Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Cipher suite" patented technology

A cipher suite is a set of algorithms that help secure a network connection that uses Transport Layer Security (TLS) or its now-deprecated predecessor Secure Socket Layer (SSL). The set of algorithms that cipher suites usually contain include: a key exchange algorithm, a bulk encryption algorithm, and a message authentication code (MAC) algorithm.

SSL VPN security gateway communication method fused with post quantum cryptography

The invention discloses an SSL VPN security gateway communication method fused with a post quantum cryptography technology. Comprising the following steps: S1, a client and a server respectively configure a serial hybrid signature digital certificate containing an SM2 algorithm and a serial hybrid encryption digital certificate containing a PQC algorithm, and a corresponding PQC encryption key pair private key, a PQC signature key pair private key, an SM2 encryption key pair private key and an SM2 signature key pair private key; s2, newly adding a hybrid algorithm password suite using an SM2 algorithm and a PQC algorithm in a password suite list of the client, and forcibly jacking the priority of the hybrid algorithm password suite; and S3, a message structure in a handshake protocol is transformed to use a series hybrid encrypted digital certificate to realize that PQC algorithm processing is added on the basis of an original national cryptographic algorithm to realize quantum key negotiation resistance. According to the method, the PQC algorithm is added on the basis of the original national secret algorithm, and the handshake protocol is transformed, so that anti-quantum-attack key agreement and identity authentication can be realized, the communication security is remarkably improved, and meanwhile, the interoperability with the standard SSL VPN is kept.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Method for applying anti-quantum certificate to TLS1.2 handshake process

The invention discloses a method for applying an anti-quantum certificate to a TLS1.2 handshake process, which realizes the application of an MLDSA anti-quantum signature algorithm and an MLKEM anti-quantum key encapsulation mechanism in the handshake process by expanding a cipher suite and a signature algorithm field of a TLS1.2 protocol. The method specifically comprises the following steps: defining a cipher suite supporting MLKEM and an MLDSA signature algorithm enumeration value; the client declares algorithm support in ClientHello, and the server responds and returns a certificate chain containing the double-antibody quantum certificate; after the client verifies the certificate, the pre-master key is encapsulated by using MLKEM, and the server de-encapsulates the derived session key; and the two parties send Finished messages to each other to complete handshake. According to the scheme, on the premise that a TLS1.2 basic framework is not changed, the communication security is enhanced through double-resistance quantum algorithm integration, international and national cryptographic algorithms are supported, quantum computing attacks can be resisted, meanwhile, adaptation of the international and national cryptographic algorithms is supported, compatibility with an existing system is ensured, the security risk of a traditional cryptographic algorithm in a quantum environment is solved, and the security risk of the traditional cryptographic algorithm in the quantum environment is reduced. And a standardized solution is provided for anti-quantum upgrade of the TLS1.2 protocol.
Owner:BEIJING SKYFAITH TECH CO LTD

Quantum cipher migration resisting method and system, electronic equipment and storage medium

The invention relates to an anti-quantum password migration method and system, electronic equipment and a storage medium, and belongs to the technical field of anti-quantum data transmission. The method comprises the following steps: carrying out adaptive expansion on a transport layer security protocol; the encryption end and the decryption end perform secure transmission of the application data based on the expanded transport layer security protocol, and the secure transmission process of the application data comprises the following steps: generating a master key, a multi-level sub-key and a path key chain according to a chain type post-quantum key generation mechanism based on the expanded cipher suite; the encryption end generates an encryption key through a part of the sub-keys, encrypts application data in a symmetric encryption mode to generate a ciphertext, and sends the ciphertext and a path node key at the tail end of the path key chain to a decryption end; and the decryption end verifies the path node key, generates a decryption key by using part of the sub-keys after the verification of the path node key is passed, and decrypts the ciphertext. According to the invention, the security and high efficiency of data transmission in the anti-quantum cryptography migration process are realized.
Owner:RELATED (BEIJING) TECHNOLOGY CO LTD

Anti-quantum migration method and system, electronic device, and storage medium

The application relates to an anti-quantum password migration method, system, electronic equipment and storage medium, and belongs to the technical field of anti-quantum data transmission. The method comprises the following steps: adaptively extending a transmission layer security protocol; and performing secure transmission of application data by an encryption end and a decryption end based on the extended transmission layer security protocol, wherein the secure transmission process of the application data comprises the following steps: respectively generating a master key, a multi-level sub-key and a path key chain based on an extended password suite according to a chained post-quantum key generation mechanism; generating an encryption key by the encryption end using part of the sub-key, encrypting the application data in a symmetric encryption mode to generate ciphertext, and sending the ciphertext and a path node key at the end of the path key chain to the decryption end; verifying the path node key by the decryption end, generating a decryption key by the decryption end using part of the sub-key after the path node key is verified, and decrypting the ciphertext. The application realizes the security and high efficiency of data transmission in the anti-quantum password migration process.
Owner:RELATED (BEIJING) TECHNOLOGY CO LTD

Commercial password evaluation system and evaluation method

The invention belongs to the technical field of information security, and particularly relates to a commercial password evaluation system and method, and the system comprises a protocol dynamic analysis layer, a multi-modal knowledge center, and an evaluation engine. The protocol dynamic analysis layer comprises a protocol grammar feature library used for defining protocol features; the SM-BERT semantic understanding module is used for protocol logic semantic extraction; the multi-modal knowledge center comprises a data modal fusion module used for integrating data and executing cross-modal alignment; the dynamic relation inference engine is used for performing incremental learning, generating association rules and filtering invalid rules; the evaluation engine comprises a multi-modal feature extraction module used for analyzing cipher suite configuration and a secret key life cycle; the compliance rule engine executes national cryptographic algorithm coverage detection and sensitive data protection verification; the physical security enhancement module simulates side channel attacks; according to the method, the problems of a static rule base, data splitting and high misjudgment rate in traditional password evaluation are solved, and the safety and evaluation efficiency of commercial password application can be remarkably improved.
Owner:FUJIAN JINMI NETWORK SECURITY EVALUATION TECH CO LTD

SSL VPN security gateway communication method based on post quantum cryptography

The invention discloses an SSL VPN security gateway communication method based on a post quantum cryptography technology. The method comprises the following steps: S1, a client and a server respectively configure a pure PQC algorithm digital certificate containing a PQC encryption key pair and a signature key pair; s2, a PQC algorithm password suite using a pure PQC algorithm is newly added in a password suite list of the client, and the priority of the PQC algorithm password suite is forcibly set up; and S3, transforming a message structure in a handshake protocol to replace a digital certificate based on an SM2 cryptographic algorithm with a pure PQC algorithm digital certificate to realize anti-quantum key negotiation. By introducing a pure PQC algorithm digital certificate and transforming a handshake protocol, quantum attack resistant key negotiation and identity authentication can be realized, the communication security is remarkably improved, the existing SSL VPN specification is compatible, only PQC related fields are expanded, and the deployment cost is reduced.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Password strategy updating method, device and system, electronic equipment and storage medium

PendingCN121125231AKey distribution for secure communicationPassword policyPassword
The invention discloses a password policy updating method, device and system, electronic equipment and a storage medium, and relates to the technical field of network security, the method comprises the following steps: in response to a received target password policy message, updating a first local password suite library based on a target password policy to obtain an updated first local password suite library; wherein the target password strategy message comprises newly added, modified or forbidden password suite information; starting a new service process based on the updated first local cipher suite library; and sending the update message containing the target password policy to the client, thereby realizing flexible adjustment and instant effectiveness of the target password policy, avoiding terminating an old service process, restarting a system or disconnecting original connection communication, avoiding service data interruption, quickly responding to a security demand, and improving the dynamic instant update capability of the target password policy.
Owner:CHINA MOBILE COMM LTD RES INST +1

Distributed password service system and method based on interlayer interface decoupling

The invention discloses a distributed password service system and method based on interlayer interface decoupling. The distributed password service system comprises a hardware layer, a service layer and an interface layer, the hardware layer comprises a security processor, and the security processor is used for providing business and management capability and externally providing a channel with interaction capability through a hardware interface; the service layer is used for a password operation service, a password management service and a middle layer API (Application Program Interface); and the interface layer is used for providing a password operation service and a password management service provided by the password suite for an external system in a unified interface mode, and when the interface layer interacts with the external system, the interface layer provides a function of processing and authenticating request data so as to ensure the security of interface access. According to the invention, triple technical effects are realized through the architecture of ''interlayer interface decoupling + service separation'', the collaborative breakthrough of safety, performance and expansibility is finally achieved, and a new generation of infrastructure support is provided for high-concurrency and cross-platform distributed password services.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY

A domain name system (DNS) domain name resolution method and related apparatus

This application discloses a Domain Name System (DNS) domain name resolution method and related apparatus, relating to the field of network security technology, used to improve the security and integrity of data in DNS. The method includes: a root server receiving a domain name query request sent by a DNS server, obtaining multiple cipher suites supported by the DNS server from the domain name query request; then, according to the signature algorithms it supports, selecting a target cipher suite from the multiple cipher suites; filtering out target signature algorithms that meet priority conditions from the target cipher suites, and digitally signing the first-level domain name obtained based on the domain name query request according to the target signature algorithm to obtain the signed first-level domain name; finally, sending the signed first-level domain name and the target cipher suite to the DNS server, so that the DNS server can digitally verify the signed first-level domain name based on the target signature algorithm in the target cipher suite to obtain the verified first-level domain name.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Post-quantum federal learning system and dynamic migration method

The invention provides a post-quantum federal learning system and a dynamic migration method, and relates to the technical field of network security. Dynamic switching between a basic cipher suite and a post quantum cipher suite is realized by introducing a dual-stack communication and cipher agility engine module, and continuous operation and business continuity of the system are ensured. The PQC performance optimizer overcomes the performance bottleneck of the PQC algorithm by reducing the calculation and communication overhead of the PQC algorithm in federated learning, so that the federated learning system can meet the real-time requirement. The hybrid encryption and hierarchical security aggregation module dynamically selects a security level according to a security policy, so that both security and efficiency are considered, and risks possibly existing in a single PQC algorithm are avoided. And the post-quantum security authentication and certification server verifies the integrity and authenticity of the hardware environment and the software environment of the client, a full-stack post-quantum trust chain is constructed, and the overall security of the system is improved.
Owner:GUANGDONG CERTIFICATE AUTHORITY

A hardware configuration designed for the execution of ascon cryptographic methods while defending against side-channel attacks

A low-area hardware architecture to execute the ASCON cipher suite and resist side-channel attacks that have a co-processor having controllers, register file, a permutation operably configured to receive input from a multiplexor structure and execute ASCON permutation, an ASCON state register that can be optionally removed and substituted by the register layer inside the permutation unit, and XOR logic gates that are operably configured to receive input from the register file and the permutation unit and provide input to the multiplexor structure.
Owner:PQSECURE TECHNOLOGIES LLC

Hardware-based data protection method

The application relates to the technical field of data processing, and particularly provides a hardware-based data protection method, aiming to solve the technical problem of poor software encryption effect in the prior art. The method comprises the following steps: based on a first module, a first public key, a first private key, a key plaintext and an initialization vector are generated; based on a preset second public key, a preset cipher suite and the first public key, additional verification data is obtained; based on the second public key and the first private key, a first symmetric key is obtained; based on the first symmetric key, the additional verification data and the initialization vector, the key plaintext is encrypted to obtain a negotiation result; and based on the key plaintext, data ciphertext is obtained by encrypting data plaintext to be protected. The hardware is used for encryption, thereby improving the security and operation efficiency; in each encryption process, the first public key, the first private key, the first key plaintext and the initialization vector are randomly generated by the hardware, thereby enhancing the forward security of the encryption process.
Owner:NIO TECH ANHUI CO LTD

Methods and arrangements for encryption of group addressed management frames

Logic for encryption and decryption of group addressed management. Logic to generate a management frame comprising a robust security network (RSN) element (RSNE), the management frame comprising a cipher suite field with a cipher suite used together with a set of one or more keys to encrypt the group addressed management frames. Logic to cause transmission of the management frame to one or more stations (STAs). Logic to receive a management frame comprising a robust security network (RSN) element (RSNE), the management frame comprising a cipher suite field with a cipher suite used together with a set of one or more keys to encrypt the group addressed management frames. And logic to decode the management frame to determine the cipher suite used together with the set of one or more keys for encryption of group addressed management frames.
Owner:INTEL CORP

Method and system for fusing quantum key one-time pad in TLS recording layer

The invention discloses a method and system for fusing quantum key one-time pad in a TLS recording layer, and relates to the technical field of quantum security communication, and the method comprises the steps: a client and a server execute a standard TLS handshake protocol, complete bidirectional identity authentication, negotiate encryption suite parameters, generate a unique session identifier, generate a classic key through a classic key exchange algorithm, and send the classic key to a server; declaring a quantum key enhancement mode in a handshake message extension field; after the handshake is completed, the client and the server are respectively connected with a locally deployed quantum key manager through a secure channel, submit the unique session identifier to carry out session binding, obtain a corresponding quantum key stream identifier, exchange information of the quantum key stream identifiers of the two parties, and carry out one-time pad encryption transmission; according to the method, on the premise of not changing a TLS protocol stack structure, sensitive data leakage and tampering risks are effectively prevented, and the information transmission security strength is improved.
Owner:UNIV OF SCI & TECH OF CHINA +1

Device for protecting data and method for protecting data

Apparatus and method for protecting data frames at a transmission side of a frame-based communication link are described. The apparatus includes a cipher suite module. The cipher suite model receives the data frame and protects the data frame based on a first cryptographic key if the data frame is a priority data frame and protects the data frame based on a second cryptographic key if the data frame is a non-priority data frame. The non-priority data frame is a data frame for which transmission can be interrupted by a data frame that is the priority data frame. After protecting the data frame, the cipher suite module provides the protected data frame for transmission over the frame-based communication link.
Owner:RENESAS ELECTRONICS CORP

A communication method, device and equipment suitable for industrial control network and storage medium

PendingCN122660966ATime delaysPassword
The application discloses a communication method and device suitable for an industrial control network, equipment and a storage medium, relates to the technical field of network security, and comprises the following steps: acquiring real-time communication time delay of communication parties in a communication process in a target industrial control system; acquiring the service importance of an industrial control asset corresponding to network congestion occurring in the communication process, and calculating a dynamic time delay threshold corresponding to a preset maximum service time delay based on the service importance; comparing the real-time communication time delay with the dynamic time delay threshold, and if the corresponding comparison result meets a preset trigger condition, generating a target decision instruction by using a preset decision engine; and dynamically adjusting the strength of a corresponding password suite of the communication process according to the target decision instruction, so as to complete a corresponding encryption communication process. By generating the instruction and adjusting the strength of the password suite, the problem that a static configuration cannot adapt to real-time service requirements is solved.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

SSL VPN security authentication gateway service compliance detection system, method and computer-readable storage medium

The present invention provides an SSLVPN security authentication gateway service compliance detection system, method, and computer-readable storage medium. The method constructs multiple test requests to communicate with an SSL server and uses a packet capture tool to capture data packets during the communication process. Further, a complete SSL data packet is obtained by reassembling the TCP segments of the pcapng data packet and checking for duplicates. The native dkpt.SSL module is then used to identify the protocol and parse and summarize the SSL, TLS, and national secret TLS protocols. Finally, the certificate and certificate chain are verified using a cryptographic tool library, and the results are visualized and displayed on a web page on a front-end display. The method of the present invention can simultaneously detect and analyze the compliance of the SSL / TLS protocol and the national secret TLS protocol. By using a traversal test method to test and verify the protocols and cryptographic algorithm suites that a VPN product may support, the cryptographic suites supported by the SSLVPN server are discovered, thereby improving detection efficiency, comprehensiveness, and accuracy.
Owner:GOLDEN SHIELD TESTING TECH CO LTD

DEVICE AND METHOD FOR SECURE FRAME-BASED COMMUNICATION WITH PRIORITY FRAME

A method and device for protecting data frames on the transmitting side of a frame-based communication link are described. The device includes a cipher suite module. The cipher suite receives the data frame and protects it based on a first cryptographic key if the data frame is a priority data frame, and based on a second cryptographic key if the data frame is a non-priority data frame. A non-priority data frame is one whose transmission can be interrupted by a priority data frame. After protecting the data frame, the cipher suite module prepares the protected data frame for transmission over the frame-based communication link.
Owner:RENESAS ELECTRONICS CORP

Post-quantum cryptography security networking and data protection device for space-based orbit data center

ActiveCN122001581AMake up for the shortcomings of insufficient trust foundation in distributionSecurity balance against quantum attacksKey distribution for secure communicationRadio transmissionPathPingKey (cryptography)
The invention provides a space-based orbit data center post quantum cryptography security networking and data protection device, and belongs to the technical field of spatial information networks and information security. The device comprises a heterogeneous key fusion management module used for receiving and storing a QKD key and generating a PQC key pair, and generating a session key through a key fusion algorithm; the integrated post quantum cryptography security gateway module is used for acquiring a session key to execute network access authentication and link encryption; a situation awareness unit of the dynamic networking strategy engine module collects a link state and a threat signal, and a strategy decision unit is internally provided with a deep reinforcement learning model to output an optimal networking path and a password suite; the on-satellite data quantum security protection module is used for on-satellite data encryption and trusted execution environment isolation; and the inter-satellite block chain module is used for constructing a block chain network to realize strategy distributed collaboration. According to the method, the QKD and PQC technologies are fused, and dynamic strategy adjustment and satellite data full-life-cycle protection are achieved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

HTTPS encrypted traffic auditing method, device, system and medium

The invention relates to an HTTPS encrypted traffic auditing method, device and system and a medium. The method comprises: receiving and processing a key packet from a client to obtain a pre-master key and TLS session metadata, the session metadata comprising a client random number, a server random number and a cipher suite identifier; performing key derivation processing on the pre-master key based on the TLS session metadata to obtain a key parameter required for decrypting the HTTPS flow; when the mirrored HTTPS flow is obtained, the secret key parameter is utilized to decrypt the HTTPS flow, and plaintext application layer data is obtained; and performing content auditing on the application layer data. According to the invention, the method effectively avoids the single-point fault and certificate trust risk of a man-in-the-middle agent, overcomes the ineffectiveness of a private key decryption scheme to a forward secrecy algorithm, avoids the system resource occupation and deployment complexity of a client agent, and achieves the efficient, compliant and bypass type auditing of the national secret and standard encrypted traffic including ECDHE and the like.
Owner:HANGZHOU DPTECH TECH

Cryptographic algorithm security negotiation method and apparatus, network function, device, storage medium, and computer program product

The application discloses a password algorithm security negotiation method, device, equipment, network function, storage medium and computer program product, wherein the method comprises the following steps: a first network function receives a first request sent by a first device; wherein the first request at least carries the identification of a password suite and / or a password algorithm, and is used for requesting to query whether the password suite and / or the password algorithm are invalid; a first response is returned to the first device; the first response carries first information, and the first information indicates whether the password suite and / or the password algorithm are invalid or not.
Owner:CHINA MOBILE COMM LTD RES INST +1

Device for protecting data and method for protecting data

The invention relates to an apparatus for protecting data and a method for protecting data. Apparatus and methods are described for protecting data frames at a transmitting side of a frame-based communication link. The apparatus includes a cipher suite module. The cryptographic suite model receives a data frame, and if the data frame is a priority data frame, protects the data frame based on a first cryptographic key, and if the data frame is a non-priority data frame, protects the data frame based on a second cryptographic key. The non-priority data frame is a data frame whose transmission can be interrupted by a data frame as a priority data frame. After protecting the data frame, the cryptographic suite module provides the protected data frame for transmission over the frame-based communication link.
Owner:RENESAS ELECTRONICS CORP

Data transmission method and device based on kTLS, equipment and storage medium

The method comprises the following steps: in the case that a TLS handshake of an application program process is completed, the application program process is used to call a first preset interface to send message data to a ULP framework, and a second preset interface is called to send a cipher suite to a hardware encryption and decryption module; the ULP framework is used to create a data structure, and the message data is stored in the data structure; a protocol stack is used to take the message data from the data structure, and the message data is encapsulated to obtain a corresponding data packet; a network device subsystem is used to store the data packet in a sending queue; a driver is used to take the data packet from the sending queue and store the data packet in a hardware queue; and the hardware encryption and decryption module is used to take the data packet from the hardware queue and encrypt the data packet based on the cipher suite.
Owner:YUSUR TECH CO LTD

A secure SSL VPN gateway communication method incorporating post-quantum cryptography technology

The application discloses a SSL VPN security gateway communication method fusing post-quantum cryptography technology, and comprises the following steps: S1, a client and a server are respectively configured with a series-connection mixed type signature digital certificate, a series-connection mixed type encryption digital certificate and corresponding PQC encryption key pair private keys, PQC signature key pair private keys, SM2 encryption key pair private keys and SM2 signature key pair private keys, wherein the series-connection mixed type signature digital certificate and the series-connection mixed type encryption digital certificate contain SM2 algorithms and PQC algorithms; S2, a mixed algorithm cipher suite using the SM2 algorithm and the PQC algorithm is added in a cipher suite list of the client and the priority thereof is forced to be on top; S3, a message structure in a handshake protocol is reformed to use the series-connection mixed type encryption digital certificate to realize anti-quantum key negotiation by adding the PQC algorithm processing on the basis of the original national secret algorithm. According to the application, the PQC algorithm is added on the basis of the original national secret algorithm and the handshake protocol is reformed, so that anti-quantum attack key negotiation and identity authentication can be realized, the communication security is obviously improved, and meanwhile, the interoperability with the standard SSL VPN is maintained.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

A V2X communication method and system

This application proposes a V2X communication method and system, comprising: a client sending a ClientHello message in SPDU format to a server, the ClientHello message including the client's communication cipher suite and a signature message, the signature message including the client's certificate and client data signature value; the server responding to the client with a ServerHello message in SPDU format based on the ClientHello message, the ServerHello message including a target communication cipher suite determined by the server and the server certificate; the server verifying the client's identity based on the signature message and determining the server's communication transmission key based on the target communication cipher suite; the client determining its own communication transmission key based on the ServerHello message; and the client and server communicating with each other based on the client's communication transmission key and the server's communication transmission key, respectively.
Owner:VANJEE TECHNOLOGY CO LTD

Roaming between generations of access points with different security protocols

The present technique allows for efficient re-association of an STA from a first Wi-Fi AP to a second Wi-Fi AP, where each Wi-Fi AP utilizes a different security protocol. Due to the fact that association and key management (AKM) protocols and cryptographic suites among all generations of Wi-Fi technologies are different, the STA usually cannot utilize a fast conversion process. However, since the present technology allows the STA to derive a security key in advance, the STA may perform a fast transition and efficiently roam to a Wi-Fi AP utilizing different association and key management (AKM) versions.
Owner:CISCO TECHNOLOGY INC

A Communication Method for SSL VPN Security Gateway Based on Post-Quantum Cryptography

This invention discloses an SSL VPN security gateway communication method based on post-quantum cryptography, comprising the following steps: S1. The client and server are respectively configured with clean PQC algorithm digital certificates containing PQC encryption key pairs and signature key pairs; S2. A PQC algorithm cipher suite using the clean PQC algorithm is added to the client's cipher suite list and its priority is forcibly set to the top; S3. Quantum-resistant key negotiation is achieved by modifying the message structure in the handshake protocol to replace the SM2-based digital certificate with the clean PQC algorithm digital certificate. This invention, by introducing a clean PQC algorithm digital certificate and modifying the handshake protocol, can achieve quantum-resistant key negotiation and authentication, significantly improving communication security. Simultaneously, it is compatible with existing SSL VPN specifications, only extending PQC-related fields, thus reducing deployment costs.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

An IPv6 encrypted traffic advanced persistent threat attack identification method and system

PendingCN122457381AFeature vectorAttack
The application relates to the technical field of network security, in particular to an IPv6 encrypted traffic advanced persistent threat attack identification method and system; the method comprises the following steps: extracting a cipher suite arrangement sequence, an extended field type set and a cipher library version identifier; performing sequence comparison and tolerance determination with a preset legal client variant fingerprint library to determine a suite arrangement coincidence level; screening out to-be-identified messages with a coincidence level lower than a preset legal threshold to generate a to-be-identified object set; and performing clustering analysis based on the arrangement feature vectors of the to-be-identified object set to identify a homologous concealed imitated traffic subset. In this way, the technical problem that the identification precision of a handshake fingerprint template and the overall identification accuracy are difficult to be considered in the prior art when dealing with the realistic scene of diversified client fingerprints in a signal creation environment is solved, and the accuracy and reliability of encrypted threat identification are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

A hardware configuration designed for the execution of ascon cryptographic methods while defending against side-channel attacks

PendingUS20260189359A1MultiplexingComputer architecture
A low-area hardware architecture to execute the ASCON cipher suite and resist side-channel attacks that have a co-processor having controllers, register file, a permutation operably configured to receive input from a multiplexor structure and execute ASCON permutation, an ASCON state register that can be optionally removed and substituted by the register layer inside the permutation unit, and XOR logic gates that are operably configured to receive input from the register file and the permutation unit and provide input to the multiplexor structure.
Owner:PQSECURE TECHNOLOGIES LLC