Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Fuzzy extractor" patented technology

Fuzzy extractors are a method that allows biometric data to be used as inputs to standard cryptographic techniques for security. "Fuzzy", in this context, refers to the fact that the fixed values required for cryptography will be extracted from values close to but not identical to the original key, without compromising the security required. One application is to encrypt and authenticate users records, using the biometric inputs of the user as a key.

Dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning

The invention relates to a dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning, and belongs to the technical field of digital content security. The problems of attack resistance, traceability obstruction and key-watermark unhooking in document cross-platform circulation are solved. According to the scheme, the method comprises the following steps of: extracting semantic fingerprints by using a sentence vector model Sentence-BERT; the fuzzy extractor generates a master key and derives a time key chain; the authentication encryption algorithm AEAD encrypts and binds the source and the timestamp load; container layer structure rearrangement and document layer zero-width character double embedding are carried out; the generative adversarial network or diffusion model adversarial training improves the optical character recognition and transcoding resistance; version binding and tracing are achieved through the watermark hash chain. The technical effects cover anti-counterfeiting migration, cross-layer fault-tolerant guarantee recoverability, rearrangement attack resistance, full-period accurate traceability and post-quantum security enhancement.
Owner:SOUTHWEST UNIV

Collaborative secret state task matching method based on edge calculation in mobile crowdsourcing

The invention discloses a collaborative secret state task matching method based on edge calculation in mobile crowdsourcing. The method comprises the steps of system initialization and key generation, requester-cloud platform registration authentication, worker-edge server registration authentication, login authentication and attribute submission, requester task issuing, cloud platform task delegation, secret state matching, worker task content decryption, worker answer submission, answer forwarding and decryption. According to the invention, cooperative authentication of workers and requesters and precise task matching based on attributes are realized under an edge-cloud architecture. A fuzzy extractor and an authentication encryption method with associated data are introduced, so that low-cost user local authentication and registration and authentication of a joining system are realized, the security is improved, and the calculation cost is reduced. Through function hidden inner product encryption and a Paillier cryptographic algorithm, task-worker matching and task answer submission are realized in a ciphertext state, and the requirements of a mobile crowdsourcing application scene with high safety, high privacy and dispersed cost are met.
Owner:SHAANXI NORMAL UNIV

Method for implementing mutual authentication protocol based on radio frequency fingerprint and fuzzy extractor

ActiveUS12689528B2EngineeringFuzzy extractor
A mutual authentication protocol based on radio frequency (RF) fingerprint and fuzzy extractor is provided. Two kinds of nodes in the protocol are denoted by authenticator and verifier respectively. In the registration phase, the verifier sends a registration request to the verifier, the verifier receives its RF fingerprint and uses the fuzzy extractor to process it. After storing the help string P related to the verifier, the key generated by R is returned to the verifier, and the verifier stores the key after receiving it. In the authentication phase, the verifier sends an encrypted message containing the challenge value to the verifier. After receiving it, the verifier recovers the key needed for decryption through the fuzzy extractor using the extracted RF fingerprint and the previously stored P value, and returns a reply message to the verifier to achieve the final two-way authentication effect.
Owner:SHANGHAI JIAOTONG UNIV

Internet of vehicles authentication method based on block chain and physical unclonable function

PendingCN121841729AAvoid the risk of identity impersonationImprove resistance to attackKey distribution for secure communicationUser identity/authority verificationPasswordEngineering
The invention discloses an Internet of Vehicles authentication method based on a block chain and a physical unclonable function, and relates to the field of data security, and the method comprises the steps: a vehicle and a communication object complete registration at a roadside base station, and a vehicle end integrates a PUF and a fuzzy extractor to generate a master key bound with equipment; during authentication, the vehicle uses the password, the biological characteristics and the PUF response to perform multi-factor authentication, and submits a Merkle proof of a target communication object to the roadside base station; and the roadside base station verifies the proof and confirms the access authority through the block chain smart contract, and assists the vehicle and the communication object to complete mutual authentication and negotiate the session key. According to the method, the block chain is utilized to ensure that data cannot be tampered, equipment cloning is resisted through the PUF, efficient authorization control is realized in combination with the Merkle tree, pseudo name dynamic updating and identity revocation are supported, and finally, the calculation, communication and storage overhead is remarkably reduced while the security is ensured.
Owner:BEIJING INST OF TECH

PUF fingerprint uniqueness binding method and system based on power network impedance response and storage medium

The invention discloses a hardware fingerprint scheme for unique binding of a vehicle-mounted terminal and a vehicle physical entity, and the scheme is cooperatively executed by the vehicle-mounted terminal and a server: the vehicle-mounted terminal applies a preset excitation sequence to a vehicle power network under a controlled excitation condition and collects voltage and / or current response; extracting impedance spectrum characteristics or time domain impulse response characteristics based on the response signals, and generating stable PUF fingerprints or derived keys in combination with environment compensation, aging compensation and a fuzzy extractor; the vehicle-mounted terminal triggers the security component to execute integrity protection operation on the fingerprint commitment value, the challenge random number and the window identifier to generate a PUF proof and report the PUF proof to the server, wherein the fingerprint commitment value is further bound with the monotonic counter reference information and the compensation version identifier to inhibit parameter rollback and support long-term drift processing; the server verifies the PUF attestation based on challenge-response consistency, threshold determination, and rule version reference, and permits or rejects key business credential generation accordingly. According to the scheme, an adversarial barrier is moved to a hardware-physical characteristic level from a simulatable software message, the counterfeit and simulator attack cost is remarkably improved, and the method is suitable for scenes such as high-value vehicle mortgage, financing lease and insurance risk control.
Owner:郝彦博

A PUF-based decentralized hardware trusted identity generation and authentication method

The application discloses a kind of centerless hardware trust identification generation and authentication method based on PUF, belong to information security technical field.The application relies on the physical unclonable feature of PUF chip, and PUF feature drift is handled by combining error correction code and auxiliary data processing fuzzy extractor, and stable hardware native fingerprint is extracted;Stable characteristics are mixed with double salt factor, and local trusted UID is generated by SM3 algorithm of national secret;Based on UID and PUF feature, unique SM2 key pair is derived by HKDF-SM3 algorithm and validity is verified;Three-level layered key system is constructed, and key derivation is completed using SM4-CBC mode;Trusted UID, dynamic data are combined to complete SM2 signature of national secret, and one-time two-dimensional code is generated to realize double offline authentication;Centerless public key synchronization and authentication result traceability are realized by combining distributed hash table and alliance chain, without central control and special medium, native compatible national secret algorithm, solve the core problem of PUF stability and centerless public key distribution, realize the real centerless hardware trust authentication.
Owner:DIGITAL FRIENDLY SCIENCE & TECHNOLOGY RESEARCH INSTITUTE (BEIJING) CO LTD

User behavior cross-domain tracing authentication method based on fuzzy identity

The invention relates to the technical field of traceable identity authentication, in particular to a user behavior cross-domain traceable authentication method based on fuzzy identity, which comprises the following steps: a trusted issuer generates parameters and creates a decentralized identifier; a user generates a secret value and auxiliary data through a fuzzy extractor based on a real identity, creates an updatable pseudo-name identity through a Hamming distance controlled algorithm, registers to an issuing mechanism and obtains a verifiable certificate binding the real identity and the pseudo-name identity; the user creates a virtual image based on the certificate in the original subsystem and completes intra-domain authentication to update a pseudo name, and when accessing the target subsystem, the original subsystem ensures that cross-domain authentication is completed and a new virtual identity record is established; and when a violation occurs, the original subsystem reconstructs a secret value according to the auxiliary data and analyzes a real identity in combination with a certificate to realize tracing. The problems that cross-domain mutual trust is difficult, and anonymity and traceability are difficult to consider are solved.
Owner:GUIZHOU UNIV

Wireless access authentication method and system

The invention belongs to the technical field of information security, and particularly discloses a wireless access authentication method and system, and the method comprises the steps: a server carries out the registration of a physical unclonable module in a communication device, extracts a challenge response pair, and presets a first challenge and a first random number to the communication device in a secure environment, and completes the system initialization. During authentication, the communication device generates an authentication request based on the device identifier, the first challenge, the first random number and the first real response and sends the authentication request to the server. After the server verifies the authentication hash value in the request, a temporary identity label, a plurality of random numbers and a second challenge are generated, and a pre-stored first response is used as a secret key to generate encrypted information and a hash value and reply the encrypted information and the hash value to the communication device. And after verification and decryption, the local authentication state is updated, a second shared key is generated, and key synchronization is completed. The application can avoid using a fuzzy extractor, significantly reduce resource overhead and improve authentication efficiency.
Owner:WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)

Two-factor authentication method and system

The application relates to the technical field of computer security, and discloses a two-factor authentication method and system, which is a two-factor authentication technology based on biological information and digital signature. The biological information is protected by using a public key encryption scheme of the digital signature and a fuzzy extractor to realize an authentication process, and the two-factor authentication method has the ability to resist replay attacks and malicious server attacks. Specifically, the scheme uses a server to randomly generate a challenge number to resist replay attacks, and uses two-factor authentication of a biological authentication factor and a private key authentication factor to resist malicious user attacks. Meanwhile, the scheme uses a fuzzy extractor to protect biological feature information of a user and uses a public key encryption scheme of the digital signature to protect private key information of the user, so as to resist malicious server attacks. The application significantly improves the security and efficiency of authentication and can better meet the needs of users.
Owner:SHANGHAI JIAOTONG UNIV

A privacy protection identity authentication method and system based on zero-knowledge proof

The application relates to network security and identity authentication, and provides a privacy protection identity authentication method and system based on zero-knowledge proof. A convolutional neural network is trained through a standard face data set to obtain a face detection, alignment and binary feature extraction model; a fuzzy extractor is used to convert high-dimensional binary features into high-entropy key shares and auxiliary data, and the high-entropy key shares and the auxiliary data are secret shared with a random key of a client. During authentication, the client restores the key shares, executes threshold Schnorr signature generation challenge signature with no less than t-1 signature nodes, and completes authentication after verification of the server. The scheme does not need to store original biological feature data, and realizes decentralized, multi-factor, high-security and anti-single-point-failure identity authentication.
Owner:SHUAN COMMERCIAL CRYPTOTECHNOLOGY (GUANGZHOU) CO LTD

Bidirectional authentication system of vehicle-mounted unit and control center of Internet of Vehicles integrated with fuzzy extractor

The invention relates to the technical field of Internet of Vehicles, in particular to an Internet of Vehicles on-board unit and control center bidirectional authentication system integrated with a fuzzy extractor, which comprises a participation entity layer, a core support layer, a business process layer and a safety guarantee layer. According to the IOV on-board unit and control center bidirectional authentication system integrated with the fuzzy extractor, an on-board unit hardware identity identification system is constructed based on a physical unclonable function, a random challenge is generated through the control center, a lightweight PUF chip is built in an OBU to generate a unique response, and a challenge-response pair which cannot be tampered is formed and serves as a hardware identity certificate; on-board unit (OBU) hardware cloning and identity forgery are completely eradicated, entity identity uniqueness is guaranteed from a physical layer, irreversible protection of biological feature privacy is achieved through a bifunction mechanism of an integrated fuzzy extractor and revocable biological feature transformation, three-factor authentication is constructed, and the security is improved. And meanwhile, timestamp validity verification, session key and PUF unclonability are designed to form a full-dimensional security protection system.
Owner:ANHUI NORMAL UNIV

Tamper detection for electronic devices using physical characteristic fingerprinting

Disclosed are methods for electronic device authentication in which distinguishing physical characteristics of electronic devices are converted into unique identification strings (UIDs) that can be used like fingerprints to verify device authenticity. Such methods may be used for tamper detection, for example in combatting warranty fraud. UIDs may be generated from physical characteristics that are unique to a given device, such as imperfections on the device exterior or unique aspects of a circuit board. Images of the device in selected areas or at selected angles may be captured and provided to an algorithm that converts the physical characteristics of the physical device into a UID, for example making use of a fuzzy extractor. When a device is presented for authentication, images of the device may be similarly converted into a verification string that can be checked against the UID.
Owner:SEAGATE TECH LLC

A method, system, device, and medium for physical layer group key generation and distribution for star-shaped Internet of Things (IoT)

This invention provides a method, system, device, and medium for generating and distributing physical layer group keys for star-shaped Internet of Things (IoT). It utilizes channel features extracted during communication as an aid, employing a fuzzy extractor method. The central node inputs channel features into the fuzzy extractor to generate a random key and auxiliary data, while edge nodes input channel features and auxiliary data to the fuzzy extractor to extract the random key. This invention significantly reduces the number of key negotiations, thereby reducing transmission time overhead caused by low transmission rates in long-distance communication. Furthermore, the joint extraction of group keys by all edge nodes avoids the process of first generating paired keys and then gradually XORing them to generate the group key, thus reducing key exchange overhead. Overall, this invention is significant and valuable.
Owner:XI AN JIAOTONG UNIV

Payment authentication method and device, electronic equipment, storage medium and product

The invention relates to the technical field of data processing, and particularly provides a payment authentication method and device, electronic equipment, a storage medium and a product. The method comprises the following steps: receiving order authentication information sent by a target object; wherein the target object comprises a payer and a commodity provider, and the order authentication information comprises an authentication identifier and a first authentication factor determined based on a physical unclonable function (PUF); based on the order authentication information, determining a verification value and a public value of a response value of the target object; wherein the public value is obtained by processing a response value through a fuzzy extractor, and the response value is obtained through calculation based on a PUF function; processing the public value and the verification value through the fuzzy extractor to obtain a first secret value of the target object; and if it is determined that the authentication identifier is the authentication identifier of the target object based on the first secret value, determining that the target object passes authentication, and sending payment reminding information to the target object.
Owner:CHINA MOBILE COMM LTD RES INST +1

Biometric Authentication and Key Negotiation Method Based on Fuzzy Extractor

This invention discloses a biometric authentication and key negotiation method based on a fuzzy extractor, comprising the following steps: (1) Initialization: The server prepares for user registration, including selecting a hash function, defining a cyclic group, and calculating a public-private key pair; (2) User registration: The user extracts biometric information through the fuzzy extractor, generates a registration request based on the password, and sends it to the server. The legitimate user will receive a dynamic identity ID returned by the server; (3) Identity authentication and key negotiation: The registered legitimate user performs two-way identity authentication with the server and negotiates a session key; (4) Password update: When the registered legitimate user needs to update the password, they send a request to the server. This invention achieves anonymous user identity authentication through dynamic ID, which more effectively protects user privacy information from being leaked. Furthermore, by deploying a blockchain, it achieves full lifecycle recording of the user's publicly available biometric information, enabling monitoring and auditing of users and the server.
Owner:HUNAN UNIV OF SCI & TECH