Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

78 results about "Authentication scheme" patented technology

Authentication Schemes. Authentication schemes provide a way to collect credentials and determine the identity of a user. During authentication, Web Agents communicate with the Policy Server to determine the proper credentials that must be retrieved from a user who is requesting resources.

Security key generation and authentication method based on microfluidic DNA detection

The invention discloses a micro-fluidic DNA detection-based security key generation and authentication method, which comprises the following steps: S1, carrying out DNA detection on a biological sample through a micro-fluidic chip to obtain SNP and STR feature data; s2, performing unified coding on the SNP and STR feature data to form stable bit string representation; s3, processing the bit string representation by using a fuzzy extraction mechanism, and generating a consistent key material under the condition of permitting a detection error; s4, deriving a final symmetric key from the key material by using a key derivation function; and S5, performing security packaging, transmission and authentication on the final symmetric key by adopting a post-quantum cryptography mechanism. According to the security key generation and authentication method based on microfluidic DNA detection, a set of key generation and identity authentication scheme with instantaneity, high specificity and anti-quantum security is constructed.
Owner:GUANGDONG UNIV OF TECH

Cloud distributed node identity authentication method based on identity identification certificate

The invention discloses a cloud distributed node identity authentication method based on an identity label certificate, and aims to solve the problems of single-point failure, difficulty in cross-domain mutual recognition, efficiency and privacy imbalance and the like of a traditional authentication scheme. The system is composed of an identity identification certificate generator, a distributed certificate verification network and a block chain certificate account book, a master key is split through threshold secret sharing, the overhead is optimized through BLS signature aggregation, state consistency is guaranteed in combination with DHT and gossip protocols, and certificate full-life-cycle management is achieved through block chain certificate storage and an intelligent contract. The process includes system initialization, identity registration and certificate issuing, identity authentication and certificate updating and revocation, technologies such as elliptic curve cryptography and zero-knowledge proof are adopted, and security, efficiency and privacy protection are considered. The method is suitable for multiple scenes such as a power grid and the Internet of Things, supports cross-domain mutual recognition and dynamic capacity expansion, can effectively prevent illegal access and data tampering, and is suitable for large-scale cloud distributed node identity authentication.
Owner:GUANGXI POWER GRID CORP

A multi-dimensional multiple access and lightweight continuous authentication combined design system

The application discloses a kind of multi-dimensional multiple access and lightweight continuous authentication combined design system.The combined design system is based on non-orthogonal multiple access technology, explores multiple domains of device access, describes the access time sequence of multiple users, sub-channel and power allocation as a joint optimization problem, improves the communication performance of system while guaranteeing the continuous identity authentication of multiple devices.The system uses the unique access time sequence and channel generated by the user in advance to realize the simultaneous verification of multiple users at the base station end;While guaranteeing the continuous authentication of multiple users, the communication performance of the system is improved by optimizing their channel and power allocation.The system provides a fast network access and continuous authentication scheme for devices, which can be widely applied in wireless communication scenarios.
Owner:SUZHOU UNIV

Equipment authentication method and device based on 5G-A network, equipment and storage medium

The invention provides an equipment authentication method and device based on a 5G-A network, equipment and a storage medium, relates to the technical field of data security, and solves the problem that an authentication scheme in the related technology is difficult to meet the dynamic security requirement of the 5G-A network. And binding is carried out according to the dynamic token and the spatial position of the access equipment to obtain corresponding space-time proof information, so that the space-time proof information obtained from the base station and the actual position of the corresponding access equipment are acquired through the server, and the space-time proof information of the access equipment is obtained based on a dynamic binding mechanism of the dynamic token and the position. According to the technical scheme, dual-source position verification is realized, the dynamic token is anchored through the block chain to verify the dynamic token, the reliability of equipment authentication is improved through dual verification, the credibility of general sensing data is ensured, and the data security in the 5G-A network is effectively improved, so that the dynamic security requirement of the 5G-A network is met.
Owner:GUANGZHOU HANTELE COMM CO LTD

Secure jtag authentication method, chip and electronic device

This disclosure provides a secure JTAG authentication method, chip, and electronic device, belonging to the field of chip debugging technology. The secure JTAG authentication method includes: obtaining an image configuration file corresponding to the bootloader during the execution of a bootloader by the processor in the chip; performing security verification on the image configuration file, and sending a JTAG interface enable command to a debugging module based on the JTAG interface enable flag contained in the image configuration file after successful verification; receiving the JTAG interface enable command through the debugging module in the chip, and configuring a first interface enable register inside the debugging module according to the JTAG interface enable command to control the JTAG interface to be in a debuggable state. The secure JTAG authentication scheme provided by this disclosure combines software and hardware, balancing flexibility and security during chip testing and debugging.
Owner:BEIJING YOUZHUJU NETWORK TECH CO LTD

Equipment authentication method and electronic equipment

The invention provides a device authentication method and an electronic device. In the method, a first electronic device receives an access request sent by a second electronic device, and sends a first authentication request message to the second electronic device. The first electronic device receives first information sent by the second electronic device, wherein the first information is related to the device type of the second electronic device. And the first electronic equipment sends a second authentication request message to the server, the second authentication request message is used for requesting to obtain an equipment credential of the second electronic equipment, and the second request message comprises the first information. And the first electronic equipment receives the equipment credential information of the second electronic equipment sent by the server. And the first electronic equipment performs equipment authentication on the second electronic equipment according to the equipment credential information of the second electronic equipment. Through the scheme, the requirements on the execution environment and the storage space of the second electronic equipment in the equipment authentication process are reduced, a more universal equipment authentication scheme is provided, and the success rate of equipment authentication is improved.
Owner:HUAWEI TECH CO LTD

Distributed gateway identity cross-trust methods, systems, and related devices

The application relates to a distributed gateway identity mutual trust method, system and related equipment. The method comprises the following steps: a first gateway node sends a registration request containing a digital certificate and an agency code to a second gateway node; the second gateway node generates and returns a registration response containing a public key certificate and a security policy template in response to the registration request; the first gateway node verifies the validity of the public key certificate and audits whether the security policy template meets a preset security policy; if the audit is passed, the first gateway node signs a mutual trust protocol and sends the signed mutual trust protocol to the second gateway node; after verifying the validity of the signature, the second gateway node establishes and stores a trust record with the first gateway node, completes the trust establishment between the gateways, solves the technical problem that the cross-domain identity authentication scheme in the prior art generally depends on a unified identity authentication center and has a single-point failure risk, and achieves the technical effect of realizing safe and reliable cross-domain identity mutual trust.
Owner:BEIJING EETRUST TECH CO LTD

NFC label anti-counterfeiting authentication method applied to intelligent household electrical appliance

The invention relates to the field of intelligent products, discloses an NFC label anti-counterfeiting authentication method applied to an intelligent household appliance, and solves the problems that an existing NFC label anti-counterfeiting authentication scheme is tedious in implementation process and high in development difficulty. According to the method, the non-repeated KEYs are generated at the cloud in batches and written into the PC end test software, the PC end test software packs the read UID of the NFC label and the selected KEYs into common data and writes the common data into the NFC label, in a user use scene, the mobile terminal supporting the NFC function touches the NFC label to read the UID and the packed data, and the user experience is improved. The method comprises the steps of reading a UID, performing preliminary verification based on the read UID and a UID analyzed from packet data, and uploading an analyzed key KEY to a cloud for re-verification after the preliminary verification is passed, so that the key generation and write-in process is simplified without an encryption algorithm, the UID cannot be duplicated, the cloud key management is utilized, and the encryption algorithm is not needed, and the key generation and write-in process is simplified, so that the key generation and write-in process is simplified, and the key generation and write-in process is simplified. Precise identification of the copy paste and the pirate paste of the NFC label is realized, and NFC label anti-counterfeiting authentication with low development difficulty and high anti-counterfeiting reliability is achieved.
Owner:SICHUAN CHANGHONG AIR CONDITIONER CO LTD

Electronic tag with infrared remote control, unlocking method thereof and anti-theft system

The present application relates to a kind of electronic tags with infrared remote control with conventional protection function and password protection function and its unlocking method and anti-theft system, including electronic tag body and infrared remote controller, the upper end surface of the shell in the electronic tag body is equipped with infrared remote controller interface and infrared receiving component is equipped in infrared remote controller interface, the lower end surface of the infrared remote controller is equipped with infrared remote controller connector and infrared transmitting component is equipped in infrared remote controller connector, after infrared remote controller connector is inserted into infrared remote controller interface, infrared receiving tube in infrared receiving component and infrared transmitting tube in infrared transmitting component are opposite and the light signal sent by infrared transmitting tube can be received by infrared receiving tube.Optical: one is not only the anti-theft function of the present application with traditional anti-theft tag, also has password unlocking function, prevent illegal unlocking;Two is the present application adopts one-to-one infrared code unlocking, can prevent non-target electronic tag be unlocked by mistake;Three is the present application in password protection, simultaneously, using voltage authentication scheme as the prerequisite of infrared remote control protocol reception, increase the difficulty of cracking, enhance the protection.
Owner:HANGZHOU CENTURY CO LTD

A data cross-domain access control method and system

The application provides a data cross-domain access control method and system, relates to the industrial internet, cross-domain access control, data protection, and in particular to a data cross-domain access control method based on the industrial internet. By using machine learning technology and an access control idea based on attribute encryption, a rule mapping mechanism and a cross-domain encryption mechanism are designed, and data cross-domain access control suitable for a large-scale dynamic industrial internet environment is realized. A cross-domain registration and authentication scheme is provided for legality authentication of a cross-domain request process, a rule mapping scheme is provided for cross-domain rule mapping by using NLP technology, a security basis is provided for data cross-domain, and a cross-domain encryption scheme is provided for optimizing CP-ABE to realize multi-permission traceable cross-domain data encryption and decryption.
Owner:GUANGZHOU UNIVERSITY

Identity verification systems and methods

Various embodiments herein each include at least one of systems, methods, and software for identity verification. Some such embodiments identify a user based on analysis of their handwriting. Some such embodiments may be utilized to authenticate an individual, for emergency authentication or when other authentication solutions are not available, as one of a two or more step authentication process, authenticating checks, authenticating a signature or other handwriting on another document, and the like. One embodiment, in the form of a method, includes storing a set of handwriting characteristics of an individual identified during processing of a plurality of handwriting samples of the individual. The method may then determine whether an input handwriting sample is handwriting of the individual based on the stored set of handwriting characteristics of the individual and then output a result of the determining.
Owner:NCR ATLEOS CORP

Node management method and device based on credibility measurement, equipment and storage medium

This invention provides a node management method, apparatus, device, and storage medium based on trust metrics. The method includes: determining a target description vector for a sensing node to be managed; determining a target trust metric for the sensing node to be managed based on the target description vector; and performing trust group management on the sensing node to be managed according to the target trust metric to obtain a group management result. This invention, by modeling 5G IoT sensing nodes and combining multi-dimensional attribute metrics and a trust-based hierarchical grouping strategy, obtains a set of trustworthy remote authentication schemes adapted to 5G IoT.
Owner:BEIJING UNIV OF TECH

End-Edge-Cloud Collaborative Security Authentication Method and System for Intelligent Converged Terminals

This invention discloses a terminal-edge-cloud collaborative security authentication method and system for intelligent converged terminals, comprising: a terminal module for acquiring authentication information input at the terminal and sending it to an edge node; an edge node module for querying a corresponding key from the edge node's database based on the identity identifier in the authentication information; if the query result is not empty, authentication is performed based on the query result; if the query result is empty, the authentication information is sent to the cloud; and a cloud module for determining whether the authentication information belongs to a genuine user based on the identity identifier in the authentication information; if it belongs to a genuine user, authentication is performed based on the corresponding key from the cloud's database based on the query result; if it belongs to a non-genuine user, an empty value is returned. This invention proposes a secure terminal-edge node-cloud collaborative authentication scheme for scenarios involving secure identity verification.
Owner:NANJING SIYU ELECTRIC TECH CO LTD

Lightweight authentication method for power internet of things based on puf and chebyshev chaotic mapping

The application discloses a kind of power internet of things lightweight identity authentication method based on PUF and Chebyshev chaotic mapping, the method includes following two parts: registration stage: device and gateway are registered to RS by secure channel to obtain the authentication parameter required;Authentication stage: terminal device and gateway utilize the authentication parameter of registration and carry out two-way identity authentication and negotiate session key for subsequent use.The PUF and Chebyshev chaotic mapping used in the application have high security and less resource consumption compared with traditional identity authentication scheme.The method utilizes PUF to generate challenge-response pair to realize two-way identity authentication and key agreement, without storing any secret information related to authentication in device memory.At the same time, Chebyshev chaotic mapping is used to protect the transmission of challenge-response pair secret information in non-secure channel, so that physical, machine learning modeling and forgery attacks can be resisted, and the security of the authentication process is ensured.
Owner:HARBIN INST OF TECH

Intelligent identity identification and authentication system based on examinee identity data

The invention belongs to the technical field of education examination management, and particularly discloses and provides an intelligent identity recognition and authentication system based on examinee identity data, which comprises the steps of: monitoring and collecting examinee waiting images in a whole process through an entrance authentication module, and restoring image quality by combining with real-time face comparison of a pre-stored identity database so as to improve authentication accuracy; the identity classification processing module performs cross comparison on face data of examinees failed in secondary verification, identifies examinees not in the examination site, generates navigation guidance, triggers early warning or alarm for examinees lacking examination and non-examinees, and performs cooperative management on abnormal identities in the whole network; behavior characteristics and writing posture data of examinees are collected through a departure monitoring module, identity credibility weight is reduced in combination with a departure duration index, a dual-channel authentication mechanism is started during returning, identity authenticity is verified in a multi-dimensional manner, a trunk micro-motion identity spectrum and iris living body authentication technology is introduced, a high-security identity authentication scheme is provided, and the safety of the examinees is improved. And accurate management of the whole process is realized.
Owner:FENGYE (SHENZHEN) TECH CO LTD

Local device authentication system

Various embodiments are generally directed to provide a semi-local authentication scheme. A server can transmit one or more encryption mechanisms to a user device, which in turn can transmit the encrypted mechanisms to one or more secondary devices associated with the user device, where the user device and the secondary devices share a local connection. The secondary devices can transmit the one or more encrypted mechanism utilizing one or more one or more decryption mechanisms supplied by the server, and then transmit the result of the decryption, e.g. decrypted codes, back to the user device, which in turn can then transmit a final decrypted code or codes to the server. Upon confirming receipt of the decryption from the user device, the server can authorize access (via the user device) to one or more devices, networks, applications, and / or components.
Owner:CAPITAL ONE SERVICES LLC

A quantum-resistant identity authentication method, system, and electronic device

The present invention relates to the field of communication security technology, and specifically to a quantum-resistant identity authentication method and device. This application introduces a trust root on the basis of a traditional authentication scheme, which is used to sign the public key and identity information in a storage device to complete the issuance of the storage device. The identity authentication end can confirm that the public key and identity information in the storage device are valid by verifying the signature of the trust root, thereby reducing the risk of identity forgery. This application also introduces a quantum-resistant cryptographic algorithm in the trust root and the identity authentication end, and uses a hybrid of the quantum-resistant cryptographic algorithm and the national secret algorithm for signing and verification, providing a higher level of security.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Adaptive authentication method based on Beidou third-generation navigation satellite message

The invention discloses a self-adaptive authentication method based on a Beidou third-generation navigation satellite message, which comprises the following steps that: a control center encrypts a navigation message and uploads the encrypted navigation message to a Beidou satellite, the Beidou satellite broadcasts the encrypted navigation message, a receiver updates a public key based on a digital certificate, and the receiver sends the updated public key to the Beidou satellite. And on the basis, the received encrypted navigation message is authenticated, and whether the navigation message has integrity and authenticity is judged. According to the scheme of the invention, a switchable authentication scheme is provided based on the transmission characteristics of the D1 navigation message and the D2 navigation message aiming at the navigation message characteristics of the Beidou third-generation navigation system, so that the security requirements of receivers with different performances on resisting navigation spoofing attacks are met; meanwhile, signature authentication, TESLA key authentication and MAC authentication are adopted, so that the non-repudiation, coherence and integrity of ciphertext information are ensured, a receiver is ensured to quickly and efficiently complete navigation message authentication work, and normal navigation message resolving work is not influenced.
Owner:THE 724TH RESEARCH INSTITUTE OF CHINA STATE SHIPBUILDING CORP LTD

Revocable Internet of Vehicles authentication method based on alliance chain

The invention discloses a revocable Internet of Vehicles authentication method based on an alliance chain. The method comprises the following steps: initializing a system to establish a trust basis; the vehicle and road side unit registers to a trusted mechanism, the pseudo identity and PUF information are subjected to uplink storage, and an intelligent contract is deployed; after the vehicle initiates authentication, the road side unit verifies information from the chain and generates a new pseudo identity and a PUF challenge value; the vehicle generates a PUF response based on the challenge and calculates a session key, and the road side unit calls an on-chain contract to verify the response, completes bidirectional authentication and updates an on-chain identity state; and if the malicious vehicle is detected, the road side unit submits the chain revocation transaction, and the whole network refuses the authentication after consensus synchronization. According to the invention, a lightweight password technology, a physical unclonable function, an alliance block chain distributed account book and a dynamic identity management mechanism are integrated to construct an Internet of Vehicles authentication scheme considering high efficiency, safety, reliability and privacy protection, and effective support is provided for safe and reliable operation of an intelligent traffic system.
Owner:ANQING NORMAL UNIV

User identity authentication scheme based on acoustic signal

According to the user identity authentication scheme based on the acoustic signal, the defects of an existing identity authentication method are overcome, additional intelligent hardware does not need to be deployed, and high-safety and high-precision identity authentication can be achieved only on the basis of existing hardware. Meanwhile, the method is not influenced by factors such as environment and equipment conditions, and has good transportability. The method is realized by utilizing a special ultrasonic signal which cannot be heard by ordinary people, the normal life of the user is not influenced during operation, and the method can be naturally integrated into the life of the user. The method comprises the following steps: firstly, capturing a special ultrasonic signal sent by a loudspeaker and reflected by the face of a user name; then measuring the distances from different face areas to the microphone and the loudspeaker; compensating energy and phase information of different distances according to a range adaptive algorithm; and finally, carrying out identity recognition by utilizing distance and energy characteristics.
Owner:山东汇金股份有限公司 +2

Biological characteristic authentication method and system based on category perception

The invention provides a biological feature authentication method and system based on category awareness, the system comprises a server and a client, after the client receives an authentication request, the client synchronously collects a to-be-authenticated palm vein image and a to-be-authenticated heart rate signal of a user, generates a multi-modal fusion feature, and sends the multi-modal fusion feature to the server; in combination with a local category distribution compensation prompt vector and the optimized discriminative activity prompt vector, constructing a target sequence, and inputting the target sequence into a multi-modal biological feature authentication model to obtain an authentication result of the user; wherein the category distribution compensation prompt vector is obtained by training a global distribution reference and a local multi-modal fusion feature sample, and the global distribution reference is generated by aggregating a plurality of client sample statistics by a server; the discriminative activity prompt vector is obtained by updating a global enhancement prompt vector issued by the client based on the server, and the global enhancement prompt vector is obtained by optimizing trained discriminative activity prompt vectors of a plurality of clients by the server. Therefore, a privacy-friendly authentication scheme adaptive to multiple scenes and multiple devices is realized.
Owner:ZKTECO CO LTD

A federated learning user identity continuous authentication method based on model matching

The present application relates to the field of identity authentication of federated learning, and provides a user identity continuous authentication scheme based on model matching. In the traditional federated learning architecture, the identity verification of each edge user by the central server depends on the network security transmission protocol and system access identity authentication, which lacks effective defense means when facing attacks on the client and transmission process. The present scheme measures the matching degree between the edge models uploaded by the edge users in the continuous two training of federated learning to continuously authenticate the user identity, and is divided into three parts: edge user-central server model parameter interaction, edge model feature extraction and user identity authentication. The central server uses the characteristic that the decision boundary of the model trained with the same data set has high dependence, collects the model feature reflecting the private data set by collecting the gradient of the decision boundary of the edge model, and then inputs the encoder based on contrast learning to calculate the matching degree between the models and exclude the identity abnormal users. The present scheme is widely applicable to various federated learning systems based on neural networks, and has high accuracy, practicability and compatibility.
Owner:SHANGHAI JIAOTONG UNIV +1

MIMO system equipment identity authentication method based on mutual coupling and spatial AoA

The invention belongs to the technical field of wireless communication security, and discloses an MIMO system equipment identity authentication method based on mutual coupling and spatial AoA, which is realized through the following steps: a transmitting end communicates with a receiving end, an uplink millimeter wave channel is constructed, a communication model with a bimodal characteristic is established, namely, a signal is received, and the signal is transmitted to the receiving end; the communication model comprises a mutual coupling fingerprint model and an AoA fingerprint statistical model, and the mutual coupling fingerprint model comprises a transmitting array mutual coupling matrix and a receiving array mutual coupling matrix; a multi-signal classification algorithm based on a feature space is adopted to extract MC features and an AoA value of a communication model, a receiving end judges whether a current received signal is from legal equipment or an attacker based on the extracted MC features and the extracted AoA value, and authentication is completed. According to the method, a hardware-level MC effect and space arrival angle characteristics are combined, an efficient and high-robustness bimodal physical layer authentication scheme is provided, and a new solution is provided for a future 6G high-security scene.
Owner:NANJING UNIV OF POSTS & TELECOMM

Lightweight encryption and integrity verification method for sensing layer data of Internet of Things

The invention relates to the technical field of Internet of Things security protection, and particularly discloses an Internet of Things perception layer data lightweight encryption and integrity verification method, which abstracts a whole original data object into a unique and compact cryptographic commitment, and securely transmits the same to a receiver through one lightweight commitment handshake. And a trust anchor point which cannot be tampered is established. And then, in a data distribution stage, each data fragment is bound with the corresponding proof path which can be independently verified for transmission. This decouples the overall integrity verification of the application layer from the physical fragmentation mechanism of the network layer. The receiver can verify each arriving fragment based on the pre-established trust anchor point, thereby overcoming the vulnerability that the fragment mode after traditional overall authentication needs overall retransmission due to single-point failure. And meanwhile, the security defects of huge authentication overhead and incapability of defending fragment recombination attacks caused by a one-by-one authentication scheme after fragmentation are also avoided.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Certificateless weighted multi-identity cross-domain authentication scheme combined with block chain

The invention discloses a certificateless weighted multi-identity cross-domain authentication scheme combined with a block chain, and aims to solve the problem that the existing related technology is difficult to adapt to diversified authentication of a complex Internet of Things environment. According to the method, a certificateless weighted cross-domain authentication scheme is designed by considering the multi-identity characteristics of cross-domain users and the credible weight difference of different identities. According to the scheme, a distributed block chain structure is adopted, and the non-tampering performance and the synchronization reliability of parameters are guaranteed; through cooperation of a threshold signature algorithm and a certificateless signature algorithm, the overall security of the system is maintained, and the third-party key escrow risk is thoroughly avoided. Besides, the digital signature protocol integrated with the identity weight is designed to realize differential authentication, the user with higher credible weight only needs less part of identity information to complete authentication of the user with low weight, and the efficiency is greatly improved. According to the invention, the security, reliability and flexibility of cross-domain authentication are enhanced, specific scene requirements of the Internet of Things are adapted, and an efficient solution is provided.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Efficient privacy protection authentication scheme for edge-assisted Internet of Things security warning system

The invention discloses an efficient privacy protection authentication scheme for an edge-assisted Internet of Things security warning system, belongs to the technical field of Internet of Things privacy protection, and is based on an improved linkable group signature mechanism and a security warning system architecture. The security warning system architecture comprises a trusted authorization mechanism TA, edge nodes ENs and equipment. Comprising a system initialization stage, an equipment registration stage, a message transmission stage, a verification and decryption stage and a malicious tracing stage. According to the efficient privacy protection authentication scheme for the edge-assisted Internet of Things security warning system, balance between anonymity and responsibility of the edge nodes can be realized, key challenges of maintaining privacy while ensuring security early warning integrity are completed, Sybil attacks are effectively resisted, and the security early warning system has the advantages that the security early warning integrity is ensured, the security early warning safety is ensured, and the security early warning safety is ensured. And safety measures in the system are further enhanced.
Owner:BEIJING INST OF TECH

Identity authentication method, device and system, electronic equipment and storage medium

The invention provides an identity authentication method, device and system, electronic equipment and a storage medium, and belongs to the technical field of communication security, the method is applied to a security gateway, and the method comprises the following steps: receiving an intranet access request sent by a user terminal; the intranet access request comprises a trusted authentication mobile phone number and encrypted data; the encrypted data comprises a digital signature; and performing verification processing on the digital signature based on the credible authentication mobile phone number, and releasing the intranet access request under the condition that the verification processing is passed. According to the application, the security gateway verifies and signs the digital signature of the encrypted data determined based on the super SIM card of the user terminal based on the trusted authentication mobile phone number of the intranet access request, and an identity authentication scheme that access hotspot equipment and a hotspot sharer can be distinguished under the condition of hotspot sharing is realized.
Owner:CHINA MOBILE COMM GRP CO LTD +1

Identity authentication control method and system for power monitoring system based on anti-quantum cryptography

The application provides an anti-quantum-cipher-based power monitoring system identity authentication control method and system, and belongs to the technical field of authentication control, which comprises the following steps: step 1, initializing the anti-quantum-cipher-based power monitoring system identity authentication control system; step 2, the anti-quantum-cipher-based power monitoring system identity authentication control system registers the edge terminal device; and step 3, the anti-quantum-cipher-based power monitoring system identity authentication control system performs two-way identity authentication and key negotiation. The application aims to overcome the defects of the existing anti-quantum-cipher-based power monitoring system identity authentication scheme in performance adaptation, key security, authentication robustness and system compatibility, and provides an identity authentication control method and system meeting the high security, low delay and high reliability requirements of the power monitoring system.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

Combination of challenge-response pair mechanisms for multi-factor authentication schemes protecting private keys

Protocols for providing multi-factor authentication to secure private encryption keys for an asymmetrical encryption algorithm are disclosed. According to the method, a user device is in possession of multiple CRP generation factors, which may include a physical addressable PUF array, a biometric print, a virtual token derived from a digital file, and a sensor-based PUF. The user device builds a combined reference table of responses from two or more of its factors, and derives an ephemeral key from the table used to encrypt a secret key. The terminal device may decrypt the key despite loss of the physical addressable PUF.
Owner:ARIZONA BOARD OF REGENTS ACTING FOR & ON BEHALF OF NORTHERN ARIZONA UNIV

Browser-based authentication scheme

Disclosed herein is a method performed by a client application of an authentication provider application. The method includes deriving a reference to a domain name based on an identity handle of a user, querying a domain name system to obtain one or more identity records associated with the identity handle, obtaining one or more public keys based on the one or more identity records, and deriving an authentication endpoint web address based on the identity handle. The authentication endpoint web address is usable to access the authentication provider application. The method further includes sending data to the authentication provider application using the authentication endpoint web address, wherein the authentication provider application is able to access one or more private keys corresponding to the one or more public keys for generating digital signatures. The method further includes receiving, from the authentication provider application, one or more digital signatures.
Owner:SHORE LABS ZBIGNIEW ZEMLA