Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

685results about "Cryptographic attack countermeasures" patented technology

Federal learning system based on multi-key homomorphic encryption and adaptive differential privacy

The invention relates to a federated learning system based on multi-key homomorphic encryption and adaptive differential privacy, and belongs to the technical field of privacy computing. According to the system, on the premise that no trusted third party exists, a multi-client collaborative key generation and threshold decryption mechanism is achieved, it is ensured that model parameters are always in an encrypted state in the aggregation process, and leakage of a single node is prevented. By introducing a parameter sensitivity analysis and selective encryption strategy, the system only encrypts high-risk parameters, and the encryption burden is effectively reduced. Meanwhile, in combination with an adaptive privacy budget allocation mechanism, the system dynamically adjusts noise intensity according to a model training state, and model performance and convergence speed are maintained while privacy protection capability is improved. According to the method, high robustness and collusion resistance are realized, stable operation under the condition that part of clients are offline is supported, and the method is suitable for application scenes such as medical treatment and finance with high data sensitivity and strict performance requirements.
Owner:FUZHOU UNIV

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Adaptive Data Processing System with Real-Time Anomaly Detection and Self-Healing

A system and method for adaptive data processing combining compression and encryption. The system analyzes input data characteristics, compares probability distributions, and creates a transformation matrix to convert data into a dyadic distribution. It generates a main data stream of transformed data and a secondary stream of transformation information. The system dynamically selects and applies processing techniques, including transformation, encoding, compression, and encryption algorithms, based on analyzed characteristics and real-time performance metrics. It compresses the main data stream using Huffman coding and implements security measures to protect the output. A feedback loop monitors technique effectiveness, updates a knowledge base, and influences future selections. The system can operate in lossless, lossy, or modified lossless modes, adapting to different application requirements. This approach offers an efficient solution for scenarios where both data reduction and security are critical concerns.
Owner:ATOMBEAM TECH INC

Anti-quantum serial digital certificate implementation method and device, equipment and storage medium

The invention discloses an anti-quantum serial digital certificate implementation method. The method comprises the following steps: generating a traditional cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; submitting a certificate request; splicing the traditional cryptographic algorithm public key and the anti-quantum cryptographic algorithm public key to form a dual-cryptographic algorithm public key, and generating a digital certificate according to the dual-cryptographic algorithm public key; signing the digital certificate by using a traditional cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key; and splicing and combining the traditional cryptographic algorithm signature value and the anti-quantum cryptographic algorithm signature value into a dual-cryptographic algorithm signature value, putting the dual-cryptographic algorithm signature value into a signature value item of the digital certificate, so that the digital certificate forms a hybrid serial digital certificate, and returning the hybrid serial digital certificate to the client. The invention further discloses a device for implementing the quantum serial digital certificate implementation method, computer equipment and a storage medium. According to the method, the problems of poor compatibility, low storage efficiency, slow verification speed and the like of the existing digital certificate under the threat of quantum computing are solved.
Owner:KOAL SOFTWARE CO LTD

Data encryption method for multilevel key stream control in industrial gateway

The invention discloses a data encryption method for multilevel key stream control in an industrial gateway, and particularly relates to the technical field of data encryption and network security. The method comprises the steps of obtaining a session identification code and communication context information; generating a first-level basic key based on the session identification code, and generating a multi-level key stream control matrix in combination with communication context information and a multi-source dynamic random factor; according to the hierarchical relationship of the matrix, key stream sequences of corresponding levels are distributed to data packets of different priorities, and the key stream sequences are switched or combined in real time according to data packet types, transmission paths and security policies in the encryption process, and time fragmentation processing and disturbance coding are executed; the encrypted data packet is sent through a multi-protocol forwarding module of the industrial gateway, and the receiving end carries out decryption by using the key stream control matrix; according to the invention, dynamic generation, hierarchical calling and safe switching of the key stream can be realized, and the data confidentiality, integrity and anti-attack capability of the industrial gateway in a complex network environment are remarkably improved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

Scheduling instruction trusted storage system based on block chain

The invention discloses a block chain-based scheduling instruction trusted storage system, which relates to the technical field of block chains, and comprises a block chain network layer, an instruction acquisition module, an instruction verification module, a cross-chain storage module, a trusted tracing interface, an instruction life cycle management smart contract and a quantum security module, the block chain network layer comprises a plurality of block chain service units deployed at power dispatching nodes, the instruction acquisition module is used for acquiring a dispatching instruction data set and an associated digital signature generated by a dispatching terminal, and the instruction verification module is configured with a compliance verification rule base and multi-level verification logic. And the cross-chain storage module realizes a sub-chain storage architecture of scheduling instruction metadata and content data. According to the method, a double-chain architecture in which a metadata chain and a content chain are separated is adopted, and an improved Merkletree cross-chain verification technology is combined, so that on the premise of ensuring data privacy, cross-regional instruction synchronization delay is reduced, and meanwhile, fine-grained access control of sensitive instruction content is realized.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Cryptographic system for post-quantum cryptographic operations

Certain examples described herein relate to at least a cryptographic system and a method of operating a cryptographic system. The cryptographic system may be implemented as a co-processor for performing post-quantum cryptographic functions. The cryptographic system has a set of bus interfaces for coupling to an external computing system, a cryptographic math unit and a control unit. The cryptographic math unit in certain examples is adapted to provide one or more masked modes of operation that secure the cryptographic operations against side-channel and non-invasive attacks. The method of operating a cryptographic system involves annotating secret data and tracking those annotations through one or more arithmetic operations.
Owner:PQSHIELD LTD

Secure data transmission method for wireless communication system

The invention discloses a secure data transmission method for a wireless communication system, which relates to the technical field of secure data transmission and comprises three steps of key generation and synchronization, physical layer subcarrier encryption and key enhancement and authentication. The method comprises the following steps: firstly, extracting multi-dimensional features through channel detection to generate a dynamic initial key, and setting a trigger condition to realize key synchronization; then, a permutation matrix is generated by using a secret key to perform scrambling encryption on a data subcarrier position, and a receiving end performs descrambling and then performs feedback through CRC verification so as to guarantee data integrity; and finally, quantum noise is introduced to enhance the randomness of the secret key, and zero-knowledge authentication is adopted to verify the identity, so that the security and the anti-attack capability of wireless communication data transmission are effectively improved.
Owner:SHENZHEN XIAOPAN TECHNOLOGY CO LTD

Novel ARE cryptosystem of infinite dimension key space for resisting ADC attack on finite dimension cryptosystem

Due to the appearance of dynamic structured mathematics responded by a global coupling structure, a great threat is generated to a traditional password system represented by AES-256 and information security. Most of current mainstream symmetric cryptographic systems such as AES and post-quantum encryption candidate schemes are based on discrete key space and structure modeling operation, the security of the current mainstream symmetric cryptographic systems depends on exhaustion infeasibility or mathematical difficulty complexity, and the current mainstream symmetric cryptographic systems and post-quantum encryption candidate schemes are difficult to resist attacks of adaptive dynamic coupling such as ADC. Therefore, the invention provides a novel ARE encryption system which is constructed by taking'non-modeling property 'as a core principle. A system key is generated by a non-numerable dimension perturbation function, has unique attributes of no structure, non-derivation, non-periodicity and the like, and is combined with an encryption method of a key function which cannot be covered, physical noise perturbation and a quantum random source to construct a new generation of ARE password architecture; the method has the capability of being incapable of being deduced, reduced in order, incapable of being converged to a key space and extremely high in structural modeling attack resistance, any analyzable optimization path can be blocked from the source, and it is ensured that ADC evolution attacks are completely resisted.
Owner:李海全

Efficient lattice cipher analysis system and method based on dynamic chaos control and quantum noise resistance

The invention discloses an efficient lattice cryptographic analysis system and method based on dynamic chaos control and quantum noise resistance. The efficient lattice cryptographic analysis system comprises a chaos control module, a mixed precision projection module, a quantum noise resistance module, a distributed architecture, a dimension compression calculator, a distributed task scheduler, a parallel execution unit, a load balancer and a result verifier. According to the efficient lattice cryptographic analysis system and method based on dynamic chaos control and quantum noise resistance, the calculation efficiency, quantum resistance and hardware adaptability of lattice cryptographic analysis are remarkably improved, and the system and method are suitable for financial audit, Internet of Things authentication, block chain security and other high-dimensional lattice reduction and quantum attack defense scenes.
Owner:杨永夏

Fusion quantum security communication method of NAT gateway

The invention discloses a fusion quantum secure communication method of an NAT gateway, and relates to the technical field of communication network information security and quantum information. Comprising the steps of 1, creating a fusion quantum security communication system of an NAT gateway, 2, adopting a quantum hybrid encryption architecture through a quantum security module, and internally arranging a quantum key distribution unit and an anti-quantum computing acceleration chipset, 3, expanding a quintuple mapping structure of NAT through a dynamic address mapping and quantum encryption module, newly adding a quantum security dimension field QSV, and carrying out quantum encryption on the quantum key distribution unit and the anti-quantum computing acceleration chipset. And 4, developing a protocol non-inductive conversion engine through a hybrid protocol stack cooperation module, supporting an IPv4 / IPv6 dual-stack quantum tunnel and a quantum key inheritance protocol to realize cross-protocol family encryption parameter migration, dynamically adjusting a quantum encapsulation mode in an address conversion process, and dynamically associating an internal network address port with a quantum key parameter and a channel fingerprint feature. And 5, constructing a quantum perception type session state machine through an anti-quantum attack session management module, and performing a joint decision-making mechanism through quantum entanglement state monitoring and classical traffic feature analysis.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Lightweight hybrid encryption transmission method and system capable of resisting quantum attack

The invention discloses an anti-quantum-attack lightweight hybrid encryption transmission method and system, and aims to solve the problems that an existing lattice-based encryption algorithm is complex in calculation, high in resource consumption and difficult to adapt to embedded equipment and an internet of things scene. According to the method, a key encapsulation mechanism is constructed based on an LWE problem, key negotiation is performed by using the quantum attack resistance of the key encapsulation mechanism, and encryption transmission is performed on data in combination with a lightweight symmetric encryption algorithm. In the de-encapsulation process, a rapid dimension reduction decoding mechanism is introduced, and dimension reduction mapping is performed on a high-dimensional ciphertext vector and a private key vector through a mapping matrix obtained through training, so that the matrix operation complexity is reduced, and the decryption efficiency is improved. According to the method, the implementation cost and operation burden of an algorithm on an embedded platform can be remarkably reduced while anti-quantum security is kept, and the method is suitable for an Internet of Things terminal, an edge computing node and other low-power-consumption equipment sensitive to security and energy consumption and has good security, light weight and deployment practicability.
Owner:WUXI ALEADER INTELLIGENT TECH

Large model federal splitting privacy protection method based on homomorphic encryption

The invention relates to a big model federal splitting privacy protection method based on homomorphic encryption, and belongs to the technical field of big language models and privacy protection. The method comprises the following steps: splitting a large language model into a client side sub-model and a server side sub-model; after the client finishes each round of local training, performing compression processing on an intermediate activation value generated by each client sub-model through a compressed sensing technology; then encrypting and transmitting the compressed activation value by using a homomorphic encryption algorithm, thereby reducing the calculation overhead of the homomorphic encryption algorithm and the communication overhead between the client and the server, and providing privacy protection capability for transmitted sensitive data; the server terminal model is updated by using the gradient of the client, and each client uses local private data to finely adjust the server terminal model, so that the original data of the client is not out of the domain and is available and invisible, and the data privacy security is protected.
Owner:KUNMING UNIV OF SCI & TECH

Anti-quantum identification signature method based on lattice SIS problem

The invention provides an anti-quantum identification signature method based on an on-lattice SIS problem. The method comprises the following steps: selecting system safety parameters and other related system parameters; generating a system public parameter and a master key by using the system security parameter and other related system parameters; generating a corresponding public and private key pair by using the user identity ID; the user generates a signature of the message by using the private key; and the verifier verifies the validity of the signature by using the system parameters and the user public key. According to the method, a lattice-based digital signature scheme is constructed by utilizing an SIS difficulty problem on a middle lattice, and quantum attack resistance security is provided for an information system for deploying the algorithm scheme; personal identity information of the user is used for registering and generating public and private keys, the key escrow problem participated by a third party is relieved, and the privacy security of the user is improved.
Owner:GUIZHOU UNIV +1

Method and device for detecting and identifying cryptographic algorithms in a communication network

The invention relates to a method for detecting a particular cryptographic algorithm used in a computer system, comprising steps of capturing data packets exchanged with a target machine in order to obtain initial measurements of time and data volume, calculating response delays by measuring the time elapsed between sending and receiving the captured data packets, determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets on the basis of the calculated response delays and the exchanged data volumes, determining a level of correspondence between the first time signature determined and at least one second time signature determined beforehand for a particular cryptographic algorithm, and transmitting an alert comprising at least one identifier of a source apparatus and / or of a destination apparatus of the network flow when the level of correspondence is greater than a threshold.
Owner:ORANGE SA

Reconfigurable multi-channel polynomial multiplier architecture and implementation method thereof

The invention relates to a reconfigurable multi-channel polynomial multiplier architecture and an implementation method thereof, and belongs to the technical field of post-quantum cryptography hardware acceleration. The architecture comprises a scheduler, a twiddle factor memory bank, a bank address routing module, a bank array and a reconfigurable butterfly unit array. According to the architecture, a cyclic decoupling multi-channel NTT / INTT / PWM algorithm is used, flexible configuration of the degree of parallelism and the flow line depth can be supported, and the adaptability of a memory access control strategy is improved; a conflict-free memory mapping scheme based on interleaved storage is adopted, so that storage and read-write of polynomial coefficients are irrelevant to polynomial length and a calculation stage, NTT / INTT / PWM access modes are unified, and hardware resource overhead is greatly reduced; and a conflict-free detection algorithm oriented to multi-channel assembly line design is adopted, so that the utilization rate of hardware resources is remarkably improved.
Owner:NAT UNIV OF DEFENSE TECH

Data security protection method and system for large model training

The invention discloses a data security protection method and system for large model training. The core of the method is that a data safe box trusted application (TA application) is deployed in a trusted execution environment (TEE) and cooperatively works with a user-defined virtual file system driver at a host machine side, so that an end-to-end secret state data access control link is constructed. Before encryption protection of sensitive data, a measurement value (including code hash, configuration parameters and a runtime state) of a current TEE instance is submitted to a remote verification service through a data safe box TA application, and the verification service only sends the measurement value (including code hash, configuration parameters and a runtime state) of the current TEE instance to the remote verification service after confirming that the TEE environment meets a preset security policy (such as a kernel version, a software version and configuration parameter compliance). And generating a secret key encrypted by a custom virtual file system on a host machine side through derivation. And malicious copying of a system memory and a storage medium is prevented, so that the traditional attack defense capability is effectively improved.
Owner:PANOVASIC TECHNOLOGY CO LTD

Quarantine control network in a 5G RAN for coordinated multi-layer resiliency of network slice resources

A system is disclosed for quarantining and recovery of a network after an outage or in advance of a potential outage. Unaffected network slices are isolated and recovery is initiated by quarantine physical and virtual network functions. An AI model is trained based on recent events detected by sensors disposed throughout the network to determine whether to quarantine network slices, move services to unaffected network slices, or initiate recovery. Once the network is stabilized, resources that are specifically allocated for recovery and services are released and the traffic moved back to the recovered network slices.
Owner:INTEL CORP

Decentralized virtual identity key collaborative management system based on block chain

The invention discloses a decentralized virtual identity key collaborative management system based on a block chain, and belongs to the field of block chain technology and cryptography. The system comprises a block chain network layer used for distributed storage of key fragments and execution of an automation strategy; the virtual identity management module is used for generating a unique identity identifier (DID) through a threshold signature algorithm after fusing the biological characteristics and the device fingerprints; the key collaborative management module is used for storing the main key in a fragmented manner through a Shamir secret sharing algorithm, and dynamically selecting an encryption algorithm to generate a sub-key according to the security score of the target platform; the verification and auditing module is used for verifying the holding legality of the secret key through a zk-SNARKs technology and injecting random noise to resist side channel attacks; and the block chain network layer, the virtual identity management module, the key collaborative management module and the verification and auditing module are connected with an encrypted communication protocol through an intelligent contract interface.
Owner:HENAN INFORMATIZATION GRP CO LTD

Anti-quantum key packaging method and device, medium and equipment

The invention discloses an anti-quantum key packaging method and device, a medium and equipment, and the method comprises the steps that a first node generates a first public key and a first private key based on an asymmetric encryption algorithm, and generates a second public key and a second private key based on an anti-quantum encryption algorithm; sending the first public key and the second public key to a second node, so that the second node encrypts a third public key based on the second public key to obtain a public key ciphertext, and generates a shared key based on the first public key and a third private key; receiving a public key ciphertext sent by the second node, and decrypting the public key ciphertext based on the second private key to obtain a third public key; generating the shared key based on a third public key and the first private key; wherein the third public key and the third private key are generated by the second node based on an asymmetric encryption algorithm. According to the invention, by combining an anti-quantum encryption algorithm and a widely used asymmetric encryption algorithm, a secure key exchange mechanism which can resist future quantum computing threats and has high compatibility is provided.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

Zero-knowledge-proof-oriented CPU-GPU data processing and transmission optimization system and method

Disclosed in the present invention is a zero-knowledge-proof-oriented CPU-GPU data processing and transmission optimization system, which is used for executing multi-scalar multiplication operations on the basis of elliptic curve cryptography, so as to generate zero-knowledge proofs. The system comprises a CPU and a GPU, wherein a data transmission channel is provided between the CPU and the GPU; the CPU is used for acquiring and storing point sets and scalar sets that are involved in multi-scalar multiplication operations, and using a set parallelized data transmission mechanism to communicate with the GPU; and the GPU executes multi-scalar multiplication computation on the basis of the point sets and the scalar sets, and returns a computation result to the CPU. By means of the coordinated effect of a plurality of technical features, the present invention significantly improves the speed and efficiency of zero-knowledge proof generation and optimizes resource utilization efficiency.
Owner:SHENZHEN INST OF ADVANCED TECH CHINESE ACAD OF SCI

Digital signature generation and authentication system and method

The invention discloses a digital signature generation and authentication system and method. The system comprises a first terminal and a second terminal, the first terminal comprises a first acquisition module for generating a first graphical interface, responding to a signature executed by a user on the first graphical interface, and acquiring first vector coordinate data signed on the first graphical interface; the second acquisition module is used for sampling facial features of the user; the data processing module is used for extracting a first secret key parameter from the first vector coordinate data, taking the facial feature as a second secret key parameter, and encrypting the first vector coordinate data through the first secret key parameter and the second secret key parameter to obtain secret key data; the storage module is used for storing key data; the communication module is used for transmitting the key data to a second terminal; the second terminal comprises a third acquisition module for verifying the facial features of the user; and the generation module verifies the facial features, decrypts the key data by using the second key parameter, and requests the first terminal to generate a digital copy to the second graphical interface.
Owner:HUNAN VOCATIONAL COLLEGE OF SCI & TECH

Security auditing method and device supporting data owner replacement, equipment, medium and product

The invention discloses a safety auditing method and device supporting data owner replacement, equipment, a medium and a product, and relates to the field of auditing, and the method comprises the steps that if the data ownership is changed, an original data owner calculates a trap door parameter value based on a random number j and a private key of the original data owner; the new data owner calculates a conversion parameter value according to the trap door parameter value and a private key of the new data owner; the cloud server calculates the label of each data block after the data ownership is changed according to the conversion parameter value, the reciprocal of the random number j and the label of each data block before the data owner changes; the cloud server generates auditing evidences according to the labels of the data blocks and the inquiry information; the third-party auditor carries out safety auditing according to the auditing evidence and the inquiry information, and after the data ownership is changed, it can be ensured that the changed data owner can still ensure the continuity of data integrity verification under the condition that all the data are not downloaded.
Owner:BEIJING INSTITUTE OF GRAPHIC COMMUNICATION

Equipment security access method of power distribution terminal

The invention provides an equipment security access method of a power distribution terminal, which belongs to the technical field of equipment security access, and comprises the following steps: caching and coding an access request of a terminal to be accessed according to a parameter category to obtain a coding field, and carrying out field analysis on the coding field to determine a preliminary gateway set; carrying out authentication analysis on the access request according to basic gateway information of each preliminary gateway in the preliminary gateway set, and determining an allowable security access probability of the terminal to be accessed based on the corresponding preliminary gateway; generating a first key depending on the authentication slice of the authentication analysis and a security protection rule corresponding to the preliminary gateway; and carrying out comparative analysis on the key security degree of the first key of each preliminary gateway and the allowable security access probability, and screening an optimal gateway to realize the security access of the terminal to be accessed. And the access safety, stability and efficiency of the power distribution terminal are obviously enhanced.
Owner:CLOUD VALLEY TECH (ZHUHAI) CO LTD

Circuitry and methods for efficient side-channel and fault attack countermeasures for cryptographic execution circuitry

Efficient side-channel and fault attack countermeasures for cryptographic execution circuitry are described. In certain examples, a system includes a processor core; and an accelerator coupled to the processor core, the accelerator comprising: execution circuitry to generate a cryptographic signature for a first input of a message value and a second input of a secret key value, and countermeasure circuitry to, in response to a request to generate the cryptographic signature, cause the execution circuitry to perform multiple sequential executions for the first input of the message value, the second input of the secret key value, and a third input of a different uniformly random value for each execution to generate a plurality of cryptographic signatures, and output, as a resultant for the request, one of the plurality of cryptographic signatures as the cryptographic signature.
Owner:INTEL CORP

Storage device including replay protected memory block (RPMB) host device accessing the RPMB, electronic device including storage device and host device, and method of operating the same

Storage devices, host devices and electronic devices are disclosed. In an embodiment of the disclosed technology, an electronic device providing an improved security function may include a storage device including a replay protected memory block (RPMB), and a host device configured to provide a command protocol information unit (PIU) instructing the storage device to access the RPMB. The command PIU may include a basic header segment including a total extra header segment length field having a value other than 0 and an extra header segment including a host RPMB message.
Owner:SK HYNIX INC

Machine learning attack resistant strong physical unclonable circuit

The invention provides a strong physical unclonable circuit resistant to machine learning attacks, and relates to the technical field of information security and communication. The circuit generates an excitation signal through an external pulse signal generator; outputting a first response signal according to the challenge signal through a first confusion vector circuit; outputting a second response signal according to the challenge signal through a second confusion vector circuit; performing linear confusion on the first response signal and the second response signal through a chained block confusion circuit to generate a challenge signal; and finally, performing nonlinear confusion on the first response signal and the second response signal through a gating circuit, and outputting a target response signal. According to the strong physical unclonable circuit resisting the machine learning attack provided by the invention, the security of identity authentication between equipment is improved under the condition that a large amount of hardware resource overhead is not increased.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Anti-quantum certificate signature verification method and device, equipment and storage medium

The invention discloses an anti-quantum certificate signature verification method, which comprises the following steps: signing and issuing a traditional certificate to a certificate issuing mechanism, and carrying out abstract operation processing on a serial number of the traditional certificate to obtain an abstract of the traditional certificate; issuing an anti-quantum certificate to a certificate issuing mechanism, and adding the abstract of the traditional certificate into an extension item of the anti-quantum certificate, so that the anti-quantum certificate is bound with the traditional certificate; when the security of the certificate needs to be verified in the interaction process with other application systems, performing signature verification processing on the traditional certificate; and after the signature verification of the traditional certificate is passed, carrying out signature verification processing on the countermeasure quantum certificate, and if the verification is passed, considering the certificate as a trusted certificate. The invention further discloses a device for implementing the anti-quantum certificate signature verification method, computer equipment and a storage medium. According to the method, the potential risk that a traditional digital certificate is attacked by quantum during use can be well solved, and the security of the certificate is greatly improved.
Owner:KOAL SOFTWARE CO LTD

Lightweight, blockchain-based reputation system for unmanned aerial vehicle networks

A system includes: one or more each of UAVs; UAV service requestors; UAV service providers; and ground stations. Using an identity authentication module, a reputation system module, and a blockchain fabric module, the UAVs, the UAV service requestors, the UAV service providers, and the ground stations are capable of sending and receiving electronic data via one or more remote connections, the identity authentication module identifies and authenticates UAVs such that only verified and authenticated UAVs can access the UAV network; the reputation system module evaluates and maintains a reputation of the UAV service requestors and the UAV service providers and assigns a reputation; and the blockchain fabric module implements a blockchain with respect to the UAV network to securely record flight data of the UAVs on the UAV network, which flight data includes one or more of a location, altitude, and one or more mission parameters of the UAV.
Owner:THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE