Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

155 results about "Authentication protocol" patented technology

An authentication protocol is a type of computer communications protocol or cryptographic protocol specifically designed for transfer of authentication data between two entities. It allows the receiving entity to authenticate the connecting entity (e.g. Client connecting to a Server) as well as authenticate itself to the connecting entity (Server to a client) by declaring the type of information needed for authentication as well as syntax. It is the most important layer of protection needed for secure communication within computer networks.

Context-aware, artificial intelligence-based system for increasing employee engagement and automating the integration of business processes.

A system for improving employee engagement and automating the integration of business processes. The system includes: a user interaction module configured to receive multimodal inputs, including natural language text and voice requests from employees via enterprise portals, mobile applications, voice-activated devices, and collaboration platforms, and to generate real-time responses via conversational output channels; a context processor that is operationally coupled with the user interaction module, wherein the context processor stores the interaction history, employee preferences, organizational role metadata, and task results in both short-term and long-term memory and dynamically derives context for controlling responses and initiating workflows; A natural language and intent processor that is communicatively linked to the context processor. The intent engine consists of large language models trained on company-specific lexicons to perform intent detection, entity extraction, ambiguity resolution, and sentiment or urgency classification from employee queries; a workflow orchestration layer in communication with the intent engine and the context processor, wherein the workflow orchestration layer includes a rule-based and AI-powered process execution engine configured to automatically initiate, route, and complete cross-functional business tasks, including approvals, escalations, and compliance checks, with workflows defined using modular templates that include conditional logic and time-based triggers; Webhooks and authentication protocols provide secure interoperability between the workflow orchestration layer and external enterprise platforms; a feedback and learning module that is operationally coupled with the workflow orchestration layer and the natural language understanding engine, wherein the feedback and learning module is configured to analyze task completion rates, response accuracy, latency metrics, and user feedback signals, and to retrain underlying language and workflow models for adaptive improvement in real time; and an administration console with role-based access controls, compliance dashboards, audit trails and interfaces for workflow configuration, whereby the administration console enables authorized personnel to monitor system operations, adjust interaction rules and enforce data protection restrictions across departments.
Owner:KURAPATI SURESH KHAMMAM +3

Communication authentication method and system of train on-board network, storage medium and equipment

The invention provides a communication authentication method and system for a train-mounted network, a storage medium and equipment, and the method only completes the key negotiation operation in the process of executing the communication authentication of the train-mounted network, enables the subsequent communication process to be executed based on a session key obtained through the negotiation of a first verification party and a second verification party, and improves the communication authentication efficiency. According to the method and the device, identity information of two communication parties is mutually verified, only a request carrying identity information of a verification party needs to be sent once in a primary communication process, only a session key generated by negotiation needs to be carried in a subsequent communication process, lightweight processing is performed on a communication authentication protocol, and the communication authentication protocol can be obtained by introducing a pairing-free password system based on an identity label. According to the method, a complex pairing process does not need to be executed, the number of calling times of Hash is reduced, the protocol calculation overhead is reduced, the communication efficiency is improved on the basis of ensuring the credible access authentication of a train-mounted network and the credible transmission of a control message, and the influence on the real-time performance of a train network monitoring management system is avoided.
Owner:NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT

Unified identity authentication and access control method for power multi-service system based on national secret algorithm

The invention discloses a unified identity authentication and access control method for a power multi-service system based on a national secret algorithm. According to the invention, through systematic deployment of SM2, SM3 and SM4 cryptographic algorithms, a full-link security protection system from identity authentication to authority management is constructed. The unified identity authentication platform adopts a mode of combining a distributed micro-service architecture and a hardware encryption machine, so that the physical security of key storage and operation is guaranteed, and the stability and response speed of the system are improved through a master-slave synchronization mechanism and interface delay control. A multi-source identity information federation acquisition mechanism realizes real-time integration of static attributes and dynamic behavior data, abnormal characteristics of user operation can be accurately captured by combining a risk assessment matrix of an improved LSTM-attention mechanism, and an SM2 bidirectional dynamic authentication protocol is automatically triggered when a risk score exceeds a dynamic threshold. Closed-loop protection of collection-evaluation-authentication-auditing is formed, and security threats such as identity counterfeiting and authority crossing are effectively resisted.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

System, method, device and equipment for safe communication between charging pile and BMS and storage medium

The invention relates to the field of electric vehicle charging control, and particularly provides a system, method, device and equipment for safe communication between a charging pile and a BMS and a storage medium, the system comprises a bidirectional authentication module, a communication encryption module, a verification module and an optimization module; the bidirectional authentication module is used for constructing a bidirectional authentication protocol between the charging pile and a battery management system (BMS) based on the hardware security module and authenticating the identity; the communication encryption module is used for customizing an integrated transport layer security protocol line through an open source tool and encrypting security communication data; the verification module is used for designing a three-level verification mechanism, blocking a malicious firmware injection path and verifying a secure communication process; and the optimization module is used for optimizing the key process by adopting a redundant backup scheme deployed in a containerization manner. Through the system, the effect of a safe communication process between the charging pile and the BMS can be realized.
Owner:CHINA FAW CO LTD

Systems and methods for using partial cookies for electronic authentication and authorization

The methods and systems disclosed herein allow for faster and more efficient authentication using a partial cookie instead of a full cookie (or other data structure). In one example, a server receives, during the first browser session at the first time, a first request for authorization from an electronic device along with authentication information. Responsive to generating a profile using the authentication information, the server transmits to the electronic device a first data source configured to grant access to the profile to the electronic device, via a first authentication protocol; and receives, at a second browser session at a second time, from the electronic device, a second request for authorization to access the profile; responsive to a determination that the electronic device includes the first data source, the server executes a secondary authentication protocol.
Owner:STRIPE LLC

API invoker authentication method and apparatus, communication device, and storage medium

A method for authenticating an application program interface (API) invoker enhances secure communication between API invokers and a Common Application Program Interface Framework (CAPIF). The method involves sending authentication information from the API invoker to the CAPIF function, which authenticates the invoker's identity. The process includes obtaining enrollment information to establish a secure transport layer security (TLS) connection with the CAPIF function. Advanced authentication mechanisms leverage an authentication and key management for applications (AKMA) anchor key, enabling secure derivation and verification of application function keys (KAF). Additionally, the CAPIF function uses received authentication data to retrieve API invoker configuration information, onboard signing keys, and certificates. These elements facilitate secure API access and interaction while ensuring compliance with authentication protocols.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for electric red-in secure connection terminal

The invention relates to the technical field of near-field communication security, in particular to a hardware-level identity authentication and end-to-end encryption near-field data interaction method and system for an electric red-connected terminal, and the method comprises the steps: a first electric red-connected terminal and a second electric red-connected terminal initiate pairing based on a Bluetooth secure connection pairing protocol, and negotiate to generate a long-term key through an ECDH algorithm; performing bidirectional identity verification by adopting an application layer authentication protocol; activating AES-CCM encryption by using a session key derived from a long-term key; bluetooth signal strength and a connection state are monitored in real time, and a negotiation key is automatically paired again when abnormity occurs; generating an interaction log, digitally signing the log by using a locally stored private key, and securely storing the signed log in a local secure storage area of the terminal; the digital signature of the latest log is verified, and if interaction abnormity is found, the local security module of the terminal recovers the local data to the pre-interaction state according to the last credible log record. The problem that traditional Bluetooth communication is prone to eavesdropping and tampering can be solved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Data use control method and system based on smart contract

The invention discloses a data use control method and system based on a smart contract, and relates to the technical field of data use control, and the system comprises an identity authentication module, a data classification and grading module, a data sandbox module and an evidence storage traceability module. Performing identity authentication on a user request of a data user based on an authentication protocol; performing classification rating on the accessed data; the data user and the data provider negotiate a contract signing detailed rule; the data user and the data provider sign a block chain smart contract; deploying the intelligent contract to a data sandbox, performing authority evaluation and distribution on the user, and performing behavior monitoring on the user; when the data user violates the signed smart contract, terminating the data access permission of the user, and calling the data sandbox to execute operation according to the contract signing content; logs are automatically generated, data access and use circulation are traced in the whole process, and it is ensured that data can be traced, audited and managed from authorization to use. According to the invention, the security and credibility of data circulation are guaranteed in a data transmission use control mode with decentration and multi-party cooperative participation.
Owner:DATA SPACE RES INST

Customized network interface card oriented to intranet security access and design method thereof

The invention discloses a network interface card with autonomous access authentication, and provides an integrated hardware authentication mechanism. The EAP-TLS client protocol stack is integrated on the bottom layer of the network card, so that the defect that an authentication module depends on a host system, manual intervention and the like in the existing scheme is overcome, TLS handshake and certificate verification are independently completed on the network card side, and authentication interaction is automatically initiated. The network interface card serves as a unique identity certificate of an access network, a client certificate and a corresponding private key are embedded in the network interface card and are stored in a protected nonvolatile area, and data confidentiality is effectively enhanced. The network card is used as an identity certificate and network access equipment at the same time, and the integrated design reduces the dependence on the service capability of management personnel. A traditional physical network card and an automatic authentication protocol are fused, and the method is suitable for application environments with high requirements for access control and authentication safety, such as an enterprise intranet and a government affair private network.
Owner:INFORMATION TECH RES INST OF EXIT & ENTRY MANAGEMENT OF THE NAT IMMIGRATION ADMINISTRATION

Meal-aid management system and meal-aid machine for old-age care service

The invention discloses a meal-assisting management system and a meal-assisting machine for old-age service, and relates to the technical field of dining management for old-age service, the meal-assisting management system and the meal-assisting machine for old-age service are characterized in that physiological parameters of old people are acquired in real time through a health data acquisition module, and a taboo food material list is generated according to the physiological parameters and the taboo food material list through a nutrition matching engine; the meal dispatching server generates a meal preparation instruction based on the meal preparation instruction, and personalized meal services conforming to the health conditions of the old people can be provided for the old people; a data desensitization unit of the health data acquisition module encrypts identity fields in physiological parameters, and establishes secure connection with a medical insurance database based on an SM2 national cryptographic algorithm bidirectional authentication protocol to ensure the security and privacy of data of the old; a space-time prediction unit of the meal dispatching server adopts a convolutional neural network to process historical meal records, and the meal delivery amount in different periods can be accurately predicted; and the path optimization unit calculates an optimal distribution path based on a genetic algorithm, so that the distribution efficiency is improved, and the distribution cost is reduced.
Owner:LIUPANSHUI VOCATIONAL & TECH COLLEGE

Wi-fi protected access 3-compatible authentication using an established binding

In response to an association request associated with an electronic device to a second WLAN that uses a WPA3-compatible authentication protocol, an access point may establish a connection with an electronic device using the second WLAN when a binding between a passphrase associated with the electronic device and the second WLAN exists in a computer system. Alternatively, when the binding does not exist, the access point may reject the association request. Instead, the access point may establish a second connection with the electronic device using a first WLAN that uses a WPA2-compatible authentication protocol, and may establish the binding in a computer system. Next, the access point may perform a BSS transition of the electronic device from the first WLAN to the second WLAN. Furthermore, the access point may perform authentication of the electronic device after the connection or the second connection is established.
Owner:RUCKUS IP HOLDINGS LLC

Auditable privacy protection authentication method based on Internet of Things access

The invention relates to the technical field of Internet of Things access, in particular to an auditable privacy protection authentication method based on Internet of Things access, which comprises the following steps: acquiring an uplink and downlink message extraction field set and verifying consistency, generating a mismatch identifier and screening a protocol candidate set if the uplink and downlink message extraction field set is not consistent, matching an optimal protocol based on the mismatch identifier and generating an instruction, and reconstructing a session collection feature construction vector to obtain a synchronization period, and predicting a trend judgment deviation adjustment period to generate a scheduling strategy. According to the invention, through uplink and downlink message structure field consistency verification and protocol matching score screening, rapid adaptation and dynamic identification of an authentication protocol are realized, a protocol vector model and similarity score are fused to improve multi-protocol authentication elasticity, and delay jitter is introduced to construct a communication dynamic vector. In combination with trend prediction and period adjustment, the key synchronization real-time adaptive ability is enhanced, key refresh is triggered when communication abnormity occurs initially, the key update sensitivity is improved, and the authentication accuracy of equipment access and the privacy protection durability are guaranteed.
Owner:BEIJING RUIYU TECHNOLOGY CO LTD

Semantic communication security enhancement system based on SIM (Subscriber Identity Module) card quantum key presetting

The invention relates to the technical field of mobile communication, and particularly provides a semantic communication security enhancement system based on SIM card quantum key presetting, comprising an SIM card security base module configured to generate physical unclonable function characteristics and preset quantum security keys by using SIM card hardware characteristics; the lightweight authentication protocol module is in communication connection with the SIM card security base module and is configured to realize dynamic identity authentication based on physical unclonable function characteristics and a quantum security key; the semantic security enhancement module is configured to perform privacy protection processing on the semantic communication data; the trusted execution environment optimization module is in communication connection with the SIM card safety base module and the lightweight authentication protocol module and is configured to construct a hardware-software collaborative trusted execution environment; the quantum security enhancement module is integrated on the SIM card security base module and is configured to provide quantum attack resistance and dynamic key management; according to the invention, the real-time performance and anti-quantum computing capability of key distribution are significantly improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Methods and Systems for In-Band Sign Up to a Wireless Network

An example method includes determining, by a client computing device, that a wireless access point (WAP) supports an in-band secure access protocol to connect to a wireless network hosted by a server, where the protocol involves establishing an initial network connection to exchange subscription data. The method includes receiving, from the WAP, a temporary login credential and an authentication protocol for the server. The method includes utilizing the temporary login credential and the authentication protocol to establish the initial network connection. The method includes exchanging the subscription data with the server over the initial network connection. The method includes completing the protocol by downloading, from the WAP and over the initial network connection, a subscription file. The subscription file enables the client computing device to establish an encrypted and trusted network connection over the wireless network.
Owner:GOOGLE LLC

Cross-application login, authentication and information synchronization method and system

The invention provides a cross-application login, authentication and information synchronization method and system. The method comprises the following steps: synchronizing user information to a plurality of target applications at regular time by utilizing a timer; setting a unified authentication interface and sharing the authentication information of the user to provide a single sign-on function; and providing a password-free login function through an encryption algorithm based on the authentication information of the user. According to the method, multiple authentication protocols can be integrated, unified management and login functions are realized, and an information synchronization mode is provided, so that information leakage and hostile attack are avoided, and convenience and security are improved.
Owner:SICHUAN DETUO INFORMATION TECHNOLOGY CO LTD

Information acquisition method, device, electronic device and storage medium

Embodiments of the present invention are applicable to the field of computer technology and provide an information acquisition method, device, electronic device, and storage medium, wherein the information acquisition method includes: upon obtaining a first access request for a set path, sending an identity authentication response to the sender of the first access request, wherein the identity authentication response is in the form of: a query / response identity authentication protocol NTLM authentication invitation; obtaining an NTLM authentication request initiated by the sender based on the NTLM authentication invitation; and obtaining the sender's identity information based on the NTLM authentication request.
Owner:SANGFOR TECH INC

Anonymity and fast identity authentication method for internet of vehicles based on double-chain architecture and national secret algorithm

The application claims a kind of anonymous fast identity authentication method for Internet of Vehicles based on double-chain architecture and national secret algorithm, comprising: constructing double-chain system, building system operation framework, including cloud chain, dynamic chain and in-vehicle TEE trusted environment;Initialization system, initialize system parameters, including cryptography curve selection, etc.;Real-name registration, vehicle submits its real identity information to cloud chain for registration, and obtains exclusive digital certificate after success;Pseudonym generation and registration of vehicle, vehicle first generates pseudonym Token locally, then calls the certificate and Token as parameters to call the evidence chain smart contract for anonymous identity registration;Anonymous fast authentication between vehicles, based on dynamic chain between vehicles, anonymous fast authentication between vehicles is realized through pseudonym Token and DH secret key negotiation algorithm.The application is based on double-chain architecture and national secret algorithm, and the evidence chain constructs vehicle node real information network, responsible for the real information trace of malicious node;Dynamic chain provides efficient two-way authentication protocol support between vehicles.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Device authentication through proxy

A software-based authentication protocol enables a client to be authenticated by a server through a host. The authentication protocol involves using mutable authentication data that changes to deter counterfeiters from making clones of authentic clients. The host requests a token from the client as proof of authenticity. The client establishes a communication channel to the server using the host as a communication proxy. The client presents mutable authentication data to the server. If the server determines that the mutable authentication data is outdated, then the client is deemed a counterfeit. If the server determined that the mutable authentication data is the latest version, then the client is deemed authentic and a token is issued to the client. Depending on a set of policies, the server changes the mutable authentication data and sends the new mutable authentication data to the client but not to counterfeit clients.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems and methods for orchestrating web authentication requests

In one embodiment, a method uses a web browser to receive an authentication request for an application from an authentication prompt of a client device. The method identifies an authentication protocol associated with web browser of the client device and use the authentication prompt to fetch a first challenge from an authentication service associated with the client device. The method uses the authentication prompt to communicate a subscribe to the authentication service and use a localhost to communicate to the application to provide the first challenge. In response to receiving the first challenge, the method uses one or more native Application Programming Interfaces (APIs) to determine an assertion associated with the authentication request and the authentication protocol. The method validates the assertion associated with the authentication request. In response to determining the assertion is valid, the method approves the authentication request.
Owner:CISCO TECHNOLOGY INC

Establishing trust for external devices

Methods and systems for establishing trust for external partner devices with verifiable credentials are disclosed. Embodiments include verifying, by a device trust issuer, DTI, adherence to a first level of security of a device external to an organization according to one or more security standards; in response to the first level of security being met, issuing, by the DTI, one or more verifiable credentials, VCs, to the external device; writing, by the DTI, the VCs into an electronic ledger; requesting, by the external device, from a Service Owner, SO, within the organization, access to the resources within the organization by: authenticating the external device at the SO using an identity authentication protocol; and providing the VCs to the SO; verifying, by the SO, and based on the VCs provided by that the external device that the DTI is trusted by the SO; in response to the DTI being trusted by the SO, verifying, by the SO based on the VCs, that the first level of security of the external device matches a second level of security required by the SO; and in response to the first level of security matching the second level of security, granting access to the external device to the resources within the organization.
Owner:SIEMENS AG

Method for verifying the setting of predefined safety functions of a field device in process and automation technology

A method for verifying the setting of predefined safety functions (SF1, ..., SFn) of a field device for process and automation technology, wherein the predefined safety functions (SF1, ..., SFn) relate in particular to access to at least one function of the field device by an unauthorized person, wherein the method provides the following steps: - Determining a security level required at the measuring point and / or at the field device, wherein the determined security level defines the target setting of the predefined safety functions (SF1, ..., SFn) of the field device (1), - Identifying a user by means of an authentication protocol (2), - Starting a query about the actual setting of the safety functions (SF1, ..., SFn) of the field device specified at the measuring point by the user (3), - Comparing the actual setting of the predefined safety functions (SF1, ..., SFn) of the field device with the target setting of the specified safety functions (SF1, ..., SFn) defined by the specified safety level (4),- Issuance of an electronic report to the user regarding a conformity or deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device (5),- in the case of conformity between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following step is provided:◯ Storage of the electronic report (6), or- in the case of deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following steps are provided:◯ Proposal of at least one measure to adjust the actual setting of at least one specified safety function (SF1, ..., SFn) of the field device to the target setting (7), whereby at least one measure is shown to the user,◯ Implementation of the at least one proposed measure to adapt the actual setting to the target setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (8),◯ Repetition of the query about the actual setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (3).
Owner:ENDRESS & HAUSER GMBH & CO KG

Devices, systems and methods for optimized, personalized administration of oral dosage forms

This invention provides methods, systems and devices for personal, secure authenticated provision of oral solid dosage forms, administered as a dosage regimen which may be altered over time. The methods and systems rely on providing a device for personal secure administration of oral solid dosage forms to a subject, where the device comprises a plurality of individually addressable oral dosage forms contained therein, wherein a first oral dosage form of the plurality contained therein differs from that of at least a second oral dosage form of the plurality, in terms of an active ingredient type, an active ingredient dosage, or a composition component of said solid oral dosage form, or any combination thereof and wherein the device provides for dispensing at least one individually addressable oral dosage form contained therein following a personal authentication protocol and wherein the device is subject to programming, which programming controls distribution of said oral dosage forms contained therein according to a first secure distribution program and wherein the device comprises a user interface and optionally at least one sensor and wherein subject response data, sensor collected data, or testing result data or any combination thereof is collected and incorporated in the programming; and_whereby the programming controls adjusting, altering or overwriting the first distribution program via a secure protocol to a second distribution program, as a function of the collected subject response data, sensor collected data, or testing result data or any combination thereof and completing an authentication protocol for dispensing the oral dosage form to the subject and dispensing the first oral dosage form within an oral cavity of the subject and following secure communication with an authorized provider,enabling adjustment, alteration or overwriting of the programming to activate the second oral dosage form distribution program in the device; and_dispensing the oral dosage forms of the second oral dosage form distribution program to the subject, whereby an oral dosage form regimen is adjusted, altered or overwritten in the device resulting in altering dispensing of the oral dosage form, by means of a secure authenticated protocol.
Owner:PAZ ILAN +1

Method and system for reliable authentication of the origin of a website

The present invention is enclosed in the area of authentication protocols, in particular web-based authentication protocols for reliably determining the origin of a web content, namely a website, and thereby legitimise / certify such website. It is an object of the present invention a method for reliable authentication of the origin of a website which includes obtaining brand digital information which is digitally associated with the website, wherein the brand digital information comprises a registered trademark and the website has a Uniform Resource Indicator (URI) which is digitally associated to the registered trademark in at least one server of a brand verification system. The solution of the present invention takes a completely different approach with regard to the above referred prior art solutions, as it focusses on a brands digital property, by attributing a self-sovereign identity with which to present itself to its customers / partners, thereby being highly simple and efficient.
Owner:PROOFMARKED INC

User right and interest level management method and device, electronic equipment and program product

The invention discloses a user right level management method and device, electronic equipment and a program product, and relates to the technical field of block chains. The method comprises the steps that after user task completion state data is obtained through a task authentication module, authentication is carried out based on a right task authentication protocol of secure multi-party calculation, and a task authentication result, an authentication signature and a user task total contribution degree are output; and the smart contract receives the task authentication result, aggregates the block chain historical task authentication result according to a preset data structure, generates an updated aggregation result and stores the updated aggregation result on the block chain, thereby providing a reliable data basis for subsequent user right level adjustment. According to the method and the device, the security of task authentication and the data credibility are effectively improved, the tampering resistance of the user right data is ensured, the user privacy is further protected, the accuracy and the adaptability of user right management are improved, and the use experience of the user is improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Systems and methods for controlling access to media assets using two-factor authentication

ActiveUS12671864B2User deviceInternet privacy
Systems and methods for authorizing operations associated with blocked media assets using two-factor authentication. In some aspects, a media guidance application (e.g., executed by a set-top box or other user equipment used to store and display media assets) prompts a user for a password (e.g., a personal information number) in order to unlock the content for viewing. In response to receiving a second request from the user to perform an operation related to the media asset (e.g., delete), the media guidance application prompts the user for an additional factor confirming his or her identity, consistent with two-factor authentication protocol. If the user's identity is authenticated as a user that has authority to perform the operation related to the media asset (e.g., delete the stored media asset), the media guidance application performs the operation related to the media asset (e.g., deletes the media asset).
Owner:ADEIA GUIDES INC

Security authentication and intelligent matching method and application based on block chain technology

The invention discloses a security authentication and intelligent matching method and application based on a block chain technology, security authentication adopts a distributed authentication protocol fusing an elliptic curve digital signature and a PBFT consensus mechanism, and the protocol generates a unique identity through an ECC key. Identity authentication, data integrity guarantee and non-repudiation are realized in combination with an SHA-256 hash abstract and an ECDSA signature, and an authentication process completes consensus through four stages of requesting, pre-preparing, preparing and submitting; intelligent matching adopts a matching mechanism based on KNN algorithm and intelligent contract cooperation, the matching similarity is calculated by constructing a multi-dimensional feature vector and adopting a weighted Euclidean distance method and a weighted cosine similarity method, and formalized matching conditions are defined in a contract layer of the block chain; according to the method, security authentication and an intelligent matching algorithm are integrated, a credible matching process scheme suitable for a recruitment scene is provided, and an algorithm path is provided for solving the problems that the identity is not real and talents are difficult to find.
Owner:GUIZHOU UNIV

An authentication protocol

The present disclosure relates to a method of establishing a secure channel between at least two clients which comprises, at an initiating client: retrieving an initiating challenge-response pair and sending a first message which comprises the initiating challenge; at the responding client: isolating the initiating challenge from the received first message and stimulating the PUF of the responding client with the isolated initiating challenge to obtain the first PUF response; at the responding client: retrieving a responding challenge-response pair, generating a shared key from the responding response and the PUF response, and transferring a second message which comprises the responding challenge to the initiating client; and at the initiating client: isolating the responding challenge from the received second message, stimulating the PUF of the initiating client with the responding challenge to obtain a second PUF response, and generating the shared key from the second PUF response and the initiating response.
Owner:FORTAEGIS TECHNOLOGIES HOLDING BV

Artificial intelligence server secure interaction method, device, equipment and medium

The invention discloses an artificial intelligence server security interaction method, device and equipment and a medium, which can be applied to the financial and medical fields. According to the method, when a request is initiated at an artificial intelligence server through a gateway system, the validity of an access credential of the request is intercepted and verified, and it is ensured that only the authorized request can enter a back-end server. For a request with invalid credentials, the system can guide the agent to obtain valid access credentials according to a preset authentication protocol. And a pre-established encryption security tunnel is adopted to safely forward the verified request to a back-end server isolated from the public network, so that the data security and integrity in the transmission process are ensured. And the response information of the back-end server is verified and encrypted through the gateway system and then is safely returned to the artificial intelligence server, so that a complete secure interaction link is formed. The reliability of access control and identity verification is enhanced, encryption protection of data in the transmission process is ensured, and therefore the safety of integrated application of the artificial intelligence server side and the back-end server is remarkably improved.
Owner:PING AN TECH (SHENZHEN) CO LTD