Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

34 results about "Adversary" patented technology

In cryptography, an adversary (rarely opponent, enemy) is a malicious entity whose aim is to prevent the users of the cryptosystem from achieving their goal (primarily privacy, integrity, and availability of data). An adversary's efforts might take the form of attempting to discover secret data, corrupting some of the data in the system, spoofing the identity of a message sender or receiver, or forcing system downtime.

System and Method for Adaptive, Closed-Loop Prioritization of Cybersecurity Controls

PendingUS20250378178A1Metadata text retrievalPlatform integrity maintainanceMultiple-criteria decision analysisEngineering
A computer-implemented system and method for dynamic, explainable, and adaptive prioritization of cybersecurity controls is disclosed. The system ingests unstructured threat reports and employs a natural language processing (NLP) module to automatically extract adversary tactics, techniques, and procedures (TTPs). A scoring module applies a mathematical time-decay function to the extracted intelligence. A novel hybrid prioritization engine provides explainability-by-design by computationally integrating these objective, data-driven scores with organization-specific context within a transparent multi-criteria decision analysis (MCDA) model. Critically, the system establishes a self-optimizing closed feedback loop; it receives real-world control effectiveness metrics from the operational environment and uses this data as new ground-truth labels to continuously and automatically retrain internal machine learning models. This adaptive mechanism improves the computer's own predictive accuracy and resource allocation efficiency over time, representing a tangible technical improvement.
Owner:PETTINGILL JEFFREY

Model robustness enhancement method and communication apparatus

PCT designated stageWO2025256353A1Biological modelsMachine learningAdversaryAttack
Embodiments of the present application relate to the field of communications, provide a model robustness enhancement method and a communication apparatus, and can improve the robustness of an AI / ML model. The method comprises: a model training function can send detected abnormal data to an NDT system for data enhancement, acquire, from the NDT system, robustness enhancement data corresponding to the abnormal data, and input the robustness enhancement data corresponding to the abnormal data as adversarial data into a model for adversarial training, so that a target model automatically learns prior knowledge of an adversary attack and prior knowledge of a feature domain drift trajectory of the target model itself in a training process, thereby improving the robustness of the model, such as attack defense robustness and feature domain drift robustness of the model.
Owner:HUAWEI TECH CO LTD

L1 security signaling

A UE may detect, at the UE, a suspected fabricated transmission attack based on PHY security. The UE may transmit, to a network node, and the network node may receive, from the UE, an indication of the suspected fabricated transmission attack. The network node may receive, from the UE, an indication of one or more characteristics associated with a potential attacker associated with the suspected fabricated transmission attack. The UE may transmit, via a sidelink to at least one additional UE, a second indication of whether the UE identifies that the suspected fabricated transmission attack corresponds to the UE being attacked. The network node may identify a geographical location of the potential attacker based on a plurality of indications of the one or more characteristics associated with the potential attacker. The network node may compile an adversary pool including one or more compromised identities.
Owner:QUALCOMM INC

Method for performing connection management of station device within wireless communications system for protection from identity confusion caused by attacks from attacker device, and associated apparatus

PCT designated stageWO2026066960A1Security arrangementCommunications systemStation
A method for performing connection management of a station (STA) device within a wireless communications system for protection from identity confusion (e.g., SSID confusion and / or icon confusion caused by attacks from an attacker device) and associated apparatus are provided. The method may include: transmitting at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device may act as the attacker device; receiving at least one probe response from the AP device; transmitting at least one association request from the STA device to the AP device; receiving at least one association response from the AP device; performing a four-way (4-way) handshake between the STA device and the AP device; and in response to a number of non-valid beacons from the AP device reaching a predetermined threshold, disconnecting from the AP device.
Owner:MEDIATEK INC

A three-party collaborative SM2 digital signature generation method and system to resist malicious adversaries

This invention discloses a method and system for generating three-party collaborative SM2 digital signatures to resist malicious adversaries. The method includes three-party collaborative key generation and three-party collaborative signing. This invention can promptly detect whether a malicious adversary deviates from the predetermined steps of the protocol during execution, and can hold the perpetrator accountable after the malicious adversary's attack causes the protocol to terminate. This scheme uses a three-party collaborative signature based on secret sharing and employs multiplication triples for security verification. It fully considers the security, reliability, and performance of collaborative signature technology, achieving a security level resistant to malicious adversary attacks while ensuring secure, reliable, and rapid digital signature generation in a three-party environment, achieving a balance between key generation and signing efficiency. This invention has advantages such as high security, high flexibility, and high performance, and can be applied to any application scenario supporting secure multi-party computation.
Owner:WUHAN UNIV

Adversary-aware authentication method in federated learning based on adaptive steganographic watermarking

The application discloses an adversary-aware authentication method in federated learning based on adaptive steganographic watermarking, and the method is as follows: a device constructs its own identity information and encrypts and transmits the identity information to an authentication server; the authentication server processes the request of the external device and ensures that each device joining the system has a controlled validity period and clear identity information; the device re-applies to the authentication server according to the validity period, and the server regularly cleans up invalid internal devices; the authentication server registers the device ID of the legal device and groups the legal device, simultaneously selects a group leader device for each group and formulates a rotation rule; the authentication server generates corresponding watermark trigger data sets for each group and sends the watermark trigger data sets to all legal devices together with a global model and an authentication data set; the legal device trains the global model and learns a trigger strategy; and the authentication server performs security authentication on the legal device. The application improves the controllability, accuracy and concealment of the authentication process, and realizes safe, efficient and concealed authentication.
Owner:FUJIAN NORMAL UNIV

A malware identification method and system based on an innocent until proven guilty IUPG model

Techniques are disclosed for providing an innocent until proven guilty (IUPG) solution for building and using deep learning models that are resistant to adversaries and resistant to false positives. In some embodiments, a system, process, and / or computer program product includes storing a collection comprising one or more innocent until proven guilty (IUPG) models for static analysis of samples; performing static analysis of content associated with a sample, wherein performing the static analysis includes using at least one stored IUPG model; and determining, based at least in part on the static analysis of the content associated with the sample, that the sample is malicious, and in response to determining that the sample is malicious, performing an action based on a security policy.
Owner:PALO ALTO NETWORKS INC

Hardware-Anchored DAO Governance Engine with Quantum-Resistant Attestation

PendingUS20260205302A1BiotechnologyByzantine fault tolerance
Every major DAO governance failure traces to a common root cause: governance logic, voting, and treasury access reside in software that adversaries can reach. The disclosed invention provides a hardware-anchored DAO governance architecture defeating five adversary classes. A supply-chain attestation layer verifies firmware integrity against a public transparency log at node initialization. A Silicon Root-of-Trust Anchor Layer binds governance to processor-embedded cryptographic keys. A Heterogeneous TEE Orchestration Layer enforces Byzantine fault-tolerant canonical quorum through threshold BLS signatures across independent hardware architecture families. An Atomic Governance Transition Engine executes indivisible state changes: record incorporation, key destruction, counter advancement, and IOMMU treasury isolation. A Quantum-Resistant Governance Key Lifecycle Engine performs CRYSTALS-Kyber (ML-KEM, FIPS 203) key rotation with cryptographic agility. A Cross-Chain Governance Attestation Bridge publishes TEE-signed proofs to multiple blockchains. A Deterministic Governance Replay Engine reconstructs governance decisions in isolated sandboxes. An Automated Governance Incident Response Engine and Governance Regulator Verification Network provide hardware-enforced, independently auditable compliance enforcement.
Owner:BICKERSTAFF III GEORGE WILLIAM

Communication and payment device and method for preventing telecommunication fraud

The invention relates to a communication and payment device and method for preventing telecommunication fraud. If whether the caller and the electronic payment operator are abroad or not can be identified, a large amount of fraud can be stopped, and even in China, the safety can be greatly improved by identifying the position. The position is indicated only by a conventional smart phone, which is unreliable, and we must adopt a more reliable method. If the position is verified at a fixed position, the verification is relatively simple, and a device (a chip for verifying the position is hereinafter referred to as a transponder) with a fixed position can be used for sending verification information to the platform; to ensure security, the transponder may indicate the location to the platform using a dynamic authentication code. A key required for generating the authentication code can be generated by a transponder. If the position of a user is not fixed and is difficult to determine, a positioning chip can encrypt coordinates, and an enemy cannot generate a correct ciphertext, so that cheating cannot be implemented, and the chip is hereinafter referred to as a'secret bit chip '. The user activity track can well indicate the identity, hereinafter referred to as track verification.
Owner:NANJING ZHENSHENG BIYING TECHNOLOGY DEVELOPMENT CO LTD

Techniques for encryption based on perfect secrecy for bounded storage

Techniques for secure remote digital storage or transmission of a ciphertext message include determining a maximum storage capacity of an adversary, determining a security parameter k, wherein 1<<k<<m, and determining a prime number n, such that ≤0.3kn. A current public portion of random string α, comprising n random elements, is read from a public site. A secret key z, wherein z has 2k elements, comprising k additive co-primes of n and k multiplicative co-primes of n is shared with a receiving site. An encryption key X, based on the secret key and the current public string, is determined and applied to a plaintext message M of length ≤m to encrypt the plaintext message as Y=M⊕X, thereby creating the ciphertext message Y, which can be placed on a public forum for receiving by a receiving node.
Owner:RGT UNIV OF CALIFORNIA

Detection and survival method against adversarial attacks on automated systems

Methods provide device authentication for an intrusion detection system implementing building automation and control network (BACnet) Master-Slave / Token-Passing (MS / TP). An authentication protocol provides countermeasures to vulnerabilities in the BACnet MS / TP physical layer by utilizing an extended message format to cloak device identifiers (IDs). Adversaries are prevented from using known device IDs to gain access to the network. An authenticating device hashes a device identifier of a device to be authenticated combined with a random number. The authenticating device receives a hash of the random number plus the device identifier from the device. The authenticating device compares the hashes and authenticates the device if the hashes match. To transmit the hash, the BACnet MS / TP frame format includes an extended header cyclic redundancy check (CRC) field having bytes reallocated from the data field of the frame format. Another countermeasure utilizes a physical unclonable function (PUF) of the device in the extended header CRC.
Owner:MORGAN STATE UNIVERSITY

A layered federated security aggregation method based on cloud-edge collaboration

This invention relates to a hierarchical federated security aggregation method based on cloud-edge collaboration, belonging to the field of network security technology. This method effectively defends against model / data poisoning attacks through a two-layer anomaly detection mechanism, and combines a cloud-edge collaborative two-way authentication mechanism to achieve trusted user identity verification and service access control, simultaneously improving edge network security and privacy protection capabilities. This method can effectively mitigate the impact of poisoning attacks on hierarchical federated learning systems in a cloud-edge-device environment, while also reducing the risk of privacy leaks caused by external adversaries obtaining model parameters through eavesdropping.
Owner:BEIJING INST OF COMP TECH & APPL

Key negotiation method for emergency rescue systems based on 5G encrypted signals

ActiveCN115835200BSecurity arrangementComputer networkAdversary
This invention discloses a key negotiation method for an emergency medical system based on 5G encrypted signal transmission, comprising: establishing two entities, a user and a hospital, within the emergency medical system for mutual authentication and key negotiation between the two entities in the 5G network, and obtaining a session key between the entities; establishing a system management module for identity management, key management, and encrypted transmission management of the user and hospital during the session; generating an encrypted signal when the user uses the emergency medical system, simultaneously establishing a temporary identity for the user, and forming a public key and a private key through the temporary identity for transmitting the encrypted signal; establishing an adversary model to calculate the probability of an adversary successfully forging authentication messages and successfully obtaining the session key when the emergency medical system is maliciously attacked. This key negotiation method for an emergency medical system based on 5G encrypted signal transmission prevents unauthorized users from forging authentication messages and resists forgery attacks, ensuring the security of the session key.
Owner:GUANGZHOU LANSWICK SOFTWARE DEV CO LTD

L1 security signaling

A UE may detect, at the UE, a suspected fabricated transmission attack based on PHY security. The UE may transmit, to a network node, and the network node may receive, from the UE, an indication of the suspected fabricated transmission attack. The network node may receive, from the UE, an indication of one or more characteristics associated with a potential attacker associated with the suspected fabricated transmission attack. The UE may transmit, via a sidelink to at least one additional UE, a second indication of whether the UE identifies that the suspected fabricated transmission attack corresponds to the UE being attacked. The network node may identify a geographical location of the potential attacker based on a plurality of indications of the one or more characteristics associated with the potential attacker. The network node may compile an adversary pool including one or more compromised identities.
Owner:QUALCOMM INC

Deception-based responses to security attacks

ActiveUS12694108B2Domain nameAdversary
Deception-based techniques for responding to security attacks are described herein. The techniques include transitioning a security attack to a monitored computing device posing as a computing device impacted by the security attack and enabling the adversary to obtain deceptive information from the monitored computing device. Also, the adversary may obtain a document configured to report identifying information of an entity opening the document, thereby identifying the adversary associated with the attack. Further, the techniques include determining that a domain specified in a domain name request is associated with malicious activity and responding to the request with a network address of a monitored computing device to cause the requesting process to communicate with the monitored computing device in place of an adversary server. Additionally, a service may monitor dormant domains names associated with malicious activity and, in response to a change, respond with an alert or a configuration update.
Owner:CROWDSTRIKE

Randomization method and single secret leader election method

The invention discloses a randomization method and a single secret leader election method, and belongs to the technical field of computer technology and information security. In order to solve the technical problems of unfair leader election and insufficient privacy caused by the fact that a decayed enemy can use a randomization process to interfere a system state, an approximately unique randomization component is constructed by using random factor commitment and hierarchical broadcast, and the component is used for driving a random shuffling process to generate a unique system state. A leader node is selected from the secret list based on the persistent random pointer and the system state is updated by the selected leader. According to the scheme, the consistency of randomization results and the approximate uniqueness of random factors can be realized, corruption opponents with any malicious behaviors can be resisted, and the fairness and privacy of election of a single secret leader can be ensured.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Device-independent quantum secret sharing method based on multiphoton entanglement

The present application belongs to the technical field of quantum communication, and discloses a device-independent quantum secret sharing method based on multi-photon entanglement, which requires a key sender to prepare a large number of identical three-photon GHZ states, and to send two photons in each GHZ state to two key receivers respectively; after receiving the photons, the three parties randomly select measurement bases to measure the adversary's photons, and publish the measurement bases and part of the measurement results, so as to estimate the values of Svetlichny polynomials and CHSH polynomials; the security of the transmitted key is ensured by Svetlichny inequality violation and CHSH inequality violation. The present application can resist all attacks from imperfect device ends, reduce the requirement for the security of experimental equipment, effectively enhance the security of QSS under actual experimental conditions, and has important application in the field of future quantum secure direct communication.
Owner:NANJING UNIV OF POSTS & TELECOMM

Protection of data and ai models executed on hardware accelerators

Protection is lacking for various artificial intelligence (AI) assets (e.g., AI models and data) after they are distributed to an end user and loaded into their target AI computing hardware (e.g., NVIDIA GPUs). In some cases, protection for such assets is limited to binding their usage with legal terms, but malicious or adversary market participants cannot be prevented from ignoring such legal terms. Computing assets, such as AI models or data associated with AI models that used on a graphics processing unit (GPU), can be protected from unauthorized use or theft via technical safeguards.
Owner:SIEMENS AG +1

Counter adversary large language models

A system and method of using generative AI to maintain conversations with attacking devices to discover their adversary techniques and tactics. The method includes receiving an initial message originating from an attacking device and directed to a target device. The method includes generating, using one or more classification models, a maliciousness score for the initial message indicating that the initial message is associated with one or more types of malicious activity. The method includes providing, by a processing device, the initial message to a predictive model trained to maintain conversations with attacking devices by predicting responses to malicious messages. The method includes generating, using the predictive model, two or more responses based on the initial message and at least one subsequent message, wherein each response of the two or more responses causes the attacking device to send a respective subsequent message to the predictive model.
Owner:CROWDSTRIKE

Method and system for analysing and mitigating security risks in open innovation ecosystem

PendingUS20260039683A1Securing communicationResearch dataInnovator
A method and system for analysing and mitigating security risks in open innovation ecosystem is disclosed. The system comprises detects potential vulnerabilities in open innovation activities, including intellectual property exchanges, research data handling, and partner collaboration processes to provide identified threat data as input. The system represents interactions between an innovator and an adversary as a two-player zero-sum game. The system computes Nash equilibrium from the payoff matrix. The Nash equilibrium represents optimal defensive investments under adversarial conditions. The system also models adversary uncertainty using probability distributions, and further updates the equilibrium strategies based on incomplete or dynamic information. The system, thereafter, evaluates adversary uncertainty using Entropy-based risk assessment to determine levels of security investment resources responsive to the quantified uncertainty. Finally, the system integrates results of the equilibrium analysis, probabilistic inference, and uncertainty quantification to generate actionable security recommendations and guidelines for mitigation strategies.
Owner:SAFDAR UMAR +3

A federated learning method based on high-availability non-interactive secure aggregation

The application discloses a kind of federal learning methods based on high availability non-interactive security aggregation scheme, its characteristics are based on the security aggregation method of pairing mask, through asynchronous public subset consensus algorithm, it is realized on distributed server cluster non-interactive high availability security aggregation federal learning, specifically includes: (A) initialization stage (B) aggregation stage epoch 0, first round, user;(C) aggregation stage epoch 0, first round, server;(D) aggregation stage epoch 0, second round, user;(E) aggregation stage epoch 0, second round, server;(F) aggregation stage epoch k (k>0), user and (G) aggregation stage epoch k (k>0), server etc.Steps.The application has high availability security aggregation, small amount of calculation, resists malicious adversary and other advantages compared with prior art, realizes the privacy protection of gradient information, and guarantees the correctness of federal learning training result, is established in the asynchronous network model closest to real network model, with higher practical application value.
Owner:EAST CHINA NORMAL UNIV +1

Cryptographic data message expansion for increasing adversarial storage requirements

The disclosure relates to generating a ciphertext of arbitrary and flexibly large size and ensures that an adversary learns little about the encrypted data, even if the decryption key later leaks, unless substantially the entire ciphertext is stored. Given that communication will be inconveniently large for the adversary to store, the incompressible ciphertexts and signatures can be sent and received with low storage requirements for the honest users. In such a setting, the honest users would not store the entire ciphertext or signature, but instead generate, send, and process the communication bit-by-bit in a streaming fashion.
Owner:NTT RESEARCH INC

Validation traps to detect adversary attempts to secure access

Embodiments relate to reinstating access to a system of an admin whose certificate is invalid or expired and to detecting an attack on the system. A requestor, who may be an admin whose certificate is expired or invalid, may send a request for reinstatement to validators. The system may provide honeypot validators in addition to legitimate validators. When the request is received by a honeypot validator or if the honeypot validator is requested to provide their share of a secret, the requestor is determined to be malicious and a protective operation or action is performed.
Owner:DELL PROD LP

Resilience against unknown denial-of-service attacks via multipath communications

Presented herein is an effective protection method against unknown and unanticipated denial-of-service attacks and guarantee mission critical message delivery. Multipath communication may be leveraged as a preventive device-centric mechanism to ensure message deliveries in the event of unknown denial-of-service attacks. The mechanism may complement other device-centric mitigation techniques as the mechanism does not wait for the detection of adversaries in the network and is attack-agnostic. In particular, the technique may be effective against a wide range of denial-of-service attacks at any protocol layer.
Owner:THE WICHITA STATE UNIV +1

Network security assessment based upon identification of an adversary

A computer-implemented method comprises establishing a database based at least in part on network traffic data received from a network, detecting adversarial behavior within the network traffic data, identifying an adversary associated with the adversarial behavior, determining a plurality of specific indicators of compromise that are associated with the adversary that has been identified, constructing a query based on the plurality of specific indicators of compromise, submitting the query to search for the plurality of specific indicators of compromise within the network traffic data, searching for the plurality of specific indicators of compromise within the network traffic data, and generating, responsive to having located at least one potential indicator of compromise, a search report containing at least one specific indicator of compromise and displaying the search report to a user interface.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A dynamic network architecture maintenance system and method under adversarial conditions

A dynamic network architecture maintenance system and method under adversarial conditions includes an attack prediction module, a decision update module, and a pre-deployment decision module. The attack prediction module predicts the sequence of important nodes that the adversary will attack in the next moment. The decision update module updates the adversary's attack strategy and feeds the results back to the attack prediction module. The pre-deployment decision module makes deployment decisions based on the prediction results of the network architecture maintainer. This invention uses a decision architecture that predicts the nodes of the SoS (Socially Targeted Systems) to be attacked based on the changes in the system's topology between time i-1 and time i, and makes advance judgments. According to the attack strategy, it outputs the importance sequence of communication nodes participating in the SoS in the next moment. The communication nodes in this sequence are highly likely to become the targets of the attack in the next moment. Based on this sequence, the SoS can make pre-deployment decisions, enabling the communication nodes in this sequence to maneuver in advance or deploy redundant silent communication nodes nearby.
Owner:XIDIAN UNIV +1

Systems and Methods for Providing Continuous Cybersecurity Readiness Using Artificial Intelligence Agents

Systems and methods for providing continuous cybersecurity readiness are disclosed. An exemplary method begins with ingesting user data and an entity playbook. An adversary AI agent generates a cybersecurity threat scenario that is customized for the user. A digital collaboration room is established for an entity, where the entity has control to grant and modify permissions to a user and artificial intelligence (AI) agents regarding the digital collaboration room. User responses to one or more questions posed in the threat scenario are received, evaluated and analyzed by a user agent AI in real-time. The readiness of the user to respond to a cybersecurity threat and the effectiveness of the playbook are evaluated. Feedback is generated about the playbook. Finally, the playbook of the entity is updated, which includes incorporation of the generated feedback.
Owner:CYGNVS INC

Two-factor authentication method and system

The application relates to the technical field of computer security, and discloses a two-factor authentication method and system, which is based on a two-factor authentication technology of biological information and homomorphic encryption. In the method, a public key encryption scheme of homomorphic encryption and a hash function with a robust reserved predicate relation are used to realize an authentication process, and the method has the ability to resist replay attacks and tolerate an adversary obtaining a database. Specifically, the method uses a random number generated by a server to resist replay attacks, and uses two-factor authentication of a biological authentication factor and a private key authentication factor to tolerate an adversary obtaining the database of the server. Meanwhile, the method uses the hash function with the robust reserved predicate relation to protect biological feature information of a user, and uses the public key encryption scheme of homomorphic encryption to protect private key information of the user. The application significantly improves the security and efficiency of authentication, and can better meet the needs of users.
Owner:SHANGHAI JIAOTONG UNIV

System and method for graphical reticulated attack vectors for internet of things aggregate security (gravitas)

According to various embodiments, a system for detecting security vulnerabilities in at least one of cyber-physical systems (CPSs) and Internet of Things (IoT) devices is disclosed. The system includes one or more processors configured to construct an attack directed acyclic graph (DAG) unique to each CPS or IoT device of the devices. The processors are further configured to generate an aggregate attack DAG from a classification of each device and a location of each device in network topology specified by a system administrator. The processors are also configured to calculate a vulnerability score and exploit risk score for each node in the aggregate attack DAG. The processors are further configured to optimize placement of defenses to reduce an adversary score of the aggregate attack DAG.
Owner:THE TRUSTEES OF PRINCETON UNIV

Privacy protection identity registration and authentication method and system compatible with standard sim card

This invention discloses a privacy-preserving identity registration and authentication method and system compatible with standard SIM cards, belonging to the field of cryptographic protocol technology. The system includes three participants: a user terminal, an operator, and an application. It is based on the SIM card issued by the mobile operator and owned by all mobile phone users. The user and the operator collaborate to complete the application's authentication of the user's identity. This invention features high security and efficiency; even if an adversary compromises the operator, they cannot obtain the user's login behavior. It also protects user authentication from man-in-the-middle attacks, is compatible with existing SIM cards, requires no replacement of existing hardware, and is easy to deploy. This invention further enhances privacy protection, ensuring that user access behavior is not tracked, has excellent interoperability, and is suitable for large-scale 5G application deployment.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI