Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

142 results about "Authenticated encryption" patented technology

Authenticated encryption (AE) and authenticated encryption with associated data (AEAD) are forms of encryption which simultaneously assure the confidentiality and authenticity of data. These attributes are provided under a single, easy to use programming interface.

Wrapper circuit for providing replay and integrity protection using an encryption algorithm

Authenticated encryption algorithms may function in both a data encryption and authentication operational mode as well as an authentication only operational mode. A first circuit may generate encrypted data and generate a first authentication tag. The first circuit may output for transmission as part of an MPDU, the first authentication tag and either the encrypted data or plaintext data based a control flag. A receiver device may receive the MPDU and a second encryption circuit of the receiver device may receive the first authentication tag and, based on a control flag, receive either the plaintext data or the encrypted data and from the MPDU and generate a second authentication tag by encrypting the plaintext data or decrypting the encrypted data depending on which is received. The second circuit may verify that management frames of the MPDU are valid / have not been tampered with if the first and second authentication tags match.
Owner:INFINEON TECHNOLOGIES AMERICAS CORP

Optical network communication method and communication device

The invention provides an optical network communication method and a communication device, the method is applied to an optical fiber network, the optical fiber network comprises a master device and at least one slave device, and the at least one slave device comprises a first slave device. Wherein in the initialization phase, after receiving the authentication encryption capability of the slave device, the master device can indicate a determined authentication encryption mode (e.g., a first authentication encryption mode) to the slave device, so that the authentication encryption capability of the slave device is enhanced in a subsequent process (e.g., a roaming parameter configuration process). The master device does not need to configure security-related parameters such as an authentication encryption mode for the slave device, so that the configuration efficiency is improved, and the configuration overhead is saved.
Owner:HUAWEI TECH CO LTD

Network security protection system and method based on electric power emergency communication environment

The invention belongs to the technical field of network security, and particularly relates to a network security protection system and method based on an electric power emergency communication environment, and the system comprises a quantum-classical hybrid encryption system which is used for generating a dynamic key in real time; the biological characteristic driven dynamic trust ring is used for equipment identity authentication; the unmanned aerial vehicle relay network protocol is used for data transmission; the secret key after-reading burn-down protocol is used for information secret key after-reading burn-down; a key output by the quantum-classical hybrid encryption system is used for authentication encryption of a biological characteristic driven dynamic trust ring, an unmanned aerial vehicle relay network protocol transmits data encrypted by the quantum key, and a key burn-down protocol is used for reading encrypted data to trigger a key burn-down mechanism. According to the method, the key security is improved, the network attack difficulty is increased, the communication delay in a disaster is reduced, man-in-the-middle capture and attack can be immunized, and the problem of contradiction between the encryption strength and the real-time performance is solved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning

The invention relates to a dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning, and belongs to the technical field of digital content security. The problems of attack resistance, traceability obstruction and key-watermark unhooking in document cross-platform circulation are solved. According to the scheme, the method comprises the following steps of: extracting semantic fingerprints by using a sentence vector model Sentence-BERT; the fuzzy extractor generates a master key and derives a time key chain; the authentication encryption algorithm AEAD encrypts and binds the source and the timestamp load; container layer structure rearrangement and document layer zero-width character double embedding are carried out; the generative adversarial network or diffusion model adversarial training improves the optical character recognition and transcoding resistance; version binding and tracing are achieved through the watermark hash chain. The technical effects cover anti-counterfeiting migration, cross-layer fault-tolerant guarantee recoverability, rearrangement attack resistance, full-period accurate traceability and post-quantum security enhancement.
Owner:SOUTHWEST UNIV

Data writing method, recovery method, and reading method, and corresponding apparatus

Implementations of the present specification provide a data writing, data recovery, and data reading method, and a corresponding secure disk apparatus. The data writing method includes following: User data blocks are first written into a write cache, and a plurality of user data blocks identified by LBAs are read from the write cache under a certain condition. For each user data block, an HBA is allocated to the user data block, authenticated encryption is performed on the user data block to generate an encrypted data block and authentication information, and first metadata corresponding to the user data block is generated, where the first metadata is organized in a form of a KV pair and includes the LBA, the HBA, and the authentication information. A plurality of write commands for the plurality of user data blocks are submitted to a host disk for the disk to store the encrypted data block based on the corresponding HBA. In addition, the first metadata corresponding to each user data block is further written into a first metadata table maintained by using an LSM tree. Then, a synchronization operation command is sent to the LSM tree and the host disk for the LSM tree and the host disk to complete data write persistence.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Anti-quantum fuzzy keyword processing method and system and electronic equipment

The invention provides an anti-quantum fuzzy keyword processing method and system and electronic equipment, and relates to the technical field of networks and security. The method comprises the following steps: a client performs wildcard character extension on a keyword set based on a target shared key, generates an encryption index, performs authentication encryption on file identifiers by using the target shared key, forms an encrypted file identifier set, constructs an index table, and uploads the index table and the encrypted file set to a cloud server. The server generates a second wildcard character set according to the query keyword and a fault-tolerant threshold value, generates a trap door set based on the same target shared key and a pseudo-random function and sends the trap door set to the cloud server, and the cloud server traverses the index table, compares the index table with the trap door set and sends the trap door set to the server; and finding out the matched target encryption index and the associated target encryption file identifier and returning the matched target encryption index and the associated target encryption file identifier to the server, and decrypting and acquiring the target file from the cloud server by the server. In this way, high-safety, high-efficiency and extensible privacy protection search service is achieved.
Owner:中电信量子信息科技集团有限公司

Collaborative secret state task matching method based on edge calculation in mobile crowdsourcing

The invention discloses a collaborative secret state task matching method based on edge calculation in mobile crowdsourcing. The method comprises the steps of system initialization and key generation, requester-cloud platform registration authentication, worker-edge server registration authentication, login authentication and attribute submission, requester task issuing, cloud platform task delegation, secret state matching, worker task content decryption, worker answer submission, answer forwarding and decryption. According to the invention, cooperative authentication of workers and requesters and precise task matching based on attributes are realized under an edge-cloud architecture. A fuzzy extractor and an authentication encryption method with associated data are introduced, so that low-cost user local authentication and registration and authentication of a joining system are realized, the security is improved, and the calculation cost is reduced. Through function hidden inner product encryption and a Paillier cryptographic algorithm, task-worker matching and task answer submission are realized in a ciphertext state, and the requirements of a mobile crowdsourcing application scene with high safety, high privacy and dispersed cost are met.
Owner:SHAANXI NORMAL UNIV

Authenticated encryption apparatus, authenticated decryption apparatus, authenticated encryption system, method, and non-transitory computer readable medium

A plaintext division unit divides a plaintext into a first plaintext and a second plaintext at a predetermined ratio. A first encryption unit acquires a first ciphertext by an encryption function by using a mask value obtained based on a first value and a plurality of plaintext blocks, respectively. A second encryption unit acquires a second ciphertext by using, among encryption results output from the encryption function in the encryption of the first plaintext, a value other than a value used for the encryption of the first plaintext and a second plaintext. An authentication tag generation unit generates a first tag. The authentication tag generation unit generates a second tag. The authentication tag generation unit generates an authentication tag.
Owner:NEC CORP

Apparatus and method for performing authenticated encryption with associated data operation of encrypted instruction with corresponding golden tag stored in memory device in event of cache miss

An apparatus and a method for performing an authenticated encryption with associated data (AEAD) operation of an encrypted instruction and a golden tag stored in a memory device in an event of a cache miss are provided. The apparatus includes a bus control circuit, a block buffer, a tag buffer and an AEAD circuit. The bus control circuit receives a read address from a cache for reading the encrypted instruction and the golden tag from the memory device. The block buffer receives and stores the encrypted instruction from the bus control circuit, wherein a size of the block buffer is preset to be N times a size of one cache line. The tag buffer receives and stores the golden tag from the bus control circuit. The AEAD circuit performs the AEAD operation upon the encrypted instruction and the golden tag to check whether the encrypted instruction is tampered or not.
Owner:PUFSECURITY CORP

Authentication encryption system, method and device and storage medium

The invention discloses an authentication encryption system, method and device and a storage medium, and relates to the technical field of wireless communication, the authentication encryption method comprises a client terminal device and a network connection module; the network connection module obtains a terminal identity and a session key structure of the client terminal equipment to be accessed based on a pre-trained session key prediction model; when a connection request of the client terminal equipment is received, generating a session key of the client terminal equipment according to the terminal identity and the session key structure; encrypting the session key, and caching the encrypted session key obtained by encryption; and when a connection request initiated by the client terminal equipment again is received, performing quick access authentication on the client terminal equipment based on the cached encrypted session key. The required session key is prepared in advance through a key prediction mechanism, and the session key is locally cached, so that the authentication time is shortened, and the network connection speed is improved.
Owner:SHENZHEN DINSTAR TECH

Optical fiber generating in use a physical unclonable function, object equipped therewith, and apparatus for manufacturing thereof

There is described an optical fiber comprising a core with non-fungible noise elements along a length thereof, wherein the non-fungible noise elements generate in use a Physical Unclonable Function (PUF). There is further described an object including the present optical fiber and uses of the present optical fiber in applications such as authentication, encryption and zero trust security. There is also described an apparatus for introducing non-fungible noise elements along a core of a bundled optical fiber, a method for extracting a digital signature of a Physical Unclonable Function (PUF) generated by introduced non-fungible noise elements in the present optical fiber and a network integrating the present optical fiber.
Owner:POLYVALOR LP

New energy automobile intelligent charging management system

The invention discloses an intelligent charging management system of a new energy automobile, and relates to the technical field of charging control of the new energy automobile, and the system comprises a user identification and authentication module which supports three authentication modes, account association related information and authentication encryption transmission; the charging demand prediction module collects multiple types of data, and predicts charging related parameters through a fusion algorithm; the charging pile and battery state monitoring module collects various operation data in real time; the power grid load sensing module collects power grid information and synchronizes peak and valley periods; the charging strategy optimization module dynamically adjusts a charging scheme in combination with multi-source data; the safety protection module has six protection functions and a fault diagnosis capability; the data storage module adopts a distributed database and an encryption technology; the man-machine interaction module supports multiple operation modes and displays key information; and the communication coordination module is responsible for multi-terminal data interaction and protocol conversion. According to the invention, intelligence and accuracy of charging management are improved, safety protection and data safety are enhanced, and multi-scene charging requirements are met.
Owner:GUANGXI AGRI ENG VOCATIONAL & TECH COLLEGE

Optical network communication method and communication device

The invention provides an optical network communication method and a communication device, the method is applied to an optical fiber network, the optical fiber network comprises a master device and at least one slave device, and the at least one slave device comprises a first slave device. Wherein in the initialization phase, after receiving the authentication encryption capability of the slave device, the master device can indicate a determined authentication encryption mode (e.g., a first authentication encryption mode) to the slave device, so that the authentication encryption capability of the slave device is enhanced in a subsequent process (e.g., a roaming parameter configuration process). The master device does not need to configure security-related parameters such as an authentication encryption mode for the slave device, so that the configuration efficiency is improved, and the configuration overhead is saved.
Owner:HUAWEI TECH CO LTD

Public network interphone with quantum chip

The invention relates to the technical field of wireless communication, in particular to a public network interphone with a quantum chip. According to the interphone, a master control module and a quantum security chip work cooperatively, a quantum random number generator is used for dynamically deriving a session key, and offline security distribution of a group master key is realized by encrypting a two-dimensional code; in a communication process, a system adaptively switches a voice coding mode according to a network condition, end-to-end authentication encryption is carried out on voice data by using a hardware encryption engine, and low-delay transmission is guaranteed through a network priority mark; the device establishes a complete key life cycle management mechanism, supports regular update and forward security of session keys and instant update and backward security of a group master key when members change, and ensures that all key operations are completed in a quantum chip. According to the invention, various eavesdropping and tampering attacks are effectively resisted, and safe, real-time and clear high-confidentiality voice communication in a public network environment is realized.
Owner:ZHEJIANG HAIGAOSI COMM TECH CO LTD

Zero-trust gateway single packet authentication method and system for new energy fan control system, computing equipment, computer storage medium, computer program product and chip

The invention discloses a zero-trust gateway single packet authentication method and system for a new energy fan control system, computing equipment, a computer storage medium, a computer program product and a chip. The authentication method comprises the steps of generating an authentication material; exchanging and deriving a mixed key; binding Hash calculation is carried out; encrypting and assembling the message; receiving and verifying by the gateway; and binding verification and registration are carried out. The invention relates to a zero-trust gateway single packet authentication method combining a post quantum cryptography algorithm and a national commercial cryptography algorithm. The method is applied to secure communication between a wind power plant and a centralized control center, an SM2, SM3 and SM4 combined algorithm in a national secret system is combined with a post-quantum key agreement algorithm CRYSTALS-Kyber512, identity authentication, encryption and integrity verification are completed through a single message, confidentiality protection and anti-quantum security guarantee under one-time interaction are achieved, and the security of the wind power plant is improved. The method is especially suitable for new energy scenes with wide fan distribution, complex links and high real-time requirements.
Owner:DATANG HUAXIAN WIND POWER GENERATION CO LTD

KNX protocol integration and remote control system applied to smart home

The invention discloses a KNX protocol integration and remote control system applied to a smart home, and relates to the technical field of smart home, Internet of Things, automatic control and computer vision, equipment is managed in a unified manner through a KNX bus main control module, and communication and task scheduling are guaranteed; the scene sensing module is fused with radar and image data to accurately recognize a scene; the energy consumption optimization module formulates an energy-saving strategy based on equipment energy consumption and use habits; the security protection module guarantees the security of the system by utilizing multiple authentication, encryption and anomaly detection; the remote control module realizes convenient remote operation by means of AR interaction; according to the system, centralized control, accurate sensing, high efficiency, energy saving, safety protection and convenient interaction of the smart home equipment are realized, and the intelligent level, user experience and energy utilization efficiency of the smart home are improved.
Owner:JIANGSU UNIV OF TECH

Enhanced secure ranging using physical layer radio frequency signatures

Disclosed are techniques for wireless communication. In an aspect, a method performed by a receiving entity includes: receiving, from a transmitting entity, a first physical layer identity matrix (PHY ID) for the transmitting entity; receiving, from the transmitting entity, an encrypted ranging message; calculating a second PHY ID for the transmitting entity based on the encrypted ranging message; and authenticating the encrypted ranging message based on a comparison of the first PHY ID and the second PHY ID. Upon determining that the encrypted ranging message is authentic, the encrypted ranging message is decrypted to produce a decrypted ranging message and processing the decrypted ranging message. In some aspects, upon determining that the encrypted ranging message is not authentic, the encrypted ranging message is not processed (e.g., ignored or discarded). In some aspects, the receiving entity rejects further signal transmission and ranging procedures with the device thereby preventing successful attack.
Owner:QUALCOMM INC

Mobile application program data encryption transmission method and system

The invention provides a mobile application program data encryption transmission method and system. The method comprises the steps of obtaining original application layer data of service interaction; generating a symmetric session key, and performing authentication encryption through the symmetric session key to obtain initial ciphertext data in a service interaction process; performing ciphertext segmentation on the initial ciphertext data to obtain a plurality of independent ciphertext fragments, and deriving a transient rotation key of each independent ciphertext fragment; independently encrypting each independent ciphertext fragment to obtain parallel encrypted data packets of different independent ciphertext fragments, and distributing all the parallel encrypted data packets to a plurality of secure network interfaces of the mobile terminal for parallel transmission; and decrypting and reconstructing each parallel encrypted data packet through a corresponding transient rotation key, and further realizing multi-path encrypted transmission of the original application layer data according to a reconstruction result. By adopting the scheme of the invention, the risk of overall leakage of the single-path ciphertext can be avoided in a complex transmission environment of the mobile terminal.
Owner:GUANGZHOU SHENGTONG QUALITY TESTING OF CONSTR

Authentication encryption method based on national secret algorithm and application

The invention discloses an authentication encryption method based on a national cryptographic algorithm and application. A sender and a receiver negotiate to generate a shared key and a symmetric encryption mode parameter through a national cryptographic asymmetric algorithm based on identification information; a sender generates an abstract of data to be transmitted through a national cryptographic hash algorithm, and signs the abstract through a national cryptographic digital signature algorithm; the sender encrypts and transmits the data and the signature value by using a national secret symmetric encryption algorithm in combination with the shared key and the mode parameters, and destroys the shared key and the mode parameters after the encryption is completed; after the receiver receives the ciphertext, the plaintext data and the signature value are obtained through decryption by using the shared key and the mode parameter through a national secret symmetric encryption algorithm, and the shared key and the mode parameter are destroyed after decryption is completed; and the receiver generates an abstract of the plaintext data through a national cryptographic hash algorithm, and verifies a signature value through a national cryptographic digital signature algorithm so as to confirm a data source and integrity. According to the invention, the problems of security and integrity of data in transmission and processing processes are solved.
Owner:GUIZHOU UNIV

SM4-based efficient authentication encryption method

The invention discloses an efficient authentication encryption method based on SM4. The method comprises the following steps of: 1) initializing and generating an initial vector IV with the length of 128 bits, a secret key K of a national secret SM4 algorithm, a random number N with the length of 128 bits and associated data AD; 2) setting the length l of state updating data in the sponge structure to be 128 bits; 3) designing permutation operation # imgabs0 # 4 based on SM4 rounds of functions, generating S = IVKN in an authentication stage, sequentially executing # imgabs1 # to divide the associated data AD into a plurality of 128-bit data blocks, and performing round transformation on S to obtain a latest state S of fused associated data information; encrypting the plaintext M based on the state S and the key K to obtain a ciphertext C and an authentication tag T; and 5) completing decryption verification in a decryption stage.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Time-sensitive network end-to-end secure communication method

The invention relates to a time-sensitive network end-to-end secure communication method, and belongs to the technical field of communication. According to the method, a TSN terminal system of Linux is used for realizing bidirectional identity authentication and key agreement based on an SM2 cryptographic algorithm, and an SM4-CCM algorithm is used for realizing time-sensitive network security communication and data integrity verification; the SM2 national secret algorithm is an asymmetric encryption algorithm, a signature pair is generated based on an elliptic curve discrete logarithm problem, the two parties negotiate a shared key through elliptic curve point operation, a public key of a receiver is used for encryption, and only a private key can be used for decryption; sM4-CCM is a combination of an SM4 block cipher algorithm and a CCM mode, and is used for providing confidentiality, integrity and authenticity of data; according to the CCM mode, through combination of CTR encryption and CBC-MAC authentication, efficient authentication encryption is realized. The method can be used for real-time secure communication in a high-reliability industrial scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Authentication encryption method, verification decryption method, system and device based on block cipher

The invention discloses an authentication encryption method, verification decryption method, system and device based on block cipher, and the authentication encryption method comprises the steps: determining a block cipher and a secret key which are used by a bottom layer, selecting an initial vector which is not used in encryption under the current secret key, taking the triad of the initial vector, the associated data and the plaintext as the input of an authentication encryption algorithm; the encryption part encrypts the masked plaintext by using a codebook mode to obtain a ciphertext; the authentication part processes the masked associated data by using a PMAC mode to obtain an authentication intermediate value, performs exclusive or on plaintext groups and encrypts the plaintext groups by using a block cipher, and performs exclusive or on the authentication intermediate value and a result encrypted by using the block cipher to generate an authentication label; and sending the initial vector, the associated data, the ciphertext and the authentication tag as a ciphertext message to a receiving end or storing the ciphertext message for decryption. According to the method, the confidentiality and integrity of data can be protected under quantum computing, and the computing efficiency can be improved through parallel computing.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Method, device and storage medium for security authentication encryption in initial stage of communication link establishment

The application discloses a kind of communication link establishment initial stage security authentication encryption method, device and storage medium, the present application is limited to narrow bandwidth for end-to-end wireless communication link establishment, cannot apply conventional encryption preparation, it is difficult to guarantee that preset symmetric key is added after planning, abandon password protection is also prone to be maliciously controlled and so on Problem, an authentication encryption adaptive method based on pre-stored and diffusion key is proposed, by making full use of the key storage space of end device pre-stored key, supplemented by the diffusion transmission of new key with the process of link establishment, combined with the two modes of offline preset loading when opening and automatic online interaction after new communication terminal joins interworking, under the premise of no manual participation, maximum reduction to the occupation of link establishment narrow band, the security of information transmission is greatly improved, so as to improve user experience.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Intelligent agent interaction system and method supporting multi-user anonymous identity proxy

The invention discloses an agent interaction system and method supporting multi-user anonymous identity agency, and the system comprises a user side which is used for generating a one-time decentralized identity identifier and a secret key, generating a zero-knowledge proof based on a local certificate, and submitting the identifier, the proof and metadata to an agent side; the intelligent agent end is used for managing multi-user session data, establishing a decentralized identity-based bidirectional authentication encryption channel with the platform end, forwarding zero-knowledge proof and metadata, signing and encrypting a result returned by the platform end, and returning the result to the user end; and the platform end is used for verifying the identity of the agent end, receiving the zero-knowledge proof and the metadata, completing proof verification based on the on-chain verification parameters, and executing the anonymous request of the user after the proof verification is passed. According to the method, the real identity of the user and the platform service are effectively isolated by introducing the intelligent agent, the privacy security of the user and the data is practically protected, and the method is suitable for scenes needing strong privacy protection and multi-user cooperation, such as online transaction, shared economy, family and enterprise agency and the like.
Owner:ZHEJIANG UNIV BINJIANG RES INST

Method, apparatus, system, and computer program for authenticated encryption providing enhanced security and nonce length extension

The present disclosure relates to an authenticated encryption method, apparatus, system, and computer program for providing enhanced security and extension of a nonce length, and more specifically, the present disclosure discloses a method for performing authenticated encryption using a computing apparatus, the method including: producing a plurality of intermediate values, based on a given input value; generating a random number, based on a combination of a plurality of intermediate random values produced by performing block cipher-based encoding on the plurality of intermediate values; and performing encryption or decryption, based on the random number.
Owner:SAMSUNG SDS CO LTD

Autonomously booting system with encryption of the entire data storage and method for this

Encryption system with an application-specific integrated circuit (ASIC) which has a permanent memory for the non-volatile storage of the operating system (OS) of a processor and software modules for encrypting the data memory of the processor and which has a hardware-implemented encryption algorithm, characterized in that a security module (SM) is integrated in the ASIC for autonomous booting of the operating system (OS), consisting of: - a symmetric cryptosystem (SK) for processing symmetric keys, - an asymmetric cryptosystem (AK) for the use of public and private keys, - a module for generating cryptographic hash functions (KH), - a module for the secure exchange of keys using hardware-implemented key exchange protocols (SP), - a key storage (SS) for the secure storage of root keys (WS), which are protected by appropriate measures in the physical structures of the ASIC and - a key management system (SMS) for the secure introduction of authenticated-encrypted key packets, and that the security module (SM) communicates with a central processing unit (CPU) via a communication interface (CS1), and that the central processing unit (CPU) communicates with at least one internal storage (IS) and one external storage (ES), as well as with at least one internal persistent storage (IP) and one external persistent storage (EP), such that the operating system (OS) is loaded by a second-stage bootloader (SSB) stored in the external persistent storage (EP), and then the operating system (OS) loads the applications, the second-stage bootloader (SSB) itself being decrypted and loaded by a first-stage bootloader (FSB) stored in the internal persistent storage (IP), and a public key (PUBOS) to verify the operating system (OS).and a symmetric key (KOS) to decrypt the operating system (OS), and that the contents of the internal memory (IS) and the external memory (ES) are decrypted by the security module (SM) during read accesses by the central management unit (CMU) or other modules integrated on the ASIC, and re-encrypted during write accesses by the same.
Owner:IAD GESELLSCHAFT FUER INFORMATIK AUTOMATISIERUNG & DATENVERARBEITUNG MBH

Hierarchical nested data encryption method supporting fine-grained access control

The invention discloses a hierarchical nested data encryption method supporting fine-grained access control, which relates to the technical field of data security, and comprises the following steps: generating a master key; receiving to-be-encrypted user data, and performing data classification on the to-be-encrypted user data through the data classifier according to a predefined privacy sensitivity strategy to obtain a hierarchical data set; deriving a first-layer key from the master key, and carrying out authentication encryption on first-layer data in the hierarchical data set by using the first-layer key to obtain a first-layer ciphertext; and cooperatively deriving a current-layer key based on the previous-layer ciphertext, the previous-layer key and the hierarchical data set, carrying out byte connection operation on the previous-layer ciphertext and the current-layer data, and executing to-be-authenticated encryption layer by layer through authentication encryption band associated data in combination with the current-layer key to obtain a final nested ciphertext. According to the method, fine-grained access control layered according to data sensitivity is realized, and the risk of core sensitive information leakage is effectively reduced.
Owner:JIANGSU PROVINCE SURVEYING & MAPPING ENG INST

System and method for providing protected data storage in data memory

A system and method are disclosed for securely transferring or storing protected working memory outside an owner thread while maintaining full encryption throughout its lifecycle. The protected working memory has an encrypted data component and a keystream component containing dynamically updated encryption information used for per-cycle decryption and re-encryption. A hardened cryptographic subsystem, such as a Trusted Execution Environment (TEE), Secure Element (SE), TPM, or HSM, performs authenticated encryption using device-bound key material to wrap either (i) the keystream component alone or (ii) the entire protected working memory blob. The wrapped object is suitable for storage or transfer across threads or in external memory, without exposing plaintext or keystream material. When restoring, an authorized owner thread supplies a key handle to the hardened subsystem to securely decrypt and reconstruct the protected working memory only within a guarded heap. At no point are plaintext contents or keystreams available to the operating system or user-accessible memory.
Owner:GURULOGIC MICROSYST

Data Communication System for Distribution Network Protection Based on SM1 National Cryptography Algorithm

The present invention relates to the technical field of power data protection, and discloses a data communication system for distribution network protection based on the SM1 national cryptographic algorithm. An identity authentication protocol request is sent to a security machine through an identity library switch, and a reply protocol for responding to the identity authentication protocol request from the security machine is received. It is verified whether the reply protocol is correct. If the verification of the reply protocol is correct, the communication blocking states between the external distribution network protection device and the encryption switch are respectively released, so as to obtain the service data in the external distribution network protection device. An identity key authentication is also performed with the encryption switch through the SM1 national cryptographic algorithm. If the authentication is successful, the service data is forwarded to the encryption switch, and the MAC of the protection terminal is bound through the encryption switch, excluding the possibility of illegal devices accessing the authenticated encryption switch, thereby improving the identity authentication security performance of the communication system, reducing the difficulty of deployment, installation and maintenance, and at the same time, improving the security of data communication transmission.
Owner:GUANGDONG POWER GRID CO LTD +1

Cryptocurrency hardware wallet on monolithic chip with common physical countermeasures and secure memory

An electronic hardware wallet for conducting cryptocurrency transactions, blockchain transactions, or other secure communications is embodied on a monolithic integrated circuit (IC) die supported on a single substrate. The monolithic semiconductor device can include a non-volatile data store for storing application software executable by the multi-core processor, and the secure element can include a secure data store for storing secret data (e.g., a private key) for use in a secure electronic transaction. In some embodiments, the secure element can include hardware logic embodying a cryptocurrency algorithm associated with executing the secure electronic transaction and can have a limited and selective communication bus between the secure element and the multi-core processor. The electronic hardware wallet can communicatively couple with one or more other devices to facilitate a multi-party computation (MPC) algorithm for authenticating the cryptocurrency algorithm and validating the secure electronic transaction.
Owner:CROSSBAR INC