Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

175 results about "Mutual authentication" patented technology

Mutual authentication or two-way authentication refers to two parties authenticating each other at the same time, being a default mode of authentication in some protocols (IKE, SSH) and optional in others (TLS).

Internet of Things secure access method based on cloud edge collaboration

The invention discloses an Internet of Things secure access method based on cloud edge collaboration, which comprises the following steps: firstly, an Internet of Things device and an edge server respectively register in a CSC (Content Service Controller), and obtain an intelligent card or related data to complete information updating and storage; the equipment is inserted into an intelligent card to log in, and data are sent to the edge server after identity password verification; the edge server verifies the timestamp and then forwards the data to the CSC; the CSC verifies the timestamp and the identity, generates a session key parameter and sends the session key parameter to the edge server; the edge server verifies the identity of the CSC and then generates session key encrypted data to be transmitted back, and after the verification of the device is passed, secure communication is established. According to the method, mutual verification and encryption protection are adopted in identity verification; a timestamp, a random value and strict verification are used for message transmission to prevent replay and man-in-the-middle attack; secret key management guarantees safety through dynamic change of secret values, attacks such as physical capture are resisted in combination with PUF, and communication safety is comprehensively guaranteed.
Owner:SICHUAN BAICHENG INFORMATION TECHNOLOGY CO LTD

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Permission credible mutual recognition method, device and system of cross-domain agent

The invention provides a credible permission mutual recognition method, device and system for cross-domain agents, and relates to the technical field of artificial intelligence security, and the method comprises the steps: receiving a call request from a source domain agent for executing a corresponding operation on a target domain agent; obtaining an affine transformation parameter set through a permission conversion model according to the space relation characteristics of a source domain permission space and a target domain permission space involved in the calling request, and finally screening out affine transformation parameters suitable for permission voucher mapping by utilizing cone volume measurement evaluation and security verification, and mapping an original permission voucher of the source domain agent from a source domain permission space to a target domain permission space by using the affine transformation parameter, and generating a mapped permission voucher which can be identified and verified by the target domain. According to the method, the permission space is geometrized, and affine transformation, space division and geometric calculation are utilized, so that the permission credible mutual recognition problem in cross-domain agent collaboration is effectively solved.
Owner:GUIZHOU ELECTRONIC CERTIFICATION TECH CO LTD

Unmanned aerial vehicle group mutual authentication and key agreement method based on PUF (Physical Unclonable Function)

The invention discloses an unmanned aerial vehicle group mutual authentication and key agreement method based on PUF, and relates to the technical field of unmanned aerial vehicle group communication security and network authentication, and the method comprises the steps: S1, obtaining change data through monitoring unmanned aerial vehicle node position coordinate tracking and connection signal intensity in real time, the method comprises the following steps: S1, carrying out state change detection on a node moving speed by adopting position deviation calculation and connection interruption records to obtain a position coordinate tracking sequence after data synchronization update, S2, carrying out data point clustering on the position coordinate tracking sequence by adopting a K-Means clustering algorithm, processing the connection interruption record groups through central point iteration and distance measurement calculation to obtain change vector groups under group number setting; the PUF-based unmanned aerial vehicle group mutual authentication and key agreement method not only effectively solves the problems of slow response, easy communication interruption, unstable key agreement and the like of a traditional unmanned aerial vehicle group authentication mechanism, but also realizes comprehensive improvement in the aspects of safety, robustness and intelligence.
Owner:GUANGZHOU YOUFEI INTELLIGENT EQUIP CO LTD

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

System and Method for Dual Remote Authentication of Digital Assisted Shopping Agents and Customers Using Proximity-Based Mobile Device Interactions, Enterprise Security, and Biometrics

Systems and methods are disclosed for dual, simultaneous, single-session, proximity-based, secure authentication of a Digital Assisted Shopping (DAS) representative and a customer in an unsecured remote location. The method includes installing a mobile banking application on the customer's device and an enterprise application on the DAS representative's device, both with biometric verification. Proximity detection using Bluetooth Low Energy (BLE) initiates a secure session via push notifications. A secure communication channel is established through a secure local handshake, involving encryption key exchange and mutual authentication. The system exchanges data related to customer profiles and financial accounts, continuously monitors geolocation using GPS, Wi-Fi, and cellular data, and performs periodic background biometric re-verifications. AI / ML algorithms analyze customer data to propose financial products and services, which are securely shared with the customer for review and selection. The system facilitates real-time enrollment and transaction processing, terminating the session upon detecting security breaches.
Owner:BANK OF AMERICA CORP

Mutual authentication system

Mutual authentication and CSR verification techniques are described in this patent document. When a first person calls a second person, neither of them know that the other person is who he or she says he or she is. After a second person receives the call, the second person can log into a provider portal using a user device. After the second person logs in, the second person can see a verification of the call, can input on the user device a time passcode, or can receive such as passcode from a central system to authenticate the first person. The first person can provide the passcode to the second person. Upon receiving the inputted passcode, the second person can use his or her user device to indicate that the time passcode is correct so that the second person can be authenticated to access the first person's account.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Radio authentication as root of trust for transport layer security

A converged radio device (MS) is configured to perform communication in an internet protocol (IP) based network and authenticate with a switching and management infrastructure (SwMI) of a second network by using pre-existing radio authentication as a root of trust for an unauthenticated IP session established between the MS and a server associated with the SwMI. The MS receives a first challenge from the SwMI via the server, and determines a result of the first challenge using data derived from a certificate associated with the server. The MS transmits, to the SwMI via the server, a second challenge and the result of the first challenge. The MS authenticates the SwMI by verifying a result of the second challenge received from the SwMI via the server matches an expected result of the second challenge. Responsive to a mutual authentication, the MS performs communication in the radio network via the server.
Owner:MOTOROLA SOLUTIONS INC

Unmanned aerial vehicle photovoltaic power station autonomous inspection and remote centralized control system

The invention provides an unmanned aerial vehicle photovoltaic power station autonomous inspection and remote centralized control system, which relates to the field of information systems and comprises a central rule kernel module, a reverse reentry authorization ring module, a revocable channel permission module, a mirror image time slot mutual authentication module and a log auditing module. The relay module is used for realizing relay execution and data management of the unmanned aerial vehicle after the remote centralized control platform issues an inspection task; continuous verification is realized through track reproduction and data comparison in a task replacement process; when a limited channel is involved, security verification can be carried out through a permission mechanism, and operation is stopped when conditions are not met; when the data is in an uncertain state, cross validation can be carried out by utilizing a re-acquisition mode under a mirroring condition, and a mutual identification record is generated; the whole process is recorded by a log module to ensure operation traceability.
Owner:JIANGSU NENGCHUAN ELECTRIC POWER TECH CO LTD

Internet of vehicles cross-domain authentication method based on block chain and certificateless ECC

The invention discloses an Internet of Vehicles cross-domain authentication method based on a block chain and a certificateless ECC (Elliptic Curve Code), and the method comprises the following steps: a trusted mechanism generates and discloses global parameters of a certificateless elliptic curve password, and deploys a block chain network; all the road side units and the vehicles sequentially initiate registration requests to the trusted mechanism, legal road side units receive pseudonyms returned by the trusted mechanism, and legal vehicles receive secret keys returned by the trusted mechanism; mutual authentication and key negotiation are carried out between the registered vehicle and the road side unit, the vehicle sends a signed authentication request packet to the road side unit, the road side unit verifies the freshness of the request and verifies the validity of the signature through a block chain smart contract, and then a data packet is returned to the vehicle through a secure channel for verification; and when the position of the vehicle changes, the vehicle is re-authenticated. According to the method, a certificateless elliptic curve cryptosystem is adopted, so that the transmission and verification overhead of a traditional certificate is saved, and the communication time delay is reduced.
Owner:HUNAN UNIV OF SCI & TECH

Electric vehicle supply equipment (EVSE) management system and method to provide secured communication to multiple evse

A charger management system includes an edge controller and a cloud server. The edge controller establishes a non-encrypted connection with a first type charger according a first security profile, and converts a first charging message, formatted according to a first communication protocol and transmitted from the first type charger, into a second charging message formatted according to a second communication protocol. The cloud server establishes a first encrypted connection with the edge charger if the edge controller passes a first mutual authentication test according to a second security profile higher than the first security profile, and performs a charging station management service on the first type charger in response to the second charging message transmitted through the first encrypted connection.
Owner:LITE ON TECH CORP +1

System and method for providing authenticated access between an implanted medical device and an external device

A system and method for facilitating bi-directional authentication between an external device and an implanted medical device (IMD), wherein a therapy application executing on the external device is operative to communicate with the IMD via wireless telemetry communications. Certified security credentials for respective devices may be provisioned with respect to the therapy application. Upon initiating wireless telemetry communications, respective certified security credentials are mutually verified by the external device and the IMD. Responsive to successful verification, a mutual authentication process may be executed between the external device and the IMD using a respective challenge-response sequence.
Owner:ADVANCED NEUROMODULATION SYSTEMS INC

Mutual authentication system and method

ActiveUS12717889B2Key pressingGraphics
Method and system for mutual authentication. The system comprises:a virtual keyboard generation unit (210) for obtaining (110) a keyboard configuration (112) of a user (201), including graphical features (114), arrangements (116) and keyboard generation rules (118); and generating (120) a virtual keyboard (212) formed by keys (214) with combination of graphics features (114) in certain arrangements (116) based on the keyboard generation rules (118);an input interface (230) for receiving (140) a key selection (144) of the virtual keyboard (212);an authentication unit (240) for applying (160) user authentication rules (152) on the virtual keyboard (212), obtaining at least one correct key sequence (162), and authenticating (170) to the user (201) if the key selection (144) is validated with respect to a correct key sequence (162).
Owner:PEDRO PEREZ GRANDE PEDRO PEREZ GRANDE

Application function based user specific authentication and activation

Described herein are systems, methods, and instrumentalities associated with user authentication and / or activation. A wireless transmit / receive unit (WTRU) as described herein may determine a key identifier of the WTRU via a primary authentication procedure. The WTRU may transmit a message associated with an application on the WTRU to an application server, wherein the message may indicate at least the key identifier of the WTRU and an identifier of a user of the application on the WTRU. The WTRU may derive a key for the user based at least on the identifier of the user and perform mutual authentication with the application server for the user based on the derived key.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Power industry internet lightweight identity authentication method based on implicit certificate

The invention discloses a power industry internet lightweight identity authentication method based on an implicit certificate, identity authentication between equipment and an edge gateway is realized by introducing the implicit certificate, different from a traditional explicit certificate, the implicit certificate does not directly contain a public key of the equipment, and the implicit certificate does not directly contain the public key of the equipment. The authentication is completed by embedding certificate information in the data instead of the data, so that the storage, verification and transmission expenses of the certificate are remarkably reduced through the design; meanwhile, an authentication mode that the device and the edge gateway mutually verify the identity of each other is adopted, and a challenge-response mechanism is added in the authentication process, that is, the device and the edge gateway ensure the freshness of the message by exchanging challenge values so as to prevent an attacker from replaying an old message. Through mutual authentication, unauthorized equipment can be prevented from pretending to be a legal node, so that the communication security is improved, and a challenge-response mechanism can resist a replay attack, so that the communication security is further improved.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST

Consumable verification method and verification system

The invention provides a consumable verification method and verification system. The system comprises a consumable, equipment, a user terminal and a cloud. According to the method, the two two-dimensional codes are set, so that the two verification codes participating in verification are both generated based on the equipment information and the consumable information, and compared with verification performed only according to the consumable information in the prior art, the method can achieve the effect that verification fails due to the fact that the equipment information cannot be counterfeited even if the consumable information can be counterfeited; besides, before the first verification code is generated, the equipment needs to be mutually authenticated with the consumable, and before the second verification code is generated, the cloud needs to verify the validity of the request, and the two verification codes can be obtained and verified after the dual verification is passed, so that the anti-cracking performance is remarkably improved; by integrating the factors, the safety of the method is relatively high.
Owner:SHANGHAI MEIJINGLING MEDICAL TECHNOLOGY CO LTD

Rights management system for electric vehicle Bluetooth terminals

The present invention relates to the technical field of electric vehicle rights management, and in particular to a rights management system for electric vehicle Bluetooth terminals. In this system, for a single communication initiated by a control terminal, a key memory matches the control terminal; in response to the key in the key memory completing the match, the key memory passes authentication by the control terminal; in response to the key memory passing authentication, a Bluetooth actuator initiates authentication of the control terminal based on the device key; in response to the key in the Bluetooth actuator completing the match, the Bluetooth actuator broadcasts that the Bluetooth actuator has passed authentication; and the control terminal responds to the Bluetooth actuator passing authentication and pairs with the Bluetooth actuator. The present invention utilizes a central platform and a plurality of matrix platforms to distribute keys of different categories, and combines the keys with hardware to utilize mutual authentication between the device and the control terminal for Bluetooth matching, effectively improving the security of both the device and the Bluetooth device.
Owner:TIANJIN XINGHANG QILIAN TECH CO LTD

Security access detection method and device based on industrial Internet of Things

The invention discloses a security access detection method and device based on the industrial Internet of Things, and the method comprises the steps: obtaining an identity verification factor of a communication entity of the industrial Internet of Things, introducing a PUF authentication mechanism between a gateway and a sensor according to the identity verification factor and a preset risk model, and obtaining a trust anchor, the method comprises the following steps: respectively carrying out identity verification on user registration, user login and an authentication stage according to a trust anchor to obtain a session key, carrying out verification calculation on the session key by adopting ProVeif to obtain a verification result, carrying out evaluation analysis on the verification result to obtain an evaluation analysis result, generating target identity verification information based on a session and the evaluation analysis result, and sending the target identity verification information to a server. Three identity verification factors (password, biological recognition and smart card) are seamlessly integrated with a lightweight encrypted graph primitive, and a PUF enhanced mutual authentication mechanism is introduced between a gateway and a sensor, so that the semantic security of a session key is improved.
Owner:SHAOXING MUNICIPAL DESIGN INST +1

A device control method, device, and distributed digital key system

This application provides a device control method, device, and distributed digital key system, relating to the field of communication technology. The method is applied to a first device and a second device. The first device stores de-identified information from first key-related information; the second device's secure element stores sensitive information from the first key-related information and second key-related information. The method includes: the first device sending de-identified information to the second device; the second device merging the de-identified information and sensitive information into first key-related information; the second device performing mutual authentication between the first and second devices based on the first and second key-related information; and the second device executing a preset instruction based on the authentication result. The technical solution provided by this application can improve the compatibility and security of terminal devices.
Owner:HUAWEI TECH CO LTD

System for encrypting and authenticating communications with mutual authentication of the communicators

A system for encrypting and authenticating communications with mutual authentication of the communicators is used between two parties who exchange messages supported by a communication network in which the parties are unequivocally identified. The system includes processes supported by respective authentication applications available to each party on a hardware / software device, the applications having at least: an identifier (Id) of the authentication application (AA); an encryption key (CC) of each party; a random number generator for encrypting and authenticating messages (Mx); and an encryption algorithm that is shared with the rest of the parties of the system, allowing them to encrypt and decrypt the sent / received messages.
Owner:VEGA CRESPO JOSÉ AGUSTÍN +1

Hardware copyboard system and method based on FPGA and external IO module

The application discloses a kind of hardware copy-preventing board system and method based on FPGA and external IO module, and the hardware copy-preventing board system and method in this method are authenticated to each other by using hash algorithm, and no true random number unit and encryption engine need to be set on FPGA master module, which can greatly reduce the design difficulty and design cost of FPGA master module, and this copy-preventing board system does not need to store the specific information of IO module in FPGA master module, has no special requirements for IO module, and has good versatility, which can meet the design requirements of different types of FPGA master module and external IO module for hardware copy-preventing board.
Owner:SUZHOU RADSYS CO LTD

Method and apparatus for registering terminal as digital key of vehicle

According to one embodiment of the present disclosure, an operation method of a terminal for performing pairing with an owner of a vehicle in a wireless communication system comprises the steps of: establishing a connection required for pairing with the owner of the vehicle using a first communication method; receiving a first message from the vehicle using a first communication method, the first message including information indicating a communication method for performing vehicle owner pairing; and performing mutual authentication with the vehicle based on information indicating a communication method for performing vehicle owner pairing. Embodiments of the present disclosure may include various other embodiments.
Owner:SAMSUNG ELECTRONICS CO LTD

Security key management system and method based on 5G communication module

The invention relates to the technical field of 5G communication modules, in particular to a security key management system and method based on a 5G communication module, a master key is generated after the 5G communication module and a network side complete mutual authentication, and the master key is safely isolated and stored as a trust basis of the whole system; according to service requirements, dynamically generating and managing multi-level sub-keys, and providing independent encryption and integrity protection for different functional domains; a sub-key is generated only when a real use scene is triggered, and a short-term caching and automatic expiration strategy is adopted, so that the security and the performance are both considered; performing encryption and integrity verification on all signaling and data streams by using the corresponding sub-keys; in a network switching or cell switching scene, pre-generating and quickly switching to a new key; according to the method, module operation and energy consumption overhead are greatly reduced through on-demand derivation and second-level expired caching strategies, non-inductive cell switching is achieved through a switching forecast pre-derivation and double-buffering atom switching mechanism, and time delay is remarkably shortened.
Owner:JIANGSU FULIAN COMM TECH CO LTD

Lightweight encryption and authentication method for wireless sensor network, and related device

Provided in the present application is a lightweight encryption and authentication method for a wireless sensor network. The method comprises: a gateway node respectively generating a sensor ephemeral key and a user ephemeral key on the basis of a one-way hash function and a preconfigured physically unclonable function, and respectively sending to a user end and a sensor node the sensor ephemeral key, the user ephemeral key, a preconfigured sensor long-term key and a preconfigured user long-term key; and after the user end and the sensor node are registered, the user end performing identity authentication on identity information currently input by a user, and performing, on the basis of the identity information, mutual authentication between the user end, the gateway node and the sensor node, so as to send a sensor hash-based message authentication code and a user hash-based message authentication code to the sensor node on the basis of the authentication result, such that the sensor node and the gateway node perform key agreement and authentication to obtain a session key, and wireless sensor network communication can thus be performed on the basis of the session key, thereby effectively solving the problem of authenticating the security of a wireless sensor network.
Owner:SHENZHEN UNIV

Mutual authentication in edge computing

An information handling system may include at least one processor and a memory. The information handling system may be configured to receive, from a second information handling system, a physical identifier, a biological identifier, and a timestamp; determine a public key and a private key for the second information handling system based on the physical identifier, the biological identifier, and the timestamp; generate a random message; encrypt the random message with the public key for the second information handling system; transmit the encrypted random message to the second information handling system; and in response to a determination that the second information handling system has successfully decrypted the random message, authenticate the second information handling system.
Owner:DELL PROD LP

Mutual authentication between clusters

A method of processing traffic to provide a service is described. A first service mesh in a first cluster is used to ensure traffic is communicated within the first cluster using a secure communications protocol with mutual authentication accomplished using a certificate chain having a root certificate. A client in the first cluster originates traffic to a second cluster for processing, the second cluster having access to the root certificate. Using the first service mesh, routing the traffic to the second cluster is done using a secure communications protocol with mutual authentication. Mutual authentication is carried out between the first cluster and the second cluster using certificate chains having the root certificate; and in response to the mutual authentication being successful, application data is routed to the second cluster using the secure communications protocol such that the application data may be processed at the second cluster to provide the service.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Distributed ledger-based methods and systems for establishing mutually authenticated connection

Disclosed are methods and systems for publishing transactions for adding and removing roles and certificates to and from a distributed ledger and for authenticating certificates of two connected servers. The roles specify what server with the roles can publish what types of transactions for certificates and roles. When a role is requested, two transactions for adding the role and an issuer certificate are published to the distributed ledger. When a certificate of a server without any role is requested, only a transaction for adding the certificate is published to the distributed ledger. All the transactions are published through operation among a certificate-requesting server, a certificate-issuing server, and a distributed ledger network maintaining the distributed ledger. Two connected servers can verify authenticity of their counterpart's identities with the certificate retrieved from the distributed ledger and having the benefits of certificate immutability and availability of the distributed ledger technology.
Owner:TBCASOFT INC

Consideration is given to a method of authenticating an access layer based on a public key infrastructure in a handover in a next generation wireless communication system

This disclosure relates to 5G or 6G communication systems for supporting higher data transmission rates than 4G communication systems such as LTE. In a wireless communication system according to an embodiment of the invention, a method for operating a serving base station for mutual authentication in the access layer (AS) portion during handover includes the following steps: receiving a measurement report from a terminal; determining, based on the measurement report, whether the terminal meets handover conditions; if the terminal meets the handover conditions, determining whether the target base station to which the terminal will connect during handover and the serving base station belong to the same authentication area (AA); and sending a handover command to the terminal, the handover command being configured differently depending on whether the target base station and the serving base station belong to the same AA.
Owner:SAMSUNG ELECTRONICS CO LTD

Internet of vehicles authentication method based on block chain and physical unclonable function

PendingCN121841729AAvoid the risk of identity impersonationImprove resistance to attackKey distribution for secure communicationUser identity/authority verificationPasswordEngineering
The invention discloses an Internet of Vehicles authentication method based on a block chain and a physical unclonable function, and relates to the field of data security, and the method comprises the steps: a vehicle and a communication object complete registration at a roadside base station, and a vehicle end integrates a PUF and a fuzzy extractor to generate a master key bound with equipment; during authentication, the vehicle uses the password, the biological characteristics and the PUF response to perform multi-factor authentication, and submits a Merkle proof of a target communication object to the roadside base station; and the roadside base station verifies the proof and confirms the access authority through the block chain smart contract, and assists the vehicle and the communication object to complete mutual authentication and negotiate the session key. According to the method, the block chain is utilized to ensure that data cannot be tampered, equipment cloning is resisted through the PUF, efficient authorization control is realized in combination with the Merkle tree, pseudo name dynamic updating and identity revocation are supported, and finally, the calculation, communication and storage overhead is remarkably reduced while the security is ensured.
Owner:BEIJING INST OF TECH