Patent classifications
G06F2221/2139
Component verification and revocation
In one example, a non-transitory computer readable medium for component verification and revocation includes instructions for a processor to verify that a component in a device is valid using a verification service and consequently enable a premium service. The processor may later use information from the verification service that the component is no longer valid and consequently alter the premium service.
Sideband authentication of storage device
Various aspects include a continuous authentication system for a storage system. The continuous authentication system includes a host having an encryption unit. The continuous authentication system includes a storage device having a decryption unit. The continuous authentication system includes a first physical connection between the host and the storage device. The first physical connection may be configured to transfer I/Os. The continuous authentication system may include a second physical connection between the host and the storage device. The encryption unit may be configured to encrypt a continuous authentication signal. The host may be configured to transmit the continuous authentication signal through the second physical connection. The storage device may be configured to receive the continuous authentication signal through the second physical connection. The decryption unit may be configured to decrypt the continuous authentication signal. When the second physical connection is tampered with, the storage device may stop processing the I/Os.
COMPUTER-IMPLEMENTED CONTINUOUS CONTROL METHOD, SYSTEM AND COMPUTER PROGRAM
The present disclosure relates to improving ways of making decisions made by, or with the assistance of, computing systems. One aspect relates to a computer-implemented continuous control method, the method comprising: obtaining a policy decision according to an application of a policy to an inference; the inference being of an authorised user's state of mind over a time interval, determined according to a plurality of biometric readings obtained passively from the user over the time interval for continuous authentication of the user; the user's identity having been continuously authenticated according to the plurality of biometric readings; and causing one or more actions in accordance with the policy decision. Further aspects relate to a data processing system comprising means for carrying out such a method, a computer program comprising instructions which, when the program is executed by a computer, cause the computer to carry out such a method, a computer-readable data carrier having stored thereon such a computer program and a data carrier signal carrying such a computer program.
Document security enhancement
A method of providing, by a computing device, access to a user of sections of an electronic document. The method includes receiving, by a computing device, a computerized image of a user accessing an electronic document. The computing device further accesses a facial recognition database and compares the computerized image to one or more entries in the facial recognition database to determine an identity of the user. The user is provided access to one or more sections of the electronic document based upon the identity of the user.
Method and system for proof of work (POW) based protection of resources
State-of-the-art techniques hardly attempt to address controlled resource access problem in context of Basic Emergent Users (BEUs). Embodiments of the present disclosure provide a method and system for Proof of Work (POW) based protection of resources. The method includes using the POW for work done by BEUs in physical world and mapping it to digital world to generate crypto currency in terms of credit score, wherein an end user is eligible or authorized to use a resource of an entity to get a desired service if accumulated credit score is above a credit threshold. Gaining points to improve the credit score is challenging as it is based on percentage of compliance achieved by the BEU through actual work in accordance with a compliance protocol. Further, the method includes authenticating the authorized user based on a set of questions with increasing difficulty, derived based on a culture graph.
METHOD AND DEVICE FOR FINGERPRINT VERIFICATION
The present disclosure relates to a method for fingerprint verification. The method includes performing a first fingerprint verification to obtain a first verification result in a process during which a physical key provided with a fingerprint verification component is pressed. If the first verification result is a failed verification, the method further includes performing a second fingerprint verification to obtain a second verification result in a process during which the physical key is raised, and using the second verification result as a final verification result of fingerprint verification.
CONTINUOUS SENSITIVE CONTENT AUTHENTICATION
Continuous sensitive content authentication is described. In one example, a request to open content, such as a photograph, spreadsheet, or text-based document, among other types of content, is received. Based on a sensitivity level or access profile rule associated with the content, an individual can be prompted to perform an authentication procedure before the content is displayed. The content can be displayed in response to a verification using the authentication procedure or removed (or not displayed) in response to a rejection using the authentication procedure. Additionally, the authentication procedure can be continuously polled to confirm the verification while the content is displayed. While the content is being displayed, the content can be removed from display at any time if the authentication procedure no longer produces the verification result. In some cases, the content can also be deleted after a rejection is detected using the authentication procedure.
SYSTEM AND METHOD FOR OMNICHANNEL TEXT-BASED COMMUNICATION UTILIZING ADAPTIVE INSTRUCTIONS
A system and method for omnichannel text-based communication using adaptive instructions. The system is a cloud-based network containing a campaign database, an analytics database, an adaptive advertisement management, a short message service server with automated response capabilities, and user mobile and compute devices that transmit a vehicle description page associated with an advertisement campaign embedded with a communication initiator for display on a customer computing device. Taken together or in part, said system optimizes advertising campaigns across multiple platforms, provides strong analytics for all advertising types while allowing users to engage with advertising quickly and in a real-time automated fashion.
METHOD AND SYSTEM FOR COMMUNICATION SESSION MANAGEMENT WITH ENHANCED SECURITY
A device captures, at the time of authentication to a secured session, secondary authentication data of the user that has authenticated using primary authentication credentials. Then, during the session, the system is caused to re-authenticate the user using the secondary authentication credentials (such as original and current user's face images). The system actively monitors the face visible to a camera of the computing device. The system compares the current face to the face image captured at the time of authentication. If the system fails to detect the same face captured initially at the time of authentication, then the system automatedly ends or otherwise locks the session to secure that session from an unauthorized user. Accordingly, the system does not rely merely upon initial authentication for an entire session, but rather reauthenticates the user during a single session in order for the session to be permitted to continue.
Device, integrated circuit and methods for detecting, responding to and removing a compromising attack
A device and methods are described that comprise at least one host application and a rich execution environment. At least one interface is operably coupled to the REE for communicating with a remote server. A security sub-system comprises a security monitoring and control circuit coupled to the REE and connectable to the remote server via the REE and the at least one interface. The security monitoring and control circuit comprises an analytics circuit configured to detect an anomaly following a compromisation of the device. The security monitoring and control circuit is arranged to treat the REE as an untrusted component and in response to a detection of a compromisation of the REE or a component in the device that is accessible by the REE by the analytics circuit, the security monitoring and control circuit is configured to re-establish a secure connection to the remote server that tunnels through the REE and at least partially removes the compromisation from the device.