Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Challenge response" patented technology

A challenge–response (or C/R) system is a type of spam filter that automatically sends a reply with a challenge to the (alleged) sender of an incoming e-mail. It was originally designed in 1997 by Stan Weatherby, and was called Email Verification. In this reply, the sender is asked to perform some action to assure delivery of the original message, which would otherwise not be delivered. The action to perform typically takes relatively little effort to do once, but great effort to perform in large numbers. This effectively filters out spammers. Challenge–response systems only need to send challenges to unknown senders. Senders that have previously performed the challenging action, or who have previously been sent e-mail(s) to, would be automatically whitelisted.

Prevent bypassing authentication and authorization checks of microservices in zero trust architecture

A method for microservice authentication includes intercepting, at a first policy engine sidecar of a first microservice, a service request from the first microservice to a second microservice. The service request includes services requested from the second microservice. The method includes generating a transaction challenge, transmitting the service request, a first token identifying the first microservice, and the transaction challenge to the second microservice, and intercepting a service request response from the second microservice to the first microservice. The method includes determining whether the service request response includes a second token identifying the second microservice and a transaction challenge response generated by a second policy engine sidecar of the second microservice, and transmitting the service request response to the first microservice in response to determining the second token identifies the second microservice and determining that the transaction challenge response includes an acceptable transaction challenge response.
Owner:LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD

Management method and device for preventing BMS firmware from being flashed

The invention provides a management method and device for preventing BMS firmware from being flashed, and relates to the technical field of asymmetric encryption, and the method comprises the steps: generating a unique response, and reconstructing an equipment root key, so as to establish a trusted firmware execution environment and complete firmware digital signature verification; digital certificate exchange and bidirectional verification of the BMS and the diagnostic instrument are carried out in the trusted firmware execution environment, a dynamic session key is generated, and a challenge response mechanism is executed to ensure that firmware flashing operation is only authorized in the trusted communication environment; performing hash check, control flow monitoring and access auditing by using the security reference data based on the dynamic session key, performing real-time hardware processing when an exception is detected, and recording a security event at the same time; and the BMS uploads the log and attack behavior characteristics corresponding to the security event to a cloud platform, and the cloud platform analyzes and generates a detection rule or certificate revocation list and issues and updates the detection rule or certificate revocation list. Through the dynamic BMS firmware flashing protection method, the safety of the BMS firmware is improved.
Owner:XIAOGAN CORNEX NEW ENERGY INNOVATION TECHNOLOGY CO LTD

Resiliency architecture for identity provisioning and verification

Identity access and management (“IAM”) systems with resiliency features and methods related to the same are provided. An identity proxy is interposed between user systems and each of two or more identity provider (“IDP”) systems. The identity proxy routes authentication requests, challenges, and responses between the user systems and the IDP systems based on availability, and verifies challenge responses to permit access to data or services.
Owner:HUMANA INC

Secure data transmission system based on dynamic encryption authentication

According to the secure data transmission system based on dynamic encryption authentication provided by the invention, a trust root which cannot be tampered is established for the whole system through the hardware password module, and continuous derivation and rotation of a session key are realized by the dynamic key management module on the basis, so that the security risk caused by long-term use of a static key is effectively solved. And the secure communication gateway module executes bidirectional authentication and anti-hijacking challenge response by using a dynamic key, so that the real-time credibility and session continuity of the communication process are ensured. And the strategy control engine uniformly coordinates the behaviors of key management and the communication gateway by receiving and compiling the declarative strategy, so that flexible deployment and centralized management and control of the security strategy are realized. According to the system, a cryptographic basis, a dynamic strategy, real-time monitoring and automatic response are deeply fused, a self-adaptive and automatic deep defense system with the capability of continuously resisting advanced threats is constructed, and the overall safety level and the operation efficiency of data transmission are remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Identifying and flagging untrustworthy microservices in zero trust architecture

PendingUS20260019429A1User identity/authority verificationMicroservicesChallenge response
A method for reporting an untrustworthy microservice includes intercepting, at a first policy engine sidecar of a first microservice, a service request from the first microservice to a second microservice. The service request includes services requested from the second microservice. The method includes generating a transaction challenge and transmitting the service request, a first token identifying the first microservice, and the transaction challenge to the second microservice. The method includes intercepting a service request response from a second microservice to the first microservice and transmitting a microservice alert to a central policy server in response to a service request response failure. The service request response failure includes a failure in determining that the service request response includes a second token properly identifying the second microservice and an acceptable transaction challenge response. The microservice alert includes an identifier of the second microservice and an indication of the service request response failure.
Owner:LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD

System and method for authentication in a client-server connection using challenge applied to a secret key

A method for managing an authentication includes establishing, by a server device, a secured network channel with a client, providing, via the secured network channel, a private key to the client, after the providing, obtaining, from the client, a request for establishing a session with the client via a second network channel, in response to the request: sending a challenge request to the client, obtaining a challenge response associated with the challenge request, wherein the challenge response specifies a first challenge answer, performing a challenge processing using a private key to generate a second challenge answer, making a determination, using the first challenge answer and the second challenge answer, that the client is authenticated, and based on the determination, initiating the session with the client.
Owner:DELL PROD LP

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Key possession based verification in endpoint devices

Methods and systems for securing endpoint devices are disclosed. To secure the endpoint devices, multiple processes for validating authority to invoke performance of commands may be implemented. The processes may include request based processes and challenge response based processes. In the challenge response based processes, an invoker of a command may establish authority for invoking the command by showing possession of a key to which the authority for the command has been delegated and that is usable to verify signatures included in responses to challenges to the invoked commands.
Owner:DELL PROD LP

User management system for computing support

A computing support system is configured to programmatically manage support access to a computing system via a support technician console across multiple levels of support access. The system receives a request to authenticate a user requesting support for the computing system, issues one or more authentication challenges to the user to authenticate the identity of the user, receives one or more corresponding authentication challenge responses from the user based on the authentication challenge, and verifies a level of authentication based on the authentication challenge response, the level of authentication being selected from multiple levels of authentication. The system also determines a level of support access to the computing system based on the verified level of authentication and the identity of the user and programmatically enforces limits on the support access to the computing system via the support technician console based on the determined level of support access.
Owner:MSP SOLUTIONS GRP LLC

Extending EAP for supporting generative AI challenges

Techniques for extending EAP for supporting generative AI challenge-response for secure access are described. The techniques may be performed at least in part by an authentication server. An indication of a request for a user account to access the network resource via a user device is received. A determination that the user device supports generative AI challenge-response authentication id determined. A posture of the user device is determined. Based at least in part on the device posture, parameters for generating a generative AI challenge-response are determined. The parameters include at least one of a level of hallucination for, and a type of, challenge response to generate, and are transmitted to a generative AI engine. The generative AI challenge-response is received from the generative AI engine and caused to be output by the user device.
Owner:CISCO TECHNOLOGY INC

Multi-factor dynamic authentication method and device for intelligent power grid-oriented swan equipment

The invention provides an intelligent power grid-oriented multi-factor dynamic authentication method and device for a swan-gap device, and the method comprises the steps: generating a dynamic random challenge code based on an authentication request initiated by a to-be-accessed swan-gap device, and transmitting the dynamic random challenge code to the to-be-accessed swan-gap device, encrypting the to-be-accessed gap equipment based on the dynamic random challenge code and returning challenge response information; performing correlation analysis based on the first communication information of the dynamic random challenge code and the challenge response information in the transmission process to obtain a communication linear correlation degree, and performing decryption and consistency verification on the challenge response information based on the communication linear correlation degree to obtain a first verification result; if the first verification result is that the verification is passed, verifying a supplementary factor returned by the to-be-accessed gap equipment based on second communication information of the gap soft bus to obtain a second verification result; and accessing the to-be-accessed gap equipment to the smart power grid based on the second verification result. The safety and the stability of the gap equipment accessing the intelligent power grid are improved.
Owner:GUANGZHOU HOPERUN YINENG SOFTWARE TECH CO LTD

Anti-quantum security authentication method suitable for space-air-ground integrated network

The invention provides an anti-quantum security authentication method suitable for a space-air-ground integrated network. The anti-quantum security authentication method comprises the steps that 1, a software defined network (SDN) controller firstly configures lattice-based homomorphic encryption parameters and generates a key pair; 2, the user terminal sends a request, the SDN controller allocates a temporary identity, an initial key and a physical unclonable function (PUF) challenge, the user terminal generates an encrypted challenge response and stores related information, and the SDN controller constructs a switching token; 3, completing identity verification and session key negotiation through authentication vector interaction, and updating a temporary identity identifier; and 4, quickly completing identity verification and key updating by using the switching token. According to the method, the cell-based homomorphic encryption is adopted to protect the PUF challenge response pair, the modeling attack risk is avoided, the switching authentication process is optimized through the switching token, and safe and efficient access of the user terminal in the air-space-ground integrated network in a high-speed moving scene is guaranteed.
Owner:BEIHANG UNIV

Distributed trusted execution of an application in a network of controllable physical unclonable function devices

A method and system for trusted execution of software parts in a network of CPUF devices are described, wherein the method comprises: establishing secure channels between controllable physical unclonable function (CPUF) devices based on challenge response pair (CRP) data, the CPUF devices defining a network, each CPUF device comprising a physical unclonable function (PUF) circuit controlled by a secure channel handler configured to establish a secret key associated with a secure channel based on CRP data; distributing program parts forming a software application over the secure channels to at least part of the CPUF devices, wherein the program parts need to be executed on the different CPUF devices in a predetermined hierarchical order, the distributing including sending a first program part to a first CPUF device in the network and a second program part to a second CPUF device in the network, the second program part being of a lower hierarchy than the first program part; and, receiving combined proof-of-execution information associated with the distributed execution of the software application, the combined proof-of- execution information including first proof-of-execution information comprising the first program part, first CRP data and a first proof-of-execution and second proof-of-execution information comprising the second program part, second CRP data and a second proof-of- execution, wherein the second proof-of-execution is computed by a second proof generation function of the second CPUF device based on information associated with the second program part, the second execution result and the second CRP data and the first proof-of- execution is computed by a first proof generation function of the first CPUF device based on information about the first program part, the first execution result, the first CRP data and the second proof of execution.
Owner:FORTAEGIS TECHNOLOGIES HOLDING BV

Generating cryptographic information based on device-unique function and physical side-channel measurements

Embodiments include computer-implemented methods for generating one or more cryptographic keys that are uniquely associated with execution of a software program by a computing device comprising a device-unique function (DUF). Such methods include obtaining at least one challenge input for the DUF. The at least one challenge input is based on measurements of side channel information resulting from the execution of the software program on the computing device. Such methods include, using the DUF, generating at least one challenge response based on the respective at least one challenge input. Such methods include generating one or more cryptographic keys based on the at least one challenge response. Other embodiments include computing devices or systems configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Biometry with challenge response pair mechanism

Methods for the encoding an encryption key for secure storage are disclosed. The methods rely on the use of unclonable, one-way functions, such as images of biological objects that may be measured according to challenges to result in responses. A biometric print of a biological object is measured with a set of n challenges resulting in n responses. The responses are an ordered sequence, with each response having a fixed position in the sequence. A key is generated of bit length n. A subset of m responses in the full set of n responses is selected, where the selected responses correspond to positions of is in the key. The response subset is stored. The key is then used, and deleted. A party wishing to re-generate the key generates the same set of challenges, measures the same biological object with the challenges a second time, and generates a second set of n responses. Responses in the stored subset of m responses will match responses in the second set of n responses at certain positions in second set of n responses. These matching positions correspond to 1s in the key. The non-matching positions correspond to 0s. Thus, comparison between the response sets recovers the key.
Owner:BROWN UNIVERSITY +1

A lightweight multi-user multi-factor two-way authentication registration method

The application discloses a kind of lightweight multi-user multi-factor two-way authentication registration method, belong to network security technical field.It includes: each user equipment collects biological characteristics, generates biological characteristic key and public parameter;Each user equipment initiates registration to authentication gateway, and carries out the registration between user equipment;User equipment carries out the transmission of hash operation message authentication code between, realizes the verification between users;First user equipment selects a random number, calculates the value for verification, and sends to authentication gateway;Authentication gateway solves out random number, carries out preliminary verification to each user equipment;Select one of challenge response pair from the registered data, calculate the value for verification, and send to the nth user equipment;User equipment n calculates the value for verification, and sends to authentication gateway;Authentication gateway calculates verification value, completes two-way verification.The application realizes that user equipment is authenticated to authentication gateway two-way, and enhances the security of user authentication.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

Method and system for managing subscription at network function

The disclosure provides a system (108) and a method (400) for managing subscription at a Network Repository Function (NRF) (304). The method (400) includes storing, by the NRF (304), subscription data associated with the subscription of a NF consumer (301) for a validity time. Upon an expiration of the validity time, the method (400) includes implementing, by the NRF (304), a hold timer to retain stored subscription data. Upon an expiration of the hold timer, the method (400) further includes sending, by the NRF (304), a validity challenge request to the NF consumer to verify stored subscription data. Further, the method (400) includes receiving, by the NRF (304), a validity challenge response from the NF consumer (301) corresponding to a status of the validity challenge request. The method (400) further includes updating, by the NRF (304), the stored subscription data at the NRF (304) based on the validity challenge response.
Owner:JIO PLATFORMS LTD

Jewelry transaction public service platform method based on 5G fusion application

The invention relates to the technical field of information indexing and data processing, and discloses a jewelry transaction public service platform method based on 5G fusion application, which comprises the following steps: receiving a re-calibration query request of a query party for verified information pairs in a search engine index database, issuing a new dynamic challenge token to a holder of the information pairs in response to the request, and sending the new dynamic challenge token to the holder of the information pairs; and receiving a 5G challenge response data stream which is uploaded by the holder and contains a real object image and the new token, dynamically refreshing the context verification state of the information pair in the search engine index database after the data stream is verified, and returning the refreshed state to the query party. The problem that the credible state of the high-value information in the index database is attenuated due to time lapse is solved, and the timeliness of information service is guaranteed.
Owner:GUANGDONG JEWELRY & JADE EXCHANGE CENT CO LTD

application identifier

A method for verifying an application configured to execute on a client device. A challenge request is sent to the application. A candidate challenge response is received from the application in response to the challenge request and then provided as input to a verification computation along with a challenge input. Based on an output of the verification computation, it is determined that the candidate challenge response was generated by providing the challenge input to a challenge computation. Based on the determination that the candidate challenge response was generated by providing the challenge input to the challenge computation, the application is verified.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC