Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

71 results about "Challenge response" patented technology

A challenge–response (or C/R) system is a type of spam filter that automatically sends a reply with a challenge to the (alleged) sender of an incoming e-mail. It was originally designed in 1997 by Stan Weatherby, and was called Email Verification. In this reply, the sender is asked to perform some action to assure delivery of the original message, which would otherwise not be delivered. The action to perform typically takes relatively little effort to do once, but great effort to perform in large numbers. This effectively filters out spammers. Challenge–response systems only need to send challenges to unknown senders. Senders that have previously performed the challenging action, or who have previously been sent e-mail(s) to, would be automatically whitelisted.

Anti-counterfeiting traceability system and method based on Beidou satellite positioning and block chain

The invention discloses an anti-counterfeiting traceability system and method based on Beidou satellite positioning and a block chain. The method comprises the following steps: generating a current positioning data tuple; performing validity judgment on the satellite signal quality index; generating current event summary information, performing encryption calculation on the event summary information by using a private key embedded in a commodity and improving a verifiable random function, and outputting a random seed and a verification proof; constructing an event fingerprint and generating an event signature by using a private key; a challenge request is generated when the commodity request state is migrated, the commodity end device responds to the challenge request and collects new Beidou positioning information, and a challenge response data packet is constructed; and performing consistency verification on the challenge response data packet according to the virtual state resume smart contract, writing the verified data into a geographic sub-chain, recording an event abstract hash path by a main chain, and updating a commodity state transfer path. According to the invention, based on Beidou positioning and an improved verifiable random function, the credible verification of the commodity position and the traceable management of the state are realized.
Owner:DALIAN CHANGTAI BEIDOU SATELLITE TECH DEV CO LTD +1

Extending EAP for supporting generative ai challenges

Techniques for extending EAP for supporting generative AI challenge-response for secure access are described. The techniques may be performed at least in part by an authentication server. An indication of a request for a user account to access the network resource via a user device is received. A determination that the user device supports generative AI challenge-response authentication id determined. A posture of the user device is determined. Based at least in part on the device posture, parameters for generating a generative AI challenge-response are determined. The parameters include at least one of a level of hallucination for, and a type of, challenge response to generate, and are transmitted to a generative AI engine. The generative AI challenge-response is received from the generative AI engine and caused to be output by the user device.
Owner:CISCO TECHNOLOGY INC

Data security communication system of Internet of Things

The invention discloses a data security communication system of the Internet of Things, which relates to the technical field of data security communication of the Internet of Things, and comprises the steps of equipment identity authentication, adoption of a Hash encryption and challenge response mechanism, dynamic key negotiation and combination with a Diffie-Hellman algorithm and an equipment operation state to generate a session key; the data encryption transmission uses AES-256 encryption and is transmitted through a TLS1.3 protocol, and abnormal traffic detection and prediction are carried out through DBSCAN clustering and an LSTM model; the data integrity is ensured through double verification of the receiving end; flexible access authority control is realized based on attributes in combination with fuzzy logic; recording an operation log and intelligently analyzing to complete safety audit; secret key updating is triggered according to a period or threat, and a new secret key is protected by a digital signature. According to the method, illegal access is prevented through multiple authentication, confidentiality is enhanced through a dynamic key, threats are intelligently detected, authority is flexibly controlled, logs are effectively audited, the key is updated in time, vulnerabilities are repaired, data leakage and attack loss are reduced, and a safety barrier is built for application of the Internet of Things.
Owner:NANJING TAOTANG INFORMATION TECH CO LTD

Prevent bypassing authentication and authorization checks of microservices in zero trust architecture

A method for microservice authentication includes intercepting, at a first policy engine sidecar of a first microservice, a service request from the first microservice to a second microservice. The service request includes services requested from the second microservice. The method includes generating a transaction challenge, transmitting the service request, a first token identifying the first microservice, and the transaction challenge to the second microservice, and intercepting a service request response from the second microservice to the first microservice. The method includes determining whether the service request response includes a second token identifying the second microservice and a transaction challenge response generated by a second policy engine sidecar of the second microservice, and transmitting the service request response to the first microservice in response to determining the second token identifies the second microservice and determining that the transaction challenge response includes an acceptable transaction challenge response.
Owner:LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD

Multi-mode challenge response identity authentication method and system based on PUF (Physical Unclonable Function)

The invention provides a PUF-based multi-mode challenge response identity authentication method and system, and the method comprises the steps: receiving an authentication instruction, and dynamically determining a dynamic input factor according to a target scene; according to the dynamic input factor and the static factor, using a dynamic weight distribution algorithm to generate a random challenge code fused with scene characteristics; sending the random challenge code to a target device, so that the target device generates a self-adaptive PUF response through a PUF chip, and binding the self-adaptive PUF response with a physical label to generate a composite anti-counterfeiting code; and according to the random challenge code and the composite anti-counterfeiting code, performing identity verification through verification logic. According to the invention, identity authentication based on the PUF in combination with a specific target scene is realized, the method is suitable for multi-scene identity authentication requirements, the calculation overhead is greatly reduced, and the randomness of challenge codes and the scene adaptability are improved.
Owner:HANGZHOU GUZI CULTURE TECHNOLOGY CO LTD

Management method and device for preventing BMS firmware from being flashed

The invention provides a management method and device for preventing BMS firmware from being flashed, and relates to the technical field of asymmetric encryption, and the method comprises the steps: generating a unique response, and reconstructing an equipment root key, so as to establish a trusted firmware execution environment and complete firmware digital signature verification; digital certificate exchange and bidirectional verification of the BMS and the diagnostic instrument are carried out in the trusted firmware execution environment, a dynamic session key is generated, and a challenge response mechanism is executed to ensure that firmware flashing operation is only authorized in the trusted communication environment; performing hash check, control flow monitoring and access auditing by using the security reference data based on the dynamic session key, performing real-time hardware processing when an exception is detected, and recording a security event at the same time; and the BMS uploads the log and attack behavior characteristics corresponding to the security event to a cloud platform, and the cloud platform analyzes and generates a detection rule or certificate revocation list and issues and updates the detection rule or certificate revocation list. Through the dynamic BMS firmware flashing protection method, the safety of the BMS firmware is improved.
Owner:XIAOGAN CORNEX NEW ENERGY INNOVATION TECHNOLOGY CO LTD

Method and apparatus for setting registration between IoT controller and IoT controlee on basis of C2C connection in wireless LAN system of smart home environment

Proposed are a method and an apparatus for setting the registration between an IoT controller and IoT controlee on the basis of a C2C connection in a wireless LAN system of a smart home environment. Particularly, the controlee receives detection information about the controlee from the controller. The controlee transmits a challenge request message for requesting the first information from the controller. The controlee receives a challenge response message including the first information from the controller. The controlee transmits a challenge confirm message to the controller.
Owner:LG ELECTRONICS INC

Unmanned aerial vehicle mobile edge computing security authentication method and system based on identity-based encryption and physical unclonable function

The invention discloses an unmanned aerial vehicle mobile edge computing security authentication method and system based on identity-based encryption and a physical unclonable function, and belongs to the field of mobile edge computing and unmanned aerial vehicle communication security. A physical response is generated in combination with PUF hardware of the unmanned aerial vehicle node, the physical response and the ID are bound as a credible voucher, and meanwhile, a derived private key for IBE is generated for the unmanned aerial vehicle node based on the ID; after the unmanned aerial vehicle is networked, the KGC periodically initiates challenge response verification, the unmanned aerial vehicle generates a current response by using PUF hardware and returns the current response, the KGC performs comparison, and if an abnormality occurs, the KGC broadcasts to a full text to isolate an abnormal node; iBE is directly carried out on the basis of the ID of the receiver in communication between the unmanned aerial vehicles, and certificate exchange overhead is avoided. According to the method, lightweight identity authentication, physical attack resistance and efficient key management under dynamic topology are realized, and the method is suitable for unmanned aerial vehicle edge computing scenes with limited resources.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Resiliency architecture for identity provisioning and verification

Identity access and management (“IAM”) systems with resiliency features and methods related to the same are provided. An identity proxy is interposed between user systems and each of two or more identity provider (“IDP”) systems. The identity proxy routes authentication requests, challenges, and responses between the user systems and the IDP systems based on availability, and verifies challenge responses to permit access to data or services.
Owner:HUMANA INC

SIM based fido authentication

Systems and techniques for authenticating user sign-on at an online service provider using a subscriber identity module (SIM) based authentication process are discussed herein. A user may request to sign-on an online service provider using a user device. The user device may be requested to provide a response to a challenge sent by the online service provider. The online service provider may interface with an identity provider (IDP) to send the challenge. The challenge may be received at a SIM component associated with the user device. The SIM component may generate a challenge response to the challenge, encrypt the response with a first security key associated with the SIM component, and send the encrypted challenge response to the IDP using the OTA component. The IDP may authenticate the encrypted challenge response using a second security key associated with the IDP.
Owner:T MOBILE US INC

Secure data transmission system based on dynamic encryption authentication

According to the secure data transmission system based on dynamic encryption authentication provided by the invention, a trust root which cannot be tampered is established for the whole system through the hardware password module, and continuous derivation and rotation of a session key are realized by the dynamic key management module on the basis, so that the security risk caused by long-term use of a static key is effectively solved. And the secure communication gateway module executes bidirectional authentication and anti-hijacking challenge response by using a dynamic key, so that the real-time credibility and session continuity of the communication process are ensured. And the strategy control engine uniformly coordinates the behaviors of key management and the communication gateway by receiving and compiling the declarative strategy, so that flexible deployment and centralized management and control of the security strategy are realized. According to the system, a cryptographic basis, a dynamic strategy, real-time monitoring and automatic response are deeply fused, a self-adaptive and automatic deep defense system with the capability of continuously resisting advanced threats is constructed, and the overall safety level and the operation efficiency of data transmission are remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Federal learning method and system based on modular component homomorphic encryption and response verification

The invention discloses a federated learning method and system based on modular component homomorphic encryption and response verification, and relates to the technical field of information security, and the method comprises the steps: obtaining an initial global model parameter, and generating a pre-shared key; the client generates a participation key and a calculation key; randomly selecting a plurality of clients as participating clients and sending challenge pairs; the participating client generates a challenge response value based on the pre-shared key and the challenge pair, performs local training based on the initial global model parameter, and encrypts the local model parameter based on the participating key and a mode component homomorphic encryption algorithm to obtain a model parameter ciphertext; carrying out credibility verification based on the challenge response value, and aggregating a credible model parameter ciphertext based on a calculation key to obtain an encrypted global model parameter; and the participating client updates the local model based on the encrypted global model parameters, the process is circulated until the model converges, and a trained global model is obtained. And the encryption calculation efficiency, the response speed and the security robustness of federal learning are improved.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Method, apparatus and device for constructing token for cloud platform resource access control

The present application discloses a method, apparatus and device for constructing a token for cloud platform resource access control. The method includes: acquiring a token application request of an authentication user; according to the token application request, generating an authorization metadata token corresponding to the authentication user; performing digital signature on the authorization metadata token by using a digital certificate, so as to generate a user token; and encrypting the user token by using a user public key, so as to generate an encrypted user token, and sending the encrypted user token and the digital certificate to a client of the authentication user, so that the client performs resource access challenge response by using the authorization metadata token.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Data auditing method and system supporting secure deduplication based on block chain oracle machine

The invention relates to the technical field of information security, in particular to a data auditing method and system supporting secure deduplication based on a block chain oracle machine, and the method comprises the steps: calling the oracle machine through a block chain smart contract, carrying out the encryption and deduplication of the to-be-stored data of a data owner through the oracle machine, uploading the deduplicated encrypted data to a cloud service provider, and carrying out the data auditing through the cloud service provider. Encryption parameters are uploaded to the block chain for storage, and the encryption parameters at least comprise a data owner identity ID, a secret key and a data repetition check hash value; the cloud service provider signs an intelligent contract for auditing, responding and exciting reward and punishment with the oracle machine, pays a corresponding deposit, and stores encrypted data; and the oracle machine periodically sends a data auditing challenge to the cloud service provider, the cloud service provider makes a corresponding challenge response, and the block chain smart contract audits the stored data according to the challenge response. According to the method, the functions of batch auditing, safe deduplication, data recovery and the like can be realized, and the method has higher fault tolerance and adaptability.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Communication method and device

The invention discloses a communication method and a communication device, which are used for supporting and adapting to verification of identifications of network function network elements in an ACME process. The method may comprise the following steps: a network function network element sends an order request, the order request comprising an identifier of the network function network element, the order request being used for requesting creation of an order issuing a first certificate for the identifier of the network function network element; the network function network element can also receive a challenge message, and the challenge message comprises verification mode information which is used for indicating a mode for verifying the identifier of the network function network element in the order; the network function network element can also send a challenge response message according to the verification mode information, the challenge response message comprises an identifier of the network function network element and / or first information obtained according to the identifier of the network function network element, and the identifier of the network function network element and / or the first information are / is used for verifying the identifier of the network function network element in the order; the network function network element may also obtain the first certificate by sending the certificate request message.
Owner:HUAWEI TECH CO LTD

Client-server response time based computer system geolocation

An embodiment sends, at a first time, from a boundary server to a client system in response to a challenge request, a challenge specifying a computational problem to be solved by the client system, the boundary server specified in a challenge list sent to the client system. An embodiment receives, at a second time, at the boundary server, a challenge response from the client system, the challenge response comprising a solution to the computational problem. An embodiment generates, at the boundary server, a certificate encoding an elapsed time between the first time and the second time, the certificate usable by the client system to prove a location of the client system. An embodiment sends, from the boundary server to the client system, the certificate.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Identifying and flagging untrustworthy microservices in zero trust architecture

A method for reporting an untrustworthy microservice includes intercepting, at a first policy engine sidecar of a first microservice, a service request from the first microservice to a second microservice. The service request includes services requested from the second microservice. The method includes generating a transaction challenge and transmitting the service request, a first token identifying the first microservice, and the transaction challenge to the second microservice. The method includes intercepting a service request response from a second microservice to the first microservice and transmitting a microservice alert to a central policy server in response to a service request response failure. The service request response failure includes a failure in determining that the service request response includes a second token properly identifying the second microservice and an acceptable transaction challenge response. The microservice alert includes an identifier of the second microservice and an indication of the service request response failure.
Owner:LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD

Secure human user verification for electronic systems

Systems and methods are provided for a secure human user verification procedure that involves physical manipulation of a user device with respect to its environment. A challenge prompt may be presented for a user to provide challenge response data. A subsystem of an application running on the user device may be configured (e.g., using a machine learning model) to evaluate the challenge response data and determine whether the challenge response data includes the subject of the challenge. To ensure that the user is not providing pre-existing data in response to the challenge prompt, data items associated with the challenge response data may be evaluated to validate the challenge response data as being provided by a human user rather than automatically generated.
Owner:TEALIUM

System and method for authentication in a client-server connection using challenge applied to a secret key

A method for managing an authentication includes establishing, by a server device, a secured network channel with a client, providing, via the secured network channel, a private key to the client, after the providing, obtaining, from the client, a request for establishing a session with the client via a second network channel, in response to the request: sending a challenge request to the client, obtaining a challenge response associated with the challenge request, wherein the challenge response specifies a first challenge answer, performing a challenge processing using a private key to generate a second challenge answer, making a determination, using the first challenge answer and the second challenge answer, that the client is authenticated, and based on the determination, initiating the session with the client.
Owner:DELL PROD LP

Computer system geolocation based on client-server response time

In one embodiment, in response to a challenge request, a challenge is sent from a border server to a client system at a first time, the challenge specifying a computing problem to be solved by the client system, the border server being specified in a list of challenges sent to the client system. One embodiment receives, at a second time, a challenge response from the client system at the border server, the challenge response including a solution to the compute question. One embodiment generates, at a border server, a certificate encoding a time elapsed between a first time and a second time, the certificate being usable by a client system to attestation a location of the client system. In one embodiment, credentials are sent from a border server to a client system.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Communication method and apparatus

A communication method and apparatus, used for supporting and adapting to verification of an identifier of a network function network element in an ACME process. The method may comprise the following steps: a network function network element sends an order request, wherein the order request comprises an identifier of the network function network element, and the order request is used for requesting to create an order for issuing a first certificate for the identifier of the network function network element; the network function network element may also receive a challenge message, wherein the challenge message comprises verification mode information which is used for indicating a mode of verifying the identifier of the network function network element in the order; the network function network element may also send a challenge response message on the basis of the verification mode information, wherein the challenge response message comprises the identifier of the network function network element and / or first information obtained on the basis of the identifier of the network function network element, and the identifier of the network function network element and / or the first information is used for verifying the identifier of the network function network element in the order; and the network function network element may also send a certificate request message to obtain the first certificate.
Owner:HUAWEI TECH CO LTD

A power acquisition terminal device information security protection method and system

The application relates to the technical field of power collection terminal device information security protection, and discloses a power collection terminal device information security protection method and system. The method generates a unique identifier through the hardware characteristics of a collection device to prevent forgery and tampering. High-dimensional transformation improves the feature complexity and enhances the anti-reverse ability. Dynamic disturbance factors make the device identifier change over time to prevent replay attacks. Multi-factor key generation combines hardware characteristics, environmental parameters and time sequence factors to improve the security of the key and avoid cracking. The hierarchical challenge response mechanism enhances security through multiple levels of authentication to prevent attackers from easily bypassing verification. High-dimensional abnormal behavior detection can dynamically identify potential security threats. The multi-stage key update mechanism ensures that the device is kept encrypted for a long time, avoiding the risks caused by key leakage. The whole system works cooperatively to effectively improve the security of device authentication, data encryption and communication.
Owner:BEIJING BONA ELECTRIC CO LTD

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Anti-counterfeiting and traceability system and method based on BeiDou satellite positioning and blockchain

This invention discloses an anti-counterfeiting and traceability system and method based on BeiDou satellite positioning and blockchain, comprising: generating a current positioning data tuple; determining the validity of satellite signal quality indicators; generating a summary of the current event, encrypting the summary using an improved verifiable random function with the private key embedded in the product, and outputting a random seed and verification proof; constructing an event fingerprint and generating an event signature using the private key; generating a challenge request when the product requests a state transition, the product-side device responding to the challenge request and collecting new BeiDou positioning information, constructing a challenge response data packet; performing consistency verification on the challenge response data packet according to a virtual state history smart contract, writing the verified data into the geographic sub-chain, and having the main chain record the event summary hash path and update the product state transition path. This invention, based on BeiDou positioning and an improved verifiable random function, achieves reliable verification of product location and traceable status management.
Owner:DALIAN CHANGTAI BEIDOU SATELLITE TECH DEV CO LTD +1

Construction distribution box door closing interlocking method

The invention relates to the technical field of electrical safety control and power distribution automation, in particular to a construction power distribution box door closing interlocking method, which comprises the following steps of: closing a door body, establishing a session time window and generating a time sequence energy token and session configuration data; according to the session configuration data, active excitation and synchronous acquisition are carried out on a magnetic circuit, electrical capacitance tomography, ultrasonic guided waves, structural vibration and magnetic coding medium fingerprints, an original observation set is formed, and door body magnetic circuit permission indication quantity and fingerprint related characteristics are obtained; constructing a factor graph model to jointly estimate a door gap, contact stiffness, structural damping and a dielectric fill factor, calculating a consistency residual error and challenge response divergence, and generating a physical fingerprint permission indication quantity and a consistency permission indication quantity; permission fusion and closing control are carried out on the same decision edge, sequential statistical monitoring, abnormal tripping and record updating are carried out in the keeping period, and anti-cheating, deterministic judgment and traceable safety locking are achieved.
Owner:HEBEI WATER CONSERVANCY ENG BUREAU GRP CO LTD

Systems and methods for using multi-factor authentication

ActiveUS12718303B2User deviceInternet privacy
An authentication computing device stores a cardholder profile that is associated with a candidate cardholder and includes a cardholder identifier, a device identifier, payment account data, and trusted authentication data in a database system, receives an authentication request that is associated with a tax filing of the candidate cardholder and includes a filing identifier from a revenue computing device, detects the authentication request is associated with the candidate cardholder based upon the filing identifier and the cardholder profile, transmits an identity challenge requesting authentication data associated with the candidate cardholder to a user device associated with the device identifier, receives a challenge response including response authentication data from the user device, determines an authentication status associated with the authentication request based on a comparison of the response authentication data and the trusted authentication data, and transmits the authentication status to the revenue computing device.
Owner:MASTERCARD INT INC

Systems and methods for entangled authentication of biosensors and biosensor outputs

Disclosed herein are systems and methods for entangled authentication of biometric sensors and biometric-sensor outputs. In an embodiment, a secure-biometric-sensor system includes a biometric sensor and a secure element physically bound to one another. The sensor is communicatively interposed between a host and the secure element. The sensor receives a cryptographic challenge from the host and forwards it to the secure element. The sensor captures a biometric reading and transmits it to the host. The sensor receives, from the secure element, a challenge response that includes a shared secret between the host and the secure element. The sensor generates a cryptographically entangled token from a predetermined combination of the shared secret and data specific to the captured biometric reading, and transmits the cryptographically entangled token to the host for use by the host in attempting to authenticate the biometric reading as having been captured by the sensor.
Owner:HID GLOBAL CORP +2

Systems and methods for use in biometric-enabled network interactions

Systems and methods are provided for facilitating network interactions based on user biometrics. One example computer-implemented method includes receiving, from a directory server, a biometric service provider (BSP) assertion having a signature computed using a private key of a BSP, where the BSP assertion includes a biometric ID of a user, and verifying the signature of the BSP assertion using a public key specific to the BSP previously shared with the computing device. The method also includes returning a verification result to the directory server, receiving an access token based on the verification result, and then receiving an authentication creation request from a device specific to the user, which includes the access token. The method further includes determining that the access token is unexpired, providing a challenge to the device, and receiving, from the device, a signed challenge response.
Owner:MASTERCARD INT INC

Key possession based verification in endpoint devices

Methods and systems for securing endpoint devices are disclosed. To secure the endpoint devices, multiple processes for validating authority to invoke performance of commands may be implemented. The processes may include request based processes and challenge response based processes. In the challenge response based processes, an invoker of a command may establish authority for invoking the command by showing possession of a key to which the authority for the command has been delegated and that is usable to verify signatures included in responses to challenges to the invoked commands.
Owner:DELL PROD LP

Smart power grid security authentication method based on ECC and PUF

The invention provides a smart power grid security authentication method based on ECC and PUF. The method comprises the steps that a trusted mechanism carries out initialization setting and issues public parameters, wherein the public parameters are used for generating verification information between the trusted mechanism and a power provider and between the trusted mechanism and a smart electric meter; the intelligent electric meter sends identity information and challenge response information based on the PUF to a trusted mechanism for registration, and the parameters of the intelligent electric meter are distributed to the power provider; and the power provider verifies the timestamp and the verification condition of the intelligent electric meter, the power provider generates a response message and sends the response message to the intelligent electric meter for response, the intelligent electric meter receives the response message for verification, and a shared session key between the intelligent electric meter and the power provider is established for secure communication. By applying the method, a plurality of security targets including mutual authentication, anonymity, session key security, perfect forward confidentiality and resistance to various security attacks can be met, and mutual authentication, session key security, anonymity and perfect forward security are ensured.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO +2