Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

83 results about "Man-in-the-middle attack" patented technology

In cryptography and computer security, a man-in-the-middle attack (MITM) is an attack where the attacker secretly relays and possibly alters the communications between two parties who believe they are directly communicating with each other. One example of a MITM attack is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all relevant messages passing between the two victims and inject new ones. This is straightforward in many circumstances; for example, an attacker within reception range of an unencrypted wireless access point (Wi-Fi) could insert themselves as a man-in-the-middle.

Data security transmission method based on ML-KEM algorithm and PUF

The invention discloses a data security transmission method based on an ML-KEM algorithm and a PUF, and the method comprises the steps: in a registration stage, mobile equipment generates an anti-quantum key through employing a PUF technology, and a CA issues an anti-quantum digital certificate based on a Falcon algorithm and a cryptographic accumulator; in an identity authentication stage, a mobile device and an edge gateway complete bidirectional identity authentication by exchanging identity labels, anti-quantum certificates and authentication key parameters in combination with a Falcon algorithm and PUF challenge-response, and negotiate to generate a shared key by using an ML-KEM algorithm, thereby effectively defending threats such as man-in-the-middle attack, replay attack and identity counterfeiting; in a data transmission stage, two communication parties realize data encryption transmission by adopting a symmetric encryption algorithm, and data integrity and source credibility are guaranteed in combination with a Falcon digital signature; the whole scheme has the advantages of quantum security resistance, efficient authentication, dynamic key updating, lightweight encryption and the like.
Owner:SICHUAN UNIV +1

Charging pile and charging pile control method

The invention relates to the technical field of charging facility network security, in particular to a charging pile and a charging pile control method. According to the charging pile, digital certificate dual verification and encryption communication are carried out between the cloud server and the gateway board, the risk of user information leakage caused by man-in-the-middle attack, data eavesdropping and the like is reduced, and the user experience is improved by carrying out second encryption verification on the gateway board and the control board. The risk that the data of the charging pile are tampered due to counterfeiting of the digital certificate is reduced, and compared with identity verification achieved only based on a cloud server in the prior art, the technical effect of improving the network security of the charging pile is achieved.
Owner:DONGGUAN AOHAI TECH CO LTD

System and method for pre-emptive detection of email impersonation and man-in-the-middle attacks using ai-driven telemetry and data leak prevention remediation

Disclosed is a system and method for pre-emptive detection, attribution, and reversal of outbound data leaks and impersonation-based attacks occurring beyond traditional enterprise endpoint security boundaries. An outbound instrumentation gateway may insert telemetry identifiers into outbound electronic communications, enabling persistent tracking of message interactions within external or third-party domains. A RAPTORAI analytics engine may process metadata collected from these interactions using a multi-stage artificial-intelligence pipeline that combines predictive anomaly modeling and large-language-model (LLM) attribution. When anomalous or malicious behavior is detected, a Double DLP remediation engine may be activated, which is capable of pausing, auto-locking, or revoking message access after transmission but before compromise. A PRE-Crime telemetry layer provides visibility into early-stage reconnaissance activities by threat actors operating beyond the endpoint, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR) to effectively zero. Administrative dashboards present live analytics of third-party risks, reconnaissance indicators, and auto-remediation events.
Owner:KHAN ZAFAR

Third-party quantum summation method with bidirectional identity authentication mechanism based on cluster state

The invention relates to the technical field of quantum security computing communication, and discloses a cluster state-based third-party quantum summation method with a bidirectional identity authentication mechanism, which comprises the following steps of: firstly, realizing bidirectional identity authentication between a participant and a third party in a quantum channel by pre-sharing secret identity information and a hash function in combination with a decoy photon technology; and impersonation and man-in-the-middle attack are fundamentally eradicated. And after the authentication is passed, the participant randomly executes measurement or reflection operation on the particle to which the participant belongs, so that an encrypted private key can be generated under the assistance of a third party, and external eavesdropping and internal participant attack can be jointly detected according to an operation combination to form multi-level security protection. Finally, the third party can only calculate the bitwise modular binary sum of the private bit string of each party, and cannot obtain any single input value. According to the method, authentication and calculation are organically fused, unconditional security is guaranteed, and meanwhile, the quantum capability requirements of participants are remarkably reduced.
Owner:SUZHOU UNIV

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Encryption sending method and device, equipment, storage medium and product

The invention discloses an encryption sending method and device, equipment, a storage medium and a product, and the method comprises the steps that a sending place node employs a first symmetric key and a second public key of a target trusted execution environment unit to encrypt to-be-transmitted target data, obtains encrypted data, and sends the encrypted data to a destination node, the target trusted execution environment unit is selected from a trusted execution environment unit set in the destination node, so that the destination node decrypts the encrypted data by adopting the second private key and the first symmetric key to obtain the target data, and the target trusted execution environment unit is selected from the trusted execution environment unit set in the destination node. According to the method, the second public key is combined for secondary encryption, so that only the target trusted execution environment unit can decrypt the data, and key leakage and man-in-the-middle attack are effectively prevented. Besides, the target trusted execution environment unit can be flexibly and temporarily determined from the trusted execution environment unit set, so that other equipment can be prevented from acquiring the second public key in advance, and the security of data encryption is further improved.
Owner:SHENZHEN POWER SUPPLY PLANNING DESIGN INST

A method and system for multi-backdoor pollution attack oriented to wireless brain-computer interface

The application discloses a kind of multi backdoor pollution attack methods and systems for wireless brain-computer interface, belong to brain-computer interface security and machine learning confrontation attack technical field, wherein method includes training phase and reasoning phase, training phase uses multiple different trigger modes, constructs pollution sample, uses the training set of being polluted to train electroencephalogram decoding model, obtains trained electroencephalogram decoding model;Reasoning phase, implement man-in-the-middle attack to Bluetooth communication link, intercept the data packet sent from electroencephalogram acquisition equipment to wireless brain-computer interface system, according to the target category of expected control, implement corresponding trigger mode to the intercepted data packet, obtain tampered data packet, use electroencephalogram decoding model to infer tampered data packet, output the target category of expected control.The application combines Bluetooth man-in-the-middle attack with training phase data pollution, so as to realize arbitrary control to model output by selectively injecting different trigger modes in reasoning phase.
Owner:HUAZHONG UNIV OF SCI & TECH

Star flash MESH-based wireless sensor network system and method

The invention belongs to the field of wireless communication and Internet of Things, and provides a wireless sensor network system based on star flash MESH, which comprises a wireless Mesh network formed by a plurality of nodes, and the nodes at least comprise one or more of star flash common nodes, star flash relay nodes, star flash fusion nodes and star flash low-power consumption nodes. According to the invention, through a hybrid node architecture and a double-loader design, low power consumption and high bandwidth requirements are considered, and high-speed services such as audio and video, firmware upgrade and the like are supported; end-to-end encryption and identity authentication are realized by adopting a national cryptographic algorithm, so that the network security is improved, and replay and man-in-the-middle attack are prevented; meanwhile, the protocol stack is designed in a layered mode, the modularization degree is high, and dynamic role configuration and flexible service expansion are supported; a quick relay mark and a sliding window anti-replay mechanism are introduced into a network layer, so that the forwarding efficiency is improved while the safety is ensured; eCDH and PIN authentication are combined in the network distribution stage, and safe and credible equipment network access and key management are achieved.
Owner:SHENZHEN WENCHANG INTELLIGENT NETWORK CO LTD

Authentication method and related apparatus

This disclosure provides an authentication method and a related apparatus. The method includes: A terminal device receives a first received encrypted reference signal corresponding to a first sent encrypted reference signal that is generated by an access network device using a pilot key and a first reference signal and transmitted through a channel; the terminal device performs channel estimation by using the first received encrypted reference signal and the first sent encrypted reference signal, to obtain downlink channel state information; and the terminal device sends first information to the access network device, where the first information includes the downlink channel state information, to effectively defend against man-in-the-middle attacks.
Owner:HUAWEI TECH CO LTD

Authentication key generation method and device of boundary device, terminal device and storage medium

The invention discloses an authentication key generation method and device of boundary equipment, terminal equipment and a storage medium, and relates to the technical field of wireless communication, and the method comprises the steps: collecting the real-time context information of the boundary equipment; generating a corresponding context feature value according to the real-time context information by adopting a national cryptographic hash algorithm; and by taking the context characteristic value, the packet loss rate threshold judgment result and the electromagnetic interference level as input data, performing key derivation operation in combination with the main root key and the random root key, and generating a one-time authorization authentication key. According to the method, key derivation operation is carried out in combination with dynamic parameters such as the main root key, the random root key, the packet loss probability threshold judgment result and the electromagnetic interference level, so that the generated one-time authorization authentication key has high randomness and unpredictability, and the situation of key multiplexing can be effectively avoided; therefore, the security risk of man-in-the-middle attack can be effectively avoided, and the security of equipment authentication is effectively improved.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Power distribution network recovery method and device for coping with man-in-the-middle attack

The invention provides a power distribution network recovery method and device for coping with man-in-the-middle attack, and the method comprises the steps: inputting a state parameter of a target power distribution network and a man-in-the-middle attack parameter into a first fault recovery model when the target power distribution network is subjected to the man-in-the-middle attack; based on the state parameter of the target power distribution network, the man-in-the-middle attack parameter, and a target function, a communication network recovery constraint, a physical system recovery constraint, a communication and physical coupling constraint and a man-in-the-middle attack influence constraint of a first fault recovery model, solving to obtain a first fault recovery strategy of the target power distribution network; the first fault recovery strategy comprises a line switching sequence, a load recovery plan and a communication link recovery sequence of the target power distribution network; and based on the first fault recovery strategy of the target power distribution network, recovering the target power distribution network. In this way, the fault recovery strategy is optimized by comprehensively considering the coupling relation between the communication network and the physical system and the man-in-the-middle attack influence, and the fault recovery efficiency of the power distribution network when the power distribution network is subjected to the man-in-the-middle attack can be improved.
Owner:NORTH CHINA ELECTRIC POWER UNIV +3

Method, device and server for obtaining platform identity certificate

The present specification provides a platform identity certificate acquisition method, device and server. By performing interaction verification of identification information related to a security chip, security risks such as man-in-the-middle attacks and platform replacement attacks in the platform identity certificate acquisition process can be effectively reduced, the platform identity certificate of a target object can be efficiently and safely generated and transmitted, the platform identity certificate is prevented from being stolen or tampered with, and the data security of the target object is protected.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Data encryption and key generation method for online payment

The application relates to the technical field of key generation, in particular to a data encryption and key generation method for online payment, which comprises the following steps: extracting a touch rhythm to generate a sequence, performing round encoding to construct a bit structure, and combining amount information to generate a key. In the application, user touch behavior characteristics are converted into a rhythm sequence, a dynamic encryption basis is constructed through sequence rotation and bit mapping mode, a user behavior level parameter is introduced in the key generation process, payment behavior and transaction data are deeply bound by fusing amount section labels, the key generation no longer depends on fixed rules or external key negotiation process, independent key output on the terminal side is realized through sequence structure reorganization and template parameter matching, the individuality and unpredictability of the key are improved, the identification ability for imitated behavior and the protection effect for man-in-the-middle attack are enhanced, and the problems of static characteristics and response lag of the traditional key mechanism in actual deployment are effectively alleviated.
Owner:JUEBA TECH CO LTD

Fine-grained relational database access control and security data interaction method

The invention discloses a fine-grained relational database access control and security data interaction method, which is characterized by comprising the following steps of: initializing, extracting an SQL (Structured Query Language), transmitting a symmetric key through a Diffie-Hellman protocol, encrypting a query result of the SQL through CP-ABE attribute encryption and generating a private key fragment, complementing a private key of an SDK (Software Development Kit) client and decrypting data. According to the method, a database name, a table name and a field name to be accessed are extracted by adopting an SQL analysis method and are compared with access authority entity configuration registered by a user, and a private key complementing method is provided based on attribute encryption, so that a private key fragment can be complemented only when a specific client uses own private attribute; in this way, only the private key fragment is transmitted on the communication channel, even if a third party initiates a man-in-the-middle attack and obtains the private key fragment, the complete private key cannot be derived, the data cannot be used, and the minimum use permission requirement for database access and the requirement for safe data transmission and use are met.
Owner:GUIZHOU DATABAO NETWORK TECH CO LTD

RFID-based bidirectional authentication and authorization method and system for operation and maintenance lockset and key of energy storage system

The invention relates to an RFID-based bidirectional authentication and authorization method for an operation and maintenance lock and a key of an energy storage system. The method comprises the following steps: registering an intelligent key Ti; the background management system S generates a secret certificate; writing the digital identity set into a storage unit of the intelligent key Ti; the intelligent key Ti sends a first message M1 to the lock Rj; judging whether the first current timestamp T1 is in a preset effective time window T or not; the background management system S remotely authorizes and responds; the lock Rj forwards authorization; and finally verifying and authorizing the intelligent key Ti. The key advantage of the invention lies in that bidirectional authentication is realized, the lockset can verify the legality of the intelligent key, and the intelligent key can also verify the legality of the lockset and the background management system, so that an end-to-end trust chain is effectively constructed, 'man-in-the-middle attack 'and'disguise attack' are fundamentally eradicated, and the security of the lockset is improved. The authenticity of the operation and maintenance operation instruction source and the correctness of the target equipment are ensured, and the safety level of the transformer substation energy storage system is greatly improved.
Owner:ANHUI ELECTRIC POWER DESIGN INST CEEC

A method for secure transmission of a collaborative encryption key

The application discloses a secure transmission method of a cooperative encryption key, which can realize secure transmission of the cooperative encryption key, cannot obtain a private key plaintext by a man-in-the-middle, can solve the problem that the private key of the cooperative encryption key is not landed when the cooperative encryption key is split into two parts, effectively deals with the transmission security of the cooperative encryption key, can well guarantee the security of the cooperative encryption key pair in the distribution transmission process, thereby guaranteeing the security of the key and avoiding a man-in-the-middle attack.
Owner:KOAL SOFTWARE CO LTD

An identity feature-based target range system bidirectional authentication method and system

This invention discloses a two-way authentication method and system for a target range system based on identity features, belonging to the field of target range system security technology. It includes three verification stages: the control server first generates a random challenge value and sends it to the target device; the target device calculates a response value using a non-cloning function and returns it. After successful verification, both parties exchange and confirm random numbers through hash operations, ultimately establishing a secure communication link. By dynamically generating random challenge values ​​and combining a two-way authentication mechanism using non-cloning functions and hash chains, it solves the problems of identity forgery, man-in-the-middle attacks, and replay attacks in traditional methods, offering advantages such as improved identity authentication security and ensured communication reliability.
Owner:HUANENG POWER INT INC +1

Single sign-on through customer authentication systems

Described herein is a system, method, and non-transitory computer readable medium related to a service provider using a third party identity provider to authenticate a user with improved security. An authentication token is received from the identity provider, and can be verified against internal configuration information. The internal configuration information includes data that is not included in the authentication token, and therefore, is not vulnerable to some security attacks, such as a man-in-the-middle attack. After the authentication token is verified, the internal configuration information and authentication token may be used to create a custom identifier, referred to as an identity ID. The identity ID may be used by the service provider to verify user access to resources.
Owner:CAPITAL ONE SERVICES LLC

Anti-quantum cryptography data security protection system and method for juveniles

The invention discloses an anti-quantum cryptography data security protection system and method for juveniles. Aiming at the problem that an existing education APP and intelligent equipment only adopt a traditional encryption algorithm (such as RSA and AES) and cannot resist quantum computing attacks, the invention provides a four-layer protection architecture of a terminal layer, a transmission layer, a storage layer and a supervision layer. The terminal layer is provided with a PQC chip in advance and encrypts the biological characteristic data by using a lattice password; the transmission layer establishes a quantum security VPN channel and deploys a forward security protocol; the storage layer adopts an anti-quantum block chain evidence storage technology; the supervision layer introduces a PQC auditing and threat intelligence sharing mechanism. Through experimental verification, the blocking rate of the system to quantum brute force attack reaches 100%, and the man-in-the-middle attack breakthrough rate is reduced to 0%. The method is suitable for education platforms, child intelligent equipment and other scenes, and the long-term safety risk of juvenile data in the quantum era is effectively solved.
Owner:李雪

A network traffic isolation method, system, device, and medium

The application discloses a network flow isolation method, system, device and medium, and the application obtains to-be-transmitted data corresponding to a received network flow isolation request, and inputs the to-be-transmitted data into a preset target DHT network by responding to the network flow isolation request; time domain information corresponding to the to-be-transmitted data is read through the target DHT network; a path selection function of the target DHT network is constructed by using node data and the time domain information corresponding to the target DHT network; the to-be-transmitted data is transmitted according to a transmission path queue corresponding to the path selection function; the to-be-transmitted data is encrypted and decrypted by using a key pair of a node corresponding to the transmission path queue, target decrypted transmission data is generated; and the target decrypted transmission data is transmitted to a receiving end. The application solves the problem of limited bandwidth of a traditional horizontal isolation and vertical isolation device. The application realizes network self-organization of flow isolation, enhances effective bandwidth of the flow isolation network, and avoids man-in-the-middle attacks.
Owner:GUANGDONG POWER GRID CO LTD +1

Apparatus and method for secure communication in wireless network

A transmitting station (110, 120) for a wireless communication network (100), in particular a Wi-Fi network (100), is disclosed. The transmitting station (110, 120) is configured to continuously broadcast a plurality of beacon frames (140) to one or more receiving stations (120, 110) of the wireless communication network (100), each beacon frame (140) comprising information for synchronizing a timer. Furthermore, the transmitting station (110, 120) is configured to transmit a data frame (150) to the one or more receiving stations (120, 110), the data frame (150) comprising an encryption timer value associated with the data frame (140). The sending station (110, 120) and the one or more receiving stations (120, 110) can detect man-in-the-middle attacks and take corresponding countermeasures accordingly.
Owner:HUAWEI TECH CO LTD

Defensive multi-factor authentication against phishing

Techniques are disclosed that relate to detecting and preventing phishing attacks (e.g., man-in-the-middle attacks) related to multi-factor authentication (MFA) or two-factor authentication (2FA) processes. A system is described that determines whether to allow or deny a subsequent authentication step based on a trust level determined between a computing device that made an initial authentication request to a service computer system and a computing device (e.g., a mobile device) that is required to perform the subsequent authentication step (e.g., a 2FA authentication step). The computing device associated with the subsequent authentication step evaluates the trust between the devices and determines whether to allow or deny the subsequent authentication step. The techniques of the present disclosure enhance the security of computer systems against phishing attacks while maintaining a satisfactory user experience for legitimate users.
Owner:PAYPAL INC

NFC encryption authentication system based on algebraic number theory

The invention discloses an NFC encryption authentication system based on an algebraic number theory, and belongs to the technical field of information security. The system comprises an NFC encryption authentication module, a data transmission optimization module and an intelligent interaction expansion module: generating public and private keys based on ideal operation by constructing an algebraic number field and an algebraic integer ring, and mapping NFC data into a ring element sequence to complete encryption and decryption; the transmission efficiency is optimized through number theory channel coding and data grouping, and the stability of big data transmission is improved; intelligent interaction and security enhancement are realized through user behavior modeling and a dynamic one-time key. Based on mathematical problem characteristics of algebraic number theory, attack means such as man-in-the-middle attack and cryptographic analysis are effectively resisted, NFC transmission efficiency and application expansibility are improved, and the method is suitable for scenes such as mobile payment, digital car keys and intelligent access control.
Owner:NANTONG UNIV

Unmanned edge device cluster anti-interference collaborative obstacle avoidance system and method based on identity verification and secret state interaction

PendingCN122001559AOvercome physical security hazardsavoid overheadUser identity/authority verificationComputer hardwareCiphertext
The invention discloses an unmanned edge device cluster anti-interference collaborative obstacle avoidance system and method based on identity verification and secret state interaction, and introduces dynamic structure homomorphic encryption DSHE and a lightweight identity-based encryption mechanism to solve the problems that encryption and decryption delay is high and the system is easily attacked by man-in-the-middle in the prior art. A lightweight encryption microchip LCMC is deployed in the system, and a dynamic structure homomorphic encryption DSHE arithmetic unit, an identity management unit and a decision arbitration unit DAU are integrated; the proxy auxiliary square operation protocol realizes relative measurement calculation of a ciphertext domain space through a pre-calculation lookup table; the identity preprocessor maps the identity label into an evaluation key and realizes ciphertext identity binding; according to the layered noise management strategy, operation is divided into three layers to implement differential control; a single-node top-speed self-decision mechanism triggers a special decryption accelerator DDA, hardware interruption is generated to directly take over an edge control unit, and the end-to-end obstacle avoidance response delay is less than 3 milliseconds.
Owner:文思涵

Dynamic and static analysis combined NAS equipment vulnerability detection method

The invention discloses an NAS (Network Attached Storage) equipment vulnerability detection method combining dynamic and static analysis, which comprises the following steps: in a local area network environment, executing full-function operation, and capturing and recording a plaintext communication message; in a local area network, full-function operation is carried out on network attached storage equipment, and plaintext traffic of communication between a client and the equipment is captured through man-in-the-middle attack. The method comprises the following steps of: manually checking flow, marking a user identity identifier in a message and a message operation sequence with a dependency relationship, performing automatic variation on key fields in the message according to variation rules of three vulnerabilities of preset command injection, memory damage and improper access control, replaying the key fields to NAS equipment, and performing protocol fuzz testing on the equipment; whether the protocol fuzz test is successful or not is detected by monitoring the response duration, the response state and the internal state of the NAS equipment; the firmware file is extracted from the NAS equipment by utilizing the vulnerability found in the fuzzy test, and the detection rate and the recall rate of the security vulnerability of the NAS equipment can be improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Data transmission method and device and computer storage medium

The invention provides a data transmission method and device and a computer storage medium, which are applied to the field of near field communication and are used for eliminating the risk that the NFC technology suffers from man-in-the-middle attack in a mobile payment scene. In the method, a card reader initiates an authorization request to a first device based on a public key in a key pair generated by the card reader, the first device encrypts a first authorization code according to a private key in the key pair generated by the first device and the public key sent by the card reader, and sends the encrypted first authorization code and the public key generated by the first device to the card reader together. And the card reader can decode the encrypted information sent by the first equipment by using the private key generated by the card reader and the public key sent by the first equipment. According to the technical scheme, the man-in-the-middle obtains the encrypted first authorization code in a manner of making up a card reader, but cannot decode the encrypted first authorization code, so that subsequent payment cannot be carried out by using the first authorization code, man-in-the-middle attack is effectively avoided, and the security of data transmission is improved.
Owner:HUAWEI TECH CO LTD

Joint authentication method based on TPM and TEE

The invention discloses a joint authentication method based on TPM and TEE, and belongs to the technical field of information security. The method is used for solving the technical problems that joint authentication in an existing scheme depends on spliced evidence, it cannot be guaranteed that a TPM state and a TEE state belong to the same execution context, and the risk of time window attack or context switching cheating exists. Through bidirectional authentication of an endorsement key and a secure start root key, independent hardware trust roots are fused into a unified joint trust root, and splicing dependence of authentication evidences is avoided; a hardware-level key negotiation and timestamp mechanism can resist man-in-the-middle attack and replay attack; the joint trust root serves as a unique trust source for subsequent state measurement and authentication, and it is ensured that TPM and TEE state measurement values are generated in the same trust domain; through time binding and space binding, space-time two-dimensional association of TPM and TEE measurement data is realized, and it can be effectively proved that the TPM and the TEE measurement data belong to the execution state of the same equipment at the same moment.
Owner:内蒙古峥创科技有限公司

Security risk assessment method for power production management system based on national secret algorithm

The invention discloses an electric power production management system security risk assessment method based on a national secret algorithm. According to the method, the inherent anti-attack ability of the algorithm is deeply coupled with the configuration compliance by introducing a national cryptographic algorithm strength correction factor, so that the risk level calculation can reflect the theoretical protection advantages of SM2, SM4 and other algorithms, and the influence of the actual operation and maintenance defects such as the key rotation period and the parameter configuration deviation on the risk can be captured. In a remote control instruction transmission scene, the basic risk value is corrected through the product of the algorithm strength coefficient and the configuration compliance rate, the problem that the man-in-the-middle attack risk is underestimated due to the lack of SM2 signature verification steps can be accurately identified, the one-sidedness of'algorithm compliance, namely security 'in traditional assessment is solved, and the method has the advantages of high accuracy and high reliability. The risk level better meets the actual combat requirement of the power production environment, a whole-process closed-loop mechanism from risk identification to disposal optimization is constructed, and the guiding value of risk assessment for actual safety construction is enhanced.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Man-in-the-middle detection method and apparatus

A man-in-the-middle detection method and apparatus. The method includes: A base station receives, in a first physical frame, a RRC message from user equipment UE; the base station receives from the UE a second RRC message including frame information of a second physical frame, and security protection is performed on the first RRC message and the second RRC message by using an access stratum AS security context established by the UE and the base station; and the base station determines whether the first physical frame matches the second physical frame. Thereby, whether a man-in-the-middle exists in air interface communication is determined by determining whether a physical frame in which the UE sends an uplink message matches a physical frame in which the base station receives the uplink message, to prevent the man-in-the-middle from bypassing detection through a mechanism of the man-in-the-middle and improve a man-in-the-middle detection rate.
Owner:HUAWEI TECH CO LTD

A strong password generation method and device based on user personal information, an electronic device, and a storage medium

ActiveCN119865310BKey distribution for secure communicationWebIDCode book
The application discloses a strong password generation method and device based on user personal information, electronic equipment and storage medium. The method comprises the following steps: in an offline state, obtaining a target website name and personal information of a password to be generated input by a user; based on the personal information, obtaining a pinyin full name or an English full name of the personal information; randomly selecting a preset first number of letters in the pinyin full name or the English full name, and performing random uppercase and lowercase conversion or special character replacement to obtain a first string; adding a preset second number of random digital characters before the first character or after the last character of the first string to generate a second string; and taking the second string as a generated strong password. The application adopts an offline mode to generate and store the strong password, effectively reduces the risk of man-in-the-middle attack and data leakage, and ensures that each generated password has high entropy and complexity by randomizing the personal information of the user, thereby effectively resisting various password cracking attacks.
Owner:NAT UNIV OF DEFENSE TECH