Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

21 results about "Impersonation attack" patented technology

Impersonation attacks are emails that attempt to impersonate a trusted individual or company in an attempt to gain access to corporate finances or data.

Multi-party password distribution method based on secret sharing

ActiveCN117097463BCode bookCovert communication
A multi-party password book distribution method based on secret sharing, a sender uploads a password book to an interstellar file system through public key encryption, adopts secret sharing to secret split information obtained by splicing a public key and a Hash of an expected receiver, a receiver obtains a secret share through biological feature recognition technology, and obtains a sender public key through a judgment function to download an original password book from the interstellar file system. According to experimental results and security analysis, the scheme can guarantee high time efficiency and resist impersonation attacks, and guarantee the safe transmission of the password book. The present application solves the security problem of password book distribution by adopting a shamir threshold scheme, changes the threshold for safe password book distribution, dynamically solves the entry and exit of receivers, solves the problem that original covert communication can only perform one-to-one communication, and realizes one-to-many communication.
Owner:SONGSHAN LAB

A camera fingerprint privacy protection method against link attacks and impersonation attacks

The application discloses a camera fingerprint privacy protection method against link attacks and fake attacks, and comprises the following steps: obtaining at least three sub-blurring noises through Gaussian distribution sampling, obtaining a picture to be processed, generating corresponding number of sub-blurring noise coefficients and noise masks (a matrix composed of 0 or 1) according to the number of sub-blurring noises, and combining all the sub-blurring noises into one blurring noise through the sub-blurring noise coefficients and the noise masks. The application realizes the premise of not affecting the normal passing of a legal user through a camera fingerprint-based identity authentication system, simultaneously solves two security risks of link attacks and fake attacks, can help the user effectively defend against identity link attacks, is far faster than multiple iteration denoising in speed, realizes stable camera fingerprint fake attack detection, and avoids illegal users from stealing the camera fingerprints of legal users to pass through the identity authentication system.
Owner:ZHEJIANG UNIV +1

A Capsule Network-Based Method for Detecting Finger Vein Impersonation Attacks

This paper proposes a method for detecting finger vein spoofing attacks based on capsule networks. Capsule networks are not only suitable for small-sample finger vein datasets, but also, by replacing neurons with vector-represented capsules on top of CNNs, they can better handle spatial information such as relative position and angle, enhancing the network's adaptability to finger offset and rotation scenarios. A Bayesian routing algorithm is proposed, incorporating the differential entropy of the capsules as a consideration in calculating activation values. During final classification, feature capsules with high activation probabilities and high concentration are selected, which helps improve the accuracy of classifying genuine and fake veins. By simulating the uncertainty of capsule parameters, training errors can be reduced, improving recognition accuracy.
Owner:NANJING UNIV OF POSTS & TELECOMM

Identity authentication method and system of USB Key of zero-knowledge proof

The application provides a USB Key identity authentication method and system based on zero-knowledge proof, and the method comprises three information interactions based on CHAP protocol to complete bidirectional identity authentication between the USB Key and an authentication host, wherein the second information interaction adopts Schnorr digital signature zero-knowledge proof, and the third information interaction adopts KEELOQ algorithm encryption and decryption. The identity authentication method can timely find and defend, successfully defend replay attacks and impersonation attacks, and improves the security of USB Key identity authentication.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Multi-party multi-data summation method based on d-dimensional cluster state

The invention relates to the technical field of quantum security calculation, and discloses a multi-party multi-data summation method based on a d-dimensional cluster state, which introduces a semi-honest third party to assist in completing summation calculation, and constructs a bidirectional identity authentication process between a participant and the third party by using a dual one-way hash function, thereby effectively preventing identity impersonation attack. In a multi-party multi-data summation stage, a multi-party quantum information interaction structure is established by using quantum entanglement association between a d-dimensional Bell state and a d-dimensional cluster state, and secure coding and aggregation of private data of participants are realized through Bell measurement. Meanwhile, detection particles from (d + 1) groups of complementary bases are randomly inserted into a quantum channel and are used for detecting potential eavesdropping behaviors and ensuring the safety of a quantum communication process.
Owner:SUZHOU UNIV

Method and device for transmission of avatar data over IMS data channel

The present disclosure relates to a 5G or 6G communication system for supporting higher data transmission rates. A method by which a first terminal performs communication in a wireless communication system, according to one embodiment of the present disclosure, may configure transmission terminal-centric avatar communication with a second terminal. The method may receive, from the second terminal, a first rendered result for the transmission terminal-centric avatar communication. The method may receive, from a network, a second rendered result performed on the basis of information about an avatar object of the second terminal. The method may determine whether the second terminal performs impersonation attacks on the basis of the first rendered result and the second rendered result.
Owner:SAMSUNG ELECTRONICS CO LTD

System and method for data filtering in machine learning model to detect impersonation attacks

A new approach is proposed to support data filtering in machine learning (ML) to detect impersonation attacks. First, filters are applied to filter data or information collected from a user in order to extract features that are specific and / or unique for the identification of the user. The features extracted from the set of data are then used to train ML models configured to identify a set of key characteristics of electronic messages or web-based resources originated by the user. When a new electronic message or web-based resource purported to be from the user is intercepted, one or more of the trained ML models that are applicable are utilized to determine or predict if the newly intercepted electronic message or web-based resource is indeed originated by the user or is impersonated by an attacker under the same filtering criteria as training of the corresponding ML models.
Owner:BARRACUDA NETWORKS INC

Methods, systems, and computer-readable media for mitigating 5g roaming spoofing attacks

ActiveCN116458121BInternet privacyEngineering
A roaming impersonation attack can be initiated in the N32-c handshake procedure used for inter-PLMN communication in 5G networks. An example solution described herein mitigates N32-c roaming impersonation attacks using a SEPP by cross-verifying the sender attribute present in the N32-c handshake security capabilities exchange message against the endpoint identity in the X.509v3 certificate shared during the TLS handshake and the remote SEPP identity configured in the local database of the SEPP.
Owner:ORACLE INT CORP

A password-based session key agreement generation method on a lattice

The application provides a simple password session key agreement generation method on a lattice, which allows a user to use a password to agree with a server on a session key and authenticate the user identity. The protocol is constructed based on an ideal lattice, and its security is established on a ring with an error learning problem, so that the protocol can effectively resist quantum attacks. The password and identity of the user are stored on the server side. During the session key agreement, the password is used to encrypt a temporary public key, so that the server can confirm the user identity. If an enemy does not have the password, even if he obtains all the information of the transmission in the protocol, he cannot obtain the temporary public key of the user to agree on the session key. Therefore, the protocol can resist impersonation attacks. In addition, the protocol uses two-way key confirmation to ensure the consistency of the session key.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

A blockchain-assisted asymmetric identity authentication method based on preset public keys

The application provides a blockchain-assisted asymmetric identity authentication method based on preset public keys, and comprises the following steps: S1. A CA issues an edge certificate to a smart fusion terminal and an end certificate to a network terminal; S2. The smart fusion terminal and the network terminal reserve the private keys of the respective certificates and exchange the public keys of the certificates; S3. The smart fusion terminal generates a random number string R0 and uses the random number string R0 to perform identity authentication on the network terminal; if the authentication is successful, step S4 is performed; S4. The smart fusion terminal performs auxiliary authentication on the network terminal; if the authentication is successful, step S5 is performed; S5. The network terminal generates a random number string R1 and uses the random number string R1 to perform identity authentication on the smart fusion terminal. The application improves the protection capability against certificate forgery, key leakage and impersonation attacks.
Owner:HEBEI UNIVERSITY

Authentication method and device based on terminal device identifier and storage medium

The application discloses a terminal device identification-based authentication method and device and a storage medium, and belongs to the technical field of communication security. The method comprises the following steps: collecting static attribute information and dynamic behavior information of a terminal device; generating a current device fingerprint for identifying the terminal device according to the static attribute information; performing static authentication on the terminal device based on the current device fingerprint and original device fingerprints in a fingerprint library; and performing dynamic authentication on the terminal device according to the dynamic behavior information in the case that the static authentication is passed. According to the application, the static authentication is performed on the terminal device through static attributes, and in the case that the static authentication is passed, the dynamic operation of the terminal device is analyzed to determine whether the behavior mode of the terminal device in the operation process is in line with the expectation. The multi-dimensional authentication mechanism combining the static and dynamic modes can not only resist traditional identity impersonation attacks, but also effectively prevent complex network threats, and the reliability and security of the authentication process are improved.
Owner:BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +3

A measurement-device-independent quantum dialogue method with bidirectional identity authentication function

The application discloses a kind of measurement equipment independent quantum conversation methods with bidirectional identity authentication function, the method is mutually authenticated whether communication two sides are legal collaborators, then directly utilize quantum channel to mutually converse each other.Communication two sides Alice and Bob mutually share a set of identity keys by BB84 protocol, Alice and Bob are only responsible for preparing entangled photon pair and single photon, and performing encoding operation to photon, all measurement tasks are completed by third party measurement end Charlie.Alice and Bob can verify the identity of two sides according to the Bell state analysis result of Charlie, determine as the legal party of communication, and complete bidirectional communication after that.The application first applies bidirectional identity authentication technology to MDI-QD field, can resist the impersonation attack of eavesdropper, and by completing measurement task by third party, can effectively resist all attacks to imperfect measurement equipment, enhance the security of two-way identity authentication code and communication.The application has very important significance to promote the practical application of quantum conversation.
Owner:NANJING UNIV OF POSTS & TELECOMM

Generating a scaled impersonation attack prediction

In some implementations, a system may obtain interaction information for a plurality of interactions, each associated with a respective user. The system may retrieve passive user authentication information for the users and may compute risk metrics for the interactions by comparing sets of interaction information to corresponding sets of passive authentication information. Based on the risk metrics, the system may generate a scaled attack prediction indicating the likelihood or occurrence of coordinated impersonation activity involving multiple unauthorized interactions. Responsive to the scaled attack prediction, the system may selectively perform a security action, such as terminating interactions, requiring additional authentication, or updating a prediction model. These actions may provide improved security for electronic systems against impersonation attacks by identifying and mitigating coordinated unauthorized activities. The approach may enhance protection by leveraging passive authentication data and dynamic risk assessment to detect and respond to threats in real time, thereby strengthening system security.
Owner:CAPITAL ONE SERVICES LLC

A method for authenticating a UAV cluster based on zero-knowledge proof

This invention proposes a drone swarm authentication method based on zero-knowledge proof, belonging to the field of drone swarm secure communication technology. Its technical solution includes the following steps: S1, system initialization; S2, secondary drone registration before takeoff; S3, bidirectional authentication and key negotiation between secondary drones during flight; S4, dynamic networking of secondary drones. This invention combines zero-knowledge proof and elliptic curve cryptography to achieve drone swarm identity authentication. Through a two-stage design of pre-registration and online authentication, it significantly reduces the computational and communication overhead of in-flight authentication while ensuring drone identity privacy and communication security. It effectively resists typical threats such as man-in-the-middle attacks, impersonation attacks, replay attacks, and message tampering, avoiding single points of failure and communication bottlenecks caused by the central node.
Owner:NANTONG UNIV

Cloud storage data integrity auditing method and device for 5g environment

The application discloses a cloud storage data integrity auditing method and device for a 5G environment, which realizes auditing of data in the cloud based on zero-knowledge proof, wherein the method comprises the following steps: receiving a data integrity auditing request sent by a PSP (Proxy Service Processor) to an audited database; executing an auditing protocol according to the data integrity auditing request to obtain a calculation value; and determining the integrity of suspicious file data based on the calculation value to realize cloud storage data integrity auditing. Thus, the problems that related technologies cannot realize data integrity design, cannot recover damaged data, cannot dynamically operate cloud storage data, are difficult to resist replay attacks, impersonation attacks and the like, are not suitable for a lightweight distributed storage environment, have complex calculation, low security and the like are solved.
Owner:BEIHANG UNIV

Intelligent card-based authentication key negotiation method for vehicle networking cross-domain

This invention discloses a smart card-based cross-domain authentication key negotiation method for vehicle-to-everything (V2X) networks. Addressing the security issues of existing cross-domain authentication key negotiation protocols in V2X environments, it proposes an improved cross-domain authentication key negotiation protocol based on user passwords and smart cards. Security analysis of this protocol shows that it can overcome the security vulnerabilities of existing solutions. It resists attacks such as temporary key leakage, man-in-the-middle attacks, impersonation attacks, and smart card leakage without requiring tamper-proof smart cards. Compared with similar solutions in terms of security and computational overhead, the results demonstrate that this invention provides high security while maintaining comparable computational overhead to traditional solutions, making it suitable for resource-constrained V2X cross-domain authentication environments.
Owner:NAVAL UNIV OF ENG PLA

A multi-party multi-data summation method based on d-dimensional cluster states

The application relates to the technical field of quantum security calculation, and discloses a multi-party multi-data summation method based on d-dimensional cluster states, a semi-honest third party is introduced to assist in completing summation calculation, and a two-way identity authentication process between participants and the third party is constructed by using a double one-way hash function, so that identity impersonation attacks are effectively prevented. In the multi-party multi-data summation stage, a multi-party quantum information interaction structure is established by using quantum entanglement correlation between d-dimensional Bell states and d-dimensional cluster states, and Bell measurement is used to realize safe coding and aggregation of private data of the participants. Meanwhile, detection particles from d+1 groups of complementary bases are randomly inserted in a quantum channel, which are used for detecting potential eavesdropping behaviors and ensuring the safety of the quantum communication process.
Owner:SUZHOU UNIV

Generating a scaled impersonation attack prediction

In some implementations, a system may receive interaction information associated with a plurality of interactions, wherein each interaction in the plurality of interactions is associated with a respective user in a plurality of users. The system may retrieve passive user authentication information associated with the plurality of users. The system may compute a plurality of risk metrics based on the interaction information and the passive user authentication information, each risk metric in the plurality of risk metrics being associated with a respective interaction from the plurality of interactions. The system may generate a scaled attack prediction based on the plurality of risk metrics, the scaled attack prediction indicating an occurrence of a scaled attack. The system may perform a security action based on the scaled attack prediction indicating the occurrence of the scaled attack.
Owner:CAPITAL ONE SERVICES LLC

Distributed trust-based anonymous cross-domain handover authentication method for industrial internet of things

The application discloses an anonymous cross-domain switching authentication method based on distributed trust for an industrial Internet of Things, which first completes initialization of system parameters in each domain; authentication servers of each domain negotiate a system master key pair through a distributed key generation protocol; devices in each domain complete registration in a domain (TA), obtain pseudonyms and keys; other domain AS complete security authentication of the devices and issue identity tokens embedded with time keys; the devices initiate cross-domain mutual authentication requests to other domain devices within a valid period of the identity tokens and negotiate session keys; and real identity tracing and revocation processing are performed on malicious devices. The application realizes complete decentralization in view of problems such as single-point failure in a traditional centralized authentication architecture in the industrial Internet of Things, reduces authentication delay through an anonymous cross-domain switching authentication scheme, and embeds time keys in identity tokens to realize dynamic management of the devices. The application can realize safe anonymous cross-domain switching authentication, resist common attacks including response attacks, impersonation attacks and man-in-the-middle attacks, and has low computing and communication overheads.
Owner:ANHUI UNIV

A Multi-Factor Dynamic Identity Authentication Method Based on Chinese Cryptographic Algorithm

This invention discloses a multi-factor dynamic identity authentication method based on the national cryptographic algorithm, comprising: generating a public-private key pair and a symmetric key according to the national cryptographic algorithm; performing cryptographic operations on verification factors using the generated key and the SM3 national cryptographic algorithm; in the first authentication stage, the terminal generates a non-repeating random number, combines it with hash and XOR operations to generate a dynamic password, encrypts the dynamic password using a symmetric cryptographic algorithm, and simultaneously encrypts the symmetric key using an asymmetric cryptographic algorithm, sending it along with the encrypted dynamic password to the power distribution gateway for identity authentication; in the second authentication stage, the power distribution gateway generates a new non-repeating random number, performs hash and XOR operations on the decrypted data to generate a new dynamic password, encrypts it using the symmetric key, and sends it to the smart terminal for identity authentication. This invention can resist common attacks such as man-in-the-middle attacks, replay attacks, and impersonation attacks, and the method does not require the installation of additional hardware or the issuance of digital certificates, reducing costs and simplifying operation and maintenance.
Owner:SHANGHAI UNIVERSITY OF ELECTRIC POWER +1