Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

13 results about "Guessing attack" patented technology

SM9-based identity-based searchable public key encryption method and system

The invention provides an SM9-based identity-based searchable public key encryption method and an SM9-based identity-based searchable public key encryption system. The system comprises a key generation center, a cloud storage server and a file sending and receiving party. A secret key generation center generates system public and private keys by using an SM9 algorithm, and generates a private key for a user in combination with identity information of the user. The file sender uses the user identity of the receiver and the file keyword to generate a keyword index and uploads the keyword index to the cloud server; when a receiver retrieves the file, the auxiliary parameters in the index are firstly obtained from the cloud server, then a keyword trap door is generated through a private key of the receiver, and the keyword trap door is uploaded to the cloud server; and the server compares the index with the trap door through a matching algorithm, and returns a corresponding ciphertext file to a receiver for decryption if matching succeeds. The secret key generation method is consistent with an SM9 algorithm, the application field of SM9 is expanded, and the safe and efficient searchable public key encryption method which does not need certificate management and can effectively resist internal keyword guessing attacks is achieved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Attribute-based searchable encryption method against keyword-guessing attack based on sm9

This invention provides an attribute-based searchable encryption method based on SM9 to resist keyword guessing attacks. It aims to address the security flaws of existing solutions, which are vulnerable to server-side keyword guessing attacks during encrypted retrieval. By cryptographically binding and randomizing user identity identifiers, attribute sets, and keywords, a complete encryption, retrieval, and verification mechanism is constructed. Its core lies in reconstructing the security trapdoor generation and verification process using the SM9 algorithm, preventing the server from offline enumerating and guessing keywords without proper attribute permission verification. This achieves secure, controllable, and efficient encrypted retrieval while ensuring data confidentiality and user privacy, meeting the urgent needs of smart grids for secure and autonomously controllable data sharing technologies.
Owner:GUILIN UNIV OF ELECTRONIC TECH +1

Forward and backward security searchable encryption method and system supporting access authorization

The invention designs a forward and backward security searchable encryption method and system supporting access authorization. Comprising the steps that when a data owner uploads data, an access control strategy of the data is uploaded at the same time, and the autonomy of a user to the data is improved; before a data user retrieves the data, an access control authorization link is added, fine-grained access control of the encrypted data is achieved, and the practicability and the safety of ciphertext data retrieval are improved; a probabilistic trap door generation algorithm is designed, random numbers are added into trap door information, so that different trap doors are generated in each retrieval, and off-line keyword guessing attacks are resisted; based on a puncturable encryption primitive, an entry is operated to add a label, and a ciphertext with a specific label is deleted by updating a key, so that backward security is realized; and an updatable encryption technology is introduced, and a client key and an encryption database are updated according to an updating strategy, so that the security risk caused by key damage is avoided, and the security of the searchable encryption method is further improved.
Owner:WUHAN UNIV

Public key authenticated encryption method and system for searchable similar data

The application discloses a public key authentication encryption method and system capable of searching similar data. The public key authentication encryption method comprises the following steps: a key generation center generates public and private keys for a data sender and a data user; the data sender encrypts a file and an abstract of the file by using the public and private keys and a public key of the data user, and sends the ciphertext to a cloud server; the data user encrypts the abstract received from the data sender previously by using a private key and a public key of the data sender, and sends the trapdoor to the cloud server; the cloud server performs similar matching on the ciphertext and the trapdoor, and if the matching is less than or equal to n times and a threshold value is reached, the matching is successful, and the cloud server sends the parsed ciphertext to the data sender; the data sender returns updated ciphertext to the data user after processing, and updates a user query frequency list; and the data user decrypts to obtain the file. The application can realize the similar data search function under the premise of guaranteeing resistance to internal and external keyword guessing attacks.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

An improved public-key searchable encryption method, system, and device.

This invention provides an improved public-key searchable encryption method, system, and device, belonging to the field of information security and cryptography. The method first generates a public-private key pair, encrypts keywords with the public key to generate searchable ciphertext, and associates it with stored documents; it receives search requests and trapdoors derived from the private key, returns an index after matching; the client downloads the ciphertext and decrypts it with the private key; it integrates an anti-guessing attack mechanism, preventing the guessing of user interests through access mode hiding; it constructs a dynamic index structure, supporting rapid addition, deletion, and modification of documents, Boolean queries, and multi-user access control. This invention ensures encryption security through public-private key separation and trapdoor mechanisms; the dynamic index supports efficient data operations; anti-guessing attacks and access mode hiding enhance user privacy protection; it is compatible with multiple queries and access control, and is suitable for various scenarios with dual requirements for privacy protection and data availability, such as cloud storage, email systems, and medical and health data management.
Owner:浪潮智能终端有限公司

A public key searchable encryption method and system against internal keyword guessing attacks

This invention discloses a public-key searchable encryption method resistant to internal keyword guessing attacks. It generates system public parameters based on bilinear mapping. The data receiver generates a public-private key pair and publishes the public key. The data sender first selects a random retrieval value, uses the receiver's public key to generate a retrieval encapsulated ciphertext and a keyword ciphertext, and uploads them to a cloud server. The data receiver retrieves the retrieval encapsulated ciphertext from the cloud server, calculates the random retrieval value, uses its own private key combined with the retrieval keyword to generate a keyword trapdoor, and uploads it to the cloud server. The cloud server compares the keyword trapdoor with the keyword ciphertext through a bilinear pairing operation; if a match is found, the corresponding ciphertext data is returned. This invention eliminates the need for the sender to configure any keys, and by using a joint binding mechanism of encrypted retrieval random values ​​and keywords, it fundamentally blocks internal keyword guessing attacks, achieving a highly secure, efficient, and lightweight public-key searchable encryption scheme.
Owner:NANJING UNIV OF POSTS & TELECOMM

End-to-end encrypted cloud storage method with security key management

The invention belongs to a communication technology in a cloud storage system, and provides an end-to-end encryption cloud storage method with a security key management function, which is characterized in that a user can securely reinforce a password by using a portable personal device through combining short authentication string message authentication and an unexpected pseudo-random function. The reinforced password may be used to derive cryptographic keys such as an encryption key and a message authentication code key. An external enemy and a compromised cloud server cannot interact with the equipment to obtain the reinforced password, so that an offline dictionary guessing attack cannot be initiated. In order to meet the requirement that a user retrieves outsourced data from ciphertext data, the user uses a message authentication code to establish an authentication label and uses a dictionary to establish an encrypted index, and verifiable keyword-based rapid ciphertext search is realized by reducing the access times of the dictionary.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Efficient mutual authentication of server and client

Password based authentication is one of the common forms of authentication used in practice. However, when a user / client device enrolls with a server using password information, the authentication process exposes hash of password information to the server which is prone to various types of passwords guessing attacks. Present disclosure provides a system and a method that authenticates a user without revealing his / her password information to a third-party identity provider. This is done by using bilinear parings to authenticate user without sending password information to the server and by way generating client shared secret, server secret, public key, private key and the like. This eliminates the need for storing any keys on multiple devices / third parties or storing password information on the server side.
Owner:TATA CONSULTANCY SERVICES LTD

A three-factor based certificateless identity authentication and key agreement method

The application discloses a three-factor-based certificateless identity authentication and key agreement method, which comprises the following steps: a user registration step, a service server registration step and an authentication step of user login to the service server; the public key self-authentication is used to realize the certificateless trust, the biological characteristics, the password and the smart card are combined, and a more secure and reasonable three-factor identity authentication and key agreement scheme in a multi-server environment is designed; and the user can easily log in to the service server by using his smart card, biological characteristics and password. The application not only effectively avoids various attacks such as disguise attack, password guessing attack and replay attack, and ensures the security, but also guarantees the efficiency of the algorithm by light-weight operation such as a hash function, and can be used in various entity identity authentication fields such as public security, medical treatment and government affairs.
Owner:BEIJING SANSEC TECH DEV

Attribute-based Boolean searchable encryption system and method for resisting quantum attack in cloud environment

The invention relates to an anti-quantum-attack attribute-based Boolean searchable encryption system and method in a cloud environment, provides a lattice-based ABBKS, and adopts a non-monotonic LSSS to express a Boolean query formula to support Boolean query. Only keyword names in the keyword index are disclosed to prevent keyword leakage, and active guessing attacks of attackers on the keywords are defended in a manner of segmenting secret values in the keyword index. Meanwhile, a lattice-based trap door smooth projection hash function is provided, and IKGA security resistance under a multi-user / multi-owner retrieval scene is achieved together with two non-collusion cloud servers. According to the scheme, each keyword in the search token is subjected to hash processing, and only two non-collusion clouds respectively holding a hash key and a TSPHF trap door can complete the search operation together. According to the method, the accurate retrieval of the cloud data is realized, and meanwhile, the balance between the safety and the practicability is realized.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System for detecting password guessing attack

The system for detecting the password guessing attack comprises a data collecting and preprocessing module, a time sequence analysis module, a clustering analysis module, an attack path analysis module and a dynamic risk scoring module. And the data collection and preprocessing module is used for data collection, data preprocessing and data distribution. And the time sequence analysis module is used for analyzing time sequence data by using a multivariable time sequence model and identifying abnormal login behaviors. And the clustering analysis module is used for identifying a user behavior mode and distinguishing a normal login behavior from a potential abnormal behavior. And the attack path analysis module is used for identifying possible attack paths, finding out activity tracks of attackers in the system, constructing an attack path model by adopting a graph theory and a path analysis technology in combination with user behavior data, and discovering potential attack behaviors through algorithm analysis. According to the system, through the modules, the safety and reliability of the password authentication system are remarkably improved, and a user account can be protected from being threatened by password guessing attacks.
Owner:LIAONING UNIVERSITY

Large model attack detection method and device, electronic equipment and storage medium

The invention provides a large model attack detection method and apparatus, an electronic device and a storage medium. The method comprises the steps of obtaining a cue word sequence of a large model input by a user; wherein the cue word sequence comprises a plurality of cue word instructions arranged according to an input time sequence; carrying out attack feature analysis on the cue word sequence; wherein the attack feature analysis comprises at least one of similarity analysis of the cue word instructions, user request frequency analysis, difference analysis of the cue word instructions, repetition analysis of the cue word instructions and information entropy analysis of the cue word instructions; and based on an analysis result corresponding to the at least one attack feature analysis, determining whether the user has a tentative attack behavior aiming at the large model or not. According to the mode, accurate recognition of various tentative attack behaviors such as jail break attacks and guess attacks can be realized, and the operation safety and stability of a large model are guaranteed.
Owner:SHANGHAI DOUXIANG INFORMATION TECH CO LTD

Large model attack detection method and device, electronic equipment and storage medium

The application provides a large model attack detection method and device, electronic equipment and storage medium, the method comprises the following steps: obtaining the prompt word sequence of the user input large model; wherein, the prompt word sequence includes a plurality of prompt word instructions arranged in chronological order; attack feature analysis is performed on the prompt word sequence; wherein, the attack feature analysis includes at least one of the following: similarity analysis of prompt word instructions, user request frequency analysis, difference analysis of prompt word instructions, repetition analysis of prompt word instructions, and information entropy analysis of prompt word instructions; based on the analysis results corresponding to at least one attack feature analysis, it is determined whether the user has exploratory attack behavior against the large model. This way can accurately identify various exploratory attack behaviors such as jailbreaking attacks and guessing attacks, and ensure the running safety and stability of the large model.
Owner:SHANGHAI DOUXIANG INFORMATION TECH CO LTD