Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

11 results about "Dictionary attack" patented technology

In cryptanalysis and computer security, a dictionary attack is a form of brute force attack technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by trying hundreds or sometimes millions of likely possibilities, such as words in a dictionary.

Asymmetric password authentication key negotiation method and system

The invention relates to the field of network security, and discloses an asymmetric password authentication key negotiation method and system for improving security. According to the method, the hash value of the user password is used as a generation seed of the public and private key pair, and the password is directly associated with the key, so that the defense capability of the system to server leakage is improved. Furthermore, the invention provides a dual encryption strategy, and symmetric encryption is carried out on the ciphertext encrypted by the public key, so that off-line dictionary attack is effectively prevented, and even if data is leaked, an attacker cannot recover a user password. The two measures significantly improve the security of data transmission and user verification, and effectively prevent information leakage and unauthorized access.
Owner:SHANGHAI JIAOTONG UNIV

Privacy intersection method, device and equipment based on salting hash, medium and product

The invention provides a privacy intersection method and device based on salting hash, equipment, a medium and a product. The method comprises the following steps: acquiring a first initial data set and a first salt value of a first participant, and a second initial data set and a second salt value of a second participant; respectively processing the first initial data set and the second initial data set according to the first salt value and the second salt value to obtain a first salted hash data set and a second salted hash data set; sending the first salted hash data set to the second participant, and sending the second salted hash data set to the first participant to obtain a data intersection; and the data intersection is subjected to bucket processing and hash value comparison to obtain the privacy intersection data, so that the dictionary attack resistance of the data is enhanced, and the security and accuracy of the privacy intersection data are improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Identity verification method and system

The invention discloses an identity verification method and system, and the method comprises the steps: generating a verification result through a verification algorithm after an identity verification server receives an identity verification request; when the verification result is successful, generating a legal identity certificate; and when the verification result is failure, generating a counterfeit identity certificate, and generating at least one of counterfeit reasonable data, counterfeit reasonable authority and counterfeit reasonable abnormity. The method has the core advantages that fake reasonable information is returned when verification fails, so that illegal visitors cannot deduce correct identity information by using failure feedback and cannot distinguish the authenticity of acquired data, authority or abnormal prompts, illegal behaviors such as library collision attacks and brute force cracking are effectively avoided, and the safety of the visitors is improved. The defect that key information is leaked due to failure feedback in the traditional identity verification technology is overcome, and the security of system data and functions is remarkably improved.
Owner:要宇轩

Password-based authenticated key agreement on grids

The application provides a password-based authentication key agreement method based on a lattice, which allows a user to use a password to agree with a server on a session key and authenticate the user identity. The method is constructed based on an ideal lattice, and its security is established on a ring-based learning problem with errors, so that the method can effectively resist quantum attacks. The user's credentials are saved in the form of password-encrypted in the server end, and only the user with the correct password can decrypt the legal credentials and establish the subsequent session key. When the session key is established, the user and the server perform an authenticated key exchange with a key hiding attribute to prevent the user's credential information from being leaked. Even if an enemy obtains the user's password-encrypted credential ciphertext and exhaustively searches the password space to decrypt the ciphertext to obtain a possible user credential set, the correct password corresponding to the credential cannot be identified from the set, so the application can resist offline dictionary attacks. In addition, two-way key confirmation can ensure the consistency of the session key and verify the user identity.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

SM3 and SM4-based data flow encryption authentication method and application

The invention discloses a data flow encryption authentication method and application based on SM3 and SM4. The core of the scheme comprises the following steps: introducing a salt value algorithm when a secret key is generated, splicing a secret character string and a random salt value, then carrying out SHA-256 Hash operation, intercepting first 16 bytes as an SM4 secret key, and enhancing dictionary attack resistance; key exchange is realized based on an SM2 asymmetric encryption algorithm, a sender transmits a public key to a receiver, the receiver encrypts an SM4 key and then returns the SM4 key, and secure transmission of the key is ensured through decryption of a private key; during data processing, fragmentation is carried out according to a preset size, multiple threads are adopted to carry out independent SM4 encryption on each fragment, and after combination, a ciphertext abstract is generated through an SM3 algorithm to verify integrity. According to the scheme, through salt value enhancement, SM2 key protection, multi-thread optimization and SM3 authentication, the problems of key management, transmission security and large file processing efficiency are solved, the method is suitable for scenes such as cloud computing, financial transactions and the Internet of Things, and confidentiality, integrity and availability guarantee is provided for data circulation.
Owner:GUIZHOU UNIV

A blockchain-based cross-domain authentication system for vehicle networking identities

The present invention relates to the technical field of vehicle networking, and in particular to a vehicle networking identity cross-domain authentication system based on blockchain. The system includes an identity management module, a blockchain network module, an authentication service module, and a data sharing module. Since the existence of anti-dictionary attack and anti-brute force attack has no influence on the validity of the signature result, when the signature request is verified and passed, the monitoring unit further monitors the signature request frequency and random number generation mode in real time, discovers and warns of frequent signature requests and abnormal random number generation in a timely manner, prevents private key leakage and signature forgery, and biometric verification can effectively prevent illegal access to the vehicle networking system, further improving the security of the system. Using blockchain technology to achieve cross-domain identity authentication, supporting interoperability and data sharing between different trust domains, vehicle users only need to send the previously obtained credentials to complete cross-domain authentication, simplifying the authentication process.
Owner:BEIJING UNIV OF TECH

Hybrid password cracking method combining neural network model and Hashcat

The invention discloses a hybrid password cracking method combining a neural network model and Hashcat, and the method comprises the steps: training a general neural network model in advance based on a password data set, carrying out the fine tuning of the general model through a short password and a long password, and constructing two exclusive models suitable for the short password and the long password; generating long password data and short password data by using an exclusive model, taking the long password data as a dictionary of dictionary attack, and mapping the short password data into masks according to a mask rule of Hashcat to generate a mask list; and aiming at a to-be-cracked target password hash value, cracking the target password hash value by combining a Hashcat mask attack mode with the mask list, cracking the target password hash value by combining a Hashcat dictionary attack mode with the dictionary, and returning a successfully cracked password. The invention aims to combine the neural network model and the Hashcat to realize password cracking so as to improve the cracking success rate and optimize the utilization of computing resources.
Owner:NAT UNIV OF DEFENSE TECH

Intranet security defense method and system based on weak password linkage risk

PendingCN122069062ASecuring communicationAttackDictionary attack
The invention discloses an intranet security defense method and system based on weak password linkage risk. The method comprises the following steps: performing weak password risk identification including account enumeration vulnerability detection, weak password dictionary attack simulation and password strategy compliance check on a boundary system, and generating a risk level report; performing high-risk function scanning, system version checking and patch checking vulnerability detection on the risk boundary system, and performing association evaluation based on the detected vulnerability and the identified weak password risk; intranet transverse movement behavior monitoring including springboard host recognition, abnormal access detection, sensitive information leakage monitoring and transverse penetration behavior recognition is carried out for the risk boundary system; and carrying out linkage defense response including real-time blocking, voucher security reinforcement, intranet access control and emergency response report aiming at a weak password linkage attack event. By constructing a full-link closed-loop defense system, the security linkage of internal and external networks is improved, and the vulnerability recognition precision and the active defense capability are improved.
Owner:XIAN THERMAL POWER RES INST CO LTD

Multi-user information sharing method and system based on probabilistic asymmetric encryption protocol

PendingCN121967019AImmunity to attackImprove analysis resistanceKey distribution for secure communicationPublic key for secure communicationChosen-plaintext attackData pack
The invention discloses a multi-user information sharing method and system based on a probabilistic asymmetric encryption protocol, which introduces a cryptographic security random number and a public quadratic polynomial parameter on the basis of a standard RSA, and generates a ciphertext tuple containing a randomized component through nonlinear mapping, thereby realizing probabilistic encryption, and improving the security of the cryptographic security random number and the public quadratic polynomial parameter. Dictionary attacks and selected plaintext attacks are effectively resisted; in the decryption process, a quadratic congruence equation is constructed, and a plaintext is recovered by using a Tonelli-Shanks algorithm and a Chinese remainder theorem. A forced circulation mechanism of'hop-by-hop decryption-re-encryption 'is adopted to ensure that a data packet of each circulation link has uniqueness and identity binding characteristics, so that accurate tracing of internal data leakage is realized, and meanwhile, the data is ensured not to be tampered through a closed-loop integrity verification mechanism.
Owner:NANJING UNIV OF POSTS & TELECOMM

Hybrid Password Cracking Method Combining Neural Network Model and Hashcat

The present invention discloses a hybrid password cracking method combining a neural network model and Hashcat. The method of the present invention includes pre-training a general neural network model based on a password data set, fine-tuning the general model with short passwords and long passwords respectively to construct two exclusive models applicable to short passwords and long passwords; using the exclusive models to generate long and short password data, the long password data is used as the dictionary for dictionary attack, and the short password data is mapped into masks according to the mask rules of Hashcat to generate a mask list; for the target password hash value to be cracked, the target password hash value is cracked through the Hashcat mask attack mode in combination with the mask list, and the target password hash value is cracked through the Hashcat dictionary attack mode in combination with the dictionary, and the cracked password is returned. The purpose of the present invention is to combine a neural network model and Hashcat to achieve password cracking so as to improve the cracking success rate and optimize the utilization of computing resources.
Owner:NAT UNIV OF DEFENSE TECH

Security authentication method and apparatus applied to Wi-Fi

This application provides a security authentication method and apparatus applied to Wi-Fi. An access point AP negotiates, based on a password, a pairwise master key PMK with a first device based on a twin base password encrypted key exchange TBPEKE protocol, where the password is a shared key between the AP and the first device; and the AP performs a 4-way handshake with the first device based on the PMK. Therefore, in embodiments of this application, a PMK with a high entropy value can be generated by performing a TBPEKE procedure, so that the security authentication method provided in embodiments of this application can help resist an offline dictionary attack.
Owner:HUAWEI TECH CO LTD