Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Adversary" patented technology

In cryptography, an adversary (rarely opponent, enemy) is a malicious entity whose aim is to prevent the users of the cryptosystem from achieving their goal (primarily privacy, integrity, and availability of data). An adversary's efforts might take the form of attempting to discover secret data, corrupting some of the data in the system, spoofing the identity of a message sender or receiver, or forcing system downtime.

L1 security signaling

A UE may detect, at the UE, a suspected fabricated transmission attack based on PHY security. The UE may transmit, to a network node, and the network node may receive, from the UE, an indication of the suspected fabricated transmission attack. The network node may receive, from the UE, an indication of one or more characteristics associated with a potential attacker associated with the suspected fabricated transmission attack. The UE may transmit, via a sidelink to at least one additional UE, a second indication of whether the UE identifies that the suspected fabricated transmission attack corresponds to the UE being attacked. The network node may identify a geographical location of the potential attacker based on a plurality of indications of the one or more characteristics associated with the potential attacker. The network node may compile an adversary pool including one or more compromised identities.
Owner:QUALCOMM INC

Method for performing connection management of station device within wireless communications system for protection from identity confusion caused by attacks from attacker device, and associated apparatus

PCT designated stageWO2026066960A1Security arrangementCommunications systemStation
A method for performing connection management of a station (STA) device within a wireless communications system for protection from identity confusion (e.g., SSID confusion and / or icon confusion caused by attacks from an attacker device) and associated apparatus are provided. The method may include: transmitting at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device may act as the attacker device; receiving at least one probe response from the AP device; transmitting at least one association request from the STA device to the AP device; receiving at least one association response from the AP device; performing a four-way (4-way) handshake between the STA device and the AP device; and in response to a number of non-valid beacons from the AP device reaching a predetermined threshold, disconnecting from the AP device.
Owner:MEDIATEK INC

A malware identification method and system based on an innocent until proven guilty IUPG model

Techniques are disclosed for providing an innocent until proven guilty (IUPG) solution for building and using deep learning models that are resistant to adversaries and resistant to false positives. In some embodiments, a system, process, and / or computer program product includes storing a collection comprising one or more innocent until proven guilty (IUPG) models for static analysis of samples; performing static analysis of content associated with a sample, wherein performing the static analysis includes using at least one stored IUPG model; and determining, based at least in part on the static analysis of the content associated with the sample, that the sample is malicious, and in response to determining that the sample is malicious, performing an action based on a security policy.
Owner:PALO ALTO NETWORKS INC

Hardware-Anchored DAO Governance Engine with Quantum-Resistant Attestation

PendingUS20260205302A1BiotechnologyByzantine fault tolerance
Every major DAO governance failure traces to a common root cause: governance logic, voting, and treasury access reside in software that adversaries can reach. The disclosed invention provides a hardware-anchored DAO governance architecture defeating five adversary classes. A supply-chain attestation layer verifies firmware integrity against a public transparency log at node initialization. A Silicon Root-of-Trust Anchor Layer binds governance to processor-embedded cryptographic keys. A Heterogeneous TEE Orchestration Layer enforces Byzantine fault-tolerant canonical quorum through threshold BLS signatures across independent hardware architecture families. An Atomic Governance Transition Engine executes indivisible state changes: record incorporation, key destruction, counter advancement, and IOMMU treasury isolation. A Quantum-Resistant Governance Key Lifecycle Engine performs CRYSTALS-Kyber (ML-KEM, FIPS 203) key rotation with cryptographic agility. A Cross-Chain Governance Attestation Bridge publishes TEE-signed proofs to multiple blockchains. A Deterministic Governance Replay Engine reconstructs governance decisions in isolated sandboxes. An Automated Governance Incident Response Engine and Governance Regulator Verification Network provide hardware-enforced, independently auditable compliance enforcement.
Owner:BICKERSTAFF III GEORGE WILLIAM

Communication and payment device and method for preventing telecommunication fraud

The invention relates to a communication and payment device and method for preventing telecommunication fraud. If whether the caller and the electronic payment operator are abroad or not can be identified, a large amount of fraud can be stopped, and even in China, the safety can be greatly improved by identifying the position. The position is indicated only by a conventional smart phone, which is unreliable, and we must adopt a more reliable method. If the position is verified at a fixed position, the verification is relatively simple, and a device (a chip for verifying the position is hereinafter referred to as a transponder) with a fixed position can be used for sending verification information to the platform; to ensure security, the transponder may indicate the location to the platform using a dynamic authentication code. A key required for generating the authentication code can be generated by a transponder. If the position of a user is not fixed and is difficult to determine, a positioning chip can encrypt coordinates, and an enemy cannot generate a correct ciphertext, so that cheating cannot be implemented, and the chip is hereinafter referred to as a'secret bit chip '. The user activity track can well indicate the identity, hereinafter referred to as track verification.
Owner:NANJING ZHENSHENG BIYING TECHNOLOGY DEVELOPMENT CO LTD

Detection and survival method against adversarial attacks on automated systems

Methods provide device authentication for an intrusion detection system implementing building automation and control network (BACnet) Master-Slave / Token-Passing (MS / TP). An authentication protocol provides countermeasures to vulnerabilities in the BACnet MS / TP physical layer by utilizing an extended message format to cloak device identifiers (IDs). Adversaries are prevented from using known device IDs to gain access to the network. An authenticating device hashes a device identifier of a device to be authenticated combined with a random number. The authenticating device receives a hash of the random number plus the device identifier from the device. The authenticating device compares the hashes and authenticates the device if the hashes match. To transmit the hash, the BACnet MS / TP frame format includes an extended header cyclic redundancy check (CRC) field having bytes reallocated from the data field of the frame format. Another countermeasure utilizes a physical unclonable function (PUF) of the device in the extended header CRC.
Owner:MORGAN STATE UNIVERSITY

A layered federated security aggregation method based on cloud-edge collaboration

This invention relates to a hierarchical federated security aggregation method based on cloud-edge collaboration, belonging to the field of network security technology. This method effectively defends against model / data poisoning attacks through a two-layer anomaly detection mechanism, and combines a cloud-edge collaborative two-way authentication mechanism to achieve trusted user identity verification and service access control, simultaneously improving edge network security and privacy protection capabilities. This method can effectively mitigate the impact of poisoning attacks on hierarchical federated learning systems in a cloud-edge-device environment, while also reducing the risk of privacy leaks caused by external adversaries obtaining model parameters through eavesdropping.
Owner:BEIJING INST OF COMP TECH & APPL

Key negotiation method for emergency rescue systems based on 5G encrypted signals

ActiveCN115835200BSecurity arrangementComputer networkAdversary
This invention discloses a key negotiation method for an emergency medical system based on 5G encrypted signal transmission, comprising: establishing two entities, a user and a hospital, within the emergency medical system for mutual authentication and key negotiation between the two entities in the 5G network, and obtaining a session key between the entities; establishing a system management module for identity management, key management, and encrypted transmission management of the user and hospital during the session; generating an encrypted signal when the user uses the emergency medical system, simultaneously establishing a temporary identity for the user, and forming a public key and a private key through the temporary identity for transmitting the encrypted signal; establishing an adversary model to calculate the probability of an adversary successfully forging authentication messages and successfully obtaining the session key when the emergency medical system is maliciously attacked. This key negotiation method for an emergency medical system based on 5G encrypted signal transmission prevents unauthorized users from forging authentication messages and resists forgery attacks, ensuring the security of the session key.
Owner:GUANGZHOU LANSWICK SOFTWARE DEV CO LTD

L1 security signaling

A UE may detect, at the UE, a suspected fabricated transmission attack based on PHY security. The UE may transmit, to a network node, and the network node may receive, from the UE, an indication of the suspected fabricated transmission attack. The network node may receive, from the UE, an indication of one or more characteristics associated with a potential attacker associated with the suspected fabricated transmission attack. The UE may transmit, via a sidelink to at least one additional UE, a second indication of whether the UE identifies that the suspected fabricated transmission attack corresponds to the UE being attacked. The network node may identify a geographical location of the potential attacker based on a plurality of indications of the one or more characteristics associated with the potential attacker. The network node may compile an adversary pool including one or more compromised identities.
Owner:QUALCOMM INC

Deception-based responses to security attacks

ActiveUS12694108B2Domain nameAdversary
Deception-based techniques for responding to security attacks are described herein. The techniques include transitioning a security attack to a monitored computing device posing as a computing device impacted by the security attack and enabling the adversary to obtain deceptive information from the monitored computing device. Also, the adversary may obtain a document configured to report identifying information of an entity opening the document, thereby identifying the adversary associated with the attack. Further, the techniques include determining that a domain specified in a domain name request is associated with malicious activity and responding to the request with a network address of a monitored computing device to cause the requesting process to communicate with the monitored computing device in place of an adversary server. Additionally, a service may monitor dormant domains names associated with malicious activity and, in response to a change, respond with an alert or a configuration update.
Owner:CROWDSTRIKE

Randomization method and single secret leader election method

The invention discloses a randomization method and a single secret leader election method, and belongs to the technical field of computer technology and information security. In order to solve the technical problems of unfair leader election and insufficient privacy caused by the fact that a decayed enemy can use a randomization process to interfere a system state, an approximately unique randomization component is constructed by using random factor commitment and hierarchical broadcast, and the component is used for driving a random shuffling process to generate a unique system state. A leader node is selected from the secret list based on the persistent random pointer and the system state is updated by the selected leader. According to the scheme, the consistency of randomization results and the approximate uniqueness of random factors can be realized, corruption opponents with any malicious behaviors can be resisted, and the fairness and privacy of election of a single secret leader can be ensured.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Device-independent quantum secret sharing method based on multiphoton entanglement

The present application belongs to the technical field of quantum communication, and discloses a device-independent quantum secret sharing method based on multi-photon entanglement, which requires a key sender to prepare a large number of identical three-photon GHZ states, and to send two photons in each GHZ state to two key receivers respectively; after receiving the photons, the three parties randomly select measurement bases to measure the adversary's photons, and publish the measurement bases and part of the measurement results, so as to estimate the values of Svetlichny polynomials and CHSH polynomials; the security of the transmitted key is ensured by Svetlichny inequality violation and CHSH inequality violation. The present application can resist all attacks from imperfect device ends, reduce the requirement for the security of experimental equipment, effectively enhance the security of QSS under actual experimental conditions, and has important application in the field of future quantum secure direct communication.
Owner:NANJING UNIV OF POSTS & TELECOMM

Protection of data and ai models executed on hardware accelerators

Protection is lacking for various artificial intelligence (AI) assets (e.g., AI models and data) after they are distributed to an end user and loaded into their target AI computing hardware (e.g., NVIDIA GPUs). In some cases, protection for such assets is limited to binding their usage with legal terms, but malicious or adversary market participants cannot be prevented from ignoring such legal terms. Computing assets, such as AI models or data associated with AI models that used on a graphics processing unit (GPU), can be protected from unauthorized use or theft via technical safeguards.
Owner:SIEMENS AG +1

Counter adversary large language models

A system and method of using generative AI to maintain conversations with attacking devices to discover their adversary techniques and tactics. The method includes receiving an initial message originating from an attacking device and directed to a target device. The method includes generating, using one or more classification models, a maliciousness score for the initial message indicating that the initial message is associated with one or more types of malicious activity. The method includes providing, by a processing device, the initial message to a predictive model trained to maintain conversations with attacking devices by predicting responses to malicious messages. The method includes generating, using the predictive model, two or more responses based on the initial message and at least one subsequent message, wherein each response of the two or more responses causes the attacking device to send a respective subsequent message to the predictive model.
Owner:CROWDSTRIKE

Method and system for analysing and mitigating security risks in open innovation ecosystem

PendingUS20260039683A1Securing communicationResearch dataInnovator
A method and system for analysing and mitigating security risks in open innovation ecosystem is disclosed. The system comprises detects potential vulnerabilities in open innovation activities, including intellectual property exchanges, research data handling, and partner collaboration processes to provide identified threat data as input. The system represents interactions between an innovator and an adversary as a two-player zero-sum game. The system computes Nash equilibrium from the payoff matrix. The Nash equilibrium represents optimal defensive investments under adversarial conditions. The system also models adversary uncertainty using probability distributions, and further updates the equilibrium strategies based on incomplete or dynamic information. The system, thereafter, evaluates adversary uncertainty using Entropy-based risk assessment to determine levels of security investment resources responsive to the quantified uncertainty. Finally, the system integrates results of the equilibrium analysis, probabilistic inference, and uncertainty quantification to generate actionable security recommendations and guidelines for mitigation strategies.
Owner:SAFDAR UMAR +3

Resilience against unknown denial-of-service attacks via multipath communications

Presented herein is an effective protection method against unknown and unanticipated denial-of-service attacks and guarantee mission critical message delivery. Multipath communication may be leveraged as a preventive device-centric mechanism to ensure message deliveries in the event of unknown denial-of-service attacks. The mechanism may complement other device-centric mitigation techniques as the mechanism does not wait for the detection of adversaries in the network and is attack-agnostic. In particular, the technique may be effective against a wide range of denial-of-service attacks at any protocol layer.
Owner:THE WICHITA STATE UNIV +1

Network security assessment based upon identification of an adversary

A computer-implemented method comprises establishing a database based at least in part on network traffic data received from a network, detecting adversarial behavior within the network traffic data, identifying an adversary associated with the adversarial behavior, determining a plurality of specific indicators of compromise that are associated with the adversary that has been identified, constructing a query based on the plurality of specific indicators of compromise, submitting the query to search for the plurality of specific indicators of compromise within the network traffic data, searching for the plurality of specific indicators of compromise within the network traffic data, and generating, responsive to having located at least one potential indicator of compromise, a search report containing at least one specific indicator of compromise and displaying the search report to a user interface.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A dynamic network architecture maintenance system and method under adversarial conditions

A dynamic network architecture maintenance system and method under adversarial conditions includes an attack prediction module, a decision update module, and a pre-deployment decision module. The attack prediction module predicts the sequence of important nodes that the adversary will attack in the next moment. The decision update module updates the adversary's attack strategy and feeds the results back to the attack prediction module. The pre-deployment decision module makes deployment decisions based on the prediction results of the network architecture maintainer. This invention uses a decision architecture that predicts the nodes of the SoS (Socially Targeted Systems) to be attacked based on the changes in the system's topology between time i-1 and time i, and makes advance judgments. According to the attack strategy, it outputs the importance sequence of communication nodes participating in the SoS in the next moment. The communication nodes in this sequence are highly likely to become the targets of the attack in the next moment. Based on this sequence, the SoS can make pre-deployment decisions, enabling the communication nodes in this sequence to maneuver in advance or deploy redundant silent communication nodes nearby.
Owner:XIDIAN UNIV +1

Two-factor authentication method and system

The application relates to the technical field of computer security, and discloses a two-factor authentication method and system, which is based on a two-factor authentication technology of biological information and homomorphic encryption. In the method, a public key encryption scheme of homomorphic encryption and a hash function with a robust reserved predicate relation are used to realize an authentication process, and the method has the ability to resist replay attacks and tolerate an adversary obtaining a database. Specifically, the method uses a random number generated by a server to resist replay attacks, and uses two-factor authentication of a biological authentication factor and a private key authentication factor to tolerate an adversary obtaining the database of the server. Meanwhile, the method uses the hash function with the robust reserved predicate relation to protect biological feature information of a user, and uses the public key encryption scheme of homomorphic encryption to protect private key information of the user. The application significantly improves the security and efficiency of authentication, and can better meet the needs of users.
Owner:SHANGHAI JIAOTONG UNIV

Privacy protection identity registration and authentication method and system compatible with standard sim card

This invention discloses a privacy-preserving identity registration and authentication method and system compatible with standard SIM cards, belonging to the field of cryptographic protocol technology. The system includes three participants: a user terminal, an operator, and an application. It is based on the SIM card issued by the mobile operator and owned by all mobile phone users. The user and the operator collaborate to complete the application's authentication of the user's identity. This invention features high security and efficiency; even if an adversary compromises the operator, they cannot obtain the user's login behavior. It also protects user authentication from man-in-the-middle attacks, is compatible with existing SIM cards, requires no replacement of existing hardware, and is easy to deploy. This invention further enhances privacy protection, ensuring that user access behavior is not tracked, has excellent interoperability, and is suitable for large-scale 5G application deployment.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

A secure and efficient momentum federated learning method for privacy protection data mining

This invention discloses a secure and efficient momentum federated learning method for privacy-preserving data mining. The method comprises two phases: an initialization phase and a secure training phase. It requires minimal communication and computational resources when aggregating user-local momentum terms. In each training round, each data owner only needs to encrypt one variable. This approach not only helps users prevent momentum terms from leaking local data but also defends against model inversion attacks launched by any adversary. Evaluation results on independent and identically distributed (i.i.d.) and non-independent and identically distributed (i.i.d.) datasets validate that this approach can securely and efficiently achieve privacy-preserving data mining.
Owner:HENAN NORMAL UNIV

Detection and survival method against adversarial attacks on automated systems

PendingUS20260197178A1Web authenticationAttack
Methods provide device authentication for an intrusion detection system implementing building automation and control network (BACnet) Master-Slave / Token-Passing (MS / TP). An authentication protocol provides countermeasures to vulnerabilities in the BACnet MS / TP physical layer by utilizing an extended message format to cloak device identifiers (IDs). Adversaries are prevented from using known device IDs to gain access to the network. An authenticating device hashes a device identifier of a device to be authenticated combined with a random number. The authenticating device receives a hash of the random number plus the device identifier from the device. The authenticating device compares the hashes and authenticates the device if the hashes match. To transmit the hash, the BACnet MS / TP frame format includes an extended header cyclic redundancy check (CRC) field having bytes reallocated from the data field of the frame format. Another countermeasure utilizes a physical unclonable function (PUF) of the device in the extended header CRC.
Owner:MORGAN STATE UNIVERSITY

Quantification of adversary tactics, techniques, and procedures using threat attribute groupings and correlation

ActiveUS12647432B2Securing communicationAdversaryAttack
The present disclosure provides a method and a system for generating a decision tree that tests security event files. The method comprises receiving attack data comprising a plurality of attack execution operations and determining threat attribute data based on the attack data. The method also comprises generating a decision tree using the threat attribute data. The decision tree includes at least one first node and a plurality of second nodes connected to the at least one first node. A first nodal data may be generated and assigned to each second node based on one or more threat attributes associated with the threat attribute data. In response to receiving a security event file, the method executes one or more security tests, using the decision tree, for the security event file.
Owner:QUALYS