Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Brute-force attack" patented technology

In cryptography, a brute-force attack consists of an attacker submitting many passwords or passphrases with the hope of eventually guessing correctly. The attacker systematically checks all possible passwords and passphrases until the correct one is found. Alternatively, the attacker can attempt to guess the key which is typically created from the password using a key derivation function. This is known as an exhaustive key search.

Information security techniques for preventing brute force attacks on networked computer systems

A system includes an originating client platform, a first intermediate client platform, and a bridge platform. A first electronic processor of the originating client platform is configured to generate an authorization request and transmit the authorization request. A second electronic processor of the first intermediate client platform is configured to receive the authorization request and determine whether the authorization request is malicious or not malicious. In response to determining that the authorization request is malicious, the second electronic processor is configured to store the authorization request in a data store, transmit an authorization request denial, and transmit an incident payload including details of the authorization request. A third electronic processor of the bridge platform is configured to receive the incident payload, generate a security profile based on the incident payload, and transmit the security profile to a second intermediate client platform.
Owner:MASTERCARD TECHNOLOGIES CANADA ULC

Encryption processing method for geographic information data

The invention belongs to the technical field of encryption transmission, and particularly relates to an encryption processing method for geographic information data, which comprises the following steps that: encryption keys of different hierarchies are constructed according to role authority, each layer of key comprises a plurality of groups of chaotic mapping parameters, and the next hierarchy comprises all parameters of the previous hierarchy. And encrypting the geographic image by using each group of chaotic mapping parameters, and forming a ciphertext of a corresponding hierarchy by using each group of results. The method specifically comprises the following steps: S1, generating a chaotic sequence; s2, selecting pixel points in the image without putting back based on the chaos sequence, performing AMBTC coding on the selected pixel points to obtain a high quantization value, a low quantization value and a binarization mask, and splicing corresponding binary numbers into a coding result; and S3, repeating the step S2 until all the pixels are selected, and summarizing encoding results to form an encryption result under the group of parameters. According to the method, authority management and chaotic characteristics are combined, hierarchical encryption of geographic images is realized, and statistical analysis attacks and brute force attack attacks can be resisted.
Owner:XIAN CHENGFA XINAN TECHNOLOGY CO LTD

Multi-factor login authentication method and system based on dynamic authentication chain

PendingCN120614183ASecuring communicationBrute forceCode coupling
The invention discloses a multi-factor login authentication method and system based on a dynamic authentication chain, and belongs to the technical field of information security, and the method comprises the steps: defining a plurality of authentication factors and an associated authentication chain sequence through extensible configuration data; recording the current authentication step and the completion state of each step through a state machine object; realizing cross-request state synchronization based on a distributed cache storage session state; and intercepting a login request through a section controller, and dynamically driving a multi-factor authentication process according to an authentication chain sequence. According to the invention, flexible and safe identity verification is realized through configurable authentication process and state machine management, the code coupling degree can be reduced, the user experience can be improved, and the brute force cracking risk can be reduced.
Owner:INSPUR SOFTWARE CO LTD

SSH brute force attack detection method and device

The invention provides an SSH brute force attack detection method and device. The method comprises the following steps: constructing a sample array; screening samples in the sample array by using a preset screening strategy to obtain reserved samples; extracting target statistical data of each reserved sample, and performing threshold judgment according to the target statistical data; and judging an SSH brute force cracking result according to a threshold judgment result. According to the method, a plurality of statistical characteristics, calculation characteristics and threshold value judgment methods are combined and used for detection, detection depending on single frequency or port characteristics is avoided, false alarms are reduced, and the detection accuracy is improved.
Owner:VIEWINTECH

Web application protection method, system and computer-readable storage medium

The present invention provides a web application protection method, system, and computer-readable storage medium. The method comprises: a front-end sending a data request to a back-end, the data request carrying a uniform resource locator (URL) and parameter information; upon receiving the data request, the back-end parsing the parameter information to obtain corresponding parameter values; and the back-end generating corresponding parameter images based on the parameter values, and saving the parameter images to a preset database. By graphically representing parameter values, the present invention can avoid web application risks caused by inserting malicious code into parameters, effectively defend against attacks such as cross-site scripting, SQL injection, file uploads, and brute force attacks, thereby improving the security of web applications and achieving comprehensive protection for web applications. This addresses the problem that existing web application protection methods lack comprehensive protection for web applications.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

A method for encrypting geographic information data

The present application belongs to the technical field of encrypted transmission, and particularly relates to a kind of encrypted processing method of geographic information data, comprising: constructing different levels of encryption keys according to role permissions, each level of key contains a plurality of groups of chaotic mapping parameters, and the next level contains all parameters of the previous level. Each group of chaotic mapping parameters is used to encrypt geographic images, and the results of each group are used to form the ciphertext of the corresponding level. The specific process is as follows: S1, generate a chaotic sequence; S2, select pixel points in the image without replacement based on the chaotic sequence, encode the selected pixel points using AMBTC, obtain high quantization values, low quantization values, and binary masks, and concatenate the corresponding binary numbers to form the encoding result; S3, repeat S2 until all pixels are selected, and collect the encoding results to form the encryption result under this group of parameters. The present application combines permission management and chaotic characteristics, realizes hierarchical encryption of geographic images, and can resist statistical analysis attacks and brute force attacks.
Owner:XIAN CHENGFA XINAN TECHNOLOGY CO LTD

Identity authentication method and apparatus, storage medium, program, and program product

An identity authentication method is disclosed in embodiments of the present application. When a requester and an authentication access controller perform identity authentication using an authentication mechanism of a pre-shared key, the identity information of entities is transmitted in the form of ciphertext, thereby preventing the identity information of the entities from being exposed during the transmission, so that attackers cannot obtain private or sensitive information. The mutual or unilateral identity authentication between the authentication access controller and the requester is achieved while ensuring the confidentiality of the entity identity and related information, thereby laying a foundation for ensuring that the user accessing the network is legitimate and / or the network accessed by the user is legitimate. Meanwhile, in connection with key exchange calculations and by an ingenious and detailed design, the ability of the authentication process to resist dictionary brute force attacks or quantum computing attacks is enhanced. Further disclosed in embodiments of the present application are an identity authentication apparatus, a storage medium, a program, and a program product.
Owner:CHINA IWNCOMM

User authentication in decentralized computing system environment

In some aspects, a computing system may authenticate a user before blockchain functions may be performed and provide obstacles to prevent brute force attacks in decentralized computing systems or other distributed computing system environments. The computing system may use a smart contract to assist with authenticating a user. As authentication attempts fail, the computing system may increase a network usage cost associated with authentication. By doing so, the security of a computing system may be improved by making it cost-prohibitive for malicious actors to perform brute force attacks. Further, a computing system may use a variety of biometric information that may provide additional verification and security when authentication is performed.
Owner:CAPITAL ONE SERVICES LLC

Multi-dimensional encryption method and system based on three-dimensional Lorentz chaotic system

The invention relates to the technical field of optical fiber communication encryption, in particular to a multi-dimensional encryption method and system based on a three-dimensional Lorenz-like chaotic system, and the key point of the technical scheme is that a dynamic key is generated through Hash512 mixing, the three-dimensional Lorenz-like chaotic system is driven to carry out DNA bit encryption, encrypted bits are mapped into symbols, and Cat mapping scrambling is carried out three times, so that the dynamic key is generated; and performing constellation rotation on the scrambling symbol by using a random angle generated by chaos, and finally embedding the dynamic key into a rotation symbol sequence to form a final multi-dimensional encryption transmission sequence. According to the method, a high-complexity chaotic sequence is generated under a three-dimensional Lorenz chaotic system driven by a dynamic key through technologies of multi-dimensional encryption fusion DNA bit-level coding, Cat mapping scrambling, constellation random rotation and the like, so that the key space is greatly expanded, and the defense capability on brute force attack, differential attack and statistical analysis attack is improved; and a modular design is adopted, so that integration in an existing optical fiber coherent transceiving and DSP platform is facilitated, and the balance of high safety and low system load is realized.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Chaotic laser secret communication device and method with large secret key space

The invention relates to the technical field of optical communication, and discloses a chaotic laser secret communication device and method with a large secret key space. The device comprises a common driving chaotic signal generation module, an optical isolator, a second optical splitter, a first chaotic carrier generation module, a second chaotic carrier generation module, a first photoelectric detector, a second photoelectric detector, an arbitrary waveform generator, a power divider and an oscilloscope. The two independent chaotic carrier generation modules are respectively excited by the shunted public driving signal, so that the driving signal and the chaotic carrier have low relevance, eavesdropping on a public driving link through direct filtering is effectively resisted, and the generated chaotic carrier is ensured to have high synchronism; and secondly, the two chaotic carrier generation modules serve as independent parameter-adjustable units, each chaotic carrier generation module has multi-dimensional adjustable physical parameters, and the parameters form a composite key of the system, so that the ability of the system to resist brute force attack is remarkably improved.
Owner:GUANGDONG UNIV OF TECH

Data anti-cracking encryption method and system

The invention is applicable to the technical field of serial port data encryption, and provides a data anti-cracking encryption method and system, and the method comprises the steps: generating an encryption key and a decryption key; encrypting the data by using the encryption key to generate encrypted data; transmitting the encrypted data; verifying the encrypted data; wherein the encryption process of a CBC mode is adopted for encrypting the data by using the encryption key to generate the encrypted data, and the decryption process of the CBC mode is adopted for decrypting the encrypted data by using the decryption key; the method further comprises the steps of presetting an initial vector of a CBC mode; further, before encrypting the data by using the encryption key, the method comprises the following steps: encrypting the encryption key by using a pseudo-random function; adding a salt value and the number of iterations to the pseudo-random function and selecting a hash algorithm; therefore, rainbow attacks and brute force attacks are effectively blocked, and the user experience is improved.
Owner:深圳市宇泰科技有限公司 +1

Private data security intelligent transmission method based on binary sequence segmentation original network

The invention relates to the technical field of data security, and discloses a privacy data security intelligent transmission method based on a binary sequence segmentation original network, comprising the following steps: S1, performing binary sequence segmentation on a deep neural network in a spatial dimension; s2, performing feature transmission; s3, bullet fish densification; and S4, performing secure storage. According to the secure and intelligent private data transmission method for segmenting the original network based on the binary sequence, the original network is segmented through the binary sequence, the client only transmits the feature vector instead of the original private data, and the sensitive information exposure risk is reduced from the source; the bullet fish algorithm enables transmission data to exist in a ciphertext form, and the possibility of reverse decoding is minimized in cooperation with antagonistic reconstruction learning, so that triple privacy barriers of data segmentation, dynamic encryption and model protection are formed; hash verification before cloud storage ensures data integrity, tampering and leakage are avoided, violent attacks and reverse engineering are effectively resisted, and the privacy compliance requirement of a high-sensitivity scene is met.
Owner:BEIJING UNIV OF CHEM TECH

Methods, systems, and machine-readable media for cryptographic techniques using set of symbols of varying size

Systems, methods, and non-transitory computer-readable media are disclosed for symmetric cryptographic techniques using a set of symbols of varying size. In order to combat brute force attacks or other similar types of attacks, multiple symbol sets of varying sizes can be used to encrypt / decrypt data. For example, different portions of data (e.g., a block of data representing multiple symbols, a set of bits representing a single symbol) may be encrypted / decrypted using different sets of symbols that include different numbers of unique symbols. The complexity of the encryption process is increased by using the symbol set with the variable size, so that the difficulty of decrypting the encrypted data by using brute force attack is greatly improved.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

An encryption deduplication method supporting file key continuous update

ActiveCN119766525BThird partyEngineering
The application discloses a random key encryption deduplication method supporting continuous updating. In order to enable a client to safely outsource private data to a server, the method comprises the following steps: after system parameters are initialized, the client selects a random key to encrypt data and sends the encrypted data to the server. The server checks and deduplicates the data of the user. The server verifies the ownership of the file of each uploader through a challenge-response mechanism to realize effective ownership management control. The application supports the replacement of the file key of the user and can guarantee that all legal users obtain the key updated for multiple times, thereby reducing the risk of private data leakage after the key leakage. Due to the randomness of the key selected by the client, the application can resist the brute force attack introduced by the deterministic convergent encryption. Compared with the encryption deduplication method assisted by a third-party independent server, the method is simpler in deployment. The application can provide data privacy in the field of encryption deduplication.
Owner:CHINA MCC5 GROUP CORP LTD +1

Information security techniques for preventing brute force attacks on networked computer systems

A system includes an originating client platform, a first intermediate client platform, and a bridge platform. A first electronic processor of the originating client platform is configured to generate an authorization request and transmit the authorization request. A second electronic processor of the first intermediate client platform is configured to receive the authorization request and determine whether the authorization request is malicious or not malicious. In response to determining that the authorization request is malicious, the second electronic processor is configured to store the authorization request in a data store, transmit an authorization request denial, and transmit an incident payload including details of the authorization request. A third electronic processor of the bridge platform is configured to receive the incident payload, generate a security profile based on the incident payload, and transmit the security profile to a second intermediate client platform.
Owner:MASTERCARD TECHNOLOGIES CANADA ULC

Brute force attack behavior identification method, device, equipment, medium and program product

The application discloses a password-cracking attack behavior identification method, device, equipment, medium and program product, and belongs to the field of information security protection. The method comprises the following steps: receiving a login request message for requesting to log in to a target account, wherein the login request message comprises a target username and a login input password, and the target username corresponds to the target account; in the case that the login input password is inconsistent with the account password of the target account, calculating a similarity parameter of the login input password and a target pseudo password preset for the target account, wherein the target pseudo password is different from the account password; determining a response delay time length based on the similarity parameter, and feeding back a login response message according to the response delay time length; in the case that the change of the similarity parameters corresponding to multiple login request messages for logging in to the target account meets a preset abnormality identification condition, it is determined that there is a password-cracking attack behavior for logging in to the target account. According to the embodiment of the application, the identification accuracy of the password-cracking attack behavior can be improved.
Owner:CHINA UNIONPAY

Big data-based property right transaction data tamper-proof storage system

The invention relates to the technical field of data tamper-proofing, in particular to a property right transaction data tamper-proofing storage system based on big data. The method comprises the following steps: a data acquisition and access unit receives original transaction data generated in a property right transaction process, and performs formatting processing and identity authentication on the original transaction data to obtain processed transaction data; the data encryption and storage unit performs encryption processing on the processed transaction data by using an AES algorithm, and submits the encrypted transaction data to a block chain network for distributed storage; and the block generation and consensus unit packages the encrypted transaction data by adopting an attribute dimension block structure. According to the method, an AES algorithm and post quantum cryptography hybrid encryption mechanism is adopted, and key life cycle management based on master key protection is combined, so that data leakage and tampering caused by quantum computing or long-term violent attack cracking of an encryption key are fundamentally prevented.
Owner:ANHUI PROPERTY RIGHTS TRADING CENT CO LTD

Detection Method, Device, Storage Medium and Electronic Device for Subdomain Brute Force Attack

The present invention discloses a detection method, device, storage medium and electronic device for subdomain brute force cracking. Among them, the method includes: responding to a detection request, obtaining target traffic data and domain name configuration data of a target server, wherein the detection request is used to request to detect whether the target server is in a state of subdomain brute force cracking, the target traffic data is HTTP traffic data of the Hypertext Transfer Protocol generated when the target server accepts access during a target time period, and the domain name configuration data is domain name data for the target server to provide domain name services externally; extracting target feature data from the target traffic data based on the domain name configuration data; and determining whether the target server is in a state of subdomain brute force cracking based on the target feature data. The present invention solves the technical problem that the method of detecting whether a server is suffering from subdomain brute force cracking by using an isolation forest algorithm to calculate an anomaly score according to the destination IP port feature value has a poor detection effect.
Owner:HILLSTONE NETWORKS CO LTD

A method and system for tracing comprehensive agricultural product sales information

The present invention relates to the field of information traceability technology, and more particularly to a method and system for tracing the source of comprehensive agricultural product sales information. The method comprises: an agricultural product traceability platform encrypting the source information of agricultural products and returning the encrypted result to consumers. The encryption process comprises: converting the source information into a digital sequence; constructing a character sequence, a shift sequence, and a symbol sequence; and encrypting the digital sequence, including: converting the #imgabs1#th number #imgabs2# in the digital sequence into a signed number #imgabs3# based on the #imgabs0#th element in the symbol sequence; when #imgabs4#, using the element indexed #imgabs5# in the character sequence as the ciphertext #imgabs7# of #imgabs6#, where #imgabs8# is the length of the character sequence; obtaining an updated index #imgabs10# of #imgabs9# based on the shift sequence, and updating the character sequence based on #imgabs11#. The encryption result of the present invention is complex, exhibits an avalanche effect, and is resistant to statistical analysis attacks and brute force attacks, thereby improving the credibility of agricultural product sales information traceability.
Owner:YUNNEX TECH +1

Prevention of brute force attacks on voicemail accounts

A voicemail server device receives a voice call from an originating device attempting to access a voicemail account associated with a subscriber of a network service provider. Accessing the voicemail account can require providing by the originating device a personal identification number (PIN) predefined for the voicemail account. The voicemail server device can determine whether the originating device is associated with the subscriber. Responsive to determining that the originating device is not associated with the subscriber, the voicemail server device can activate an attempt limit for the voicemail account. The attempt limit can correspond to a predefined number of failed attempts to access the voicemail account by providing an incorrect PIN. The voicemail server device can receive attempts to access the voicemail account by incorrect PINs. Responsive to determining that a number of the attempts has reached the attempt limit, the voicemail server device can redefine the PIN.
Owner:T MOBILE US INC

Anonymous password authentication and encryption method for deduplication-oriented cloud storage system

The application discloses an anonymous password authentication and encryption scheme for a deduplication cloud storage system, and is characterized in that, in the deduplication cloud storage system, under a three-party architecture of a key server, a cloud server and a user, the three parties jointly generate an MLE key, encryption data deduplication is realized, and the problems of brute force attack and single point failure are avoided; an anonymous authentication of the user to the cloud storage server is constructed based on a non-interactive zero-knowledge proof scheme, and the privacy protection of the user identity information is realized; a key protection mechanism based on a reinforced password is constructed by using an identity-based careless pseudo-random function, so that the user can safely store and maintain the key at the remote cloud server side without occupying local resources. The security analysis and simulation experiment results show that the scheme can guarantee the encryption and authentication security, and provide higher calculation and communication efficiency.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Multi-level chaotic encryption-based mp-wfrft communication method and system

The present disclosure relates to a multi-cascaded chaotic encryption-based MP-WFRFT communication method and system. The method comprises: building a multi-cascaded chaotic system model using Logistic mapping and Henon-Sine mapping, wherein the multi-cascaded chaotic system comprises a cryptographic kernel space having a bit scrambling matrix and a constellation rotation matrix; performing triple encryption processing on an input signal using the cryptographic kernel space of the multi-cascaded chaotic system and MP-WFRFT transformation, generating an encrypted signal, and completing hybrid carrier modulation; receiving the hybrid carrier signal at a receiving end and performing WFRFT inverse transformation on the hybrid carrier signal; generating a decryption matrix according to parameters of the multi-cascaded chaotic system, in combination with MP-WFRFT transformation parameters and a scale vector, and decrypting the encrypted signal using the decryption matrix to complete the demodulation process. The present disclosure improves the wireless communication physical layer security transmission performance through triple encryption processing, and can effectively prevent brute force attacks.
Owner:AIR FORCE UNIV PLA