Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

113 results about "Authenticated encryption" patented technology

Authenticated encryption (AE) and authenticated encryption with associated data (AEAD) are forms of encryption which simultaneously assure the confidentiality and authenticity of data. These attributes are provided under a single, easy to use programming interface.

Network security protection system and method based on electric power emergency communication environment

The invention belongs to the technical field of network security, and particularly relates to a network security protection system and method based on an electric power emergency communication environment, and the system comprises a quantum-classical hybrid encryption system which is used for generating a dynamic key in real time; the biological characteristic driven dynamic trust ring is used for equipment identity authentication; the unmanned aerial vehicle relay network protocol is used for data transmission; the secret key after-reading burn-down protocol is used for information secret key after-reading burn-down; a key output by the quantum-classical hybrid encryption system is used for authentication encryption of a biological characteristic driven dynamic trust ring, an unmanned aerial vehicle relay network protocol transmits data encrypted by the quantum key, and a key burn-down protocol is used for reading encrypted data to trigger a key burn-down mechanism. According to the method, the key security is improved, the network attack difficulty is increased, the communication delay in a disaster is reduced, man-in-the-middle capture and attack can be immunized, and the problem of contradiction between the encryption strength and the real-time performance is solved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning

The invention relates to a dynamic double-layer hidden watermark and encryption binding file protection method and system based on deep learning, and belongs to the technical field of digital content security. The problems of attack resistance, traceability obstruction and key-watermark unhooking in document cross-platform circulation are solved. According to the scheme, the method comprises the following steps of: extracting semantic fingerprints by using a sentence vector model Sentence-BERT; the fuzzy extractor generates a master key and derives a time key chain; the authentication encryption algorithm AEAD encrypts and binds the source and the timestamp load; container layer structure rearrangement and document layer zero-width character double embedding are carried out; the generative adversarial network or diffusion model adversarial training improves the optical character recognition and transcoding resistance; version binding and tracing are achieved through the watermark hash chain. The technical effects cover anti-counterfeiting migration, cross-layer fault-tolerant guarantee recoverability, rearrangement attack resistance, full-period accurate traceability and post-quantum security enhancement.
Owner:SOUTHWEST UNIV

Anti-quantum fuzzy keyword processing method and system and electronic equipment

The invention provides an anti-quantum fuzzy keyword processing method and system and electronic equipment, and relates to the technical field of networks and security. The method comprises the following steps: a client performs wildcard character extension on a keyword set based on a target shared key, generates an encryption index, performs authentication encryption on file identifiers by using the target shared key, forms an encrypted file identifier set, constructs an index table, and uploads the index table and the encrypted file set to a cloud server. The server generates a second wildcard character set according to the query keyword and a fault-tolerant threshold value, generates a trap door set based on the same target shared key and a pseudo-random function and sends the trap door set to the cloud server, and the cloud server traverses the index table, compares the index table with the trap door set and sends the trap door set to the server; and finding out the matched target encryption index and the associated target encryption file identifier and returning the matched target encryption index and the associated target encryption file identifier to the server, and decrypting and acquiring the target file from the cloud server by the server. In this way, high-safety, high-efficiency and extensible privacy protection search service is achieved.
Owner:中电信量子信息科技集团有限公司

Collaborative secret state task matching method based on edge calculation in mobile crowdsourcing

The invention discloses a collaborative secret state task matching method based on edge calculation in mobile crowdsourcing. The method comprises the steps of system initialization and key generation, requester-cloud platform registration authentication, worker-edge server registration authentication, login authentication and attribute submission, requester task issuing, cloud platform task delegation, secret state matching, worker task content decryption, worker answer submission, answer forwarding and decryption. According to the invention, cooperative authentication of workers and requesters and precise task matching based on attributes are realized under an edge-cloud architecture. A fuzzy extractor and an authentication encryption method with associated data are introduced, so that low-cost user local authentication and registration and authentication of a joining system are realized, the security is improved, and the calculation cost is reduced. Through function hidden inner product encryption and a Paillier cryptographic algorithm, task-worker matching and task answer submission are realized in a ciphertext state, and the requirements of a mobile crowdsourcing application scene with high safety, high privacy and dispersed cost are met.
Owner:SHAANXI NORMAL UNIV

Authenticated encryption apparatus, authenticated decryption apparatus, authenticated encryption system, method, and non-transitory computer readable medium

A plaintext division unit divides a plaintext into a first plaintext and a second plaintext at a predetermined ratio. A first encryption unit acquires a first ciphertext by an encryption function by using a mask value obtained based on a first value and a plurality of plaintext blocks, respectively. A second encryption unit acquires a second ciphertext by using, among encryption results output from the encryption function in the encryption of the first plaintext, a value other than a value used for the encryption of the first plaintext and a second plaintext. An authentication tag generation unit generates a first tag. The authentication tag generation unit generates a second tag. The authentication tag generation unit generates an authentication tag.
Owner:NEC CORP

Apparatus and method for performing authenticated encryption with associated data operation of encrypted instruction with corresponding golden tag stored in memory device in event of cache miss

An apparatus and a method for performing an authenticated encryption with associated data (AEAD) operation of an encrypted instruction and a golden tag stored in a memory device in an event of a cache miss are provided. The apparatus includes a bus control circuit, a block buffer, a tag buffer and an AEAD circuit. The bus control circuit receives a read address from a cache for reading the encrypted instruction and the golden tag from the memory device. The block buffer receives and stores the encrypted instruction from the bus control circuit, wherein a size of the block buffer is preset to be N times a size of one cache line. The tag buffer receives and stores the golden tag from the bus control circuit. The AEAD circuit performs the AEAD operation upon the encrypted instruction and the golden tag to check whether the encrypted instruction is tampered or not.
Owner:PUFSECURITY CORP

Optical fiber generating in use a physical unclonable function, object equipped therewith, and apparatus for manufacturing thereof

There is described an optical fiber comprising a core with non-fungible noise elements along a length thereof, wherein the non-fungible noise elements generate in use a Physical Unclonable Function (PUF). There is further described an object including the present optical fiber and uses of the present optical fiber in applications such as authentication, encryption and zero trust security. There is also described an apparatus for introducing non-fungible noise elements along a core of a bundled optical fiber, a method for extracting a digital signature of a Physical Unclonable Function (PUF) generated by introduced non-fungible noise elements in the present optical fiber and a network integrating the present optical fiber.
Owner:POLYVALOR LP

New energy automobile intelligent charging management system

The invention discloses an intelligent charging management system of a new energy automobile, and relates to the technical field of charging control of the new energy automobile, and the system comprises a user identification and authentication module which supports three authentication modes, account association related information and authentication encryption transmission; the charging demand prediction module collects multiple types of data, and predicts charging related parameters through a fusion algorithm; the charging pile and battery state monitoring module collects various operation data in real time; the power grid load sensing module collects power grid information and synchronizes peak and valley periods; the charging strategy optimization module dynamically adjusts a charging scheme in combination with multi-source data; the safety protection module has six protection functions and a fault diagnosis capability; the data storage module adopts a distributed database and an encryption technology; the man-machine interaction module supports multiple operation modes and displays key information; and the communication coordination module is responsible for multi-terminal data interaction and protocol conversion. According to the invention, intelligence and accuracy of charging management are improved, safety protection and data safety are enhanced, and multi-scene charging requirements are met.
Owner:GUANGXI AGRI ENG VOCATIONAL & TECH COLLEGE

Public network interphone with quantum chip

The invention relates to the technical field of wireless communication, in particular to a public network interphone with a quantum chip. According to the interphone, a master control module and a quantum security chip work cooperatively, a quantum random number generator is used for dynamically deriving a session key, and offline security distribution of a group master key is realized by encrypting a two-dimensional code; in a communication process, a system adaptively switches a voice coding mode according to a network condition, end-to-end authentication encryption is carried out on voice data by using a hardware encryption engine, and low-delay transmission is guaranteed through a network priority mark; the device establishes a complete key life cycle management mechanism, supports regular update and forward security of session keys and instant update and backward security of a group master key when members change, and ensures that all key operations are completed in a quantum chip. According to the invention, various eavesdropping and tampering attacks are effectively resisted, and safe, real-time and clear high-confidentiality voice communication in a public network environment is realized.
Owner:ZHEJIANG HAIGAOSI COMM TECH CO LTD

Zero-trust gateway single packet authentication method and system for new energy fan control system, computing equipment, computer storage medium, computer program product and chip

The invention discloses a zero-trust gateway single packet authentication method and system for a new energy fan control system, computing equipment, a computer storage medium, a computer program product and a chip. The authentication method comprises the steps of generating an authentication material; exchanging and deriving a mixed key; binding Hash calculation is carried out; encrypting and assembling the message; receiving and verifying by the gateway; and binding verification and registration are carried out. The invention relates to a zero-trust gateway single packet authentication method combining a post quantum cryptography algorithm and a national commercial cryptography algorithm. The method is applied to secure communication between a wind power plant and a centralized control center, an SM2, SM3 and SM4 combined algorithm in a national secret system is combined with a post-quantum key agreement algorithm CRYSTALS-Kyber512, identity authentication, encryption and integrity verification are completed through a single message, confidentiality protection and anti-quantum security guarantee under one-time interaction are achieved, and the security of the wind power plant is improved. The method is especially suitable for new energy scenes with wide fan distribution, complex links and high real-time requirements.
Owner:DATANG HUAXIAN WIND POWER GENERATION CO LTD

Enhanced secure ranging using physical layer radio frequency signatures

Disclosed are techniques for wireless communication. In an aspect, a method performed by a receiving entity includes: receiving, from a transmitting entity, a first physical layer identity matrix (PHY ID) for the transmitting entity; receiving, from the transmitting entity, an encrypted ranging message; calculating a second PHY ID for the transmitting entity based on the encrypted ranging message; and authenticating the encrypted ranging message based on a comparison of the first PHY ID and the second PHY ID. Upon determining that the encrypted ranging message is authentic, the encrypted ranging message is decrypted to produce a decrypted ranging message and processing the decrypted ranging message. In some aspects, upon determining that the encrypted ranging message is not authentic, the encrypted ranging message is not processed (e.g., ignored or discarded). In some aspects, the receiving entity rejects further signal transmission and ranging procedures with the device thereby preventing successful attack.
Owner:QUALCOMM INC

Mobile application program data encryption transmission method and system

The invention provides a mobile application program data encryption transmission method and system. The method comprises the steps of obtaining original application layer data of service interaction; generating a symmetric session key, and performing authentication encryption through the symmetric session key to obtain initial ciphertext data in a service interaction process; performing ciphertext segmentation on the initial ciphertext data to obtain a plurality of independent ciphertext fragments, and deriving a transient rotation key of each independent ciphertext fragment; independently encrypting each independent ciphertext fragment to obtain parallel encrypted data packets of different independent ciphertext fragments, and distributing all the parallel encrypted data packets to a plurality of secure network interfaces of the mobile terminal for parallel transmission; and decrypting and reconstructing each parallel encrypted data packet through a corresponding transient rotation key, and further realizing multi-path encrypted transmission of the original application layer data according to a reconstruction result. By adopting the scheme of the invention, the risk of overall leakage of the single-path ciphertext can be avoided in a complex transmission environment of the mobile terminal.
Owner:GUANGZHOU SHENGTONG QUALITY TESTING OF CONSTR

Time-sensitive network end-to-end secure communication method

The invention relates to a time-sensitive network end-to-end secure communication method, and belongs to the technical field of communication. According to the method, a TSN terminal system of Linux is used for realizing bidirectional identity authentication and key agreement based on an SM2 cryptographic algorithm, and an SM4-CCM algorithm is used for realizing time-sensitive network security communication and data integrity verification; the SM2 national secret algorithm is an asymmetric encryption algorithm, a signature pair is generated based on an elliptic curve discrete logarithm problem, the two parties negotiate a shared key through elliptic curve point operation, a public key of a receiver is used for encryption, and only a private key can be used for decryption; sM4-CCM is a combination of an SM4 block cipher algorithm and a CCM mode, and is used for providing confidentiality, integrity and authenticity of data; according to the CCM mode, through combination of CTR encryption and CBC-MAC authentication, efficient authentication encryption is realized. The method can be used for real-time secure communication in a high-reliability industrial scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Method, device and storage medium for security authentication encryption in initial stage of communication link establishment

The application discloses a kind of communication link establishment initial stage security authentication encryption method, device and storage medium, the present application is limited to narrow bandwidth for end-to-end wireless communication link establishment, cannot apply conventional encryption preparation, it is difficult to guarantee that preset symmetric key is added after planning, abandon password protection is also prone to be maliciously controlled and so on Problem, an authentication encryption adaptive method based on pre-stored and diffusion key is proposed, by making full use of the key storage space of end device pre-stored key, supplemented by the diffusion transmission of new key with the process of link establishment, combined with the two modes of offline preset loading when opening and automatic online interaction after new communication terminal joins interworking, under the premise of no manual participation, maximum reduction to the occupation of link establishment narrow band, the security of information transmission is greatly improved, so as to improve user experience.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Intelligent agent interaction system and method supporting multi-user anonymous identity proxy

The invention discloses an agent interaction system and method supporting multi-user anonymous identity agency, and the system comprises a user side which is used for generating a one-time decentralized identity identifier and a secret key, generating a zero-knowledge proof based on a local certificate, and submitting the identifier, the proof and metadata to an agent side; the intelligent agent end is used for managing multi-user session data, establishing a decentralized identity-based bidirectional authentication encryption channel with the platform end, forwarding zero-knowledge proof and metadata, signing and encrypting a result returned by the platform end, and returning the result to the user end; and the platform end is used for verifying the identity of the agent end, receiving the zero-knowledge proof and the metadata, completing proof verification based on the on-chain verification parameters, and executing the anonymous request of the user after the proof verification is passed. According to the method, the real identity of the user and the platform service are effectively isolated by introducing the intelligent agent, the privacy security of the user and the data is practically protected, and the method is suitable for scenes needing strong privacy protection and multi-user cooperation, such as online transaction, shared economy, family and enterprise agency and the like.
Owner:ZHEJIANG UNIV BINJIANG RES INST

Method, apparatus, system, and computer program for authenticated encryption providing enhanced security and nonce length extension

The present disclosure relates to an authenticated encryption method, apparatus, system, and computer program for providing enhanced security and extension of a nonce length, and more specifically, the present disclosure discloses a method for performing authenticated encryption using a computing apparatus, the method including: producing a plurality of intermediate values, based on a given input value; generating a random number, based on a combination of a plurality of intermediate random values produced by performing block cipher-based encoding on the plurality of intermediate values; and performing encryption or decryption, based on the random number.
Owner:SAMSUNG SDS CO LTD

Autonomously booting system with encryption of the entire data storage and method for this

Encryption system with an application-specific integrated circuit (ASIC) which has a permanent memory for the non-volatile storage of the operating system (OS) of a processor and software modules for encrypting the data memory of the processor and which has a hardware-implemented encryption algorithm, characterized in that a security module (SM) is integrated in the ASIC for autonomous booting of the operating system (OS), consisting of: - a symmetric cryptosystem (SK) for processing symmetric keys, - an asymmetric cryptosystem (AK) for the use of public and private keys, - a module for generating cryptographic hash functions (KH), - a module for the secure exchange of keys using hardware-implemented key exchange protocols (SP), - a key storage (SS) for the secure storage of root keys (WS), which are protected by appropriate measures in the physical structures of the ASIC and - a key management system (SMS) for the secure introduction of authenticated-encrypted key packets, and that the security module (SM) communicates with a central processing unit (CPU) via a communication interface (CS1), and that the central processing unit (CPU) communicates with at least one internal storage (IS) and one external storage (ES), as well as with at least one internal persistent storage (IP) and one external persistent storage (EP), such that the operating system (OS) is loaded by a second-stage bootloader (SSB) stored in the external persistent storage (EP), and then the operating system (OS) loads the applications, the second-stage bootloader (SSB) itself being decrypted and loaded by a first-stage bootloader (FSB) stored in the internal persistent storage (IP), and a public key (PUBOS) to verify the operating system (OS).and a symmetric key (KOS) to decrypt the operating system (OS), and that the contents of the internal memory (IS) and the external memory (ES) are decrypted by the security module (SM) during read accesses by the central management unit (CMU) or other modules integrated on the ASIC, and re-encrypted during write accesses by the same.
Owner:IAD GESELLSCHAFT FUER INFORMATIK AUTOMATISIERUNG & DATENVERARBEITUNG MBH

Hierarchical nested data encryption method supporting fine-grained access control

The invention discloses a hierarchical nested data encryption method supporting fine-grained access control, which relates to the technical field of data security, and comprises the following steps: generating a master key; receiving to-be-encrypted user data, and performing data classification on the to-be-encrypted user data through the data classifier according to a predefined privacy sensitivity strategy to obtain a hierarchical data set; deriving a first-layer key from the master key, and carrying out authentication encryption on first-layer data in the hierarchical data set by using the first-layer key to obtain a first-layer ciphertext; and cooperatively deriving a current-layer key based on the previous-layer ciphertext, the previous-layer key and the hierarchical data set, carrying out byte connection operation on the previous-layer ciphertext and the current-layer data, and executing to-be-authenticated encryption layer by layer through authentication encryption band associated data in combination with the current-layer key to obtain a final nested ciphertext. According to the method, fine-grained access control layered according to data sensitivity is realized, and the risk of core sensitive information leakage is effectively reduced.
Owner:JIANGSU PROVINCE SURVEYING & MAPPING ENG INST

System and method for providing protected data storage in data memory

A system and method are disclosed for securely transferring or storing protected working memory outside an owner thread while maintaining full encryption throughout its lifecycle. The protected working memory has an encrypted data component and a keystream component containing dynamically updated encryption information used for per-cycle decryption and re-encryption. A hardened cryptographic subsystem, such as a Trusted Execution Environment (TEE), Secure Element (SE), TPM, or HSM, performs authenticated encryption using device-bound key material to wrap either (i) the keystream component alone or (ii) the entire protected working memory blob. The wrapped object is suitable for storage or transfer across threads or in external memory, without exposing plaintext or keystream material. When restoring, an authorized owner thread supplies a key handle to the hardened subsystem to securely decrypt and reconstruct the protected working memory only within a guarded heap. At no point are plaintext contents or keystreams available to the operating system or user-accessible memory.
Owner:GURULOGIC MICROSYST

Cryptocurrency hardware wallet on monolithic chip with common physical countermeasures and secure memory

An electronic hardware wallet for conducting cryptocurrency transactions, blockchain transactions, or other secure communications is embodied on a monolithic integrated circuit (IC) die supported on a single substrate. The monolithic semiconductor device can include a non-volatile data store for storing application software executable by the multi-core processor, and the secure element can include a secure data store for storing secret data (e.g., a private key) for use in a secure electronic transaction. In some embodiments, the secure element can include hardware logic embodying a cryptocurrency algorithm associated with executing the secure electronic transaction and can have a limited and selective communication bus between the secure element and the multi-core processor. The electronic hardware wallet can communicatively couple with one or more other devices to facilitate a multi-party computation (MPC) algorithm for authenticating the cryptocurrency algorithm and validating the secure electronic transaction.
Owner:CROSSBAR INC

Safe remote control and cut-off method for electric energy meter

The invention discloses a safe remote control and cut-off method for an electric energy meter, and aims to solve the problems that an instruction is counterfeited or replayed and executed out of order in a remote cut-off / switch-on closed loop in a weak network (NB-IoT / PLC) environment, and ACK can be counterfeited by a concentrator. The method comprises the following steps: generating a work order identifier by a work order serial number, an operation type and a previous closed loop label through a verifiable random function; performing authentication encryption on the instruction and the feedback by using the session key; deriving a one-time fragment key of each work order for metering and executing the two microcontrollers based on the chained context, and aggregating a threshold signature; the command label, the action proof, the time window and the double count are hashed into a binding message; fountain code coding is adopted for feedback, and end-to-end credible closed-loop control which is unforgeable in ACK, strong in binding of instructions and physical actions, resistant to replay and disorder, reliable in delivery under a weak network and capable of being audited is achieved.
Owner:LIYANG HUAPENG ELECTRIC POWER METER

Distributed storage data protection method for cryptographic algorithm dynamic reconstruction

The invention discloses a distributed storage data protection method for cryptographic algorithm dynamic reconstruction, which relates to the technical field of data encryption, and comprises the following steps of: determining an algorithm capability set and an alternating window before data writing, calculating path hash and generating an algorithm reconstruction vector, deriving a session key from a root key and signing and issuing a key algorithm capsule, forming write context data; the method comprises the following steps of: performing deterministic fragmentation on data by using a write-in context, generating an abstract from the tail part of a fragment, performing hash synthesis on the abstract and a path to obtain an initialization vector, encrypting a head part by using a path-sensitive authentication encryption algorithm, protecting the rest part by using a pseudo-random mask, and generating a fragment ciphertext list and an original index table; according to the method, after deterministic fragmentation, an initialization vector is synthesized through a tail abstract and path hash, path-sensitive authentication encryption and body segment pseudo-random mask are executed, and fragmentation-level anti-replay and high-throughput data encryption is achieved.
Owner:SUZHOU GUANWEN STORAGE TECH CO LTD

An optical network communication method and communication device

This application provides an optical network communication method and a communication device. The method is applied to an optical fiber network, which includes a master device and at least one slave device, wherein the at least one slave device includes a first slave device. During the initialization phase, after receiving the authentication and encryption capabilities of the slave device, the master device can indicate a specific authentication and encryption mode (e.g., a first authentication and encryption mode) to the slave device. This eliminates the need for the master device to configure security-related parameters such as the authentication and encryption mode for the slave device in subsequent processes (e.g., roaming parameter configuration processes), thereby improving configuration efficiency and saving configuration overhead.
Owner:HUAWEI TECH CO LTD

Systems and methods for AI directed tiered post quantum protection of multimodal data

Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency. This approach automates sensitivity classification, optimizes cryptographic resource allocation, and improves confidentiality and integrity for simulation and mission data.
Owner:UNIVERSITY OF CENTRAL FLORIDA RESEARCH FOUNDATION INC

Authentication encryption method and device and verification decryption method and device

The invention provides an authentication encryption method and device and a verification decryption method and device, and a specific implementation mode of the authentication encryption method comprises the following steps: segmenting plaintext data to be encrypted to obtain a plurality of plaintext blocks with index values; generating initial state information based on the associated data of the plaintext data and a message authentication code algorithm; generating first intermediate state information by using a compression function of a preset Hash algorithm; based on the compression function, performing encryption operation on the plurality of plaintext blocks, the encryption operation comprising: based on the current intermediate state information and the current plaintext block, generating a current ciphertext block; processing the secret key, the current plaintext block, the current intermediate state information and the index value and the mark value of the current plaintext block by using a compression function to obtain next intermediate state information; and generating ciphertext data based on the plurality of ciphertext blocks, and determining the next intermediate state information generated based on the last plaintext block as the authentication tag.
Owner:NINGBO UNIVERSITY OF TECHNOLOGY +2

Authentication encryption device, authentication encryption method, and authentication encryption program

An initial processing unit (21) generates a secret value (B) on the basis of a secret key in authentication encryption. The function F processing unit (22) repeats a process for updating the secret value (B) by block encryption using the secret value (B) generated by the initial processing unit (21) as an input block for block encryption. The ciphertext processing unit (23) uses the secret value (B) updated by the function F processing unit (22) to execute at least one of an encryption process for encrypting the plaintext (M) and a decryption process for decrypting the ciphertext (C).
Owner:MITSUBISHI ELECTRIC CORP

Robot remote operation and maintenance method and system, robot and readable storage medium

The invention discloses a robot remote operation and maintenance method and system, a robot and a readable storage medium, and relates to the technical field of robots. The method comprises the steps that a current remote operation and maintenance request of a robot is acquired from an operation and maintenance terminal through an operation and maintenance platform, and the current remote operation and maintenance request and the current state of the robot are verified; after the verification is passed, generating a session identifier corresponding to the current remote operation and maintenance request through the operation and maintenance platform, and establishing an operation and maintenance session based on the session identifier; based on the operation and maintenance session, performing bidirectional identity authentication between the operation and maintenance platform and the robot, and after the bidirectional identity authentication is passed, establishing a communication channel between the operation and maintenance platform and the robot according to a session identifier; and executing the current remote operation and maintenance request through the robot based on the communication channel. Thus, the current remote operation and maintenance request and the current state of the robot are verified, an independent bidirectional authentication encryption communication operation and maintenance session is dynamically established for each remote operation and maintenance task, and safe remote operation and maintenance are achieved.
Owner:UBTECH ROBOTICS CORP LTD

QSL—data at rest

A method to allow a client to communicate with a server, specifically to conduct a key management service, in order to obtain encryption / decryption keys for data-at-rest, wherein the method comprises: causing the client to use Authenticated Encryption with Associated Data (AEAD) to encrypt data according to a moving target design and causing the client, at a later time, to use AEAD to check the integrity of the data and decrypt the data according to the moving target design.
Owner:QUSECURE INC

A method for detecting that elephant authentication encryption algorithm resists fault analysis

The application relates to a method for detecting that an Elephant authentication encryption algorithm resists fault analysis. First, a plaintext to be processed is randomly generated, the plaintext M is taken as an input of the Elephant algorithm, a random half-byte fault is introduced, error ciphertext is output, and the plaintext and the ciphertext passing signature verification are collected. Secret masks are exhausted, error secret mask candidate bits are excluded in advance through impossible relation analysis, an intermediate state is calculated, the Hamming weight of the intermediate state is calculated through a statistical method, and part of correct values of the secret mask are obtained. The fault introduction and the analysis process are repeated, finally, all bits of the correct secret mask can be deduced, and the correct master key can be deduced according to a key arrangement scheme of the algorithm. The method provided by the application is easy to implement, fast and high in accuracy, and provides an important analysis basis for the security research of the Elephant password algorithm.
Owner:DONGHUA UNIV +1

A method of optical network communication and a communication device

The application provides an optical network communication method and a communication device. The method is applied to an optical fiber network, and the optical fiber network comprises a master device and at least one slave device, and the at least one slave device comprises a first slave device. In an initialization stage, after receiving an authentication encryption capability of the slave device, the master device can indicate a determined authentication encryption mode (for example, a first authentication encryption mode) to the slave device, so that in a subsequent process (for example, in a roaming parameter configuration process), the master device does not need to configure the authentication encryption mode and other security-related parameters for the slave device, thereby improving the configuration efficiency and saving the configuration overhead.
Owner:HUAWEI TECH CO LTD