST +1

Network authentication service security

Some embodiments provide or utilize technology which increases the security of network authentication operations, such as Kerberos operations, New Technology LAN Manager operations, or other network authentication operations which utilize security tickets or security tokens or both. In some embodiments, a user machine (also known as a client machine) receives an authentication data structure (ADS) which includes one or more security tickets or security tokens or both. Embodiments constrain the ADS according to at least one security requirement, such as a volatile-memory-only constraint, a secured-memory-only constraint, or a multilayer encryption constraint. Embodiments also transmit the ADS from the machine as a part of performing the network authentication service. Some embodiments inhibit virtual memory, or memory dumping, or both. Some embodiments bind the ADS to the user machine, and some embodiments limit ADS usage counts.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network authentication method, device, system, electronic device and storage medium

This disclosure provides a network authentication method, apparatus, system, electronic device, and storage medium. The main technical features include: generating a set of authentication vectors based on a root key; sending the set of authentication vectors to an on-board network device, so that the on-board network device can perform authentication interaction with the user terminal when receiving an authentication request from the user terminal. By pre-generating and sending a set of authentication vectors to the on-board network device, the on-board network device can complete the authentication interaction based on the set of authentication vectors, reducing the reliance of the authentication process on real-time satellite-to-ground communication, effectively avoiding the impact of power supply link interruptions or delays on the authentication process, and ensuring the smooth progress of user terminal authentication.
Owner:CHINA MOBILE COMM LTD RES INST +1

Policy based multi-link operation access for devices

Methods to restrict the number of multi-link operation (MLO) links while Layer 3 (web) authentication is in progress and permit additional links only after the web authentication is completed. The methods involve obtaining an MLO policy for establishing a multi-link connection to a wireless network and performing an MLO association for establishing the multi-link connection to the wireless network based on the MLO policy in which the MLO association is restricted to a single link during a web authentication for access to the wireless network.
Owner:CISCO TECHNOLOGY INC

Iot security authentication method based on communication network

This invention relates to the field of IoT security authentication technology, specifically to an IoT security authentication method based on a communication network. The method includes: when an IoT device connects to the network, it collects its own multi-dimensional physical fingerprint information, including the device's hardware signature, firmware version hash value, and current operating environment signal feature profile. This information is then encapsulated as a component of an identity credential and combined with a dynamic temporary identifier to construct an initial authentication request message, which is then sent. The network authentication entity parses the message, queries the device's legitimate fingerprint feature database based on the dynamic temporary identifier to obtain a registered physical fingerprint template, and calculates a comprehensive similarity by performing multi-level matching between the real-time fingerprint and the template. When the similarity exceeds a threshold, a session key seed with a time-limited window is generated, deriving a pair of temporary communication keys. This method improves the authenticity and security of IoT device access authentication through multi-dimensional physical fingerprint fusion and dynamic key derivation.
Owner:CHINA TELECOM CONSTR 4TH ENG

Space-ground integrated network authentication method, apparatus and device, and medium

The embodiment of the invention provides a space-ground integrated network authentication method and device, equipment and a medium, and relates to the technical field of satellite communication. The method comprises the steps that a terminal sends an authentication request to a satellite; the authentication request at least comprises a terminal identifier, a terminal public key and authentication information; in response to the fact that the satellite passes verification according to the authentication information, the satellite stores the terminal identifier and forwards the terminal public key to the ground station; the ground station generates a session key and a ciphertext based on the terminal public key, and returns the ciphertext to the satellite; the satellite returns authentication response information to the terminal; the authentication response information at least comprises a ciphertext; and the terminal decrypts the ciphertext based on the terminal private key to obtain the session key. According to the method, the authentication process is transferred to satellite processing, the terminal authentication process is simplified, the single-point bottleneck of high-concurrency access is eliminated, the bidirectional identity authentication of the satellite and the user is realized through the PQC algorithm, and the network security is improved.
Owner:CHINA TELECOM CORP LTD +1

Web authentication enhancement method and system based on user behavior analysis

The invention relates to the technical field of network security, in particular to a Web authentication enhancement method and system based on user behavior analysis, and the method comprises the following steps: collecting multi-dimensional behavior data of a user, including login behavior data, access behavior data, operation behavior data and equipment fingerprint data; predefining a behavior rule base comprising a login time limit rule, an equipment fingerprint matching rule, an access frequency threshold rule and an operation path compliance rule; the method has the beneficial effects that the system can timely discover and prevent potential security threats, such as cross-site script attack, SQL injection attack, unauthorized access and the like, through predefined behavior rules and real-time comparison of user behaviors. The collection and analysis of the multi-dimensional behavior data enable the system to more comprehensively understand the behavior characteristics of the user, thereby improving the accuracy of authentication.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Network-based authentication in an ambient internet of things architecture

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, an ambient Internet of Things (AIoT) device may perform an authentication and key agreement procedure with a network function to generate a root key. The AIoT device may receive, from an AIoT controller, a key confirmation message. The AIoT device may generate, using the key confirmation message and the root key, a protection key. The AIoT device may transmit, to the AIoT controller, a key confirmation acknowledgement using the protection key and in response to the key confirmation message. Numerous other aspects are described.
Owner:QUALCOMM INC

Auto-form fill based website authentication

A method for a website authentication is provided. The method includes receiving a reference uniform resource locator (URL) at a browser and determining whether the reference URL adheres to an authentication protocol including a credential identifier and a web authentication host URL. When the reference URL adheres to the authentication protocol, the method also includes extracting the credential identifier and the web authentication host URL from the reference URL. The method further includes obtaining credential data from a remote service using the credential identifier and sending web authentication instructions to the browser. The web authentication instructions include the web authentication host URL and the credential data.
Owner:GOOGLE LLC

Apparatus, system, and method of federated authentication service (FAS) for wireless communication roaming

For example, a Federated Authentication Service (FAS) server may be configured to register the FAS server with a wireless communication roaming federation service; to authenticate a user of a mobile device according to a network authentication protocol of the wireless communication roaming federation service, e.g., over a Remote Authentication Dial-In User Service (RADIUS) over Transport Layer Security (RADSec) tunnel between the FAS server and an Access Network Provider (ANP); to identify an Identity Provider (IDP) for the user based on user information for the user received from the ANP via the RADSec tunnel; to trigger user authentication of the user with the IDP for the user via an authentication interface between the FAS server and the IDP for the user; and based on a determination that the user is successfully authenticated with the IDP for the user, to send an authentication success message to the ANP via the RADSec tunnel.
Owner:INTEL CORP

Authentication and network access control method for FTTR

The invention relates to the technical field of network and security, in particular to an authentication and network access control method for FTTR. The method comprises the following steps: acquiring initial communication data of equipment to be accessed; generating an equipment security level initial mapping table based on the initial communication data; performing environment context collection based on the equipment security level initial mapping table to obtain network environment context data; generating an authentication strategy according to the equipment security level initial mapping table and the network environment context data to obtain a differential authentication strategy set; performing virtual slice demand analysis according to the equipment security level initial mapping table to obtain virtual slice configuration parameters; and performing micro-isolation virtual network slice creation based on the virtual slice configuration parameters to obtain a virtual network slice topology. According to the invention, the differentiated requirements of different types of equipment on network security and access authority can be met, and the flexibility and adaptability of network authentication and access control are improved.
Owner:UNIONMANTECH

Network authentication method and device, equipment, and storage medium

The application discloses a network authentication method and device, equipment and a storage medium. The method comprises the following steps: a client on a terminal device determines an extension field of a current region of the terminal device from extension fields corresponding to respective regions; the client acquires authentication information corresponding to the extension field of the current region; the client writes the authentication information into the extension field of the current region to obtain extension information; and the client sends the extension information to system firmware of the terminal device, so that the system firmware performs information interaction with a network authentication device based on the extension information, thereby authenticating whether the terminal device has network access permission.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Network authentication using UE SIM verification

Network authentication, that is more resistant to cyberattacks, uses verification of subscriber identity modules (SIMs) in user equipment (UEs) such as cellphones. A person visits a website with a computer, or calls customer service, to access their user account and their UE receives an interaction identifier (ID) that includes a session ID, an identifier of the customer ID or their UE, and a time indicator. This may be in the form of a QR code displayed on the computer screen or a text message from customer service. The UE forwards the interaction ID to a verification website, providing the IP address or ID stored in the SIM. The verification website compares the UE-provided information with what has been stored earlier by the UE's home wireless carrier to verify the SIM in the UE, providing a proxy for verifying the identity of the person.
Owner:T MOBILE US INC

Network authentication method and device, terminal and network-side equipment

The application provides a network authentication method, device, terminal and network side equipment. The method comprises the following steps: receiving a first authentication parameter sent by the network side equipment; generating an authentication response message and a root key of a current session according to the first authentication parameter; in the case that the authentication response message indicates that the network authentication fails, performing encryption processing on the authentication response message by using an encryption key and an integrity key, wherein the authentication response message comprises an error type corresponding to the network authentication failure; the encryption key and the integrity key are obtained according to the root key of the current session; and sending the authentication response message after the encryption processing to the network side equipment. In the embodiment of the application, the terminal derives the encryption key and the integrity key by using the root key of the current session known by the network side equipment, and performs encryption on the authentication response message by using a symmetric encryption algorithm, so that the attack of an attacker can be avoided.
Owner:CHINA MOBILE COMM LTD RES INST +1

Network apparatus and network authentication method thereof

A network apparatus and a network authentication method thereof are provided. The network apparatus serving as a server end includes a network interface device and a processor. The network interface device is configured to connect to a network. The processor is coupled to the network interface device, and configured to receive a network packet send by a client end through the network, acquire a verification data commonly agreed with the client end, and establish a network connection with the client end in response to a verification data recorded in the network packet matching the acquired verification data.
Owner:MOXA INC

Network Authentication Evaluation

This patent relates to determining whether network authentication events are legitimate or malicious. One example includes receiving network data relating to past timestamped authentication events between network users and network devices and extracting graphical features from the timestamped authentication events. The example also includes extracting temporal features from the timestamped authentication events and training a temporal graph authentication anomaly detection model with both the extracted graphical features and the extracted temporal features.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Information access handover

A computerized method of information access handover between a first device and a second device of a user is presented. The method comprises displaying, on the first device, a QR code generated by a synchronizer. The method further comprises capturing the QR code with the second device for displaying the data record and providing a registration option for associating the data record with the user at a relying party. The method further comprises performing a web authentication registration and, in response to that the web authentication registration flow has been performed successfully, performing an information access handover and securing process. The information access handover and securing process comprises sharing, by the second device, the unique user identifier and the device identifier with the first device, storing them at the first device, and securing access to the data record. A corresponding system and computer program are provided, too.
Owner:AMADEUS SAS

Network access authentication method and system, remote interaction system, VPN

Network access authentication method and system, remote interaction system, VPN. Embodiments of the present application disclose a remote interaction system of a medical imaging system, a network access authentication system and method, a computer readable storage medium, and a VPN. The medical imaging system comprises a medical imaging device and a computer device for controlling the medical imaging device, the computer device being connected to a local network to be accessed. The network authentication system comprises an authentication module and a resource scheduling module. The authentication module is configured to receive an authorized connection request from an authorized end, send the authorized connection request to a remote end, and receive a response message from the remote end. The resource scheduling module is configured to receive the authorized connection request sent by the authentication module, and allocate a virtual network server and generate a security rule based on the authorized connection request. The remote interaction system comprises the network authentication system and the virtual network server allocated by the resource scheduling module.
Owner:GE PRECISION HEALTHCARE LLC