Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

252 results about "Mutual authentication" patented technology

Mutual authentication or two-way authentication refers to two parties authenticating each other at the same time, being a default mode of authentication in some protocols (IKE, SSH) and optional in others (TLS).

Computer systems and methods for secure and scalable digital asset custodian

Embodiments described herein relate to computer systems and methods for digital asset custodian that seamlessly integrates off-chain multi-party computation (MPC) signing with on-chain party identity authentication. The system comprises a service provider node, multiple computation nodes equipped with robust secure hardware, and a Blockchain accessible to all participating nodes. The nodes deliver a threshold signing service with utmost security—ensuring that no single node can recover the private key, while simultaneously recording and mutually authenticating each node's identity on-chain. The system boasts intrinsic support for hierarchical address creation and signing, facilitated by an enhanced protocol. Its scalability, particularly in the quantity of computation nodes, is complemented by efficient communication tailored to the demands of the MPC protocol.
Owner:BULLISH GLOBAL

Techniques for enrolling a device or service using a proximity channel and a cloud channel

Systems, devices, and methods are provided for establishing trust between devices using a proximity channel and a cloud channel. An enrollee device and manager may perform a mutual authentication process where grant codes are exchanged, wherein the enrollee grants the manager the ability to be a manager in the enrollment process and the manger grants the enrollee the ability to issue an identity certificate. A proximity channel may be used to establish proof-of-possession and a cloud-based authorization may be performed to verify that the enrollee is a legitimate participant.
Owner:AMAZON TECH INC

Internet of Things secure access method based on cloud edge collaboration

The invention discloses an Internet of Things secure access method based on cloud edge collaboration, which comprises the following steps: firstly, an Internet of Things device and an edge server respectively register in a CSC (Content Service Controller), and obtain an intelligent card or related data to complete information updating and storage; the equipment is inserted into an intelligent card to log in, and data are sent to the edge server after identity password verification; the edge server verifies the timestamp and then forwards the data to the CSC; the CSC verifies the timestamp and the identity, generates a session key parameter and sends the session key parameter to the edge server; the edge server verifies the identity of the CSC and then generates session key encrypted data to be transmitted back, and after the verification of the device is passed, secure communication is established. According to the method, mutual verification and encryption protection are adopted in identity verification; a timestamp, a random value and strict verification are used for message transmission to prevent replay and man-in-the-middle attack; secret key management guarantees safety through dynamic change of secret values, attacks such as physical capture are resisted in combination with PUF, and communication safety is comprehensively guaranteed.
Owner:SICHUAN BAICHENG INFORMATION TECHNOLOGY CO LTD

Secure communication method, system and device between unmanned aerial vehicle and ground station, and readable medium

The invention relates to a secure communication method, system and device between an unmanned aerial vehicle and a ground station, and a readable medium. The method comprises the following steps: a control center generates and issues public parameters for safety communication of a system; registering the ground station and the unmanned aerial vehicle; the ground station and the unmanned aerial vehicle respectively send respective real identities to the control center; receiving and storing safety parameters and challenge sets which are respectively sent to the ground station and the unmanned aerial vehicle by the control center; randomly selecting a challenge from the received challenge set, and generating a registration parameter in combination with the public parameter; the ground station and the unmanned aerial vehicle generate mutually sent authentication information by using respective registration parameters to perform mutual authentication, and a session key special for secure communication is established between the ground station and the unmanned aerial vehicle after the authentication succeeds; and after authentication and key negotiation are successfully completed, the ground station and the unmanned aerial vehicle reselect challenges from respective stored challenge sets, and update authentication parameters. According to the invention, secure communication between the unmanned aerial vehicle and the ground station is realized.
Owner:JIAXING UNIV

Apparatus and method for mutual authentication of quantum entities based on measurement-device-independent quantum key distribution

Disclosed herein are an apparatus and method for mutual authentication of quantum entities based on Measurement-Device-Independent Quantum Key Distribution (MDI-QKD). The method may include configuring a quantum input form based on an authentication key shared in advance with a counterpart entity, applying polarization modulation to the configured quantum input form, transmitting the quantum input form to which polarization modulation is applied to a quantum measurement device, and authenticating the counterpart entity by checking whether the counterpart entity configures a quantum input form according to the shared authentication key using a measurement result and information about polarization modulation.
Owner:ELECTRONICS & TELECOMM RES INST

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Mutual authentication and encryption key generation in wireless ambient power (AMP) devices

A method for receiving, by an ambient power (AMP) device that harvests environmental energy, an identification (ID) request frame from a powered wireless device. The ID request frame includes one or more frame-exchange parameters and an authentication and key management (AKM) method. The method includes retrieving, from memory, a secret that is shared with the powered wireless device, determining, using the secret, one or more first AKM parameters, and transmitting, to the powered wireless device, by the AMP device, an ID response frame including an ID of the AMP device, at least one of the one or more frame-exchange parameters and the one or more AKM parameters with which the powered wireless device is to be mutually authenticated with the AMP device and to generate an encryption key to initiate an encrypted wireless communication session.
Owner:INFINEON TECHNOLOGIES AMERICAS CORP

Unmanned aerial vehicle identity authentication and key negotiation system and method

The invention discloses an unmanned aerial vehicle identity authentication and key negotiation system and method. The system comprises a trusted registration mechanism, an unmanned aerial vehicle, a cloud server and a mobile terminal, in a system initialization stage, a trusted registration mechanism publicly releases a single hash function and a symmetric encryption / decryption algorithm; in a mobile terminal registration stage, a trusted registration mechanism verifies a registration request of a user; in the unmanned aerial vehicle registration stage, the unmanned aerial vehicle sends its identity ID to the trusted registration mechanism to request registration, and the trusted registration mechanism distributes a unique challenge and random number to the unmanned aerial vehicle after receiving the identity ID; in the user login stage, a user ID, a password and biological characteristics are input into the mobile terminal, and the mobile terminal verifies the user identity through pre-stored parameters; in the identity authentication and key negotiation stage, mutual authentication is carried out among the mobile terminal, the cloud server and the unmanned aerial vehicle, and a session key for future encrypted communication is negotiated.
Owner:JIANGSU SECOND NORMAL UNIVERSITY

Permission credible mutual recognition method, device and system of cross-domain agent

The invention provides a credible permission mutual recognition method, device and system for cross-domain agents, and relates to the technical field of artificial intelligence security, and the method comprises the steps: receiving a call request from a source domain agent for executing a corresponding operation on a target domain agent; obtaining an affine transformation parameter set through a permission conversion model according to the space relation characteristics of a source domain permission space and a target domain permission space involved in the calling request, and finally screening out affine transformation parameters suitable for permission voucher mapping by utilizing cone volume measurement evaluation and security verification, and mapping an original permission voucher of the source domain agent from a source domain permission space to a target domain permission space by using the affine transformation parameter, and generating a mapped permission voucher which can be identified and verified by the target domain. According to the method, the permission space is geometrized, and affine transformation, space division and geometric calculation are utilized, so that the permission credible mutual recognition problem in cross-domain agent collaboration is effectively solved.
Owner:GUIZHOU ELECTRONIC CERTIFICATION TECH CO LTD

Unmanned aerial vehicle group mutual authentication and key agreement method based on PUF (Physical Unclonable Function)

The invention discloses an unmanned aerial vehicle group mutual authentication and key agreement method based on PUF, and relates to the technical field of unmanned aerial vehicle group communication security and network authentication, and the method comprises the steps: S1, obtaining change data through monitoring unmanned aerial vehicle node position coordinate tracking and connection signal intensity in real time, the method comprises the following steps: S1, carrying out state change detection on a node moving speed by adopting position deviation calculation and connection interruption records to obtain a position coordinate tracking sequence after data synchronization update, S2, carrying out data point clustering on the position coordinate tracking sequence by adopting a K-Means clustering algorithm, processing the connection interruption record groups through central point iteration and distance measurement calculation to obtain change vector groups under group number setting; the PUF-based unmanned aerial vehicle group mutual authentication and key agreement method not only effectively solves the problems of slow response, easy communication interruption, unstable key agreement and the like of a traditional unmanned aerial vehicle group authentication mechanism, but also realizes comprehensive improvement in the aspects of safety, robustness and intelligence.
Owner:GUANGZHOU YOUFEI INTELLIGENT EQUIP CO LTD

Secure connections and mutual authentications among an intermediary device, a client device, and a server system

In some examples, an intermediary device includes a memory to store mapping information correlating an intermediary server public key to an intermediary server private key of the intermediary device, and correlating an intermediary client public key to an intermediary client private key of the intermediary device. The intermediary device establishes a first secure connection between the intermediary device and the client device using the intermediary server public key and the intermediary server private key, where the establishing of the first secure connection comprises a mutual authentication between the intermediary device and the client device. The intermediary device establishes a second secure connection between the intermediary device and the server system using the intermediary client public key and the intermediary client private key, where the establishing of the second secure connection comprises a mutual authentication between the intermediary device and the server system.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

System and Method for Dual Remote Authentication of Digital Assisted Shopping Agents and Customers Using Proximity-Based Mobile Device Interactions, Enterprise Security, and Biometrics

Systems and methods are disclosed for dual, simultaneous, single-session, proximity-based, secure authentication of a Digital Assisted Shopping (DAS) representative and a customer in an unsecured remote location. The method includes installing a mobile banking application on the customer's device and an enterprise application on the DAS representative's device, both with biometric verification. Proximity detection using Bluetooth Low Energy (BLE) initiates a secure session via push notifications. A secure communication channel is established through a secure local handshake, involving encryption key exchange and mutual authentication. The system exchanges data related to customer profiles and financial accounts, continuously monitors geolocation using GPS, Wi-Fi, and cellular data, and performs periodic background biometric re-verifications. AI / ML algorithms analyze customer data to propose financial products and services, which are securely shared with the customer for review and selection. The system facilitates real-time enrollment and transaction processing, terminating the session upon detecting security breaches.
Owner:BANK OF AMERICA CORP

Method and device for updating and transmitting secret key between hardware devices based on network layer

The invention provides a method and a device for updating and transmitting a secret key between hardware equipment based on a network layer. The method aims at two paired and mutually authenticated equipment. A new secret key is generated at a first device serving as a sending end, updating is started, identity authentication information related to the new secret key is generated through an original secret key, and the new secret key is encrypted through a device certificate of a second device to form data encryption information. The information is packaged into an update request data frame, and an update identifier is set at a destination MAC address of the frame. And sending the data frame to the second equipment. And the second equipment serving as a receiving end receives the update request data frame from the first equipment, and extracts the identity authentication information and the data encryption information. And verifying the identity authentication information by using the device certificate of the first device, and decrypting the data encryption information by using the original key to obtain a new key after successful verification. And setting a key update result identifier at the destination MAC address of the response data frame, and sending the key update result identifier back to the first device. According to the invention, the key of the paired device can be updated online, and the security and efficiency of key update data transmission are improved.
Owner:BEIJING BEIDOU HONGPENG TECH CO LTD

Mutual authentication system

Mutual authentication and CSR verification techniques are described in this patent document. When a first person calls a second person, neither of them know that the other person is who he or she says he or she is. After a second person receives the call, the second person can log into a provider portal using a user device. After the second person logs in, the second person can see a verification of the call, can input on the user device a time passcode, or can receive such as passcode from a central system to authenticate the first person. The first person can provide the passcode to the second person. Upon receiving the inputted passcode, the second person can use his or her user device to indicate that the time passcode is correct so that the second person can be authenticated to access the first person's account.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Medical system identity authentication and key negotiation system and method based on associated data encryption

The invention discloses a medical system identity authentication and key negotiation system and method based on associated data encryption, and the system comprises a registration mechanism, a wearable device, a mobile terminal, and a medical server, and the registration mechanism completes the registration of a sensor device, the mobile terminal, and the medical server through a secure channel. And the sensor equipment, the mobile terminal and the medical server communicate with one another through an unsafe wireless public channel. In the initialization stage, the registration mechanism generates a master key for the medical server and selects a long-term identity ID and a temporary identity ID for the wearable device; in a mobile terminal registration stage, a registration mechanism stores and sends a secret certificate; in the user login stage, identity information is calculated, and service is provided according to a user request; in the identity authentication and key negotiation stage, mutual authentication among the mobile terminal, the medical server and the wearable device is executed, and session keys for future encrypted communication are negotiated and stored.
Owner:YANGZHOU POLYTECHNIC COLLEGE

Forming, authenticating and securing non-fungible items

Embodiments relate to a non-fungible physical (NFP) item. The non-fungible physical (NW) item comprises an identifier. The identifier is embedded and layered within the non-fungible physical item in an unplanned pattern. The identifier in the unplanned pattern is configured to provide high security against counterfeiting of the non-fungible physical (NFP) item. The identifier comprises at least one of a random marker and a unique marker. The unplanned pattern comprises at least one of a random pattern and a unique pattern. Further the non-fungible physical (NFP) item is registered as a non-fungible token on a blockchain. The NFP item is then paired with the non-fungible token for enabling two-way mutual authentication and enhanced authenticity. The pairing of the NFP item with the non-fungible token enables tracking condition, provenance, and grading of the NFP item.
Owner:ELITE COINAGE CO

Radio authentication as root of trust for transport layer security

A converged radio device (MS) is configured to perform communication in an internet protocol (IP) based network and authenticate with a switching and management infrastructure (SwMI) of a second network by using pre-existing radio authentication as a root of trust for an unauthenticated IP session established between the MS and a server associated with the SwMI. The MS receives a first challenge from the SwMI via the server, and determines a result of the first challenge using data derived from a certificate associated with the server. The MS transmits, to the SwMI via the server, a second challenge and the result of the first challenge. The MS authenticates the SwMI by verifying a result of the second challenge received from the SwMI via the server matches an expected result of the second challenge. Responsive to a mutual authentication, the MS performs communication in the radio network via the server.
Owner:MOTOROLA SOLUTIONS INC

System and method to control access of ultra-wideband (UWB) devices

An ultra-wideband (UWB) system of a user device is disclosed. The UWB system receives a session identifier associated with a first session key from an access control device to facilitate an access control operation for the user device. Based on successful mutual authentication between the user device and the access control device, a secure data exchange session is scheduled between the user device and the access control device based on the first session key and a second session key that is generated by a secure element of the user device. First transaction payloads that include the session identifier are received from the access control device during the secure data exchange session. The first transaction payloads are decrypted by way of a ranging payload set, to generate second transaction payloads. The access control operation is executed based on the second transaction payloads.
Owner:NXP BV

Communication method and apparatus

The present application relates to the technical field of communications. Provided are a communication method and apparatus. A terminal acquires a first identifier and a first long-term key of the terminal, and the terminal can send to a network a first message carrying a second identifier that is determined on the basis of the first identifier, so as to trigger mutual authentication, such that the network can determine, on the basis of the second identifier, a second long-term key that is symmetric to the first long-term key of the terminal, and authenticates the terminal on the basis of the second long-term key. The terminal can generate a random number on the basis of the first identifier, and authenticates the network on the basis of the first long-term key, first authentication data from the network, and the random number. The terminal and the network perform mutual authentication by means of symmetric keys, without the need for complex computations. Furthermore, during the mutual authentication between the terminal and the network, the random number for the mutual authentication is generated on the basis of the first identifier, and the network and the terminal do not need to carry the random number during signaling interaction for the mutual authentication, thereby further improving the efficiency of mutual authentication, and saving on signaling resources.
Owner:HUAWEI TECH CO LTD

Unmanned aerial vehicle photovoltaic power station autonomous inspection and remote centralized control system

The invention provides an unmanned aerial vehicle photovoltaic power station autonomous inspection and remote centralized control system, which relates to the field of information systems and comprises a central rule kernel module, a reverse reentry authorization ring module, a revocable channel permission module, a mirror image time slot mutual authentication module and a log auditing module. The relay module is used for realizing relay execution and data management of the unmanned aerial vehicle after the remote centralized control platform issues an inspection task; continuous verification is realized through track reproduction and data comparison in a task replacement process; when a limited channel is involved, security verification can be carried out through a permission mechanism, and operation is stopped when conditions are not met; when the data is in an uncertain state, cross validation can be carried out by utilizing a re-acquisition mode under a mirroring condition, and a mutual identification record is generated; the whole process is recorded by a log module to ensure operation traceability.
Owner:JIANGSU NENGCHUAN ELECTRIC POWER TECH CO LTD

Underground water pollution tracing method and system based on block chain

The invention relates to the technical field of block chains, in particular to an underground water pollution tracing method and system based on a block chain, and the method comprises the following steps: obtaining parameters such as permeation rate, aquifer thickness, water flow direction and the like, writing the parameters into a chain structure, generating a hydrological dynamic label, verifying pollution direction consistency to generate a space-time label, and screening credible nodes to generate a credible identifier. And calculating a diffusion range to form a liability list, and verifying emission records to generate a multi-chain evidence chain. According to the method, by recording hydrological parameters and pollutant concentration gradient differences in real time, generating diffusion threshold values, checking space-time consistency of pollution diffusion paths and screening credible node data, it is ensured that pollution source positioning and diffusion paths are accurate, a responsibility subject is determined through sequential logic checking, and a multi-chain mutual authentication data chain is generated; the credibility and transparency of pollution traceability are improved, the risk of data tampering is reduced, the cross-mechanism data sharing and cooperation efficiency is enhanced, and the completeness of a traceability chain is ensured.
Owner:JIANGXI COALFIELD GEOLOGICAL SURVEY RES INST

Internet of vehicles cross-domain authentication method based on block chain and certificateless ECC

The invention discloses an Internet of Vehicles cross-domain authentication method based on a block chain and a certificateless ECC (Elliptic Curve Code), and the method comprises the following steps: a trusted mechanism generates and discloses global parameters of a certificateless elliptic curve password, and deploys a block chain network; all the road side units and the vehicles sequentially initiate registration requests to the trusted mechanism, legal road side units receive pseudonyms returned by the trusted mechanism, and legal vehicles receive secret keys returned by the trusted mechanism; mutual authentication and key negotiation are carried out between the registered vehicle and the road side unit, the vehicle sends a signed authentication request packet to the road side unit, the road side unit verifies the freshness of the request and verifies the validity of the signature through a block chain smart contract, and then a data packet is returned to the vehicle through a secure channel for verification; and when the position of the vehicle changes, the vehicle is re-authenticated. According to the method, a certificateless elliptic curve cryptosystem is adopted, so that the transmission and verification overhead of a traditional certificate is saved, and the communication time delay is reduced.
Owner:HUNAN UNIV OF SCI & TECH

Electric vehicle supply equipment (EVSE) management system and method to provide secured communication to multiple evse

A charger management system includes an edge controller and a cloud server. The edge controller establishes a non-encrypted connection with a first type charger according a first security profile, and converts a first charging message, formatted according to a first communication protocol and transmitted from the first type charger, into a second charging message formatted according to a second communication protocol. The cloud server establishes a first encrypted connection with the edge charger if the edge controller passes a first mutual authentication test according to a second security profile higher than the first security profile, and performs a charging station management service on the first type charger in response to the second charging message transmitted through the first encrypted connection.
Owner:LITE ON TECH CORP +1

System and method for providing authenticated access between an implanted medical device and an external device

A system and method for facilitating bi-directional authentication between an external device and an implanted medical device (IMD), wherein a therapy application executing on the external device is operative to communicate with the IMD via wireless telemetry communications. Certified security credentials for respective devices may be provisioned with respect to the therapy application. Upon initiating wireless telemetry communications, respective certified security credentials are mutually verified by the external device and the IMD. Responsive to successful verification, a mutual authentication process may be executed between the external device and the IMD using a respective challenge-response sequence.
Owner:ADVANCED NEUROMODULATION SYSTEMS INC

A Cross-Domain Collaborative Authentication Method for the Internet of Things Based on Blockchain

The present invention discloses an Internet of Things cross-domain collaborative authentication method based on blockchain, which includes the following steps: Step 1, initialization of the system, where the domain management machines of each domain execute the initialization algorithm; Step 2, joining of devices: Before a device performs cross-domain authentication, it needs to join a specific management domain; Step 3, cross-domain authentication: Authentication is performed before a device accesses across domains; Step 4, key negotiation: After the devices authenticate each other successfully, a key is negotiated, and then encrypted communication is carried out through the shared key; Step 5, device exit: The device actively exits a certain domain. In view of the problems of the above-mentioned traditional cross-domain solutions and the applicability of blockchain in the Internet of Things, the present invention proposes a new blockchain-based Internet of Things cross-domain authentication method. Through this method, devices from different domains can be authenticated while ensuring security, and at the same time, its authentication efficiency can also be guaranteed.
Owner:HANGZHOU DIANZI UNIV

Mutual authentication system and method

ActiveUS12717889B2Key pressingGraphics
Method and system for mutual authentication. The system comprises:a virtual keyboard generation unit (210) for obtaining (110) a keyboard configuration (112) of a user (201), including graphical features (114), arrangements (116) and keyboard generation rules (118); and generating (120) a virtual keyboard (212) formed by keys (214) with combination of graphics features (114) in certain arrangements (116) based on the keyboard generation rules (118);an input interface (230) for receiving (140) a key selection (144) of the virtual keyboard (212);an authentication unit (240) for applying (160) user authentication rules (152) on the virtual keyboard (212), obtaining at least one correct key sequence (162), and authenticating (170) to the user (201) if the key selection (144) is validated with respect to a correct key sequence (162).
Owner:PEDRO PEREZ GRANDE PEDRO PEREZ GRANDE

Application function based user specific authentication and activation

Described herein are systems, methods, and instrumentalities associated with user authentication and / or activation. A wireless transmit / receive unit (WTRU) as described herein may determine a key identifier of the WTRU via a primary authentication procedure. The WTRU may transmit a message associated with an application on the WTRU to an application server, wherein the message may indicate at least the key identifier of the WTRU and an identifier of a user of the application on the WTRU. The WTRU may derive a key for the user based at least on the identifier of the user and perform mutual authentication with the application server for the user based on the derived key.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Power industry internet lightweight identity authentication method based on implicit certificate

The invention discloses a power industry internet lightweight identity authentication method based on an implicit certificate, identity authentication between equipment and an edge gateway is realized by introducing the implicit certificate, different from a traditional explicit certificate, the implicit certificate does not directly contain a public key of the equipment, and the implicit certificate does not directly contain the public key of the equipment. The authentication is completed by embedding certificate information in the data instead of the data, so that the storage, verification and transmission expenses of the certificate are remarkably reduced through the design; meanwhile, an authentication mode that the device and the edge gateway mutually verify the identity of each other is adopted, and a challenge-response mechanism is added in the authentication process, that is, the device and the edge gateway ensure the freshness of the message by exchanging challenge values so as to prevent an attacker from replaying an old message. Through mutual authentication, unauthorized equipment can be prevented from pretending to be a legal node, so that the communication security is improved, and a challenge-response mechanism can resist a replay attack, so that the communication security is further improved.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST

An Encryption and Decryption Method and System for Electronic Contracts Based on Mutual Authentication

The present invention provides an encryption and decryption method and system for electronic contracts based on two-way authentication. The method includes: the client sends a certificate application to the bidding service institution; after the bidding service institution verifies the legality of the client, it sends the certificate application to the CA and the key management platform, signs the certificate data packet returned by the CA and the key management platform using the signature private key, and sends the signed certificate data packet, the signature value, and its own signature certificate to the client; after the client verifies the legality of the signature certificate of the bidding service institution, it uses the signature private key to decrypt the digital envelope in the certificate data packet to obtain a temporary symmetric key, and then signs and encrypts the electronic contract using its own signature private key and the temporary symmetric key, and sends the encrypted electronic contract to the bidding center through the bidding service institution. Since the client and the bidding service institution conduct two-way verification, the security of both parties' identities is ensured, and the contract is protected using a single-use temporary symmetric key, thereby ensuring the security of the contract.
Owner:SICHUAN UNIV