Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

331 results about "Replay attack" patented technology

A replay attack (also known as playback attack) is a form of network attack in which a valid data transmission is maliciously or fraudulently repeated or delayed. This is carried out either by the originator or by an adversary who intercepts the data and re-transmits it, possibly as part of a masquerade attack by IP packet substitution. This is one of the lower tier versions of a "Man-in-the-middle attack".

High-security method for negotiating temporary session key based on national secret algorithm

The invention relates to the technical field of commercial password detection methods, and discloses a high-security method for negotiating a temporary session key based on a national secret algorithm, and the commercial password detection method comprises the following steps: initialization and identity authentication: two communication parties generate an SM2 public and private key pair, and the identity is verified through a digital certificate and an SM2 signature; temporary key negotiation: generating a shared key point based on an SM2 key exchange protocol; session key derivation: generating a temporary session key by using an SM3 hash algorithm; key confirmation and encrypted communication: verifying the key through an SM4 algorithm and encrypting communication data; according to the high-security method for negotiating the temporary session key based on the national secret algorithm, efficient key negotiation of both communication parties in an unsecure channel is realized through an SM2 key exchange protocol, an SM3 hash algorithm and an SM4 symmetric encryption algorithm. The method combines digital certificate authentication, dynamic random numbers and timestamps, has forward security, replay attack resistance and man-in-the-middle attack resistance, and is suitable for high-security scenes such as finance and government affairs.
Owner:SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD

Interface authentication method, system and equipment based on national cryptographic algorithm and medium

The invention discloses an interface authentication method, system and device based on a national cryptographic algorithm and a medium, belongs to the technical field of computer security, and aims to solve the technical problem of how to realize identity authentication, data encryption, integrity verification and replay attack protection of interface interaction and meet the security requirement of a key information system. According to the technical scheme, the method comprises the following steps: system initialization: a server and a client respectively generate SM2 key pairs, the client and the server exchange public keys through a secure channel, and a mapping relation between the public key of the opposite side and an identity label is stored; session key negotiation: exchanging a temporary public key based on an SM2-ECDH algorithm, calculating a shared secret value, and deriving an SM4 session key through a KDF; the client side carries out SM3 hash and SM2 signature on request parameters, and the server side verifies the signature and verifies a timestamp and a random number to resist replay attacks; and session key updating: triggering key updating according to a preset condition, and encrypting the new key negotiation message by using the original session key.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Privacy protection for a-iot device identifiers

An apparatus and system for privacy protection for Ambient Internet-of-Things (A-IoT) devices are disclosed. A-IoT devices transmit obfuscated identifiers (OIDs) instead of actual identifiers, which are de-obfuscated by the network to retrieve the original identifiers. The device identifiers are obfuscated using shared secret parameters and periodically updated configurations. Hash-based lightweight privacy mechanisms, temporary identifiers (TempIDs), and pseudonym generation may be used to ensure secure communication and prevent replay attacks.
Owner:INTEL CORP

Identity authentication and control method and device based on block chain

The invention discloses an identity authentication and control method and device based on a block chain. According to the method, biological features are collected through edge nodes to generate feature vectors, a combined hash value is generated in combination with a device scene label and a service role label, the combined hash value is uploaded to a cloud server after encrypted signature, and the combined hash value is written into a block chain through an intelligent contract; and during user authentication, the edge node calculates a real-time risk level, dynamically selects an authentication mode, calls an intelligent contract for verification after verification of the cloud server, and adjusts the risk level according to a verification result to implement management and control. According to the method, the edge cloud collaborative architecture is adopted, and the dynamic multi-factor authentication mechanism and the block chain consensus technology are combined, so that high-security privacy protection authentication is realized, the security requirements of different service scenes can be met, data leakage and replay attacks are effectively prevented, and the authentication efficiency and reliability are improved.
Owner:BEIJING BOSHI YUANXIN TECH CO LTD

Cloud edge collaborative multi-factor identity authentication method and system for ubiquitous network

The invention relates to the technical field of security authentication and ubiquitous networks, and discloses a ubiquitous-network-oriented cloud-side collaborative multi-factor identity authentication method and system, and the method comprises the steps: issuing an identity certificate based on an elliptic curve and a PUF challenge-response library of a parameter initialization edge node through a cloud, and achieving the cloud-side bidirectional authentication; when the terminal is accessed, multi-factor authentication combining PUF challenge and a dynamic threshold value is adopted, so that the capability of resisting counterfeiting and replay attacks is improved; after the authentication is passed, the edge node generates a group public key locally and constructs a binary tree group key structure with a preset depth, and post-quantum safe and efficient group signature management is supported; when a newly added terminal joins, generating a secret key based on an elliptic curve algorithm and distributing a group signature private key share to realize lightweight member management; the integrity, confidentiality and traceability are realized while the transmission efficiency is guaranteed, and safe communication and dynamic revocation in an edge resource limited environment are effectively supported.
Owner:CHANGCHUN UNIV OF SCI & TECH

Data security transmission method based on ML-KEM algorithm and PUF

The invention discloses a data security transmission method based on an ML-KEM algorithm and a PUF, and the method comprises the steps: in a registration stage, mobile equipment generates an anti-quantum key through employing a PUF technology, and a CA issues an anti-quantum digital certificate based on a Falcon algorithm and a cryptographic accumulator; in an identity authentication stage, a mobile device and an edge gateway complete bidirectional identity authentication by exchanging identity labels, anti-quantum certificates and authentication key parameters in combination with a Falcon algorithm and PUF challenge-response, and negotiate to generate a shared key by using an ML-KEM algorithm, thereby effectively defending threats such as man-in-the-middle attack, replay attack and identity counterfeiting; in a data transmission stage, two communication parties realize data encryption transmission by adopting a symmetric encryption algorithm, and data integrity and source credibility are guaranteed in combination with a Falcon digital signature; the whole scheme has the advantages of quantum security resistance, efficient authentication, dynamic key updating, lightweight encryption and the like.
Owner:SICHUAN UNIV +1

Security inter-core communication method based on derived key negotiation

The invention discloses a safety inter-core communication method based on derived key negotiation. The safety defect of a traditional inter-core communication scheme is overcome through a dynamic key negotiation mechanism. Based on a preset derived base key and a random salt value, a unique temporary session key is negotiated before each communication, and forward security is ensured: even if the derived base key is leaked, historical encrypted data still cannot be decoded; a bidirectional salt value check code verification mechanism is adopted, chip identity legality authentication is achieved in the negotiation stage, and forgery or tampering attacks are blocked; during communication, a data ciphertext check code is generated through a check key, and data integrity and source authenticity are guaranteed; it is ensured that the session key is unpredictable each time through the random salt value, and replay attacks are effectively resisted in combination with a timeliness verification mechanism. In addition, key re-negotiation is triggered according to data sensitivity, a key exposure time window is dynamically reduced, the risk of long-term key leakage is further reduced, and safety and resource efficiency are both considered.
Owner:SHENZHEN ROADROVER TECH

Network range-based iframe bidirectional encryption communication method and system

The invention discloses an iframe two-way encryption communication method and system based on a network target range, and belongs to the technical field of network security. In the aspect of data communication of iframes of a front-end platform and a third-party platform, security is enhanced, a digital certificate is generated through an ECDH key pair, and a foundation is laid for identity verification; then TCP handshake is simulated to establish a reliable channel, and two-way identity authentication resisting replay attack is achieved through two-way certificate verification and random number exchange; then negotiating a shared key by using ECDH, deriving a dynamic session key through an HKDF algorithm, and ensuring forward confidentiality; and finally, real-time data encryption and integrity verification are carried out by adopting AES-GCM, and the anti-leakage capability is continuously improved through a timing key rotation mechanism. The whole process fuses the characteristics of quantum computing resistance, low resource consumption, efficient transmission and the like, an end-to-end secure communication normal form is provided for Web application, and cross-session key confusion is prevented.
Owner:SAINING WANGAN

Network security verification method and system for distributed communication

The invention relates to the technical field of communication network security, and particularly discloses a distributed communication network security verification method and system, which comprises a two-factor identity authentication module, a dynamic key arrangement and encryption module and a cross-node integrity verification module, and the dynamic key arrangement is respectively connected with the two-factor identity authentication module, the encryption module and the cross-node integrity verification module. Through combination of biological feature anchoring and secure multi-party calculation, on the premise of protecting privacy of original biological data, deep binding of biological features and public keys is realized, and biological uniqueness is given to identity authentication; and dynamic authentication interaction is fused with a timestamp, a biological characteristic entropy value and zero knowledge proof, replay attacks are resisted, 'human-equipment-identity 'consistency is accurately verified, a public key fragment is updated after authentication is passed, an identity trust chain is continuously reinforced, and it is ensured that node identities are true and credible from the source.
Owner:SUZHOU COLLEGE OF INFORMATION TECH

Key sharing and detection scheme based on intelligent electric meter

The invention discloses a key sharing and security detection scheme based on an intelligent electric meter, and aims to solve the problems that an untrusted electric meter in an intelligent power grid is difficult to identify effectively, the detection scale is uncontrollable and the communication security is insufficient. According to the scheme, the elliptic curve cryptography, the threshold secret sharing mechanism and the physical unclonable function are combined, and hardware-level binding of the unique identity of the equipment and the secret key is achieved in the registration stage. Through a threshold password mechanism, a plurality of intelligent electric meters cooperatively participate in key reconstruction and encryption communication, and the intelligent electric meters can still work normally when part of the electric meters fail or are broken through. The center node can actively identify a fault or a malicious ammeter and dynamically adjust a communication strategy according to the integrity and correctness of the feedback information. Meanwhile, the scheme supports dynamic identity updating and integrity verification, and effectively resists modeling attacks, Sybil attacks, replay attacks and DoS / DDoS attacks. According to the invention, secure identity authentication, reliable key distribution and efficient anomaly detection are realized, and the security of smart grid terminal communication is improved.
Owner:CHUXIONG POWER SUPPLY BUREAU OF YUNNAN POWER GRID CO LTD

User Authentication, Spoofing and Replay Attack Prevention, Liveness Detection, and User-and-Document Verification using a Live Video Stream with Spatial Challenges

User authentication, spoofing and replay attack prevention, liveness detection, and user-and-document verification using a live video stream with spatial challenges. A camera of an electronic device captures and transmit a live selfie user-facing video, as part of a user registration process. The user is instructed to spatially move his body or face, such that his face would appear within a first particular on-screen shape; and to also, concurrently or simultaneously, spatially hold in his hand or move a particular an identification document such that it would appear within a second on-screen shape. Optionally, the on-screen shape moves on the screen, and the user is required to spatially move the relevant item to keep it within the boundaries of the moving on-screen shape. The system then analyzes the video via computerized vision, to determine whether the user complied with the spatial manipulation challenges.
Owner:IRONVEST INC

Secure communications using pre-shared keys and live membership

The described techniques address issues to achieve key agreement without the need to exchange separate key agreement messages and, consequently, meets the stringent starting time requirements for real-time control systems. This is achieved using a group-wide key counter, with each node storing the latest value of this counter that was observed via the last received secured message. This counter value increases monotonically, and nodes maintain synchronization by transmitting this counter value (or a representation of the counter value) in each secured message. The use of key counters may be extended to guard against weak replay attacks via the implementation of a live membership tracking solution, which defines one or more membership groups. Each node within a membership group may request, or “challenge” other nodes with the same membership group at any time to verify their online status, and this online status may be maintained over time.
Owner:INFINEON TECHNOLOGIES AG

Vehicle-mounted controller encryption communication method

The invention discloses an encryption communication method for a vehicle-mounted controller, which relates to the technical field of encryption communication, and comprises the following steps: remarkably improving the synchronization efficiency, dynamically screening relay nodes by weight, greatly reducing the key distribution flow, avoiding broadcast storm under large-scale formation, and ensuring the real-time performance of vehicle cooperative control. Attack resistance is enhanced, a chaotic timestamp is fused with multi-source noise and clock disturbance, a non-replicable dynamic identifier is generated, and replay attacks and signal tampering are effectively defended; through triple weight adjustment of hop count attenuation, signal-to-noise compensation and time delay deduction, vehicle position change and link fluctuation are automatically adapted, and the synchronization failure risk in scenes such as a tunnel is eliminated; a safety degradation mechanism is introduced, control instruction transmission is prohibited when abnormity occurs, basic communication is maintained in combination with a pre-stored key, and vehicle misoperation caused by key synchronization failure is prevented.
Owner:CHINA VAGON AUTOMOTIVES HLDG CO LTD

System and method to detect and countermeasure RPL attacks in IoT network

A system and a method to detect an attack on an IoT network is disclosed. The IoT network includes interconnection of multiple IoT devices. The method includes receiving, by a network connection device, multiple ICMPv6 network packets from IoT devices and outputting multiple output packets; and matching, by a routing device, a network traffic pattern to attack signatures structured as a taxonomy according to which part of a packet is misused. The taxonomy includes a branch to a data plane attack and a control plane attack, respectively. When an IPv6 RPL packet is detected, the method includes checking for generating, modifying, and replaying attacks by an attacker. When a non-RPL packet is detected, the method includes checking for dropping and leaking packet attacks by the attacker. When the attack is detected, the method includes invoking a solution to the attack. The solution includes mitigation of the attack by the attacker.
Owner:KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS

Sound authenticity identification method and system based on multi-modal feature deep interactive fusion

The invention discloses a sound authenticity identification method based on multi-modal feature deep interactive fusion. According to the method, a double-flow architecture is adopted, and a pre-trained BEATs model and a CNN14 network are respectively utilized to extract Transform sequence features and convolution time-frequency embedding features of an audio; an adaptive MobileFormer fusion device is innovatively proposed, an original MobileFormer structure used in the image field is transformed into a bidirectional cross-modal interaction module suitable for one-dimensional time sequence audio features, dynamic complementary modeling of local details and global semantic features is achieved through a cross attention mechanism, and dynamic nonlinearity is introduced to activate and enhance the expression ability; and the fused enhanced features are input into a hierarchical graph attention network ASSIST, and high-order semantic modeling and authenticity classification are completed by combining spectrogram and time sequence double-flow reasoning. Experimental results show that the performance of the method on an ASVspoof2021LA data set is superior to that of an existing baseline model. The method can effectively detect AI generation voice, replay attack and other forged voice, and is suitable for a voice authentication system.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Electronic bidding file encryption transmission system and method and storage medium

The invention discloses an electronic bidding file encryption transmission system and method and a storage medium, and the method comprises the steps: dividing an electronic bidding file of a transmitting end into a plurality of data blocks, and distributing a unique identifier for each data block; generating a permutation table and a round key sequence according to the session key and the data block identifier; multiple rounds of dynamic obfuscation operation are executed on the data block, each round of operation comprises bit operation based on a round key sequence and byte position rearrangement based on a replacement table, and an obfuscated data block is obtained; generating an authentication label for the confusion data block, binding the authentication label with the timestamp, the block identifier, the session identifier and the confusion data block, and sending the binding result to a receiving end; and the receiving end performs reverse decryption operation on the confused data block based on multiple rounds of dynamic confusion operation to obtain decrypted data, and verifies the decrypted data according to the authentication tag and the timestamp. The invention relates to the technical field of electronic information security, and solves the technical problem that in the prior art, an electronic bidding file is easily subjected to data tampering and replay attacks in the transmission process.
Owner:ANHUI TENDERING GRP INC

Sufficiently secure controller area network

As automotive security concerns are rising, the Controller Area Network (CAN)—the de facto standard of in-vehicle communication protocol—has come under scrutiny due to its lack of encryption and authentication. Several vulnerabilities, such as eavesdropping, spoofing, and replay attacks, have shown that the current implementation needs to be extended. Both academic and commercial solutions for a secure CAN have been proposed, but OEMs have not yet integrated them into their products. The main reasons for this lack of adoption are their heavy use of limited computational resources in the vehicle, increased latency that can lead to missed deadlines for safety-critical messages, as well as insufficient space available in a CAN frame to include a Message Authentication Code (MAC). By making a trade-off between security and performance, this disclosure overcomes the aforementioned problems of a secure CAN.
Owner:THE RGT UNIV OF MICHIGAN

Internet of Things equipment security authentication and data encryption transmission system and method

The invention relates to the technical field of Internet of Things equipment, particularly provides an Internet of Things equipment security authentication and data encryption transmission system and method, and solves the problems of limited equipment resources and difficult key management. The system comprises an equipment identity authentication component, a key management component and a lightweight encryption component. The method comprises the following steps: authenticating the legal identity of the Internet of Things equipment by adopting a lightweight symmetric key; the authority is dynamically adjusted according to factors such as equipment position, time and network state; the Internet of Things equipment generates and distributes a secret key after passing the access authority authentication; key exchange is carried out between the Internet of Things devices by adopting a key exchange protocol, and local key management is realized at an edge node in combination with edge calculation; and transmitting the data containing the key and the key exchange protocol to the target equipment, encrypting the transmitted data by adopting lightweight encryption and a Hash algorithm during transmission, and preventing a replay attack by using a timestamp and a random number. According to the invention, comprehensive safety protection of the Internet of Things equipment is realized.
Owner:SHENZHEN AISHANSI TECHNOLOGY CO LTD

USB key identity authentication method, system and device based on digital signature trusted chain and medium

The invention discloses a USB key identity authentication method, system and device based on a digital signature trusted chain and a medium, and belongs to the technical field of information security, and the method comprises the following steps: after a receiving terminal accesses a USB key, reading a digital certificate, collecting a device identifier, a network parameter and geographical location information, generating first environment abstract data through abstract processing, and signing; and the authentication server stores the abstract data after passing the signature verification. In the authentication request stage, the server generates random challenge data; the receiving terminal collects the current environment information to generate second environment abstract data, and the second environment abstract data is signed and sent again after being combined with the challenge data. And the server extracts the second abstract data after signature verification, performs similarity comparison with the first abstract data, and confirms that the identity authentication is valid when conditions are met. According to the method, the binding of the environment characteristics and the identity is realized, the protection capability of the U-type shield authentication system on counterfeiting, cloning and replay attacks is remarkably improved, and the credibility and the stability of an authentication result are enhanced.
Owner:YUNNAN POWER GRID CO LTD

QR code verification engine

A QR Code Verification Engine provides a multi-layered security framework for generating, validating, and authenticating QR codes while preventing tampering, fraud, and unauthorized access. The system embeds a hidden security layer within the QR code using steganographic encoding or invisible watermarking techniques, ensuring detection of any modifications. The hidden layer is encrypted using asymmetric cryptography, allowing only an authorized verification system to extract and validate it. An AI-powered tamper detection module analyzes QR codes for anomalies, while cryptographic hash verification ensures integrity. The system employs biometric authentication, push notification approvals, and contextual security measures to enhance user verification. Dynamic QR codes with expiration rules prevent replay attacks. Secure offline verification allows authentication without network connectivity. The system integrates with financial platforms, web security tools, and real-time fraud detection mechanisms, ensuring a highly secure and scalable QR code validation framework for transactions, identity verification, and access control applications.
Owner:BANK OF AMERICA CORP

Multi-factor authentication with device and carrier validation

The invention provides systems, methods, and computer-readable media for multi-factor authentication (MFA) using device and carrier validation. A user device generates an attested blob containing cryptographic keys and a Universal Integrated Circuit Card (UICC)-originated International Mobile Subscriber Identity (IMSI), which is transmitted to a cloud-based MFA service. The service validates the attested blob, coordinates with an Original Equipment Manufacturer (OEM) service, and executes an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) process with the carrier network to establish mutual trust. Authentication data, including a validated phone number independent of the device's stored number, is securely stored in a cloud wallet. The invention enhances security by mitigating risks such as spoofing, replay attacks, and SIM swapping, providing a novel authentication framework compatible with modern networks.
Owner:SYNIVERSE TECHNOLOGIES LLC

Secure automatic speaker verification system

ActiveUS12354607B2Speech analysisDigital data authenticationSpeaker verificationEngineering
Traditional speaker verification systems are vulnerable to voice spoofing attacks, such as voice-replay attack, voice-cloning attack, and cloned-replay attack. To overcome these vulnerabilities, a secure automatic speaker verification system based on a novel sign modified acoustic local ternary pattern (sm-ALTP) features and asymmetric bagging-based classifier-ensemble with enhanced attack vector is presented. The proposed audio representation approach clusters the high and low frequency components in audio frames by normally distributing them against a convex function. Afterwards, the neighborhood statistics are applied to capture the user specific vocal tract information.
Owner:THE RGT UNIV OF MICHIGAN

Robot health consensus system and method based on ontology trust

The invention relates to the technical field of robots and network security, discloses a robot health consensus system and method based on ontology trust, and aims to solve the problems that an existing robot health declaration is easy in identity counterfeiting, one-sided in state evaluation, and easy in privacy leakage and replay attack in a certification process. The method comprises the following steps: generating an identity label strongly bound with robot hardware based on a physical unclonable function (PUF); fusing multi-source sensor data in a recursive updating mode to generate a state topology vector capable of reflecting a historical evolution trend; and obtaining a comprehensive health value in combination with the internal health value calculated by the vector and a network consensus factor. Through physical layer identity anchoring, dynamic and continuous state evaluation and an encryption certification mechanism, the authenticity and fraud resistance of the health declaration of the robot are remarkably improved, comprehensive evaluation of the health state of the robot is achieved, state privacy of the robot is effectively protected in interaction, and replay attacks are prevented.
Owner:CHENGDU PATZHILIHU DIGITAL TECHNOLOGY CO LTD

Switching type safety control method and device for wind turbine generator set under replay attack

The invention provides a switching type safety control method and device for a wind turbine generator set under replay attack. The method comprises the steps of establishing a wind turbine generator dynamical model based on a wind turbine generator operation mechanism and a physical structure; according to the replay attack characteristics, establishing a replay attack model aiming at the measured value of the wind turbine generator rotor speed sensor; setting a lower limit of a detection threshold value, designing a dynamic detector with an updated threshold value, and judging whether a replay attack exists or not; based on the Lyapunov stability theory, a rotor rotating speed state estimator and a switching type safety controller are designed, and normal operation and expected rotor rotating speed output performance of the wind turbine generator under the replay attack are achieved. According to the method, an effective solution is provided for the attack and defense problem of the wind turbine generator set under the nonlinear characteristic, normal operation of the wind turbine generator set can be ensured, malicious influences of replay attacks in the wind turbine generator set are relieved, and the power output performance of the wind turbine generator set is improved.
Owner:ZHEJIANG UNIV

Multi-carrier wireless optical communication physical layer security authentication system and method

ActiveCN121887314ARealize fine identificationSolve impersonation attacksKey distribution for secure communicationLine-of-sight transmissionComputer hardwarePhotodetector
The invention relates to the technical field of wireless optical communication, and discloses a multi-carrier wireless optical communication physical layer security authentication system and method.The receiving end of the system comprises a multi-receiver joint judgment module, a data gating module, an information sink and at least three receivers; each receiver comprises an optical detector, a cyclic prefix removal module, an FFT (Fast Fourier Transform) module, a receiving end key update storage and watermark generation module, a channel estimation and watermark extraction module, a subcarrier authentication module, a multi-carrier self-adaptive decision judgment module and a multi-carrier integration module; oFDM frequency domain channel response is used as an implicit fingerprint, a self-adaptive switching decision strategy is executed according to the average signal-to-noise ratio, fine recognition of legal device position features is achieved without ranging hardware, IM / DD can be adapted, the problem of imitation attack and replay attack authentication of attackers is effectively solved from the physical mechanism, and the method has the advantages of being high in practicability and high in practicability. And the accuracy and robustness of physical layer authentication are obviously improved.
Owner:SUZHOU UNIV

Data secure transmission method and system, computer and storage medium

The invention provides a data security transmission method and system, a computer and a storage medium. The method comprises the following steps: generating a dynamic key seed sequence according to network environment parameters of transmission equipment; establishing a transformation matrix for data encryption based on the dynamic key seed sequence to transform the fragmentation unit data; and the receiving end performs integrity and time-space continuity verification based on the verification hash. A key seed sequence is dynamically generated by collecting network environment parameters in real time to achieve one-time pad encryption, and replay attacks are blocked; performing exclusive-or transformation on the fragmented data by using the transformation matrix, and enhancing the randomness of the ciphertext to resist traffic analysis; the time-space associated verification hash is constructed to realize the integrity and time sequence continuity dual verification of the multipath transmission data, and the transmission reliability in the industrial internet high dynamic environment is improved.
Owner:CHINA UNICOM (JIANGXI) IND INTERNET CO LTD

Method for realizing firmware security access on network card driving layer

The invention discloses a method for realizing secure access of firmware on a network card driving layer. According to the method, an application program is authenticated by adopting a challenge-response mechanism based on a symmetric key; after the authentication succeeds, the driving program obtains and records a process identifier of the application, and a single effective authorization session bound with the specific process is established. Secondly, when a read-write request is processed, the driver compulsively verifies the consistency of the requested PID and the authorized PID; for a write-in request, a digital signature verification based on asymmetric encryption is added to ensure the authenticity and integrity of a data source. And finally, after each hardware operation is successfully completed, the drive program immediately makes the current authorized session invalid. Through a multi-level security mechanism, illegal access, replay attack and session hijacking are effectively resisted, and secure, controllable and refined access to internal data of hardware is realized.
Owner:SUZHOU HONGCUNXINJIE TECH CO LTD

Cross-platform implementation method for national secret file encryption system compatible with exFAT

The invention discloses a cross-platform implementation method for a national secret encryption file system compatible with exFAT, and belongs to the field of file system encryption and cross-platform application. In order to solve the encryption problem of an exFAT file system, a system architecture comprising metadata compatibility, national secret encryption and a cross-platform adaptation layer is constructed. The metadata compatible module reuses an exFAT directory entry reserved field, dynamically identifies an encryption identification bit and generates a file fingerprint; the national cryptographic encryption module performs key management and data encryption based on a national cryptographic algorithm, resists a replay attack and adopts a key destruction mechanism; and the cross-platform adaptation layer realizes encryption function integration in different operating systems (Windows, Linux and macOS). Cross-platform encrypted storage and access of the exFAT file system are realized through key algorithm processes such as generation of a temporary session key, calculation of metadata fingerprints, encryption and decryption of data streams and the like. According to the method, the encryption compliance, the cross-platform convenience, the system compatibility and the data security are improved, and the method is stably operated under multiple operating systems and different exFAT versions.
Owner:GUANGXI POWER GRID CORP

Patient privacy data protection method used in operating room

The invention relates to the technical field of medical information security, and discloses a patient privacy data protection method used in an operating room. The method comprises the following steps: uniformly coding patient privacy into a binary system, zero-filling the binary system into a square matrix, and filling according to rows; a disturbance seed is generated through combination of operating room environment temperature and noise quantification, and chaotic mapping is driven to carry out two-dimensional replacement on a matrix; applying position-related mask XOR to the sub-blocks, and overturning odd columns or even rows according to global parameters; and then linearization is carried out according to rows and filling is eliminated, and a final ciphertext is output. Meanwhile, disturbance control parameters are constructed and bound, and then Hash check is calculated and structured packaging is carried out. Through global and local double-layer disturbance, field seed driving and reversible coding, the scheme enhances the resistance to statistical analysis, plaintext attack and replay attack on the premise of no fixed key, and gives consideration to real-time performance, security and traceability.
Owner:BEIJING SHIJITAN HOSPITAL CAPITAL MEDICAL UNIVERSITY

Vehicle-mounted ECU identity authentication method and system based on multi-factor random seed and multiple security levels

The invention relates to the technical field of electronic security, and discloses a vehicle-mounted ECU identity authentication method and system based on a multi-factor random seed and multiple security levels, and the method comprises the steps: synthesizing a random seed at an ECU end through multiple factors such as CRC32, a random number, a timestamp and a global seed, and returning the random seed to a client; the client calculates a key and returns the key by using a corresponding key algorithm according to the target security level; the ECU calculates an expected key through the same algorithm and compares the expected key with a client key, if the expected key is consistent with the client key, the session of the level is opened and the delay timer is closed, if the session fails, the number of failure times of the level is accumulated, and if a threshold value is reached, the delay timer of the corresponding security level is started and the access of the level is locked until the timing is finished; and meanwhile, the authentication result, the security level, the timestamp, the failure count and the seed state are written into a security log. According to the method, it is guaranteed that each time of seed is unpredictable and is strongly correlated with the historical state, a non-zero recalculation mechanism is matched, hidden dangers of fixed seeds, replay attacks and prediction attacks are thoroughly eliminated, and attacks can be protected, and events can be traced.
Owner:BEIJING NEW ENERGY VEHICLE TECH INNOVATION CENT CO LTD