Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Attribute-based encryption" patented technology

Attribute-based encryption is a type of public-key encryption in which the secret key of a user and the ciphertext are dependent upon attributes (e.g. the country in which he lives, or the kind of subscription he has). In such a system, the decryption of a ciphertext is possible only if the set of attributes of the user key matches the attributes of the ciphertext.

Zero-trust multi-party security data exchange method

The invention relates to the technical field of network and information security, in particular to a zero-trust multi-party security data exchange method, which comprises the following steps of: generating a zero-trust token and a capability authorization bill and constructing context description data; authentication encryption is performed on the plaintext fragment, attribute-based encryption is performed on the data one-time key, and a policy bearing ciphertext container is assembled; in the trusted execution environment, authentication decryption is completed through a one-time secret key of data recovery through joint challenge and threshold deblocking, or strategy migration and transfer are achieved through proxy re-encryption; and aggregating the decryption event and the forwarding event by vector commitment, generating a time anchor, and mapping the time anchor into a next round of random base. According to the invention, fine-grained authorization of the key layer, no plaintext transfer, event-level verifiable auditing and rapid revocation are realized.
Owner:杭州市余杭区巡察保障中心

Engineering building BIM data safety management method

ActiveCN121093370ADigital data protectionAttribute-based encryptionAnomaly detection
The invention discloses an engineering building BIM (Building Information Modeling) data security management method, which comprises the following steps of: 1, embedding authority parameters into BIM model metadata through an attribute-based encryption algorithm; 2, deploying a permission management smart contract in an alliance chain, when project management triggers a stage change event, automatically calling the permission matrix generated in the step 1 by the smart contract, calling a BIMBase platform API to obtain a latest model version, recalculating the permission matrix, verifying the identity of an operator, and distributing an encrypted new permission set to related nodes; 3, constructing an auditing module containing a three-party alliance chain, and performing auditing confirmation within 5 seconds by adopting an improved PBFT consensus algorithm; a BIM event log visual interface is developed, and multi-dimensional retrieval according to roles, time and operation types is supported; 4, constructing an anomaly detection module of the LSTM-CNN hybrid model; constructing a normal behavior baseline model through transfer learning; when continuous three times of baseline deviation operation are detected, the module automatically triggers a three-level response mechanism.
Owner:SICHUAN TECH & BUSINESS UNIV

Attribute-based encryption system for selective document security

The present disclosure provides a method for selectively encrypting and decrypting portions of a document. The method includes receiving a document containing plaintext, analyzing the document using an artificial intelligence system to identify portions containing sensitive information, assigning predefined security levels or attributes to the identified portions, sending an encrypt file content request to a cryptographic engine, receiving an encrypted file content response, building an encrypted document by replacing portions with masking symbols and storing encrypted portions as metadata, and sending the encrypted document to a client device. The artificial intelligence system uses machine learning models trained on domain-specific data and employs pattern recognition and contextual analysis to identify sensitive content based on semantic understanding and classification rules.
Owner:NTT RESEARCH INC

Lightweight block chain encryption method based on hybrid encryption

InactiveCN120934809AKey distribution for secure communicationMultiple keys/algorithms usageAttribute-based encryptionDigital Signature Algorithm
The invention relates to the technical field of block chains, in particular to a lightweight block chain encryption method based on hybrid encryption, and the method comprises the following steps: S1, carrying out the encryption of transaction data in a block chain through employing a lightweight symmetric encryption algorithm, and generating encrypted transaction data; s2, using an asymmetric encryption algorithm and an anti-quantum encryption algorithm to cooperatively encrypt a key of the lightweight symmetric encryption algorithm in the S1 to generate an encrypted key; s3, carrying out signature processing on the encrypted transaction data and the encryption key by adopting a lightweight digital signature algorithm to generate signature information; and S4, setting access authority for the encrypted transaction data by adopting an attribute-based encryption algorithm. According to the invention, the transaction data is encrypted by adopting the lightweight symmetric encryption algorithm, so that the problem that the application is limited in the resource limited scene such as lightweight equipment due to the fact that most of the traditional block chain encryption methods adopt a single encryption mechanism is solved.
Owner:QINGDAO MEIYANG DATA TECHNOLOGY CO LTD

Information disclosure method, information disclosure system, transmission terminal, and verification terminal

PCT designated stageWO2025248577A1Public key for secure communicationInternet privacyAttribute-based encryption
Provided is an information disclosure method for disclosing transaction information in an information disclosure system that includes a transmission terminal and a verification terminal, wherein the information disclosure method includes: an encrypted VC generation step in which the transmission terminal generates an encrypted item, from a transaction VC which includes items (hereinafter referred to as transaction items) related to one or more pieces of transaction information, by using an encryption key of an attribute-based encryption for each transaction item to encrypt the transaction item and a conditional expression input by a sender with respect to said transaction item, and generates an encrypted VC which includes one or more encrypted items; and an encrypted VC decryption step in which the verification terminal generates a decrypted VC by using a decryption key of the attribute-based encryption to decrypt each encrypted item included in the encrypted VC. In the encrypted VC decryption step, if attribute information included in the decryption key for each encrypted item satisfies the conditional expression included in the relevant encrypted item, a transaction item corresponding to the encrypted item is acquired, and a decrypted VC which includes the acquired transaction item is generated.
Owner:NT T INC

Real-time IoT data sharing system supporting attribute-based access control and method thereof

An IoT device according to an embodiment encrypts IoT data using a peripheral device and transmits the IoT data to a server, and a user device requests and obtains necessary IoT data from the server, thereby achieving real-time IoT data sharing. The IoT device performs only relatively low-performance operation of attribute-based encryption to encrypt IoT data collected through a sensor and outsources the remaining high-performance operations of attribute-based encryption to the peripheral device providing external communication network connection to the IoT device to generate a final ciphertext. A user device generates an attribute bloom filter using an access policy thereof, requests and obtains IoT data encrypted according to attribute-based encryption. A cloud server receives and stores IoT data encrypted by the IoT device and the peripheral device according to attribute-based encryption and transmits IoT data retrieved using the attribute bloom filter as a query to the user device.
Owner:DAEGU GYEONGBUK INSTITUTE OF SCIENCE AND TECHNOLOGY +1

Zero trust multi-party secure data exchange method

The present application relates to the technical field of network and information security, and particularly relates to a zero-trust multi-party secure data exchange method, which comprises the following steps: generating a zero-trust token and a capability authorization ticket and constructing context description data; performing authentication encryption on plaintext fragments and performing attribute-based encryption on data one-time keys to assemble a policy-carrying ciphertext container; in a trusted execution environment, recovering the data one-time key through joint challenge and threshold unsealing to complete authentication decryption, or realizing policy migration and transfer through proxy re-encryption; and aggregating the decryption and transfer events into a vector commitment and generating a time anchor, which is mapped into a next round of random base. The present application realizes fine-grained authorization at the key layer, plaintext-free transfer, event-level verifiable audit and fast revocation.
Owner:杭州市余杭区巡察保障中心

A method for access control with distinguished permissions based on attribute-based encryption

The application relates to a kind of attribute-based encryption-based differentiated permission access control methods, and belongs to the field of attribute cryptography and access control technology.The application adopts hybrid encryption mechanism, encrypts shared data using symmetric encryption system, and encrypts symmetric key using attribute-based encryption system, and only when the key associated attributes of a user meet the access control policy, the user can decrypt to obtain the symmetric key, and then decrypt to obtain the shared data plaintext using the symmetric key.In order to ensure the integrity and non-repudiation of shared data, the private key of the data owner is used for signing while the data owner generates the ciphertext.By using symmetric encryption mechanism and attribute-based encryption system, attribute-based, fine-grained permission control is realized, and the encryption and decryption efficiency of data is ensured.
Owner:BEIJING INST OF COMP TECH & APPL

Data distribution system, data distribution method, and data distribution program

PendingUS20260067074A1Key distribution for secure communicationAttribute-based encryptionDistribution method
A data distribution system that distributes an encrypted data from a transmitting device to a receiving device via a relay device with support by a key issuing device, wherein the key issuing device is configured to generate public parameters for ElGamal encryption and a secret key for attribute-based encryption, send the public parameters to the transmitting device and keep the secret key; and the transmitting device is configured to encrypt data by the public parameters, create a user defined policy for each data ID, attach the defined policy for the corresponding data ID to the encrypted data and send the encrypted data with the user defined policy to the relay device.
Owner:NEC CORP

Data distribution system, data distribution method, and data distribution program

PendingJP2026044418AKey distribution for secure communicationAttribute-based encryptionDistribution method
The workload on the data transmission device is reduced. [Solution] A data distribution system that distributes encrypted data from a transmitting device to a receiving device via a relay device with the support of a key issuing device, wherein the key issuing device is configured to generate public parameters for ElGamal encryption and a private key for attribute-based encryption, transmit the public parameters to the transmitting device, and retain the private key, and the transmitting device is configured to encrypt data using the public parameters, create a user-defined policy for each data ID, attach the policy defined for the corresponding data ID to the encrypted data, and transmit the encrypted data together with the user-defined policy to the relay device.
Owner:NEC CORP

An engineering building BIM data security management method

ActiveCN121093370BDigital data protectionAttribute-based encryptionAnomaly detection
The application discloses an engineering building BIM data security management method, comprising the following steps: step one: embedding a permission parameter into BIM model metadata through an attribute-based encryption algorithm; step two: deploying a permission management smart contract on a consortium chain, when a project management triggers a phase change event, the smart contract automatically calls the permission matrix generated in step one, calls a BIMBase platform API to obtain the latest model version, recalculates the permission matrix, verifies the identity of an operation party, and distributes the encrypted new permission set to relevant nodes; step three: building a three-party consortium chain audit module and adopting an improved PBFT consensus algorithm to perform audit confirmation within 5 seconds; developing a BIM event log visualization interface, and supporting multi-dimensional retrieval according to roles, time and operation types; and step four: building an abnormality detection module of an LSTM-CNN hybrid model; building a normal behavior baseline model through transfer learning; when it is detected that an operation deviates from the baseline for three times in succession, the module automatically triggers a three-level response mechanism.
Owner:SICHUAN TECH & BUSINESS UNIV

Encryption apparatus, decryption apparatus, decryption-possible verification apparatus, cryptosystem, encryption method, and computer readable medium

An encryption unit (403) that an encryption apparatus (400) includes, when a user secret key SKΓ is generated using a secret key MSK of attribute based encryption and a set of attributes Γ corresponding to a decryption-possible condition L, generates a key K and a ciphertext P corresponding to the key K by encrypting the decryption-possible condition L using, as an encryption key of the attribute based encryption, a key PK consisting of a public key MPK corresponding to the secret key MSK and a public key PQCPK of post quantum cryptography, regards a part of the ciphertext P where the decryption-possible condition L is encrypted based on a secret value as P-D, regards a part of the ciphertext P where the secret value that is shared is encrypted as P-SS, and generates K′ and P′-D by randomizing each of the key K and the P-D using a random number R, and generates a ciphertext C by encrypting data consisting of the P-D and the random number R using the public key PQCPK. Here, the P-SS, the P′-D, and the K′ are decryption-possible verification parameters corresponding to the user secret key SKΓ.
Owner:MITSUBISHI ELECTRIC CORP

Encryption and decryption method and device for multi-modal data such as voice text

The invention relates to the technical field of information security, in particular to a voice text and other multi-mode data encryption and decryption method and device. The method comprises the following steps: decomposing a medical record containing multiple data types into independent composition modes; for each mode, using a unique and disposable symmetric key to encrypt large-volume data of the mode through a symmetric algorithm; defining an independent attribute-based access strategy for each mode, and encrypting a corresponding symmetric key by using a ciphertext strategy based on an attribute-based encryption scheme; and packaging the symmetric ciphertexts of all the modes and the corresponding encrypted symmetric keys into a structured multi-mode encryption container. The apparatus includes a plurality of functional modules for performing encryption and decryption steps. According to the scheme, the user can only decrypt the symmetric key corresponding to the data mode of which the authority meets the access strategy by virtue of the attribute private key, so that the problems of coarse access control granularity, high calculation overhead and easiness in leakage of strategy privacy in the prior art can be effectively solved.
Owner:MINIMALIST INTERNET (BEIJING) INFORMATION TECHNOLOGY CO LTD

Data sovereignty gateway for telemetry signals

PCT designated stageWO2026069060A1Multiple keys/algorithms usageUser identity/authority verificationAttribute-based encryptionCiphertext
A method, system, and computer program product are configured to: receive a telemetry message in a telemetry pipeline; determine a classification of the telemetry message; select, based on the classification of the telemetry message, an attribute-based encryption (ABE) ciphertext from plural different ABE ciphertexts, wherein each respective one of the plural different ABE ciphertexts is encoded with a respective data sovereignty policy; attach the ABE ciphertext to the telemetry message; and forward the telemetry message with the ABE ciphertext to a data sovereignty gateway.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

Attribute-based encryption for selective document content protection

ActiveEP4557144C0Attribute-based encryptionDocumentation
Owner:NTT DATA SERVICES FEDERAL GOVERNMENT LLC +2

Electronic license security protection method and system based on block chain, and storage medium

The invention discloses an electronic license security protection method and system based on a block chain, and a storage medium, and belongs to the field of electronic license security. According to the method, an attribute-based encryption technology is utilized for privacy protection of the electronic license, good access control is provided for an electronic license library, meanwhile, indexes are stored by utilizing a block chain technology, sharing and acquisition of data are realized by utilizing an intelligent contract, user revocation is realized by changing version permission, and the privacy of the user is effectively prevented from being leaked; the electronic certificate credibility verification is combined with a cryptographic algorithm and a high-robustness watermarking algorithm, an electronic certificate sharing certificate storage process is designed, an electronic certificate credibility verification framework is constructed, and three-party credibility verification of the electronic certificate is ensured.
Owner:SKILL TRAINING CENT OF STATE GRID JIANGSU ELECTRIC POWER CO LTD

Access control and protection of telemetry signals using attribute-based encryption

A system, method and computer program product are configured to: receive, at a telemetry backend, a request for telemetry data from a user, the request including an attribute-based encryption (ABE) ciphertext associated with the user; attempt to decrypt the ABE ciphertext using plural different ABE decryption keys; successfully decrypt the ABE ciphertext using a respective one of the plural different ABE decryption keys; and based on the successfully decrypting the ABE ciphertext using the respective one of the plural different ABE decryption keys, provide the user with access to telemetry data stored in a respective one of plural storage partitions associated with the respective one of the plural different ABE decryption keys, wherein the telemetry data stored in the respective one of plural storage partitions includes the telemetry data requested by the user.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Cross-chain data transmission method and system

The application discloses a cross-chain data transmission method and system, relates to the technical field of blockchains, and applies to a data possession end. The method comprises the following steps: generating a corresponding linear key matrix according to an access strategy of each attribute; encrypting to-be-transmitted data according to a security vector set and the linear key matrix to obtain target encrypted ciphertext; sending the target encrypted ciphertext to a main chain, and storing the target encrypted ciphertext to a target storage position through the main chain, so that a data user end obtains the target encrypted ciphertext through a relay chain and a parallel chain. The blockchains in the data transmission system are divided into the main chain, the parallel chain and the relay chain. Then, data is stored on a distributed storage network. Finally, an attribute-based encryption algorithm is used to resist quantum attacks and ensure the safety of data in the transmission process, so that the overall execution efficiency, the computing performance and the system safety of the blockchain network data transmission are improved.
Owner:CHINA MOBILE ZIJIN INNOVATION INST CO LTD +2

Data sovereignty gateway for telemetry signals

PendingUS20260088991A1Key distribution for secure communicationAttribute-based encryptionCiphertext
A method, system, and computer program product are configured to: receive a telemetry message in a telemetry pipeline; determine a classification of the telemetry message; select, based on the classification of the telemetry message, an attribute-based encryption (ABE) ciphertext from plural different ABE ciphertexts, wherein each respective one of the plural different ABE ciphertexts is encoded with a respective data sovereignty policy; attach the ABE ciphertext to the telemetry message; and forward the telemetry message with the ABE ciphertext to a data sovereignty gateway.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Attribute based encryption with bounded collusion resistance

An attribute based encryption system includes a key generator configured to generate a cyclic group (G) having a prime order q; generate an attribute key matrix (M); generate a master public key (MPK) based, at least in part, on the group (G) and (M); generate a master secret key (MSK) based on a first vector s and a second vector t that represent an encryption policy; generate a user secret key based, at least in part, on the MSK and on a set of one or more user attributes; and send the user secret key to a user device, wherein a ciphertext message can be successfully decrypted if a vector y associated with attributes of the user associated with the user secret key is orthogonal to each row of a set of rows of M selected according to a set of authorization attributes used to encrypt the ciphertext message.
Owner:SRI INTERNATIONAL

Defense system for information security of trusted data space

The invention relates to the technical field of information security defense, in particular to a defense system for information security of a trusted data space. The system comprises a data encryption module, an environment verification module, a response execution module, a data use monitoring module and a block chain evidence storage module. According to the data sensitivity and the real-time network delay, the bit number of the security key is dynamically selected, the attribute-based encryption or proxy re-encryption technology is adopted, the data and the executable strategy are packaged into the trusted data unit, when the data reach the edge node, the credibility of the node environment is strictly verified through integrity measurement and remote certification, and the reliability of the node environment is improved. And after the verification is passed, dynamic authorization is performed in combination with a real-time context, the data is decrypted for use, whether to increase or decrease the security key bit is intelligently decided based on the violation frequency and the performance index so as to seek the optimal balance between the security and the performance, and low time delay and high availability can be maintained while the integrity and confidentiality of the data are guaranteed on the whole.
Owner:GUANGZHOU YUANFENG INTELLIGENT TECH CO LTD

Access control and protection of telemetry signals using attribute-based encryption

PCT designated stageWO2026069059A1Multiple keys/algorithms usageDigital data protectionAttribute-based encryptionCiphertext
A system, method and computer program product are configured to: receive, at a telemetry backend, a request for telemetry data from a user, the request including an attribute-based encryption (ABE) ciphertext associated with the user; attempt to decrypt the ABE ciphertext using plural different ABE decryption keys; successfully decrypt the ABE ciphertext using a respective one of the plural different ABE decryption keys; and based on the successfully decrypting the ABE ciphertext using the respective one of the plural different ABE decryption keys, provide the user with access to telemetry data stored in a respective one of plural storage partitions associated with the respective one of the plural different ABE decryption keys, wherein the telemetry data stored in the respective one of plural storage partitions includes the telemetry data requested by the user.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

A searchable registration attribute base encryption method

A searchable registration attribute-based encryption method includes: generating a public reference string using a public reference string generator; users generating their own public and private keys; a key manager collecting and aggregating the public keys of all registered users to generate a unified master public key and auxiliary decryption keys; the data owner encrypting the original data while generating a searchable ciphertext index, uploading it to a cloud server for storage, thus achieving data encryption and searchability; the user generating a search trapdoor based on the keywords to be searched, sending it to the cloud server through a secure channel, with the trapdoor bound to the user's own attributes to ensure fine-grained search permissions; the cloud server verifying whether the user's attributes meet the access policy without decrypting the data, then performing keyword matching and returning the successfully matched ciphertext; the user using their private key, the ciphertext returned by the cloud server, and the search component to decrypt the ciphertext and recover the original data.
Owner:SHAANXI NORMAL UNIV

Encryption device, decryption device, decryption-possible verification device, cryptosystem, encryption method and encryption program

Encryption device (400), comprising: an encryption unit (403) that is set up when a user secret SKΓ is generated using a secret key MSK of attribute-based encryption and a set of attributes Γ according to a decryption-possible condition L, to generate a key K and a ciphertext P corresponding to key K by encrypting the decryption-possible condition L using attribute-based encryption, where a key PK is used as an encryption key of the attribute-based encryption, consisting of a public key MPK corresponding to the secret key MSK and a public key PQCPK of post-quantum cryptography, to consider a part of the ciphertext P in which the decryption-possible condition L is encrypted on the basis of a secret value as PD and to consider a part of the ciphertext P in which the secret value being shared is encrypted as P-SS, K' and P'-D are generated by randomizing the key K and the PD using a random number R, and to generate a ciphertext C by encrypting data consisting of the PD and the random number R using post-quantum cryptography with the public key PQCPK, wherein The P-SS, P'-D and K' decryption-possible verification parameters correspond to the secret user key SKΓ.
Owner:MITSUBISHI ELECTRIC CORP