Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Guessing attack" patented technology

Anti-frequency analysis searchable encryption method and system

According to the anti-frequency analysis searchable encryption method and system, a certificateless encryption system is introduced, for a scene with limited computing resources, the scheme is ensured to be safe and suitable for the scene with the limited computing resources, meanwhile, a trap door algorithm is designed based on a probability trap door generation algorithm, and the security of the scheme is improved. The method improves the resistance of a system to frequency analysis attacks, solves the problem of secret key trusteeship due to the fact that identity information and secret key distribution are concentrated in a private key generation center in a traditional encryption scheme, and improves the encryption efficiency. The technical problem that malicious users are easy to obtain the privacy information of the target keyword by performing frequency analysis on trap doors and initiating keyword guessing attacks is solved.
Owner:GUIZHOU UNIV

SM9-based identity-based searchable public key encryption method and system

The invention provides an SM9-based identity-based searchable public key encryption method and an SM9-based identity-based searchable public key encryption system. The system comprises a key generation center, a cloud storage server and a file sending and receiving party. A secret key generation center generates system public and private keys by using an SM9 algorithm, and generates a private key for a user in combination with identity information of the user. The file sender uses the user identity of the receiver and the file keyword to generate a keyword index and uploads the keyword index to the cloud server; when a receiver retrieves the file, the auxiliary parameters in the index are firstly obtained from the cloud server, then a keyword trap door is generated through a private key of the receiver, and the keyword trap door is uploaded to the cloud server; and the server compares the index with the trap door through a matching algorithm, and returns a corresponding ciphertext file to a receiver for decryption if matching succeeds. The secret key generation method is consistent with an SM9 algorithm, the application field of SM9 is expanded, and the safe and efficient searchable public key encryption method which does not need certificate management and can effectively resist internal keyword guessing attacks is achieved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Improved public key searchable encryption method, system and equipment

The invention provides an improved public key searchable encryption method, system and device, and belongs to the technical field of information security and cryptography, the method comprises the following steps: firstly generating a public and private key pair, encrypting a keyword by using a public key to generate a searchable ciphertext, and associating a storage document; receiving a search request and a trap door derived by a private key, and returning an index after matching; the client downloads the ciphertext and decrypts the ciphertext through a private key; an anti-guess attack mechanism is integrated, and user interests are prevented from being speculated through access mode hiding; a dynamic index structure is constructed, and rapid addition, deletion and modification of documents, Boolean query and multi-user permission control are supported. According to the invention, the encryption security is guaranteed through the public and private key separation and trap door mechanism; the dynamic index supports efficient data operation; user privacy protection is enhanced through anti-guess attack and access mode hiding; and the method is compatible with multi-query and authority control, and is suitable for various scenes with dual requirements on privacy protection and data availability, such as cloud storage, e-mail systems, medical health data management and the like.
Owner:浪潮智能终端有限公司

Lattice-based updatable private key password protection secret sharing method

The invention discloses a lattice-based updatable private key password protection secret sharing method. The method comprises the steps of system initialization, a secret recovery method and a secret key share updating method. According to the method, a zero update technology is adopted, password protection secret sharing dynamic key update is achieved, key share update is achieved between servers, the correctness of key update is verified through a Lagrange interpolation polynomial, the key does not affect the value of a master key, the application range is expanded, and the method is suitable for popularization and application. According to the invention, quantum resistance, continuous leakage resistance and online password guess attack resistance are realized, authentication with a plurality of key servers can be carried out securely, an encryption key for decrypting cloud privacy data is reconstructed, user privacy is effectively guaranteed, secure storage and controllable access of data are realized, and key privacy protection is provided for a cloud storage technology. The method has the advantages of being good in robustness, high in secret key updating efficiency, high in reliability, wide in application range and the like, and can be applied to the technical field of privacy of password protection secret sharing.
Owner:SHAANXI NORMAL UNIV

Attribute-based searchable encryption method against keyword-guessing attack based on sm9

This invention provides an attribute-based searchable encryption method based on SM9 to resist keyword guessing attacks. It aims to address the security flaws of existing solutions, which are vulnerable to server-side keyword guessing attacks during encrypted retrieval. By cryptographically binding and randomizing user identity identifiers, attribute sets, and keywords, a complete encryption, retrieval, and verification mechanism is constructed. Its core lies in reconstructing the security trapdoor generation and verification process using the SM9 algorithm, preventing the server from offline enumerating and guessing keywords without proper attribute permission verification. This achieves secure, controllable, and efficient encrypted retrieval while ensuring data confidentiality and user privacy, meeting the urgent needs of smart grids for secure and autonomously controllable data sharing technologies.
Owner:GUILIN UNIV OF ELECTRONIC TECH +1

Forward and backward security searchable encryption method and system supporting access authorization

The invention designs a forward and backward security searchable encryption method and system supporting access authorization. Comprising the steps that when a data owner uploads data, an access control strategy of the data is uploaded at the same time, and the autonomy of a user to the data is improved; before a data user retrieves the data, an access control authorization link is added, fine-grained access control of the encrypted data is achieved, and the practicability and the safety of ciphertext data retrieval are improved; a probabilistic trap door generation algorithm is designed, random numbers are added into trap door information, so that different trap doors are generated in each retrieval, and off-line keyword guessing attacks are resisted; based on a puncturable encryption primitive, an entry is operated to add a label, and a ciphertext with a specific label is deleted by updating a key, so that backward security is realized; and an updatable encryption technology is introduced, and a client key and an encryption database are updated according to an updating strategy, so that the security risk caused by key damage is avoided, and the security of the searchable encryption method is further improved.
Owner:WUHAN UNIV

Anonymous and keyword-guessing-attack-resistant attribute-based rapid ciphertext retrieval method

The invention provides an anonymous and keyword-guessing-attack-resistant attribute-based rapid ciphertext retrieval method, which comprises the following steps that: an authorization center initializes to generate system parameters and a master key, publishes the system parameters, and generates a user key according to attribute information of each user; a data owner generates a data owner public and private key pair and discloses a public key. Before the data owner uploads the encrypted data, attribute-based searchable encryption is carried out on the keyword index. And the data user uses the user key and the keyword to generate a searchable trap door and sends the searchable trap door to the cloud server. And the cloud server matches the encrypted index with the trap door. If the attribute contained in the ciphertext meets the access control strategy in the trap door and the keywords are matched, the matching is successful. According to the method, the calculation efficiency of the algorithm is greatly improved, the communication overhead is reduced, and efficient attribute-based ciphertext retrieval which is anonymous and resistant to keyword guessing attacks is achieved.
Owner:SHAANXI NORMAL UNIV

V2C post-quantum authentication and key agreement method based on RLWE

The present invention discloses a V2C post-quantum authentication and key negotiation method based on RLWE. During system initialization, a master key, public key, hash function, and related parameters are selected. During the registration phase, the vehicle and cloud server CS register with a registration authority RA. During the login phase, the vehicle and CS log in to the local system. During the authentication and key negotiation phase, the vehicle and CS perform identity authentication and key negotiation through the RA, negotiating a session key for subsequent secure communication without revealing their true identity. During the identity and password update phase, users can directly update their identity and password without going through the RA. The present invention is based on ring fault-tolerant learning RLWE and a hash method design, effectively reducing the computational and communication overhead of the AKA process, resisting attacks by quantum adversaries, and ensuring the confidentiality of the true identity of legitimate vehicles. Furthermore, the "fuzzy verifier + honeyword" technology is used in the AKA process to resist signal leakage and key guessing attacks, ensuring key security.
Owner:ANHUI UNIV

A password strength measurement method based on reinforcement learning

The application discloses a password strength measurement method based on reinforcement learning, which comprises the following steps: firstly, constructing a password data set, then establishing a reinforcement learning model and a scoring model, training the reinforcement learning model and the scoring model, and obtaining an optimal reinforcement learning model; after the deployment is completed, a user inputs a password into the optimal reinforcement learning model, and outputs a probability; then the probability is compared with a password probability dictionary through a Monte Carlo calculation algorithm to obtain a guessing number of the password; and finally, according to the corresponding relationship between the guessing number of the password and the password strength, the password strength of the password is obtained. The password modeling method based on reinforcement learning regards the process of generating a password by a user as a Markov decision process, calculates the reward brought by each action, and can better model a password sequence; the application can resist online directional guessing attacks and offline wandering guessing attacks at the same time, and is more accurate and more robust.
Owner:NANKAI UNIV

Public key authenticated encryption method and system for searchable similar data

The application discloses a public key authentication encryption method and system capable of searching similar data. The public key authentication encryption method comprises the following steps: a key generation center generates public and private keys for a data sender and a data user; the data sender encrypts a file and an abstract of the file by using the public and private keys and a public key of the data user, and sends the ciphertext to a cloud server; the data user encrypts the abstract received from the data sender previously by using a private key and a public key of the data sender, and sends the trapdoor to the cloud server; the cloud server performs similar matching on the ciphertext and the trapdoor, and if the matching is less than or equal to n times and a threshold value is reached, the matching is successful, and the cloud server sends the parsed ciphertext to the data sender; the data sender returns updated ciphertext to the data user after processing, and updates a user query frequency list; and the data user decrypts to obtain the file. The application can realize the similar data search function under the premise of guaranteeing resistance to internal and external keyword guessing attacks.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

An improved public-key searchable encryption method, system, and device.

This invention provides an improved public-key searchable encryption method, system, and device, belonging to the field of information security and cryptography. The method first generates a public-private key pair, encrypts keywords with the public key to generate searchable ciphertext, and associates it with stored documents; it receives search requests and trapdoors derived from the private key, returns an index after matching; the client downloads the ciphertext and decrypts it with the private key; it integrates an anti-guessing attack mechanism, preventing the guessing of user interests through access mode hiding; it constructs a dynamic index structure, supporting rapid addition, deletion, and modification of documents, Boolean queries, and multi-user access control. This invention ensures encryption security through public-private key separation and trapdoor mechanisms; the dynamic index supports efficient data operations; anti-guessing attacks and access mode hiding enhance user privacy protection; it is compatible with multiple queries and access control, and is suitable for various scenarios with dual requirements for privacy protection and data availability, such as cloud storage, email systems, and medical and health data management.
Owner:浪潮智能终端有限公司

PAEMKS-based Data Management and Search Method, Device, and System

The present invention discloses a data management and search method based on PAEMKS, including: system initialization, generating system public parameters according to the input security parameters; each participant generating a public-private key pair based on the public parameters, publicly disclosing the public key, and privately hiding the private key; the data owner encrypting the data to be shared based on the public parameters and its own private key to obtain ciphertext data; the data user generating trapdoors for a number of keywords to be queried based on the public parameters and its own private key, and uploading them to the cloud server; the cloud server performing a matching test on the ciphertext data and the trapdoors, and returning the ciphertext data with successful pairing as the search result to the data user. This method can resist external online / offline keyword guessing attacks and keyword guessing attacks initiated by internal malicious servers simultaneously, with high security; and supports the function of multiple keyword retrievals, improving the retrieval efficiency and accuracy, and is applicable to scenarios with multiple receivers, with high practicality.
Owner:XIDIAN UNIV

A Financial System Identity Authentication Method Based on Elliptic Curves

The present invention discloses an identity authentication method for a financial system based on elliptic curves. The identity authentication method is applied in a financial system. This method provides an authentication method for mutual authentication and key verification among a user device, a gateway, and a wireless device carrying the financial system. By introducing elliptic curves to perform encryption operations on key parameters in the authentication process, the security of the entire authentication process is improved, and at the same time, the computing pressure on the wireless device is reduced. Through this identity authentication method, the present invention can effectively resist offline password guessing attacks, session key leakage attacks, and man-in-the-middle attacks, making the entire authentication process safe and efficient, and having high application value especially in the financial management scenario.
Owner:HANGZHOU NORMAL UNIVERSITY

A public key searchable encryption method and system against internal keyword guessing attacks

This invention discloses a public-key searchable encryption method resistant to internal keyword guessing attacks. It generates system public parameters based on bilinear mapping. The data receiver generates a public-private key pair and publishes the public key. The data sender first selects a random retrieval value, uses the receiver's public key to generate a retrieval encapsulated ciphertext and a keyword ciphertext, and uploads them to a cloud server. The data receiver retrieves the retrieval encapsulated ciphertext from the cloud server, calculates the random retrieval value, uses its own private key combined with the retrieval keyword to generate a keyword trapdoor, and uploads it to the cloud server. The cloud server compares the keyword trapdoor with the keyword ciphertext through a bilinear pairing operation; if a match is found, the corresponding ciphertext data is returned. This invention eliminates the need for the sender to configure any keys, and by using a joint binding mechanism of encrypted retrieval random values ​​and keywords, it fundamentally blocks internal keyword guessing attacks, achieving a highly secure, efficient, and lightweight public-key searchable encryption scheme.
Owner:NANJING UNIV OF POSTS & TELECOMM

A lightweight public key authentication encryption method supporting paid query of similar data

The present invention discloses a lightweight public key authenticated encryption method for supporting paid query of similar data, including: the key generation center generates public and private key pairs for the cloud server, the data owner, and the data user; the data owner encrypts the file and its digest to generate ciphertext and stores it in the cloud server; the data user encrypts the previously received digest from the data owner to generate a trapdoor and initiates a query request to the cloud server; the cloud server performs a similarity match between the ciphertext and the trapdoor. If the match is successful, the cloud server deducts the fee of the data user and sends the parsed ciphertext to the data owner; the data owner records the query times of the user and returns the updated ciphertext to the data user after calculation; the data user decrypts to obtain the file. The present invention is not only applicable to mobile devices, but also applicable to the scenario of paid query of similar data, and can also prevent the cloud server and the data user from colluding to deny the deduction of fees, resist adaptive chosen target attacks and internal keyword guessing attacks.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

End-to-end encrypted cloud storage method with security key management

The invention belongs to a communication technology in a cloud storage system, and provides an end-to-end encryption cloud storage method with a security key management function, which is characterized in that a user can securely reinforce a password by using a portable personal device through combining short authentication string message authentication and an unexpected pseudo-random function. The reinforced password may be used to derive cryptographic keys such as an encryption key and a message authentication code key. An external enemy and a compromised cloud server cannot interact with the equipment to obtain the reinforced password, so that an offline dictionary guessing attack cannot be initiated. In order to meet the requirement that a user retrieves outsourced data from ciphertext data, the user uses a message authentication code to establish an authentication label and uses a dictionary to establish an encrypted index, and verifiable keyword-based rapid ciphertext search is realized by reducing the access times of the dictionary.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Efficient mutual authentication of server and client

Password based authentication is one of the common forms of authentication used in practice. However, when a user / client device enrolls with a server using password information, the authentication process exposes hash of password information to the server which is prone to various types of passwords guessing attacks. Present disclosure provides a system and a method that authenticates a user without revealing his / her password information to a third-party identity provider. This is done by using bilinear parings to authenticate user without sending password information to the server and by way generating client shared secret, server secret, public key, private key and the like. This eliminates the need for storing any keys on multiple devices / third parties or storing password information on the server side.
Owner:TATA CONSULTANCY SERVICES LTD

A three-factor based certificateless identity authentication and key agreement method

The application discloses a three-factor-based certificateless identity authentication and key agreement method, which comprises the following steps: a user registration step, a service server registration step and an authentication step of user login to the service server; the public key self-authentication is used to realize the certificateless trust, the biological characteristics, the password and the smart card are combined, and a more secure and reasonable three-factor identity authentication and key agreement scheme in a multi-server environment is designed; and the user can easily log in to the service server by using his smart card, biological characteristics and password. The application not only effectively avoids various attacks such as disguise attack, password guessing attack and replay attack, and ensures the security, but also guarantees the efficiency of the algorithm by light-weight operation such as a hash function, and can be used in various entity identity authentication fields such as public security, medical treatment and government affairs.
Owner:BEIJING SANSEC TECH DEV

Verifiable Lightweight Searchable Encryption Method in Cloud-Edge-Terminal Environment

The present invention provides a verifiable, lightweight, searchable encryption method in a cloud-edge environment. By introducing edge nodes to replace the client to perform signature calculation and verification tasks, the client verification and storage overhead are lightweight. The edge node solves the problem of insufficient client computing and storage resources. Using a distributed double-trapdoor public key cryptography system, a subset decision mechanism, and a cross-domain secure computing protocol technology, an algorithm for filtering search tasks before searching is designed. The entire process is calculated under ciphertext to protect user privacy and reduce the system's communication overhead when there are many meaningless tasks in the task set. Experimental results show that the present invention is suitable for situations where there are many incomplete matching tasks in the task set. By comparing the differences between several schemes in offline keyword guessing attacks, multiple keywords, multiple users, multiple data holders, verifiability, etc., it is shown that the present invention has certain advantages in overall functionality, security, computing and storage overhead, etc.
Owner:HEBEI UNIVERSITY

Attribute-based Boolean searchable encryption system and method for resisting quantum attack in cloud environment

The invention relates to an anti-quantum-attack attribute-based Boolean searchable encryption system and method in a cloud environment, provides a lattice-based ABBKS, and adopts a non-monotonic LSSS to express a Boolean query formula to support Boolean query. Only keyword names in the keyword index are disclosed to prevent keyword leakage, and active guessing attacks of attackers on the keywords are defended in a manner of segmenting secret values in the keyword index. Meanwhile, a lattice-based trap door smooth projection hash function is provided, and IKGA security resistance under a multi-user / multi-owner retrieval scene is achieved together with two non-collusion cloud servers. According to the scheme, each keyword in the search token is subjected to hash processing, and only two non-collusion clouds respectively holding a hash key and a TSPHF trap door can complete the search operation together. According to the method, the accurate retrieval of the cloud data is realized, and meanwhile, the balance between the safety and the practicability is realized.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Lightweight ciphertext similarity testing method and device

The present invention provides a lightweight ciphertext similarity testing method and device, comprising: obtaining encrypted ciphertext CT1 of user 1 and encrypted ciphertext CT2 of user 2; decrypting the encrypted ciphertext CT1 and encrypted ciphertext CT2, respectively, to obtain a Bloom vector BV1 for user 1 and a Bloom vector BV2 for user 2; determining the similarity between the Bloom vector BV1 and the Bloom vector BV2, and determining the similarity between the plaintext of user 1 and the plaintext of user 2 based on the similarity. The present invention can perform similarity testing on plaintext contained in ciphertext without decrypting the plaintext; has higher computational efficiency; and can improve resistance to guessing attacks by the test server by sacrificing a small amount of test accuracy.
Owner:GUANGZHOU JINGSHI INTELLECTUAL PROPERTY SERVICE CO LTD

System for detecting password guessing attack

The system for detecting the password guessing attack comprises a data collecting and preprocessing module, a time sequence analysis module, a clustering analysis module, an attack path analysis module and a dynamic risk scoring module. And the data collection and preprocessing module is used for data collection, data preprocessing and data distribution. And the time sequence analysis module is used for analyzing time sequence data by using a multivariable time sequence model and identifying abnormal login behaviors. And the clustering analysis module is used for identifying a user behavior mode and distinguishing a normal login behavior from a potential abnormal behavior. And the attack path analysis module is used for identifying possible attack paths, finding out activity tracks of attackers in the system, constructing an attack path model by adopting a graph theory and a path analysis technology in combination with user behavior data, and discovering potential attack behaviors through algorithm analysis. According to the system, through the modules, the safety and reliability of the password authentication system are remarkably improved, and a user account can be protected from being threatened by password guessing attacks.
Owner:LIAONING UNIVERSITY

Large model attack detection method and device, electronic equipment and storage medium

The invention provides a large model attack detection method and apparatus, an electronic device and a storage medium. The method comprises the steps of obtaining a cue word sequence of a large model input by a user; wherein the cue word sequence comprises a plurality of cue word instructions arranged according to an input time sequence; carrying out attack feature analysis on the cue word sequence; wherein the attack feature analysis comprises at least one of similarity analysis of the cue word instructions, user request frequency analysis, difference analysis of the cue word instructions, repetition analysis of the cue word instructions and information entropy analysis of the cue word instructions; and based on an analysis result corresponding to the at least one attack feature analysis, determining whether the user has a tentative attack behavior aiming at the large model or not. According to the mode, accurate recognition of various tentative attack behaviors such as jail break attacks and guess attacks can be realized, and the operation safety and stability of a large model are guaranteed.
Owner:SHANGHAI DOUXIANG INFORMATION TECH CO LTD

Large model attack detection method and device, electronic equipment and storage medium

The application provides a large model attack detection method and device, electronic equipment and storage medium, the method comprises the following steps: obtaining the prompt word sequence of the user input large model; wherein, the prompt word sequence includes a plurality of prompt word instructions arranged in chronological order; attack feature analysis is performed on the prompt word sequence; wherein, the attack feature analysis includes at least one of the following: similarity analysis of prompt word instructions, user request frequency analysis, difference analysis of prompt word instructions, repetition analysis of prompt word instructions, and information entropy analysis of prompt word instructions; based on the analysis results corresponding to at least one attack feature analysis, it is determined whether the user has exploratory attack behavior against the large model. This way can accurately identify various exploratory attack behaviors such as jailbreaking attacks and guessing attacks, and ensure the running safety and stability of the large model.
Owner:SHANGHAI DOUXIANG INFORMATION TECH CO LTD