Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

355 results about "Cipher" patented technology

In cryptography, a cipher (or cypher) is an algorithm for performing encryption or decryption—a series of well-defined steps that can be followed as a procedure. An alternative, less common term is encipherment. To encipher or encode is to convert information into cipher or code. In common parlance, "cipher" is synonymous with "code", as they are both a set of steps that encrypt a message; however, the concepts are distinct in cryptography, especially classical cryptography.

A method and apparatus for improving data card security

This invention discloses a method and apparatus for improving the security of data cards, relating to the field of information security, and is invented to enhance the security of information stored in data cards. The method includes: binding a data card inserted into a first terminal to the first terminal; generating a decryption password; when a read / write operation is required on the data card, determining whether a second terminal requiring the read / write operation is the first terminal, and if so, decrypting the data card using the decryption password. This invention is mainly applicable to various data cards.
Owner:YULONG COMPUTER TELECOMM SCI (SHENZHEN) CO LTD

An encryption method fusing quantum key and post-quantum cryptographic algorithm

The application discloses an encryption method fusing quantum key and post-quantum cryptographic algorithm, and belongs to the technical field of data encryption. The original quantum key is generated by a BB84 protocol QKD device, and a post-quantum key generation seed, a lattice noise scaling factor and a quantum enhanced session base key are obtained through hash derivation; quantum derived mask is generated by combining the original quantum key and the operation data characteristics of the water and power terminal; the quantum mask protection data is obtained by performing XOR preprocessing on the data to be encrypted; based on the post-quantum encryption algorithm, the two-part basic ciphertext is generated by using the above-mentioned seed, parameters and protection data; the original quantum key is divided into pieces to obtain quantum enhanced encryption values, and the two-part ciphertext is subjected to secondary disturbance encryption and XOR processing, thereby forming enhanced ciphertext; and finally, the enhanced ciphertext and the check code are spliced and transmitted to the central control room. Through multi-level encryption and key enhancement, the security and attack resistance of data transmission in the water and power terminal and the like are significantly improved.
Owner:SICHUAN LIANGSHANSHUILUOHE ELECTRICITY DEV CO LTD

A load scheduling method and system for cryptographic devices based on shared locks

This invention provides a load balancing method and system for cryptographic devices based on shared locks. When receiving a request from a business system, the method determines the request source based on request parameters and calls the corresponding resource occupancy ratio and group identifier. Based on the group identifier, it searches the corresponding shared lock pool. Based on the number of locks in the shared lock pool, it calculates the maximum number of idle locks that the corresponding business system can use. It then searches the shared lock pool for idle locks and finds the corresponding Socket connection object through the association relationship of the successfully found locks. Finally, it uses this Socket connection object to call the cryptographic device for cryptographic operations. This method can solve the scheduling problem of multiple cryptographic devices and ensure balanced scheduling across multiple cryptographic machines.
Owner:SHANDONG INST OF BLOCKCHAIN

Hybrid signature method, signature verification method, and electronic device

Embodiments of the present application provide a hybrid signature method, a signature verification method, an electronic device and a computer readable storage medium. In the method, the target message to be signed is input into the first trusted execution environment to perform a signature operation based on a traditional cryptographic algorithm, to obtain a first digital signature, and then the target message and the first digital signature are input into the second trusted execution environment to perform a signature operation based on a post-quantum cryptography, to obtain a second digital signature, and finally the first digital signature and the second digital signature are spliced to obtain a hybrid digital signature. Based on different cryptographic algorithms, the signature operation is performed to obtain a hybrid digital signature, which can significantly improve the security of message transmission.
Owner:HONOR DEVICE CO LTD

Information security-based data processing acceleration method and device, equipment and medium

The application discloses a data processing acceleration method and device based on information security, equipment and medium, applied to the field of information transmission and information encryption, comprising: generating a target golden sequence based on target data and a corresponding encryption code; bilateral sampling is performed on the target golden sequence, and the obtained rising edge sampling data and falling edge sampling data are sent to a first-in first-out queue; the sampling data is sent to a local data splicing component based on a preset phase difference and a preset clock frequency; the local data splicing component receives the sampling data based on a preset first high-speed clock, splices the data, and obtains target splicing data; and the target splicing data is sent to a local decryption component based on a preset first high-speed clock, so that the local decryption component decrypts the target splicing data based on a preset second high-speed clock and the encryption code. In this way, the processing flow of data can be effectively accelerated while ensuring information security.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

Vehicle security starting method and system based on post-quantum cryptography

The application provides a vehicle security starting method and system based on post-quantum cryptography, and relates to the technical fields of vehicle electronic control and vehicle network security. The method is applied to an ECU of a vehicle, the ECU is pre-stored with public key information based on a post-quantum cryptographic algorithm and stores an image package containing a post-quantum cryptographic digital signature; the method comprises the following steps: in response to the power-on of the ECU, loading the image package, separating original image data and the digital signature therefrom; determining a cryptographic hash value of the original image data; based on the public key information, performing a signature verification operation of the post-quantum cryptographic algorithm on the hash value and the digital signature; and controlling the starting process of the ECU according to the result of the signature verification operation. The application reconstructs the trust chain of the vehicle by using the post-quantum cryptographic algorithm, and implements quantum security signature verification at the vehicle end, which effectively ensures that the software integrity and authenticity can still be effectively verified under the quantum computing environment, thereby providing full-life-cycle security protection for intelligent networked vehicles.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

Unmanned aerial vehicle inspection data security transmission method and system based on 4G private deployment

PendingCN122458026AInterference (communication)Eavesdropping
The application discloses a kind of unmanned aerial vehicle inspection data security transmission method and system based on 4G private deployment.The method comprises: deploying 4G non-public network containing communication perception integrated base station, and identifying illegal eavesdropping channel by active eavesdropping perception module;Task unmanned aerial vehicle and the physical layer protection system of collaborative protection unmanned aerial vehicle are constructed, and task unmanned aerial vehicle transmits integrated beam back data and locates eavesdropper, and protection unmanned aerial vehicle directional transmission interference signal;End-to-end encryption and identity authentication are executed on the basis of physical layer protection, and form double security mechanism;With the security transmission rate under unit energy consumption as optimization goal, establish joint optimization model;The model is decomposed into two coupled sub-problems and solved alternately, and after iterative convergence, according to optimal parameter, security transmission is executed.The application reduces system energy consumption while ensuring the security transmission of inspection data by double protection of physical layer and cryptographic layer, double unmanned aerial vehicle cooperation and security energy efficiency joint optimization.
Owner:ZHONGXIN HANCHUANG BEIJING TECH CO LTD

Method of and computerized apparatus for securing a computing device, and kit-of-parts system

Proposed is a method of securing a manufactured computing device (1) to be performed by a manufacturer thereof and comprising: a) installing, during manufacture of the computing device, a cryptographic device identity record (2) on the computing device, the cryptographic device identity record (2) comprising at least a private key (21) and a certificate (22) certifying a public key (221) corresponding to the private key; b) generating a certificate revocation secret (3) associated with the issued certificate; and c) causing the certificate revocation secret to be transferred to a customer using a transfer method that keeps it separate from the manufactured computing device (1). Also proposed is a corresponding apparatus; and a kit-of-part-system comprising the computing device and a physical or digital embodiment of the certificate revocation secret. Revocation of a cryptographic device identity record in case of loss of control over the computing device is facilitated.
Owner:SIEMENS AG

A cryptographic processing method and system based on SM2 and SM4 algorithms

PendingCN122457240ABatch processingAlgorithm
The application discloses a kind of based on SM2 algorithm and SM4 algorithm's password processing method and system, belong to computer information security technical field, comprising: the enhanced task control block including service index number and data amount is constructed;Based on historical performance data calculation processing coefficient, utilize double threshold hysteresis comparator decision serial or parallel mode, avoid mode frequent switching;Parallel mode is through load balancing weight function for subtask allocation IP core;Hardware synchronization control unit maintains three index tables being processing, blocking and having been processed, realizes the automatic blocking and wake-up of associated job package, and with service index number as address accesses key and intermediate state;Adopt interrupt aggregation and double buffering batch processing result;Based on sliding window adaptive calibration double threshold and dynamically adjusting weight coefficient.The application effectively reduces interrupt overhead, eliminates scheduling ping-pong effect, realizes hardware level job synchronization, improves load balancing and image encryption structure fidelity.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Blockchain-based methods for protecting medical data privacy and authorizing sharing

This invention discloses a blockchain-based method for medical data privacy protection and authorized sharing, relating to the field of medical data technology. This invention achieves medical data privacy protection and compliant sharing through a four-step closed-loop process. The first step is data splitting and encryption: the original data from the target hospital is split into cell units according to the smallest clinical semantic unit, independently encrypted using the SM4 algorithm, and then differentiated enhancement processing is implemented according to sensitivity to build a strong privacy defense. The second step is storage and evidence preservation: the encrypted units are distributed and stored in fragments, and the fragment hash value, semantic tag, and storage index are uploaded to the shared chain for evidence preservation, simultaneously building a cross-chain gateway and protocol to break down sharing barriers. The third step is authorization and verification: a four-dimensional intelligent authorization model is built to verify requests and generate a temporary key bound to this authorization, achieving precise authorization. The fourth step is usage control: the user decrypts and reassembles the data in a TEE adapted to the cryptographic algorithm, with real-time monitoring of the entire operation and synchronization to both chains, ensuring end-to-end security, controllability, and traceability.
Owner:ANQING VOCATIONAL & TECHN COLLEGE

Key cooperative exchange method and device, electronic equipment and medium

ActiveCN116405197BKey exchangeComputer network
This application discloses a method, apparatus, electronic device, and medium for collaborative key exchange. In this application, upon receiving a peer random number public key from a peer key device, the peer random number public key and a first random number public key are sent to a second communicating party. The first random number public key is calculated by the first communicating party using an elliptic curve cryptography algorithm. The second communicating party calculates its own random number public key based on the peer random number public key, the first random number public key, and a second sub-private key, and then sends its own random number public key and intermediate parameters to the first communicating party. The first communicating party calculates a shared key based on its own random number public key, intermediate parameters, and the first sub-private key, and then sends its own random number public key to the peer key device.
Owner:BEIJING WATCH DATA SYSTEM CO LTD

Hierarchical cryptographic service platform and service method fusing qkd technology

This invention discloses a hierarchical cryptographic service platform and method integrating QKD technology. The hierarchical cryptographic service platform includes a cryptographic service platform and at least one level of sub-cryptographic service platforms. At least one level of QKD network is built around the cryptographic service platform. Each level of the QKD network accesses an application system and / or connects to the corresponding level of the sub-cryptographic service platform. In this invention, the QKD network is built around the cryptographic service platform, which means that the QKD network can be built specifically according to application needs, giving full play to the ability of the cryptographic service platform to provide services for business applications. It is also easy to adapt and tailor according to business needs, and can be expanded on demand.
Owner:QUANTUMCTEK CO LTD +1

A Linux kernel-based password device master-slave cluster load balancing method

PendingCN122394795APasswordinit
The application discloses a kind of based on Linux kernel's cryptographic device master-standby cluster load balancing method, it is related to information security and high-availability cluster technical field, including the following steps: step one, at least one main cryptographic device node is configured with at least one backup cryptographic device node, and cryptographic service program is deployed on all nodes to initialize cluster configuration, Keepalived service module is deployed in main cryptographic device node and backup cryptographic device node, periodically send heartbeat message by groupcast mode, and real-time perception node state;Step two, set up health detection module, and adopt dual detection mechanism of node survival detection and cryptographic service availability detection;It can realize that cryptographic device master-standby automatically switches quickly, load intelligent distribution, security context real-time synchronization, comprehensively improve the availability of cryptographic service, reliability, efficiency and security, meet the high-level security needs of critical information system.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

A quantum-mixing-resistant cryptographic gateway and data transmission method

The embodiment of the application provides an anti-quantum mixing password gateway and a data transmission method, and belongs to the technical field of network security. The gateway comprises: a quantum key management module, which is used for acquiring quantum keys generated by a quantum key distribution network and quantum random numbers; an entity authentication module, which is used for performing challenge-response authentication on a communication terminal; a mixed certificate management module, which is used for performing mixed certificate authentication processing; a mixed key negotiation module, which is used for performing mixed key negotiation processing to generate a communication session key; and an encrypted tunnel module, which is used for establishing an anti-quantum encrypted communication tunnel based on the communication session key and performing encrypted transmission processing of communication data through the anti-quantum encrypted communication tunnel. The anti-quantum encrypted communication tunnel with the key derivation and quantum key dynamic refreshing mechanism is constructed, and the transmission security and stability of communication data in an anti-quantum attack environment are improved.
Owner:SICHUAN LIANGSHANSHUILUOHE ELECTRICITY DEV CO LTD

Method, apparatus, system, and computer program for authenticated encryption providing enhanced security and nonce length extension

The present disclosure relates to an authenticated encryption method, apparatus, system, and computer program for providing enhanced security and extension of a nonce length, and more specifically, the present disclosure discloses a method for performing authenticated encryption using a computing apparatus, the method including: producing a plurality of intermediate values, based on a given input value; generating a random number, based on a combination of a plurality of intermediate random values produced by performing block cipher-based encoding on the plurality of intermediate values; and performing encryption or decryption, based on the random number.
Owner:SAMSUNG SDS CO LTD

A Method for Integrity Protection of Access Control Records Based on Commercial Cryptographic Algorithms

This invention discloses a method for protecting the integrity of access control record storage based on commercial cryptographic algorithms, comprising: collecting access control records and concatenating them into complete record data A1 according to a predetermined format; calling a PCI-E cryptographic card and calculating the MAC value M1 of A1 using HMAC technology based on the SM3 national cryptographic algorithm, and storing A1 and M1 together in a background database; when it is necessary to verify the integrity of the access control record, reading the current record data A2 and the originally stored MAC value M1 from the background database; calling a PCI-E cryptographic card and calculating the MAC value M2 of A2 using the same algorithm; comparing M1 and M2, if they match, the record is determined to be complete; if they do not match, the record is determined to have been tampered with and an alarm message is generated. This invention has the advantages of high security, strong compliance, superior performance, and good economy, and can be widely used in access control systems with security levels of Level 3 and above.
Owner:TOEC ANCHEN INFORMATION TECH

Quantum secure infrastructure system and user terminal access method based on the system

The application discloses a quantum security infrastructure system and a user terminal access method based on the system, belongs to the field of quantum security communication and cryptography, and comprises the following steps: a cryptographic management service platform (CMSP) responds to an access request of a user terminal, determines an identity and access management system (IAM) and a key management system (KMS) that need to be accessed by the user terminal; if the IAM and the KMS belong to the same region, the CMSP sends IAM information of the IAM to the user terminal; the user terminal accesses the IAM based on the IAM information; if the IAM and the KMS do not belong to the same region, the IAM performs a key relay process through the CMSP, generates a service authentication token and access token ciphertext, and sends the service authentication token and the access token ciphertext to the user terminal; and the user terminal accesses the IAM based on the service authentication token and the access token ciphertext. The application improves the resistance to quantum attacks and the security of the system.
Owner:中电信量子信息科技集团有限公司

Secure device communication using mult-key encapsulation

A method for establishing secure communication between a first device and a second device. The method includes generating ephemeral keys at the first device, encapsulating a public key of the second device to generate a first cipher key and a first shared secret key, transmitting a first message to the second device including the ephemeral public key and the first cipher key, receiving a second message from the second device containing a second cipher key, decapsulating the second cipher key to achieve a second shared secret key, receiving and decapsulating a third cipher key to achieve a third shared secret key, deriving a final encryption key using the first, second, and third shared secret keys, and establishing secure communication by encrypting communication using the final encryption key. The method further includes verifying the final encryption key with the second device through hash exchange.
Owner:AAPOON INC

A power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm

PendingCN122437681AData packData stream
The present application relates to the field of power grid dispatching data security, and more particularly to a power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm. The method captures power grid dispatching network data streams in real time, obtains original service data containing dispatching instructions, measurement data and state information through protocol analysis and deep packet detection; then uses a dynamic data perception engine to identify sensitive data units, and dynamically generates data sensitivity labels according to the business type and the power grid operation state; dynamically matches commercial cryptographic algorithms from the commercial secret algorithm library according to the labels and distributes temporary session keys to generate an encryption strategy; encrypts the sensitive units, adds a security mark containing an algorithm identifier and a key index to the data packet header to form a protected data stream; sends the protected data stream to the target end, updates the session key state and uploads the execution log to the audit center. The present application realizes dynamic, accurate identification and differentiated encryption protection of power grid dispatching sensitive data.
Owner:HAINAN POWER GRID CO LTD

VPN communication system and method based on quantum server cryptomachine and post-quantum cryptography

This invention provides a VPN communication system and method based on a quantum server cryptography machine and post-quantum cryptography, comprising: a cloud platform and a VPN terminal encryption device; the VPN terminal encryption device is connected to the cloud platform via a network; the cloud platform includes a quantum server cryptography machine, a key management service platform, and a quantum key service platform; the quantum server cryptography machine is used to generate quantum true random numbers and generate quantum keys based on the quantum true random numbers; the key management service platform is used to store and manage quantum keys; the quantum key service platform is used to support the secure distribution of quantum keys to the VPN terminal encryption device through a post-quantum cryptography algorithm; the VPN terminal encryption device is used to obtain quantum keys from the cloud platform as session keys and establish a VPN communication tunnel with the peer VPN terminal encryption device based on the session keys.
Owner:SHANGHAI CIRCULATION QUANTUM TECH CO LTD

Large language model driven password protocol automatic formalization modeling method and system

PendingCN122433679ALinguistic modelPassword
The present application belongs to the technical field of network security and artificial intelligence, and provides a large language model driven password protocol automatic formalization modeling method and system, acquires a natural language protocol specification document, and performs preprocessing; according to the priority order of a message block, a verification block and a calculation statement, a large language model extracts corresponding semi-structured intermediate representations from text blocks; all intermediate representation statements are scanned at one time by using the large language model, protocol functions and symbols are identified and stored in a knowledge base, the large language model is driven in units of intermediate representation statements to be refined one by one, and global context and local context are extracted; the completely structured intermediate representations, a protocol role set and the updated knowledge base are taken as inputs to perform deterministic one-to-one mapping with formal verification tool code, and conversion is completed. The present application can automatically generate symbol model code which can be directly input into a formal verification tool.
Owner:SHANDONG UNIV

Communication encryption method based on adversarial neural password model

This invention discloses a communication encryption method based on an Adversarial Neural Cryptography (ANC) model, aiming to address the problems of insufficient randomness and limited security in ciphertext caused by the structural homogeneity of ANC models. This invention introduces a pre-trained randomness detector into a three-party game framework involving the sender, receiver, and attacker. During ANC model training, basic encryption / decryption and anti-attack training are performed initially. In the later stages of training, the detector is periodically used to evaluate the randomness of the ciphertext generated by the sender, and the evaluation result is used as part of the loss function to guide the sender to generate ciphertext with both strong confidentiality and high randomness. Finally, the well-trained sender and receiver neural networks are used as encryption and decryption modules and applied to actual communication. This invention effectively enhances the randomness of the generated cryptographic algorithm and improves communication security through structural innovation and diversified training objectives.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Method and device for testing password security of cloud platform access of power monitoring system

This application relates to the field of cryptographic security testing technology, and discloses a method and apparatus for testing the access password security of a cloud platform in a power monitoring system. The method includes: first, acquiring access password records and role information to generate a password-role mapping table; then, constructing a permission coupling structure and adding a time weight to form a permission coupling evolution structure; collecting system evolution factor data and normalizing it into security erosion parameters; subsequently, starting with the access password, combining the permission coupling evolution structure and the set of evolution factors to construct a permission-aware security degradation model and calculate the path degradation amplification coefficient; based on this coefficient, generating a permission-time joint security test signal containing a comprehensive risk value, and determining the password security status by comparing it with a preset security threshold. This method can accurately identify high-risk passwords without affecting system operation, meeting the high security and high reliability requirements of the power industry.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD

A key management system with key recovery

The present invention presents a key management system for handling cryptographic keys. The key management system comprises a computer device. The key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers. The IdP servers is configured to send an authentication token to the key management system upon an authentication request from the key management system. The key management system is configured to generate an access ID related to said IdP servers. The key management system is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to the group of computing servers, wherein the group of computing servers is configured to generate a decryption key and sending the decryption key or shares of the decryption key to the computer device or a selected device different from the computer device.
Owner:PARTISIA INFRASTRUCTURE APS

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

A cipher domain reversible information hiding method of all 0 row and all 0 column coding

ActiveCN116437019BAlgorithmCiphertext
The application discloses a ciphertext domain reversible information hiding method of all-0 row and all-0 column coding, and is characterized by comprising the following steps: 1) coding of all-0 row and all-0 column of a bit plane block; 2) compression space calculation of the all-0 row and all-0 column coded bit plane block; and 3) reversible information hiding of the all-0 row and all-0 column coded bit plane block. The method has the advantages of large embedding capacity and high security.
Owner:GUANGXI NORMAL UNIV

A 3D visualized cryptographic device security demonstration method

The present application relates to a kind of 3D visual cryptographic device security display method, it is related to cryptographic security application technical field, including the division 3D model component based on the physical structure of cryptographic device;The present application is based on the division 3D model component of the physical structure of cryptographic device, independent encryption is carried out using symmetric encryption algorithm, according to the current security state result of cryptographic device, and establish periodic confirmation mechanism and connect with cryptographic device, when communication connection is interrupted, the decryption key held by client is automatically invalid, the 3D model loaded is switched to grey frozen state, according to dynamic security state data, corresponding component is added on the surface of corresponding component model on corresponding component, according to user authority level, the component range required to be loaded is decrypted, according to current security state result, automatically trigger decryption loading of corresponding sensitive component, component model after adding visual special effect is rendered in 3D engine and is exhibited, form the complete 3D visual security posture view of cryptographic device.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1