Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

116 results about "Mutual authentication" patented technology

Mutual authentication or two-way authentication refers to two parties authenticating each other at the same time, being a default mode of authentication in some protocols (IKE, SSH) and optional in others (TLS).

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

System and Method for Dual Remote Authentication of Digital Assisted Shopping Agents and Customers Using Proximity-Based Mobile Device Interactions, Enterprise Security, and Biometrics

Systems and methods are disclosed for dual, simultaneous, single-session, proximity-based, secure authentication of a Digital Assisted Shopping (DAS) representative and a customer in an unsecured remote location. The method includes installing a mobile banking application on the customer's device and an enterprise application on the DAS representative's device, both with biometric verification. Proximity detection using Bluetooth Low Energy (BLE) initiates a secure session via push notifications. A secure communication channel is established through a secure local handshake, involving encryption key exchange and mutual authentication. The system exchanges data related to customer profiles and financial accounts, continuously monitors geolocation using GPS, Wi-Fi, and cellular data, and performs periodic background biometric re-verifications. AI / ML algorithms analyze customer data to propose financial products and services, which are securely shared with the customer for review and selection. The system facilitates real-time enrollment and transaction processing, terminating the session upon detecting security breaches.
Owner:BANK OF AMERICA CORP

System and method for providing authenticated access between an implanted medical device and an external device

A system and method for facilitating bi-directional authentication between an external device and an implanted medical device (IMD), wherein a therapy application executing on the external device is operative to communicate with the IMD via wireless telemetry communications. Certified security credentials for respective devices may be provisioned with respect to the therapy application. Upon initiating wireless telemetry communications, respective certified security credentials are mutually verified by the external device and the IMD. Responsive to successful verification, a mutual authentication process may be executed between the external device and the IMD using a respective challenge-response sequence.
Owner:ADVANCED NEUROMODULATION SYSTEMS INC

Consumable verification method and verification system

The invention provides a consumable verification method and verification system. The system comprises a consumable, equipment, a user terminal and a cloud. According to the method, the two two-dimensional codes are set, so that the two verification codes participating in verification are both generated based on the equipment information and the consumable information, and compared with verification performed only according to the consumable information in the prior art, the method can achieve the effect that verification fails due to the fact that the equipment information cannot be counterfeited even if the consumable information can be counterfeited; besides, before the first verification code is generated, the equipment needs to be mutually authenticated with the consumable, and before the second verification code is generated, the cloud needs to verify the validity of the request, and the two verification codes can be obtained and verified after the dual verification is passed, so that the anti-cracking performance is remarkably improved; by integrating the factors, the safety of the method is relatively high.
Owner:SHANGHAI MEIJINGLING MEDICAL TECHNOLOGY CO LTD

Security access detection method and device based on industrial Internet of Things

The invention discloses a security access detection method and device based on the industrial Internet of Things, and the method comprises the steps: obtaining an identity verification factor of a communication entity of the industrial Internet of Things, introducing a PUF authentication mechanism between a gateway and a sensor according to the identity verification factor and a preset risk model, and obtaining a trust anchor, the method comprises the following steps: respectively carrying out identity verification on user registration, user login and an authentication stage according to a trust anchor to obtain a session key, carrying out verification calculation on the session key by adopting ProVeif to obtain a verification result, carrying out evaluation analysis on the verification result to obtain an evaluation analysis result, generating target identity verification information based on a session and the evaluation analysis result, and sending the target identity verification information to a server. Three identity verification factors (password, biological recognition and smart card) are seamlessly integrated with a lightweight encrypted graph primitive, and a PUF enhanced mutual authentication mechanism is introduced between a gateway and a sensor, so that the semantic security of a session key is improved.
Owner:SHAOXING MUNICIPAL DESIGN INST +1

A device control method, device, and distributed digital key system

This application provides a device control method, device, and distributed digital key system, relating to the field of communication technology. The method is applied to a first device and a second device. The first device stores de-identified information from first key-related information; the second device's secure element stores sensitive information from the first key-related information and second key-related information. The method includes: the first device sending de-identified information to the second device; the second device merging the de-identified information and sensitive information into first key-related information; the second device performing mutual authentication between the first and second devices based on the first and second key-related information; and the second device executing a preset instruction based on the authentication result. The technical solution provided by this application can improve the compatibility and security of terminal devices.
Owner:HUAWEI TECH CO LTD

Method and apparatus for registering terminal as digital key of vehicle

According to one embodiment of the present disclosure, an operation method of a terminal for performing pairing with an owner of a vehicle in a wireless communication system comprises the steps of: establishing a connection required for pairing with the owner of the vehicle using a first communication method; receiving a first message from the vehicle using a first communication method, the first message including information indicating a communication method for performing vehicle owner pairing; and performing mutual authentication with the vehicle based on information indicating a communication method for performing vehicle owner pairing. Embodiments of the present disclosure may include various other embodiments.
Owner:SAMSUNG ELECTRONICS CO LTD

Security key management system and method based on 5G communication module

The invention relates to the technical field of 5G communication modules, in particular to a security key management system and method based on a 5G communication module, a master key is generated after the 5G communication module and a network side complete mutual authentication, and the master key is safely isolated and stored as a trust basis of the whole system; according to service requirements, dynamically generating and managing multi-level sub-keys, and providing independent encryption and integrity protection for different functional domains; a sub-key is generated only when a real use scene is triggered, and a short-term caching and automatic expiration strategy is adopted, so that the security and the performance are both considered; performing encryption and integrity verification on all signaling and data streams by using the corresponding sub-keys; in a network switching or cell switching scene, pre-generating and quickly switching to a new key; according to the method, module operation and energy consumption overhead are greatly reduced through on-demand derivation and second-level expired caching strategies, non-inductive cell switching is achieved through a switching forecast pre-derivation and double-buffering atom switching mechanism, and time delay is remarkably shortened.
Owner:JIANGSU FULIAN COMM TECH CO LTD

Lightweight encryption and authentication method for wireless sensor network, and related device

Provided in the present application is a lightweight encryption and authentication method for a wireless sensor network. The method comprises: a gateway node respectively generating a sensor ephemeral key and a user ephemeral key on the basis of a one-way hash function and a preconfigured physically unclonable function, and respectively sending to a user end and a sensor node the sensor ephemeral key, the user ephemeral key, a preconfigured sensor long-term key and a preconfigured user long-term key; and after the user end and the sensor node are registered, the user end performing identity authentication on identity information currently input by a user, and performing, on the basis of the identity information, mutual authentication between the user end, the gateway node and the sensor node, so as to send a sensor hash-based message authentication code and a user hash-based message authentication code to the sensor node on the basis of the authentication result, such that the sensor node and the gateway node perform key agreement and authentication to obtain a session key, and wireless sensor network communication can thus be performed on the basis of the session key, thereby effectively solving the problem of authenticating the security of a wireless sensor network.
Owner:SHENZHEN UNIV

Consideration is given to a method of authenticating an access layer based on a public key infrastructure in a handover in a next generation wireless communication system

This disclosure relates to 5G or 6G communication systems for supporting higher data transmission rates than 4G communication systems such as LTE. In a wireless communication system according to an embodiment of the invention, a method for operating a serving base station for mutual authentication in the access layer (AS) portion during handover includes the following steps: receiving a measurement report from a terminal; determining, based on the measurement report, whether the terminal meets handover conditions; if the terminal meets the handover conditions, determining whether the target base station to which the terminal will connect during handover and the serving base station belong to the same authentication area (AA); and sending a handover command to the terminal, the handover command being configured differently depending on whether the target base station and the serving base station belong to the same AA.
Owner:SAMSUNG ELECTRONICS CO LTD

Internet of vehicles authentication method based on block chain and physical unclonable function

PendingCN121841729AAvoid the risk of identity impersonationImprove resistance to attackKey distribution for secure communicationUser identity/authority verificationPasswordEngineering
The invention discloses an Internet of Vehicles authentication method based on a block chain and a physical unclonable function, and relates to the field of data security, and the method comprises the steps: a vehicle and a communication object complete registration at a roadside base station, and a vehicle end integrates a PUF and a fuzzy extractor to generate a master key bound with equipment; during authentication, the vehicle uses the password, the biological characteristics and the PUF response to perform multi-factor authentication, and submits a Merkle proof of a target communication object to the roadside base station; and the roadside base station verifies the proof and confirms the access authority through the block chain smart contract, and assists the vehicle and the communication object to complete mutual authentication and negotiate the session key. According to the method, the block chain is utilized to ensure that data cannot be tampered, equipment cloning is resisted through the PUF, efficient authorization control is realized in combination with the Merkle tree, pseudo name dynamic updating and identity revocation are supported, and finally, the calculation, communication and storage overhead is remarkably reduced while the security is ensured.
Owner:BEIJING INST OF TECH

Mutual authentication for vehicular communications using a proxy device

Systems and methods are provided for authenticating vehicle communications. The system can identify, by a roadway device, a vehicle traveling on a roadway and authenticate a proxy device associated with the vehicle. Sensor data can be transmitted to the vehicle based on the authentication of the proxy device, wherein the vehicle is operated to navigate the roadway based on the sensor data.
Owner:TOYOTA MOTOR ENG & MFG NORTH AMERICA INC +1

Method, apparatus and system for authentication of a device

There are provided methods and apparatuses for multi-device authentication based on physical unclonable functions (PUFs). Embodiments may establish secure, authenticated communication groups. Methods are provided regarding full mutual authentication for a master device (agroup leader) and partial mutual authentication for other devices (group members). After a successful authentication using these methods, all devices may have the same root key, and each device may possess its own device key derived from that same root key. Further methods are provided regarding full mutual authentication without a master device and partial mutual authentication for other devices. Following successful authentication via these methods, all devices may have their own root key and their own device key which is derived from their own root key. Embodiments may also provide for dynamic authentication facilitating dynamic access of the device to the network.
Owner:HUAWEI TECH CO LTD

A safety access authentication method and system of an automobile detection equipment diagnostic instrument

The application discloses a kind of safety access authentication method and system of automobile detection equipment diagnostic instrument, method includes the following steps: the certificate management system of automobile whole vehicle system receives equipment certificate application, and issues and generates equipment certificate;Equipment certificate is filled in detection equipment diagnostic instrument;Automobile whole vehicle system and the detection equipment diagnostic instrument filled with equipment certificate carry out mutual authentication, and establish safe HTTPS transmission channel;Automobile whole vehicle system carries out authority management to the detection equipment diagnostic instrument filled with equipment certificate through safe HTTPS transmission channel.The application achieves the control of authentication session time limit, while greatly reducing equipment authentication time.
Owner:CHONGQING CHANGAN TECH CO LTD

Xin creation terminal compatibility mutual authentication and performance tuning pedestal system

The application discloses a kind of Xinxin terminal compatibility mutual authentication and performance tuning pedestal system, it is related to Xinxin terminal compatibility mutual authentication and performance tuning pedestal technical field, for solving the problem that address book module, service number module and workbench module under multiple Xinxin operating system and domestic CPU architecture are difficult to be uniformly carried, multi-security domain service routing error and terminal performance and compatibility are difficult to collaborative optimization;Around Xinxin terminal pedestal, collaborative work such as dependent reconstruction module, mobile application interface architecture rendering scheduling module is constructed, based on environmental compatibility score, Xinxin terminal pedestal construction and dependent reconstruction are automatically completed, under the premise that unlicensed personal information in public places is not collected, in combination with business module loading sequence optimization, interface scaling and rendering priority control and performance score and Xinxin compatibility test matrix closed loop optimization, improve the unified interface experience and running stability under multiple operating systems, multiple CPU architecture and multiple security domain deployment.
Owner:SICHUAN ZHONGDIAN AOSTAR INFORMATION TECHNOLOGIES CO LTD +1

Mutual authentication of devices or systems that are user-controllable and contain sensitive or confidential data

A method for mutual authentication of a controllable electronic device (ED) and its user (USER) who can control the device to provide the device with a service (DS), wherein the device (ED) stores sensitive or confidential data (DA) and is arranged to perform an operation (SO) for providing the service (DS) in an operation phase (OP) including a user authentication pre-step (UAP), and further includes a device authentication pre-phase (SDAP) for verifying the authenticity of the device (ED), so that if the device (ED) is found to be authentic at the end of the device authentication pre-phase (SDAP), the user (USER) can execute the operation phase (OP), whereas if the device (ED) is not found to be authentic, the user (USER) can prevent the execution of the operation phase (OP). [Selected Figure] Figure 1
Owner:LEDGER SAS

Authentication for ambient internet of things (IOT) devices

Disclosed are methods, systems, and computer-readable media to perform operations that include performing mutual authentication between an Ambient Internet of Things (AIoT) device and a control plane entity in a network, the control plane entity including an AIoT Function (AIoTF), an AIoT Authentication Server Function (AUSF), and AIoT Unified Data Management (UDM), wherein the AIoT AUSF is an authentication anchor.
Owner:APPLE INC

Security establishment method, terminal device, and network device

Security establishment method, terminal device, and network device. The security establishment method includes the steps of: generating a key pair by mutual authentication of a terminal device (110) and a service network, the terminal device (110) and the service network sharing K ASME using the generated key pair; the terminal device (110) and a roaming destination network of the terminal device (110) using K ASME generating K SEAF associated with the SEAF (50) using the steps (S140, S150); and the terminal device (110) and the roaming destination network using at least K SEAF and a SUPI identifying a subscriber in the service network generating K AMF associated with the AMF (60) using the steps (S140, S150).
Owner:NTT DOCOMO INC

System, device, method, and program

A system according to one aspect of the present disclosure includes a plurality of entities each of which provides a predetermined service. Each of the entities includes: an authentication unit that performs mutual authentication with another entity; an attestation unit that, when the mutual authentication is successful, mutually performs attestation with the other entity; and a process execution unit that, when the attestation is performed, executes a predetermined process for realizing the service with the other entity.
Owner:NT T INC

Security Handling Method and Apparatus, and Storage Medium

A security handling method includes a first device performing a security handling operation with a second device, where the security handling operation includes one or more of the following operations: mutual authentication or key agreement. After successfully performing the security handling operation, the first device monitors a status of a link between the first device and the second device. The first device re-performs the security handling operation with the second device based on a first moment, where the first moment is a moment at which it is monitored that the status of the link changes from an online state to an offline state.
Owner:HUAWEI TECH CO LTD

Secure health management system

Techniques and protocols for establishing secure communications between a display device, a sensor system, and a server system are disclosed. In certain embodiments, the techniques and protocols include secure diabetes device identification techniques and protocols, user-centric mutual authentication techniques and protocols, and device-centric mutual authentication techniques and protocols.
Owner:DEXCOM INC

Authentication method, system, client and server based on key derivation function

The application discloses a kind of authentication method, system, client and server based on key derivation function, wherein the method includes: client is based on key derivation function according to Secret Key, salt and master password Derivation authentication key, and corresponding verification key is calculated;VC of service end is obtained and verified, and the DID of service end in VC is used to obtain the communication key of service end from the verifiable data registry to encrypt account information, verification key and salt, and the encrypted content is sent to service end;Service end decrypts the account information to be registered, verification key and salt, and sends verification request to client, after verification succeeds, stores verification key and salt, and returns the account information of registration success to client;Verification key and salt are used for mutual authentication between client and server when user identity authentication is carried out.The application can completely authenticate user identity independently of TLS / SSL certificate chain, and improves the security of identity authentication.
Owner:北京泰尔英福科技有限公司

Certificateless key negotiation method and system supporting public key check and application

The invention relates to the field of electric power information network and data security, in particular to a certificateless key negotiation method and system supporting public key check and application, and the method comprises the steps: initializing a key generation center, outputting public parameters, constructing a revocation system based on an accumulator, and outputting revocation state parameters; the user sequentially generates a user private key and a user public key based on the public parameter, and sends the user public key to the key generation center, so that the key generation center returns part of the private key and part of the public key, accumulates the user to an accumulator, and updates the revocation state parameter; according to the invention, the revocation state of the user can be checked, the user generates the user key in the key generation process, and the key generation center only generates a part of keys, so that the problem of key escrow is solved, and the security of the user is improved. And the safety and light weight of the system are ensured.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +4

Network attack defense method and device, storage medium and computer program product

The invention provides a network attack defense method and device, a storage medium and a computer program product, and can solve the technical problem that a defense method consumes a large amount of computing resources in related technologies. The method comprises the following steps: confirming original feature data of a target data stream based on identity mutual recognition and key agreement operation of the target data stream; generating first format fingerprint information based on the original feature data; matching the first format fingerprint information with fingerprint information in a black and white fingerprint information base to obtain a fingerprint matching result; the fingerprint information base comprises black fingerprint information used for representing attack traffic and white fingerprint information used for representing normal traffic; and when the fingerprint matching result is that the first format fingerprint information is matched with the black fingerprint information, executing an interception operation. Based on fingerprint defense encryption attack, high-performance defense is achieved through non-decryption defense, and accurate matching is achieved through fingerprint defense. Therefore, the attack traffic is effectively blocked, the normal service traffic is released, and the service availability is ensured.
Owner:CHINA MOBILE GROUP DESIGN INST +1

Method and device for safely starting electronic control device through mutual authentication

The invention relates to a method and a device for safely starting an electronic control device through mutual authentication. According to one embodiment of the present disclosure, a method for implementing secure boot of an electronic control device through mutual authentication is provided, comprising: in response to receiving a boot signal of a micro control unit (MCU) included in the electronic control device in a vehicle, performing first integrity verification on secure boot firmware and a software security module; based on the first integrity verification result, mutual authentication between the security boot firmware and the software security module is carried out; and performing a second integrity verification on the first host firmware based on a result of the mutual authentication.
Owner:FESCARO CO LTD

Lightweight secure communication method suitable for resource-limited power internet of things

The invention provides a lightweight secure communication method suitable for a resource-constrained power Internet of Things, and the method comprises the steps: constructing a wireless power Internet of Things based on a WAPI architecture, enabling a sensor node to be in interactive connection with a network layer through an edge node, and enabling the network layer to comprise an access controller AC and an authentication server AS; a sensor node and an edge node are used for carrying out link negotiation, and the edge node triggers a WAI authentication process for a user and cooperates with an AS to complete mutual authentication with the user; once the authentication is passed, the AP initiates key negotiation for the user, and provides encryption and decryption services for the WAPI user through the WPI by using the negotiated key; representing a link channel between the sensor node and the edge node by adopting a spherical wave model; based on the ASCON, a 128-bit key shared between the sender and the receiver is adopted to encrypt and decrypt messages, including encryption, decryption and replacement. According to the method, various network attacks can be efficiently resisted, and the average energy consumption and the average time delay are remarkably reduced while the security is ensured.
Owner:ANHUI JIYUAN SOFTWARE CO LTD

Access-control-purpose system, communication system, access control method, and program

An access-control-purpose system that provides access information to first and second communication devices that perform mutual authentication using ID-based encryption creates an access secret key by generating a hash value of a logical sum of a character string based on the access information and a master secret key, creates first authentication data by generating a hash value of a first authentication ID for the first communication device by using a first hash function, creates second authentication data by generating a hash value of a second authentication ID for the second communication device by using a second hash function, creates access confirmation data configured by a product of the access secret key and a generation source of a subgroup in a group on a first elliptic curve and a product of the access secret key and a generation source of a subgroup in a group on a second elliptic curve, transmits the first authentication data and the access confirmation data to the first communication device, and transmits the second authentication data and the access confirmation data to the second communication device.
Owner:NT T INC

Mutually authenticated ECDHE key exchange for a device and a network using multiple PKI key pairs

A device can (i) store public keys Ss and Sn for a network and (ii) record private key sd. A network can record a corresponding private keys ss and sn. The device can (i) generate a device ephemeral PKI key pair (Ed, ed) and (ii) send public key Ed to the network. The device can receive an ephemeral public key Es from the network. The device can calculate values for A: an elliptic curve point addition over Ss, Sn, and Es, and B: (sd+ed) mod n. The device can input values for X and Y into an elliptic curve Diffie Hellman key exchange (ECDH) in order to determine a mutually derived shared secret X5, where the network can also derive shared secret X5. The device can (i) use X5 to derive a key K2 and (ii) decrypt a ciphertext from the network using key K2.
Owner:IOT & M2M TECHNOLOGIES LLC

An anonymous dynamic authentication and key agreement method based on certificateless signature

This invention discloses an anonymous dynamic authentication and key negotiation method based on certificateless signatures. This method is based on a system model operating in an edge intelligent IoT environment, consisting of four entities: intelligent nodes, a key generation center, edge nodes, and a trusted authority. The method comprises five stages: system initialization performed by the key generation center; pseudo-identities assigned to system entities and public-private key pairs generated through entity registration involving intelligent nodes, edge nodes, and the trusted authority; mutual authentication and key negotiation between intelligent nodes and edge nodes; batch authentication; and encryption transmission of intelligent IoT data using a symmetric encryption algorithm based on the negotiated session key. This invention, based on a certificateless signature mechanism, avoids the complexity of certificate management and key escrow, while eliminating high-overhead operations such as bilinear pairing and exponential operations, effectively reducing the computational burden on resource-constrained terminals.
Owner:GUIZHOU NORMAL UNIVERSITY