Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

43 results about "Replay attack" patented technology

A replay attack (also known as playback attack) is a form of network attack in which a valid data transmission is maliciously or fraudulently repeated or delayed. This is carried out either by the originator or by an adversary who intercepts the data and re-transmits it, possibly as part of a masquerade attack by IP packet substitution. This is one of the lower tier versions of a "Man-in-the-middle attack".

Method and system for securely selecting applications

PCT designated stageWO2026130660A1Multiple keys/algorithms usageDigital data protectionEngineeringMessage authentication code
The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB

A smart lock security authentication method based on mobile terminal virtual credentials

The present application relates to the field of information security technology, and particularly relates to a kind of smart lock security authentication method based on mobile terminal virtual credential;Including door lock end generates non-repeated random challenge value using random disturbance mechanism;Mobile terminal utilizes HMAC algorithm to operate challenge value and credential identity key, generates dynamic token;Dynamic token is processed using hash algorithm to obtain response digest by one-way mapping;Zero-knowledge proof algorithm is used to construct mathematical proof body;Door lock end verifies proof body;Session binding credential is generated by chain check mechanism;Session isolation mechanism is used to mark consumed state and detect replay attack.The present application realizes identity authentication under zero contact condition of credential original text, effectively eliminates the possibility of replay attack, and ensures the security of credential key.
Owner:DONGGUAN XINXINGXIN INTELLIGENT TECH CO

Authentication method and device for data multi-party computation based on data operation

The embodiment of the present application relates to a kind of authentication method and device based on data operation of data multi-party computing, the method comprises: based on predetermined computing task to client sends handshake request;Identity certificate sent by client is received, and first signature value, second signature value and third signature value are obtained from the predetermined field of the identity certificate;From database, pre-stored data record is obtained, and the data record is related to the client;The first signature value, second signature value and third signature value are verified using the data record.The technical scheme provided in the embodiment of the present application verifies the signature value of algorithm / data, platform and hardware in the process of multi-party computing, and algorithm / data, platform and hardware are associated with each other, so that algorithm / data is verified while the platform (software) and hardware on which algorithm / data is deployed are also verified, the security of multi-party computing is improved, and replay attack can be prevented.
Owner:HANGZHOU NUOWEI INFORMATION TECHNOLOGY CO LTD

Open Application Programming Interface Gateway Management System and Method

This application relates to the field of interface gateway management technology, and discloses an open application programming interface (API) gateway management system and method. The method includes: responding to a received API call request, extracting the caller's identity information and request context parameters, performing dynamic authentication on the call request, and obtaining the authentication result; obtaining the corresponding rate limiting rules, performing dynamic mixed-mode traffic control on the call request, and obtaining the traffic control result; forwarding the call request to the corresponding backend service, and monitoring the backend service's operating status data in real time during the forwarding process, performing circuit breaker analysis based on the operating status data and preset business semantic rules, and obtaining the circuit breaker control signal; executing the corresponding request processing action according to the circuit breaker control signal, and collecting full-link observable data such as call chain tracing data and network performance data in real time to manage interface calls; this application can effectively intercept replay attacks, abnormal logins from different locations, etc., and improve gateway throughput.
Owner:SIMBA NETWORK TECH (NANJING) CO LTD

An electronic seal analysis and verification method based on AI and cryptography fusion

The application belongs to the technical field of electronic seal security, and more particularly to an electronic seal analysis and verification method based on AI and cryptography fusion. The AI feature extraction and comparison steps locate the seal area and extract multi-dimensional features by means of a pre-trained convolutional neural network model, realize accurate verification at the level of seal visual features, and break through the limitation of single verification dimension of traditional technology. Then, SM2 and SM3 national encryption algorithms are used for signature verification and hash value verification respectively, the signature anti-counterfeiting capability is strengthened, and the risks of forgery and tampering are resisted. Finally, the effectiveness is determined by combining the two-dimensional verification results, the reliability of the verification conclusion is ensured, the security and accuracy of the electronic seal verification are significantly improved, and malicious behaviors such as forgery, tampering and replay attacks are effectively resisted.

A ship-to-shore information communication method and device

ActiveCN116346421BImprove data integrityimprove privacyData packOriginal data
This application discloses a ship-to-shore information communication method and apparatus, relating to the technical field of coastal communication. The method includes: responding to receiving an encrypted data packet from a ship-based or shore-based IPSec security gateway device; if the packet's message structure is an ESP protocol message, then searching for an encryption algorithm and security specification according to the security parameter index; after verifying the integrity of the ESP message in the data packet according to the encryption algorithm and security specification, detecting whether the data packet is a replay attack; if the data packet is not a replay attack, then decrypting the data packet in reverse according to the encryption algorithm and security specification, obtaining and sending the original IP data to the core network layer for subsequent processing and forwarding. This method ensures the integrity and privacy of transmitted data in high-security scenarios such as ship-to-shore communication.
Owner:THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA +1

Secure Authentication and Distribution of Redundancy Configuration Data for Compute Modules

PendingUS20260189403A1Security frameworkTerm memory
A security framework for redundancy configuration management ensures that multiplexer control data and redundancy maps distributed to compute modules are authenticated, verified, and securely applied. Configuration packets are cryptographically signed, versioned, and transmitted through an isolated sideband channel. A coordination processor verifies signatures, checks integrity hashes, prevents replay, and applies updates only during redundancy-safe intervals. Logs of verified configurations are stored in secure memory and may be audited through a hierarchical management structure. The invention prevents unauthorized or corrupted redundancy configurations in multi-module compute systems.
Owner:SILVEBROOK KIA

Agricultural perception node-oriented lightweight secure communication method and system

PendingCN122457243APlaintextCloud data management
The application discloses a kind of light security communication method and system for agricultural perception node.The method includes that 256-bit static master key is preset in the bottom layer security storage area of perception node and heterogeneous convergence gateway, and the unique hardware serial number is read as node identification;Synchronous acquisition environmental data and visual feature data, splice into long payload plaintext;Derive dynamic session key, use dynamic session key to drive stream cipher to encrypt long payload plaintext, static master key drives block cipher to encrypt short header, and encapsulates into data frame;Data frame is sent through wireless channel, and heterogeneous convergence gateway receives and reversely decrypts short header to extract dynamic anti-fake factor, and replay attack verification is carried out;After verification, dynamic session key is reconstructed to restore data and uploaded to cloud data management server.The application also discloses a system using the above light security communication method for agricultural perception node, realizes the high security node legitimacy authentication and anti-replay attack under limited hardware computing power.
Owner:QIQIHAR UNIVERSITY

An identity feature-based target range system bidirectional authentication method and system

PendingCN122339700ASecure communicationMan-in-the-middle attack
This invention discloses a two-way authentication method and system for a target range system based on identity features, belonging to the field of target range system security technology. It includes three verification stages: the control server first generates a random challenge value and sends it to the target device; the target device calculates a response value using a non-cloning function and returns it. After successful verification, both parties exchange and confirm random numbers through hash operations, ultimately establishing a secure communication link. By dynamically generating random challenge values ​​and combining a two-way authentication mechanism using non-cloning functions and hash chains, it solves the problems of identity forgery, man-in-the-middle attacks, and replay attacks in traditional methods, offering advantages such as improved identity authentication security and ensured communication reliability.
Owner:HUANENG POWER INT INC +1

A voiceprint spoofing defense method, device and computer readable storage medium

PendingCN122372302ASound sourcesDecision model
A method, apparatus, and computer-readable storage medium for voiceprint spoofing defense include: acquiring a speech signal to be verified; extracting multi-dimensional features from the speech signal to obtain a multi-dimensional feature vector, wherein the multi-dimensional feature vector includes at least speech text content features, identity features, sound quality features representing recording or synthesis traces, liveness features representing the physiological characteristics of the sound source, and adversarial perturbation features; fusing the multi-dimensional feature vector to obtain a joint feature vector; inputting the joint feature vector into a pre-trained joint risk decision model to obtain a spoofing risk score; and determining the verification result of the speech signal to be verified based on the comparison result of the spoofing risk score and a preset threshold. This application can effectively detect multiple attack modes such as replay attacks, speech synthesis attacks, and adversarial example attacks simultaneously; and accurately detect high-quality spoofing attacks.
Owner:XIANGYANG DAAN AUTOMOBILE TEST CENT

Security authentication method, device and system

PendingCN122339705AInternet privacyEngineering
The application discloses a security authentication method, device and system, relates to the technical field of security management, and realizes comparison in the time sequence level by collecting synchronization authentication information of a main device and an auxiliary device, comparing collected timestamp information, so that even if an attacker obtains historical authentication data of a user, the timestamp of the historical data cannot satisfy a moment synchronization condition, and a replay attack path is blocked. When identity authentication and time sequence authentication are simultaneously satisfied, an authentication request is passed, so that the authentication request is ensured to come from a legal user and be initiated at a real physical time, and the credibility of an authentication result is improved.
Owner:SHENZHEN JIARUNXIN COMM TECH CO LTD

A bluetooth identity-oriented end-to-end secure communication method and system

The application discloses a kind of end-to-end security communication methods and systems for bluetooth identity identification, method includes the following steps: S1, initialization stage, using LE Secure Connections protocol establishes trusted key negotiation channel, and core key is derived;S2, daily identification stage, through dynamic resolvable private address RPA and encryption verification, prevent replay attack and relay attack;S3, storage stage, utilize hardware encryption engine and partition protection, ensure the physical security of key.The application uses the above-mentioned end-to-end security communication method and system for bluetooth identity identification, realizes end-to-end security coverage, from the initial pairing of mobile phone and equipment, to the dynamic verification of daily communication, to the hardware level protection of core key, forms whole-link closed-loop security system, effectively resists various malicious attacks, adapts high-risk scene such as finance, security, improves the security and reliability of bluetooth identity identification.
Owner:GUIZHOU HUOYANSHAN ELECTRICAL CORP

Communication method, terminal, network element, system and medium

The present disclosure relates to a communication method, a terminal, a network element, a system and a medium. The method performed by a terminal comprises: sending a first message, the first message being used for requesting to establish a non-access stratum (NAS) connection with a first network element; and creating or activating a first NAS security context for the first network element in a case that a security mode command (SMC) procedure is successfully performed, wherein the SMC procedure is triggered by the first message received by the first network element, the first NAS security context corresponds to a second NAS security context, and the second NAS security context is created or activated for the terminal by the first network element in the case that the SMC procedure is successfully performed. This can establish the NAS connection between the terminal and the first network element, and guarantee the integrity and confidentiality of the NAS message between the terminal and the first network element, and can prevent message replay attacks, etc.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Device, method and system for communication between devices in the absence of time synchronization

PendingUS20260189372A1Secure communicationClock drift
A method, system, and device for secure communication in environments without synchronized clocks. Using a clock-skew server, devices embed clock-skew certificates in MIKEY-SAKKE messages to compute and verify message generation times. These certificates facilitate secure message exchange, including peer-to-peer scenarios and applications requiring intermediary servers, by addressing clock drift without relying on external time references. Embodiments support mission-critical communication while mitigating replay attacks and resource inefficiencies inherent in traditional synchronization-dependent methods.
Owner:MOTOROLA SOLUTIONS INC

Network card firmware security access method based on dynamic instruction mapping and transactional buffering

This invention discloses a secure access method for network interface card (NIC) firmware based on dynamic instruction mapping and transactional buffering. During session initialization, the driver and application construct an instruction opcode mapping table and data structure offset rules valid only for the current session based on a negotiated random seed, achieving dynamic obfuscation of communication protocol features. When processing write requests, the driver temporarily stores the data, reads the current hardware snapshot, performs semantic-level virtual assembly and logical conflict prediction, and intercepts dangerous operations with valid signatures but mutually exclusive configuration logic. Only after pre-verification passes and a commit instruction is received does the driver calculate the differential bitstream between the shadow buffer and the hardware data, lock the bus, and perform atomic incremental synchronization. This invention effectively resists reverse engineering and replay attacks through three mechanisms: dynamic protocol transformation, logical conflict immunity, and differential atomic commit, while also preventing firmware corruption caused by configuration errors or abnormal interruptions.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Systems and methods for detecting replay attacks to an authentication system

A REE can approve or deny authentication based on a sensor output signal and a secure element (SE) operatively coupled to the REE can detect a replay attack. A feature extractor produces a feature vector from the sensor output signal. The feature vector can be used to authenticate a user. Detecting the replay attack can include storing previous feature vectors, sending a security breached signal to the REE in response to determining that the feature vector equals one of the previous feature vectors, and storing the feature vector as one of the previous feature vectors. The REE can deny authentication in response to receiving the security breached signal.
Owner:NXP BV

An edge AI model-based SD-WAN zero-contact deployment automation system

This invention discloses an automated SD-WAN zero-contact deployment system based on an edge AI model, belonging to the field of information networks. To address the problems in existing technologies, such as single-mode system authentication, susceptibility to forgery and replay attacks, insufficient AI decision reliability, lack of a safety net, coarse configuration verification, coarse rollback granularity, and susceptibility to model training contamination, lack of gradient anomaly detection, this invention effectively resists device forgery and replay attacks by using multimodal fusion verification of hardware fingerprints, visual recognition, and digital certificates, combined with timestamps, random number anti-replay, and certificate chain verification. Furthermore, it introduces a comprehensive confidence assessment; when the confidence level falls below a threshold, it automatically switches to a safety net rule generation mode, ensuring that devices can still obtain the minimum operational configuration in unknown scenarios and preventing network paralysis due to AI misjudgment.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

A method, device, equipment and medium for API request anti-replay attack

This application provides a method, apparatus, device, and medium for preventing API request replay attacks. The method includes: when it is determined that all interface request parameters contained in the API request are valid, determining whether a timestamp parameter in the interface request parameters has timed out; if the timestamp parameter has not timed out, generating server signature information using the interface request parameters and a preset signature rule; when the terminal signature information is the same as the server signature information, and it is determined that the salt value does not exist in the Redis distributed lock, determining that the API request is successful, and returning the request data corresponding to the API request to the terminal based on the API request. Through this method and apparatus, the imitation and replay of interface requests are effectively prevented, improving the security of interface requests in software systems.
Owner:RICHFIT INFORMATION TECH +1

A layered decoupled deterministic idempotent identity generation method and system

PendingCN122268567AEliminate dependenciesEliminate long-term bidirectional mapping indexKey distribution for secure communicationEncryption apparatus with shift registers/memoriesPaymentDeterministic algorithm
The application discloses a layered decoupling deterministic idempotent identification generation method and system. The method physically separates the session access stage and the service identification generation stage: the session access stage generates a session access certificate based on non-service attributes to prevent replay attacks; the service identification generation stage only constructs a service unique key based on service parameters and generates an idempotent handle through a deterministic algorithm; a minute boundary double window atomic query and TTL guarantee threshold checking mechanism are adopted to provide a clock drift tolerance of ±30 seconds; and offline verification capability is realized through reverse verification of the server. The application eliminates the long-term bidirectional mapping index of the service key to the identification, and the storage overhead can be reduced by more than 70%, the generation delay can be optimized to less than 1ms, and 100,000 + high-concurrency scenarios per second are supported; 100% cross-node consistency, zero-downtime configuration hot update, financial-grade security salt value rotation and cross-system offline verification capability are provided, and the application can be widely applied to distributed payment, e-commerce transaction and other scenarios.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Method for secure communication between programmable logic controllers, computing device and storage medium

The application relates to the technical field of industrial Ethernet communication, and discloses a safe communication method between programmable logic controllers, a computing device and a storage medium, wherein the method inserts a safe extension header of a fixed protocol identifier after an RTC header of a standard PROFINET data frame, realizes the transparent transmission of a safe field without destroying an original frame format and without modifying old equipment. A session key between devices is dynamically derived from a master key, a clock value synchronized based on a built-in precise clock transmission protocol of the PROFINET and a device hardware ID, double verification is conducted in combination with an encrypted time stamp and a rolling serial number, a replay attack is effectively resisted, and a misjudgment rate caused by network delay is significantly reduced. The scheme realizes seamless compatibility with an existing PROFINET network, dynamically resists a replay attack and a captured replay attack, and provides a solution with high availability and high security for an industrial real-time network.
Owner:SHENZHEN HUICHEN AUTOMATION TECH CO LTD

Method for replay attack-oriented multi-agent system differential privacy consistency control

The application belongs to the technical field of distributed control of multi-agent systems, and discloses a multi-agent system differential privacy consensus control method for replay attacks. The method effectively overcomes the shortcomings of existing methods in privacy protection and can provide stronger privacy protection capability. The core idea is that agents do not transmit real data but transmit perturbed data after adding privacy protection noise, which makes it impossible for malicious attackers to obtain real data, thereby achieving the effect of privacy protection. In addition, to resist replay attacks, the method of the application couples the perturbed data to be transmitted with a key before transmitting the perturbed data, so as to achieve the purpose of replay attack detection. In addition, through the design of a time-varying step length based on a stochastic approximation method, the method of the application realizes the privacy protection effect and the mean square asymptotic consistency while ensuring that the noise variance is allowed to increase.
Owner:SHANDONG UNIV OF SCI & TECH

A flexible paging method and system based on dynamic security roots

PendingCN122421018ATimestampEngineering
本发明公开了一种基于动态安全根基的灵活寻呼方法及系统。针对现有寻呼机制信令开销大、缺乏群组唤醒、易受攻击等问题,本发明扩展了基础寻呼专利,网络侧确定广播时序(包括SFN / Slot、GNSS时间戳等),利用密码学函数生成寻呼导频:P_paging=PRF(K_sec,(广播时序) || ID),ID为单终端或群组标识。终端在相同时刻生成导频副本并匹配滤波判定寻呼。本发明还包括:群组 / 子组标识派生、多种标识适配、基于广播时序的功率预测、隐式资源自适应的可配置窗口、引入计数器抗重放攻击、基于P‑PSSM的逻辑寻呼周期(解耦物理帧号)、以及跨PLMN共享密钥寻呼。本发明降低了信令开销与功耗,支持海量物联网、卫星通信及漫游场景,增强了安全性与灵活性。
Owner:SHANGHAI HUAPAITE TECHNOLOGY CO LTD

Storage device including protected area and data write method thereof

A method of writing data in a replay protected memory block (RPMB) area of a storage device in response to a request of a host device includes receiving a write request, including a message authentication code, data, and a bitmap index, from the host device and verifying the write request based on the message authentication code and the bitmap index. The verifying the write request may include calculating a message authentication code based on data and a bitmap index received from the host device, comparing a message authentication code, calculated in the storage device, with the message authentication code of the write request, and comparing the bitmap index of the write request with bitmap indexes, stored in the storage device, to check whether a replay attack has been made.
Owner:SAMSUNG ELECTRONICS CO LTD

Short-range radio frequency identification encryption security communication method

This invention relates to a short-range RFID encrypted secure communication method, specifically in the field of short-range RFID. This solution constructs an adaptive, highly concealed, and intrinsically secure short-range RFID communication mechanism in complex electromagnetic environments. By extracting dynamic interference fingerprints of the environment in real time, it drives the dynamic and unique generation of encryption parameters and session keys, achieving semantic security and resistance to replay attacks. Simultaneously, based on interference characteristics, it intelligently matches forward error correction coding and physical layer covert transmission modes, ensuring communication reliability and low interception probability under adverse channel conditions. Finally, based on consistency verification of instantaneous characteristics of the shared physical environment, it provides a secure closed-loop confirmation for each session, preventing tampering and resisting man-in-the-middle attacks. This comprehensively and synergistically improves the system's environmental adaptability, transmission robustness, and communication confidentiality.
Owner:CHENGDU UNIV

Systems and methods for verifiable physical emblem-anchored domain-basepoint service discovery and policy-gated issuance of beidid and time-denominated assets

A terminal device captures an image of a verifiable physical emblem bearing an optically decodable texture code encoding an EmblemIndex and emblem identifier (EID). The terminal decodes the EmblemIndex, computes an authenticity score from anti-counterfeit optical features, resolves the EID to a domain basepoint identifier, retrieves a signed endpoint record (SER), and verifies the SER signature and time window. The terminal generates a nonce and verifies a wallet signature over a canonical message satisfying SER nonce rules to prevent replay. Policy fragments are merged across namespace scopes using constrained overrides to obtain an effective policy configuration. When gating conditions are satisfied, a policy-gated operation issues a BEIDID and / or time-denominated digital assets (TimeCurrency) or releases an execution permit for a computation function. A tamper-evident receipt with a hash anchor is produced for audit and rollback and may be reconciled by a settlement gateway.
Owner:BEI FURONG

Electronic identity link mapping authentication system and method for trusted identity resolution

This application relates to the field of cyberspace security, and discloses an electronic identity link mapping authentication system and method for trusted identifier resolution. The system includes an identity link mapping authentication center, integrating modules for message reception and parsing, user identity verification, link integrity verification, and path matching. The method includes: parsing the data packet to be authenticated and extracting the link tracing list; verifying the legality of the user's logical identity; traversing and verifying the validity of node signatures in the link feature entries and the rationality of the timing logic of adjacent nodes; comparing the consistency of the link feature sequence to be detected with a preset standard legal link feature sequence to generate a path compliance signal. The system can also dynamically adjust the reputation score based on path deviation to execute hierarchical authorization, or identify VPN bypass behavior through cross-verification of logical addresses and physical paths. By constructing physical link evidence, this invention achieves the binding of user identity and physical location, effectively defending against replay attacks and unauthorized remote access.
Owner:TSINGHUA UNIVERSITY

Open application interface gateway management system and method

The application relates to the technical field of interface gateway management and control, and discloses an open application program interface (API) gateway management and control system and method. The method comprises the following steps: in response to an API calling request received, identity information and request context parameters of a caller are extracted, dynamic authentication is performed on the calling request, and an authentication result is obtained; corresponding flow limiting rules are acquired, dynamic mixed mode flow control is performed on the calling request, and a flow control result is obtained; the calling request is forwarded to a corresponding backend service, running state data of the backend service is monitored in real time during the forwarding process, based on the running state data and preset business semantic rules, a fuse analysis is performed, and a fuse control signal is obtained; corresponding request processing actions are performed according to the fuse control signal, and full-link observable data of calling chain tracking data and network performance data are collected in real time, so that interface calling is managed and controlled; and the application can effectively intercept replay attacks, abnormal login in different places and the like, and improve gateway throughput.
Owner:SIMBA NETWORK TECH (NANJING) CO LTD

A method for authenticating a UAV cluster based on zero-knowledge proof

This invention proposes a drone swarm authentication method based on zero-knowledge proof, belonging to the field of drone swarm secure communication technology. Its technical solution includes the following steps: S1, system initialization; S2, secondary drone registration before takeoff; S3, bidirectional authentication and key negotiation between secondary drones during flight; S4, dynamic networking of secondary drones. This invention combines zero-knowledge proof and elliptic curve cryptography to achieve drone swarm identity authentication. Through a two-stage design of pre-registration and online authentication, it significantly reduces the computational and communication overhead of in-flight authentication while ensuring drone identity privacy and communication security. It effectively resists typical threats such as man-in-the-middle attacks, impersonation attacks, replay attacks, and message tampering, avoiding single points of failure and communication bottlenecks caused by the central node.
Owner:NANTONG UNIV