Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

51 results about "Adversary" patented technology

In cryptography, an adversary (rarely opponent, enemy) is a malicious entity whose aim is to prevent the users of the cryptosystem from achieving their goal (primarily privacy, integrity, and availability of data). An adversary's efforts might take the form of attempting to discover secret data, corrupting some of the data in the system, spoofing the identity of a message sender or receiver, or forcing system downtime.

System and Method for Adaptive, Closed-Loop Prioritization of Cybersecurity Controls

PendingUS20250378178A1Metadata text retrievalPlatform integrity maintainanceMultiple-criteria decision analysisEngineering
A computer-implemented system and method for dynamic, explainable, and adaptive prioritization of cybersecurity controls is disclosed. The system ingests unstructured threat reports and employs a natural language processing (NLP) module to automatically extract adversary tactics, techniques, and procedures (TTPs). A scoring module applies a mathematical time-decay function to the extracted intelligence. A novel hybrid prioritization engine provides explainability-by-design by computationally integrating these objective, data-driven scores with organization-specific context within a transparent multi-criteria decision analysis (MCDA) model. Critically, the system establishes a self-optimizing closed feedback loop; it receives real-world control effectiveness metrics from the operational environment and uses this data as new ground-truth labels to continuously and automatically retrain internal machine learning models. This adaptive mechanism improves the computer's own predictive accuracy and resource allocation efficiency over time, representing a tangible technical improvement.
Owner:PETTINGILL JEFFREY

Threat-informed adversary attack simulation

A dynamic adversary profile is generated for a simulated attack on components of the enterprise network by selecting a profile of at least one specific threat group. The simulated attack is based on historical attack data, threat intelligence feeds, and real-time monitoring of adversary profiles. One or more relevant adversary group profiles is selected. An attack pattern (e.g., an APT attack pattern) is simulated on the components by injecting data packets based on the specific threat group without malicious components of the specific threat group to test security defenses of the components. Logs are collected from the simulated attack pattern. Based on results of the simulated attack pattern, defenses to the simulated attack on components are measured. Optionally, a security action concerning at least one of the components to better protect against an actual attack.
Owner:FORTINET INC

Quantum secure anonymous communication networks

An embodiment provides a quantum-resistant technique for distributing symmetric or other keys (e.g., in quantum key distribution (QKD), etc.). The embodiment pertains to a protocol and network architecture that integrates QKD without the need for trusted nodes, thereby meeting the requirements of the Tor or other anonymous communication network and creating a quantum-secure anonymous communication network. The embodiment re-designs the key establishment and exchange mechanisms of Tor to incorporate QKD, and provides a theoretical guarantee of security against quantum-powered adversaries (QPAs) while meeting all network or system requirements.
Owner:CISCO TECHNOLOGY INC

Model robustness enhancement method and communication apparatus

PCT designated stageWO2025256353A1Biological modelsMachine learningAdversaryAttack
Embodiments of the present application relate to the field of communications, provide a model robustness enhancement method and a communication apparatus, and can improve the robustness of an AI / ML model. The method comprises: a model training function can send detected abnormal data to an NDT system for data enhancement, acquire, from the NDT system, robustness enhancement data corresponding to the abnormal data, and input the robustness enhancement data corresponding to the abnormal data as adversarial data into a model for adversarial training, so that a target model automatically learns prior knowledge of an adversary attack and prior knowledge of a feature domain drift trajectory of the target model itself in a training process, thereby improving the robustness of the model, such as attack defense robustness and feature domain drift robustness of the model.
Owner:HUAWEI TECH CO LTD

L1 security signaling

A UE may detect, at the UE, a suspected fabricated transmission attack based on PHY security. The UE may transmit, to a network node, and the network node may receive, from the UE, an indication of the suspected fabricated transmission attack. The network node may receive, from the UE, an indication of one or more characteristics associated with a potential attacker associated with the suspected fabricated transmission attack. The UE may transmit, via a sidelink to at least one additional UE, a second indication of whether the UE identifies that the suspected fabricated transmission attack corresponds to the UE being attacked. The network node may identify a geographical location of the potential attacker based on a plurality of indications of the one or more characteristics associated with the potential attacker. The network node may compile an adversary pool including one or more compromised identities.
Owner:QUALCOMM INC

Method for performing connection management of station device within wireless communications system for protection from identity confusion caused by attacks from attacker device, and associated apparatus

PCT designated stageWO2026066960A1Security arrangementCommunications systemStation
A method for performing connection management of a station (STA) device within a wireless communications system for protection from identity confusion (e.g., SSID confusion and / or icon confusion caused by attacks from an attacker device) and associated apparatus are provided. The method may include: transmitting at least one probe request from the STA device to an access point (AP) device of an adversary, the adversary to a user of the STA device, wherein the AP device may act as the attacker device; receiving at least one probe response from the AP device; transmitting at least one association request from the STA device to the AP device; receiving at least one association response from the AP device; performing a four-way (4-way) handshake between the STA device and the AP device; and in response to a number of non-valid beacons from the AP device reaching a predetermined threshold, disconnecting from the AP device.
Owner:MEDIATEK INC

A three-party collaborative SM2 digital signature generation method and system to resist malicious adversaries

This invention discloses a method and system for generating three-party collaborative SM2 digital signatures to resist malicious adversaries. The method includes three-party collaborative key generation and three-party collaborative signing. This invention can promptly detect whether a malicious adversary deviates from the predetermined steps of the protocol during execution, and can hold the perpetrator accountable after the malicious adversary's attack causes the protocol to terminate. This scheme uses a three-party collaborative signature based on secret sharing and employs multiplication triples for security verification. It fully considers the security, reliability, and performance of collaborative signature technology, achieving a security level resistant to malicious adversary attacks while ensuring secure, reliable, and rapid digital signature generation in a three-party environment, achieving a balance between key generation and signing efficiency. This invention has advantages such as high security, high flexibility, and high performance, and can be applied to any application scenario supporting secure multi-party computation.
Owner:WUHAN UNIV

Adversary-aware authentication method in federated learning based on adaptive steganographic watermarking

The application discloses an adversary-aware authentication method in federated learning based on adaptive steganographic watermarking, and the method is as follows: a device constructs its own identity information and encrypts and transmits the identity information to an authentication server; the authentication server processes the request of the external device and ensures that each device joining the system has a controlled validity period and clear identity information; the device re-applies to the authentication server according to the validity period, and the server regularly cleans up invalid internal devices; the authentication server registers the device ID of the legal device and groups the legal device, simultaneously selects a group leader device for each group and formulates a rotation rule; the authentication server generates corresponding watermark trigger data sets for each group and sends the watermark trigger data sets to all legal devices together with a global model and an authentication data set; the legal device trains the global model and learns a trigger strategy; and the authentication server performs security authentication on the legal device. The application improves the controllability, accuracy and concealment of the authentication process, and realizes safe, efficient and concealed authentication.
Owner:FUJIAN NORMAL UNIV

A malware identification method and system based on an innocent until proven guilty IUPG model

Techniques are disclosed for providing an innocent until proven guilty (IUPG) solution for building and using deep learning models that are resistant to adversaries and resistant to false positives. In some embodiments, a system, process, and / or computer program product includes storing a collection comprising one or more innocent until proven guilty (IUPG) models for static analysis of samples; performing static analysis of content associated with a sample, wherein performing the static analysis includes using at least one stored IUPG model; and determining, based at least in part on the static analysis of the content associated with the sample, that the sample is malicious, and in response to determining that the sample is malicious, performing an action based on a security policy.
Owner:PALO ALTO NETWORKS INC

V2C post-quantum authentication and key agreement method based on RLWE

The present invention discloses a V2C post-quantum authentication and key negotiation method based on RLWE. During system initialization, a master key, public key, hash function, and related parameters are selected. During the registration phase, the vehicle and cloud server CS register with a registration authority RA. During the login phase, the vehicle and CS log in to the local system. During the authentication and key negotiation phase, the vehicle and CS perform identity authentication and key negotiation through the RA, negotiating a session key for subsequent secure communication without revealing their true identity. During the identity and password update phase, users can directly update their identity and password without going through the RA. The present invention is based on ring fault-tolerant learning RLWE and a hash method design, effectively reducing the computational and communication overhead of the AKA process, resisting attacks by quantum adversaries, and ensuring the confidentiality of the true identity of legitimate vehicles. Furthermore, the "fuzzy verifier + honeyword" technology is used in the AKA process to resist signal leakage and key guessing attacks, ensuring key security.
Owner:ANHUI UNIV

Hardware-Anchored DAO Governance Engine with Quantum-Resistant Attestation

Every major DAO governance failure traces to a common root cause: governance logic, voting, and treasury access reside in software that adversaries can reach. The disclosed invention provides a hardware-anchored DAO governance architecture defeating five adversary classes. A supply-chain attestation layer verifies firmware integrity against a public transparency log at node initialization. A Silicon Root-of-Trust Anchor Layer binds governance to processor-embedded cryptographic keys. A Heterogeneous TEE Orchestration Layer enforces Byzantine fault-tolerant canonical quorum through threshold BLS signatures across independent hardware architecture families. An Atomic Governance Transition Engine executes indivisible state changes: record incorporation, key destruction, counter advancement, and IOMMU treasury isolation. A Quantum-Resistant Governance Key Lifecycle Engine performs CRYSTALS-Kyber (ML-KEM, FIPS 203) key rotation with cryptographic agility. A Cross-Chain Governance Attestation Bridge publishes TEE-signed proofs to multiple blockchains. A Deterministic Governance Replay Engine reconstructs governance decisions in isolated sandboxes. An Automated Governance Incident Response Engine and Governance Regulator Verification Network provide hardware-enforced, independently auditable compliance enforcement.
Owner:BICKERSTAFF III GEORGE WILLIAM

Communication and payment device and method for preventing telecommunication fraud

The invention relates to a communication and payment device and method for preventing telecommunication fraud. If whether the caller and the electronic payment operator are abroad or not can be identified, a large amount of fraud can be stopped, and even in China, the safety can be greatly improved by identifying the position. The position is indicated only by a conventional smart phone, which is unreliable, and we must adopt a more reliable method. If the position is verified at a fixed position, the verification is relatively simple, and a device (a chip for verifying the position is hereinafter referred to as a transponder) with a fixed position can be used for sending verification information to the platform; to ensure security, the transponder may indicate the location to the platform using a dynamic authentication code. A key required for generating the authentication code can be generated by a transponder. If the position of a user is not fixed and is difficult to determine, a positioning chip can encrypt coordinates, and an enemy cannot generate a correct ciphertext, so that cheating cannot be implemented, and the chip is hereinafter referred to as a'secret bit chip '. The user activity track can well indicate the identity, hereinafter referred to as track verification.
Owner:NANJING ZHENSHENG BIYING TECHNOLOGY DEVELOPMENT CO LTD

Techniques for encryption based on perfect secrecy for bounded storage

Techniques for secure remote digital storage or transmission of a ciphertext message include determining a maximum storage capacity of an adversary, determining a security parameter k, wherein 1<<k<<m, and determining a prime number n, such that ≤0.3kn. A current public portion of random string α, comprising n random elements, is read from a public site. A secret key z, wherein z has 2k elements, comprising k additive co-primes of n and k multiplicative co-primes of n is shared with a receiving site. An encryption key X, based on the secret key and the current public string, is determined and applied to a plaintext message M of length ≤m to encrypt the plaintext message as Y=M⊕X, thereby creating the ciphertext message Y, which can be placed on a public forum for receiving by a receiving node.
Owner:RGT UNIV OF CALIFORNIA

Detection and survival method against adversarial attacks on automated systems

Methods provide device authentication for an intrusion detection system implementing building automation and control network (BACnet) Master-Slave / Token-Passing (MS / TP). An authentication protocol provides countermeasures to vulnerabilities in the BACnet MS / TP physical layer by utilizing an extended message format to cloak device identifiers (IDs). Adversaries are prevented from using known device IDs to gain access to the network. An authenticating device hashes a device identifier of a device to be authenticated combined with a random number. The authenticating device receives a hash of the random number plus the device identifier from the device. The authenticating device compares the hashes and authenticates the device if the hashes match. To transmit the hash, the BACnet MS / TP frame format includes an extended header cyclic redundancy check (CRC) field having bytes reallocated from the data field of the frame format. Another countermeasure utilizes a physical unclonable function (PUF) of the device in the extended header CRC.
Owner:MORGAN STATE UNIVERSITY

A layered federated security aggregation method based on cloud-edge collaboration

This invention relates to a hierarchical federated security aggregation method based on cloud-edge collaboration, belonging to the field of network security technology. This method effectively defends against model / data poisoning attacks through a two-layer anomaly detection mechanism, and combines a cloud-edge collaborative two-way authentication mechanism to achieve trusted user identity verification and service access control, simultaneously improving edge network security and privacy protection capabilities. This method can effectively mitigate the impact of poisoning attacks on hierarchical federated learning systems in a cloud-edge-device environment, while also reducing the risk of privacy leaks caused by external adversaries obtaining model parameters through eavesdropping.
Owner:BEIJING INST OF COMP TECH & APPL

Adaptive steganography watermark-based opponent perception authentication method in federal learning

The invention discloses an opponent perception authentication method in federal learning based on an adaptive steganography watermark, and the method comprises the steps: constructing the identity information of a device, encrypting the identity information, and transmitting the encrypted identity information to an authentication server; the authentication server processes the request of the external equipment to ensure that each equipment added into the system has a controlled validity period and clear identity information; the equipment sends an application to the authentication server again according to the validity period, and the server cleans internal invalid equipment regularly; the authentication server registers device IDs for legal devices and groups the legal devices, selects group leader devices for each group and formulates rotation rules; the authentication server generates a corresponding watermark triggering data set for each group, and sends the watermark triggering data set together with the global model and the authentication data set to all legal devices; legal equipment trains a global model and learns a trigger strategy; and the authentication server performs security authentication on the legal equipment. According to the invention, the controllability, accuracy and concealment of the authentication process are improved, and safe, efficient and concealed authentication is realized.
Owner:FUJIAN NORMAL UNIV

A robust multi-label website fingerprint defense method based on hybrid deep learning

The present invention discloses a robust multi-label website fingerprint defense method based on hybrid deep learning, belonging to the field of network security technology. The present invention comprises two stages: reconstructing input sequences and constructing an anonymous sequence model. In the first stage, some overlapping virtual packet traces are first generated to the trainer adversary, making the trainer adversary familiar with the multi-tab overlapping traffic and website identities, thereby reducing the adversary's accuracy. Then, LSTM (long short-term memory) autoencoder technology is designed to effectively reconstruct the overlapping input sequences in the multi-tab interface and separate the overlapping regions. In the second stage, bidirectional long short-term memory (Bi-LSTM) is applied to anonymize the traffic sequence to blur the sequential pattern of user interactions. At the same time, adversarial examples are added during the training process to further improve the robustness of the method.
Owner:TIANJIN UNIV

Key negotiation method for emergency rescue systems based on 5G encrypted signals

This invention discloses a key negotiation method for an emergency medical system based on 5G encrypted signal transmission, comprising: establishing two entities, a user and a hospital, within the emergency medical system for mutual authentication and key negotiation between the two entities in the 5G network, and obtaining a session key between the entities; establishing a system management module for identity management, key management, and encrypted transmission management of the user and hospital during the session; generating an encrypted signal when the user uses the emergency medical system, simultaneously establishing a temporary identity for the user, and forming a public key and a private key through the temporary identity for transmitting the encrypted signal; establishing an adversary model to calculate the probability of an adversary successfully forging authentication messages and successfully obtaining the session key when the emergency medical system is maliciously attacked. This key negotiation method for an emergency medical system based on 5G encrypted signal transmission prevents unauthorized users from forging authentication messages and resists forgery attacks, ensuring the security of the session key.
Owner:GUANGZHOU LANSWICK SOFTWARE DEV CO LTD

L1 security signaling

A UE may detect, at the UE, a suspected fabricated transmission attack based on PHY security. The UE may transmit, to a network node, and the network node may receive, from the UE, an indication of the suspected fabricated transmission attack. The network node may receive, from the UE, an indication of one or more characteristics associated with a potential attacker associated with the suspected fabricated transmission attack. The UE may transmit, via a sidelink to at least one additional UE, a second indication of whether the UE identifies that the suspected fabricated transmission attack corresponds to the UE being attacked. The network node may identify a geographical location of the potential attacker based on a plurality of indications of the one or more characteristics associated with the potential attacker. The network node may compile an adversary pool including one or more compromised identities.
Owner:QUALCOMM INC

Deception-based responses to security attacks

ActiveUS12694108B2Domain nameAdversary
Deception-based techniques for responding to security attacks are described herein. The techniques include transitioning a security attack to a monitored computing device posing as a computing device impacted by the security attack and enabling the adversary to obtain deceptive information from the monitored computing device. Also, the adversary may obtain a document configured to report identifying information of an entity opening the document, thereby identifying the adversary associated with the attack. Further, the techniques include determining that a domain specified in a domain name request is associated with malicious activity and responding to the request with a network address of a monitored computing device to cause the requesting process to communicate with the monitored computing device in place of an adversary server. Additionally, a service may monitor dormant domains names associated with malicious activity and, in response to a change, respond with an alert or a configuration update.
Owner:CROWDSTRIKE

Randomization method and single secret leader election method

The invention discloses a randomization method and a single secret leader election method, and belongs to the technical field of computer technology and information security. In order to solve the technical problems of unfair leader election and insufficient privacy caused by the fact that a decayed enemy can use a randomization process to interfere a system state, an approximately unique randomization component is constructed by using random factor commitment and hierarchical broadcast, and the component is used for driving a random shuffling process to generate a unique system state. A leader node is selected from the secret list based on the persistent random pointer and the system state is updated by the selected leader. According to the scheme, the consistency of randomization results and the approximate uniqueness of random factors can be realized, corruption opponents with any malicious behaviors can be resisted, and the fairness and privacy of election of a single secret leader can be ensured.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Device-independent quantum secret sharing method based on multiphoton entanglement

The present application belongs to the technical field of quantum communication, and discloses a device-independent quantum secret sharing method based on multi-photon entanglement, which requires a key sender to prepare a large number of identical three-photon GHZ states, and to send two photons in each GHZ state to two key receivers respectively; after receiving the photons, the three parties randomly select measurement bases to measure the adversary's photons, and publish the measurement bases and part of the measurement results, so as to estimate the values of Svetlichny polynomials and CHSH polynomials; the security of the transmitted key is ensured by Svetlichny inequality violation and CHSH inequality violation. The present application can resist all attacks from imperfect device ends, reduce the requirement for the security of experimental equipment, effectively enhance the security of QSS under actual experimental conditions, and has important application in the field of future quantum secure direct communication.
Owner:NANJING UNIV OF POSTS & TELECOMM

A method for selecting the optimal distributor in a peer-to-peer content distribution network based on blockchain

This invention provides a method for selecting the optimal distributor in a blockchain-based peer-to-peer content distribution network. Under the conditions of a synchronous network, a static polynomial-time adversary, a global predicate defining the correctness of a given content, and a global synchronization time function, a verifiable distribution quality protocol is used to certify the quality of content distribution in the interaction between a sender S, a receiver R, and a verifier V. A comprehensive distributor reputation evaluation mechanism is established based on quantifiable and verifiable distributor service quality and domain entropy weight calculation to obtain the comprehensive credibility of each distributor. An optimal distributor selection algorithm is designed to select the most suitable distributor based on the comprehensive credibility of the distributor and the total budget of the content provider. This invention addresses the issue of trustworthiness of distributor evaluation dimension information, selects the most suitable distributor within the budget provided by the content provider, improves distribution efficiency, and fully guarantees security and efficiency.
Owner:SOUTHWEST JIAOTONG UNIV

Protection of data and ai models executed on hardware accelerators

Protection is lacking for various artificial intelligence (AI) assets (e.g., AI models and data) after they are distributed to an end user and loaded into their target AI computing hardware (e.g., NVIDIA GPUs). In some cases, protection for such assets is limited to binding their usage with legal terms, but malicious or adversary market participants cannot be prevented from ignoring such legal terms. Computing assets, such as AI models or data associated with AI models that used on a graphics processing unit (GPU), can be protected from unauthorized use or theft via technical safeguards.
Owner:SIEMENS AG +1

Counter adversary large language models

A system and method of using generative AI to maintain conversations with attacking devices to discover their adversary techniques and tactics. The method includes receiving an initial message originating from an attacking device and directed to a target device. The method includes generating, using one or more classification models, a maliciousness score for the initial message indicating that the initial message is associated with one or more types of malicious activity. The method includes providing, by a processing device, the initial message to a predictive model trained to maintain conversations with attacking devices by predicting responses to malicious messages. The method includes generating, using the predictive model, two or more responses based on the initial message and at least one subsequent message, wherein each response of the two or more responses causes the attacking device to send a respective subsequent message to the predictive model.
Owner:CROWDSTRIKE

Method and system for analysing and mitigating security risks in open innovation ecosystem

PendingUS20260039683A1Securing communicationResearch dataInnovator
A method and system for analysing and mitigating security risks in open innovation ecosystem is disclosed. The system comprises detects potential vulnerabilities in open innovation activities, including intellectual property exchanges, research data handling, and partner collaboration processes to provide identified threat data as input. The system represents interactions between an innovator and an adversary as a two-player zero-sum game. The system computes Nash equilibrium from the payoff matrix. The Nash equilibrium represents optimal defensive investments under adversarial conditions. The system also models adversary uncertainty using probability distributions, and further updates the equilibrium strategies based on incomplete or dynamic information. The system, thereafter, evaluates adversary uncertainty using Entropy-based risk assessment to determine levels of security investment resources responsive to the quantified uncertainty. Finally, the system integrates results of the equilibrium analysis, probabilistic inference, and uncertainty quantification to generate actionable security recommendations and guidelines for mitigation strategies.
Owner:SAFDAR UMAR +3

A federated learning method based on high-availability non-interactive secure aggregation

The application discloses a kind of federal learning methods based on high availability non-interactive security aggregation scheme, its characteristics are based on the security aggregation method of pairing mask, through asynchronous public subset consensus algorithm, it is realized on distributed server cluster non-interactive high availability security aggregation federal learning, specifically includes: (A) initialization stage (B) aggregation stage epoch 0, first round, user;(C) aggregation stage epoch 0, first round, server;(D) aggregation stage epoch 0, second round, user;(E) aggregation stage epoch 0, second round, server;(F) aggregation stage epoch k (k>0), user and (G) aggregation stage epoch k (k>0), server etc.Steps.The application has high availability security aggregation, small amount of calculation, resists malicious adversary and other advantages compared with prior art, realizes the privacy protection of gradient information, and guarantees the correctness of federal learning training result, is established in the asynchronous network model closest to real network model, with higher practical application value.
Owner:EAST CHINA NORMAL UNIV +1

Cryptographic data message expansion for increasing adversarial storage requirements

The disclosure relates to generating a ciphertext of arbitrary and flexibly large size and ensures that an adversary learns little about the encrypted data, even if the decryption key later leaks, unless substantially the entire ciphertext is stored. Given that communication will be inconveniently large for the adversary to store, the incompressible ciphertexts and signatures can be sent and received with low storage requirements for the honest users. In such a setting, the honest users would not store the entire ciphertext or signature, but instead generate, send, and process the communication bit-by-bit in a streaming fashion.
Owner:NTT RESEARCH INC

Validation traps to detect adversary attempts to secure access

Embodiments relate to reinstating access to a system of an admin whose certificate is invalid or expired and to detecting an attack on the system. A requestor, who may be an admin whose certificate is expired or invalid, may send a request for reinstatement to validators. The system may provide honeypot validators in addition to legitimate validators. When the request is received by a honeypot validator or if the honeypot validator is requested to provide their share of a secret, the requestor is determined to be malicious and a protective operation or action is performed.
Owner:DELL PROD LP

Resilience against unknown denial-of-service attacks via multipath communications

Presented herein is an effective protection method against unknown and unanticipated denial-of-service attacks and guarantee mission critical message delivery. Multipath communication may be leveraged as a preventive device-centric mechanism to ensure message deliveries in the event of unknown denial-of-service attacks. The mechanism may complement other device-centric mitigation techniques as the mechanism does not wait for the detection of adversaries in the network and is attack-agnostic. In particular, the technique may be effective against a wide range of denial-of-service attacks at any protocol layer.
Owner:THE WICHITA STATE UNIV +1