Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

162 results about "Man-in-the-middle attack" patented technology

In cryptography and computer security, a man-in-the-middle attack (MITM) is an attack where the attacker secretly relays and possibly alters the communications between two parties who believe they are directly communicating with each other. One example of a MITM attack is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all relevant messages passing between the two victims and inject new ones. This is straightforward in many circumstances; for example, an attacker within reception range of an unencrypted wireless access point (Wi-Fi) could insert themselves as a man-in-the-middle.

Container mirror image security management method and system

The invention relates to the technical field of data access security, and discloses a container mirror image security management method and system, and the method comprises the steps: constructing a container mirror image, generating a differential encryption key through a strategy center, carrying out the encryption strategy of a kernel dependence layer, a runtime environment layer, an application code layer and a sensitive configuration layer, and forming a hierarchical protection basis. If an access request is triggered, firstly collecting equipment fingerprints and geofence information and evaluating an environmental risk score, verifying access authority and an access scene matching degree through attribute-based encryption, analyzing operation track characteristics in real time, identifying an abnormal mode, and if the three-layer verification is passed, generating a temporary access token; according to the method, access request authority is verified, a temporary access token is matched, key fragments are synthesized, a master key is only temporarily generated in a memory and encrypted and stored, and through combination of a double-layer encryption channel and inner-layer and outer-layer defense, the anti-attack ability of container mirror image transmission is improved, and man-in-the-middle attack and data tampering are effectively coped with.
Owner:NANJING TORTOISE & HARE RACE SOFTWARE RES INST CO LTD

Bidirectional authentication security mobile communication method and system based on public key digital fingerprint

The invention discloses a bidirectional authentication secure mobile communication method and system based on a public key digital fingerprint, and belongs to the technical field of communication security. The method specifically comprises the following steps: S1, digital certificate application and issuing: a mobile terminal and a service server respectively use an encryption algorithm to generate an asymmetric key pair which comprises a public key and a private key, an entity submits a CSR file which comprises a public key, entity identity information and an extension field to a CA, and the CA strictly audits the entity identity and issues a digital certificate; and performing digital signature on the public key and the entity information by using a CA private key after the auditing is passed. Two-way identity authentication is achieved, communication safety is improved, a traditional scheme only supports one-way authentication of a client to a server and is prone to phishing attack and identity false use, digital certificates are exchanged before communication between a mobile terminal and a service server, the legality of the certificates is verified through a public key of a CA root certificate, and the authenticity of the identities of the two parties is ensured. A bidirectional authentication mechanism effectively prevents man-in-the-middle attack and identity counterfeiting problems, and the security risk is greatly reduced.
Owner:HAINAN SOFTWARE VOCATIONAL & TECH COLLEGE

High-security method for negotiating temporary session key based on national secret algorithm

The invention relates to the technical field of commercial password detection methods, and discloses a high-security method for negotiating a temporary session key based on a national secret algorithm, and the commercial password detection method comprises the following steps: initialization and identity authentication: two communication parties generate an SM2 public and private key pair, and the identity is verified through a digital certificate and an SM2 signature; temporary key negotiation: generating a shared key point based on an SM2 key exchange protocol; session key derivation: generating a temporary session key by using an SM3 hash algorithm; key confirmation and encrypted communication: verifying the key through an SM4 algorithm and encrypting communication data; according to the high-security method for negotiating the temporary session key based on the national secret algorithm, efficient key negotiation of both communication parties in an unsecure channel is realized through an SM2 key exchange protocol, an SM3 hash algorithm and an SM4 symmetric encryption algorithm. The method combines digital certificate authentication, dynamic random numbers and timestamps, has forward security, replay attack resistance and man-in-the-middle attack resistance, and is suitable for high-security scenes such as finance and government affairs.
Owner:SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD

Secure communication method and system based on QRNG and Beidou positioning terminal

The invention provides a secure communication method and system based on a QRNG and a Beidou positioning terminal. A sending end and a receiving end of communication preset a pre-shared initial key, and a space-time reference parameter group is obtained through Beidou positioning; a secret key packaging secret key is generated by using a national secret SM4 algorithm; monitoring time-space parameter deviation in a communication process in real time, and triggering a key updating protocol when the time-space parameter deviation exceeds a threshold value; and after the receiving end verifies the Hash verification value, decrypting to obtain the primary encryption key, and restoring the plaintext data. According to the system, the generated true random number sequence is used as an encryption key, so that the unpredictability and randomness of the key are fundamentally enhanced, and quantum computing attack and man-in-the-middle attack are effectively resisted. The use of the pre-shared key mechanism and the key packaging key improves the response speed and efficiency of the communication system. And meanwhile, the position parameter and the timestamp are deeply fused to the key generation process, so that the spatio-temporal information is more difficult to counterfeit, and the defense capability of the system is further improved.
Owner:YIXUNTONG TECH CO LTD

Data security transmission method based on ML-KEM algorithm and PUF

The invention discloses a data security transmission method based on an ML-KEM algorithm and a PUF, and the method comprises the steps: in a registration stage, mobile equipment generates an anti-quantum key through employing a PUF technology, and a CA issues an anti-quantum digital certificate based on a Falcon algorithm and a cryptographic accumulator; in an identity authentication stage, a mobile device and an edge gateway complete bidirectional identity authentication by exchanging identity labels, anti-quantum certificates and authentication key parameters in combination with a Falcon algorithm and PUF challenge-response, and negotiate to generate a shared key by using an ML-KEM algorithm, thereby effectively defending threats such as man-in-the-middle attack, replay attack and identity counterfeiting; in a data transmission stage, two communication parties realize data encryption transmission by adopting a symmetric encryption algorithm, and data integrity and source credibility are guaranteed in combination with a Falcon digital signature; the whole scheme has the advantages of quantum security resistance, efficient authentication, dynamic key updating, lightweight encryption and the like.
Owner:SICHUAN UNIV +1

Internet of Things secure access method based on cloud edge collaboration

The invention discloses an Internet of Things secure access method based on cloud edge collaboration, which comprises the following steps: firstly, an Internet of Things device and an edge server respectively register in a CSC (Content Service Controller), and obtain an intelligent card or related data to complete information updating and storage; the equipment is inserted into an intelligent card to log in, and data are sent to the edge server after identity password verification; the edge server verifies the timestamp and then forwards the data to the CSC; the CSC verifies the timestamp and the identity, generates a session key parameter and sends the session key parameter to the edge server; the edge server verifies the identity of the CSC and then generates session key encrypted data to be transmitted back, and after the verification of the device is passed, secure communication is established. According to the method, mutual verification and encryption protection are adopted in identity verification; a timestamp, a random value and strict verification are used for message transmission to prevent replay and man-in-the-middle attack; secret key management guarantees safety through dynamic change of secret values, attacks such as physical capture are resisted in combination with PUF, and communication safety is comprehensively guaranteed.
Owner:SICHUAN BAICHENG INFORMATION TECHNOLOGY CO LTD

All-in-one machine encryption communication transmission method and system based on dynamic strategy

The invention relates to the technical field of communication transmission, and particularly discloses an all-in-one machine encryption communication transmission method and system based on a dynamic strategy, and the method comprises the steps: collecting hardware state parameters, network environment parameters and communication content characteristics of an all-in-one machine and a target communication opposite end in real time; calculating a risk index of the current communication process based on the network environment parameters of the all-in-one machine and the target communication opposite terminal; matching an encryption algorithm sequence, a key updating frequency and a transmission protocol according to hardware state parameters, risk indexes and communication content characteristics of the all-in-one machine and a target communication opposite end, performing segmented encryption and multi-channel parallel transmission on communication data of the all-in-one machine, and performing security key distribution in combination with a distributed key management mechanism to obtain a security key; performing encrypted communication security verification based on the security key to obtain communication verification data; the security of the communication process of the all-in-one machine is improved, and the risks of data leakage and man-in-the-middle attack are prevented.
Owner:JINJI FUTURE (SHENZHEN) TECHNOLOGY CO LTD

Man-in-the-middle attack detection method and device

The invention discloses a man-in-the-middle attack detection method and device, and the method comprises the steps: obtaining equipment information in a communication network, and the equipment information comprises hardware information, software information and network environment information; calculating a safety coefficient of the communication equipment according to the equipment information; calculating a data transmission deviation degree according to the bandwidth, the network delay and the packet loss rate; calculating feature vector similarity according to the feature information of the current communication data; calculating a risk assessment value according to the communication equipment safety coefficient, the data transmission deviation degree and the feature vector similarity; and performing man-in-the-middle attack detection according to the risk assessment value to obtain a detection result. According to the method, man-in-the-middle attack detection is realized, and the accuracy and adaptability are improved. The method can be widely applied to the technical field of safety communication.
Owner:GUANGZHOU KETENG INFORMATION TECH

One time voice passphrase to protect against man-in-the-middle attack

Embodiments described herein provide for automatically authenticating operation requests and end-users who submit operation requests during contact events. A server obtains an operation request for an operation originated at an end-user device. The server generates a voice-based one-time password (OTP) using contextual information associated with the requested operation. The server generates and transmits an OTP prompt having text representing the OTP for display at a user interface of the user device. The server receives a response including an audio signal that contains the recording of the user speaking the OTP text aloud. The server uses the audio signal to authenticate the user and the operation request based on the speaker's voice, the accuracy of the user speaking the OTP, and liveness or fraud detection features extracted from the audio signal or metadata from the user device.
Owner:PINDROP SECURITY INC

Charging pile and charging pile control method

The invention relates to the technical field of charging facility network security, in particular to a charging pile and a charging pile control method. According to the charging pile, digital certificate dual verification and encryption communication are carried out between the cloud server and the gateway board, the risk of user information leakage caused by man-in-the-middle attack, data eavesdropping and the like is reduced, and the user experience is improved by carrying out second encryption verification on the gateway board and the control board. The risk that the data of the charging pile are tampered due to counterfeiting of the digital certificate is reduced, and compared with identity verification achieved only based on a cloud server in the prior art, the technical effect of improving the network security of the charging pile is achieved.
Owner:DONGGUAN AOHAI TECH CO LTD

System and method for pre-emptive detection of email impersonation and man-in-the-middle attacks using ai-driven telemetry and data leak prevention remediation

Disclosed is a system and method for pre-emptive detection, attribution, and reversal of outbound data leaks and impersonation-based attacks occurring beyond traditional enterprise endpoint security boundaries. An outbound instrumentation gateway may insert telemetry identifiers into outbound electronic communications, enabling persistent tracking of message interactions within external or third-party domains. A RAPTORAI analytics engine may process metadata collected from these interactions using a multi-stage artificial-intelligence pipeline that combines predictive anomaly modeling and large-language-model (LLM) attribution. When anomalous or malicious behavior is detected, a Double DLP remediation engine may be activated, which is capable of pausing, auto-locking, or revoking message access after transmission but before compromise. A PRE-Crime telemetry layer provides visibility into early-stage reconnaissance activities by threat actors operating beyond the endpoint, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR) to effectively zero. Administrative dashboards present live analytics of third-party risks, reconnaissance indicators, and auto-remediation events.
Owner:KHAN ZAFAR

Multi-level encryption authentication and data integrity protection method in vehicle cloud communication environment

The invention discloses a multi-level encryption authentication and data integrity protection method in a vehicle cloud communication environment, and aims to guarantee communication security between an electric vehicle and a cloud platform. According to the method, a unique digital certificate is allocated to each electric vehicle, and identity verification of a vehicle end and a cloud platform is realized in combination with a two-way TLS handshake protocol. In the data transmission process, the transmission content is encrypted by adopting a symmetric encryption algorithm, so that the confidentiality of the data is ensured. Meanwhile, the integrity of information in the data transmission process is ensured by using a digital signature technology, and tampering is prevented. And if the data verification fails, an early warning mechanism is triggered, and abnormal information is fed back to a related supervision platform through the V2X communication system, so that instant response and fault positioning are realized. According to the method, potential safety hazards such as man-in-the-middle attack and data leakage in the communication process can be effectively prevented, and the safety and data integrity of an Internet of Vehicles system are improved. The method is widely applied to scenes such as intelligent transportation, motorcade management and electric vehicle remote monitoring.
Owner:SHANDONG JIANZHU UNIV

Intelligent door lock safety management and control system based on Internet of Things

The invention discloses an intelligent door lock safety management and control system based on the Internet of Things, and relates to the technical field of door lock management and control. A sliding window is adopted to process data, and improved adaptive median filtering is used for noise reduction; environment parameter dynamic features are extracted, and a three-dimensional environment feature vector is constructed; handle pressure distribution is collected, the angle change rate and complexity are calculated, and behavior feature vectors are constructed; generating a 128-bit dynamic key in combination with environment and behavior characteristics; and mixing the dynamic key and the master key, encrypting and transmitting to the cloud for password authentication and instruction updating. Multi-dimensional environment parameters are collected in real time, space-time association fusion is carried out on the multi-dimensional environment parameters and user operation behaviors, a dynamic secret key is generated, it is ensured that each authentication process is bound with the current environment and user operation characteristics, the secret key cannot be predicted or copied through historical data, and the defense capacity for man-in-the-middle attacks and data stealing is improved.
Owner:NANJING FORESTRY UNIV

Computer network equipment remote control system for Internet of Things

The invention discloses a computer network equipment remote control system for the Internet of Things, and relates to the technical field of the Internet of Things, and the remote control system comprises an equipment end security agent module which is deployed on controlled network equipment and is used for collecting equipment operation state data and environment data and executing an instruction from a cloud control platform, and the cloud control platform is connected with the equipment end security agent module. And the equipment end security agent module is in communication connection with the equipment end security agent module through a network, and is used for receiving, storing and processing the equipment operation state data and the environment data. A high-reliability communication basis conforming to a network security protocol is constructed, the risk of illegal equipment access and man-in-the-middle attack is fundamentally eradicated, the integrity, confidentiality and authenticity of control instructions and state data in the transmission process are ensured, and the security level of the whole Internet of Things equipment control network is remarkably improved.
Owner:HOHHOT XUNHE TECHNOLOGY CO LTD

Industrial gateway data encryption transmission method based on national secret algorithm

The invention discloses an industrial gateway data encryption transmission method based on a national cryptographic algorithm, which relates to the technical field of information security, and comprises the following steps: S001, an industrial gateway and a server respectively generate collaborative challenge seeds based on a physical random number source, and confirm consistency after exchange and synchronous comparison, so as to ensure that a session initial entropy source is synchronous and cannot be counterfeited; according to the method, through multiple mechanisms such as collaborative challenge seed, time consistency monitoring, intermediate parameter bidirectional comparison, symmetric cross validation, full-process mapping identification and link hash fingerprint, real-time identification and blocking can be ensured when each link of key negotiation encounters delay disturbance or man-in-the-middle attack, and session key inconsistency and pseudo-encryption link are prevented. Through data packet level mapping identification and Hash fingerprint bidirectional evidence storage, traceability and non-repudiation of a communication path are realized, and link security and anti-attack capability of industrial control and key infrastructure are guaranteed.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Security authentication method and device for eSIM network access, electronic equipment and storage medium

The embodiment of the invention relates to a security authentication method and device for eSIM network access, electronic equipment and a storage medium, and the method comprises the steps: obtaining first eSIM identification information, first equipment identification information and first user identification information in response to a received network access request; determining a verification hash value based on the first eSIM identification information, the first device identification information and the first user identification information; the verification hash value is sent to the cloud server and the equipment security chip for verification, the cloud server activates the network under the condition that the verification hash value passes verification, and the equipment security chip accesses the network under the condition that the verification hash value passes verification. According to the scheme, data of multiple dimensions of eSIM identification information, equipment identification information and user identification information are fused through Hash, deep association of different data is achieved, an irreversible multi-dimensional binding certificate is formed, multiple pieces of data need to be stolen at the same time for cracking, clone attacks can be effectively prevented, and the purpose of resisting man-in-the-middle attacks is achieved.
Owner:BEIJING TSINGTENG MICROSYSTEM CO LTD

Third-party quantum summation method with bidirectional identity authentication mechanism based on cluster state

The invention relates to the technical field of quantum security computing communication, and discloses a cluster state-based third-party quantum summation method with a bidirectional identity authentication mechanism, which comprises the following steps of: firstly, realizing bidirectional identity authentication between a participant and a third party in a quantum channel by pre-sharing secret identity information and a hash function in combination with a decoy photon technology; and impersonation and man-in-the-middle attack are fundamentally eradicated. And after the authentication is passed, the participant randomly executes measurement or reflection operation on the particle to which the participant belongs, so that an encrypted private key can be generated under the assistance of a third party, and external eavesdropping and internal participant attack can be jointly detected according to an operation combination to form multi-level security protection. Finally, the third party can only calculate the bitwise modular binary sum of the private bit string of each party, and cannot obtain any single input value. According to the method, authentication and calculation are organically fused, unconditional security is guaranteed, and meanwhile, the quantum capability requirements of participants are remarkably reduced.
Owner:SUZHOU UNIV

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

A network security identity authentication system based on cryptographic technology and its implementation method

This invention discloses a cryptographically based network security authentication system and implementation method. By constructing a time-varying elliptic curve group and incorporating the device-level physical unclonability feature, this system achieves: 1. Automatically updating cryptographic parameters during each authentication cycle, eliminating the security risks of fixed-parameter systems; 2. Deep integration of hardware-level key protection and software cryptography; and 3. Provably secure quantum computing resistance. Tests have shown that this system improves security by five orders of magnitude compared to the AES-256+ECDSA solution in resisting man-in-the-middle attacks and replay attacks.
Owner:CHANGCHUN GOLDSUN HI-TECH CO LTD

Firmware upgrade switching device based on encryption verification and physical isolation

The invention mainly relates to the technical field of firmware upgrading, and provides a firmware upgrading switching device based on encryption verification and physical isolation in order to improve the security and convenience of firmware upgrading, which is characterized in that an encryption algorithm is set in the switching device, and after the legality of target equipment is verified based on the encryption algorithm, the switching device is connected with the encryption algorithm; through combined control of a relay and an optical coupling isolator, physical disconnection and connection of a data channel in the upgrading process are achieved, it is ensured that a communication channel is completely cut off in an unauthorized state, the risks of man-in-the-middle attack, malicious code injection and data stealing are remarkably reduced, and higher-level safety guarantee is provided by combining an algorithm and a hardware level.
Owner:四川长虹新网科技有限责任公司

Encryption sending method and device, equipment, storage medium and product

The invention discloses an encryption sending method and device, equipment, a storage medium and a product, and the method comprises the steps that a sending place node employs a first symmetric key and a second public key of a target trusted execution environment unit to encrypt to-be-transmitted target data, obtains encrypted data, and sends the encrypted data to a destination node, the target trusted execution environment unit is selected from a trusted execution environment unit set in the destination node, so that the destination node decrypts the encrypted data by adopting the second private key and the first symmetric key to obtain the target data, and the target trusted execution environment unit is selected from the trusted execution environment unit set in the destination node. According to the method, the second public key is combined for secondary encryption, so that only the target trusted execution environment unit can decrypt the data, and key leakage and man-in-the-middle attack are effectively prevented. Besides, the target trusted execution environment unit can be flexibly and temporarily determined from the trusted execution environment unit set, so that other equipment can be prevented from acquiring the second public key in advance, and the security of data encryption is further improved.
Owner:SHENZHEN POWER SUPPLY PLANNING DESIGN INST

A method and system for multi-backdoor pollution attack oriented to wireless brain-computer interface

The application discloses a kind of multi backdoor pollution attack methods and systems for wireless brain-computer interface, belong to brain-computer interface security and machine learning confrontation attack technical field, wherein method includes training phase and reasoning phase, training phase uses multiple different trigger modes, constructs pollution sample, uses the training set of being polluted to train electroencephalogram decoding model, obtains trained electroencephalogram decoding model;Reasoning phase, implement man-in-the-middle attack to Bluetooth communication link, intercept the data packet sent from electroencephalogram acquisition equipment to wireless brain-computer interface system, according to the target category of expected control, implement corresponding trigger mode to the intercepted data packet, obtain tampered data packet, use electroencephalogram decoding model to infer tampered data packet, output the target category of expected control.The application combines Bluetooth man-in-the-middle attack with training phase data pollution, so as to realize arbitrary control to model output by selectively injecting different trigger modes in reasoning phase.
Owner:HUAZHONG UNIV OF SCI & TECH

Bidirectional system authentication method and device, equipment and storage medium

The invention discloses a bidirectional system authentication method, device and equipment and a storage medium, and relates to the technical field of communication, and the method realizes reliable verification and authorization of a user identity through a series of safe and efficient authentication processes. Firstly, by obtaining an authorization service link and skipping to an authentication server, the entrance security and normalization of the authentication process are ensured; and then, a challenge code is applied and signed, so that the authentication security is further enhanced, and security threats such as man-in-the-middle attack and the like are prevented. By applying for the token from the authentication server and receiving the token after verification is passed, accurate identification and authorization management of the user identity are realized. The process not only guarantees the security of the user data, but also improves the overall security of the system, simplifies the authentication operation of the user, and improves the user experience.
Owner:太保科技有限公司

SDN-oriented trusted dynamic routing construction method and system

The invention belongs to the technical field of networks, and particularly relates to an SDN-oriented trusted dynamic routing construction method and system. The method comprises the following steps: constructing a credible control plane by utilizing a credible computing technology for measuring and protecting the integrity of the control plane; a trusted path between a data plane and a control plane is constructed based on a remote attestation technology, and the integrity of routing table information is ensured; routing table rules are updated in an incremental mode, and performance losses caused by remote attestation and encryption and decryption processes are reduced. According to the method, the SDN controller can be protected from being attacked and damaged, modification of flow table rules, flow forgery or initiation of denial of service attacks can be defended, communication links between the SDN controller and each switch in the network can be protected, man-in-the-middle attacks, data tampering or information leakage and the like can be defended, and the VNF with virtualized network functions can be protected. The attack of malicious system software is prevented.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Star flash MESH-based wireless sensor network system and method

The invention belongs to the field of wireless communication and Internet of Things, and provides a wireless sensor network system based on star flash MESH, which comprises a wireless Mesh network formed by a plurality of nodes, and the nodes at least comprise one or more of star flash common nodes, star flash relay nodes, star flash fusion nodes and star flash low-power consumption nodes. According to the invention, through a hybrid node architecture and a double-loader design, low power consumption and high bandwidth requirements are considered, and high-speed services such as audio and video, firmware upgrade and the like are supported; end-to-end encryption and identity authentication are realized by adopting a national cryptographic algorithm, so that the network security is improved, and replay and man-in-the-middle attack are prevented; meanwhile, the protocol stack is designed in a layered mode, the modularization degree is high, and dynamic role configuration and flexible service expansion are supported; a quick relay mark and a sliding window anti-replay mechanism are introduced into a network layer, so that the forwarding efficiency is improved while the safety is ensured; eCDH and PIN authentication are combined in the network distribution stage, and safe and credible equipment network access and key management are achieved.
Owner:SHENZHEN WENCHANG INTELLIGENT NETWORK CO LTD

Communication method and related device

The invention provides a communication method and a related device, which are applied to the technical field of communication. According to the embodiment of the invention, the first communication device can judge whether the man-in-the-middle attack exists or not based on the feature information, and the feature information is determined based on the reference information of the second communication device. And determining whether the man-in-the-middle attack exists or not according to the first feature information and the second feature information, so that the first communication device can disconnect with the current equipment in time under the condition of determining that the man-in-the-middle attack exists, the man-in-the-middle attack is resisted, and the communication security is effectively ensured.
Owner:HUAWEI TECH CO LTD

Authentication method and related apparatus

This disclosure provides an authentication method and a related apparatus. The method includes: A terminal device receives a first received encrypted reference signal corresponding to a first sent encrypted reference signal that is generated by an access network device using a pilot key and a first reference signal and transmitted through a channel; the terminal device performs channel estimation by using the first received encrypted reference signal and the first sent encrypted reference signal, to obtain downlink channel state information; and the terminal device sends first information to the access network device, where the first information includes the downlink channel state information, to effectively defend against man-in-the-middle attacks.
Owner:HUAWEI TECH CO LTD

Authentication key generation method and device of boundary device, terminal device and storage medium

The invention discloses an authentication key generation method and device of boundary equipment, terminal equipment and a storage medium, and relates to the technical field of wireless communication, and the method comprises the steps: collecting the real-time context information of the boundary equipment; generating a corresponding context feature value according to the real-time context information by adopting a national cryptographic hash algorithm; and by taking the context characteristic value, the packet loss rate threshold judgment result and the electromagnetic interference level as input data, performing key derivation operation in combination with the main root key and the random root key, and generating a one-time authorization authentication key. According to the method, key derivation operation is carried out in combination with dynamic parameters such as the main root key, the random root key, the packet loss probability threshold judgment result and the electromagnetic interference level, so that the generated one-time authorization authentication key has high randomness and unpredictability, and the situation of key multiplexing can be effectively avoided; therefore, the security risk of man-in-the-middle attack can be effectively avoided, and the security of equipment authentication is effectively improved.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Power distribution network recovery method and device for coping with man-in-the-middle attack

The invention provides a power distribution network recovery method and device for coping with man-in-the-middle attack, and the method comprises the steps: inputting a state parameter of a target power distribution network and a man-in-the-middle attack parameter into a first fault recovery model when the target power distribution network is subjected to the man-in-the-middle attack; based on the state parameter of the target power distribution network, the man-in-the-middle attack parameter, and a target function, a communication network recovery constraint, a physical system recovery constraint, a communication and physical coupling constraint and a man-in-the-middle attack influence constraint of a first fault recovery model, solving to obtain a first fault recovery strategy of the target power distribution network; the first fault recovery strategy comprises a line switching sequence, a load recovery plan and a communication link recovery sequence of the target power distribution network; and based on the first fault recovery strategy of the target power distribution network, recovering the target power distribution network. In this way, the fault recovery strategy is optimized by comprehensively considering the coupling relation between the communication network and the physical system and the man-in-the-middle attack influence, and the fault recovery efficiency of the power distribution network when the power distribution network is subjected to the man-in-the-middle attack can be improved.
Owner:NORTH CHINA ELECTRIC POWER UNIV +3

Road side unit communication method and electronic equipment

The invention provides a road side unit communication method and electronic equipment, and the method comprises the steps: a first road side unit selects a second road side unit from a traffic network, and carries out the identity authentication with the second road side unit; in response to the fact that the identity authentication of the second road side unit on the first road side unit passes, the second road side unit performs key negotiation with the first road side unit to obtain a first session key corresponding to the first road side unit and a second session key corresponding to the second road side unit; and the first road side unit communicates with the second road side unit by using the first session key, and the second road side unit communicates with the first road side unit by using the second session key. Through an identity authentication mechanism, mutual authentication of identities of two communication parties is realized, man-in-the-middle attack and identity counterfeiting behaviors are effectively prevented, and the security of a communication process is enhanced. After identity authentication is completed, the two communication parties negotiate to generate a session key for subsequent encryption communication, and confidentiality and integrity of data in the transmission process are guaranteed.
Owner:BEIJING UNIV OF POSTS & TELECOMM