Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

3286 results about "Cipher" patented technology

In cryptography, a cipher (or cypher) is an algorithm for performing encryption or decryption—a series of well-defined steps that can be followed as a procedure. An alternative, less common term is encipherment. To encipher or encode is to convert information into cipher or code. In common parlance, "cipher" is synonymous with "code", as they are both a set of steps that encrypt a message; however, the concepts are distinct in cryptography, especially classical cryptography.

Big data auxiliary key generation method and system in communication data encryption transmission

The invention discloses a big data auxiliary key generation method and system in communication data encryption transmission, and relates to the technical field of big data analysis and processing. The dynamic entropy source processing module is used for generating a high-randomness entropy pool by combining an information entropy quantification model and adopting a Shannon entropy and minimum entropy fusion algorithm; the anti-quantum key generation module is used for generating a dynamic variable-length key seed based on an entropy pool driven post-quantum cryptographic algorithm; the hierarchical key negotiation module adopts a clustering Diffie-Hellman protocol, dynamically divides negotiation according to network topology, and precomputes and reduces the load of a core network through edge nodes; and a lightweight verification and update module. According to the method, high-entropy sources such as environmental noise, user behaviors and equipment hardware fingerprints are fused with low-entropy sources such as network messages and sensor data, and an intelligent acquisition strategy and a nonlinear decorrelation technology are combined, so that the anti-quantum dynamic entropy pool is generated, and the randomness of a secret key and the reliability of the entropy sources are improved.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Cross-platform dynamic security baseline and loophole closed-loop repair method and system based on federated learning

The invention provides a cross-platform dynamic security baseline and vulnerability closed-loop repair method and system based on federated learning, and the method comprises the steps: constructing a heterogeneous policy mapping rule base of a Windows registry, Linux sysctl and iOS plist by configuring a semantic analysis algorithm, and forming a multi-operating system policy consistency guarantee mechanism by combining a configuration conflict detection model of formalized verification; a dynamic reinforcement decision engine is designed based on a vulnerability influence surface analysis model driven by a knowledge graph and a double-circulation reinforcement learning architecture (outer-layer strategy exploration and inner-layer parameter optimization); a special evaluation system is constructed for key fields such as electric power and finance, a domestic cryptographic algorithm is deeply fused, and an electric power monitoring system PCSR / IIR / SCAR multi-dimensional index and SM2 / SM4 / SM9 full-stack security scheme is developed. According to the intelligent security baseline reinforcement method, the problems of wide cross-platform strategy gap, extensive vulnerability repair decision and insufficient industry adaptability of a traditional scheme are solved, and the intelligent security baseline reinforcement method supporting dynamic confrontation, accurate adaptation and service fusion is provided.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

Distributed intelligent authentication method based on dynamic multi-modal fusion

A distributed intelligent authentication method based on dynamic multi-modal fusion relates to the field of network security, and adopts an alliance chain + DAG hybrid block chain architecture, combines a threshold signature to realize secret key fragment management, and switches among PBFT, Raft and probabilistic algorithms through a dynamic consensus mechanism to improve authentication efficiency. The multi-mode authentication module is based on a dynamic weight distribution algorithm, integrates biological characteristics, behavior analysis, equipment fingerprints and environmental factors, and combines an LSTM-GAN model and a quantum random number driven challenge-response mechanism to realize zero-trust verification under environmental perception. The session management module generates a session key by using a chaotic mapping algorithm. In the aspect of privacy protection, CKKS homomorphic encryption, zero-knowledge proof and attribute-based encryption are fused. According to the method, the block chain technology, the secure multi-party computing technology, the machine learning technology and the quantum cryptography technology are fused, and a high-performance, high-security and strong-privacy-protection distributed authentication solution is provided.
Owner:JINLING INST OF TECH

Vehicle-mounted ad hoc network security communication system and method based on NTRU lattice cryptosystem

The invention belongs to the technical field of digital information transmission, and relates to a vehicle-mounted ad hoc network security communication system and method based on an NTRU lattice cryptosystem, and the system comprises a message signature module, a message encryption module, a message decryption module, an identity authentication module, and a key exchange module. The message signature module carries out signature by utilizing a private key and a random polynomial dynamically generated by a pseudo-random number generator based on an NTRU lattice cryptosystem; the message encryption module encrypts a to-be-sent message by randomly selecting a temporary polynomial and combining a public key of a receiver; the message decryption module is used for decrypting the received ciphertext # imgabs1 # by using a private key and an inverse element # imgabs0 # of a module p of the private key; the identity authentication module is used for performing identity authentication; the key exchange module realizes secure key exchange between communication nodes in the vehicle-mounted ad hoc network through an improved Blom key distribution protocol. The system improves the security and communication efficiency of the vehicle-mounted network.
Owner:CHANGCHUN UNIV OF TECH

Threat Mitigation System and Method

A computer-implemented method, computer program product and computing system for receiving a message concerning an event within a computer platform, wherein the message concerns a technology type and includes raw data; defining a cipher for the technology type, thus defining an associated cipher; processing the raw data included within the message using the associated cipher to define supplemental data for the technology type; and forming enriched data for the technology type based, at least in part, upon the raw data and the supplemental data.
Owner:RELIAQUEST HOLDINGS LLC

High-security method for negotiating temporary session key based on national secret algorithm

The invention relates to the technical field of commercial password detection methods, and discloses a high-security method for negotiating a temporary session key based on a national secret algorithm, and the commercial password detection method comprises the following steps: initialization and identity authentication: two communication parties generate an SM2 public and private key pair, and the identity is verified through a digital certificate and an SM2 signature; temporary key negotiation: generating a shared key point based on an SM2 key exchange protocol; session key derivation: generating a temporary session key by using an SM3 hash algorithm; key confirmation and encrypted communication: verifying the key through an SM4 algorithm and encrypting communication data; according to the high-security method for negotiating the temporary session key based on the national secret algorithm, efficient key negotiation of both communication parties in an unsecure channel is realized through an SM2 key exchange protocol, an SM3 hash algorithm and an SM4 symmetric encryption algorithm. The method combines digital certificate authentication, dynamic random numbers and timestamps, has forward security, replay attack resistance and man-in-the-middle attack resistance, and is suitable for high-security scenes such as finance and government affairs.
Owner:SHAANXI QINGSHAN SIJI INFORMATION TECH CO LTD

Method and system for artificial intelligence based cryptocurrency regulatory analysis

The present invention discloses a method and system for artificial intelligence-based cryptocurrency regulatory analysis capable of performing automated, adaptive, and verifiable compliance evaluation across multiple blockchain ecosystems. The invention integrates blockchain data acquisition, data normalization, graph-based behavioral modeling, artificial intelligence inference, and cryptographically anchored reporting within a unified architecture. The system comprises a blockchain data acquisition unit for retrieving multi-chain transaction data, a data normalization unit for harmonizing heterogeneous blockchain formats, a graph construction unit for generating dynamic transaction graphs, a regulatory knowledge base unit storing jurisdiction-specific regulatory rule graphs, an artificial intelligence processor configured for hybrid neural and symbolic reasoning, and a regulatory reporting unit for generating explainable compliance reports cryptographically anchored to a blockchain ledger.
Owner:VAYYASI NAVEEN KUMAR

Industrial internet data security communication method based on hybrid anti-quantum cryptography

The invention discloses an industrial internet data security communication method based on hybrid anti-quantum cryptography, which relates to the technical field of data communication, and comprises the following steps: acquiring a key pair and an anti-quantum security certificate; sending a connection request to data receiver equipment to complete certificate credibility authentication, and sending an anti-quantum security certificate of the equipment; receiving a shared key seed sent by the data receiver equipment; decrypting the encapsulated ciphertext to obtain a shared key seed, and generating a corresponding shared key according to the same shared key generation algorithm as the data receiver equipment; the method comprises the following steps of: signing original data by using a signature private key, splicing a signature and the original data to obtain spliced data, encrypting the spliced data by using a shared key based on an AES-256-GCM algorithm to obtain an encrypted ciphertext and an ML-DSA signature, and sending the encrypted ciphertext to data receiver equipment. According to the method, the key distribution step is simplified, the signature verification calculation overhead is optimized, and the data communication efficiency is improved.
Owner:SICHUAN UNIV +1

Methods and systems for facilitating single sign-on and passwordless sign-on

Computer-implemented methods and systems for facilitating single sign-on (SSO) and passwordless sign-on to a web service provider are provided. A client device authorized for SSO or passwordless sign-on generates and stores a device-specific key that it uses to encrypt a credential bundle containing key(s) necessary to access a cryptographically protected resource provided by the web service provider. The encrypted credential bundle is stored by the web service provider and provided to the authorized client device upon a successful authentication via SSO or passwordless sign-on. The authorized device uses the locally stored device-specific key to decrypt the encrypted credential bundle received from the web service provider to obtain the key(s) necessary to access the cryptographically protected resource.
Owner:AGILEBITS INC DBA 1PASSWORD

Market supervision data exchange platform migration and security enhancement method and system based on credential environment

The invention discloses a market supervision data exchange platform migration and security enhancement method and system based on a credential environment, and relates to the technical field of network security. In the data migration process, the consistency and privacy protection of the data are ensured through Hash check and a multi-party security computing technology; a domestic commercial cryptographic algorithm and a quantum resistance encryption technology are introduced, so that the protection capability of the platform to existing security threats is effectively improved, and the resistance to future quantum computing threats is enhanced; an intrusion detection system and a virtual honeypot node are integrated, and a defense strategy is monitored and updated in real time in combination with a deep learning model, so that novel attack behaviors can be detected and coped with in real time; according to an intrusion detection alarm and a block chain audit result, a security policy and resource allocation are dynamically adjusted in combination with a machine learning technology, it is ensured that high-risk nodes are monitored in time, resource allocation is automatically optimized, and the resource utilization efficiency and security of the system are improved.
Owner:江苏省市场监督管理局数据中心

Internet of Things test platform adaptation method, system and device based on post quantum cryptography

The invention discloses an Internet of Things test platform adaptation method, system and device based on post quantum cryptography. The method comprises the following steps: constructing a quantum threat perception model; establishing a multi-dimensional adaptive decision matrix, and generating a candidate post-quantum cryptography algorithm set; dynamic injection of a cryptographic protocol is executed, and lossless replacement of a communication layer encryption suite is achieved; deploying a runtime performance monitoring engine, and collecting encryption and decryption delay, memory occupancy rate and electromagnetic radiation characteristic data in real time; and constructing an algorithm switching decision tree based on reinforcement learning, and when a quantum attack feature or an equipment performance threshold is detected to break through, triggering cryptographic algorithm dynamic migration. A quantum threat perception driven Internet of Things security adaptation system is constructed, and by introducing a dynamic password switching mechanism, a hardware acceleration optimization scheme and a trusted execution environment, the security upgrading problem of traditional Internet of Things equipment in the post-quantum era is solved. According to the invention, the execution efficiency of the PQC algorithm of the resource-constrained equipment can be improved, and the key updating delay is reduced.
Owner:HANGZHOU YUNXIANG NETWORK TECH

Control method of multi-protocol switching anti-quantum security gateway

The invention relates to a control method for a multi-protocol switching anti-quantum security gateway, and the method comprises the steps: carrying out the safety self-inspection of a hardware environment after the security gateway is powered on, generating a unique root key of equipment based on a physical unclonable function, continuously collecting and analyzing the network traffic characteristics, and carrying out the self-inspection of the hardware environment. Based on a machine learning model, a quantum attack mode is identified and an encryption algorithm mode is dynamically decided, protocol analysis is carried out on a communication data packet, dynamic conversion and adaptation are carried out between a traditional protocol and an anti-quantum cryptography protocol according to an instruction and a preset rule, and an anti-quantum cryptography engine is called to carry out encryption or signature operation. And dynamically deriving and managing a session key in a complete period based on a root key, switching an algorithm mode, a communication protocol and a key in a linkage manner according to a quantum attack detection result, and starting anti-side channel attack protection and hardware security response. According to the method, active protection of the security gateway on quantum attacks, multi-protocol seamless compatibility and full-life-cycle security management of keys are realized.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Systems and Methods for Performing Secure Transactions on Blockchain

Systems and methods for securing transactions in accordance with various embodiments of the invention are illustrated. One embodiment includes a method for confirming token ownership rights. The method generates a pre-image value using a random number generator. The method generates an action request that corresponds to an action performed cryptographic token(s). The method derives a commit output based on the pre-image value. The method generates a commit request that obfuscates the action request based on the commit output and submits the commit request to an immutable ledger. The method receives a confirmation when the commit request is approved by the ledger. When a reveal request referencing the commit output is published, the method receives a confirmation of at least one of: the reveal request being published, that the reveal request comprises a reference to the commit output, or that the action request has been approved.
Owner:ARTEMA LABS INC

Quantum key distribution method based on cryptographic infrastructure system

The embodiment of the invention provides a quantum key distribution method based on a cryptographic infrastructure system, relates to the technical field of quantum secret communication, and provides a quantum key distribution method based on fusion of quantum key distribution and post quantum cryptography, which integrates a classical commercial cryptographic algorithm, a PQC post quantum cryptographic algorithm and quantum key distribution. A QKD-based quantum key secure distribution process combining SM2 and PQC mixed signature, SM2 and PQC mixed key packaging, PQC collaborative signature, PQC collaborative decryption, token access and other cryptographic technologies is designed, and anti-quantum cryptographic capability support is provided for voice applications through collaborative signature and collaborative decryption, so that the security of software for realizing a PQC cryptographic algorithm is improved, and the security of the PQC cryptographic algorithm is improved. Moreover, the software implementation mode does not have the inherent security problem of the IP, the dependency on the server is low, and the standardization program is high.
Owner:中电信量子信息科技集团有限公司

NTRU-based efficient and compact key packaging, encryption and decryption method

The invention discloses an efficient and compact key packaging, encryption and decryption method based on NTRU. The invention belongs to the technical field of lattice passwords, and particularly relates to an NTRU-based secret key packaging, encrypting and decrypting method with scalable ciphertext compression and balanced performance. According to the method, a public key compression and scaling ciphertext compression technology is provided for an NTRU password system, only one polynomial is needed in the encryption and decryption process, and the technology is also suitable for other password schemes based on NTRU. The method has the advantages of being shorter in ciphertext size, more flexible in parameter selection, capable of proving security under classical and quantum random oracle models, tighter in theoretical security protocol advantage, higher in known attack resistance, efficient in implementation, negligible in error rate and the like.
Owner:FUDAN UNIVERSITY

Password authentication using cryptographic key handle-based authentication records

A process includes receiving credentials associated with a request to access a computer platform. The credentials include a password and a user identification. The process includes determining a key handle and a reference cryptographic digest corresponding to the user identification. The process includes determining a second cryptographic digest corresponding to the user identification. Determining the second cryptographic digest includes providing the key handle and the password to a security processor of the computer platform and initiating an operation by the security processor to apply a keyed-hashing function to the password based on a cryptographic key corresponding to the key handle to provide the second cryptographic digest. The security processor stores the cryptographic key. The process includes regulating access to the computer platform based on a comparison of the second cryptographic digest to the reference cryptographic digest.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Bar code and RFID dual-mode fused tamper-proof data storage system

The invention discloses a bar code and RFID dual-mode fused tamper-proof data storage system, and relates to the field of data security storage, which comprises the following steps: uploading complete data to be stored into a scanning monitoring platform, splitting the data into static data and dynamic data, writing the static data into a bar code module, and writing the dynamic data into the bar code module; randomly distributed initial fluorescent particles are generated on the surface of the bar code data label through a scanning monitoring platform, a unique initial optical fingerprint is generated, if a bar code module is tried to be written or modified, the distribution position of the initial fluorescent particles is modified, an abnormal optical fingerprint is obtained, and an alarm is given; and writing the dynamic data into the RFID module, generating a dynamic key in each communication, and performing cross validation on the hash value based on the static data and the dynamic data. The method has the advantages that a three-dimensional protection system is constructed through a dual tamper-proof mechanism of a physical layer of fluorescent particle displacement and a password layer of a dynamic key in combination with cross validation of a hash tree, and the tamper-proof capability is improved.
Owner:SHENZHEN MINDE ELECTRONICS TECH

Communication authentication method and system of train on-board network, storage medium and equipment

The invention provides a communication authentication method and system for a train-mounted network, a storage medium and equipment, and the method only completes the key negotiation operation in the process of executing the communication authentication of the train-mounted network, enables the subsequent communication process to be executed based on a session key obtained through the negotiation of a first verification party and a second verification party, and improves the communication authentication efficiency. According to the method and the device, identity information of two communication parties is mutually verified, only a request carrying identity information of a verification party needs to be sent once in a primary communication process, only a session key generated by negotiation needs to be carried in a subsequent communication process, lightweight processing is performed on a communication authentication protocol, and the communication authentication protocol can be obtained by introducing a pairing-free password system based on an identity label. According to the method, a complex pairing process does not need to be executed, the number of calling times of Hash is reduced, the protocol calculation overhead is reduced, the communication efficiency is improved on the basis of ensuring the credible access authentication of a train-mounted network and the credible transmission of a control message, and the influence on the real-time performance of a train network monitoring management system is avoided.
Owner:NAT HIGH SPEED TRAIN QINGDAO TECH INNOVATION CENT

Education robot-based intelligent system and method for fusing mental health evaluation in interest scene

PendingCN120636769AEnsemble learningDigital data protectionNumber generatorPsychometric testing
The invention discloses an intelligent system and method for fusing mental health evaluation in an interest scene based on an education robot. The system realizes non-intrusive mental health assessment by constructing a technical architecture of'multi-modal biological feature anonymization-quantum hybrid encryption-federated learning privacy protection-dynamic risk assessment '. The method is characterized by comprising the following steps of: (1) generating irreversible biological characteristic codes by adopting a chaos random number generator, and realizing anonymized association by combining a double hash chain technology; (2) designing a quantum enhanced hybrid encryption system, fusing an SM4 algorithm, NTRU post quantum cryptography and quantum key distribution; (3) developing a dynamic scene generator, and naturally fusing psychological test questions into interest topics by using a generative adversarial network (GAN) and a curiosity engine; (4) constructing a multi-modal emotion analysis system, and combining an LSTM + CNN hybrid model to realize physiology-behavior-voice data fusion analysis; and (5) deploying a federated learning framework, and protecting model training data through differential privacy noise injection (epsilon = 0.5).
Owner:张景飞

Key management device, quantum cryptography communication system, and computer program product

A key management device according to an embodiment includes one or more hardware processors configured to function as a determination unit, a generation unit, and a supply unit. The determination unit determines a type of request data requested by a request message transmitted from an application that performs encrypted data communication. The generation unit generates a response message including at least one of a random number and an encryption key shared by quantum key distribution (QKD) via a communication network according to a type of the request data. The supply unit supplies the response message to the application.
Owner:KK TOSHIBA

System and method for policy-constrained symbolic rendering of AI outputs

An end-to-end rendering system enforces policy-constrained, symbolic presentation of artificial-intelligence (AI) outputs prior to any pixel emission. An AI accelerator emits inference tokens as (token identifier, confidence, domain tag) tuples into an output FIFO. A graphics processor with a command processor and SIMD co-processor executes a policy engine that runs a deterministic finite automaton (DFA) stored in non-transitory memory. The DFA consumes the tuples and produces, before any frame-buffer writes, a permit / deny decision and a visibility mask that constrain presentation attributes. A glyph selector maps permitted tuples to entries in a constrained glyph dictionary specifying a glyph identifier, semantic class, and allowed substitutions. A provenance tagger computes a cryptographic hash over at least the glyph identifier, a DFA-state policy identifier, a session nonce, and a checksum of the tuples to create an evidence capsule bound to the glyph. A device-aware renderer, consulting a device profile registry and a rendering grammar, emits a renderable asset for the glyph only when permitted by the visibility mask and grammar. A justification ledger records, for each displayed glyph, the evidence capsule and a monotonic timestamp. Executed entirely within the graphics processor, the pipeline prevents unauthorized tokens from entering the display path, enables cryptographically verifiable traceability of visible content, and reduces bandwidth by representing outputs as glyph identifiers rather than text or raster imagery, while allowing runtime policy updates without modifying the underlying inference model.
Owner:ONESOURCE SOLUTIONS INT INC

Anti-quantum computing public key cryptography method and system

The invention relates to the technical field of information security, in particular to an anti-quantum computing public key cryptography method and system. The method comprises the following steps: acquiring a large prime number p and constructing a multivariable polynomial ring; randomly generating a group of polynomial coefficients, generating a polynomial embedding rule public key, and generating a multivariable polynomial ring embedding public key; the method comprises the following steps: acquiring a quantum computer message, performing polynomial space mapping conversion and message public key encryption, and meanwhile, generating a quantum message public key encrypted ciphertext by introducing a polynomial perturbation term and a transcendental coding term; the quantum message public key encryption ciphertext and the corresponding polynomial ring embedded public key are transmitted to a quantum message decryption party for inversion decryption processing, and a quantum computer message decryption plaintext is generated; and performing anti-quantum computing security analysis on the encryption and decryption processes, and regenerating a multivariable polynomial ring dynamic public key. According to the method, the attack of quantum computing can be effectively resisted, so that the security of quantum information transmission is guaranteed.
Owner:QINGDAO HUITIANXIA BIG DATA TECHNOLOGY SERVICE CO LTD

IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

The invention provides an IKE (Internet Key Exchange) protocol security enhancement method based on PUF (Physical Unclonable Function) dynamic authentication and a post-quantum mixed key, which organically combines a PUF, a post-quantum cryptographic algorithm (PQC, especially Kyber KEM) and an improved Internet Key Exchange Protocol (IKE) to realize key exchange of post-quantum security and enhanced identity authentication. The method comprises the following steps: generating a dynamic pre-shared key (PSK) by utilizing the PUF; the method comprises the following steps: integrating a Kyber KEM to an IKE protocol, and replacing traditional Diffie-Hellman key exchange; the PUF-driven dynamic PSK is used as an identity authentication method of the IKE; meanwhile, Kyber KEM and ECDH are adopted for key exchange, and a final session key is generated through joint participation of a Kyber negotiation key, an ECDH negotiation key and PSK derived by PUF; and an IKE protocol process is optimized, and Kyber key exchange and PUF (Physical Unclonable Function) authentication are completed in an IKESAINIT stage and an IKEINTERMEDIATE stage. According to the method, key exchange is post-quantum secure, identity authentication is also post-quantum secure, and the final key integrates three key components of Kyber, ECDH and PUF, so that triple security assurance is provided.
Owner:MIXUAN TECHNOLOGY (HANGZHOU) CO LTD

Anonymous Internet of Things identity authentication method and device based on anti-quantum computing password

The invention provides an anonymous Internet of Things identity authentication method and device based on an anti-quantum computing password. A key generation device sends a public key to a message sending end and a message receiving end, and sends a private key to an authentication server; the authentication server generates a blind parameter based on the private key, and sends the blind parameter to the message sending end; the message sending end performs blind operation based on the blind parameter, the public key and the to-be-transmitted message to obtain a blind message, and sends the blind message to the authentication server; the authentication server performs post-quantum signature on the blind message based on the private key to obtain a to-be-solved blind signature, and sends the to-be-solved blind signature to the message sending end; the message sending end carries out blind resolution operation on the to-be-resolved blind signature to obtain a target signature; the message sending end sends the to-be-transmitted message and the target signature to a message receiving end; and the message receiving end performs post-quantum verification on the target signature based on the public key, and if verification succeeds, processing is performed based on the to-be-transmitted message. Through the scheme of the invention, the user data security can be improved.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Configurable number-theory transformation parallel computing acceleration method and device for post quantum cryptography algorithm

The invention discloses a configurable number-theory transformation parallel computing acceleration method and device for a post quantum cryptographic algorithm, and relates to the technical field of cryptographic algorithms. The number theory transformation is a calculation bottleneck in lattice-based post-quantum cryptography and PQC; a hardware accelerator specially designed for number theory transformation (NTT) is an effective solution for improving the execution speed. At present, a mainstream design neglects the influence of the scale of a calculation array, so that the design of an NTT calculation circuit is poor in flexibility and low in memory utilization rate, and a two-dimensional reconfigurable number theory transformation acceleration circuit is provided; the method is applied to a key generation stage, an encryption stage and a decryption stage of the post-quantum cryptographic algorithm. The NTT reconfigurable computing circuit provided by the invention can keep the utilization rate of hardware resources, and is suitable for mobile terminal equipment with limited resources; the NTT circuit adopts a low-complexity memory mapping scheme, so that the address control logic is greatly simplified, and the hardware overhead is reduced.
Owner:BEIJING INST OF TECH +1

Cross-industry logistics data trusted sharing method and system based on block chain

The invention relates to the technical field of computers and information processing, in particular to a block chain-based cross-industry logistics data trusted sharing method and system, and the method comprises the steps: S1, carrying out the cross-industry semantic alignment; s2, performing field-level ciphertext access; s3, zero knowledge permission verification; s4, federal learning and on-chain coordination are carried out; s5, carrying out privacy budget and service linkage; s6, variable structure consensus; step S7, two-way auditing tracing is carried out; and S8, carrying out consistency challenge. Semantic alignment and chaining commitment are achieved through industry ontology, visibility is controlled through attribute-based field-level encryption and zero-knowledge verification, and commitment-driven median anchoring, symmetric truncation, quality * sample size weighted federal aggregation and on-chain differential privacy budget linkage are combined. And an end-to-end trusted sharing closed loop is constructed in cooperation with PBFT scalable consensus of VRF grouping, forward security signature and Merkle bidirectional auditing and challenge-response verification.
Owner:HARBIN INST OF TECH WEIHAI RES INST

Anti-quantum cryptographic dual-mode cryptographic algorithm switching method and system based on dynamic scheduling

The invention provides an anti-quantum national secret dual-mode cryptographic algorithm switching method and system based on dynamic scheduling, and relates to the technical field of dynamic scheduling, and the method comprises the steps: collecting the operation characteristics of a cryptographic communication session, and carrying out the analysis to obtain an evaluation result containing an attenuation inflection point and an algorithm failure time boundary; determining a candidate switching algorithm set from the heterogeneous algorithm pool according to an evaluation result, and calculating a resource overhead expected value and a safety gain expected value of each candidate algorithm; establishing a dual-mode collaborative switching decision mechanism, mapping resource overhead and security gain into a Pareto leading edge solution set in a reserved response interval before an algorithm failure time boundary, and determining a switching scheme by combining a semantic fragment boundary; algorithm switching is executed by inserting a control frame at a semantic fragment boundary, and iterative correction is carried out by utilizing scheduling execution feedback. According to the method, smooth switching between the national cryptographic algorithm and the anti-quantum algorithm is realized, the security and the resource efficiency are both considered, and the long-term security of the cryptographic system is ensured.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Substation dispatching data network security communication method based on quantum tunnel encryption

The invention discloses a substation dispatching data network security communication method based on quantum tunnel encryption, relates to the technical field of large-scale power grid security assurance, and aims to solve the problems of endpoint security loss, boundary solidification, weak quantum threat resistance and inflexible deployment of a dispatching data network. According to the method, the establishment of a secure session and the encapsulation, encryption and restoration of data are realized by integrating quantum key distribution and a post quantum cryptographic operation module through quantum secure communication terminals deployed in a dispatching master station and a transformer substation. According to the method, application layer encryption and signature are carried out on telecontrol protocol data, a double-layer encryption tunnel is constructed, and transmission of various physical network media is supported. By means of the scheme, end-to-end protection is achieved, quantum attacks are effectively resisted, double encryption is provided, and networking flexibility and smooth evolution are improved.
Owner:INNER MONGOLIA HUIQIANG TECH CO LTD

Mobile device management including features of passwordless authentication

A method of securely storing a device password. The method includes receiving from a relying party, via a communication interface, a first public encryption key associated with a first device associated with a user identity. The method includes generating, at a second device associated with the same user identity and registering with the relying party, a public encryption key pair that includes a second public encryption key. The method includes performing a first level of encryption with respect to a password encryption key associated with encrypting a device password of the second device to produce a singly encrypted password encryption key using the second public encryption key. The method includes performing a second level of encryption with respect to the singly encrypted password encryption key to produce a doubly encrypted password encryption key using the first public encryption key and storing the it on the second device.
Owner:IVANTI INC

Artificial intelligence assisted password security policy dynamic adaptive adjustment method

The invention relates to the technical field of data processing, in particular to an artificial intelligence-assisted password security policy dynamic adaptive adjustment method, which comprises the following steps of: acquiring login operation data to generate an encryption feature gradient; the aggregation server generates a dynamically updated federal reference model through a double-channel model updating mechanism, wherein a long-term model updating channel is fused with historical parameters to maintain system stability, and a short-term behavior time window channel dynamically adjusts recent gradient weight based on a time decay function. A graph computation engine generates a spatio-temporal composite risk score. And the risk decision engine generates a third-level response instruction. A risk misjudgment event is verified based on a response result, high-value training samples are screened to drive incremental training, space-time sensitive parameters are finely adjusted by a meta-learning optimizer, and noise is injected into a quantum gradient jammer to defend attacks. Optimized parameters are synchronized to a system module, and a closed-loop adaptive system is formed by combining homomorphic encryption transmission, model digital watermarking, quantum source hardware binding and anti-quantum signature.
Owner:CHINA ACADEMY OF INFORMATION & COMM