Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

9 results about "Fuzzy extractor" patented technology

Fuzzy extractors are a method that allows biometric data to be used as inputs to standard cryptographic techniques for security. "Fuzzy", in this context, refers to the fact that the fixed values required for cryptography will be extracted from values close to but not identical to the original key, without compromising the security required. One application is to encrypt and authenticate users records, using the biometric inputs of the user as a key.

Method for implementing mutual authentication protocol based on radio frequency fingerprint and fuzzy extractor

ActiveUS12689528B2EngineeringFuzzy extractor
A mutual authentication protocol based on radio frequency (RF) fingerprint and fuzzy extractor is provided. Two kinds of nodes in the protocol are denoted by authenticator and verifier respectively. In the registration phase, the verifier sends a registration request to the verifier, the verifier receives its RF fingerprint and uses the fuzzy extractor to process it. After storing the help string P related to the verifier, the key generated by R is returned to the verifier, and the verifier stores the key after receiving it. In the authentication phase, the verifier sends an encrypted message containing the challenge value to the verifier. After receiving it, the verifier recovers the key needed for decryption through the fuzzy extractor using the extracted RF fingerprint and the previously stored P value, and returns a reply message to the verifier to achieve the final two-way authentication effect.
Owner:SHANGHAI JIAOTONG UNIV

Internet of vehicles authentication method based on block chain and physical unclonable function

PendingCN121841729AAvoid the risk of identity impersonationImprove resistance to attackKey distribution for secure communicationUser identity/authority verificationPasswordEngineering
The invention discloses an Internet of Vehicles authentication method based on a block chain and a physical unclonable function, and relates to the field of data security, and the method comprises the steps: a vehicle and a communication object complete registration at a roadside base station, and a vehicle end integrates a PUF and a fuzzy extractor to generate a master key bound with equipment; during authentication, the vehicle uses the password, the biological characteristics and the PUF response to perform multi-factor authentication, and submits a Merkle proof of a target communication object to the roadside base station; and the roadside base station verifies the proof and confirms the access authority through the block chain smart contract, and assists the vehicle and the communication object to complete mutual authentication and negotiate the session key. According to the method, the block chain is utilized to ensure that data cannot be tampered, equipment cloning is resisted through the PUF, efficient authorization control is realized in combination with the Merkle tree, pseudo name dynamic updating and identity revocation are supported, and finally, the calculation, communication and storage overhead is remarkably reduced while the security is ensured.
Owner:BEIJING INST OF TECH

PUF fingerprint uniqueness binding method and system based on power network impedance response and storage medium

The invention discloses a hardware fingerprint scheme for unique binding of a vehicle-mounted terminal and a vehicle physical entity, and the scheme is cooperatively executed by the vehicle-mounted terminal and a server: the vehicle-mounted terminal applies a preset excitation sequence to a vehicle power network under a controlled excitation condition and collects voltage and / or current response; extracting impedance spectrum characteristics or time domain impulse response characteristics based on the response signals, and generating stable PUF fingerprints or derived keys in combination with environment compensation, aging compensation and a fuzzy extractor; the vehicle-mounted terminal triggers the security component to execute integrity protection operation on the fingerprint commitment value, the challenge random number and the window identifier to generate a PUF proof and report the PUF proof to the server, wherein the fingerprint commitment value is further bound with the monotonic counter reference information and the compensation version identifier to inhibit parameter rollback and support long-term drift processing; the server verifies the PUF attestation based on challenge-response consistency, threshold determination, and rule version reference, and permits or rejects key business credential generation accordingly. According to the scheme, an adversarial barrier is moved to a hardware-physical characteristic level from a simulatable software message, the counterfeit and simulator attack cost is remarkably improved, and the method is suitable for scenes such as high-value vehicle mortgage, financing lease and insurance risk control.
Owner:郝彦博

A PUF-based decentralized hardware trusted identity generation and authentication method

The application discloses a kind of centerless hardware trust identification generation and authentication method based on PUF, belong to information security technical field.The application relies on the physical unclonable feature of PUF chip, and PUF feature drift is handled by combining error correction code and auxiliary data processing fuzzy extractor, and stable hardware native fingerprint is extracted;Stable characteristics are mixed with double salt factor, and local trusted UID is generated by SM3 algorithm of national secret;Based on UID and PUF feature, unique SM2 key pair is derived by HKDF-SM3 algorithm and validity is verified;Three-level layered key system is constructed, and key derivation is completed using SM4-CBC mode;Trusted UID, dynamic data are combined to complete SM2 signature of national secret, and one-time two-dimensional code is generated to realize double offline authentication;Centerless public key synchronization and authentication result traceability are realized by combining distributed hash table and alliance chain, without central control and special medium, native compatible national secret algorithm, solve the core problem of PUF stability and centerless public key distribution, realize the real centerless hardware trust authentication.
Owner:DIGITAL FRIENDLY SCIENCE & TECHNOLOGY RESEARCH INSTITUTE (BEIJING) CO LTD

User behavior cross-domain tracing authentication method based on fuzzy identity

The invention relates to the technical field of traceable identity authentication, in particular to a user behavior cross-domain traceable authentication method based on fuzzy identity, which comprises the following steps: a trusted issuer generates parameters and creates a decentralized identifier; a user generates a secret value and auxiliary data through a fuzzy extractor based on a real identity, creates an updatable pseudo-name identity through a Hamming distance controlled algorithm, registers to an issuing mechanism and obtains a verifiable certificate binding the real identity and the pseudo-name identity; the user creates a virtual image based on the certificate in the original subsystem and completes intra-domain authentication to update a pseudo name, and when accessing the target subsystem, the original subsystem ensures that cross-domain authentication is completed and a new virtual identity record is established; and when a violation occurs, the original subsystem reconstructs a secret value according to the auxiliary data and analyzes a real identity in combination with a certificate to realize tracing. The problems that cross-domain mutual trust is difficult, and anonymity and traceability are difficult to consider are solved.
Owner:GUIZHOU UNIV

Wireless access authentication method and system

The invention belongs to the technical field of information security, and particularly discloses a wireless access authentication method and system, and the method comprises the steps: a server carries out the registration of a physical unclonable module in a communication device, extracts a challenge response pair, and presets a first challenge and a first random number to the communication device in a secure environment, and completes the system initialization. During authentication, the communication device generates an authentication request based on the device identifier, the first challenge, the first random number and the first real response and sends the authentication request to the server. After the server verifies the authentication hash value in the request, a temporary identity label, a plurality of random numbers and a second challenge are generated, and a pre-stored first response is used as a secret key to generate encrypted information and a hash value and reply the encrypted information and the hash value to the communication device. And after verification and decryption, the local authentication state is updated, a second shared key is generated, and key synchronization is completed. The application can avoid using a fuzzy extractor, significantly reduce resource overhead and improve authentication efficiency.
Owner:WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)

A privacy protection identity authentication method and system based on zero-knowledge proof

The application relates to network security and identity authentication, and provides a privacy protection identity authentication method and system based on zero-knowledge proof. A convolutional neural network is trained through a standard face data set to obtain a face detection, alignment and binary feature extraction model; a fuzzy extractor is used to convert high-dimensional binary features into high-entropy key shares and auxiliary data, and the high-entropy key shares and the auxiliary data are secret shared with a random key of a client. During authentication, the client restores the key shares, executes threshold Schnorr signature generation challenge signature with no less than t-1 signature nodes, and completes authentication after verification of the server. The scheme does not need to store original biological feature data, and realizes decentralized, multi-factor, high-security and anti-single-point-failure identity authentication.
Owner:SHUAN COMMERCIAL CRYPTOTECHNOLOGY (GUANGZHOU) CO LTD

Tamper detection for electronic devices using physical characteristic fingerprinting

Disclosed are methods for electronic device authentication in which distinguishing physical characteristics of electronic devices are converted into unique identification strings (UIDs) that can be used like fingerprints to verify device authenticity. Such methods may be used for tamper detection, for example in combatting warranty fraud. UIDs may be generated from physical characteristics that are unique to a given device, such as imperfections on the device exterior or unique aspects of a circuit board. Images of the device in selected areas or at selected angles may be captured and provided to an algorithm that converts the physical characteristics of the physical device into a UID, for example making use of a fuzzy extractor. When a device is presented for authentication, images of the device may be similarly converted into a verification string that can be checked against the UID.
Owner:SEAGATE TECH LLC

A method, system, device, and medium for physical layer group key generation and distribution for star-shaped Internet of Things (IoT)

This invention provides a method, system, device, and medium for generating and distributing physical layer group keys for star-shaped Internet of Things (IoT). It utilizes channel features extracted during communication as an aid, employing a fuzzy extractor method. The central node inputs channel features into the fuzzy extractor to generate a random key and auxiliary data, while edge nodes input channel features and auxiliary data to the fuzzy extractor to extract the random key. This invention significantly reduces the number of key negotiations, thereby reducing transmission time overhead caused by low transmission rates in long-distance communication. Furthermore, the joint extraction of group keys by all edge nodes avoids the process of first generating paired keys and then gradually XORing them to generate the group key, thus reducing key exchange overhead. Overall, this invention is significant and valuable.
Owner:XI AN JIAOTONG UNIV