Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

859 results about "Cryptogram" patented technology

A cryptogram is a type of puzzle that consists of a short piece of encrypted text. Generally the cipher used to encrypt the text is simple enough that the cryptogram can be solved by hand. Frequently used are substitution ciphers where each letter is replaced by a different letter or number. To solve the puzzle, one must recover the original lettering. Though once used in more serious applications, they are now mainly printed for entertainment in newspapers and magazines.

Method and device for evaluating password strength in real time

The invention provides a password strength real-time evaluation method and device. The method comprises the following steps: training a polynomial naive Bayesian model through a password data set, wherein the password data set comprises a cracked weak password sample and a verified strong password sample; responding to a trigger event of password input by the user, and extracting character-level features and semantic features of the password input by the user; respectively generating sub-feature vectors according to the character-level features and the semantic features, and weighting the sub-feature vectors to obtain feature vectors; scoring the feature vector by using a trained polynomial naive Bayesian model to obtain a password strength score; and determining a password strength grade according to the password strength score. According to the method provided by the invention, the password strength can be evaluated in real time, and the accuracy of password security evaluation is improved.
Owner:BEIJING VRV SOFTWARE CO LTD

Generating password complexity rules based on attack pattern analysis using hash segmentation

Aspects of the disclosure relate to a network traffic monitoring platform. The platform may train an attack pattern analysis model to output a behavior profile and a cumulative attack score. The platform may identify a password failure rate spike. The platform may extract a password hash from the network traffic. The platform may generate the behavior profile based on the password hash. The platform may generate the cumulative attack score based on the behavior profile. The platform may compare the cumulative attack score to a threshold. Based on identifying that the cumulative attack score is below the threshold, the platform may identify the password hash as a secure hash. Based on identifying that the cumulative attack score meets or exceeds the threshold, the platform may and generate password complexity rules. The platform may refine the attack pattern analysis model based on the attacked hash and the cumulative attack score.
Owner:BANK OF AMERICA CORP

Multi-encryption-based AI glasses security payment method and related device

The invention discloses a multi-encryption-based AI glasses security payment method and a related device, and relates to the field of security payment. In the method, multi-modal biological information of a user is collected, when the multi-modal biological information is consistent with preset biological information, a dynamic password request is sent to bound target equipment, and a dynamic password returned by the target equipment is received and displayed on a display interface; and when the user inputs the dynamic password on the payment interface, encrypting payment information by using a private key to obtain encrypted information, sending the encrypted information to a payment server to decrypt the payment information through the payment server and verify the decrypted data through a block chain network, and when the verification result is successful, sending the encrypted information to the user. Fund transfer is executed according to the payment information; and fund transfer information returned by the payment server is received. By implementing the technical scheme provided by the invention, the payment security and convenience are improved, and information leakage is effectively prevented through a multi-encryption technology.
Owner:GUANGZHOU GUDONG INTELLIGENT TECHNOLOGY CO LTD

Time-based one-time password on authentication token

The disclosed systems and methods are directed to an implementation of time-based authentication with a contactless card based on remotely provisioned timing data. In one described implementation the timing information is provided by an external agent such as a client device and / or a remote verification server associated with the user account. The timing information is then incorporated into a cryptogram generation process executing on the contactless card, resulting in creation of an encrypted time-based token. The authentication request message that includes the time-based authentication token, may be further supplemented by the inclusion of the timing information separately encoded using, for example, public key cryptography. This modification of the authentication request message generated by the contactless card, enables an additional time-based filtering mechanism that may be performed by a third-party client device.
Owner:CAPITAL ONE SERVICES LLC

Commercial password application security assessment evidence identification method based on image identification

The invention discloses a commercial password application security assessment evidence identification method based on image identification, relates to the technical field of image identification, and aims to assess employee advanced engineer certificates, extract information from multi-modal documents by using a Qwen-VL visual language model, generate vectors, label the vectors, convert the vectors into structured evidence nodes and store the structured evidence nodes in a graph database. Establishing various edges according to different associations, and constructing a preliminary evidence network; identifying certificate nodes, and clustering to form a certificate entity group; a correlation score is calculated by searching the support evidence through forward traceability, a correlation score is calculated by searching the contradiction evidence through reverse traceability, the credibility of the certificate entity group is dynamically adjusted, and the influence is propagated according to the updated credibility; and screening abnormal certificates lower than a threshold value, analyzing causes and contradictory points, listing abnormal information, visually displaying key evidences, the contradictory points and associated paths, and generating text description.
Owner:ZHIXUN CIPHER (SHANGHAI) TESTING TECH CO LTD

Using cross workloads signals to remediate password spraying attacks

A method for detecting password spray attacks. The method includes obtaining information from an on-machine malware detection application for a particular machine indicating that a password spray tool is detected on the particular machine. Information is obtained indicating that the particular machine has performed failed sign in attempts. As a result, a determination is made that the particular machine is performing password spray attacks.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Password plaintext risk monitoring system and method based on traffic analysis and large model

The invention discloses a password plaintext risk monitoring system and method based on traffic analysis and a large model. The method comprises the following steps: collecting related basic information based on a traffic background environment to construct a knowledge base; analysis is carried out based on the pre-collected traffic, marking analysis is carried out on field information identified in the traffic, and a prompt word library is generated; the method comprises the following steps: collecting environment traffic, performing traffic analysis on the collected traffic, extracting interaction information in the traffic, performing cleaning and structural processing, and submitting the interaction information to a password plaintext risk identification agent; and the intelligent agent performs analysis through large model capability according to submitted content in combination with a knowledge base and cue words, judges a password plaintext state in the traffic information, and finally generates a risk report and returns the risk report. According to the method, the accuracy of password plaintext risk identification is improved through the intelligent analysis capability of the large model.
Owner:FUJIAN FUJITSU COMM SOFTWARE CO LTD

Context-based deep mail password strength measurement method

The invention provides a context-based deep mail password strength measurement method, which comprises the following steps of: introducing user context information such as an e-mail, a name and a birthday on a basic password measurement model framework, and realizing information fusion through a multi-head self-attention mechanism; and a password sequence probability calculation model is constructed in combination with a character-level long-short-term memory network (LSTM). An evaluation system taking guess times as a core index is established to quantify the performance difference of different models under the condition that whether user context information exists or not. Experiments show that the method can more truly reflect the cracking capability of an attacker when the attacker masters the context information of the user.
Owner:SHENYANG AEROSPACE UNIVERSITY

Filtering passwords based on a plurality of criteria

Provided is a process, including: obtaining a first password to a private computer network; determining, with a credential-monitoring application within the private computer network, whether the first password satisfies one or more criteria by: comparing the first password to a set of compromised credentials within a database within the private computer network; and determining whether the first password matches one or more passwords within the database; and in response to the determination that the first password satisfies the one or more criteria from among the plurality of criteria, causing a use of the first password to access the private computer network to be rejected and causing a first user associated with the first password to be notified to change the first password.
Owner:SPYCLOUD INC

Linear homomorphic digital signature method based on identity on lattice and related equipment

The invention discloses an on-lattice identity-based linear homomorphic digital signature method and related equipment, and belongs to the technical field of information security and passwords, and the method comprises the following steps: S1, generating a public parameter based on a preset security level; s2, calculating a main public key and a main private key based on the public parameters and an NTRU equation; s3, calculating an identity private key based on the main public key, the main private key, the public parameter and the identity id; s4, calculating a signature of the to-be-signed message based on the to-be-signed message, the identity private key and the identity id; s5, performing linear homomorphic operation on the signature of the to-be-signed message based on the public parameter to obtain a homomorphic signature; and S6, verifying whether the signature is passed based on the to-be-signed message, the homomorphic signature, the identity id, the main public key and the public parameter. According to the method, the problem of dependence on a public key certificate management system is solved while the efficient homomorphic operation capability is kept, and more times of linear homomorphic operation are supported, so that the security and practicability of a signature scheme in a quantum computing environment are improved.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Intelligent password key management method and device based on SKF standard

The invention relates to an intelligent password key management method and device based on an SKF standard, and belongs to the technical field of computers. The method comprises the steps that a first interface calling request for a first management interface is received, and the first interface calling request comprises information of a target operation based on a first intelligent password key; if the operation is the equipment layer operation, calling an SKF standard interface corresponding to the target operation to execute the target operation; if the operation is the application layer operation, an SKF standard interface is called to generate an application handle, the application handle is stored in a memory, and the SKF standard interface corresponding to the target operation is called to execute the target operation; if the operation is the container layer operation, calling an SKF standard interface to generate an application handle and a container handle, storing the application handle and the container handle in a memory, and calling the SKF standard interface corresponding to the target operation to execute the target operation. According to the method, the target operation is executed through the packaged interface, so that the development difficulty is reduced, the development convenience and the development efficiency are improved, and the stability of a program and the security of a memory are improved.
Owner:BEIJING LINX SOFTWARE CORP

Encapsulation of payment accounts with tokenization

A method for encapsulating transaction instrument information in a transaction includes storing, in association with a first transaction and by a processor of the primary transaction processor server, transaction data associated with a transaction instrument for a first transaction. The primary transaction processor server transmits the transaction data to a payment network processor, and receives an authorization package in response that includes a cryptograph and a first network token. The primary transaction processor server generates a second token that includes a changeable alpha-numeric string associated with the transaction instrument used in the first transaction, and transmits the second token to a merchant device. The second token indicates that a transaction associated with the second token is either i) a customer-initiated transaction or ii) a merchant-initiated transaction. The secondary transaction processor may approve or reject a transaction using the second token without a cryptogram.
Owner:BLOCK INC

Methods and systems for building rich context for effective password detection in plaintext

The disclosure relates generally to methods and systems for building rich context for effective password detection in plaintext. Detecting and securing plaintext passwords on hard-disk or storage device is difficult as humans generate passwords in a variety of idiosyncratic ways which results in high false negatives and involves a high computation cost. In the present disclosure, a stepped context analysis is performed which applies different context discovery strategies in sequential manner. In scenarios, where a potential password is unable to find in a file using simple detection method, but if the context likelihood of the file is higher than the configured threshold then the file is searched again with more detailed techniques for detecting presence of a potential password. This selective second pass for a few files helps in reducing the false negatives while balancing the proposed solution's performance.
Owner:TATA CONSULTANCY SERVICES LTD

Power business anti-quantum cryptography migration progressive control method based on risk perception

The invention provides a power business anti-quantum cryptography migration progressive control method based on risk awareness, and belongs to the technical field of migration control, and the method comprises the steps: collecting key parameters of all to-be-migrated businesses in a power system, carrying out the standardization preprocessing of the collected key parameters, and constructing a business feature matrix; acquiring relevant parameters of quantum attacks in real time, and calculating a real-time quantum attack risk value of each service to be migrated; based on the service feature matrix and the real-time quantum attack risk value, constructing a dynamic migration rhythm adaptation model, and calculating a migration priority, a migration rate and a migration interval of each service to be migrated; and constructing a migration fault-tolerant and recovery model, monitoring the migration process in real time, calculating a fault influence range and recovery cost based on fault information, and executing corresponding adjustment operation. Accurate, dynamic and high-reliability control of anti-quantum password migration of the power business is realized, safe and stable operation of the power business in the migration process is guaranteed, and the migration efficiency and the anti-quantum attack capability are improved.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

End-to-end encryption with password access

Presented herein are techniques to implement end-to-end encryption. A method includes, encrypting content C with an encryption key EK to obtain encrypted content C′, generating a key encrypting key KEK based on a password, encrypting the encryption key EK with the key encrypting key KEK to obtain an encrypted encryption key EK′, storing the encrypted content C′ and the encrypted encryption key EK′ such that the encrypted content C′ and the encrypted encryption key EK′ are accessible to a content consumer via a link, sending the link and the password to the content consumer, and in response to a request, received via the link, for the encrypted content C′ and the encrypted encryption key EK′, sending the encrypted content C′ and the encrypted encryption key EK′ to the consumer based on the content consumer being on an access control list.
Owner:CISCO TECHNOLOGY INC

Passkey-based authentication for the 3-d secure protocol

Disclosed are various embodiments for integrating the use of passkeys in the 3-D SECURE authentication protocol for transactions. A user of a client device can be prompted to enter a secondary factor of authentication for a second transaction, wherein the prompt includes transaction information and merchant information. In response to a selection to enter the secondary factor of authentication, biometric authentication of the user of the client device can be performed. In response to successful biometric authentication of the second transaction, a challenge comprising the transaction information and the merchant information can be cryptographically signed with a private passkey. The cryptographic signature of the challenge can then be sent to the transaction authorization service.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Passwordless authentication across multiple layers and multiple directory services

In one embodiment, a method includes receiving a first request to access one or more resources in the first network layer. The method may include acquiring first identity information of a first user account specified in the first request. The method may include performing multi-factor authentication of the first user account using the first identity information. In response to authenticating the first user account using the first identity information, the method may include acquiring multiple shares of pre-configured first hidden data from a distributed ledger in the first network layer. The method may include determining a first password from the multiple shares of pre-configured first hidden data and, using the first password, authenticating the first user account to access the one or more resources in the first network layer.
Owner:XAGE SECURITY INC

Secure generation of one-time passcodes using a contactless card

Systems, methods, apparatuses, and computer-readable media for secure generation of one-time passcodes using a contactless card. In one example, an operating system (OS) of a device may receive a uniform resource locator (URL) and a cryptogram from a contactless card. The OS may launch an application associated with the URL. The application may transmit the cryptogram to an authentication server. The application may receive a decryption result from the authentication server indicating the authentication server decrypted the cryptogram. Based on the decryption result, the application may request an OTP. The processor may receive an OTP from an OTP generator. The application may receive an input value and compare the input value to a copy of the OTP. The application may determine that the comparison results in a match, and display, based on the determination that the comparison results in the match, one or more attributes of the account.
Owner:CAPITAL ONE SERVICES LLC

Establishing sessions via a proxy service

A method for managing sessions with an application server via an identity management system is described. The method may include receiving, via an application protocol interface (API) of a cloud service of the identity management system, a first request associated with a first user for user access to an account of the application server. The API may transmit a second request for a secrets service to encrypt a password associated with the first user to a public key of a keypair. The API may receive a message including the encrypted password and forward the encrypted password to an end-client. The identity management system may establish a session on behalf of the first user for the account of the application server based on the end-client having access to a private key of the keypair.
Owner:OKTA INC

A multiple payment tokenized digital transaction authentication method

Following a tokenized consumer-initiated transaction, it is typical for subsequent merchant-initiated transactions to be processed without a cryptogram, causing a real opportunity for fraudulently generated merchant-initiated transactions to be submitted and subsequently processed. The present disclosure provides a method that solves or alleviates this problem. The method comprises: receiving a first transaction request including a payment token, first payment information, a first cryptogram and a next transaction notification identifying a future second transaction; authenticating the first transaction request based at least in part on the first cryptogram; providing an authorization response approval message to authorize the first transaction request; and providing a next transaction cryptogram suitable for use in authenticating a second transaction request.
Owner:MASTERCARD INT INC

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

Method, user device, verifier device, server and system for authenticating user data while preserving user privacy

A method comprises:receiving, by a user device, from a verifier device, a request for user data;retrieving a first cryptogram and a decryption key;sending and, to a server, the first cryptogram;retrieving a random and a second cryptogram generated using reference user authentication data concatenated with the random;sending, to the verifier device, the second cryptogram and the random;storing the reference random;sending, to the user device, the second cryptogram;decrypting the second cryptogram using the decryption key;extracting the reference user authentication data and the random;providing, the user device, with user authentication data;verifying that it matches the reference user authentication data;providing, the verifier device, with the random;verifying that it matches the reference random; andauthenticating the user data.
Owner:THALES DIS CZECH REPUBLIC SRO +1

System and method for secure and performance-optimized management of blockchain-based token life cycle operations

The present invention relates to a system for secure and performance-optimized management of the entire token life cycle operations in decentralized investment ecosystems, especially applicable to blockchain platforms integrating immutable hardware-enforced parameters, trusted execution environments, multi-source price oracles, hybrid mint-and-buyback token allocation mechanisms, and compliance-gated vesting schedules to provide tamper-resistant, revenue-funded investor protection and resilience against network manipulation. The system enforces strict supply and governance safety bounds at the hardware level, preventing any software-based or governance-initiated override of critical operational parameters. The system integrates real-time, TEE-verified oracle feeds, MEV-resistant commit-reveal protocols, and cryptographically verifiable event logging to ensure data integrity, mitigate transaction ordering attacks, maintain compliance throughout the vesting period, and enable efficient off-chain auditing without requiring full-chain scans.
Owner:PITCHMATTER INC

Secure generation of one-time passcodes using a contactless card

Systems, methods, apparatuses, and computer-readable media for secure generation of one-time passcodes using a contactless card. In one example, an operating system (OS) of a device may receive a uniform resource locator (URL) and a cryptogram from a contactless card. The OS may launch an application associated with the URL. The application may transmit the cryptogram to an authentication server. The application may receive a decryption result from the authentication server indicating the authentication server decrypted the cryptogram. Based on the decryption result, the application may request an OTP. The processor may receive an OTP from an OTP generator. The application may receive an input value and compare the input value to a copy of the OTP. The application may determine that the comparison results in a match, and display, based on the determination that the comparison results in the match, one or more attributes of the account.
Owner:CAPITAL ONE SERVICES LLC

Supply system, server, dispenser, and supply method

To provide a supply system that can provide an absorbent article without a registration operation of user information.SOLUTION: A supply system 100 includes a dispenser 5 for an absorbent article A and controllers (processors 11, 51) that control the discharge from the dispenser. The dispenser includes a discharge mechanism that discharges the absorbent article stored therein. The controller is configured to: generate a two-dimensional code including a one-time password generated on the basis of time at a predetermined timing and access information, and cause it to be displayed on a surface of the dispenser (S1); determine whether or not the absorbent article can be provided in response to access from a user terminal that reads the two-dimensional code (S2-1 to 5); and cause a discharge operation to be performed when the determination is affirmative (S6). The determination thereof includes determining whether or not the one-time password included in the access from the user terminal is within a valid period based on a timing of receiving the access from the user terminal.SELECTED DRAWING: Figure 1
Owner:OMOTETE CO LTD

BIOS password retention system and method for replacing a motherboard

Systems and methods for providing a Basic Input / Output System (BIOS) password retention system that may be used for motherboard replacement are disclosed. According to one embodiment, an Information Handling System (IHS) includes computer-executable instructions to, when a replacement motherboard is booted on the HIS, obtain An encrypted BIOS password associated with a previous motherboard that has been removed from the IHS, configure the BIOS password on the replacement motherboard without providing a clear text version of the BIOS pw, and complete booting of the IHS into a normal mode of operation.
Owner:DELL PROD LP

Method and system for quickly switching double-password system

The invention discloses a quick switching method and system for a double-password system. According to the method, a private identifier is generated based on a unique identifier of equipment and biological characteristic information of a user, a double-password system key pair is generated according to the identifier and channel state information, an optimal password system selection result is obtained through security strength and performance evaluation, a switching instruction set is generated, and a block is allocated for privilege; and confirming the final block according to the block privilege, and executing cryptosystem switching. According to the method and the device, the problems of low key generation reliability and low switching efficiency among the password systems in a channel uncertainty environment in the prior art are solved, and a password system switching mechanism with high efficiency is realized while the security is guaranteed.
Owner:CHINA YANGTZE POWER

Anti-quantum cryptography application method and device based on FIDO2.0 standard and related product

The invention provides an anti-quantum cryptography application method and device based on an FIDO 2.0 standard and a related product, and relates to the technical field of information security. According to the method, on the basis of an FIDO2.0 standard specification, two groups of keys, namely a traditional key and an anti-quantum key, are generated by using cryptographic algorithm key derivation through the same random number seed; the two groups of keys are tightly coupled to serve as a composite key for FIDO authentication to be used for a subsequent authentication signature process, so that the anti-quantum security is enhanced; when the composite signature is used, the anti-quantum signature covers the traditional password signature, so that a strong dependency chain of two password algorithms is formed, and the security authentication strength is enhanced; when the signature is verified, the composite public key is used for verifying the traditional signature and the anti-quantum signature, authentication can be passed only when the traditional signature and the anti-quantum signature pass, double security protection of the traditional password technology and the anti-quantum password technology is achieved, and the attack risk of the traditional password in quantum computing is effectively resisted.
Owner:CHINA FINANCIAL CERTIFICATION AUTHORITY

Mobile intelligent node lightweight identity authentication method based on block chain

The invention relates to the technical field of credible authentication, and discloses a mobile intelligent node lightweight identity authentication method based on a block chain, which comprises the following steps: an initialization stage: a credible center generates a public password parameter, and writes a PUF challenge-response table subjected to redundancy coding, a dynamic pseudonym and each entity public key into the block chain; in the message signature stage, a node obtains a random challenge at one time through an intelligent contract, calculates a single-frame signature according to a local PUF response and a public parameter, and broadcasts the single-frame signature; in the authentication stage, the receiver completes decentralized verification according to the on-chain parameters, and if verification fails, the trusted center traces the real identity through pseudonym mapping. According to the method, multiple rounds of handshake are abandoned, only minimum auxiliary data are stored on a chain, anonymity, traceability and low calculation and low communication load of resource-constrained equipment are considered, and the method is suitable for high-dynamic scenes such as Internet of Vehicles and unmanned aerial vehicle clusters.
Owner:CHANGCHUN UNIV OF SCI & TECH