Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

66 results about "Key authentication" patented technology

Key authentication is used to solve the problem of authenticating the keys of the person (say "person B") to whom some other person ("person A") is talking to or trying to talk to. In other words, it is the process of assuring that the key of "person A" held by "person B" does in fact belong to "person A" and vice versa.

Two-factor authentication key negotiation method and system based on biological characteristics

The invention relates to the field of cryptology, and discloses a two-factor authentication key negotiation method based on biological characteristics, a user holds double authentication factors, namely a private key authentication factor and a biological characteristic authentication factor, a server holds secret information, and the private key authentication factor and the biological characteristic authentication factor perform mutual authentication and form a shared key, so that the service can be obtained. A user can pass authentication only by holding two authentication factors at the same time, and when an enemy steals one authentication factor or secret information of a server, the enemy cannot disguise that the user passes the authentication of the server; even if an enemy steals the two authentication factors of the user, the enemy cannot be disguised as a server to pass the authentication of the user, so that the authentication threshold is greatly improved, an unauthorized user / server is prevented from abusing the authority of the authorized user, the security is higher, the entropy rate of a biological source is not required, and the authentication efficiency is higher.
Owner:SHANGHAI JIAOTONG UNIV

Multi-tenant API key authentication and resource isolation system in containerized environment

The invention discloses a multi-tenant API key authentication and resource isolation system in a containerized environment, and relates to the field of containerized multi-tenant authentication. Comprising an authentication authorization layer, a resource management and control layer and a security isolation layer. The authentication authorization layer comprises a multi-tenant authentication engine, an API key verification sub-module, a tenant identity recognition sub-module, an authority cascade verification sub-module and a dynamic authority calculation sub-module. And the resource management and control layer comprises a resource quota manager, a dynamic quota allocation sub-module, a real-time use monitoring sub-module, a threshold alarm control sub-module and an elastic capacity expansion and contraction sub-module. The security isolation layer comprises a multi-dimensional isolation engine, a container network isolation sub-module, a storage space isolation sub-module, a process permission isolation sub-module and a system call filtering sub-module; deep fusion of API authentication and container resource control is realized, a dynamic resource quota management mechanism based on tenant identities is established, and fine-grained API authority control and resource use limitation are provided.
Owner:CHINA IND INTERNET RES INST

Key authentication method and apparatus, electronic device, and storage medium

This application provides a key authentication method and apparatus, an electronic device, and a storage medium. The key authentication method provided in this application includes: determining user information based on a key authentication request sent by a user end, where the key authentication request includes the user information and an initial key; determining whether the initial key matches a first key, where the first key is used to determine whether the user end has a registration need for a pre-shared key; and when the initial key matches the first key, registering the first pre-shared key for the user end and binding the first pre-shared key to the user information.
Owner:RUIJIE NETWORKS CO LTD

Authentication method, apparatus and device based on pre-shared key

The embodiment of the application provides a kind of based on pre-shared key authentication method, device and equipment, in the above-mentioned pre-shared key authentication method, device sends key acquisition request to first server, then receives the ciphertext of pre-shared key sent by first server, then the ciphertext of pre-shared key is decrypted, the plaintext of pre-shared key is obtained, and then according to the plaintext of pre-shared key, identity authentication or encryption and decryption service is carried out with second server, so that it can be realized by one first server with security authentication and authentication mechanism to store the ciphertext of pre-shared key encrypted by the key of equipment side, so that the security of pre-shared key is greatly improved, and in the above-mentioned method, key and ciphertext are separated, and first server does not have decryption capability (because first server does not have decryption key), so that the risk of pre-shared key leakage in first server end can be avoided.
Owner:HUAWEI TECH CO LTD

DIGITAL KEY SYSTEM FOR A VEHICLE AND OPERATING PROCEDURES FOR IT

The present disclosure provides a digital key system for a vehicle (100), comprising a digital key management server (200), and a vehicle (100). The vehicle (100) can be configured to send a digital key authentication request to the digital key management server (200) based on the fact that a user terminal (300) is within a threshold distance of the vehicle (100). The digital key management server (200) can be configured to send the digital key authentication request to the user terminal (300).The digital key authentication request can cause the user terminal (300) to authenticate the user based on the digital key authentication request and the user's biometric identification information, and to send an authentication response to the digital key management server (200) indicating the authentication result. The digital key management server (200) can also be configured to send the authentication response to the vehicle (100). The vehicle (100) can further be configured to perform an action based on the authentication response.
Owner:HYUNDAI MOTOR CO LTD +1

Digital-key sharing method, digital-key authentication method, and computing device

Provided are a digital key sharing method, a digital key authentication method, and a computing device. The digital key sharing method is executed by a first device and includes: sending to a second device a digital key creation request that includes valid space information for a digital key, so as to generate the digital key at the second device; receiving a digital key signature request from the second device, wherein the digital key signature request includes data to be signed of the digital key, and said data includes the valid space information; and on the basis that the signing of the digital key signature request is completed, sending a digital key import request to the second device, so as to indicate the second device to save the generated digital key. Therefore, the security of a digital key can be improved in a spatial dimension.
Owner:BEIJING BOE TECH DEV CO LTD +1

A method and system for updating root keys when switching communication networks on a device terminal.

ActiveCN122027155BAccess networkCiphertext
This invention discloses a method and system for updating the root key when a device terminal switches communication networks. The method includes: a root key generation and storage device pre-stores an initial root key ciphertext in the quantum-safe device terminal; when the quantum-safe device terminal first connects to a communication network (i.e., connects to a first communication network), it performs root key authentication with the first network communication device, and encrypted communication can be established after successful authentication; when the quantum-safe device terminal changes its access network (i.e., connects to a second communication network), it needs to perform identity authentication and update the initial root key to obtain a root key usable in the second communication network. Based on the pre-stored root key ciphertext, this invention updates the original root key when the terminal deregisters from one communication network and connects to another independent communication network, enabling the terminal to complete network switching and subsequent encrypted communication without returning to the factory, significantly improving the flexibility and availability of the device.
Owner:MATRICTIME DIGITAL TECH CO LTD

Digital Key System for Vehicles and Operating Method Thereof

The present disclosure provides a vehicle digital key system including a digital key management server and a vehicle. The vehicle may be configured to transmit, to the digital key management server and based on a user terminal being located within a threshold distance from the vehicle, a digital key authentication request. The digital key management server may be configured to transmit, to the user terminal, the digital key authentication request. The digital key authentication request may cause the user terminal to perform, based on the digital key authentication request and based on biometric identification information of a user, authentication of the user; and transmit, to the digital key management server, an authentication response. The digital key management server may be further configured to transmit, to the vehicle, the authentication response. The vehicle may be further configured to perform an operation of the vehicle.
Owner:HYUNDAI MOTOR CO LTD +1

Key authentication method for quantum encryption call

The invention discloses a secret key authentication method for quantum encryption conversation. The method comprises the following steps: receiving an authentication request sent by a collection control station and first identity information of a first terminal; in response to the authentication request, determining a first symmetric key and a first key identifier according to the first identity information; and the first symmetric key and the first key identifier are sent to the centralized control station, and the centralized control station carries out authentication processing according to the first symmetric key and the first key identifier. Thus, the key transmission direction and mode are changed, so that the authentication of the terminal can be completed without directly transmitting the authentication key between the terminal and the quantum key management server, the risk that the authentication key is illegally intercepted by others in the transmission process is effectively reduced, and the user experience is improved. The potential safety hazard in the quantum encryption call authentication process is eliminated to a certain extent, so that the security of quantum encryption call authentication is ensured to a certain extent.
Owner:中电信量子信息科技集团有限公司

Digital key security authentication method

The application provides a digital key security authentication method, comprising: a second device sends authentication request information to a first device, and the first device obtains a first data packet according to the authentication request information and sends the first data packet to the second device. The second device decrypts first encrypted data, obtains first authentication information, and compares the first authentication information with stored first authentication information; the second device generates a second data packet and sends the second data packet to the first device. The first device decrypts second encrypted data, obtains second authentication information, compares the second authentication information with stored second authentication information, and sends a third data packet to the second device. The second device decrypts third encrypted data, obtains third authentication information, compares the third authentication information with stored third authentication information, and if the results are consistent, authentication is successful, a success notification request information is generated and sent to the first device; the first device accepts the success notification request information, generates a success notification reply information, and sends the success notification reply information to the second device. Thus, the security of digital key authentication is improved.
Owner:SAIC MOTOR

Key management method, key encryption method, data encryption method, and related devices

Embodiments of the present application provide a key management method, a key encryption method, a data encryption method and related devices, wherein the key management method is applied to a password module built in a processor, and includes: receiving a key management request for requesting management of a target key, the key management request including key management requirement information; the target key being used at least for encrypting an application key, the application key being a key for implementing data secure transmission of a virtual private network; generating target key ciphertext corresponding to the target key by using a root key; saving the target key ciphertext and target key authentication information into a special storage; the storage content of the special storage being managed by the password module, and when the storage content is used, the storage content is loaded into a secure memory; and returning index information for indexing the saving position of the target key ciphertext and the target key authentication information. The technical solution provided by the embodiments of the present application can improve the security of the execution result of the encryption and decryption program.
Owner:HYGON INFORMATION TECH CO LTD

Internet of vehicles authentication method based on block chain and physical unclonable function

PendingCN121841729AAvoid the risk of identity impersonationImprove resistance to attackKey distribution for secure communicationUser identity/authority verificationPasswordEngineering
The invention discloses an Internet of Vehicles authentication method based on a block chain and a physical unclonable function, and relates to the field of data security, and the method comprises the steps: a vehicle and a communication object complete registration at a roadside base station, and a vehicle end integrates a PUF and a fuzzy extractor to generate a master key bound with equipment; during authentication, the vehicle uses the password, the biological characteristics and the PUF response to perform multi-factor authentication, and submits a Merkle proof of a target communication object to the roadside base station; and the roadside base station verifies the proof and confirms the access authority through the block chain smart contract, and assists the vehicle and the communication object to complete mutual authentication and negotiate the session key. According to the method, the block chain is utilized to ensure that data cannot be tampered, equipment cloning is resisted through the PUF, efficient authorization control is realized in combination with the Merkle tree, pseudo name dynamic updating and identity revocation are supported, and finally, the calculation, communication and storage overhead is remarkably reduced while the security is ensured.
Owner:BEIJING INST OF TECH

Resource viewing methods, devices, and computer-readable storage media

This application relates to the field of key management technology, and in particular to a resource viewing method, device, and computer-readable storage medium. The method includes: an authentication server obtaining a root key, receiving an encrypted password, generating a static master key based on the root key and the encrypted password, and sending the static master key to a user terminal, where the user terminal receives and stores the static master key; when the authentication server determines that the user terminal requests to view a content protection server, it generates a dynamic master key, generates a content protection master key according to preset rules using the static and dynamic master keys, and sends it to the content protection server; the content protection server encrypts digital resources based on the content protection master key to obtain encrypted resources and sends them to the user terminal; the authentication server sends the dynamic master key to the user terminal, the user terminal generates a content protection master key, and decrypts the encrypted resources using the content protection master key to obtain the digital resources. This application improves the security of key management, thereby improving the security of digital resources.
Owner:CHINA MOBILE (JIANGXI) VIRTUAL REALITY TECH CO LTD +3

Method and system for activating preset key

The invention discloses a preset key activation method and system. The method comprises the steps that a preset key distribution mechanism distributes a preset key file 1 and an authentication key file 0 to first equipment and second equipment; the device authentication mechanism performs device identity authentication on the first device and the second device based on the authentication key file file0; according to the message that the identity authentication of the device is passed, the first device and the second device respectively execute an activation operation on the preset key file (file1); the first device authenticates the key data with the second device based on the data information of the preset key file file1; and the first device and the second device determine an available preset key file (file2) according to the message that the key authentication is passed. According to the method disclosed by the invention, before the terminal equipment enters a communication network for use, the key storage module of the preset key unit is in a black box state and an inaccessible state and is not interacted or connected with any unit, so that the possibility that bad users steal the preset key is avoided from the source.
Owner:MATRICTIME DIGITAL TECH CO LTD

Adaptive authentication method based on Beidou third-generation navigation satellite message

The invention discloses a self-adaptive authentication method based on a Beidou third-generation navigation satellite message, which comprises the following steps that: a control center encrypts a navigation message and uploads the encrypted navigation message to a Beidou satellite, the Beidou satellite broadcasts the encrypted navigation message, a receiver updates a public key based on a digital certificate, and the receiver sends the updated public key to the Beidou satellite. And on the basis, the received encrypted navigation message is authenticated, and whether the navigation message has integrity and authenticity is judged. According to the scheme of the invention, a switchable authentication scheme is provided based on the transmission characteristics of the D1 navigation message and the D2 navigation message aiming at the navigation message characteristics of the Beidou third-generation navigation system, so that the security requirements of receivers with different performances on resisting navigation spoofing attacks are met; meanwhile, signature authentication, TESLA key authentication and MAC authentication are adopted, so that the non-repudiation, coherence and integrity of ciphertext information are ensured, a receiver is ensured to quickly and efficiently complete navigation message authentication work, and normal navigation message resolving work is not influenced.
Owner:THE 724TH RESEARCH INSTITUTE OF CHINA STATE SHIPBUILDING CORP LTD

Vehicle and encryption authentication method thereof

The invention discloses a vehicle and an encryption authentication method thereof. The method comprises the following steps: under the condition of determining that a digital key is valid, sending an encryption authentication instruction, so that a near field communication module of the digital key receives the encryption authentication instruction and generates an authentication response message according to the encryption authentication instruction; receiving an authentication response message, and under the condition that the authentication response message comprises the first random plaintext data and the first reference encrypted data, performing encryption processing on the first random plaintext data based on a preset encryption algorithm to determine first target encrypted data; and under the condition that the first target encrypted data is consistent with the first reference encrypted data, it is determined that digital key authentication succeeds, and under the condition that digital key authentication succeeds, the vehicle is controlled to be started. Thus, the starting operation of the digital key function without legal authentication is forbidden through secondary verification, the vehicle anti-theft function is achieved, user participation is not needed in the whole anti-theft authentication process, and the authentication process is invisible to a user.
Owner:CHERY NEW ENERGY AUTOMOBILE TECH CO LTD

Key authentication method, device, electronic device, and storage medium

The present application provides a key authentication method, a device, an electronic device, and a storage medium, which determine user information based on a key authentication request sent from a user side, where the key authentication request includes the user information and an initial key, and determine whether the initial key matches a first key, where the first key is used to determine whether the user side needs to register a pre-shared key, and if the initial key matches the first key, register a first pre-shared key for the user side and bind the first pre-shared key to the user information.
Owner:ルイジェ ネットワークス カンパニーリミテッド

A method and apparatus for code privacy protection inference based on model segmentation and random activation

A code privacy-preserving inference method and apparatus based on model segmentation and random activation, wherein the method includes the following steps: Step 1, segmenting the original code audit model into an original client and a server; Step 2, expanding the feedforward neural network of the Transformer block inside the original client to generate a pseudo client; Step 3, establishing a key authentication mechanism on the pseudo client; if key authentication is successful, the expanded neuron part automatically does not participate in the processing of input data, and the pseudo client automatically transforms into a client; if key authentication fails, the pseudo client randomly activates the expanded neuron part according to a random activation strategy; Step 4, establishing an encrypted channel connection mechanism between the pseudo client and the server. This invention can greatly defend against member inference attacks and inversion reconstruction attacks, while not affecting the model performance during normal user use.
Owner:HANGZHOU DIANZI UNIV

Multi-device collaborative authentication methods, devices, equipment, media and procedures

This application provides a method, apparatus, device, medium, and program for multi-device collaborative identity authentication. The method includes: receiving an identity authentication request for a target user sent by an authentication server; generating data to be signed based on the identity authentication request; digitally signing the data to be signed using a local first private key component to obtain a first signature component; receiving a second signature component, which is obtained by a second authentication device digitally signing the data to be signed using a local second private key component; combining the first and second signature components to obtain complete signature data; sending an identity authentication response containing the complete signature data to the authentication server, instructing the authentication server to verify the complete signature data using the target public key, obtaining a signature verification result, and determining the identity authentication result of the target user based on the signature verification result. This application can solve the problem that some devices cannot independently authenticate user identities based on a passkey authentication mode.
Owner:CHINA FINANCIAL CERTIFICATION AUTHORITY

Authentication method and device, equipment and storage medium

The application of the invention is a divisional application of 202280098715.8. The invention also discloses a method for The invention discloses an authentication method and device, equipment and a storage medium, and relates to the field of wireless communication. The method is executed by an STA and an AP, and comprises the steps that an authentication frame is transmitted between the STA and the AP to execute an authentication process, and a field in the authentication frame indicates that identity authentication is executed by adopting at least one of the following authentication modes: an extended PASN supporting FILS shared key authentication with complete forward secrecy, an extended PASN supporting FILS public key authentication and an extended PASN supporting 802.1 X authentication. And using the PTK generated in the authentication process to protect messages in the STA and AP association establishment process. After the association is established, data communication is carried out by using the PTK generated in the authentication process; or, creating a new PTK after the association is established, and performing data communication by using a new PTS.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Authenticating certificate packages with asymmetric keys

Operations of a digital signature manager may include: detecting a set of one or more new certificate authority (CA) certificates in a certificate repository on a first virtual cloud network; transmitting a CA data set comprising a set of one or more new CA certificates to a key management service hosted on a second virtual cloud network; receiving, from the key management service, a digital signature of a CA dataset generated based on at least a global private key stored in a private key repository associated with the key management service on the second virtual cloud network; and storing the digital signature in a certificate repository in a data structure associating the digital signature with the CA data set.
Owner:ORACLE INT CORP

Two-factor authentication method and system

The application relates to the technical field of computer security, and discloses a two-factor authentication method and system, which is based on a two-factor authentication technology of biological information and public key encryption. In the method, a public key encryption scheme with semantic security and a hash function with robust reserved predicate relation are used to realize an authentication process, and the method has the ability to resist replay attacks and malicious server attacks. Specifically, the scheme uses a server to randomly generate a challenge number and uses a user public key to encrypt and send the challenge number, so as to resist replay attacks; and the scheme uses two-factor authentication of a biological authentication factor and a private key authentication factor to resist malicious user attacks. Meanwhile, the scheme uses the hash function with robust reserved predicate relation to protect biological feature information of a user, and uses the public key encryption scheme with semantic security to protect private key information of the user, so as to resist malicious server attacks. The application significantly improves the security and efficiency of authentication, and can better meet the needs of users.
Owner:SHANGHAI JIAOTONG UNIV

Two-factor authentication method and system

The application relates to the technical field of computer security, and discloses a two-factor authentication method and system, which is a two-factor authentication technology based on biological information and digital signature. The biological information is protected by using a public key encryption scheme of the digital signature and a fuzzy extractor to realize an authentication process, and the two-factor authentication method has the ability to resist replay attacks and malicious server attacks. Specifically, the scheme uses a server to randomly generate a challenge number to resist replay attacks, and uses two-factor authentication of a biological authentication factor and a private key authentication factor to resist malicious user attacks. Meanwhile, the scheme uses a fuzzy extractor to protect biological feature information of a user and uses a public key encryption scheme of the digital signature to protect private key information of the user, so as to resist malicious server attacks. The application significantly improves the security and efficiency of authentication and can better meet the needs of users.
Owner:SHANGHAI JIAOTONG UNIV

Authentication without pre-knowledge of credentials

ActiveCN113300847Bavoid deploymentavoid replayUser identity/authority verificationCommunications systemEngineering
A communication system is disclosed. The communication system includes: a network device including a plurality of communication ports; and a plurality of communication nodes coupled to the network device through the plurality of communication ports. The communication system further includes a controller configured to generate a security key and to send a new configuration along with a message authentication code to the network device. The controller is further configured to divide the security key into portions and send portions of the security key to at least some of the plurality of communication nodes, such that each of the at least some of the plurality of communication nodes receives one portion of the security key. The network device is configured to retrieve portions of the security key from the at least some of the plurality of communication nodes, and is configured to combine the retrieved portions of the security key into a new security key, and to authenticate the new configuration using the combined security key.
Owner:NXP BV

System and method for de-identification of personal information in medical services

Disclosed in one embodiment of the present disclosure are a system and a method by which a computing device de-identifies personal information in medical services. The method may comprise: a key server having a key for the encryption and decryption of medical data in a clinical environment; an authentication server which authenticates access information about a user client, and which issues a token for maintaining a session; a ticket server for issuing, on the basis of a request by the user client for access to the encrypting medical data, a ticket by which the user client is authorized to receive the key; and a key exchange server for transmitting, to the user client, on the basis of a request by the user client for decryption of the encrypted medical data, the key issued by the key server.
Owner:MEDICAL AI CO LTD

Digital key authentication utilizing device metadata

Various examples are disclosed for an authentication model for user sessions utilizing a digital key incorporating metadata identifying device location and network conditions. Upon user authentication of a session, a digital key can be generated that incorporates information about the location and network conditions of a device, which can be utilized to grant conditional access to resources.
Owner:OMNISSA LLC

Block chain digital asset transaction security verification method and device based on cross-dimensional biometric key right confirmation

PendingCN121788139AImplement end-to-end security protectionRealize dynamic protectionMultiple biometrics useProtocol authorisationComputer networkInternet privacy
The invention discloses a block chain digital asset transaction security verification method and device based on cross-dimensional biometric key right confirmation, and the method comprises the steps: constructing a feature set and a unique identification code based on a fingerprint ridge key and a facial feature key, carrying out the cross-dimensional fusion to form a biometric key reference vector, and calculating a hash value of an encrypted ciphertext; constructing a key retrieval voucher, and registering and storing the key retrieval voucher together with the unique identification code; when a user initiates a block chain digital asset transaction request, a to-be-verified biological key reference vector is generated based on a user fingerprint ridge key and a facial feature key, validity verification of hash and key feature right verification is performed in combination with a unique identification code and transaction information, and early warning is performed based on user verification frequency. And the safe and credible node performs secondary verification on the early warning. According to the method, a decentralized security verification system is constructed, safer, more reliable and more efficient security verification in block chain digital asset transactions is realized, and the credibility and security of the transactions are improved.
Owner:ZHEJIANG BANGSUN TECH CO LTD

Vehicle and vehicle control method

This invention relates to vehicles and vehicle control methods. According to one embodiment, a vehicle is provided, comprising an authentication controller and a processor. The authentication controller is configured to output an FOB key authentication request when a FOB key approaches. The processor is configured to, in response to the FOB key authentication request, send an FOB key search command to an antenna and output a ping signal control command to a wireless charging device to control the output of a ping signal. The FOB key search command includes FOB key search commands for a first area where a wireless charging pad is located and for areas other than the first area. Furthermore, the output period of the ping signal controlled according to the ping signal control command does not overlap with the FOB key search period for the first area.
Owner:HYUNDAI MOTOR CO LTD +1

Multi-mode activation and reset method and system for diagnostic code reader

The invention relates to the technical field of fault diagnosis, and discloses a multi-mode activation and reset method and system for a diagnostic code reader. The method comprises the following steps: performing protocol type identification on an ECU response frame and reading a VIN code sequence; performing seed key authentication based on the VIN code sequence, and returning a programming session state flag; selecting an on-line programming mode or an off-line programming mode, executing Flash writing, and returning a programming completion mark; activating the TPMS sensor based on the programming completion mark, writing the TPMS sensor into the ID mapping table, and returning a writing confirmation mark of the ID mapping table; and clearing the fault code according to the write confirmation mark, resetting the throttle learning value and the clutch pressure calibration table, executing ECU hard resetting, and returning a resetting completion mark. According to the method, ECU damage caused by flashing failure can be effectively prevented, different maintenance scene requirements are met through four modes of OBD copying, activation copying, automatic creation and manual creation, and accurate positioning of the sensor wheel position is achieved.
Owner:SHENZHEN FOXWELL TECHNOLOGY CO LTD