Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

45 results about "Authentication scheme" patented technology

Authentication Schemes. Authentication schemes provide a way to collect credentials and determine the identity of a user. During authentication, Web Agents communicate with the Policy Server to determine the proper credentials that must be retrieved from a user who is requesting resources.

Security key generation and authentication method based on microfluidic DNA detection

The invention discloses a micro-fluidic DNA detection-based security key generation and authentication method, which comprises the following steps: S1, carrying out DNA detection on a biological sample through a micro-fluidic chip to obtain SNP and STR feature data; s2, performing unified coding on the SNP and STR feature data to form stable bit string representation; s3, processing the bit string representation by using a fuzzy extraction mechanism, and generating a consistent key material under the condition of permitting a detection error; s4, deriving a final symmetric key from the key material by using a key derivation function; and S5, performing security packaging, transmission and authentication on the final symmetric key by adopting a post-quantum cryptography mechanism. According to the security key generation and authentication method based on microfluidic DNA detection, a set of key generation and identity authentication scheme with instantaneity, high specificity and anti-quantum security is constructed.
Owner:GUANGDONG UNIV OF TECH

Cloud distributed node identity authentication method based on identity identification certificate

The invention discloses a cloud distributed node identity authentication method based on an identity label certificate, and aims to solve the problems of single-point failure, difficulty in cross-domain mutual recognition, efficiency and privacy imbalance and the like of a traditional authentication scheme. The system is composed of an identity identification certificate generator, a distributed certificate verification network and a block chain certificate account book, a master key is split through threshold secret sharing, the overhead is optimized through BLS signature aggregation, state consistency is guaranteed in combination with DHT and gossip protocols, and certificate full-life-cycle management is achieved through block chain certificate storage and an intelligent contract. The process includes system initialization, identity registration and certificate issuing, identity authentication and certificate updating and revocation, technologies such as elliptic curve cryptography and zero-knowledge proof are adopted, and security, efficiency and privacy protection are considered. The method is suitable for multiple scenes such as a power grid and the Internet of Things, supports cross-domain mutual recognition and dynamic capacity expansion, can effectively prevent illegal access and data tampering, and is suitable for large-scale cloud distributed node identity authentication.
Owner:GUANGXI POWER GRID CORP

A multi-dimensional multiple access and lightweight continuous authentication combined design system

The application discloses a kind of multi-dimensional multiple access and lightweight continuous authentication combined design system.The combined design system is based on non-orthogonal multiple access technology, explores multiple domains of device access, describes the access time sequence of multiple users, sub-channel and power allocation as a joint optimization problem, improves the communication performance of system while guaranteeing the continuous identity authentication of multiple devices.The system uses the unique access time sequence and channel generated by the user in advance to realize the simultaneous verification of multiple users at the base station end;While guaranteeing the continuous authentication of multiple users, the communication performance of the system is improved by optimizing their channel and power allocation.The system provides a fast network access and continuous authentication scheme for devices, which can be widely applied in wireless communication scenarios.
Owner:SUZHOU UNIV

Secure jtag authentication method, chip and electronic device

This disclosure provides a secure JTAG authentication method, chip, and electronic device, belonging to the field of chip debugging technology. The secure JTAG authentication method includes: obtaining an image configuration file corresponding to the bootloader during the execution of a bootloader by the processor in the chip; performing security verification on the image configuration file, and sending a JTAG interface enable command to a debugging module based on the JTAG interface enable flag contained in the image configuration file after successful verification; receiving the JTAG interface enable command through the debugging module in the chip, and configuring a first interface enable register inside the debugging module according to the JTAG interface enable command to control the JTAG interface to be in a debuggable state. The secure JTAG authentication scheme provided by this disclosure combines software and hardware, balancing flexibility and security during chip testing and debugging.
Owner:BEIJING YOUZHUJU NETWORK TECH CO LTD

Distributed gateway identity cross-trust methods, systems, and related devices

ActiveCN121262018BUser identity/authority verificationEngineeringPublic key certificate
The application relates to a distributed gateway identity mutual trust method, system and related equipment. The method comprises the following steps: a first gateway node sends a registration request containing a digital certificate and an agency code to a second gateway node; the second gateway node generates and returns a registration response containing a public key certificate and a security policy template in response to the registration request; the first gateway node verifies the validity of the public key certificate and audits whether the security policy template meets a preset security policy; if the audit is passed, the first gateway node signs a mutual trust protocol and sends the signed mutual trust protocol to the second gateway node; after verifying the validity of the signature, the second gateway node establishes and stores a trust record with the first gateway node, completes the trust establishment between the gateways, solves the technical problem that the cross-domain identity authentication scheme in the prior art generally depends on a unified identity authentication center and has a single-point failure risk, and achieves the technical effect of realizing safe and reliable cross-domain identity mutual trust.
Owner:BEIJING EETRUST TECH CO LTD

NFC label anti-counterfeiting authentication method applied to intelligent household electrical appliance

The invention relates to the field of intelligent products, discloses an NFC label anti-counterfeiting authentication method applied to an intelligent household appliance, and solves the problems that an existing NFC label anti-counterfeiting authentication scheme is tedious in implementation process and high in development difficulty. According to the method, the non-repeated KEYs are generated at the cloud in batches and written into the PC end test software, the PC end test software packs the read UID of the NFC label and the selected KEYs into common data and writes the common data into the NFC label, in a user use scene, the mobile terminal supporting the NFC function touches the NFC label to read the UID and the packed data, and the user experience is improved. The method comprises the steps of reading a UID, performing preliminary verification based on the read UID and a UID analyzed from packet data, and uploading an analyzed key KEY to a cloud for re-verification after the preliminary verification is passed, so that the key generation and write-in process is simplified without an encryption algorithm, the UID cannot be duplicated, the cloud key management is utilized, and the encryption algorithm is not needed, and the key generation and write-in process is simplified, so that the key generation and write-in process is simplified, and the key generation and write-in process is simplified. Precise identification of the copy paste and the pirate paste of the NFC label is realized, and NFC label anti-counterfeiting authentication with low development difficulty and high anti-counterfeiting reliability is achieved.
Owner:SICHUAN CHANGHONG AIR CONDITIONER CO LTD

A data cross-domain access control method and system

The application provides a data cross-domain access control method and system, relates to the industrial internet, cross-domain access control, data protection, and in particular to a data cross-domain access control method based on the industrial internet. By using machine learning technology and an access control idea based on attribute encryption, a rule mapping mechanism and a cross-domain encryption mechanism are designed, and data cross-domain access control suitable for a large-scale dynamic industrial internet environment is realized. A cross-domain registration and authentication scheme is provided for legality authentication of a cross-domain request process, a rule mapping scheme is provided for cross-domain rule mapping by using NLP technology, a security basis is provided for data cross-domain, and a cross-domain encryption scheme is provided for optimizing CP-ABE to realize multi-permission traceable cross-domain data encryption and decryption.
Owner:GUANGZHOU UNIVERSITY

Identity verification systems and methods

Various embodiments herein each include at least one of systems, methods, and software for identity verification. Some such embodiments identify a user based on analysis of their handwriting. Some such embodiments may be utilized to authenticate an individual, for emergency authentication or when other authentication solutions are not available, as one of a two or more step authentication process, authenticating checks, authenticating a signature or other handwriting on another document, and the like. One embodiment, in the form of a method, includes storing a set of handwriting characteristics of an individual identified during processing of a plurality of handwriting samples of the individual. The method may then determine whether an input handwriting sample is handwriting of the individual based on the stored set of handwriting characteristics of the individual and then output a result of the determining.
Owner:NCR ATLEOS CORP

Node management method and device based on credibility measurement, equipment and storage medium

ActiveCN116437338BEngineeringAuthentication scheme
This invention provides a node management method, apparatus, device, and storage medium based on trust metrics. The method includes: determining a target description vector for a sensing node to be managed; determining a target trust metric for the sensing node to be managed based on the target description vector; and performing trust group management on the sensing node to be managed according to the target trust metric to obtain a group management result. This invention, by modeling 5G IoT sensing nodes and combining multi-dimensional attribute metrics and a trust-based hierarchical grouping strategy, obtains a set of trustworthy remote authentication schemes adapted to 5G IoT.
Owner:BEIJING UNIV OF TECH

Local device authentication system

Various embodiments are generally directed to provide a semi-local authentication scheme. A server can transmit one or more encryption mechanisms to a user device, which in turn can transmit the encrypted mechanisms to one or more secondary devices associated with the user device, where the user device and the secondary devices share a local connection. The secondary devices can transmit the one or more encrypted mechanism utilizing one or more one or more decryption mechanisms supplied by the server, and then transmit the result of the decryption, e.g. decrypted codes, back to the user device, which in turn can then transmit a final decrypted code or codes to the server. Upon confirming receipt of the decryption from the user device, the server can authorize access (via the user device) to one or more devices, networks, applications, and / or components.
Owner:CAPITAL ONE SERVICES LLC

Adaptive authentication method based on Beidou third-generation navigation satellite message

The invention discloses a self-adaptive authentication method based on a Beidou third-generation navigation satellite message, which comprises the following steps that: a control center encrypts a navigation message and uploads the encrypted navigation message to a Beidou satellite, the Beidou satellite broadcasts the encrypted navigation message, a receiver updates a public key based on a digital certificate, and the receiver sends the updated public key to the Beidou satellite. And on the basis, the received encrypted navigation message is authenticated, and whether the navigation message has integrity and authenticity is judged. According to the scheme of the invention, a switchable authentication scheme is provided based on the transmission characteristics of the D1 navigation message and the D2 navigation message aiming at the navigation message characteristics of the Beidou third-generation navigation system, so that the security requirements of receivers with different performances on resisting navigation spoofing attacks are met; meanwhile, signature authentication, TESLA key authentication and MAC authentication are adopted, so that the non-repudiation, coherence and integrity of ciphertext information are ensured, a receiver is ensured to quickly and efficiently complete navigation message authentication work, and normal navigation message resolving work is not influenced.
Owner:THE 724TH RESEARCH INSTITUTE OF CHINA STATE SHIPBUILDING CORP LTD

Revocable Internet of Vehicles authentication method based on alliance chain

The invention discloses a revocable Internet of Vehicles authentication method based on an alliance chain. The method comprises the following steps: initializing a system to establish a trust basis; the vehicle and road side unit registers to a trusted mechanism, the pseudo identity and PUF information are subjected to uplink storage, and an intelligent contract is deployed; after the vehicle initiates authentication, the road side unit verifies information from the chain and generates a new pseudo identity and a PUF challenge value; the vehicle generates a PUF response based on the challenge and calculates a session key, and the road side unit calls an on-chain contract to verify the response, completes bidirectional authentication and updates an on-chain identity state; and if the malicious vehicle is detected, the road side unit submits the chain revocation transaction, and the whole network refuses the authentication after consensus synchronization. According to the invention, a lightweight password technology, a physical unclonable function, an alliance block chain distributed account book and a dynamic identity management mechanism are integrated to construct an Internet of Vehicles authentication scheme considering high efficiency, safety, reliability and privacy protection, and effective support is provided for safe and reliable operation of an intelligent traffic system.
Owner:ANQING NORMAL UNIV

User identity authentication scheme based on acoustic signal

According to the user identity authentication scheme based on the acoustic signal, the defects of an existing identity authentication method are overcome, additional intelligent hardware does not need to be deployed, and high-safety and high-precision identity authentication can be achieved only on the basis of existing hardware. Meanwhile, the method is not influenced by factors such as environment and equipment conditions, and has good transportability. The method is realized by utilizing a special ultrasonic signal which cannot be heard by ordinary people, the normal life of the user is not influenced during operation, and the method can be naturally integrated into the life of the user. The method comprises the following steps: firstly, capturing a special ultrasonic signal sent by a loudspeaker and reflected by the face of a user name; then measuring the distances from different face areas to the microphone and the loudspeaker; compensating energy and phase information of different distances according to a range adaptive algorithm; and finally, carrying out identity recognition by utilizing distance and energy characteristics.
Owner:山东汇金股份有限公司 +2

Biological characteristic authentication method and system based on category perception

The invention provides a biological feature authentication method and system based on category awareness, the system comprises a server and a client, after the client receives an authentication request, the client synchronously collects a to-be-authenticated palm vein image and a to-be-authenticated heart rate signal of a user, generates a multi-modal fusion feature, and sends the multi-modal fusion feature to the server; in combination with a local category distribution compensation prompt vector and the optimized discriminative activity prompt vector, constructing a target sequence, and inputting the target sequence into a multi-modal biological feature authentication model to obtain an authentication result of the user; wherein the category distribution compensation prompt vector is obtained by training a global distribution reference and a local multi-modal fusion feature sample, and the global distribution reference is generated by aggregating a plurality of client sample statistics by a server; the discriminative activity prompt vector is obtained by updating a global enhancement prompt vector issued by the client based on the server, and the global enhancement prompt vector is obtained by optimizing trained discriminative activity prompt vectors of a plurality of clients by the server. Therefore, a privacy-friendly authentication scheme adaptive to multiple scenes and multiple devices is realized.
Owner:ZKTECO CO LTD

MIMO system equipment identity authentication method based on mutual coupling and spatial AoA

The invention belongs to the technical field of wireless communication security, and discloses an MIMO system equipment identity authentication method based on mutual coupling and spatial AoA, which is realized through the following steps: a transmitting end communicates with a receiving end, an uplink millimeter wave channel is constructed, a communication model with a bimodal characteristic is established, namely, a signal is received, and the signal is transmitted to the receiving end; the communication model comprises a mutual coupling fingerprint model and an AoA fingerprint statistical model, and the mutual coupling fingerprint model comprises a transmitting array mutual coupling matrix and a receiving array mutual coupling matrix; a multi-signal classification algorithm based on a feature space is adopted to extract MC features and an AoA value of a communication model, a receiving end judges whether a current received signal is from legal equipment or an attacker based on the extracted MC features and the extracted AoA value, and authentication is completed. According to the method, a hardware-level MC effect and space arrival angle characteristics are combined, an efficient and high-robustness bimodal physical layer authentication scheme is provided, and a new solution is provided for a future 6G high-security scene.
Owner:NANJING UNIV OF POSTS & TELECOMM

Lightweight encryption and integrity verification method for sensing layer data of Internet of Things

The invention relates to the technical field of Internet of Things security protection, and particularly discloses an Internet of Things perception layer data lightweight encryption and integrity verification method, which abstracts a whole original data object into a unique and compact cryptographic commitment, and securely transmits the same to a receiver through one lightweight commitment handshake. And a trust anchor point which cannot be tampered is established. And then, in a data distribution stage, each data fragment is bound with the corresponding proof path which can be independently verified for transmission. This decouples the overall integrity verification of the application layer from the physical fragmentation mechanism of the network layer. The receiver can verify each arriving fragment based on the pre-established trust anchor point, thereby overcoming the vulnerability that the fragment mode after traditional overall authentication needs overall retransmission due to single-point failure. And meanwhile, the security defects of huge authentication overhead and incapability of defending fragment recombination attacks caused by a one-by-one authentication scheme after fragmentation are also avoided.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Certificateless weighted multi-identity cross-domain authentication scheme combined with block chain

The invention discloses a certificateless weighted multi-identity cross-domain authentication scheme combined with a block chain, and aims to solve the problem that the existing related technology is difficult to adapt to diversified authentication of a complex Internet of Things environment. According to the method, a certificateless weighted cross-domain authentication scheme is designed by considering the multi-identity characteristics of cross-domain users and the credible weight difference of different identities. According to the scheme, a distributed block chain structure is adopted, and the non-tampering performance and the synchronization reliability of parameters are guaranteed; through cooperation of a threshold signature algorithm and a certificateless signature algorithm, the overall security of the system is maintained, and the third-party key escrow risk is thoroughly avoided. Besides, the digital signature protocol integrated with the identity weight is designed to realize differential authentication, the user with higher credible weight only needs less part of identity information to complete authentication of the user with low weight, and the efficiency is greatly improved. According to the invention, the security, reliability and flexibility of cross-domain authentication are enhanced, specific scene requirements of the Internet of Things are adapted, and an efficient solution is provided.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Identity authentication method, device and system, electronic equipment and storage medium

The invention provides an identity authentication method, device and system, electronic equipment and a storage medium, and belongs to the technical field of communication security, the method is applied to a security gateway, and the method comprises the following steps: receiving an intranet access request sent by a user terminal; the intranet access request comprises a trusted authentication mobile phone number and encrypted data; the encrypted data comprises a digital signature; and performing verification processing on the digital signature based on the credible authentication mobile phone number, and releasing the intranet access request under the condition that the verification processing is passed. According to the application, the security gateway verifies and signs the digital signature of the encrypted data determined based on the super SIM card of the user terminal based on the trusted authentication mobile phone number of the intranet access request, and an identity authentication scheme that access hotspot equipment and a hotspot sharer can be distinguished under the condition of hotspot sharing is realized.
Owner:CHINA MOBILE COMM GRP CO LTD +1

Identity authentication control method and system for power monitoring system based on anti-quantum cryptography

The application provides an anti-quantum-cipher-based power monitoring system identity authentication control method and system, and belongs to the technical field of authentication control, which comprises the following steps: step 1, initializing the anti-quantum-cipher-based power monitoring system identity authentication control system; step 2, the anti-quantum-cipher-based power monitoring system identity authentication control system registers the edge terminal device; and step 3, the anti-quantum-cipher-based power monitoring system identity authentication control system performs two-way identity authentication and key negotiation. The application aims to overcome the defects of the existing anti-quantum-cipher-based power monitoring system identity authentication scheme in performance adaptation, key security, authentication robustness and system compatibility, and provides an identity authentication control method and system meeting the high security, low delay and high reliability requirements of the power monitoring system.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

Combination of challenge-response pair mechanisms for multi-factor authentication schemes protecting private keys

Protocols for providing multi-factor authentication to secure private encryption keys for an asymmetrical encryption algorithm are disclosed. According to the method, a user device is in possession of multiple CRP generation factors, which may include a physical addressable PUF array, a biometric print, a virtual token derived from a digital file, and a sensor-based PUF. The user device builds a combined reference table of responses from two or more of its factors, and derives an ephemeral key from the table used to encrypt a secret key. The terminal device may decrypt the key despite loss of the physical addressable PUF.
Owner:ARIZONA BOARD OF REGENTS ACTING FOR & ON BEHALF OF NORTHERN ARIZONA UNIV

Browser-based authentication scheme

Disclosed herein is a method performed by a client application of an authentication provider application. The method includes deriving a reference to a domain name based on an identity handle of a user, querying a domain name system to obtain one or more identity records associated with the identity handle, obtaining one or more public keys based on the one or more identity records, and deriving an authentication endpoint web address based on the identity handle. The authentication endpoint web address is usable to access the authentication provider application. The method further includes sending data to the authentication provider application using the authentication endpoint web address, wherein the authentication provider application is able to access one or more private keys corresponding to the one or more public keys for generating digital signatures. The method further includes receiving, from the authentication provider application, one or more digital signatures.
Owner:SHORE LABS ZBIGNIEW ZEMLA

Request verification method and device, equipment, storage medium and computer program product

The invention discloses a request verification method and device, equipment, a storage medium and a computer program product, which are used for solving the problems that the existing real-name system authentication scheme is single in verification dimension, so that a protection system is fragile, association analysis and complex mode recognition capabilities are lacked, and the verification efficiency is high. And therefore, complex attack modes such as gang fraud and cross-account collaborative crime cannot be effectively identified and intercepted. The method comprises the steps of determining an initial risk portrait corresponding to a to-be-authenticated request according to acquired environment data and behavior data of a user corresponding to the to-be-authenticated request; determining a multi-dimensional cross validation strategy according to the initial risk portrait, and performing multi-dimensional cross validation on the to-be-authenticated request according to the multi-dimensional cross validation strategy to obtain a cross validation result; based on a pre-constructed risk knowledge graph, performing association analysis on the to-be-authenticated request to obtain an association analysis result; and determining a final verification result for the to-be-authenticated request according to the cross verification result and the correlation analysis result.
Owner:CHINA MOBILE ZHIJIE TECHNOLOGY (BEIJING) CO LTD +1

Massive MIMO communication system physical layer authentication method

The invention provides a physical layer authentication method for a massive MIMO communication system. The method comprises the following steps: an expected receiver determines a test statistic Lx used for evaluating channel state information difference between adjacent time intervals through a log-likelihood ratio; and when the sender is the legal user equipment and assumed H0, when the sender is the attacker and assumed H1, and when Lx is smaller than or equal to a threshold value delta, the expected receiver accepts the assumed H0 and judges that the sender is the legal user equipment, otherwise, the expected receiver accepts the assumed H1 and judges that the sender is the attacker. According to the authentication scheme, modeling is carried out on a channel in a massive MIMO antenna communication scene, and the influence of antenna coupling, antenna space correlation and the like caused by antenna element spacing reduction and antenna data increase on the physical layer authentication performance is measured. And the PCA and the SVD are used for carrying out spatial domain and frequency domain decorrelation on the high-dimensional channel information, so that the storage space occupied by the channel information at a base station end can be reduced, and the authentication overhead is greatly reduced under the condition that the same authentication performance is ensured.
Owner:BEIJING RES INST OF TELEMETRY

Vehicle identity authentication scheme and reputation evaluation method and system based on multi-access edge calculation

The invention provides a vehicle identity authentication scheme based on multi-access edge computing and a reputation evaluation method and system, and relates to the technical field of communication. The method comprises the following steps: firstly, selecting a random number by using CA to generate a system main private key and a main public key, issuing system parameters, then registering a roadside unit, a multi-edge access node server and an automobile based on the system main private key, the main public key and the system parameters, performing reputation evaluation on the roadside unit and the automobile by the multi-edge access node server, and performing reputation evaluation on the roadside unit and the automobile. When a vehicle sends a path request to the multi-edge access node server, the multi-edge access node system server verifies a vehicle reputation value, when the vehicle reputation value is higher than a threshold value, a path planning service is provided for the vehicle, a road side unit list is generated, and a vehicle pseudonym and the road side unit list are sent to a CA; and the auxiliary vehicle and the road side unit perform bidirectional verification. According to the invention, the identity authentication security and the node credibility evaluation capability are effectively improved.
Owner:BEIJING ELECTRONICS SCI & TECH INST

A lightweight physical layer authentication method based on bilstm-linformer

This invention presents a lightweight physical layer authentication method based on BiLSTM-Linformer. It addresses the decline in model adaptability caused by the complex time-varying nature of CSI data in dynamic environments by proposing a data augmentation method based on temporal interpolation and contrastive learning, a dimensionality reduction method combining PCA and shallow autoencoders, and a lightweight authentication scheme centered on BiLSTM and multi-head self-attention mechanisms. The scheme first uses temporal interpolation to augment CSI data, enhancing temporal continuity, and combines contrastive learning to optimize the model's discriminative ability, improving adaptability to mobile environments. Subsequently, PCA and shallow autoencoders are used for feature dimensionality reduction, reducing computational burden while preserving key CSI patterns and improving authentication efficiency. Finally, BiLSTM is introduced for temporal modeling, and a multi-head self-attention mechanism is combined to optimize temporal feature weight allocation, enabling the model to focus on key changes in CSI data, further improving authentication accuracy and robustness. Experimental results show that the proposed authentication scheme achieves an authentication stability score of 0.95 in dynamic environments, an improvement of approximately 27% compared to existing methods.
Owner:SICHUAN GREAT WALL COMPUTER SYST CO LTD

Authentication scheme for providing software updates to an update agent

A method, an update agent and an off-card entity are provided for implementing an authentication scheme for providing a software image to a secure element. An installation package includes a package binding function for linking the installation package to the secure element, a manifest, a manifest signature generated using a block-cipher algorithm, and a software image is received at an update agent within the secure element. The update agent implements an authentication and integrity scheme by verifying various signatures contained within the installation package and installing the software image in case of successful authentication and integrity verification.
Owner:GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH

Lightweight network authentication for resource constrained devices via mergeable stateful signatures

Signature-based authentication is a core cryptographic primitive essential for most secure networking protocols. A new signature scheme, MSS, allows a client to efficiently authenticate herself to a server. The new scheme is modeled in an offline / online model where client online time is premium. The offline component derives basis signatures that are then composed based on the data being signed to provide signatures efficiently and securely during run-time. MSS requires the server to maintain state and is suitable for applications where a device has long-term associations with the server. MSS allows direct comparison to hash chains-based authentication schemes used in similar settings, and is relevant to resource-constrained devices, e.g., IoT. MSS instantiations are derived for two cryptographic families, assuming the hardness of RSA and decisional Diffie-Hellman (DDH) respectively. Then used is the new scheme to design an efficient time-based one-time password (TOTP) protocol.
Owner:RGT UNIV OF CALIFORNIA

Smart packaging digital human multi-modal interaction system and method based on NFC triggering

This invention discloses an NFC-triggered smart packaging digital human multimodal interaction system and method, belonging to the field of smart packaging and human-computer interaction technology. The system includes an NFC triggering unit, a context parsing unit, a multimodal interaction unit, a digital human rendering unit, an AR immersive experience unit, an intelligent decision-making unit, and a synchronization control unit. The system stores structured context data through an NFC chip. When a user device approaches the packaging, a communication connection is automatically established, context information is parsed, the digital human model is activated, and an AR immersive scene is constructed, realizing audio-driven facial animation technology, multimodal interaction, and synchronization control. This invention is specifically designed for smart packaging scenarios, differing from general digital human interaction systems and general authentication schemes. It solves the technical problems of traditional smart packaging, such as single interaction, long activation time, fragmented user experience, and insufficient privacy compliance. It achieves a time of ≤2.7 seconds from NFC triggering to system activation, lip-sync accuracy of ≤100ms, and interaction response time of ≤1.8 seconds, and can be applied to scenarios such as product culture explanation and brand marketing.
Owner:HUZHOU HEPIN NETWORK TECHNOLOGY CO LTD

Data security access and sharing system based on block chain and attribute signature

The invention belongs to the technical field of medical data sharing, and discloses a block chain and attribute signature-based data security access and sharing system, which comprises a distributed identity authentication module, a privacy set intersection module and an algorithm module, and the distributed identity authentication module is used for providing a block chain-based distributed identity authentication scheme with an attribute signature. Through a distributed identity authentication system, the cross-mechanism identity mutual recognition efficiency is improved, and through application of DID registration and VP verification, the problem of repeated authentication in a medical scene can be solved, and technical support is provided for medical reform such as hierarchical diagnosis and treatment; synchronous verification of identities and permissions is realized through an improved attribute signature algorithm, so that medical data security access control is enhanced; in addition, the blockchain enabled privacy set intersection scheme eliminates the dependence of the cloud server, and ensures that the computing process is not tampered through the smart contract, so that the privacy computing credibility can be effectively improved.
Owner:BEIJING INFORMATION SCI & TECH UNIV +1

Function execution apparatus, computer program for function execution apparatus, and method executed by function execution apparatus

To provide a new technique for making a function execution device execute a specific function according to a predetermined authentication system using a pair of keys.SOLUTION: In a case of accepting an input of the specific account information, send a first authentication request to the server and receive first verification information from the server; In a case where the authentication of the target user is successful and the first verification information is received from the server, the function execution apparatus acquires the first signature information, transmits the first signature information to the server, and receives the first function execution instruction from the server. The function execution apparatus transmits a second authentication request including predetermined information to the server without receiving an input of the account information, and receives second verification information from the server. In a case where the authentication of the target user is successful and the second verification information is received from the server, the function execution apparatus acquires the second signature information, transmits the second signature information to the server, and receives the second function execution instruction from the server.SELECTED DRAWING: Figure 6
Owner:BROTHER KOGYO KK