Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

221 results about "Replay attack" patented technology

A replay attack (also known as playback attack) is a form of network attack in which a valid data transmission is maliciously or fraudulently repeated or delayed. This is carried out either by the originator or by an adversary who intercepts the data and re-transmits it, possibly as part of a masquerade attack by IP packet substitution. This is one of the lower tier versions of a "Man-in-the-middle attack".

Privacy protection for a-iot device identifiers

An apparatus and system for privacy protection for Ambient Internet-of-Things (A-IoT) devices are disclosed. A-IoT devices transmit obfuscated identifiers (OIDs) instead of actual identifiers, which are de-obfuscated by the network to retrieve the original identifiers. The device identifiers are obfuscated using shared secret parameters and periodically updated configurations. Hash-based lightweight privacy mechanisms, temporary identifiers (TempIDs), and pseudonym generation may be used to ensure secure communication and prevent replay attacks.
Owner:INTEL CORP

Data security transmission method based on ML-KEM algorithm and PUF

The invention discloses a data security transmission method based on an ML-KEM algorithm and a PUF, and the method comprises the steps: in a registration stage, mobile equipment generates an anti-quantum key through employing a PUF technology, and a CA issues an anti-quantum digital certificate based on a Falcon algorithm and a cryptographic accumulator; in an identity authentication stage, a mobile device and an edge gateway complete bidirectional identity authentication by exchanging identity labels, anti-quantum certificates and authentication key parameters in combination with a Falcon algorithm and PUF challenge-response, and negotiate to generate a shared key by using an ML-KEM algorithm, thereby effectively defending threats such as man-in-the-middle attack, replay attack and identity counterfeiting; in a data transmission stage, two communication parties realize data encryption transmission by adopting a symmetric encryption algorithm, and data integrity and source credibility are guaranteed in combination with a Falcon digital signature; the whole scheme has the advantages of quantum security resistance, efficient authentication, dynamic key updating, lightweight encryption and the like.
Owner:SICHUAN UNIV +1

User Authentication, Spoofing and Replay Attack Prevention, Liveness Detection, and User-and-Document Verification using a Live Video Stream with Spatial Challenges

User authentication, spoofing and replay attack prevention, liveness detection, and user-and-document verification using a live video stream with spatial challenges. A camera of an electronic device captures and transmit a live selfie user-facing video, as part of a user registration process. The user is instructed to spatially move his body or face, such that his face would appear within a first particular on-screen shape; and to also, concurrently or simultaneously, spatially hold in his hand or move a particular an identification document such that it would appear within a second on-screen shape. Optionally, the on-screen shape moves on the screen, and the user is required to spatially move the relevant item to keep it within the boundaries of the moving on-screen shape. The system then analyzes the video via computerized vision, to determine whether the user complied with the spatial manipulation challenges.
Owner:IRONVEST INC

System and method to detect and countermeasure RPL attacks in IoT network

A system and a method to detect an attack on an IoT network is disclosed. The IoT network includes interconnection of multiple IoT devices. The method includes receiving, by a network connection device, multiple ICMPv6 network packets from IoT devices and outputting multiple output packets; and matching, by a routing device, a network traffic pattern to attack signatures structured as a taxonomy according to which part of a packet is misused. The taxonomy includes a branch to a data plane attack and a control plane attack, respectively. When an IPv6 RPL packet is detected, the method includes checking for generating, modifying, and replaying attacks by an attacker. When a non-RPL packet is detected, the method includes checking for dropping and leaking packet attacks by the attacker. When the attack is detected, the method includes invoking a solution to the attack. The solution includes mitigation of the attack by the attacker.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

Sound authenticity identification method and system based on multi-modal feature deep interactive fusion

The invention discloses a sound authenticity identification method based on multi-modal feature deep interactive fusion. According to the method, a double-flow architecture is adopted, and a pre-trained BEATs model and a CNN14 network are respectively utilized to extract Transform sequence features and convolution time-frequency embedding features of an audio; an adaptive MobileFormer fusion device is innovatively proposed, an original MobileFormer structure used in the image field is transformed into a bidirectional cross-modal interaction module suitable for one-dimensional time sequence audio features, dynamic complementary modeling of local details and global semantic features is achieved through a cross attention mechanism, and dynamic nonlinearity is introduced to activate and enhance the expression ability; and the fused enhanced features are input into a hierarchical graph attention network ASSIST, and high-order semantic modeling and authenticity classification are completed by combining spectrogram and time sequence double-flow reasoning. Experimental results show that the performance of the method on an ASVspoof2021LA data set is superior to that of an existing baseline model. The method can effectively detect AI generation voice, replay attack and other forged voice, and is suitable for a voice authentication system.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

USB key identity authentication method, system and device based on digital signature trusted chain and medium

The invention discloses a USB key identity authentication method, system and device based on a digital signature trusted chain and a medium, and belongs to the technical field of information security, and the method comprises the following steps: after a receiving terminal accesses a USB key, reading a digital certificate, collecting a device identifier, a network parameter and geographical location information, generating first environment abstract data through abstract processing, and signing; and the authentication server stores the abstract data after passing the signature verification. In the authentication request stage, the server generates random challenge data; the receiving terminal collects the current environment information to generate second environment abstract data, and the second environment abstract data is signed and sent again after being combined with the challenge data. And the server extracts the second abstract data after signature verification, performs similarity comparison with the first abstract data, and confirms that the identity authentication is valid when conditions are met. According to the method, the binding of the environment characteristics and the identity is realized, the protection capability of the U-type shield authentication system on counterfeiting, cloning and replay attacks is remarkably improved, and the credibility and the stability of an authentication result are enhanced.
Owner:YUNNAN POWER GRID CO LTD

QR code verification engine

A QR Code Verification Engine provides a multi-layered security framework for generating, validating, and authenticating QR codes while preventing tampering, fraud, and unauthorized access. The system embeds a hidden security layer within the QR code using steganographic encoding or invisible watermarking techniques, ensuring detection of any modifications. The hidden layer is encrypted using asymmetric cryptography, allowing only an authorized verification system to extract and validate it. An AI-powered tamper detection module analyzes QR codes for anomalies, while cryptographic hash verification ensures integrity. The system employs biometric authentication, push notification approvals, and contextual security measures to enhance user verification. Dynamic QR codes with expiration rules prevent replay attacks. Secure offline verification allows authentication without network connectivity. The system integrates with financial platforms, web security tools, and real-time fraud detection mechanisms, ensuring a highly secure and scalable QR code validation framework for transactions, identity verification, and access control applications.
Owner:BANK OF AMERICA CORP

Multi-factor authentication with device and carrier validation

The invention provides systems, methods, and computer-readable media for multi-factor authentication (MFA) using device and carrier validation. A user device generates an attested blob containing cryptographic keys and a Universal Integrated Circuit Card (UICC)-originated International Mobile Subscriber Identity (IMSI), which is transmitted to a cloud-based MFA service. The service validates the attested blob, coordinates with an Original Equipment Manufacturer (OEM) service, and executes an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) process with the carrier network to establish mutual trust. Authentication data, including a validated phone number independent of the device's stored number, is securely stored in a cloud wallet. The invention enhances security by mitigating risks such as spoofing, replay attacks, and SIM swapping, providing a novel authentication framework compatible with modern networks.
Owner:SYNIVERSE TECHNOLOGIES LLC

Multi-carrier wireless optical communication physical layer security authentication system and method

ActiveCN121887314ARealize fine identificationSolve impersonation attacksKey distribution for secure communicationLine-of-sight transmissionComputer hardwarePhotodetector
The invention relates to the technical field of wireless optical communication, and discloses a multi-carrier wireless optical communication physical layer security authentication system and method.The receiving end of the system comprises a multi-receiver joint judgment module, a data gating module, an information sink and at least three receivers; each receiver comprises an optical detector, a cyclic prefix removal module, an FFT (Fast Fourier Transform) module, a receiving end key update storage and watermark generation module, a channel estimation and watermark extraction module, a subcarrier authentication module, a multi-carrier self-adaptive decision judgment module and a multi-carrier integration module; oFDM frequency domain channel response is used as an implicit fingerprint, a self-adaptive switching decision strategy is executed according to the average signal-to-noise ratio, fine recognition of legal device position features is achieved without ranging hardware, IM / DD can be adapted, the problem of imitation attack and replay attack authentication of attackers is effectively solved from the physical mechanism, and the method has the advantages of being high in practicability and high in practicability. And the accuracy and robustness of physical layer authentication are obviously improved.
Owner:SUZHOU UNIV

Method for realizing firmware security access on network card driving layer

The invention discloses a method for realizing secure access of firmware on a network card driving layer. According to the method, an application program is authenticated by adopting a challenge-response mechanism based on a symmetric key; after the authentication succeeds, the driving program obtains and records a process identifier of the application, and a single effective authorization session bound with the specific process is established. Secondly, when a read-write request is processed, the driver compulsively verifies the consistency of the requested PID and the authorized PID; for a write-in request, a digital signature verification based on asymmetric encryption is added to ensure the authenticity and integrity of a data source. And finally, after each hardware operation is successfully completed, the drive program immediately makes the current authorized session invalid. Through a multi-level security mechanism, illegal access, replay attack and session hijacking are effectively resisted, and secure, controllable and refined access to internal data of hardware is realized.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Patient privacy data protection method used in operating room

The invention relates to the technical field of medical information security, and discloses a patient privacy data protection method used in an operating room. The method comprises the following steps: uniformly coding patient privacy into a binary system, zero-filling the binary system into a square matrix, and filling according to rows; a disturbance seed is generated through combination of operating room environment temperature and noise quantification, and chaotic mapping is driven to carry out two-dimensional replacement on a matrix; applying position-related mask XOR to the sub-blocks, and overturning odd columns or even rows according to global parameters; and then linearization is carried out according to rows and filling is eliminated, and a final ciphertext is output. Meanwhile, disturbance control parameters are constructed and bound, and then Hash check is calculated and structured packaging is carried out. Through global and local double-layer disturbance, field seed driving and reversible coding, the scheme enhances the resistance to statistical analysis, plaintext attack and replay attack on the premise of no fixed key, and gives consideration to real-time performance, security and traceability.
Owner:BEIJING SHIJITAN HOSPITAL CAPITAL MEDICAL UNIVERSITY

Vehicle-mounted ECU identity authentication method and system based on multi-factor random seed and multiple security levels

The invention relates to the technical field of electronic security, and discloses a vehicle-mounted ECU identity authentication method and system based on a multi-factor random seed and multiple security levels, and the method comprises the steps: synthesizing a random seed at an ECU end through multiple factors such as CRC32, a random number, a timestamp and a global seed, and returning the random seed to a client; the client calculates a key and returns the key by using a corresponding key algorithm according to the target security level; the ECU calculates an expected key through the same algorithm and compares the expected key with a client key, if the expected key is consistent with the client key, the session of the level is opened and the delay timer is closed, if the session fails, the number of failure times of the level is accumulated, and if a threshold value is reached, the delay timer of the corresponding security level is started and the access of the level is locked until the timing is finished; and meanwhile, the authentication result, the security level, the timestamp, the failure count and the seed state are written into a security log. According to the method, it is guaranteed that each time of seed is unpredictable and is strongly correlated with the historical state, a non-zero recalculation mechanism is matched, hidden dangers of fixed seeds, replay attacks and prediction attacks are thoroughly eliminated, and attacks can be protected, and events can be traced.
Owner:BEIJING NEW ENERGY VEHICLE TECH INNOVATION CENT CO LTD

Implementation method and system of dual access control mechanism based on block chain and encryption machine

The invention relates to the technical field of data security and access control, in particular to an implementation method and system of a dual access control mechanism based on a block chain and an encryption machine, and the implementation method comprises the steps of authority management based on a smart contract, encryption machine dynamic key generation, dual access control, and exception handling and auditing. The method has the beneficial effects that the non-tampering property of authority distribution and operation records is ensured through a distributed account book technology of the block chain, and a double-layer security barrier of logic credibility and physical isolation is formed in combination with hardware-level key protection (such as a security chip HSM) of an encryption machine. And the anti-attack capability is improved, the block chain resists data tampering and insider disintegration, the encryption machine prevents key side channel attacks, and the double mechanisms can cope with complex attack modes such as man-in-the-middle attacks, replay attacks and advanced persistent threats (APT).
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Method and system for securely selecting applications

The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB

A communication network anonymous authentication method, user equipment, home network and product

The application discloses a communication network anonymous authentication method, user equipment, a home network and a product, wherein a network side parameter value is obtained by calculating according to an encryption parameter value in received authentication data; and a replay attack is identified according to the size of the network side parameter value and a locally stored terminal parameter value. The application scheme can identify a tracking attack on user location information and protect the privacy security of a terminal user.
Owner:CHINA MOBILE COMM LTD RES INST +1

Lightweight network security protection method for intelligent control terminal of Internet of Things

The invention provides a lightweight network security protection method for an intelligent control terminal of the Internet of Things, and aims to solve the problem of contradiction between security and real-time performance of resource-constrained equipment. According to the method, three core stages of equipment registration, bidirectional identity authentication and information encryption authentication are covered through layered architecture design. The method comprises the following steps: firstly, binding hardware characteristics and registration information by using physical unclonable functions (PUF) and HMAC to ensure that the identity of equipment is unique and credible; secondly, bidirectional identity authentication among the RTU, the LCS and the CCS is realized based on the PUF, the HMAC and the digital signature, and counterfeiting and replay attacks are prevented; and finally, symmetric encryption and asymmetric encryption are adopted to guarantee confidentiality, integrity and non-repudiation of communication data. According to the scheme, a timestamp and random number mechanism is introduced, the anti-attack ability is enhanced, the resource overhead and communication delay are optimized, the real-time requirement of the industrial Internet of Things is met, and the method is suitable for a distributed Internet of Things system in the fields of electric power, energy and the like and has the advantages of being efficient, safe and extensible.
Owner:CHUXIONG POWER SUPPLY BUREAU OF YUNNAN POWER GRID CO LTD

A smart lock security authentication method based on mobile terminal virtual credentials

The present application relates to the field of information security technology, and particularly relates to a kind of smart lock security authentication method based on mobile terminal virtual credential;Including door lock end generates non-repeated random challenge value using random disturbance mechanism;Mobile terminal utilizes HMAC algorithm to operate challenge value and credential identity key, generates dynamic token;Dynamic token is processed using hash algorithm to obtain response digest by one-way mapping;Zero-knowledge proof algorithm is used to construct mathematical proof body;Door lock end verifies proof body;Session binding credential is generated by chain check mechanism;Session isolation mechanism is used to mark consumed state and detect replay attack.The present application realizes identity authentication under zero contact condition of credential original text, effectively eliminates the possibility of replay attack, and ensures the security of credential key.
Owner:DONGGUAN XINXINGXIN INTELLIGENT TECH CO

A pure electric vehicle information security anti-replay control method and system

The application provides a pure electric vehicle information security anti-replay control method and system, relates to the technical field of new energy vehicle information security, and solves the technical problems that the prior art cannot add a check field to a standardized message and is difficult to cope with variable period attacks. The method comprises the following steps: obtaining repeated messages caused by a replay attack on a CAN bus; when the repeated messages are gear messages, a life signal check and period arbitration method is used to arbitrate the repeated messages; when the repeated messages are brake messages, a deep fuzzy arbitration and time domain period delay check method is used to arbitrate the repeated messages; and hierarchical alarm is performed according to the duration of the replay attack and the arbitration result. The application is used in the process of transmitting key control messages such as gear messages and brake messages on a CAN bus of a pure electric vehicle, realizes accurate defense against replay attacks, and guarantees the information security and driving stability of the vehicle CAN network.
Owner:ANHUI ANKAI AUTOMOBILE

Replay Attack Preventtion System

Various aspects of the disclosure relate to a smart contract-based security system for near field communication (NFC) data transactions. An NFC data transaction initiated by a first computing device generates a transaction token used to complete the NFC data transaction with a second computing device via an NFC communication link between the two devices. The transaction token is communicated to a remote device with transaction information, where the transaction information may be embedded with the transaction token. The transaction token is processed via smart contract operation to analyze the transaction token to determine whether the token is valid. If valid, the smart contract triggers completion of the data transaction. If invalid, the data transaction is inhibited by the smart contract. Once processed, the smart contract modifies transaction parameters and generates a stale token.
Owner:BANK OF AMERICA CORP

Rapid two-factor identity authentication method based on equipment position proximity relation

The invention discloses a rapid two-factor identity authentication method based on an equipment position proximity relationship. The method comprises the following steps of: generating an acoustic sensing signal by adopting a broadband high-autocorrelation linear frequency modulation signal, playing the signal by a mobile terminal, synchronously acquiring a signal sample pair recorded by the mobile terminal and login equipment, and inputting the signal sample pair into an authentication model network after environmental noise elimination and segmentation. The authentication model network is based on a twin neural network architecture, microphone frequency response difference interference can be eliminated, and equipment position acoustic multipath feature extraction and position proximity relation identification are realized. The authentication model network extracts the frequency response specificity characteristics of the loudspeaker of the mobile terminal, and constructs a personalized authentication model of the registered terminal in combination with a weighted joint loss function, thereby realizing accurate authentication of the registered terminal in an authentication stage. According to the method, bidirectional acoustic communication between devices is not needed, the device synchronization complexity and hardware requirements are reduced, same-position attacks and replay attacks can be resisted, and rapidness, adaptability and safety are taken into account.
Owner:BEIJING UNIV OF TECH

Equipment authentication method and system, equipment and storage medium

The invention discloses a device authentication method, system and device and a storage medium, relates to the technical field of information security, and solves the specific problem of device identity authentication in resource limited scenes such as the Internet of Things. A challenge response data set is established through a pre-registration mechanism, so that an authentication party can complete verification on the premise of not knowing a symmetric key in the equipment, and the key management complexity and the leakage risk are remarkably reduced. Through the design that the device locally generates and stores a secret key, prestores challenge response pairs with limited times, compares hash values instead of plaintext response values and the like, the calculation and storage overhead and the communication load of the device end are effectively controlled while the replay attack resistance is ensured. By independently establishing a new challenge-response data set, the equipment can still realize security identity verification in a closed network or a specific application environment, the mandatory dependence on a key management system of an equipment manufacturer is reduced, and the flexibility and applicability of an authentication mechanism are enhanced.
Owner:WATCHDATA SYST +1

Authentication method and device for data multi-party computation based on data operation

The embodiment of the present application relates to a kind of authentication method and device based on data operation of data multi-party computing, the method comprises: based on predetermined computing task to client sends handshake request;Identity certificate sent by client is received, and first signature value, second signature value and third signature value are obtained from the predetermined field of the identity certificate;From database, pre-stored data record is obtained, and the data record is related to the client;The first signature value, second signature value and third signature value are verified using the data record.The technical scheme provided in the embodiment of the present application verifies the signature value of algorithm / data, platform and hardware in the process of multi-party computing, and algorithm / data, platform and hardware are associated with each other, so that algorithm / data is verified while the platform (software) and hardware on which algorithm / data is deployed are also verified, the security of multi-party computing is improved, and replay attack can be prevented.
Owner:HANGZHOU NUOWEI INFORMATION TECHNOLOGY CO LTD

Open Application Programming Interface Gateway Management System and Method

This application relates to the field of interface gateway management technology, and discloses an open application programming interface (API) gateway management system and method. The method includes: responding to a received API call request, extracting the caller's identity information and request context parameters, performing dynamic authentication on the call request, and obtaining the authentication result; obtaining the corresponding rate limiting rules, performing dynamic mixed-mode traffic control on the call request, and obtaining the traffic control result; forwarding the call request to the corresponding backend service, and monitoring the backend service's operating status data in real time during the forwarding process, performing circuit breaker analysis based on the operating status data and preset business semantic rules, and obtaining the circuit breaker control signal; executing the corresponding request processing action according to the circuit breaker control signal, and collecting full-link observable data such as call chain tracing data and network performance data in real time to manage interface calls; this application can effectively intercept replay attacks, abnormal logins from different locations, etc., and improve gateway throughput.
Owner:SIMBA NETWORK TECH (NANJING) CO LTD

Lightweight identity authentication method for limited equipment under power internet of things

The invention relates to the field of security protection of the electric power Internet of Things, in particular to a lightweight identity authentication method for limited equipment under the electric power Internet of Things, which can adapt to a large-scale and widely distributed network environment of the electric power Internet of Things by introducing a lightweight encryption algorithm and an efficient key exchange protocol, ensures the security, and improves the authentication efficiency of the limited equipment under the electric power Internet of Things. The calculation burden and the energy consumption of limited equipment in the power Internet of Things are effectively reduced; a decentralized authentication mechanism is adopted, so that the problems of single-point failure and performance bottleneck in a traditional centralized authentication method are solved, efficient equipment authentication and key exchange are realized, and the expandability of a network is ensured; security threats such as replay attacks and man-in-the-middle attacks are effectively prevented by periodically updating session keys and using digital signatures, and the reliability of network communication and the confidentiality of data are enhanced. By introducing a key exchange protocol and a digital signature technology, the integrity and authenticity of data are guaranteed, tampering behaviors of malicious nodes are prevented, and the overall security of the system is improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD +3

New energy intelligent production management platform network security protection method based on national cryptographic algorithm

The invention discloses a new energy intelligent production management platform network security protection method based on a cryptographic algorithm. According to the invention, through deep fusion of a national cryptographic algorithm and a physical feature authentication technology, a security system of dual verification of cryptographic protection and an equipment entity state is constructed, and access and replay attacks of a forged terminal are effectively resisted. A dynamic secret key system and multi-dimensional access control form a three-dimensional protective net, so that the real-time confidentiality of mass production data transmission can be guaranteed, and abnormal operation instructions can be accurately blocked. In particular, in an equipment identity verification link, a dynamic coupling mechanism of physical characteristics and environmental parameters breaks through a traditional static authentication mode, so that an attacker cannot implement camouflage by copying a secret key or a certificate, and the risk of identity fraudulent use caused by frequent access of mobile equipment in a new energy scene is fundamentally solved.
Owner:华电(贵州)新能源发展有限公司

Vxlan packet processing method and device, electronic equipment and storage medium

Embodiments of the present application provide a VXLAN message processing method and device, electronic equipment and storage medium, when processing service messages based on the VXLAN protocol, the service messages can be encapsulated by using an encapsulation method based on the endogenous security VXLAN protocol, and the service messages can be decapsulated by using a decapsulation method based on the endogenous security VXLAN protocol, so that the VXLAN payload can be transmitted in the form of ciphertext, and the network security device implementing the VXLAN protocol can be protected from replay attacks, thereby not only solving the problem that the traditional VXLAN protocol does not have security capabilities, but also solving the problems that the VXLAN over IPSec level is too many and the VXLAN protocol header and the UDP header are invisible to the intermediate devices in the link, and the network security device cannot quickly identify the tenant to which the message belongs, and is suitable for many VXLAN application scenarios.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Method, device and computer storage medium for transmitting service request information

The application discloses a service request information transmission method, device and equipment and a computer storage medium. The method is applied to a gateway and includes the following steps: receiving first service request information sent by a target device, wherein the first service request information comprises target additional check information and second service request information; decrypting the target additional check information by using a preset decryption algorithm to obtain a first timestamp and acquiring a second timestamp at the time of decryption completion; and sending the second service request information to a target server in the case that the difference between the first timestamp and the second timestamp is less than a first preset value and the target additional check information is inconsistent with pre-stored additional check information. In this way, an attacker cannot modify the encrypted timestamp, and the target additional check information of the service request information is checked twice, so that multiple repeated service request information cannot enter the server, that is, a replay attack cannot occur.
Owner:CHINA MOBILE GROUP ANHUI +1

Remote real-time control method and system for operating system based on dynamic encryption

The application discloses a remote real-time control method and system of an operating system based on dynamic encryption, and belongs to the technical field of network communication, comprising collecting original data to obtain a state description vector; obtaining a key through the state description vector; constructing a structure abstract vector, introducing a state disturbance term, performing an encryption operation, and outputting ciphertext; decrypting the ciphertext using the key to obtain a control instruction and a structure abstract, verifying the integrity of the control instruction through the structure abstract; calculating a behavior prediction vector through a behavior prediction model after the instruction integrity check; aggregating and unifying the behavior prediction results of all devices, and outputting a final instruction execution judgment result through a federal consistency judgment function. The application establishes a remote control system based on the linkage of an encryption mechanism and behavior judgment based on state perception, can effectively resist high-risk problems such as replay attacks, control hijacking, illegal execution, and is suitable for practical application scenarios with high safety sensitivity and multi-terminal cooperation.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

A device authentication method, system, device and storage medium

The application discloses a device authentication method, system, device and storage medium, relates to the technical field of information security, and solves the specific problem of device identity authentication in a resource-constrained scene such as the Internet of Things. A challenge-response data set is established through a pre-registration mechanism, so that an authenticator can complete verification without knowing the internal symmetric key of the device, thereby significantly reducing the key management complexity and leakage risk. Through the design of locally generating and keeping the key by the device, pre-storing a limited number of challenge-response pairs, and comparing the hash value instead of the plaintext response value, the anti-replay attack capability is ensured, and the calculation, storage overhead and communication load of the device end are effectively controlled. A new challenge-response data set is independently established, so that the device can still realize safe identity verification in a closed network or a specific application environment, the mandatory dependence on the key management system of the device manufacturer is reduced, and the flexibility and applicability of the authentication mechanism are enhanced.
Owner:WATCHDATA SYST +1