Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

91 results about "Pre-shared key" patented technology

In cryptography, a pre-shared key (PSK) is a shared secret which was previously shared between the two parties using some secure channel before it needs to be used.

Real estate full life cycle intelligent management method and system based on Internet of Things perception

The invention provides a real estate full life cycle intelligent management method and system based on Internet of Things perception, and the method comprises the steps: distributing a unique hardware identifier of equipment, combining a lightweight digital certificate with a pre-shared key to achieve two-factor authentication, and storing a root certificate in a cloud end; an access authentication process is optimized, an identity label and a certificate signature request need to be submitted when a node accesses for the first time, a temporary session key is generated after the gateway verifies, and abnormal access is immediately isolated and reported; data integrity verification is implemented, and after a sensor collects data, an abstract is generated and data encryption transmission is carried out; after decryption, the receiving end recalculates the abstract for comparison, and if not, the abstract is discarded and nodes are marked to be abnormal; a data anomaly detection model is constructed, energy consumption fluctuation is determined based on historical data, a frequency baseline is collected, data reasonability is monitored in real time, secondary authentication is triggered when the data is abnormal, and node data access is suspended if the data fails; a hierarchical key system is established, hardware is solidified by a root key, session keys are alternated for 24 hours, and data encryption keys are dynamically derived and distributed through encryption channels.
Owner:LERUAN CENTURY (BEIJING) INFORMATION TECHNOLOGY CO LTD

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Security data isolation and information exchange method and system based on lightweight protocol

The invention relates to a security data isolation and information exchange method and system based on a lightweight protocol, belongs to the technical field of industrial automation control system security, and solves the technical problems of low transmission efficiency, high analysis overhead, high security risk and high resource consumption of an existing method. Comprising the following steps: collecting and preprocessing original plaintext data at an industrial control network side; an external unit identifier, a timestamp and a pre-shared key on the industrial control network side are used as encryption factors, lightweight stream cipher encryption and packaging are carried out on the preprocessed data, and a lightweight protocol data packet is generated; through a special physical isolation device, the light-weight protocol data packet subjected to deep detection is unidirectionally isolated and ferried from an industrial control network side to an internal network side; performing post-processing on the received lightweight protocol data packet at the intranet side to restore original data; and delivering the restored original plaintext data to an intranet service application. And safe and efficient information data exchange is realized.
Owner:BEIJING JINGHANG COMPUTING & COMM RES INST

Key distribution between open fronthaul (OFH) media access control security (macsec) endpoints

A method (400) is disclosed. The method includes establishing (402), at an Open Radio Access Network (O-RAN)-Radio Unit Controller (O-RU Controller), a session with an O-RU. In response to establishment of the session, the method includes configuring (404), at the O-RU controller one or more Media Access Control security (MACsec) configuration parameters for the O-RU. The one or more MACsec configuration parameters comprises at least a pre-shared key. The method also includes generating (406), at the O-RU controller, using a random number generator, at least one of a Secure Authentication Key (SAK) and a Key Encryption Key (KEK) based on the pre-shared key. Moreover, the method includes transmitting (408), from the O-RU controller to the O-RU, at least one of the one or more MACsec configuration parameters and the at least one of the SAK and the KEK.
Owner:RAKUTEN SYMPHONY INC +1

Data communication equipment dynamic encryption authentication method and related device

The invention discloses a dynamic encryption authentication method for data communication equipment and a related device, and relates to the technical field of network security, and the method comprises the steps that an authentication server establishes an encryption communication channel based on a transport layer security protocol between a user terminal and the data communication equipment; on the channel, the authentication server receives the static identity credential of the user terminal for first verification; and after the verification is passed, the dynamic password is sent to the user terminal through the short message gateway, and the dynamic password submitted by the user terminal is subjected to second verification. When the user terminal initiates a control instruction, the authentication server sends a challenge value to the user terminal; the user terminal calculates a challenge value by using the pre-shared key, generates a response code and returns the response code to the authentication server; the authentication server verifies the validity of the response code, and forwards the control instruction to the target data communication equipment after the verification is passed; and the data communication device executes the instruction and records an execution event in a security audit log. According to the invention, the data transmission security and authentication efficiency of the data communication equipment in different network environments can be effectively improved.
Owner:BEIJING XINQIAO INFORMATION TECH CO LTD

Opening local applications from browsers

Computer-implemented procedure, executed by a sync client (320), which includes: Receiving a request from a first application on a local device (302) to open a document which has a document identifier and is associated with a first file stored on a server (206), wherein the request includes the document identifier and a user identifier; Determine that a second file stored on the local device (302) is associated with the document identifier and that a user associated with the user identifier is authorized to access the second file; Sending (524) a list comprising one or more applications that are on the local device (302) and that are capable of opening the second file, based on the determination to the first application; Receiving (534) a specification of a second application selected from the list (528), from the first application; and Sending (536) a message to open the second file with the second application; including determining whether the user is authorized to access the second file: Received (606) from the first application, an authentication request containing an initial one-time key; Calculate (608) an initiation hash based on the first one-time key and a pre-shared key; Sending the initiation hash to the first application for verification; Received (614), from the first application, of an acknowledgment hash; and Verify (616) that the confirmation hash matches an independently calculated confirmation hash; wherein the first application is a browser (312) or a browser extension (324) associated with the browser (312).
Owner:GOOGLE LLC

Authentication method using pre-shared symmetric key for location selection of authentication information in quantum communication system, and apparatus therefor

The present disclosure provides a method of performing user authentication in a quantum communication system. More specifically, the method includes transmitting an information sequence including at least one data block on the quantum channel, wherein based on a preshared key and at least one key generated based on the preshared key, a checking sequence for a quantum bit error rate (QBER) estimation is determined from each of the at least one data block, wherein the preshared key is used to select a location of a sequence included in the at least one data block; performing the user authentication based on a portion of the checking sequence; and performing a QBER estimation based on a result of the user authentication and a remaining checking sequence excluding the portion of the checking sequence. A user authentication error rate and a QBER estimation error rate are used for the QBER estimation.
Owner:LG ELECTRONICS INC

Authentication method, apparatus and device based on pre-shared key

The embodiment of the application provides a kind of based on pre-shared key authentication method, device and equipment, in the above-mentioned pre-shared key authentication method, device sends key acquisition request to first server, then receives the ciphertext of pre-shared key sent by first server, then the ciphertext of pre-shared key is decrypted, the plaintext of pre-shared key is obtained, and then according to the plaintext of pre-shared key, identity authentication or encryption and decryption service is carried out with second server, so that it can be realized by one first server with security authentication and authentication mechanism to store the ciphertext of pre-shared key encrypted by the key of equipment side, so that the security of pre-shared key is greatly improved, and in the above-mentioned method, key and ciphertext are separated, and first server does not have decryption capability (because first server does not have decryption key), so that the risk of pre-shared key leakage in first server end can be avoided.
Owner:HUAWEI TECH CO LTD

Access point and method for establishing wireless connection executed by access point and client

An access point (AP), a method performed by the AP and a client (STA) for establishing a wireless connection are provided. Wherein the method executed by the AP comprises: providing a plurality of wireless networks having the same SSID and different BSSIDs, the plurality of wireless networks including a first wireless network supporting only a Wi-Fi protected access (WPA) protocol, a second wireless network supporting WPA and WPA2 protocols, and a third wireless network supporting WPA2 and WPA3 protocols; and in response to receiving an access request from the STA, establishing a wireless connection with the STA using the first wireless network, the second wireless network and the third wireless network in sequence, in which the first wireless network records a unique mapping relationship between the STA and a private pre-shared key (PSK) used by the STA during establishment of the wireless connection with the STA using the first wireless network, and the second wireless network records a unique mapping relationship between the STA and the private pre-shared key (PSK) used by the STA during establishment of the wireless connection with the STA using the third wireless network. To use the private PSK in the unique mapping relationship during establishment of a wireless connection with the STA using the second wireless network and the third wireless network.
Owner:TP-LINK INT SHENZHEN CO LTD

Out-of-Band Quantum Key Distribution Using Cellular SMS

Out-of-band quantum key distribution using cellular SMS can include receiving, from a user device, a client identifier that identifies the user device and a first key identifier that identifies a first key having a first key value that is a first quantumly generated random bit string. A second key that includes a second key value can be requested and received from the key service, the second key value including a second quantumly generated random bit string. The second key value can be provided to a short message service center for delivery to the user device. An operation can be performed on the first key value and the second key value to obtain a copy of a pre-shared key, which can be used when exchanging encrypted communications with the user device.
Owner:INTERWISE CO LTD +1

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Methods and systems for micro edge applications and grouping

A method for establishing connections and forming groups in an edge computing system includes detecting and identifying devices attempting to connect to the network using a processor. The method involves authenticating detected devices with a common pre-shared key (PSK) stored in memory, forming groups of connected devices based on predefined criteria, and sharing the PSK within each group via a secured channel. It also includes creating a subnetwork or private LAN for each subscriber using network configuration data, assigning virtual pre-shared keys (vPSKs) to devices based on service requirements, determining device capabilities by analyzing received device-specific information, and identifying supported applications based on device capabilities and application compatibility data stored in memory.
Owner:VEEA INC

Secured application-to-person SMS messaging

The present invention relates to a method for secure Application-to-Person, A2P, short messaging service, SMS, communication at a network node. The method comprises receiving an A2P SMS from an A2P sender for delivery to a subscriber and determining that the A2P SMS requires secure A2P SMS delivery to the subscriber. The method also comprises encrypting a payload of the A2P SMS using at least one pre-shared key, PSK, and an encryption algorithm, wherein the at least one PSK and the encryption algorithm have been securely provided to a SIM associated with the subscriber. The method further comprises encoding the encrypted A2P SMS payload to obtain an encoded A2P SMS payload and relaying the encoded A2P SMS payload to the SIM. A method for communication at a subscriber device comprising a SIM associated with a subscriber.
Owner:ANAM TECH

Quantum network and a quantum authentication server

ActiveUS12556382B2Key distribution for secure communicationEngineeringQuantum authentication
A server configured to provide a pre-shared key “PSK” with a first user node, to allow a first user node and a second user node to share a PSK, the server comprising:a network interface; an authentication unit; an encryption unit; a key management system and a quantum key distribution unit,the authentication unit being configured to receive a request for authentication, via the network interface, of a first channel between a first user node and the server,the quantum key distribution unit being configured to allow a quantum key to be distributed between the first user node and the server, the quantum key being sifted using communication over the authenticated first channel to establish a first quantum key for the first user and server,the key management system being configured to provide a first PSK for the first user to allow the first user to authenticate with the second user,the encryption unit being configured to encrypt the first PSK with the quantum key to send to the first user node via the network interface.
Owner:KK TOSHIBA

Establishing security in a common application programming interface framework

Various aspects of the present disclosure relate to establishing security in a common application programming interface framework. An apparatus for wireless communication implements a first common application programming interface (API) framework (CAPIF) core function (CCF). The apparatus receives a first signaling indicating a first authentication request corresponding to an API invoker, the first authentication request including one or more of an API invoker identifier (ID) of the API invoker, an API exposing function (AEF) information, or service API information. The apparatus transmits, to a second CCF, a second signaling indicating a second authentication request, wherein the second authentication request includes one or more of the API invoker ID, an API invoker uniform resource indicator (URI), the indication of the AEF, the service API information, a pre-shared key for the AEF, or a root certifying authority (CA) for a certificate of the API invoker.
Owner:LENOVO UNITED STATES INC

Mixing pre-shared keys with post-quantum cryptography

Example embodiments of the present disclosure are directed to mixing pre-shared keys with post-quantum cryptography. A method comprises sending a key exchange request to a second apparatus, wherein the key exchange request comprises at least a first public key generated using a post-quantum cryptography (PQC) key generation mechanism (KEM), and information indicating that a post-quantum pre-shared key (PPK) is used; receiving a response from the second apparatus, wherein the response to the key exchange request comprises at least a first responder ciphertext generated based on the first public key using the PQC KEM by the second apparatus and information indicating that a PPK is used; and generating a seed key based on a first PQC KEM shared secret extracted from the first responder ciphertext, wherein the seed key is used to derive one or more intermediate cryptographic keys which are then mixed with the PPK using a pseudorandom function to derive one or more cryptographic keys used for security and authenticity of the communication between the first apparatus and the second apparatus.
Owner:NOKIA TECHNOLOGIES OY

Forward security zero round-trip time authentication method and system based on hash function

The invention discloses a forward security zero round-trip time authentication method and system based on a hash function, and the method comprises the steps: generating a first random number, a first private key and a corresponding public key through a client, encrypting application data through combining with a temporary session key, and constructing a protocol request message for transmission; the server generates a second random number, a second private key and a public key after verification, returns a protocol response message, and negotiates a shared key based on temporary private keys of the two parties; the two parties derive a new pre-shared key, a temporary session key and a session key using the shared key and a hash function. And the temporary private key is discarded after being used, so that the historical session still has forward security even if the key is leaked for a long time, and 0-RTT data transmission is supported at the same time. According to the invention, the shared key based on temporary private key negotiation is introduced, and the hash function is combined to derive and dynamically update the pre-shared key and the temporary session key, so that authentication key exchange with forward security and 0-RTT low-delay characteristics is realized.
Owner:XIAMEN UNIV

A key acquisition method and related apparatus

Embodiments of the present application provide a security authentication method and related device, applied to the field of short-distance communication, and particularly related to cabin domain communication. The method comprises: a first node receiving a first association request message from a second node, the first association request message comprising a first freshness parameter; the first node obtaining a first pre-shared key (PSK); wherein the first PSK corresponds to an identity of the second node; the first PSK is a PSK generated according to a second freshness parameter from the second node and a third freshness parameter from the first node, and the first PSK is used to verify the identity of the second node. By using the embodiments of the present application, the security of communication can be improved.
Owner:HUAWEI TECH CO LTD

Access authentication methods, devices, equipment, storage media, and computer program products

This application relates to the field of network security technology and discloses an access authentication method, apparatus, device, storage medium, and computer program product. The method includes: receiving a converged authorization protocol packet sent by a user terminal, wherein the extended field of the converged authorization protocol packet embeds encrypted biometric data, and the converged authorization protocol packet also includes encrypted access request information encrypted with a pre-shared key; decrypting the encrypted biometric data and the encrypted access request information respectively to obtain the biometric data and access request information; verifying the biometric data and the access request information respectively; and authenticating the user terminal's access request based on the verification results. Because this application uses dual authentication of pre-shared key and biometrics, and utilizes the uniqueness of biometrics, it avoids illegal authentication after key theft, thereby improving the security of access authentication protection.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Communication method and system

The present disclosure relates to a communication method and system. Firstly, a quantum secure key is obtained. Then, a pre-shared key is derived based on the quantum secure key. Next, the pre-shared key is imported into a secure transmission layer protocol. In this way, a master key can be generated based on the pre-shared key in the secure transmission layer protocol, and / or authentication can be performed based on the pre-shared key. Thus, the present disclosure generates a pre-shared key based on a quantum secure key in an out-of-band manner, and imports the pre-shared key into a secure transmission layer protocol, so that the pre-shared key has the ability to resist quantum attacks when used for key exchange and identity authentication.
Owner:ALIBABA (CHINA) CO LTD

Authentication for wireless networks

A network system includes a processor and memory encoded with instructions that, when executed, cause the system to receive an offered pre-shared key from a wireless device via a wireless network; access a mapped key-user pair comprising a unique pre-shared key and a user profile; and determine whether the offered pre-shared key corresponds to the unique pre-shared key. The instructions further permit the wireless device to connect to the wireless network according to a network policy associated with the mapped key-user pair in response to determining that the offered pre-shared key corresponds to the unique pre-shared key, or reject a network connection between the wireless device and the wireless network in response to determining that the offered pre-shared key does not correspond to the unique pre-shared key. The unique pre-shared key is used to encrypt and decrypt data transmitted between the wireless device and the wireless network.
Owner:INSIGHT DIRECT USA INC

Communication method and device, communication equipment, medium and product

The invention relates to a communication method and device, communication equipment, a medium and a product, and relates to the technical field of communication. The method is applied to a central controller, and comprises the following steps: determining a plaintext SID path between a source node and a destination node according to network topology information; according to the pre-shared key, encoding each plaintext SID in the plaintext SID path to obtain a ciphertext SID of the corresponding plaintext SID; establishing a mapping relationship between each plaintext SID and the corresponding ciphertext SID; and sending the mapping relationship to the nodes corresponding to the plaintext SIDs, so that the nodes package and transmit the message to be transmitted between the source node and the destination node according to the ciphertext SIDs in the mapping relationship. According to the technology of the application, the security of the data transmission process is improved, and the risk of data tampering is reduced.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Method for carrying out user authentication by applying pre-shared key to basis selection in quantum communication system, and device therefor

The present disclosure provides a method for carrying out user authentication in a quantum communication system. More specifically, the method comprises the steps of: on the basis of a pre-shared key, generating authentication quantum information by encoding an authentication message for user authentication, wherein a basis, for encoding each bit element constituting the authentication message, the respective bit elements corresponding to the respective positions of bit elements constituting the pre-shared key, is determined on the basis of respective bit values of the bit elements constituting the pre-shared key; transmitting the authentication quantum information to a receiving end via a quantum channel; receiving, from the receiving end, authentication quantum information measurement information related to a value derived by means of the receiving end measuring the authentication quantum information; and carrying out user authentication with the receiving end on the basis of the authentication quantum information measurement information.
Owner:LG ELECTRONICS INC

Identity authentication method and apparatus, storage medium, program, and program product

An identity authentication method is disclosed in embodiments of the present application. When a requester and an authentication access controller perform identity authentication using an authentication mechanism of a pre-shared key, the identity information of entities is transmitted in the form of ciphertext, thereby preventing the identity information of the entities from being exposed during the transmission, so that attackers cannot obtain private or sensitive information. The mutual or unilateral identity authentication between the authentication access controller and the requester is achieved while ensuring the confidentiality of the entity identity and related information, thereby laying a foundation for ensuring that the user accessing the network is legitimate and / or the network accessed by the user is legitimate. Meanwhile, in connection with key exchange calculations and by an ingenious and detailed design, the ability of the authentication process to resist dictionary brute force attacks or quantum computing attacks is enhanced. Further disclosed in embodiments of the present application are an identity authentication apparatus, a storage medium, a program, and a program product.
Owner:CHINA IWNCOMM

Out-of-Band Quantum Key Distribution Using Cellular SMS

Out-of-band quantum key distribution using cellular SMS can include receiving, from a user device, a client identifier that identifies the user device and a first key identifier that identifies a first key having a first key value that is a first quantumly generated random bit string. A second key that includes a second key value can be requested and received from the key service, the second key value including a second quantumly generated random bit string. The second key value can be provided to a short message service center for delivery to the user device. An operation can be performed on the first key value and the second key value to obtain a copy of a pre-shared key, which can be used when exchanging encrypted communications with the user device.
Owner:INTERWISE CO LTD +1

Key authentication method, device, electronic device, and storage medium

The present application provides a key authentication method, a device, an electronic device, and a storage medium, which determine user information based on a key authentication request sent from a user side, where the key authentication request includes the user information and an initial key, and determine whether the initial key matches a first key, where the first key is used to determine whether the user side needs to register a pre-shared key, and if the initial key matches the first key, register a first pre-shared key for the user side and bind the first pre-shared key to the user information.
Owner:ルイジェ ネットワークス カンパニーリミテッド

A network security transmission method for accessing a power information intranet and related equipment

The application relates to the technical field of network security, and discloses a network security transmission method for accessing a power information intranet and related equipment, which comprises the following steps: receiving an access request sent by a security agent module, establishing a control security channel for interacting with the security agent module according to the access request; exchanging parameters with the security agent module in the control security channel, and authenticating the exchanged parameters to obtain an authentication result; exchanging a pre-shared key for data encryption with the security agent module based on the authentication result, and establishing a data security channel according to the pre-shared key for data encryption; and processing received SSL data packets through the data security channel for network security transmission. In the application, the control security channel is used for negotiation and authentication of security parameters, and the data security channel is used for transmission of encrypted data. The control security channel and the data security channel are established in steps, and hierarchical protection of a communication process is realized.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO

Identity registration for wireless networks

A network system includes a processor and computer-readable memory. The computer-readable memory is encoded with instructions that, when executed by the processor, cause the network system to register a unique pre-shared key, a user profile, and a network policy. The instructions further associate the unique pre-shared key with the user profile to form a key-user pair, associate the key-user pair with the network policy to form a mapped key-user pair, and provide the unique pre-shared key to a user to connect one or more devices to a wireless network. The unique pre-shared key is used to encrypt and decrypt data transmitted between a connected wireless device and the wireless network.
Owner:INSIGHT DIRECT USA INC

Hybrid post-quantum TLS migration with binder-enforced resumption

A system and method for secure transport resumption during post-quantum migration. A server negotiates a handshake and issues a session ticket embedding scope metadata that identifies a key-exchange class (e.g., hybrid post-quantum and classical, or classical), and may include a schema version, service-identity scope, policy flags, a rollout epoch, and a site identifier. On a subsequent connection the client presents the ticket with a resumption binder. The server selects an expected binder class from the scope metadata, verifies the binder using a pre-shared key derived for the selected class, and accepts or refuses resumption accordingly. Binding resumption to the negotiated class mitigates cross-class replay and downgrade while remaining compatible with classical endpoints and middleboxes. Optional embodiments include certificate-transparency enforcement via policy flags, point-of-presence scoping, epoch-based rollout and rollback, and hardware-security-module-gated key activation with quorum approval and attestation. The approach enables black-box verifiability and incremental, standards-conformant deployment.
Owner:VON LIECHTENSTEIN MAXIMILIAN RALPH PETER