Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

675 results about "Cryptogram" patented technology

A cryptogram is a type of puzzle that consists of a short piece of encrypted text. Generally the cipher used to encrypt the text is simple enough that the cryptogram can be solved by hand. Frequently used are substitution ciphers where each letter is replaced by a different letter or number. To solve the puzzle, one must recover the original lettering. Though once used in more serious applications, they are now mainly printed for entertainment in newspapers and magazines.

Commercial password application security assessment evidence identification method based on image identification

The invention discloses a commercial password application security assessment evidence identification method based on image identification, relates to the technical field of image identification, and aims to assess employee advanced engineer certificates, extract information from multi-modal documents by using a Qwen-VL visual language model, generate vectors, label the vectors, convert the vectors into structured evidence nodes and store the structured evidence nodes in a graph database. Establishing various edges according to different associations, and constructing a preliminary evidence network; identifying certificate nodes, and clustering to form a certificate entity group; a correlation score is calculated by searching the support evidence through forward traceability, a correlation score is calculated by searching the contradiction evidence through reverse traceability, the credibility of the certificate entity group is dynamically adjusted, and the influence is propagated according to the updated credibility; and screening abnormal certificates lower than a threshold value, analyzing causes and contradictory points, listing abnormal information, visually displaying key evidences, the contradictory points and associated paths, and generating text description.
Owner:ZHIXUN CIPHER (SHANGHAI) TESTING TECH CO LTD

Using cross workloads signals to remediate password spraying attacks

A method for detecting password spray attacks. The method includes obtaining information from an on-machine malware detection application for a particular machine indicating that a password spray tool is detected on the particular machine. Information is obtained indicating that the particular machine has performed failed sign in attempts. As a result, a determination is made that the particular machine is performing password spray attacks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Password plaintext risk monitoring system and method based on traffic analysis and large model

The invention discloses a password plaintext risk monitoring system and method based on traffic analysis and a large model. The method comprises the following steps: collecting related basic information based on a traffic background environment to construct a knowledge base; analysis is carried out based on the pre-collected traffic, marking analysis is carried out on field information identified in the traffic, and a prompt word library is generated; the method comprises the following steps: collecting environment traffic, performing traffic analysis on the collected traffic, extracting interaction information in the traffic, performing cleaning and structural processing, and submitting the interaction information to a password plaintext risk identification agent; and the intelligent agent performs analysis through large model capability according to submitted content in combination with a knowledge base and cue words, judges a password plaintext state in the traffic information, and finally generates a risk report and returns the risk report. According to the method, the accuracy of password plaintext risk identification is improved through the intelligent analysis capability of the large model.
Owner:FUJIAN FUJITSU COMM SOFTWARE CO LTD

Context-based deep mail password strength measurement method

The invention provides a context-based deep mail password strength measurement method, which comprises the following steps of: introducing user context information such as an e-mail, a name and a birthday on a basic password measurement model framework, and realizing information fusion through a multi-head self-attention mechanism; and a password sequence probability calculation model is constructed in combination with a character-level long-short-term memory network (LSTM). An evaluation system taking guess times as a core index is established to quantify the performance difference of different models under the condition that whether user context information exists or not. Experiments show that the method can more truly reflect the cracking capability of an attacker when the attacker masters the context information of the user.
Owner:SHENYANG AEROSPACE UNIVERSITY

Filtering passwords based on a plurality of criteria

Provided is a process, including: obtaining a first password to a private computer network; determining, with a credential-monitoring application within the private computer network, whether the first password satisfies one or more criteria by: comparing the first password to a set of compromised credentials within a database within the private computer network; and determining whether the first password matches one or more passwords within the database; and in response to the determination that the first password satisfies the one or more criteria from among the plurality of criteria, causing a use of the first password to access the private computer network to be rejected and causing a first user associated with the first password to be notified to change the first password.
Owner:SPYCLOUD INC

Intelligent password key management method and device based on SKF standard

The invention relates to an intelligent password key management method and device based on an SKF standard, and belongs to the technical field of computers. The method comprises the steps that a first interface calling request for a first management interface is received, and the first interface calling request comprises information of a target operation based on a first intelligent password key; if the operation is the equipment layer operation, calling an SKF standard interface corresponding to the target operation to execute the target operation; if the operation is the application layer operation, an SKF standard interface is called to generate an application handle, the application handle is stored in a memory, and the SKF standard interface corresponding to the target operation is called to execute the target operation; if the operation is the container layer operation, calling an SKF standard interface to generate an application handle and a container handle, storing the application handle and the container handle in a memory, and calling the SKF standard interface corresponding to the target operation to execute the target operation. According to the method, the target operation is executed through the packaged interface, so that the development difficulty is reduced, the development convenience and the development efficiency are improved, and the stability of a program and the security of a memory are improved.
Owner:BEIJING LINX SOFTWARE CORP

Methods and systems for building rich context for effective password detection in plaintext

The disclosure relates generally to methods and systems for building rich context for effective password detection in plaintext. Detecting and securing plaintext passwords on hard-disk or storage device is difficult as humans generate passwords in a variety of idiosyncratic ways which results in high false negatives and involves a high computation cost. In the present disclosure, a stepped context analysis is performed which applies different context discovery strategies in sequential manner. In scenarios, where a potential password is unable to find in a file using simple detection method, but if the context likelihood of the file is higher than the configured threshold then the file is searched again with more detailed techniques for detecting presence of a potential password. This selective second pass for a few files helps in reducing the false negatives while balancing the proposed solution's performance.
Owner:TATA CONSULTANCY SERVICES LTD

Power business anti-quantum cryptography migration progressive control method based on risk perception

The invention provides a power business anti-quantum cryptography migration progressive control method based on risk awareness, and belongs to the technical field of migration control, and the method comprises the steps: collecting key parameters of all to-be-migrated businesses in a power system, carrying out the standardization preprocessing of the collected key parameters, and constructing a business feature matrix; acquiring relevant parameters of quantum attacks in real time, and calculating a real-time quantum attack risk value of each service to be migrated; based on the service feature matrix and the real-time quantum attack risk value, constructing a dynamic migration rhythm adaptation model, and calculating a migration priority, a migration rate and a migration interval of each service to be migrated; and constructing a migration fault-tolerant and recovery model, monitoring the migration process in real time, calculating a fault influence range and recovery cost based on fault information, and executing corresponding adjustment operation. Accurate, dynamic and high-reliability control of anti-quantum password migration of the power business is realized, safe and stable operation of the power business in the migration process is guaranteed, and the migration efficiency and the anti-quantum attack capability are improved.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

End-to-end encryption with password access

Presented herein are techniques to implement end-to-end encryption. A method includes, encrypting content C with an encryption key EK to obtain encrypted content C′, generating a key encrypting key KEK based on a password, encrypting the encryption key EK with the key encrypting key KEK to obtain an encrypted encryption key EK′, storing the encrypted content C′ and the encrypted encryption key EK′ such that the encrypted content C′ and the encrypted encryption key EK′ are accessible to a content consumer via a link, sending the link and the password to the content consumer, and in response to a request, received via the link, for the encrypted content C′ and the encrypted encryption key EK′, sending the encrypted content C′ and the encrypted encryption key EK′ to the consumer based on the content consumer being on an access control list.
Owner:CISCO TECHNOLOGY INC

Passkey-based authentication for the 3-d secure protocol

Disclosed are various embodiments for integrating the use of passkeys in the 3-D SECURE authentication protocol for transactions. A user of a client device can be prompted to enter a secondary factor of authentication for a second transaction, wherein the prompt includes transaction information and merchant information. In response to a selection to enter the secondary factor of authentication, biometric authentication of the user of the client device can be performed. In response to successful biometric authentication of the second transaction, a challenge comprising the transaction information and the merchant information can be cryptographically signed with a private passkey. The cryptographic signature of the challenge can then be sent to the transaction authorization service.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Passwordless authentication across multiple layers and multiple directory services

In one embodiment, a method includes receiving a first request to access one or more resources in the first network layer. The method may include acquiring first identity information of a first user account specified in the first request. The method may include performing multi-factor authentication of the first user account using the first identity information. In response to authenticating the first user account using the first identity information, the method may include acquiring multiple shares of pre-configured first hidden data from a distributed ledger in the first network layer. The method may include determining a first password from the multiple shares of pre-configured first hidden data and, using the first password, authenticating the first user account to access the one or more resources in the first network layer.
Owner:XAGE SECURITY INC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

Method, user device, verifier device, server and system for authenticating user data while preserving user privacy

A method comprises:receiving, by a user device, from a verifier device, a request for user data;retrieving a first cryptogram and a decryption key;sending and, to a server, the first cryptogram;retrieving a random and a second cryptogram generated using reference user authentication data concatenated with the random;sending, to the verifier device, the second cryptogram and the random;storing the reference random;sending, to the user device, the second cryptogram;decrypting the second cryptogram using the decryption key;extracting the reference user authentication data and the random;providing, the user device, with user authentication data;verifying that it matches the reference user authentication data;providing, the verifier device, with the random;verifying that it matches the reference random; andauthenticating the user data.
Owner:THALES DIS CZECH REPUBLIC SRO +1

System and method for secure and performance-optimized management of blockchain-based token life cycle operations

The present invention relates to a system for secure and performance-optimized management of the entire token life cycle operations in decentralized investment ecosystems, especially applicable to blockchain platforms integrating immutable hardware-enforced parameters, trusted execution environments, multi-source price oracles, hybrid mint-and-buyback token allocation mechanisms, and compliance-gated vesting schedules to provide tamper-resistant, revenue-funded investor protection and resilience against network manipulation. The system enforces strict supply and governance safety bounds at the hardware level, preventing any software-based or governance-initiated override of critical operational parameters. The system integrates real-time, TEE-verified oracle feeds, MEV-resistant commit-reveal protocols, and cryptographically verifiable event logging to ensure data integrity, mitigate transaction ordering attacks, maintain compliance throughout the vesting period, and enable efficient off-chain auditing without requiring full-chain scans.
Owner:PITCHMATTER INC

Secure generation of one-time passcodes using a contactless card

Systems, methods, apparatuses, and computer-readable media for secure generation of one-time passcodes using a contactless card. In one example, an operating system (OS) of a device may receive a uniform resource locator (URL) and a cryptogram from a contactless card. The OS may launch an application associated with the URL. The application may transmit the cryptogram to an authentication server. The application may receive a decryption result from the authentication server indicating the authentication server decrypted the cryptogram. Based on the decryption result, the application may request an OTP. The processor may receive an OTP from an OTP generator. The application may receive an input value and compare the input value to a copy of the OTP. The application may determine that the comparison results in a match, and display, based on the determination that the comparison results in the match, one or more attributes of the account.
Owner:CAPITAL ONE SERVICES LLC

BIOS password retention system and method for replacing a motherboard

Systems and methods for providing a Basic Input / Output System (BIOS) password retention system that may be used for motherboard replacement are disclosed. According to one embodiment, an Information Handling System (IHS) includes computer-executable instructions to, when a replacement motherboard is booted on the HIS, obtain An encrypted BIOS password associated with a previous motherboard that has been removed from the IHS, configure the BIOS password on the replacement motherboard without providing a clear text version of the BIOS pw, and complete booting of the IHS into a normal mode of operation.
Owner:DELL PROD LP

Anti-quantum cryptography application method and device based on FIDO2.0 standard and related product

The invention provides an anti-quantum cryptography application method and device based on an FIDO 2.0 standard and a related product, and relates to the technical field of information security. According to the method, on the basis of an FIDO2.0 standard specification, two groups of keys, namely a traditional key and an anti-quantum key, are generated by using cryptographic algorithm key derivation through the same random number seed; the two groups of keys are tightly coupled to serve as a composite key for FIDO authentication to be used for a subsequent authentication signature process, so that the anti-quantum security is enhanced; when the composite signature is used, the anti-quantum signature covers the traditional password signature, so that a strong dependency chain of two password algorithms is formed, and the security authentication strength is enhanced; when the signature is verified, the composite public key is used for verifying the traditional signature and the anti-quantum signature, authentication can be passed only when the traditional signature and the anti-quantum signature pass, double security protection of the traditional password technology and the anti-quantum password technology is achieved, and the attack risk of the traditional password in quantum computing is effectively resisted.
Owner:CHINA FINANCIAL CERTIFICATION AUTHORITY

Mobile intelligent node lightweight identity authentication method based on block chain

The invention relates to the technical field of credible authentication, and discloses a mobile intelligent node lightweight identity authentication method based on a block chain, which comprises the following steps: an initialization stage: a credible center generates a public password parameter, and writes a PUF challenge-response table subjected to redundancy coding, a dynamic pseudonym and each entity public key into the block chain; in the message signature stage, a node obtains a random challenge at one time through an intelligent contract, calculates a single-frame signature according to a local PUF response and a public parameter, and broadcasts the single-frame signature; in the authentication stage, the receiver completes decentralized verification according to the on-chain parameters, and if verification fails, the trusted center traces the real identity through pseudonym mapping. According to the method, multiple rounds of handshake are abandoned, only minimum auxiliary data are stored on a chain, anonymity, traceability and low calculation and low communication load of resource-constrained equipment are considered, and the method is suitable for high-dynamic scenes such as Internet of Vehicles and unmanned aerial vehicle clusters.
Owner:CHANGCHUN UNIV OF SCI & TECH

Method for Secure Access to Digital Data

The invention relates to a method for secure access to digital data, said digital data being encrypted with a given user's public encryption key and stored on a server. The method comprises the following steps:A. receiving at said server a request from said user to access said digital data;B. transmitting, via said server, via a secure communication interface, a request to a secure user device to release a password stored on said user device;C. obtaining said password via said secure communication interface, from said user device in response to a validated security test issued by said user device to a user; andD. retrieving, via said server, the user's encrypted private key, said user's private key being encrypted with said password, and decrypting said user's encrypted private key with said password to obtain that user's private key, and decrypting said encrypted digital data with said user's private key, and presenting said digital data to said user.Another method is provided for new users who do not yet have encryption keys, where the sender temporarily encrypts the digital data and, upon user enrollment, the server re-encrypts the data to the user's public encryption key before proceeding with the server-assisted decryption process.
Owner:MAILSPEC LLC

Tying access / redaction to authentication levels

A media is created. The media may be a document, an image, a video file, an audio file, a real-time communication session, an email, a chat session, and / or the like. The media is associated with a plurality of authentication levels. For example, the media may use a first authentication level that requires a username / password and a second authentication level that requires a fingerprint scan of a user. The media is created based on a security process according to the plurality of authentication levels. For example, the security process may be an encryption process and / or a tokenization process. The media is divided into a plurality of sections based on the plurality of authentication levels. The security process is applied to the plurality of sections based on the plurality of authentication levels.
Owner:MICRO FOCUS LLC

Multistage password protection and operation tracing system of intelligent electric actuating mechanism

The invention discloses a multistage password protection and operation tracing system of an intelligent electric actuating mechanism. The multistage password protection and operation tracing system comprises a multistage authority management module, a password security module, an operation recording module and an authority auditing module, the multi-level permission management module is provided with three levels of permissions and manages distribution, change and switching of the permissions; the password security module manages new establishment, modification, retrieval, storage, error locking and regular replacement of passwords; the operation recording module records all permission-related and equipment control operations; and the permission auditing module retrieves the operation record, generates an auditing report and identifies an abnormal operation behavior. According to the invention, through three-level authority level-to-level management, the operation range is finely divided, and low-authority users are prevented from executing high-risk operations; password cracking and violent attack are resisted through a high-level password security mechanism; through full-operation record coverage and tamper-proof design, operation traceability is realized, and responsibility ownership is clear; and an abnormal behavior analysis and audit report function is realized, and safety risks are actively identified.
Owner:JIANGSU JUSHI DIGITAL TECH CO LTD

Techniques for alternative data exchange mechanisms at terminal devices

Techniques are disclosed for determining data exchange options during a data exchange session. An application executing on a user device can initiate a data exchange session with a terminal device and determine a data exchange account associated with a third party service provider. The application can then obtain, from a server device, a data exchange option corresponding to the data exchange account and provided by the third party service provider. The application can receive an indication that the data exchange option was selected and, responsive to the indication, transmit to the server device a confirmation request associated with the data exchange option. The application can then receive a confirmation that the data exchange option is approved by the third party service provider and responsive to the confirmation, transmit, to the terminal device within the data exchange session, a data cryptogram comprising information usable to identify the data exchange account.
Owner:APPLE INC

Limited-use keys and cryptograms

Techniques for enhancing the security of a communication device when conducting a transaction using the communication device may include encrypting account information with a first encryption key to generate a second encryption key, and encrypting key index information using the second key to generate a limited-use key (LUK). The key index information may include a key index having information pertaining to generation of the LUK. The LUK and the key index can be provided to the communication device to facilitate generation of a transaction cryptogram for a transaction conducted using the communication device, and the transaction can be authorized based on the transaction cryptogram generated from the LUK.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Point of Sale Terminal of A Mobile Device

Disclosed are various embodiments for a point of sale application for a mobile device. In some embodiments, a system comprises a mobile device that is configured to initiate a transaction with a virtual terminal system and provide an identifier of the mobile device to the virtual terminal system. An activation command can be received from the service system. A user interface for the virtual terminal system can be presented for indicating a product for the transaction. The user interface is updated to receive a confirmation for an acceptance of the transaction. The mobile device is configured to generate a cryptogram transmit the cryptogram for the transaction to the service system.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Communications system and methods

A method of securely communicating a message in a communication system comprises receiving, by a secure messaging platform, a message at a receiving step. The receiving step may include at least one of: confirming that the message is secure, encrypting the message, confirming that the message includes a digital signature, or generating and associating a digital signature with the message and its sender. The method includes transmitting, by the secure messaging platform, the message at a transmission step. The method includes delivering, by the secure messaging platform, the message at a delivery step. The message is maintained in a cryptographically secure state during each step of the method, and each encryption and signing operation is logged to enable end-to-end auditability of the message through the receiving, transmission, and / or delivery steps.
Owner:GOLOGIC GRP PTY LTD

Systems and methods for providing secure passwords

Systems and methods for identifying and remedying password insecurities are disclosed. The systems and methods include crawling websites to identify popular cultural terms and saving the cultural terms in a backend system. The cultural terms can include names of celebrities, politicians, movies, and the like. An identification system receives a password and compares the received password to the cultural terms using a similarity score. If the number of similarities is above a predetermined threshold, or if the number of differences is below a predetermined threshold, the identification system denies the password. A recommendation system can generate a suggested password, which can also be compared to the cultural terms. The systems and methods also provide the ability to calculate a similarity score if the cultural terms or passwords are saved in an encrypted or hashed format.
Owner:CAPITAL ONE SERVICES LLC

Digital service authentication using a contactless card

A method, a system, a device, and a computer program product for executing authentication. A user login information associated with using at least one digital service in a plurality of digital services is authenticated. Authentication includes verifying the user login information with at least one digital service, and storing the verified user login information. A cryptogram including the verified user login information is generated. The generated cryptogram including the verified user login information is provided to a contactless card communicatively coupled to at least one processor, causing the generated cryptogram to be stored in a memory location of the contactless card. The generated cryptogram is configured to automatically authenticate the user login information for accessing at least one digital service using the contactless card.
Owner:CAPITAL ONE SERVICES LLC

Secure password generation and management using NFC and contactless smart cards

Various embodiments are directed to securely generating and managing passwords using a near-field communication (NFC) enabled contactless smart card. For example, a secure password may be generated by generating a random number via a random number generator of the contactless smart card and converting the random number to one or more human-readable characters. In another example, a secure cryptographic hash function of the contactless smart card may generate a hash output value, which may be converted to one or more human-readable characters. The human-readable characters may be used as the secure password or it may be transformed to add more layers of security and complexity.
Owner:CAPITAL ONE SERVICES LLC

Weak password cracking method and device, electronic equipment and readable storage medium

The embodiment of the invention provides a weak password cracking method and device, electronic equipment and a readable storage medium, and the method comprises the steps: dynamically positioning a target login component in a target interface through combining image recognition, character recognition, source code analysis and cross-modal verification technologies; automatically capturing a target login request based on a target character string corresponding to the preset account information; for any target password in the weak password dictionary, automatically replacing a user name field in the target login request based on the to-be-tested user name, and automatically replacing a password field in the target login request based on the target password; and when a login success response corresponding to the target login request after field replacement is detected, determining that an original user password corresponding to the to-be-tested user name is a weak password. Through automatic integration of login box dynamic positioning, login request real-time capture, field intelligent replacement and response result verification, dependence on technical experience of testers is reduced, and test efficiency and test accuracy are improved to a certain extent.
Owner:新奥新智科技有限公司

Secure verification of medical status using a contactless card

Systems, methods, articles of manufacture, and computer-readable media for verification of medical status using a contactless card. An application may receive a request specifying a subject and a medical condition. The application may receive a cryptogram from a contactless card. The application may receive a decryption result from a server and determine that the server decrypted the cryptogram. The application may receive, from the contactless card, a medical attestation, a digital signature of the medical attestation, and a public key of the digital signature. The application may decrypt the digital signature based on the public key of the digital signature and verify the medical attestation based on the decrypted digital signature. The application may determine, based on the verification of the medical attestation, that the subject is immune to the medical condition. The application may output a result that the subject is immune to the medical condition.
Owner:CAPITAL ONE SERVICES LLC