Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

6 results about "Dictionary attack" patented technology

In cryptanalysis and computer security, a dictionary attack is a form of brute force attack technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by trying hundreds or sometimes millions of likely possibilities, such as words in a dictionary.

Privacy intersection method, device and equipment based on salting hash, medium and product

The invention provides a privacy intersection method and device based on salting hash, equipment, a medium and a product. The method comprises the following steps: acquiring a first initial data set and a first salt value of a first participant, and a second initial data set and a second salt value of a second participant; respectively processing the first initial data set and the second initial data set according to the first salt value and the second salt value to obtain a first salted hash data set and a second salted hash data set; sending the first salted hash data set to the second participant, and sending the second salted hash data set to the first participant to obtain a data intersection; and the data intersection is subjected to bucket processing and hash value comparison to obtain the privacy intersection data, so that the dictionary attack resistance of the data is enhanced, and the security and accuracy of the privacy intersection data are improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1

Identity verification method and system

The invention discloses an identity verification method and system, and the method comprises the steps: generating a verification result through a verification algorithm after an identity verification server receives an identity verification request; when the verification result is successful, generating a legal identity certificate; and when the verification result is failure, generating a counterfeit identity certificate, and generating at least one of counterfeit reasonable data, counterfeit reasonable authority and counterfeit reasonable abnormity. The method has the core advantages that fake reasonable information is returned when verification fails, so that illegal visitors cannot deduce correct identity information by using failure feedback and cannot distinguish the authenticity of acquired data, authority or abnormal prompts, illegal behaviors such as library collision attacks and brute force cracking are effectively avoided, and the safety of the visitors is improved. The defect that key information is leaked due to failure feedback in the traditional identity verification technology is overcome, and the security of system data and functions is remarkably improved.
Owner:要宇轩

Password-based authenticated key agreement on grids

The application provides a password-based authentication key agreement method based on a lattice, which allows a user to use a password to agree with a server on a session key and authenticate the user identity. The method is constructed based on an ideal lattice, and its security is established on a ring-based learning problem with errors, so that the method can effectively resist quantum attacks. The user's credentials are saved in the form of password-encrypted in the server end, and only the user with the correct password can decrypt the legal credentials and establish the subsequent session key. When the session key is established, the user and the server perform an authenticated key exchange with a key hiding attribute to prevent the user's credential information from being leaked. Even if an enemy obtains the user's password-encrypted credential ciphertext and exhaustively searches the password space to decrypt the ciphertext to obtain a possible user credential set, the correct password corresponding to the credential cannot be identified from the set, so the application can resist offline dictionary attacks. In addition, two-way key confirmation can ensure the consistency of the session key and verify the user identity.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Intranet security defense method and system based on weak password linkage risk

PendingCN122069062ASecuring communicationAttackDictionary attack
The invention discloses an intranet security defense method and system based on weak password linkage risk. The method comprises the following steps: performing weak password risk identification including account enumeration vulnerability detection, weak password dictionary attack simulation and password strategy compliance check on a boundary system, and generating a risk level report; performing high-risk function scanning, system version checking and patch checking vulnerability detection on the risk boundary system, and performing association evaluation based on the detected vulnerability and the identified weak password risk; intranet transverse movement behavior monitoring including springboard host recognition, abnormal access detection, sensitive information leakage monitoring and transverse penetration behavior recognition is carried out for the risk boundary system; and carrying out linkage defense response including real-time blocking, voucher security reinforcement, intranet access control and emergency response report aiming at a weak password linkage attack event. By constructing a full-link closed-loop defense system, the security linkage of internal and external networks is improved, and the vulnerability recognition precision and the active defense capability are improved.
Owner:XIAN THERMAL POWER RES INST CO LTD

Multi-user information sharing method and system based on probabilistic asymmetric encryption protocol

PendingCN121967019AImmunity to attackImprove analysis resistanceKey distribution for secure communicationPublic key for secure communicationChosen-plaintext attackData pack
The invention discloses a multi-user information sharing method and system based on a probabilistic asymmetric encryption protocol, which introduces a cryptographic security random number and a public quadratic polynomial parameter on the basis of a standard RSA, and generates a ciphertext tuple containing a randomized component through nonlinear mapping, thereby realizing probabilistic encryption, and improving the security of the cryptographic security random number and the public quadratic polynomial parameter. Dictionary attacks and selected plaintext attacks are effectively resisted; in the decryption process, a quadratic congruence equation is constructed, and a plaintext is recovered by using a Tonelli-Shanks algorithm and a Chinese remainder theorem. A forced circulation mechanism of'hop-by-hop decryption-re-encryption 'is adopted to ensure that a data packet of each circulation link has uniqueness and identity binding characteristics, so that accurate tracing of internal data leakage is realized, and meanwhile, the data is ensured not to be tampered through a closed-loop integrity verification mechanism.
Owner:NANJING UNIV OF POSTS & TELECOMM

Security authentication method and apparatus applied to Wi-Fi

This application provides a security authentication method and apparatus applied to Wi-Fi. An access point AP negotiates, based on a password, a pairwise master key PMK with a first device based on a twin base password encrypted key exchange TBPEKE protocol, where the password is a shared key between the AP and the first device; and the AP performs a 4-way handshake with the first device based on the PMK. Therefore, in embodiments of this application, a PMK with a high entropy value can be generated by performing a TBPEKE procedure, so that the security authentication method provided in embodiments of this application can help resist an offline dictionary attack.
Owner:HUAWEI TECH CO LTD