Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

47 results about "Bilinear pairing" patented technology

The bilinear pairing is a bilinear, non-degenerate map between G_1 and G_2 to an element in G_T. The users can build complex pairing-based software by the Pairing library without much.

Unmanned aerial vehicle cluster dynamic cross-domain group key management method and system based on CRT

The invention discloses an unmanned aerial vehicle cluster dynamic cross-domain key management method and system based on the Chinese remainder theorem (CRT), a key generation center generates system public and private keys and public parameters, and a ground station and an unmanned aerial vehicle perform hierarchical registration and verify respective keys; the unmanned aerial vehicles respectively generate signature messages and send the signature messages to a specified ground station for identity verification, and the ground station constructs a group key based on CRT and publishes the group key to the block chain; when a new unmanned aerial vehicle applies for joining, a signature message is sent to the ground station, and the ground station updates and publishes the group key; when the unmanned aerial vehicle applies for leaving, a leaving message is sent to the ground station, and the ground station updates and publishes the group key. According to the method, complex operations such as bilinear pairing operation and large integer modular exponentiation operation are avoided by optimizing the group key derivation process based on the CRT, and the calculation complexity is remarkably reduced. Meanwhile, efficient cross-domain authentication and batch verification are realized through Pedersen commitment and a zero-knowledge proof technology, and communication and calculation overhead is reduced.
Owner:SOUTHEAST UNIV

Block chain smart contract controllable anonymous optimization method

The invention provides a controllable anonymity optimization method for a block chain smart contract, and belongs to the technical field of block chain smart contracts, and the method comprises the steps: generating a user private key through employing a threshold secret sharing protocol and a three-layer GPU acceleration architecture, storing a corresponding relation between identity information and a Hash ciphertext to a supervision center, and carrying out the encryption of the user private key; a user signs a smart contract calling parameter by using a private key and then sends the smart contract calling parameter to a block chain network, a block chain node extracts all signatures in a transaction to construct a dependency graph and groups each parallel verification group by using a greedy coloring algorithm, and parallel verification is performed on each parallel verification group by using bilinear pairing batch processing and a three-layer GPU acceleration architecture. After verification is passed, intelligent contract service logic is executed to complete transaction uplink, the supervision user retrieves the user identity information original text through the Hash ciphertext, and the technical problem that the on-chain calculation cost is too high due to the fact that signature batch verification efficiency is low when controllable anonymity is achieved in the block chain intelligent contract is solved.
Owner:SHUJIN PUBLIC SERVICE (QINGDAO) CO LTD +1

Anonymous credential generation system and method

The invention discloses an anonymous voucher generation system and method, and belongs to the technical field of computer security, and the anonymous voucher generation system comprises a certificate mechanism, a plurality of users and a server side. The certificate authority is used for sending the attribute, the credential value, the pseudonym and the accumulator evidence of the first user to the first user; the first user is configured to generate a blinded credential using the credential value, generate an accumulator auxiliary parameter based on the accumulator value and the accumulator evidence, generate a first zero knowledge proof based on the accumulator auxiliary parameter and a blinding auxiliary parameter in the blinded credential, the first zero knowledge proof is used for proving that the first user has the blinded certificate, the accumulator evidence, the accumulator auxiliary parameter and the blinding auxiliary parameter; and the server side is used for verifying the validity of the first zero knowledge proof, and verifying the correctness of the public attribute, the blinded certificate and the accumulator auxiliary parameters by adopting a bilinear pairing operation. The system can reduce the calculation overhead of the user in the anonymous credential technology.
Owner:WUHAN UNIV

Bls traceable secure threshold signature method and system based on distributed key generation

The present application belongs to the technical field of information security, and particularly relates to a BLS traceable security threshold signature method and system based on distributed key generation. The method comprises the following steps: S1, generating a bilinear pairing environment, and initializing public security parameters; S2, determining a group mapping relationship based on a symmetric balanced incomplete block design, each participant interacting in a group to generate respective key shares and a system global public key; S3, a signer performing partial signature and zero-knowledge proof corresponding to the partial signature on a message according to the corresponding key share; S4, an aggregator collecting and verifying the partial signature, screening out an effective signature set, aggregating to generate a final signature, and generating a commitment ciphertext; S5, a verifier verifying the final signature, and confirming the signature as valid if the verification is passed; S6, when the verification is not passed, a tracing mechanism is activated, and a tracer traces the signature group; and S7, according to the group mapping relationship, regularly performing active refreshing of the key shares.
Owner:ZHEJIANG SCI-TECH UNIV +1

A blockchain-based distributed data encryption sharing method

PendingCN122119943ASecuring communicationAccess structureCiphertext
The application discloses a kind of distributed data encryption sharing methods based on block chain, and using block chain realizes the traceable management of search and authorization process.The scheme is first by multi-authorization center to carry out distributed management to attribute domain, and generates attribute key associated with identity for user;In access verification link, construct parameter masking mechanism based on bilinear pairing, so that user attribute private key is not directly exposed in block chain verification and query process.Secondly, data owner carries out layered encryption to shared data and session key, and constructs the improved multi-key search structure, index and ciphertext positioning information are recorded to block chain, to support fast positioning target ciphertext.In addition, the application uses linear secret sharing to set access structure, and designs subset determination mechanism of general attribute name set, binds the download permission of ciphertext with the attribute condition that user can satisfy, to prevent overreach download behavior.Finally, with the help of cloud, outsourcing decryption is executed to generate intermediate result, and terminal only needs to complete light recovery and decryption.The application can give consideration to fine-grained control, high-performance search access and terminal side low load, and is suitable for secure data encryption sharing in resource-limited scene.
Owner:SOUTHEAST UNIV

An optimization method for controllable anonymity of a blockchain smart contract

This invention provides an optimized method for controllable anonymity of blockchain smart contracts, belonging to the field of blockchain smart contract technology. This invention generates user private keys using a threshold secret sharing protocol and a three-layer GPU-accelerated architecture, storing the correspondence between identity information and hash ciphertext in a monitoring center. Users sign smart contract call parameters using their private keys and send the results to the blockchain network. Blockchain nodes extract all signatures from the transaction, construct a dependency graph, and group them using a greedy coloring algorithm. Each parallel verification group is then verified in parallel using bilinear pairing batch processing and a three-layer GPU-accelerated architecture. After successful verification, the smart contract business logic is executed to complete the transaction on-chain. Monitoring users retrieve the original user identity information using the hash ciphertext. This invention solves the technical problem of low efficiency in batch signature verification leading to excessively high on-chain computation costs when achieving controllable anonymity in blockchain smart contracts.
Owner:SHUJIN PUBLIC SERVICE (QINGDAO) CO LTD +1

Two-way authentication key negotiation method and electricity consumption information collection system using the method

This invention belongs to the field of smart grid technology, specifically relating to a two-way authentication key negotiation method and an electricity consumption information collection system using this method. During the two-way authentication key negotiation process, both parties generate their own digital signatures, and include the digital signatures and timestamps in the generated authentication key negotiation request message, authentication key negotiation response message, or authentication key negotiation confirmation message. After each signature is successfully authenticated, both parties are considered to have authenticated each other's identities. This method applies a certificate-free authentication key negotiation protocol based on the elliptic curve discrete logarithm problem (without bilinear pairings) to a high-speed dual-mode communication system for electricity consumption information collection. This eliminates the necessity of traditional public key certificates in authentication key negotiation, avoiding the problems of high computational overhead, communication latency, storage space, and high power consumption caused by certificate management in the high-speed dual-mode communication system for electricity consumption information collection. Furthermore, the addition of timestamps to the messages helps resist replay attacks.
Owner:HENAN XJ INSTR +1

Identity verification middleware applied to PaaS platform

The invention relates to identity authentication middleware applied to a PaaS platform, and belongs to the field of data processing, and the identity authentication middleware comprises a user interface which is used for providing a task creation interface, a data uploading interface and an application configuration interface for a user; the identity verification module is used for verifying the identity of the user based on a bilinear pairing technology; the application program interface server is used for receiving an API request of a user; the composer is used for screening user requests initiated by the users passing the identity verification and determining resource scheduling schemes for all the user requests; the workflow engine is used for converting the resource scheduling scheme into a workflow; the execution adapter is used for converting the task description in the workflow into a specific operation command; the application directory module is used for storing all scientific applications supported by the PaaS platform and parameter templates of the scientific applications; the credential management module is used for managing keys of the user and the cloud service provider; and the message system is used for asynchronous communication among the components in the identity authentication middleware.
Owner:CHINA DATACOM CORP LTD

Identity-based encryption method for multi-data owner sharing

PendingCN122339674APlaintextCiphertext
This invention discloses an identity-based encryption method for multi-owner sharing. Multiple data owners distribute and manage a share of the master secret, using a Shamir threshold mechanism to achieve secure, distributed storage and use of the master secret. The user end non-interactively generates a complete user private key by aggregating partial keys from a threshold number of data owners. The encryption end generates ciphertext using the system public key and identity identifier, and the decryption end recovers the plaintext through bilinear pairing operations. This invention completely eliminates the single point of failure risk of traditional identity-based encryption, ensuring that the master secret does not need to be reconstructed throughout the key generation process, thus improving system security and efficiency. It is suitable for privacy protection scenarios such as distributed storage and blockchain.
Owner:ANHUI UNIV

Medical image file data management system

The invention discloses a medical image file data management system, and belongs to the technical field of zero-knowledge proof. Comprising a verifiable zero-knowledge image fingerprint generation module, a multi-modal federal feature fusion training module, a dynamic contribution intelligent quantitative excitation module, a dynamic privacy calculation sandbox module, an intelligent diagnosis routing network module and an archive evaluation optimization module. Global features and local features of an original medical image are mapped into polynomials and encrypted through a hash function, fingerprints only containing feature parameters are generated, image content is prevented from being directly exposed, and original data are not leaked while fingerprint legality is ensured through calculation of a bilinear pairing function and an elliptic curve base point in a verification stage; and the block chain evidence storage further ensures that the fingerprints cannot be tampered.
Owner:INNER MONGOLIA NORMAL UNIVERSITY

Proxy re-encryption method and system

The invention relates to a proxy re-encryption method and system. The system comprises a first user side, a second user side and a proxy server side, the method comprises the following steps: a first user side and a proxy server side generate a first shared secret; the second user side and the proxy server side generate a second shared secret; the first user side encrypts the plaintext to obtain an original ciphertext; the second user side generates a second random number, calculates a first intermediate parameter, sends the first intermediate parameter to the first user side, and sends the second random number to the proxy server side; the first user side calculates a second intermediate parameter and sends the second intermediate parameter to the proxy server side; and the proxy server side calculates a conversion parameter based on the first shared secret, the second shared secret, the second random number and the second intermediate parameter, converts the original ciphertext to obtain a new ciphertext, and sends the new ciphertext to the second user side for decryption. According to the method, bilinear pair calculation is avoided, only numerical multiplication calculation is used, and the processing performance is improved.
Owner:THE FIRST AFFILIATED HOSPITAL OF HENAN UNIV OF SCI & TECH

Identity authentication method of alliance chain under identity-based strong permission control mode

The application discloses an identity authentication mode of a consortium chain in a strong permission control mode based on identification, calculates a user public key from a user identification and a set of public mathematical parameters by using an elliptic curve bilinear pair theory, the user public key comprises a user identification and a version number of the user on the consortium chain, wherein the user identification is used for identity authentication, and the version number is used for key update; and a user private key corresponding to the user public key is calculated from the user identification, the set of public mathematical parameters and a secret value in a domain range, and is uniformly generated by a key generation center and downloaded to the user. The application adopts the above identity authentication mode, does not need the participation of a trusted third party, effectively resists attacks of intermediaries, does not need to bind identity information and a public key by using a digital certificate, reduces the bandwidth occupied by the transmission of a certificate in an identity authentication process, improves identity authentication efficiency, and solves the problem of IBC key update.
Owner:BEIHANG UNIV

Efficient aggregation anonymous verification method for vehicular ad hoc networks and related devices

The embodiment of the application discloses a kind of vehicle ad hoc network efficient aggregation anonymous verification method and related device, the method is verified based on the freshness of time stamp first, guarantee the freshness of time stamp from source;Then the validity of single signature is verified one by one, eliminate received invalid signature;Finally, aggregate signature verification is carried out, and the overall validity of all signatures can be verified by once bilinear pairing operation, compared with the verification of traditional method one by one, multiple bilinear pairing operations are needed, and the calculation complexity can be reduced.In high concurrency scene, processing delay is shortened from seconds to hundreds of milliseconds, which can effectively solve the problem of low efficiency of dynamic message authentication in Internet of Things, especially in vehicle networking, and meet the real-time demand.In addition, the application also introduces the smart contract and distributed digital identity verification technology of block chain, which can prevent malicious attacks of Internet of Things virus or node, and it is particularly important to improve privacy protection and prevent privacy leakage.
Owner:ANHUI AGRICULTURAL UNIVERSITY

Data sharing method based on bilinear pairing and linear secret sharing scheme

The invention discloses a data sharing method based on a bilinear pairing and linear secret sharing scheme, and relates to the technical field of information security, the method comprises the following steps: step 1, inputting security parameters, and generating a main public key and a main private key; step 2, generating an encryption key based on the main private key and an attribute set S of a sender; step 3, generating a decryption key based on the main private key and an access strategy of a receiver; step 4, generating a ciphertext by using the encryption key, the attribute set S of the sender, the access strategy R of the sender and a plaintext; 5, generating a trap door for strategy matching based on the main public key and the preference of the receiver; step 6, verifying the matching between the attribute of the sender and the strategy of the receiver, and forwarding the ciphertext only when the matching succeeds; and step 7, the receiving party reconstructs the plaintext by using the decryption key.
Owner:NINGBO ARTIFICIAL INTELLIGENCE RES INST OF SHANGHAI JIAOTONG UNIV

An anonymous dynamic authentication and key agreement method based on certificateless signature

This invention discloses an anonymous dynamic authentication and key negotiation method based on certificateless signatures. This method is based on a system model operating in an edge intelligent IoT environment, consisting of four entities: intelligent nodes, a key generation center, edge nodes, and a trusted authority. The method comprises five stages: system initialization performed by the key generation center; pseudo-identities assigned to system entities and public-private key pairs generated through entity registration involving intelligent nodes, edge nodes, and the trusted authority; mutual authentication and key negotiation between intelligent nodes and edge nodes; batch authentication; and encryption transmission of intelligent IoT data using a symmetric encryption algorithm based on the negotiated session key. This invention, based on a certificateless signature mechanism, avoids the complexity of certificate management and key escrow, while eliminating high-overhead operations such as bilinear pairing and exponential operations, effectively reducing the computational burden on resource-constrained terminals.
Owner:GUIZHOU NORMAL UNIVERSITY

Lightweight message distribution mechanism of Internet of Things terminal equipment based on block chain

The invention discloses a block chain-based lightweight message distribution mechanism for Internet of Things end equipment, CP-ABE decryption operation is unloaded to edge equipment for processing, and after the edge equipment completes ciphertext dimension reduction conversion, terminal equipment only needs to execute bilinear pairing operation and group element multiplication operation once to complete decryption. A task scheduling mechanism based on attribute cooperative authorization is designed, and distribution of ciphertext conversion tasks between edge devices is supported. According to the method, the ciphertext is encrypted by adopting CP-ABE, the identity information of the message receiver on the block chain is encrypted and hidden, and the temporary identity credential is decrypted on the edge equipment, so that correct distribution of the message is ensured, and the risk of inferring the long-term behavior privacy of the user through on-chain transaction mode analysis is prevented. A credible collaboration system is constructed based on an intelligent contract, and the traceability of a collaboration process, the compliance of node screening and the blocking of illegal equipment are guaranteed. The mechanism effectively avoids the limitation of the traditional scheme in the aspects of terminal computing load, edge expansibility, identity privacy protection and the like.
Owner:JIANGSU UNIV

Data encryption method, decryption method, and revocable ciphertext database disease matching system

The application discloses a data encryption method, a decryption method and a revocable ciphertext database disease matching system, and the ciphertext database disease matching system comprises a user end, a matching end and a cloud server, the user end is at least two, the user ends are connected with each other, each user end is connected with the matching end respectively, and each user end and the matching end are connected with the cloud server respectively. By introducing the time key, the matched authorization trapdoor and the ciphertext have time effectiveness, when the user wants to revoke the matching authority of the medical institution staff at the current time, the matched authorization trapdoor and part of the ciphertext are updated, and the distribution of the authorization trapdoor of the current time is stopped, so that the medical institution staff cannot perform data matching, and the lightweight revocation is achieved. When data matching is performed, a bilinear pair operation is not needed, efficient matching is achieved, the application has practicability, and can be widely applied to medical systems and other scenes.
Owner:SOUTH CHINA AGRICULTURAL UNIVERSITY

A two-way verifiable secure aggregation method for federated learning

PendingCN122316633ATrusted authorityData set
This invention discloses a bidirectional, verifiable, and secure aggregation method for federated learning, comprising three entities: a trusted authority, a client, and a server. Bidirectional verification is achieved through verifiable secret sharing and homomorphic encryption: the server verifies the legitimacy of the client's identity before aggregation, and the client independently verifies the correctness of the server's aggregation result before updating. The specific process includes five stages: initialization, key distribution, masking and sharing, verification and aggregation, and checking and updating. The protocol uses Paillier homomorphic encryption to protect model gradient privacy, avoids high-complexity operations such as bilinear pairing, and reduces verification computational overhead. Experiments on the MNIST and CIFAR-100 datasets verify the correctness and efficiency of the protocol. Compared with existing schemes, it has advantages in computational and communication costs, while enhancing the robustness and security of federated learning.
Owner:NANJING UNIV OF POSTS & TELECOMM

A public key searchable encryption method and system against internal keyword guessing attacks

This invention discloses a public-key searchable encryption method resistant to internal keyword guessing attacks. It generates system public parameters based on bilinear mapping. The data receiver generates a public-private key pair and publishes the public key. The data sender first selects a random retrieval value, uses the receiver's public key to generate a retrieval encapsulated ciphertext and a keyword ciphertext, and uploads them to a cloud server. The data receiver retrieves the retrieval encapsulated ciphertext from the cloud server, calculates the random retrieval value, uses its own private key combined with the retrieval keyword to generate a keyword trapdoor, and uploads it to the cloud server. The cloud server compares the keyword trapdoor with the keyword ciphertext through a bilinear pairing operation; if a match is found, the corresponding ciphertext data is returned. This invention eliminates the need for the sender to configure any keys, and by using a joint binding mechanism of encrypted retrieval random values ​​and keywords, it fundamentally blocks internal keyword guessing attacks, achieving a highly secure, efficient, and lightweight public-key searchable encryption scheme.
Owner:NANJING UNIV OF POSTS & TELECOMM

An identity authentication middleware applied to a PaaS platform

The application relates to an identity authentication middleware applied to a PaaS platform, belonging to the field of data processing, and comprising the following: a user interface used for providing a user with interfaces for task creation, data uploading and application configuration; an identity authentication module used for authenticating the identity of a user based on a bilinear pairing technology; an application program interface server used for receiving an API request of the user; an orchestrator used for screening a user request initiated by the user who passes the identity authentication, and determining a resource scheduling scheme for each user request; a workflow engine used for converting the resource scheduling scheme into a workflow; an execution adapter used for converting a task description in the workflow into a specific job command; an application directory module used for storing all scientific applications and parameter templates supported by the PaaS platform; a credential management module used for managing the keys of the user and a cloud service provider; and a message system used for asynchronous communication between various components in the identity authentication middleware.
Owner:CHINA DATACOM CORP LTD

Controllable function calculation method for data flow utilization

The invention relates to the technical field of data security and privacy computing, and discloses a controllable function computing method for data circulation and utilization, which comprises the following steps of: constructing system parameters based on a bilinear mapping group; according to the predicate vector and the function vector, generating a function decryption key containing a permission verification and calculation component; generating a ciphertext containing an attribute and data confusion component according to the attribute vector and the data vector; and carrying out orthogonality verification on the ciphertext by using the key, eliminating random interference only when the attribute and the predicate are orthogonal, executing pairing operation, solving discrete logarithms, and obtaining an inner product of data and a function. According to the method, strict calculation permission control is achieved through an orthogonality verification mechanism of bilinear pairings, meanwhile, attribute hiding and function hiding are achieved through randomized matrix transformation, specific inner product calculation is completed on the premise that original data are not leaked, and data are available and invisible.
Owner:GUIZHOU MINZU UNIV +1

Efficient mutual authentication of server and client

Password based authentication is one of the common forms of authentication used in practice. However, when a user / client device enrolls with a server using password information, the authentication process exposes hash of password information to the server which is prone to various types of passwords guessing attacks. Present disclosure provides a system and a method that authenticates a user without revealing his / her password information to a third-party identity provider. This is done by using bilinear parings to authenticate user without sending password information to the server and by way generating client shared secret, server secret, public key, private key and the like. This eliminates the need for storing any keys on multiple devices / third parties or storing password information on the server side.
Owner:TATA CONSULTANCY SERVICES LTD

An edge data sharing method and system with white-box tracking based on ciphertext policy attribute-based encryption

PendingCN122660955APlaintextCiphertext
The application discloses an edge data sharing method and system with white-box tracking based on ciphertext policy attribute-based encryption, and relates to the technical field of information security and edge computing. The method comprises the following steps: a certification agency generates public parameters and a global identifier on a bilinear group; each authorized agency selects three random numbers to issue a public key; the authorized agency embeds the global identifier value and a hash element into an attribute key to generate an outsourcing label and issues the outsourcing label to a user; a data owner generates outsourcing ciphertext by using an access matrix and linear secret sharing, and stores the outsourcing ciphertext in the cloud through an edge server; the user takes local random numbers and inverse elements thereof, performs key component operation with the inverse elements as exponents, combines an identity and a tracking label to obtain a conversion key, and submits the conversion key to the edge server; the edge server performs bilinear pairing and linear reconstruction to generate intermediate ciphertext and encapsulated components and returns the intermediate ciphertext and the encapsulated components to the user; and the user performs exponent operation on the intermediate ciphertext with the local random numbers to restore a session key and plaintext.
Owner:YUNNAN UNIVERSITY OF FINANCE AND ECONOMICS

Arweave light node verification method based on KZG polynomial commitment

The invention belongs to the technical field of block chains, particularly relates to an Arweave light node verification method based on KZG polynomial commitment, and solves the problems of high light node verification cost and prevention of miner parallel computing through the KZG commitment and chained hash challenge mechanism. Comprising the steps of system initialization, data commitment uplink, anti-cheating chained challenge path generation, aggregation existence proof calculation and light node bilinear pairing verification. According to the method, the bilinear pairing characteristic is utilized, so that the light node can verify whether the candidate block generated by the miner node and the historical data block have the access capability or not without downloading the original data, the verification and bandwidth overhead of the light node end is reduced, the verification efficiency of the light node is improved, and long-term storage of the data is ensured.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Low-altitude Internet of Things bidirectional anonymous authentication method based on BLS aggregation signature

The invention discloses a low-altitude Internet of Things bidirectional anonymous authentication method based on a BLS aggregation signature. The method comprises the steps that a trusted mechanism generates and discloses bilinear pairing system parameters; the unmanned aerial vehicle registers with a ground control station to obtain a public and private key pair based on a BLS algorithm and an initial dynamic pseudonym with timeliness; the unmanned aerial vehicle generates a BLS signature for the authentication message by using the current dynamic pseudonym and the private key and broadcasts the BLS signature; the ground control station executes aggregation verification on the received at least one BLS signature, and verifies the validity of all signatures at one time; the two parties complete bidirectional authentication after the verification is passed; and after the authentication session ends, the unmanned aerial vehicle updates the dynamic pseudonym without mathematical association between the new and old pseudonyms. According to the method, the calculation complexity of batch verification is reduced to a constant level through the BLS aggregation signature, and the authentication delay in a high-concurrency scene is remarkably reduced; and intersession linkability is cut off through a dynamic pseudonym updating mechanism, and identity and track privacy protection is realized.
Owner:JIANGSU UNIV OF TECH

Internet of Vehicles condition privacy data sharing method based on block chain

The invention discloses an Internet of Vehicles condition privacy data sharing method based on a block chain. The method comprises the steps that an authorization center generates system parameters and deploys a smart contract; obtaining a pseudo identity and a secret key based on the attribute set during vehicle registration; the data owner uploads the encrypted data and generates an index to the block chain; a data requester queries the index and sends a signature request; the smart contract verifies that the requester attribute meets the strategy and then returns encrypted data; the requester decrypts and verifies the data integrity, and initiates tracing if an exception is found; and the authorization center traces the identity of the malicious vehicle based on the audit log and executes management operation. According to the method, lightweight elliptic curve cryptography and symmetric encryption are combined, bilinear pairing is abandoned, unification of fine-grained access control, conditional privacy protection and efficient data sharing is achieved, and the problems that in the prior art, calculation overhead is large, privacy protection and access control are difficult to consider at the same time are solved.
Owner:ANQING NORMAL UNIV

SM9 key generation and attribute-based policy dynamic delivery method across mcu and server

The application discloses an SM9 key generation and attribute-based policy dynamic distribution method across MCUs and servers, and belongs to the technical field of Internet of Things devices. The application deeply binds the multi-dimensional attributes such as the device type and the geographic position of the MCU terminal to the terminal private key based on the SM9 identity cryptography system, realizes fine-grained access control between the cloud and the massive MCU terminals based on the device attributes, can realize differentiated permission management and control for terminals of different types and different deployment areas, greatly reduces the data transmission amount and the terminal operation amount during attribute change and policy adjustment through the private key incremental update and the policy incremental distribution mechanism, adapts to the characteristics of the MCU terminal resource limitation, reduces the operation overhead of large-scale deployment, optimizes the bilinear pairing operation process in combination with the decryption pre-computation processing, reduces the performance consumption of the decryption operation on the MCU terminal, and improves the policy decryption execution efficiency.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Dynamic threshold ring signature electronic voting method based on SM9 algorithm

The invention discloses a dynamic threshold ring signature electronic voting method based on an SM9 algorithm. The method comprises the following steps: a key generation center generates a public parameter according to a security parameter; the voters submit identity information to the registration center, and after verification is passed, the secret key generation center generates private keys bound with the identities and distributes the private keys to the voters through the secure channel; the server initiates a voting activity and generates a unique invitation code containing a dynamic threshold parameter; after the client inputs an invitation code, members are randomly selected through a reservoir sampling algorithm, a signature is generated in combination with an SM9 signature algorithm, efficiency is optimized through pre-calculation of bilinear pairs of parameters, and random numbers are adjusted through a Hash chain to ensure signature closeness; and the server analyzes the signature, verifies the consistency of the member set and the validity of the signature, and counts voting results and generates a visual report after a threshold condition is met. The method achieves remarkable effects in the aspects of dynamic adaptability, high efficiency, strong collusion resistance, high anonymity and the like.
Owner:SHAANXI SCI TECH UNIV

Lightweight certificateless authentication method based on double-layer threshold

The invention discloses a lightweight certificateless authentication scheme based on a double-layer threshold, and relates to the technical field of information security. The scheme aims to solve the problems of single-point failure of a key generation center and low key escrow and authentication efficiency in a certificateless system. According to the method, firstly, a decentralized key management mechanism is provided, a non-homogeneous double-variant polynomial is utilized to construct a double-layer threshold architecture of transverse node cooperation and longitudinal key synthesis, safe distribution and reconstruction of a main key and a private key are achieved, and the attack resistance and robustness of the key generation process are improved. On this basis, a lightweight anonymous authentication protocol is designed, a dynamic pseudo identity is generated through a random number to resist identity association attacks, and linear operation is adopted to replace bilinear pairing operation. The method is mainly used in a distributed network environment, reduces the calculation overhead while guaranteeing the privacy and anti-aggressiveness of the user, and improves the overall performance of an authentication system.
Owner:CHONGQING UNIV OF POSTS & TELECOMM