Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

326 results about "Secure authentication" patented technology

Authentication in cybersecurity. Authentication is important because it enables organizations to keep their networks secure by permitting only authenticated users (or processes) to access its protected resources, which may include computer systems, networks, databases, websites and other network-based applications or services.

Server BMC dynamic security authentication and firmware protection method and system based on hardware root of trust

The invention discloses a server BMC dynamic security authentication and firmware protection method and system based on a hardware root of trust, relates to the technical field of server remote management security, and discloses the server BMC dynamic security authentication and firmware protection method and system based on the hardware root of trust, which realize dynamic authentication by generating a device fingerprint through a security chip. According to the method, a multi-layer protection mechanism is constructed in combination with fragment encryption, differential hash check and memory integrity verification, and meanwhile, the data credibility is enhanced by using a block chain storage key hash value, so that the problems of static authentication risk, insufficient firmware tampering detection and missing of a trust chain in a traditional scheme are effectively solved, and the security protection capability of a BMC system can be improved.
Owner:SHENZHEN HUAKUN INFORMATION TECH CO LTD +1

Intelligent warehouse login verification method and system based on dynamic living body detection

The invention relates to the technical field of information security, provides an intelligent warehouse login verification method and system based on dynamic living body detection, and is used for realizing accurate generation of an identity label vector, enhanced authentication of a dynamic password and automatic matching of warehouse authority while accurately performing living body detection. And the security and convenience of warehousing system login are comprehensively improved. The method comprises the following steps: collecting real-time interaction action data of a warehousing system login user, calling a preset living body detection algorithm to carry out dynamic biological characteristic analysis on the real-time interaction action data, and generating a living body verification confidence coefficient and a user identity identification vector; performing dynamic password enhanced authentication according to the living body verification confidence coefficient and a preset security authentication threshold value, and generating a dynamic access token containing multiple layers of encryption identifiers; and based on the user identity identification vector and the dynamic access token, executing storage permission automatic matching processing, and outputting a login verification result associated with the user permission level to the storage system according to the permission matching label.
Owner:SHANDONG LUNENG SOFTWARE TECH

Vehicle scheduling and cooperative control system and method for surface mine

The invention discloses a vehicle scheduling and cooperative control system and method in the technical field of surface mine construction vehicle scheduling, and the system comprises an equipment management layer which is used for obtaining surface mine environment and equipment state data and controlling equipment, and an edge layer which is used for carrying out the preprocessing and preliminary analysis of the data uploaded by the equipment management layer. The cloud end is used for constructing a digital twin environment of the surface mine, calculating a vehicle collaborative scheduling scheme and a vehicle optimal path of the surface mine by utilizing a multi-objective optimization and heuristic algorithm and a multi-agent reinforcement learning algorithm, and performing vehicle trajectory tracking control; the cloud end is used for forwarding a control instruction issued by the cloud end or the edge layer to the equipment management layer; and the security access control layer is used for performing dynamic authority security authentication and access control. According to the invention, dynamic path planning and multi-task cooperative scheduling in a surface mine scene can be realized.
Owner:JIANGSU XCMG STATE KEY LAB TECH CO LTD

IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

The invention provides an IKE (Internet Key Exchange) protocol security enhancement method based on PUF (Physical Unclonable Function) dynamic authentication and a post-quantum mixed key, which organically combines a PUF, a post-quantum cryptographic algorithm (PQC, especially Kyber KEM) and an improved Internet Key Exchange Protocol (IKE) to realize key exchange of post-quantum security and enhanced identity authentication. The method comprises the following steps: generating a dynamic pre-shared key (PSK) by utilizing the PUF; the method comprises the following steps: integrating a Kyber KEM to an IKE protocol, and replacing traditional Diffie-Hellman key exchange; the PUF-driven dynamic PSK is used as an identity authentication method of the IKE; meanwhile, Kyber KEM and ECDH are adopted for key exchange, and a final session key is generated through joint participation of a Kyber negotiation key, an ECDH negotiation key and PSK derived by PUF; and an IKE protocol process is optimized, and Kyber key exchange and PUF (Physical Unclonable Function) authentication are completed in an IKESAINIT stage and an IKEINTERMEDIATE stage. According to the method, key exchange is post-quantum secure, identity authentication is also post-quantum secure, and the final key integrates three key components of Kyber, ECDH and PUF, so that triple security assurance is provided.
Owner:MIXUAN TECHNOLOGY (HANGZHOU) CO LTD

Systems and methods for secure authentication

A system for authentication includes a validation system and an agent configured to communicate a first credential indicating an identification to the validation system and communicate a second credential indicating the identification to a verification service. The validation system includes a database configured to store authorized user data and a portal configured to provide selection of the verification service from a plurality of verification services. The validation system is configured to compare the first credential to the authorized user data, determine a confidence level of validity of the identification based on the comparison of the first credential to the authorized user data, receive a verification of the second credential from the verification service, and modify the confidence level based on the verification.
Owner:NETARX LLC

Factory real-time digital monitoring method and system based on Internet of Things, and storage medium

The invention relates to the technical field of industrial monitoring, and discloses a factory real-time digital monitoring method and system based on the Internet of Things, and a storage medium. The method comprises the following steps: carrying out encryption access on heterogeneous Internet of Things equipment through dual identity authentication to obtain a security authentication equipment identifier pool; performing multi-dimensional data acquisition on the equipment identification pool based on Hash verification to obtain an encrypted time sequence data chain; performing dynamic identification on the factory visual image by adopting a confidence adaptive threshold to obtain a multi-task fusion feature code; performing heterogeneous fusion on the time sequence data chain and the feature code by using a sliding window weight distribution algorithm to obtain a factory digital state fingerprint; and performing knowledge graph reasoning on the state fingerprint through three-level early warning threshold judgment to obtain a real-time risk level early warning code. The technical problems that heterogeneous Internet of Things equipment cannot be uniformly accessed and authenticated, multi-source data lacks safety fusion processing, and the factory state cannot be intelligently reasoned and pre-warned are solved.
Owner:BEIJING TIANYUAN 3D TECH CO LTD

Automated rule-based smart contract approval via blockchain cybersecurity authentication services

In one embodiment, a method includes accessing transaction data associated with a protected first function of a first blockchain transaction protocol by a cybersecurity authentication service of a blockchain cybersecurity platform, accessing a transaction protocol runbook comprising preconfigured conditions associated with the protected first function, determining that the protected first function is eligible to be analyzed by an automated decisional logic module based on the transaction protocol runbook, determining each preconfigured condition is satisfied based on the transaction data by the automated decisional logic module, generating an authentication object for the protected first function, generating signed transaction data based on the accessed transaction data and a private encryption key, wherein the signed transaction data is configured to update a second blockchain transaction protocol to indicate that the protected first function is authenticated, and transmitting a transaction bundle comprising the accessed transaction data and the signed transaction data.
Owner:HALBORN INC

Smart power grid cloud edge collaborative heterogeneous data security access method

The invention provides a smart power grid cloud edge collaborative heterogeneous data security access method, which comprises the following steps: collecting multi-source heterogeneous power equipment data in real time based on a deployed multi-mode sensor network; based on a lightweight federated learning edge inference engine deployed on an edge end network, performing adaptive semantic enhancement preprocessing on the multi-source heterogeneous power equipment data to generate an edge encryption feature tensor; performing three-dimensional credible security authentication and knowledge fusion on the edge encryption feature tensor based on an electric power space-time knowledge graph fusion engine deployed on the cloud side to generate secure and credible electric power data; and performing space-time causal reasoning and twin mirror image comparison on the secure and credible power data based on a federated block chain-driven digital twin decision engine deployed at a cloud end to generate a dynamic security policy map and store the dynamic security policy map. According to the scheme, the data security is enhanced, intelligent analysis and dynamic decision can be performed according to the real-time state of the power grid, and optimal scheduling and stable operation of the power grid are realized.
Owner:浙江浙能数字科技有限公司

Control of memory devices over computer networks using digital signatures generated by a server system for commands to be executed in the memory devices

A system, method and apparatus to control memory devices over computer networks. For example, a server system establishes a secure authenticated connection with a client computer system. Over the connection, the server receives from the client computer system a request identifying a memory device and determine, based on data stored in the server system, that the client computer system is eligible to control the memory device. In response to a request from the client computer system, the server system generates a digital signature for a command using at least a cryptographic key stored in the server system in association with the memory device. The client computer system receives the digital signature from the server system and submits the command with the digital signature to the memory device. The memory device validates the digital signature prior to execution of the command.
Owner:MICRON TECHNOLOGY INC

Intelligent factory equipment safety management system and method

The invention relates to the technical field of intelligent manufacturing and industrial Internet of Things, in particular to an intelligent factory equipment safety management system and method, and the system comprises an identity authentication module, a dynamic safety interaction module, an intelligent monitoring response module and a self-adaptive optimization module. An identity authentication module; through fusion of multi-dimensional information authentication, block chain decentralized storage, intelligent algorithm behavior analysis, encrypted communication and fine-grained authority control, multi-source data threat detection and reinforcement learning driven strategy optimization, a whole-process security system is constructed. The method comprises the steps of identity authentication, security interaction, monitoring response and adaptive optimization. The problems that in a traditional industrial scene, equipment identity authentication is fragile, data transmission is not safe, threat response lags and strategies are staticized are solved, high-safety authentication, dynamic encryption communication, real-time threat response and strategy self-optimization are achieved, and the equipment safety protection capacity and the system intelligence level are improved.
Owner:ZHEJIANG GUOLI SECURITY TECH CO LTD

Security authentication system and method for space-air-ground fusion vehicle-mounted network based on double chains

The invention provides a double-chain-based air-space-ground fusion vehicle-mounted network security authentication system and method, and belongs to the technical field of intelligent transportation, in an air-space-ground fusion vehicle-mounted network, a vehicle-mounted unit, a road side unit, an unmanned aerial vehicle node and a satellite node interact through a trusted mechanism and a double-chain architecture, after interaction in a single domain is completed, cross-domain interaction is performed, and the security authentication of the vehicle-mounted unit, the road side unit, the unmanned aerial vehicle node and the satellite node is completed. The authentication token is stored on the block chain after being obtained in the first interaction, and the quick interaction can be completed by directly calling the authentication token subsequently. According to the invention, through the double-chain block chain architecture, the authentication time delay is optimized, the cross-domain authentication efficiency is improved, and the privacy protection problem of the node in a high dynamic environment is effectively solved.
Owner:TIANJIN CHENGJIAN UNIV +1

Extended Embedded Controller Authenticated BIOS Interface for Analysis of Firmware Variable Transactions

A firmware management operation. The firmware management operation includes providing an information handling system with a distributed BIOS, the distributed BIOS including a BIOS component and a BIOS variable, the BIOS variable being stored within a firmware variable non-volatile memory store; instantiating a firmware variable transaction; and, authenticating, via a secure authenticated BIOS interface, the firmware variable transaction.
Owner:DELL PROD LP

Secure authentication of digital humans

A video stream that depicts at least the face of an individual, and information identifying a known individual is received. Predetermined validation data derived from the known individual is accessed. An analysis of a segment of the video stream based on the predetermined validation data is performed. Based on the analysis, an output signal indicative of a confidence level that the video stream is a video stream generated by the known individual is provided.
Owner:CHARTER COMM OPERATING LLC

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Power distribution internet-of-things terminal management method and system based on quantum cloud code, and electronic equipment

The invention relates to the technical field of power data transmission, and discloses a power distribution Internet of Things terminal management method and system based on quantum cloud codes, and electronic equipment. The method comprises the steps of mixing original data through a random number generator to obtain a quantum cloud code seed, obtaining a quantum cloud code sequence through fragmentation encryption, forming a terminal equipment grouping key according to a preset rule, generating an equipment identity feature code in combination with operation state information, and establishing a data transmission channel according to the feature code. A secure communication link is formed through encryption and verification of a session key, operation data in the communication link is collected, a standardized data set is obtained through cleaning and normalization, output equipment behavior characteristics are mapped, operation authority is dynamically adjusted to construct a management system, regular snapshot and distributed backup are performed, and disaster recovery backup data are formed to establish a recovery strategy. According to the invention, security authentication, dynamic permission allocation and intelligent management of the terminal equipment are realized, and the security and management efficiency of the system are remarkably improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD NINGBO POWER SUPPLY CO

Emergency communication high-altitude base station system for unmanned aerial vehicle

The invention discloses an emergency communication high-altitude base station system for an unmanned aerial vehicle, which relates to the technical field of communication and comprises an unmanned aerial vehicle platform, an intelligent flight control module, a communication management module, a multi-unmanned aerial vehicle cooperative technology module, a data analysis and decision support module, an encryption and security authentication module and a modular design structure. And the remote monitoring and maintenance module is used for maintaining the service system module. The intelligent flight control module integrates functions of flight strategy optimization, automatic obstacle avoidance and the like, can automatically adjust the flight height, angle and path of the unmanned aerial vehicle according to communication coverage requirements, and reduces the complexity and risk of manual operation; the multi-unmanned aerial vehicle cooperation technology module can realize information sharing, task cooperation and optimal distribution of communication resources among multiple unmanned aerial vehicles to form a distributed communication network, thereby not only improving the communication coverage and capacity, but also enabling the resource utilization to be more efficient.
Owner:ZHEJIANG JIACHUANG AEROSPACE POWER TECHNOLOGY CO LTD +1

Internet of Things equipment security authentication and data encryption transmission system and method

The invention relates to the technical field of Internet of Things equipment, particularly provides an Internet of Things equipment security authentication and data encryption transmission system and method, and solves the problems of limited equipment resources and difficult key management. The system comprises an equipment identity authentication component, a key management component and a lightweight encryption component. The method comprises the following steps: authenticating the legal identity of the Internet of Things equipment by adopting a lightweight symmetric key; the authority is dynamically adjusted according to factors such as equipment position, time and network state; the Internet of Things equipment generates and distributes a secret key after passing the access authority authentication; key exchange is carried out between the Internet of Things devices by adopting a key exchange protocol, and local key management is realized at an edge node in combination with edge calculation; and transmitting the data containing the key and the key exchange protocol to the target equipment, encrypting the transmitted data by adopting lightweight encryption and a Hash algorithm during transmission, and preventing a replay attack by using a timestamp and a random number. According to the invention, comprehensive safety protection of the Internet of Things equipment is realized.
Owner:SHENZHEN AISHANSI TECHNOLOGY CO LTD

Blockchain-Based System and Method for Secure Authentication of Training Data for Machine Learning Models

The disclosed system includes a memory and a processor designed to execute operations for generating non-fungible tokens for training data utilized in training machine learning models. The memory is configured to store both data records of the training data and their corresponding metadata. The processor performs operations to identify a set of fields within each data record and to annotate each field. Such annotation process involves creating field metadata, including information that identifies each field in the data record and assigning a label to each field. Additionally, for each field, the processor is further configured to generate a non-fungible token and create a non-fungible token attribute record, incorporating details from both the data record metadata and the field metadata. Also, the processor is configured to store the non-fungible token attribute record in the memory, thereby facilitating comprehensive and secure authentication of data records.
Owner:BANK OF AMERICA CORP

Enterprise governance inventory and automation tool

A system may include a directory-based identity-related services component that authenticates and authorizes enterprise users and computers in a network and enforces security policies. A business intelligence, application development, and application connectivity component may implement business workflow products and exchange application authentication data with the directory-based identity-related services component. A database storage component may provide document management and storage of dashboard tables and lists associated with inventory data received from the business intelligence, application development, and application connectivity component. A cloud-based storage and data management engine may exchange secure authentication storage data with the business intelligence, application development, and application connectivity component. At least one governance or user application may then automatically determine enterprise site inventory information, and, responsive to the determined enterprise site inventory information, automatically determine enterprise site membership information. The dashboard tables and lists may be exchanged in support of a graphical user display.
Owner:HARTFORD FIRE INSURANCE CO

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Passkey-based authentication for the 3-d secure protocol

Disclosed are various embodiments for integrating the use of passkeys in the 3-D SECURE authentication protocol for transactions. A user of a client device can be prompted to enter a secondary factor of authentication for a second transaction, wherein the prompt includes transaction information and merchant information. In response to a selection to enter the secondary factor of authentication, biometric authentication of the user of the client device can be performed. In response to successful biometric authentication of the second transaction, a challenge comprising the transaction information and the merchant information can be cryptographically signed with a private passkey. The cryptographic signature of the challenge can then be sent to the transaction authorization service.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

System and Method for Dual Remote Authentication of Digital Assisted Shopping Agents and Customers Using Proximity-Based Mobile Device Interactions, Enterprise Security, and Biometrics

Systems and methods are disclosed for dual, simultaneous, single-session, proximity-based, secure authentication of a Digital Assisted Shopping (DAS) representative and a customer in an unsecured remote location. The method includes installing a mobile banking application on the customer's device and an enterprise application on the DAS representative's device, both with biometric verification. Proximity detection using Bluetooth Low Energy (BLE) initiates a secure session via push notifications. A secure communication channel is established through a secure local handshake, involving encryption key exchange and mutual authentication. The system exchanges data related to customer profiles and financial accounts, continuously monitors geolocation using GPS, Wi-Fi, and cellular data, and performs periodic background biometric re-verifications. AI / ML algorithms analyze customer data to propose financial products and services, which are securely shared with the customer for review and selection. The system facilitates real-time enrollment and transaction processing, terminating the session upon detecting security breaches.
Owner:BANK OF AMERICA CORP

Permission-based tiered authorization for smart contracts via blockchain cybersecurity authentication services

In one embodiment, a method includes receiving transaction data associated with a protected first function of a first blockchain transaction protocol by a cybersecurity authentication service of a blockchain cybersecurity platform, assigning a first authority classification to the protected first function based on a transaction protocol runbook comprising preconfigured conditions associated with the protected first function, accessing the transaction data via a cybersecurity authentication interface by a first cybersecurity authority having an authority classification corresponding to the first authority classification, determining that the protected first function should be authenticated by the first cybersecurity authority based on each preconfigured condition being satisfied, inputting an authentication of the protected first function via the cybersecurity authentication interface by the first cybersecurity authority, and transmitting a transaction bundle configured to update a second blockchain transaction protocol to indicate that the protected first function is authenticated.
Owner:HALBORN INC

Internet of vehicles security authentication and data encryption transmission system integrated with IPv6 technology

The invention discloses an Internet of Vehicles security certification and data encryption transmission system integrated with an IPv6 (Internet Protocol Version 6) technology. According to the invention, the key strategy can be automatically optimized according to the dynamic environment in the actual operation of the Internet of Vehicles, and the dynamic balance between the security protection and the communication efficiency is realized. The system can intelligently judge the cracking risk faced by a current key by combining real-time data such as a vehicle driving state and network environment characteristics, so as to flexibly adjust the key length and the updating frequency: when the network environment is safe and the vehicle is in a low-risk area, the key service cycle is properly prolonged, and the basic key length is maintained to reduce the communication overhead; when a potential threat is detected or a vehicle enters a complex road section, the secret key security level is automatically improved, and the rotation period is shortened to enhance the protection capability. The system burden cannot be increased due to excessive encryption, potential safety hazards cannot be left due to insufficient protection, and key management better meets the actual requirements of high-speed movement of vehicles and rapid change of scenes in the Internet of Vehicles.
Owner:XIANGTAN TECHNICIAN COLLEGE

Lightweight multi-factor authentication method and system oriented to multiple modes

The invention relates to the technical field of identity authentication, in particular to a multi-mode-oriented lightweight multi-factor authentication method and a multi-mode-oriented lightweight multi-factor authentication system. The method comprises the following steps: taking a real voice sample as input to realize lightweight voice deception detection, synchronously acquiring voiceprint modal data and auxiliary modal data of a user through terminal equipment, extracting modal feature vectors and performing dimension reduction processing; distributing a weight for the modal feature vector, and calculating a fusion feature vector; inputting a password by a user, performing AES encryption on the password by the system, and performing local comparison with the ciphertext in the database; homomorphic encryption is carried out on the fusion feature vector by using an ASPE homomorphic encryption algorithm based on chaotic scrambling and semi-tensor product optimization, and the fusion feature vector is compared with a stored voiceprint ciphertext vector; and when both the password comparison authentication and the voiceprint recognition authentication are passed, determining that the user authentication is successful. According to the method, key technologies such as voice deception detection, multi-modal fusion and knowledge distillation are fused, and low overhead and high safety in the safety certification process are ensured.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Intelligent dynamic security authentication method, device and system

The invention discloses an intelligent dynamic security authentication method, device and system, and relates to the field of network security. Comprising the following steps of: 1, configuring an authentication strategy, and configuring an authentication process according to the authentication strategy: selecting authentication factors according to personal preference and security requirements to combine into a personalized authentication chain, setting a logical relationship among the authentication factors, and defining which condition to carry out additional verification; step 3, monitoring and analyzing user authentication behaviors in real time, evaluating security risks, and adjusting the authentication process according to an evaluation result: evaluating the current login authentication behaviors by using a large model, outputting risk levels, and adjusting the authentication process according to the evaluation result; and if the risk level is no risk, authentication succeeds, otherwise, authentication intervention is carried out, the security risk is evaluated, the risk level is output, and if the risk level still exists, early warning notification is carried out.
Owner:INSPUR SOFTWARE TECH CO LTD

Security authentication method and system based on secure computer

The embodiment of the invention relates to the technical field of computer security authentication, in particular to a security authentication method and system based on a secure computer. The method comprises the following steps: carrying out sensing array deployment and data acquisition on a secure computer to obtain calibrated time-space synchronization data; performing temperature and current fusion processing on the calibrated time-space synchronization data to obtain a thermoelectric coupling characteristic spectrum; carrying out point location time sequence correlation analysis on the thermoelectric coupling characteristic spectrum to obtain a point location cross-correlation matrix; performing nonlinear feature extraction on the point location cross-correlation matrix to obtain a nonlinear dynamic feature set; performing dynamic behavior analysis on the nonlinear dynamic feature set to obtain a security calculation behavior dynamic phase spectrum; and performing phase difference calculation on the dynamic phase spectrum of the security calculation behavior to obtain a phase difference vector. According to the method, the early detection capability of threats which are difficult to reproduce and are in a novel hardware level is improved through real-time monitoring and anomaly recognition of computer microcosmic physical characteristics.
Owner:HUNAN AGRI UNIV

User security authentication method and system based on encryption processing

The invention discloses a user security authentication method and system based on encryption processing. The method comprises an initialization stage, user key processing, secondary encryption, user identity authentication, server identity authentication, secondary security authentication, dynamic update of an expansion mechanism and key management. The invention belongs to the field of data encryption, and particularly relates to a user security authentication method and system based on encryption processing, according to the scheme, Q is generated through a high-entropy pseudo-random number, and the anti-prediction capacity of key generation is greatly improved; introducing a double confusion mechanism to carry out secondary encryption; detecting data errors by checking the basic groups; therefore, the security of encryption authentication is obviously improved; primary identity authentication, direct authentication between a user and a target server and secondary security authentication are performed in combination with biological characteristic data of the user, so that a multi-layer authentication mechanism is constructed, and the confidentiality and integrity of a key are ensured; based on dynamic expansion and hierarchical key management, the risk of single-point key leakage is reduced; and the encryption authentication effect is improved.
Owner:CHINA UNICOM ONLINE INFORMATION TECHNOLOGY CO LTD +1

Unmanned aerial vehicle cross-domain service function link accessing method based on alliance chain

The invention discloses an alliance chain-based unmanned aerial vehicle cross-domain service function link accessing method, which comprises the following steps of: 1, initializing a system and configuring an alliance chain, generating a global password parameter and a root key by a trusted mechanism, and finishing domain registration and certificate chain storage by each management domain edge server; 2, blockchain-driven identity management is carried out, and the unmanned aerial vehicle completes chain registration and anti-counterfeiting registration certificate acquisition through a domain edge server to which the unmanned aerial vehicle belongs; 3, deploying a flexible threshold signature algorithm to realize multi-domain joint signature and Byzantine fault tolerance; 4, executing a cross-domain SFC security authentication protocol, including SFC pre-verification and security authorization certificate issuing, first node verification starting, hop-by-hop key negotiation and handover certificate transmission, and on-chain auditing; and 5, based on the topology centrality and the path coverage, dynamically electing an orchestrator to realize load balancing. According to the invention, safe access and identity authentication of the cross-domain service function chain of the unmanned aerial vehicle are realized, safety, efficiency and expandability are balanced, and reliable guarantee is provided for cross-domain cooperation of the unmanned aerial vehicle.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Network security authentication method, device and system

The invention relates to the technical field of network security authentication, in particular to a network security authentication method, device and system. When a server side authenticates the identity of a request side, the method comprises the following steps: acquiring signature data, abstract data and a digital certificate from the request side; decrypting the signature data through a public key in the digital certificate to obtain biological characteristic data and decryption action instruction data; calculating the biological characteristic data and the decryption action instruction data obtained from the self-signature data by adopting a Hash algorithm, and comparing a calculation result with the abstract data; matching the biological characteristic data and the decryption action instruction data with a secret order database arranged at a server side; and completing identity authentication of the server side to the request side. According to the invention, identity authentication of the request end from the server end can be well realized.
Owner:SHANXI ELECTRIC POWER CO POWER COMM CENT +1