Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

109 results about "Block cipher" patented technology

In cryptography, a block cipher is a deterministic algorithm operating on fixed-length groups of bits, called blocks, with an unvarying transformation that is specified by a symmetric key. Block ciphers operate as important elementary components in the design of many cryptographic protocols, and are widely used to implement encryption of bulk data.

Systems and methods for establishing a secure digital network environment

According to the instant application, there are provided systems and methods to create a quantum secure / resistant secure communication channel (QSR-SCC) for communication between two or more end-points at or within devices, applications, services, APIs, secure communication protocols, etc. In one example of a QSR-SCC, a quantum secure / resistant private network (QSR-PN) extends existing VPN solutions using one time pad (OTP) based keys, augmented handshake mechanisms, and interchangeable ciphers, for example, stream ciphers or block ciphers, for enhancing security associated with the QSR-PN.
Owner:QDS HLDG INC

Flight data processing method and device of unmanned aerial vehicle and electronic equipment

The invention provides a flight data processing method and device for an unmanned aerial vehicle and electronic equipment, and relates to the technical field of communication, and the method comprises the steps: collecting the original flight data of the unmanned aerial vehicle through a sensor disposed on the unmanned aerial vehicle, and carrying out the calculation, denoising and smoothing of the original flight data, and obtaining the real-time flight data of the unmanned aerial vehicle; generating a flight data packet according with a specified format based on the real-time flight data, a specified unmanned aerial vehicle ID corresponding to the unmanned aerial vehicle and specified flight plan data; encrypting the flight data packet by using an SM4 block cipher algorithm to obtain flight ciphertext data; in response to detecting that the signal receiving power of the current network of the data recording equipment is greater than the specified power, transmitting the flight ciphertext data to a supervision server by using the current network; and in response to detection that the signal receiving power of the current network is lower than or equal to the specified power, switching a communication channel for transmitting the flight ciphertext data to a satellite short message communication channel.
Owner:SHANGHAI XINLAN INTELLIGENT TECH CO LTD

Anti-quantum message authentication code construction method and system adopting adjustable block cipher

The invention belongs to the field of passwords, and discloses an anti-quantum message authentication code construction method and system adopting an adjustable block cipher. The MAC generation method comprises the steps that two communication parties share a key value K generated by a key generation algorithm, the label length tau = Tag is agreed, the tau is limited to be smaller than or equal to n, and n represents the packet length; and taking the key K, the message M and the unique value N as input to generate a tau-bit message authentication code Tag. Furthermore, the MAC verification method verifies the generated message authentication code, and judges whether the message is correct or not and whether the message is accepted or not. According to the method, the adjustment handle value is an encryption result of a unique value initially, and then the adjustment handle is updated by using a function h when the adjustable block cipher is called every time. The method has the quantum attack resisting capability, and compared with the existing known MAC scheme with the quantum attack resisting capability, the required storage is small under the condition of providing the same quantum security intensity.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI +1

Time-sensitive network end-to-end secure communication method

The invention relates to a time-sensitive network end-to-end secure communication method, and belongs to the technical field of communication. According to the method, a TSN terminal system of Linux is used for realizing bidirectional identity authentication and key agreement based on an SM2 cryptographic algorithm, and an SM4-CCM algorithm is used for realizing time-sensitive network security communication and data integrity verification; the SM2 national secret algorithm is an asymmetric encryption algorithm, a signature pair is generated based on an elliptic curve discrete logarithm problem, the two parties negotiate a shared key through elliptic curve point operation, a public key of a receiver is used for encryption, and only a private key can be used for decryption; sM4-CCM is a combination of an SM4 block cipher algorithm and a CCM mode, and is used for providing confidentiality, integrity and authenticity of data; according to the CCM mode, through combination of CTR encryption and CBC-MAC authentication, efficient authentication encryption is realized. The method can be used for real-time secure communication in a high-reliability industrial scene.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Block cipher algorithm identification method based on multi-modal feature fusion

The invention discloses a block cipher algorithm identification method based on multi-modal feature fusion. The method comprises the following steps: firstly, converting ciphertext data into three modal representations of a text, an image and voice; then integrating a deep learning model suitable for each mode through a multi-mode feature fusion strategy, and performing feature extraction on ciphertext data of different modes; on this basis, based on a transform model and by adopting a medium-term fusion strategy, performing weighted fusion on the features of different modals, and training the model; and finally, based on the trained model, realizing identification of an encryption algorithm adopted by an unknown ciphertext. According to the method, feature extraction is completed through different encoders, a feature fusion thought is adopted, and a transform model containing a self-attention mechanism is introduced to perform multi-modal feature fusion, so that the robustness and generalization ability of the model are effectively improved, and the recognition accuracy of the model is improved.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Semiconductor device, processing method, control program, and recording medium

To suppress an increase in computation time in a semiconductor device while further improving resistance to side-channel attacks.SOLUTION: A semiconductor device (1) according to one embodiment of the present invention includes: a dividing unit (10) for dividing data into at least two pieces of divided data; a block cipher execution unit (10) for applying a specific process included in a block cipher algorithm only to at least one of the pieces of divided data among the at least two pieces of divided data; and a data holding unit (11) for holding, in each block, the pieces of divided data to which the process has been applied only to a part thereof, the data holding unit (11) being configured such that side-channel information radiated differs at least partially among the blocks.SELECTED DRAWING: Figure 3
Owner:SHARP SEMICON INNOVATION CORP TENRI CITY

Apparatus and method for detecting elements of an assembly

A processing module for a communication device includes memory for storing a key and processing elements. These elements receive a current sequence number and a random number from a network entity, and check if the current sequence number is within a range based on a previously received sequence number stored in memory. If not, they generate a sequence number encryption key from the random number and stored key, encrypt the previously received sequence number using a block cipher encryption function, and send the encrypted sequence number in a response message to the network entity.
Owner:VODAFONE GROUP SERVICES LTD

Method, apparatus, system, and computer program for authenticated encryption providing enhanced security and nonce length extension

The present disclosure relates to an authenticated encryption method, apparatus, system, and computer program for providing enhanced security and extension of a nonce length, and more specifically, the present disclosure discloses a method for performing authenticated encryption using a computing apparatus, the method including: producing a plurality of intermediate values, based on a given input value; generating a random number, based on a combination of a plurality of intermediate random values produced by performing block cipher-based encoding on the plurality of intermediate values; and performing encryption or decryption, based on the random number.
Owner:SAMSUNG SDS CO LTD

Block cipher key security analysis method based on neural discriminator

The invention provides a block cipher key security analysis method based on a neural discriminator. The method comprises the following steps: generating a plaintext pair according to a given input differential feature; the method comprises the following steps of: respectively carrying out specified round encryption operation on a plaintext pair by utilizing a grouped key to obtain a primary ciphertext pair, respectively carrying out full round encryption on the plaintext pair by utilizing a random grouped key to obtain a complete ciphertext pair, and calculating an intermediate state difference of the primary ciphertext pair; marking the complete ciphertext pair according to an intermediate difference screening mechanism to construct a training sample; training a deep learning neural network model by using the training sample; and inputting a to-be-analyzed ciphertext pair into the trained deep learning neural network model, and outputting a classification result whether a preset difference feature condition is met or not. The method shows excellent adaptive capacity to unknown encryption rounds and key variants, and the password security analysis effect is improved.
Owner:BEIJING ELECTRONICS SCI & TECH INST

A self-reversible block cipher, application, instruction set, device and program

Disclosed is a block cipher with a self-reversible overall structure. The self-reversible structure is constructed from three inventive points: 1. The main structure starts with an odd-numbered round and alternates between even-numbered and odd-numbered rounds. 2. The odd-numbered round consists of three components in series, decomposing in the encryption direction as: entry operator → S-odd component → exit operator, where the two operators are designed to be inverses of each other, and the inputs of the entry and exit operators are connected to the wheel key. Even-numbered rounds are equal to S-even; both S-odd and S-even are self-reversible logic design components. 3. It is recommended that S-even ≠ S-odd. The main effect of this invention is that the encryption and decryption logic are completely consistent, and the mode transition is equivalent to the reversed wheel key, enabling the construction of a fast-spreading SP-type block cipher. Also disclosed are X-component design, EWES, and other embodiments, operating mode applications, instruction set design methods, IP core products, CPU products, devices, and programs.
Owner:BEIJING RED & BLUE TREE TECHNOLOGY CO LTD

Quantum block cipher resisting coprocessor for computer monitoring system and operation method

The invention discloses an anti-quantum block cipher coprocessor operation method for a computer monitoring system, and the method comprises the following steps: S1, loading data to generate a random number and a secret key, and splicing the random number and the secret key with a preset initialization vector to generate an input state; s2, receiving the associated parameters and the plaintext, and performing preprocessing to generate grouping mask shares; s3, performing parallel encryption on the grouped mask shares based on an input state to generate a plurality of mask ciphertexts and mask authentication tags; and S4, performing linear reconstruction on the mask ciphertext to finally run to obtain a complete ciphertext, decomposing plaintext data into a plurality of mask shares for parallel processing, effectively diluting data structure features, and fundamentally cutting off a way of acquiring key information by an attacker through power consumption analysis. Compared with the prior art, the parallel computing advantage of reconfigurable hardware is fully utilized, efficient execution of cryptographic operation is achieved, the whole data processing process is completed in the register, and the influence of memory access delay on system performance is remarkably reduced.
Owner:HANGZHOU HUADIAN BANSHAN POWER GENERATION

Authentication encryption method and system with bidirectional linearity

The invention discloses an authentication encryption method and system with bidirectional linearity. The method comprises the following steps of: (1) jointly selecting an n-bit block cipher E, a secret key K and a block length m by participants; (2) executing an encryption scheme by a sender: calculating an initial state S0 = EK (N) according to a temporary value N; dividing the plaintext M into m bits of blocks M1,..., M1; connecting the Mi with the bit representation of the ordinal number in sequence, inputting a state chain value Si-1 and the Mi [i] n-m into a linear mixing function rho to obtain Si and Ci, and outputting a ciphertext Ci; for the last two blocks Ml-1 and M1, calculating C * for the Ml-1 by using the same method, dividing the C * into Cl-1 and Z, and outputting the Cl-1; and connecting and filling the M1 and the Z, calculating # imgabs0 # and a plaintext length M, calculating # imgabs1 #, and outputting the # imgabs1 #. And (3) the receiver executes the decryption scheme, checks the correctness of the ciphertext and outputs a correctly decrypted plaintext. The method has the implementation advantage of low storage space, the required storage space is close to the block length (32-512 bits) of the block cipher, and the method is suitable for application scenes with limited resources.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Agricultural perception node-oriented lightweight secure communication method and system

PendingCN122457243APlaintextCloud data management
The application discloses a kind of light security communication method and system for agricultural perception node.The method includes that 256-bit static master key is preset in the bottom layer security storage area of perception node and heterogeneous convergence gateway, and the unique hardware serial number is read as node identification;Synchronous acquisition environmental data and visual feature data, splice into long payload plaintext;Derive dynamic session key, use dynamic session key to drive stream cipher to encrypt long payload plaintext, static master key drives block cipher to encrypt short header, and encapsulates into data frame;Data frame is sent through wireless channel, and heterogeneous convergence gateway receives and reversely decrypts short header to extract dynamic anti-fake factor, and replay attack verification is carried out;After verification, dynamic session key is reconstructed to restore data and uploaded to cloud data management server.The application also discloses a system using the above light security communication method for agricultural perception node, realizes the high security node legitimacy authentication and anti-replay attack under limited hardware computing power.
Owner:QIQIHAR UNIVERSITY

Method for updating cryptographic keys to 256-bit cryptographic keys using a cryptographic key update system

Methods for updating 256-bit cryptographic keys using a cryptographic key update system include the transmission of a first transmission, a second transmission, and a third transmission. The second transmission is a symmetric key encryption using a cipher key consisting of a concatenation of a plurality of parameters and a new cryptographic key.The sender derives the encryption key by transforming an authentication key and a bit sequence of constant values ​​based on a one-way compression function, which is one of the following: a Modification Detection Code 2 (MDC-2) cryptographic hash function with an advanced 128-bit encryption standard (AES-128) as the underlying block cipher, a Modification Detection Code 4 (MDC-4) cryptographic hash function with the advanced 128-bit encryption standard (AES-128) as the underlying block cipher, the Hirose compression function with the advanced 256-bit encryption standard (AES-256) as the underlying block cipher, and a 256-bit hash function.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Galois extension field-based block cipher

Various examples are provided related to a block cipher adaptation of the Galois Extension Fields (GEF) combination technique. In one example, a GEF-based block encryption includes forming an output from a PRNG into a key matrix, where the key matrix is formatted as an invertible square matrix; applying a GEF operation to the key matrix to map elements to a closed subset in a higher-order GEF space; mapping plaintext to a plaintext matrix; applying a GEF operation to the plaintext matrix to map elements to the higher-order GEF space; combining the plaintext matrix and the key matrix to produce a vector of ciphertext in the higher-order GEF space; reducing the vector to a reduced vector of ciphertext using an inverse of the GEF operation; and during the reducing, applying a ceiling operation to bijectively map elements in the reduced vector to a closed subset. Another example includes GEF-based block decryption.
Owner:VIRGINIA TECH INTELLECTUAL PROPERTIES INC

Encryption scheme for providing software update to update agent

To provide an efficient and secure solution for managing encryption of a software image updated on a secure element.SOLUTION: The present invention relates to methods, apparatuses and systems for implementing an encryption scheme for providing a software image to a secure element. The software image is converted into a sequence of ciphered blocks, which is protected with an authentication tag to obtain a sequence of protected blocks, which are then transmitted to an update agent on the secure element. The steps of converting the software image into a sequence of ciphered blocks and protecting the sequence of ciphered blocks with an authentication tag are implemented by an authenticated encryption function using a same block cipher.SELECTED DRAWING: Figure 3
Owner:GIESECKE PLUS DEFRIENT MOBILE SECURITY GERMANY GMBH

Quantum security parallelizable message authentication code construction method and system

The invention discloses a parallel message authentication code construction method and system for quantum security. The method comprises the following steps: 1) selecting an adjustable block cipher algorithm key K, nonlinear transformation theta and the length tau of a message identification code by a participant; 2) the sender executes an MAC generation scheme, takes the key K, the temporary value N and the message M as input, outputs a message identification code and sends the message identification code to the receiver; the flow of the MAC generation scheme is as follows: a) dividing a message M into a plurality of n-bit groups; b) encrypting the ith group Mi by using an algorithm, and inputting theta to obtain a state Si after the output and the state Si-1 are subjected to XOR; c) intercepting the leftmost side tau bit of the state Sm corresponding to the last group as a message identification code; and 3) the receiver executes an MAC verification scheme, and verifies whether (MAC, M) is correct or not by taking the key K, the temporary value N, the message M and the message authentication code MAC as input.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Multi-scale pooling feature-based block cipher algorithm identification method

The invention discloses a block cipher algorithm identification method based on multi-scale pooling characteristics. The method comprises the following steps: normalizing a ciphertext data set after encrypting a public data set, and carrying out multi-scale segmentation; constructing calculation methods of a repetition degree feature, a compression ratio feature, a frequency deviation, a run observation value and a structural strength feature, calculating a feature vector of each segmented ciphertext, and carrying out pooling calculation to obtain a feature data set of the ciphertext; inputting the feature data set into the constructed gradient boosting decision-making tree for training to obtain an optimal decision-making tree; and for unknown ciphertext data, the trained optimal gradient boosting decision tree is used as a classifier to complete the identification of the cryptographic algorithm. The method is based on multiple scales, adopts multiple feature calculation methods to quantify subtle differences of different ciphertext data, and performs feature fusion through pooling calculation, so that the feature extraction capability of the ciphertext data is improved, and the cryptographic algorithm recognition accuracy of the model is improved.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Block cryptographic method for encrypting / decrypting messages and cryptographic devices for implementing this method

ActiveUS12676730B2AlgorithmCiphertext
A block cipher method and apparatus using round repetition for providing, from a plaintext message (10), a ciphertext message (50) and a global tag (52) is disclosed. The plaintext message is converted into a plurality of ordered plaintext blocks (11) which are successively processed during a round for computing:—a cryptogram (30) by encrypting input data (20) using a single cryptographic key, said cryptogram comprising a first segment (31) and a second segment (32)—a ciphertext block (51) by performing a first operation (41) using, as operands: said first segment (31) said current plaintext block (11) and said second segment (32). At each next round said input data is newly determined based on the current ciphertext block and an updated reproducible data. The ciphertext message is determined by concatenating the ciphertext blocks and the global tag by a second operation (42) using computed authentication local tags as operands.
Owner:NAGRAVISION SA

Block cipher side channel analysis method based on experience accumulation and three-dimensional decision

The invention relates to a block cipher side channel analysis method based on experience accumulation and three-dimensional decision, and belongs to the technical field of cipher security analysis and side channel analysis. Aiming at the problems of large search space, low information utilization rate, computing power waste and the like in the traditional correlation coefficient energy analysis, the method provides an analysis framework combining a dynamic hierarchical screening mechanism and a cross validation strategy. The method comprises the following steps: randomly initializing each byte of a key to generate a candidate set; constructing a three-dimensional decision-making structure comprising a data layer, a statistical layer and a decision-making layer so as to record and analyze correlation coefficient distribution; screening conditions are automatically tightened through dynamic threshold attenuation, and the search range is gradually reduced; and adopting a multi-stage single-byte perturbation and cross validation strategy to carry out iterative optimization and ranking on each byte candidate value, and finally selecting an optimal key combination to carry out verification. According to the method, the success rate, robustness and convergence speed of side channel analysis are effectively improved, and the method is suitable for key recovery of block cipher.
Owner:BEIJING INST OF TECH +1

A GPU-based optimal differential characteristic search method for ARX-type block cipher

The application discloses a GPU-based ARX type block cipher optimal differential characteristic search method, which first selects a high-probability differential transition to split the whole search process into forward search and reverse search; differential transition construction and probability calculation are taken as kernel functions, a GPU-based parallel scheme is designed, and the differential transition probability of different states in each round is calculated in parallel; the GPU parallel calculation result and the set probability threshold are taken as the determination condition of pruning in the search process, the optimal differential characteristic is searched round by round according to the branch and bound strategy, the forward and reverse searches are completed, and the optimal differential characteristics of the two parts are obtained; finally, the optimal differential characteristics of the two parts are spliced to obtain the optimal differential characteristics of the complete rounds. The search method can effectively reduce the recursion depth, improve the search efficiency through parallel calculation, shorten the calculation time and improve the search speed of the ARX type block cipher optimal differential characteristic.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Cryptographic key update system for updating 256-bit cryptographic key

A method for updating a 256-bit cryptographic key by a cryptographic key update system includes transmitting a first transmission, a second transmission, and a third transmission. The second transmission is symmetric key encryption under a serial key encryption key and a new cryptographic key of a plurality of parameters. The transmitter derives a key encryption key by converting an authentication key and a constant bit string based on a one-way compression function, the one-way compression function is one of the following functions: taking a 128-bit advanced encryption standard (AES-128) as a password hash function of a modified detection code 2 (MDC-2) of a bottom block password, taking the 128-bit advanced encryption standard (AES-128) as a password hash function of a modified detection code 4 (MDC-4) of the bottom block password, and taking a 256-bit advanced encryption standard (AES-256) as a Hirose compression function of the bottom block password; and a 256-bit hash function.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Fast post-quantum cryptographic sortition

A method for cryptographic sortition among a group of parties includes committing, by a first party, to a set of n party-specific secret keys k1, kn for a block cipher E and obtaining, by the first and a second party, a common input x and an index r. The method further includes encrypting, by the first party, the input x with the r-th key kr of the committed keys k1, . . . , kn, thereby generating an output y1 of the block-cipher E, and publishing the output y1 with the key kr used for encryption. The method further includes encrypting, by the second party, the common input x with the published key kr, thereby generating an output y1′ of the block-cipher E, and comparing the generated output y1′ with the published output y1. The method can be used to optimize the cryptographic sortition and support secure decision making.
Owner:NEC CORP

A method for recognizing block ciphers based on quantum self-organizing fuzzy neural network

The application relates to a grouping cipher identification method based on a quantum self-organizing fuzzy neural network. The method comprises the following steps: acquiring ciphertext data to be identified and encoding the ciphertext data into an input quantum state; processing the ciphertext data to be identified and an activation intensity vector of a multi-expert system by using a biological heuristic gating network and a neural synapse excitation-inhibition mechanism to determine a net synapse input value of each quantum expert; adopting a Top-K sparsification strategy to select k quantum experts with the maximum net synapse input value from the multi-expert system to form an activated expert subset; analyzing the net synapse input value and the corresponding activation intensity of each quantum expert in the activated expert subset to determine the final gating weight of each quantum expert in the activated expert subset; inputting the input quantum state into each quantum expert in the activated expert subset to identify the grouping cipher type, and obtaining a final grouping cipher type identification result. Resource consumption is reduced.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Cryptographic algorithm and operation mode classification method and system based on BCAM-LGST model

The invention discloses a cryptographic algorithm-mode classification method and system based on a BCAM-LGST model, and belongs to the technical field of information security and cryptographic analysis. Comprising the following steps: converting an original ciphertext into a fixed-length sequence and a grayscale image in parallel, and constructing complementary bimodal data representation; the method comprises the following steps: extracting high-level probability features of a sequence by adopting a LightGBM model as semantic priori, and carrying out cross-modal depth fusion on a priori-guided hierarchical dual-channel gating modulation mechanism and image structure features extracted by Swin Transform; and introducing spatial position association of a spatial perception enhancement matrix enhancement feature, and carrying out multi-scale feature modeling on a fusion feature under prior guidance by using layered window attention, so as to finally realize end-to-end joint classification. The block cipher algorithm-mode joint identification method can quickly, accurately and robustly realize block cipher algorithm-mode joint identification, and is suitable for practical engineering scenes such as network security level protection, cipher application security evaluation, digital forensics, encrypted traffic analysis and compliance auditing.
Owner:NINGXIA UNIVERSITY

Lightweight, cryptographically based system for secure firmware updates for Internet of Things devices

A secure firmware update system for Internet of Things (IoT) devices using simple cryptographic mechanisms. The system includes: a communication interface configured to receive firmware update data packets from an update server over a wired or wireless network; a secure update processing unit that is operationally coupled with the communication interface, wherein the secure update processing unit comprises the following: a cryptographic verification processing unit configured to authenticate firmware update data packets using a simple digital signature scheme selected from hash-based signatures, restricted-environment optimized elliptic curve signatures, or message authentication codes (MACs) generated by block ciphers with reduced rounds; a decryption module configured to decrypt encrypted firmware payloads using light symmetric encryption techniques stored in secure non-volatile memory, with the decryption keys provided in a tamper-proof form; an integrity check control unit configured to perform rolling hash-based validation of decrypted firmware segments to ensure end-to-end update integrity while minimizing RAM usage; and a memory management unit configured to store the validated firmware payload in a secondary memory partition separate from a primary execution partition, thereby enabling atomic firmware switching and rollback protection.
Owner:ATEEQ KARAMATH DR +2

Method and circuit arrangement for constructing a versatile hash function based on a turbo encoder

PendingCN122394764AHash functionAlgorithm
The application discloses a multi-functional hash function construction method and circuit device based on a turbo encoder, and proposes a new security strategy and a new overall structure for ICCS new commercial secret hash standard collection.The overall structure is as follows: a master control unit is a turbo encoder, a controlled unit is a nonlinear logic iterator, the controlled unit works in a block cipher mode or a strong permutation mode, and the c.r of the controlled unit is preferably outputted, and the c.r is outputted and updated by the master control unit, and the plaintext block updates the state of the master control unit.The application point is that the c.l of the controlled unit is not directly modified and directly outputted, and the security capacity c.l is used to resist the original image attack and the collision attack.The technical effect is that the maximum code rate + the anti-original image / state capacity is an optimal design, the sponge structure is enabled to increase the code rate, a large state capacity large input large output overall structure is constructed by supporting a plurality of small state capacity overall structures, the controlled units are basically the same, so that one circuit supports a combination mode / decomposition mode, and one set of code covers a family of algorithms.The multi-function is hash / xof, mac or duplex mode.
Owner:BEIJING RED & BLUE TREE TECHNOLOGY CO LTD

A design method for a highly adjustable block cipher operating mode

This invention relates to a design method for a highly adjustable block cipher operating mode, belonging to the field of information security. This invention uses a handle and internal variables encrypted from the handle to adjust the input, output, and key of the block cipher respectively to encrypt data blocks. The adjustable block cipher proposed in this invention relies solely on the block cipher without using a hash function, thus avoiding the loss of handle information. It can be implemented using standard block algorithms with consistent security, facilitating use in various scenarios. This invention significantly increases the handle length it can accommodate, reaching five times the block length, basically meeting the needs for adjustable block cipher handle length in currently known scenarios.
Owner:BEIJING INST OF COMP TECH & APPL

Lightweight password white box security assessment method based on neural discriminator

The invention relates to a lightweight password white box security assessment method based on a neural discriminator, and belongs to the technical field of information security and password engineering. According to the method, the ciphertext difference serves as a positive sample, an ideal random permutation hypothesis is introduced, random difference vectors obeying uniform distribution are generated to serve as negative samples, and a difference data set is constructed. And feature extraction and dichotomy training are carried out on the difference bit vector by using a depth discriminator, so that the statistical difference between the real difference and the random difference is learned. The trained discriminator is used for reasoning samples collected by the target white box, the distinguishing advantage is calculated according to the classification accuracy, an equivalent security bit or security level is given accordingly, and automatic and quantitative evaluation of the security of the white box is achieved. The method has the advantages of being independent of manual design of experts, automatic in evaluation process and lightweight in model, and can be used for safety evaluation and monitoring of lightweight block cipher white-box testing in a resource-constrained equipment environment.
Owner:BEIJING INST OF COMP TECH & APPL

A secure data transmission method suitable for open-source honeycomb terminal devices

A kind of security data transmission method suitable for open source Hongmeng terminal equipment between, this method deeply integrates the distributed architecture of open source Hongmeng.1, by HMAC-SM3 two-way authentication to build "super terminal" trust domain, and the authentication system is integrated into the distributed identity authentication of Hongmeng.2, the data to be transmitted is encapsulated as Hongmeng atomization service, which is uniformly distributed by the distributed task scheduling center, and the encryption and authentication are completed in the distributed security sandbox using SM4-CCM block cipher mode.3, the present application utilizes the trusted device group mechanism and distributed database / file system to perform security hierarchical management on the keys and data throughout their life cycle. Finally, based on the device capability perception, the transmission strategy is dynamically adjusted, and the seamless networking of heterogeneous network devices is realized through the distributed soft bus. This scheme forms a native security transmission system deeply coupled with the underlying capabilities of Hongmeng system, effectively solving the security and efficiency problems of cross-device data flow.
Owner:BEIJING SPACEFLIGHT TUOPUGAO SCI & TECH CO LTD