Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1068results about "Cryptographic attack countermeasures" patented technology

System and Methods for Adaptive Edge-Cloud Processing with Dynamic Task Distribution and Migration

A system and method for adaptive edge-cloud data processing dynamically distributes computational tasks between edge devices and cloud infrastructure in response to changing conditions. The system continuously monitors resource availability, network parameters, and workload characteristics while predicting future conditions using hierarchical forecasting models. A multi-objective optimization approach determines optimal task distribution, balancing processing latency, energy consumption, bandwidth utilization, and result quality. The system implements a partitionable processing pipeline that enables seamless task migration through state synchronization protocols and checkpoint mechanisms. During migration, the system preserves processing continuity by establishing dependencies, creating execution checkpoints, and verifying successful state transfer. Performance metrics may be continuously collected and analyzed to improve future decision-making. The system maintains operational resilience during connectivity disruptions through local decision-making capabilities and eventual consistency protocols, making it suitable for diverse applications including industrial IoT, connected vehicles, healthcare wearables, and smart city infrastructure.
Owner:ATOMBEAM TECH INC

Data access authority control method and system based on block chain

The invention discloses a data access permission control method and system based on a block chain, and relates to the technical field of block chains, the system is composed of a plurality of function modules, and the system comprises a hierarchical permission module which adopts a role hierarchical strategy and defines the access granularity of a role through an intelligent contract; the dynamic permission adjustment module is used for dynamically adjusting the permission range by analyzing user behaviors in real time through machine learning according to the principle of following the minimum permission in the permission distribution process; attribute encryption and zero-knowledge proof are introduced, an access key is dynamically generated according to user attributes, and sensitive information is hidden in the verification process; the multi-chain collaboration module is used for coding an intelligent contract through an authority rule, automatically executing access request verification, storing encrypted data through a private chain, managing an index and an access strategy through an alliance chain, isolating a storage domain from an access domain, and carrying out process traceability on a data request through a cross-chain verification mechanism; and the key management module is used for generating a true random number private key by adopting a hardware security unit.
Owner:WUHAN SPARK ZHONGDA INFORMATION TECH CO LTD

Federal learning system based on multi-key homomorphic encryption and adaptive differential privacy

The invention relates to a federated learning system based on multi-key homomorphic encryption and adaptive differential privacy, and belongs to the technical field of privacy computing. According to the system, on the premise that no trusted third party exists, a multi-client collaborative key generation and threshold decryption mechanism is achieved, it is ensured that model parameters are always in an encrypted state in the aggregation process, and leakage of a single node is prevented. By introducing a parameter sensitivity analysis and selective encryption strategy, the system only encrypts high-risk parameters, and the encryption burden is effectively reduced. Meanwhile, in combination with an adaptive privacy budget allocation mechanism, the system dynamically adjusts noise intensity according to a model training state, and model performance and convergence speed are maintained while privacy protection capability is improved. According to the method, high robustness and collusion resistance are realized, stable operation under the condition that part of clients are offline is supported, and the method is suitable for application scenes such as medical treatment and finance with high data sensitivity and strict performance requirements.
Owner:FUZHOU UNIV

Multi-party collaborative signature management method and system based on key segmentation technology

The invention discloses a multi-party collaborative signature management method and system based on a key segmentation technology, and relates to the technical field of fragmentation encryption, and the method comprises the steps: initializing data in an encryption system, collecting behavior data when a key anomaly occurs in history, deploying an AI anomaly detection model, generating a master key through a distributed key generation protocol, and generating a multi-party collaborative signature in the encryption system; deriving time by using a hierarchical deterministic algorithm, segmenting a master key to form key fragments, and distributing each fragment to different nodes; formulating a periodic rotation triggering mechanism; calculating an abnormal score of each node, judging whether each node has an abnormal risk or not, and marking the abnormal risk; for the marked nodes with the abnormal risk, fragments are redistributed for alternation; dynamically adjusting the threshold according to the abnormal score; a client initiates a signature request, abnormal nodes are eliminated, fragment node aggregation is screened, and collaborative signature is carried out.
Owner:GLANCE DIGITAL TECH (JIANGSU) CO LTD

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Security guarantee system for cross-domain communication and data sharing of network platform software

The invention relates to the technical field of computer network security, in particular to a security guarantee system for cross-domain communication and data sharing of network platform software, which comprises a data security transmission module, an identity authentication and access control module, an encryption module, a security audit and anomaly detection module and an anti-interference disaster recovery module. According to the invention, through linkage of equipment fingerprint end-to-end encryption, threat adaptive dynamic key updating and a timestamp-random number anti-replay mechanism and AI risk pre-judgment, reinforcement learning path planning, digital twinning pre-verification and fault automatic switching technologies, collaborative guarantee of key security and transmission continuity in cross-domain audio transmission is realized; encryption intensity is dynamically upgraded along with threats, a transmission path is optimized in advance, and it is ensured that the audio stream resists various network attacks and interferences in low-delay transmission.
Owner:ICLOUDSHIELD SECURITY TECHNOLOGY CO LTD

Industrial personal computer data security dynamic protection method and system based on AI edge calculation

The invention belongs to the crossing field of industrial control and edge computing, and particularly relates to an industrial personal computer data security dynamic protection method and system based on AI edge computing. Firstly, industrial control data encryption and standardization preprocessing are achieved through a hardware-level trusted execution environment; secondly, performing real-time anomaly detection on the encrypted data stream based on an AI model, generating a threat score by combining industrial control protocol feature analysis, and forming an edge layer intelligent detection capability; the authentication mode is dynamically switched based on the threat score, and self-adaptive strategy adjustment is realized in a fog layer; then optimizing edge resource allocation according to the threat index and the equipment load, and constructing a cloud elastic scheduling mechanism; and finally, a security system covering data encryption, real-time detection, dynamic protection and resource optimization is formed through grading component cooperation, and the method is suitable for real-time threat detection and self-adaptive response in an industrial internet scene.
Owner:GUANGZHOU SPECIAL CONTROL ELECTRONIC IND CO LTD

Dynamic access control management method and system based on zero-trust architecture

The invention provides a dynamic access control management method and system based on a zero-trust architecture. The method comprises the following steps: acquiring original feature data, constructing feature data, distributing a label for the feature data, generating an identity chain based on the feature data and the label, performing encrypted signature and authentication on the identity chain, and acquiring an initial authentication result set; performing sample attack resistance on the initial authentication result set so as to increase the detection capability of the authentication result set and prevent fake identity attack, and generating a final authentication result set; obtaining the user identity credibility based on the authentication result set, obtaining resource information of the user request, dynamically adjusting the access permission of the user request based on the user identity credibility, and outputting the user access permission; and performing identity chain monitoring in real time, updating the access authority through an identity credibility updating model according to the dynamically calculated user identity credibility and the real-time access record, and triggering further security measures or authority adjustment through anomaly detection.
Owner:GUANGDONG LINGBU INFORMATION TECHNOLOGY CO LTD

Adaptive Data Processing System with Real-Time Anomaly Detection and Self-Healing

A system and method for adaptive data processing combining compression and encryption. The system analyzes input data characteristics, compares probability distributions, and creates a transformation matrix to convert data into a dyadic distribution. It generates a main data stream of transformed data and a secondary stream of transformation information. The system dynamically selects and applies processing techniques, including transformation, encoding, compression, and encryption algorithms, based on analyzed characteristics and real-time performance metrics. It compresses the main data stream using Huffman coding and implements security measures to protect the output. A feedback loop monitors technique effectiveness, updates a knowledge base, and influences future selections. The system can operate in lossless, lossy, or modified lossless modes, adapting to different application requirements. This approach offers an efficient solution for scenarios where both data reduction and security are critical concerns.
Owner:ATOMBEAM TECH INC

Decentralized network access authority management system based on block chain

The invention relates to the technical field of block chain security, and discloses a decentralized network access authority management system based on a block chain, and the system comprises a data collection module which is used for collecting and preprocessing multi-dimensional attribute data, and then outputting the data to a dynamic tensor processing module; the dynamic tensor processing module receives the data of the data acquisition module, constructs a three-dimensional attribute tensor and is used for executing dynamic rank decomposition and then outputting a nuclear tensor to the strategy generation module; and the strategy generation module is connected with the dynamic tensor processing module and the cross-chain synchronization module and is used for generating an access control strategy matrix based on the kernel tensor. A dynamic strategy matrix with environment perception capability is constructed by fusing real-time network situation data and a global reference strategy generated by federal learning, and balance optimization of a local strategy and a network consensus is realized by adopting a gradient correction fusion algorithm, so that the problem that a traditional static strategy is difficult to cope with complex network environment changes is solved.
Owner:NINGXIA VOCATIONAL & TECH COLLEGE (NINGXIA OPEN UNIV)

Anti-quantum serial digital certificate implementation method and device, equipment and storage medium

The invention discloses an anti-quantum serial digital certificate implementation method. The method comprises the following steps: generating a traditional cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; submitting a certificate request; splicing the traditional cryptographic algorithm public key and the anti-quantum cryptographic algorithm public key to form a dual-cryptographic algorithm public key, and generating a digital certificate according to the dual-cryptographic algorithm public key; signing the digital certificate by using a traditional cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key; and splicing and combining the traditional cryptographic algorithm signature value and the anti-quantum cryptographic algorithm signature value into a dual-cryptographic algorithm signature value, putting the dual-cryptographic algorithm signature value into a signature value item of the digital certificate, so that the digital certificate forms a hybrid serial digital certificate, and returning the hybrid serial digital certificate to the client. The invention further discloses a device for implementing the quantum serial digital certificate implementation method, computer equipment and a storage medium. According to the method, the problems of poor compatibility, low storage efficiency, slow verification speed and the like of the existing digital certificate under the threat of quantum computing are solved.
Owner:KOAL SOFTWARE CO LTD

Dyadic Distribution-Based Compression and Encryption with Adaptive Transformation Matrix Generation

An adaptive transformation matrix generation is used simultaneous compression and encryption of data. The system continuously monitors input data streams to detect changes in distribution patterns, dynamically updating transformation matrices in response to these changes. Using performance evaluation criteria, the system selects and deploys optimal matrices that maintain both compression efficiency and cryptographic security as data characteristics evolve. The system implements configurable adaptation policies that govern when and how matrices are updated, ensuring system stability while maximizing performance. By employing sliding window analysis and distribution variance metrics, the system can quantify data drift and trigger appropriate adaptations. The system maintains compatibility with various operational modes including lossless, lossy, and modified lossless configurations, applying mode-specific optimization criteria to each scenario. This adaptive approach offers a resilient solution for data transmission and storage scenarios where both data reduction and security must be maintained across diverse and evolving data streams.
Owner:ATOMBEAM TECH INC

Data encryption method for multilevel key stream control in industrial gateway

The invention discloses a data encryption method for multilevel key stream control in an industrial gateway, and particularly relates to the technical field of data encryption and network security. The method comprises the steps of obtaining a session identification code and communication context information; generating a first-level basic key based on the session identification code, and generating a multi-level key stream control matrix in combination with communication context information and a multi-source dynamic random factor; according to the hierarchical relationship of the matrix, key stream sequences of corresponding levels are distributed to data packets of different priorities, and the key stream sequences are switched or combined in real time according to data packet types, transmission paths and security policies in the encryption process, and time fragmentation processing and disturbance coding are executed; the encrypted data packet is sent through a multi-protocol forwarding module of the industrial gateway, and the receiving end carries out decryption by using the key stream control matrix; according to the invention, dynamic generation, hierarchical calling and safe switching of the key stream can be realized, and the data confidentiality, integrity and anti-attack capability of the industrial gateway in a complex network environment are remarkably improved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

Scheduling instruction trusted storage system based on block chain

The invention discloses a block chain-based scheduling instruction trusted storage system, which relates to the technical field of block chains, and comprises a block chain network layer, an instruction acquisition module, an instruction verification module, a cross-chain storage module, a trusted tracing interface, an instruction life cycle management smart contract and a quantum security module, the block chain network layer comprises a plurality of block chain service units deployed at power dispatching nodes, the instruction acquisition module is used for acquiring a dispatching instruction data set and an associated digital signature generated by a dispatching terminal, and the instruction verification module is configured with a compliance verification rule base and multi-level verification logic. And the cross-chain storage module realizes a sub-chain storage architecture of scheduling instruction metadata and content data. According to the method, a double-chain architecture in which a metadata chain and a content chain are separated is adopted, and an improved Merkletree cross-chain verification technology is combined, so that on the premise of ensuring data privacy, cross-regional instruction synchronization delay is reduced, and meanwhile, fine-grained access control of sensitive instruction content is realized.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Cryptographic system for post-quantum cryptographic operations

Certain examples described herein relate to at least a cryptographic system and a method of operating a cryptographic system. The cryptographic system may be implemented as a co-processor for performing post-quantum cryptographic functions. The cryptographic system has a set of bus interfaces for coupling to an external computing system, a cryptographic math unit and a control unit. The cryptographic math unit in certain examples is adapted to provide one or more masked modes of operation that secure the cryptographic operations against side-channel and non-invasive attacks. The method of operating a cryptographic system involves annotating secret data and tracking those annotations through one or more arithmetic operations.
Owner:PQSHIELD LTD

Secure data transmission method for wireless communication system

The invention discloses a secure data transmission method for a wireless communication system, which relates to the technical field of secure data transmission and comprises three steps of key generation and synchronization, physical layer subcarrier encryption and key enhancement and authentication. The method comprises the following steps: firstly, extracting multi-dimensional features through channel detection to generate a dynamic initial key, and setting a trigger condition to realize key synchronization; then, a permutation matrix is generated by using a secret key to perform scrambling encryption on a data subcarrier position, and a receiving end performs descrambling and then performs feedback through CRC verification so as to guarantee data integrity; and finally, quantum noise is introduced to enhance the randomness of the secret key, and zero-knowledge authentication is adopted to verify the identity, so that the security and the anti-attack capability of wireless communication data transmission are effectively improved.
Owner:SHENZHEN XIAOPAN TECHNOLOGY CO LTD

System and method for detecting cybersecurity vulnerabilities via device attribute resolution

A system and method for vulnerability detection. A method includes: tokenizing device attribute data for a device into at least one set of first tokens, wherein each of the first tokens is formatted according to a token schema; creating at least one device attribute string, each device attribute string including one of the first tokens; matching each of the at least one device attribute string to combinations of device attributes stored in a vulnerabilities database in order to identify at least one matching combination of device attributes for the device, wherein the vulnerabilities database stores mappings between combinations of device attributes and vulnerabilities, wherein each combination of device attributes in the vulnerabilities database includes second tokens formatted according to the token schema; detecting at least one vulnerability of the device based on the at least one matching combination of device attributes and the mappings in the vulnerabilities database.
Owner:ARMIS SECURITY LTD

ARM-based embedded image decoding display system

The invention discloses an embedded image decoding display system based on an ARM, and relates to the technical field of computers, and the system comprises a dynamic sensing module which is used for monitoring the CPU occupancy rate, the cache hit rate and the memory bandwidth utilization rate of an ARM processor in real time, establishing a three-dimensional resource vector containing a dynamic weight coefficient, and calculating a threshold boundary; the adaptive decoding engine comprises an optimization unit which is used for reconstructing a bit stream processing channel and a register data exchange mechanism based on an SIMD expansion instruction of an ARMv8.2 instruction set; the prediction unit is used for predicting instruction-level hotspot distribution of the decoding task by adopting a TinyLSTM model and generating an instruction transmitting strategy; the hardware optimization module is used for executing a heterogeneous collaboration strategy of the NEON coprocessor and the MaliGPU, and the heterogeneous collaboration strategy comprises the following steps: dividing DCT / IDCT (discrete cosine transform / inverse discrete cosine transform) calculation granularity; determining a mixing precision conversion assembly line of the GPU shader according to the color gamut of the display equipment; and the display driving module is used for implementing a decoding parameter dynamic confusion algorithm in the security domain and forming a tamper-proof closed loop with the optimization unit.
Owner:TRONLONG

Key verification methods, key acquisition method, and devices

A verification device receives first information. The first information includes a key negotiation parameter of a first terminal, ciphertext information and zero-knowledge proof information. The ciphertext information is derived based on a public key of a supervisory device, a communication key determined by negotiation between the first terminal and a second terminal, and a first random number generated by the first terminal. The zero-knowledge proof information includes first proof information and / or second proof information, the first proof information is determined based on the ciphertext information, and the second proof information is determined based on the ciphertext information and / or the key negotiation parameter. The first proof information is used for verifying whether a private key of the supervisory device is capable of decrypting the ciphertext information, and the second proof information is used for verifying whether a key decrypted in the ciphertext information is the communication key.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Novel ARE cryptosystem of infinite dimension key space for resisting ADC attack on finite dimension cryptosystem

Due to the appearance of dynamic structured mathematics responded by a global coupling structure, a great threat is generated to a traditional password system represented by AES-256 and information security. Most of current mainstream symmetric cryptographic systems such as AES and post-quantum encryption candidate schemes are based on discrete key space and structure modeling operation, the security of the current mainstream symmetric cryptographic systems depends on exhaustion infeasibility or mathematical difficulty complexity, and the current mainstream symmetric cryptographic systems and post-quantum encryption candidate schemes are difficult to resist attacks of adaptive dynamic coupling such as ADC. Therefore, the invention provides a novel ARE encryption system which is constructed by taking'non-modeling property 'as a core principle. A system key is generated by a non-numerable dimension perturbation function, has unique attributes of no structure, non-derivation, non-periodicity and the like, and is combined with an encryption method of a key function which cannot be covered, physical noise perturbation and a quantum random source to construct a new generation of ARE password architecture; the method has the capability of being incapable of being deduced, reduced in order, incapable of being converged to a key space and extremely high in structural modeling attack resistance, any analyzable optimization path can be blocked from the source, and it is ensured that ADC evolution attacks are completely resisted.
Owner:李海全

SM4 hardware acceleration and anti-side channel protection method and system for domestic FPGA

The invention relates to the technical field of FPGA architecture, in particular to an SM4 hardware acceleration and anti-side-channel protection method and system of a domestic FPGA, which comprises the following steps of: performing data type identification operation on bright-ciphertext batch data by utilizing an acceleration block to obtain a data type, and according to a pre-constructed parallelization strategy and the data type, performing data type identification operation on the SM4 hardware acceleration and anti-side-channel protection on the SM4 hardware acceleration and anti-side-channel protection on the SM4 hardware acceleration and anti-side-channel protection system; performing dynamic resource configuration on the plaintext-ciphertext batch data to obtain resource configuration information, and performing configuration according to the resource configuration information, the key-mode parameter and the dynamic control instruction to obtain a configured SM4 algorithm; according to the configured SM4 algorithm, performing encryption processing on the plaintext-ciphertext batch data to obtain to-be-protected encrypted data; and performing protection operation based on physical layer leakage suppression, logic layer confusion association and system layer dynamic response on key-mode parameters, dynamic control instructions, plaintext-ciphertext batch data and encryption processing by using the protection block, and converting to-be-protected encrypted data into protected encrypted data. According to the invention, the encryption processing performance and security can be improved.
Owner:JINAN UNIVERSITY

Federal identity authentication method fusing mouse behavior modeling and adaptive differential privacy

The invention relates to the technical field of identity authentication, in particular to a federated identity authentication method fusing mouse behavior modeling and self-adaptive differential privacy, which comprises the following steps: building a federated learning framework; an authentication problem is converted into a time sequence behavior modeling task; updating model parameters by each client, and calculating local gradient information of the current round; cutting the local gradient information; the privacy budget is dynamically distributed; gaussian noise is added to the cut local gradient information; the central server aggregates the disturbed local model parameters to obtain new global model parameters; when the model reaches the preset convergence standard or the maximum round limit after multiple communication rounds, training is ended, a global model terminal is deployed, mouse behavior modeling and a federal learning mechanism are combined, the collection requirement for original user data is avoided, the leakage risk of sensitive data in the transmission and storage process is fundamentally reduced, and the user experience is improved. And the data security and the privacy protection capability are improved.
Owner:GUILIN UNIV OF ELECTRONIC TECH +2

Cloud face authentication method and device based on RNS-CKKS encryption and cosine similarity, and storage medium

The invention discloses a cloud face authentication method and device based on RNS-CKKS encryption and cosine similarity and a storage medium. A user initiates an authentication request, a client obtains and preprocesses a face image, extracts a feature vector and performs modular length normalization; the cloud server generates a random number and sends the random number to the client, and the client adds noise to a feature value by adopting a differential privacy technology, carries out Hadamard product operation, carries out homomorphic encryption on the feature by using an RNS-CKKS scheme and sends a ciphertext to the cloud server; the cloud server receives the ciphertext, encrypts the face feature template by using an RNS-CKKS scheme, calculates cosine similarity, ensures the correctness of a calculation result by using a Plonk protocol, and transmits a similarity ciphertext back to the client; and the client decrypts the similarity ciphertext and compares the similarity ciphertext with a set threshold value to obtain a user identity authentication result. According to the scheme, by combining differential privacy, zero-knowledge proof and homomorphic encryption technologies, privacy protection is enhanced, the recognition accuracy is improved, and user information leakage is effectively prevented.
Owner:JIANGSU UNIV

Encryption device and authentication method and signature generating method of system including the same

The present disclosure relates to methods, devices, and systems for generating a signature of a message by a first device based on a secret key and a public key. The method includes generating a first parameter based on a first multiplication operation on the secret key and a first random number. The method further includes generating a first electronic signature based on the first parameter and the public key. The method further includes generating a second parameter based on the first random number, a second random number, and the message. The method further includes generating a second electronic signature based on the first parameter, the second parameter, the second random number, and the first electronic signature. The method further includes outputting, to a second device, the message, the first electronic signature, and the second electronic signature.
Owner:SAMSUNG ELECTRONICS CO LTD

Side channel analysis method and device based on feature coding convolutional neural network

The invention provides a side channel analysis method and device based on a feature coding convolutional neural network, equipment and a medium. The method comprises the following steps: acquiring side channel energy trace data of target equipment; a pre-trained first neural network model is utilized to perform feature coding and decoding on the energy trace data to obtain coding features, and the first neural network model comprises a feature head coder and a feature head decoder; inputting the encoding features into a feature head encoder of a second neural network model, performing multi-scale feature fusion through a classification sub-model of the second neural network model, dynamically weighting the encoding features by using an attention mechanism, and extracting target leakage features; calculating guess probability distribution of each candidate key based on the target leakage characteristics; and determining a target key of the target device from the candidate keys based on the guess probability distribution.
Owner:INST OF SEMICONDUCTORS - CHINESE ACAD OF SCI

Protection of transformations by intermediate randomization in cryptographic operations

Aspects of the present disclosure involve a method and a system to perform a cryptographic operation that involves a number theoretic transformation of a first vector to a second vector by obtaining components of the first vector, performing a plurality of iterations that each include determining a plurality of output values, wherein each of the plurality of output values is a linear combination of two or more input values, the input values into a first iteration being the components of the first vector and the output values of the last iteration being representative of components of the second vector, and wherein one or more of the output values of at least one iteration are randomized by multiplying at least one input value by a random number, and determining, based on the output values of the last of the plurality of iterations, the components of the second vector.
Owner:CRYPTOGRAPHY RESEARCH INC

Efficient lattice cipher analysis system and method based on dynamic chaos control and quantum noise resistance

The invention discloses an efficient lattice cryptographic analysis system and method based on dynamic chaos control and quantum noise resistance. The efficient lattice cryptographic analysis system comprises a chaos control module, a mixed precision projection module, a quantum noise resistance module, a distributed architecture, a dimension compression calculator, a distributed task scheduler, a parallel execution unit, a load balancer and a result verifier. According to the efficient lattice cryptographic analysis system and method based on dynamic chaos control and quantum noise resistance, the calculation efficiency, quantum resistance and hardware adaptability of lattice cryptographic analysis are remarkably improved, and the system and method are suitable for financial audit, Internet of Things authentication, block chain security and other high-dimensional lattice reduction and quantum attack defense scenes.
Owner:杨永夏

Fusion quantum security communication method of NAT gateway

The invention discloses a fusion quantum secure communication method of an NAT gateway, and relates to the technical field of communication network information security and quantum information. Comprising the steps of 1, creating a fusion quantum security communication system of an NAT gateway, 2, adopting a quantum hybrid encryption architecture through a quantum security module, and internally arranging a quantum key distribution unit and an anti-quantum computing acceleration chipset, 3, expanding a quintuple mapping structure of NAT through a dynamic address mapping and quantum encryption module, newly adding a quantum security dimension field QSV, and carrying out quantum encryption on the quantum key distribution unit and the anti-quantum computing acceleration chipset. And 4, developing a protocol non-inductive conversion engine through a hybrid protocol stack cooperation module, supporting an IPv4 / IPv6 dual-stack quantum tunnel and a quantum key inheritance protocol to realize cross-protocol family encryption parameter migration, dynamically adjusting a quantum encapsulation mode in an address conversion process, and dynamically associating an internal network address port with a quantum key parameter and a channel fingerprint feature. And 5, constructing a quantum perception type session state machine through an anti-quantum attack session management module, and performing a joint decision-making mechanism through quantum entanglement state monitoring and classical traffic feature analysis.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD