Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12 results about "Authenticated Key Exchange" patented technology

Authenticated Key Exchange (AKE) (or Authenticated Key Agreement) is the exchange of session key in a key exchange protocol which also authenticate the identities of parties involved in the key exchange.

Identity binding authentication key negotiation method based on user password enhancement

The invention discloses an identity binding authentication key negotiation method based on user password enhancement, and belongs to an information security technology. According to the method, aiming at the problems that an existing identity binding password authentication key exchange protocol cannot resist brute force attack after compromise and communication rounds are many, a high-entropy key is introduced to be bound with a user password and a device identity, and an enhanced long-term identity certificate is constructed. The protocol comprises three stages of system initialization, equipment registration and single-round authentication key exchange. In the registration stage, the device generates an authentication file containing a long-term private key and public parameters based on a password, a high-entropy key and identity information. In a key exchange stage, both parties only need to exchange single-round messages, identity authentication and a key exchange process are fused in a mode of encrypting a temporary public key by using own identity public keys, a receiver can independently decrypt and verify the identity of the opposite party, and then a shared session key is calculated in combination with own private keys and public parameters of the opposite party; the communication security is ensured, and the protocol efficiency and the anti-attack capability are improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Password-based authenticated key agreement on grids

The application provides a password-based authentication key agreement method based on a lattice, which allows a user to use a password to agree with a server on a session key and authenticate the user identity. The method is constructed based on an ideal lattice, and its security is established on a ring-based learning problem with errors, so that the method can effectively resist quantum attacks. The user's credentials are saved in the form of password-encrypted in the server end, and only the user with the correct password can decrypt the legal credentials and establish the subsequent session key. When the session key is established, the user and the server perform an authenticated key exchange with a key hiding attribute to prevent the user's credential information from being leaked. Even if an enemy obtains the user's password-encrypted credential ciphertext and exhaustively searches the password space to decrypt the ciphertext to obtain a possible user credential set, the correct password corresponding to the credential cannot be identified from the set, so the application can resist offline dictionary attacks. In addition, two-way key confirmation can ensure the consistency of the session key and verify the user identity.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Forward security zero round-trip time authentication method and system based on hash function

The invention discloses a forward security zero round-trip time authentication method and system based on a hash function, and the method comprises the steps: generating a first random number, a first private key and a corresponding public key through a client, encrypting application data through combining with a temporary session key, and constructing a protocol request message for transmission; the server generates a second random number, a second private key and a public key after verification, returns a protocol response message, and negotiates a shared key based on temporary private keys of the two parties; the two parties derive a new pre-shared key, a temporary session key and a session key using the shared key and a hash function. And the temporary private key is discarded after being used, so that the historical session still has forward security even if the key is leaked for a long time, and 0-RTT data transmission is supported at the same time. According to the invention, the shared key based on temporary private key negotiation is introduced, and the hash function is combined to derive and dynamically update the pre-shared key and the temporary session key, so that authentication key exchange with forward security and 0-RTT low-delay characteristics is realized.
Owner:XIAMEN UNIV

Equipment certification methods, devices, electronic equipment and storage media

This invention provides a device authentication method, apparatus, electronic device, and storage medium, belonging to the field of information security. The method includes: determining a trusted device for a first device and a second device; generating a challenge random number, and generating challenge parameters based on the challenge random number and the device identity identifier of the trusted device; sending the challenge parameters to the trusted device and obtaining verification parameters returned by the trusted device; when the verification parameters pass verification, negotiating a session key with the second device using a password authentication key exchange protocol based on the challenge random number; and performing a device identity identifier exchange operation based on the session key, so that the first device and the second device exchange their respective device identity identifiers. This method significantly improves the efficiency of device authentication.
Owner:深圳开鸿数字产业发展有限公司

Blockchain-based password authentication key exchange and authentication method resistant to quantum attacks

This invention discloses a quantum-attack-resistant blockchain-based password authentication key exchange and authentication method. The method involves inputting preset parameters, a trapdoor, a matrix, a noise vector, a password, and a public key into a computer system; executing a parameter generation algorithm to generate public parameters; executing a hash key generation algorithm to generate a hash key and a projected hash key generation algorithm to generate a projected hash key; generating a tag based on the identifiers of both communicating parties and the projected hash key, encrypting it to obtain ciphertext, and transmitting and receiving the projected hash key and ciphertext from the communicating party; verifying the validity of the communicating party's projected hash key, and generating a session key based on relevant parameters; and finally, the computer system processor executes a computer program and outputs the session key. This invention integrates a lattice-based smooth projected hash function with a trapdoor and a blockchain structure, possessing quantum attack resistance, general composable security characteristics, requiring only one round of communication, and is suitable for large-scale blockchain node scenarios.
Owner:GUIZHOU UNIV

Pairing method applied to short-range communication system and wireless device

A pairing method applied to a short-range communication system and a related wireless device in the field of wireless communication are disclosed. The method includes: obtaining, by a first wireless device, a first password, where the first password is shared by the first wireless device and a second wireless device; and pairing, by the first wireless device, with the second wireless device based on a password-based authenticated key exchange (PAKE) protocol and by using the first password as an encryption password in a key exchange process.
Owner:HUAWEI TECH CO LTD

Apparatus and a Method for Interacting With a Digital Key on a Key Card

The present document describes an apparatus for interacting with a key card, wherein the apparatus is configured to automatically determine a password for an authenticated key exchange (PAKE) scheme, and to execute the PAKE scheme with the key card using the password. Furthermore, the apparatus is configured to, subsequent to executing the PAKE scheme, perform a digital key-related interaction with the key card, which relates to a digital key enabled for controlling one or more vehicle functions of a vehicle.
Owner:BAYERISCHE MOTOREN WERKE AG

Content transmission protection method and related equipment thereof

The invention discloses a content transmission protection method and related equipment thereof, which can avoid audio and video stream leakage when a sending end and a receiving end are authenticated. The method comprises the following steps: in the process of establishing a transmission link between a sending end and a receiving end, the sending end and the receiving end exchange an authentication key to obtain an authentication key; the sending end carries out session key negotiation on the receiving end based on the authentication key to obtain a session key; after the transmission link between the sending end and the receiving end is established, the sending end performs authorization control on the receiving end; and after the sending end completes authorization control on the receiving end, the sending end sends the encrypted audio and video stream to the receiving end, and the encrypted audio and video stream is encrypted based on the session key.
Owner:HUAWEI TECH CO LTD

QKD remote key distribution method, system and device based on PQC channel and medium

The invention belongs to the technical field of quantum communication, and particularly relates to a QKD remote key distribution method, system and device based on a PQC channel and a medium. In order to overcome the defect that performance overhead and risk exposure cannot be coordinated in the prior art, the technical scheme adopted by the invention is as follows: the QKD remote key distribution method based on the PQC channel comprises the following steps: completing storage of a mother key in a server in a hardware security module in advance; a temporary PQC authentication key exchange channel with forward confidentiality and quantum attack resistance is established between a client side and a server side, the server side adopts a standard PQC digital signature to perform identity authentication, and the client side indirectly realizes identity authentication on the server side through a key packaging mechanism; the remotely distributed key is a one-time service key; and carrying out encrypted communication between the clients by using the service key. The method has the beneficial effects that the contradiction between the performance overhead and the risk exposure is solved through an asymmetric authentication protocol and a strict risk isolation architecture.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Qkd remote key distribution method, system, device and medium based on pqc channel

ActiveCN121923817BImplement identity authenticationlower the thresholdRisk exposureHardware security module
The present application belongs to the technical field of quantum communication, and particularly relates to a QKD remote key distribution method, system, device and medium based on a PQC channel. In view of the fact that the prior art fails to coordinate performance overhead and risk exposure, the present application adopts the following technical solution: a QKD remote key distribution method based on a PQC channel, comprising: pre-storing a parent key in a service end in a hardware security module; establishing a temporary, forward-secure, anti-quantum-attack PQC authentication key exchange channel between a client and the service end, the service end performing identity authentication by using a standard PQC digital signature, and the client indirectly implementing identity authentication of the service end through a key encapsulation mechanism; the remotely distributed key is a one-time business key; and the business keys are used for encrypted communication between clients. The present application has the beneficial effect of resolving the contradiction between performance overhead and risk exposure through an asymmetric authentication protocol and a strict risk isolation architecture.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Face recognition based authentication key secure communication method and system

This disclosure provides a secure communication method and system for authentication keys based on facial recognition, relating to the field of authentication key exchange technology in applied cryptography. The method includes initializing the two parties involved in the communication and generating common parameters; the two parties are a sender and a receiver; acquiring the facial information recorded by both parties, converting it into facial embedding vectors, and storing it in a set; generating a public key based on the recorded facial information; when the Euclidean distance between the facial embedding vector of the facial information and an element in the set is less than a set threshold, sending the public key to the other party through an authentication channel for exchange; mutual authentication and negotiation of a session key between the two parties; the sender selecting a random message to generate a session key, then encapsulating the random message; the receiver performing a facial registration to generate a private key to decapsulate the random message and obtain the session key, thus completing the acquisition of the random message. This disclosure achieves secure communication of facial recognition technology in high-dimensional noisy environments.
Owner:SHANDONG UNIV

Interface program of key distribution security protocol and security protection implementation method

The invention discloses an interface program of a key distribution security protocol and a security protection implementation method, which are implemented through four stages of initialization, identity authentication, key exchange and generation, and security protection and updating aiming at the problems of security vulnerability, low efficiency, incomplete interface and the like of the traditional protocol. In the initialization stage, system parameter configuration and key pair generation are completed, biological feature + PUF equipment multi-factor authentication is adopted in identity authentication, key exchange is based on an improved Diffie-Hellman protocol, and safety protection comprises dynamic key updating, HMAC verification and anomaly detection. The method integrates a national secret algorithm and a TEE / HSM security environment, resists attacks such as man-in-the-middle, replay and the like, optimizes the operation efficiency, perfects an interface and log system, adapts to multiple scenes such as a power grid, finance and the like, meets the security compliance requirements, and guarantees the full-life-cycle security of a secret key and the confidentiality and integrity of data transmission.
Owner:GUANGXI POWER GRID CORP