Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

21 results about "Cipher suite" patented technology

A cipher suite is a set of algorithms that help secure a network connection that uses Transport Layer Security (TLS) or its now-deprecated predecessor Secure Socket Layer (SSL). The set of algorithms that cipher suites usually contain include: a key exchange algorithm, a bulk encryption algorithm, and a message authentication code (MAC) algorithm.

Commercial password evaluation system and evaluation method

The invention belongs to the technical field of information security, and particularly relates to a commercial password evaluation system and method, and the system comprises a protocol dynamic analysis layer, a multi-modal knowledge center, and an evaluation engine. The protocol dynamic analysis layer comprises a protocol grammar feature library used for defining protocol features; the SM-BERT semantic understanding module is used for protocol logic semantic extraction; the multi-modal knowledge center comprises a data modal fusion module used for integrating data and executing cross-modal alignment; the dynamic relation inference engine is used for performing incremental learning, generating association rules and filtering invalid rules; the evaluation engine comprises a multi-modal feature extraction module used for analyzing cipher suite configuration and a secret key life cycle; the compliance rule engine executes national cryptographic algorithm coverage detection and sensitive data protection verification; the physical security enhancement module simulates side channel attacks; according to the method, the problems of a static rule base, data splitting and high misjudgment rate in traditional password evaluation are solved, and the safety and evaluation efficiency of commercial password application can be remarkably improved.
Owner:FUJIAN JINMI NETWORK SECURITY EVALUATION TECH CO LTD

Password strategy updating method, device and system, electronic equipment and storage medium

PendingCN121125231AKey distribution for secure communicationPassword policyPassword
The invention discloses a password policy updating method, device and system, electronic equipment and a storage medium, and relates to the technical field of network security, the method comprises the following steps: in response to a received target password policy message, updating a first local password suite library based on a target password policy to obtain an updated first local password suite library; wherein the target password strategy message comprises newly added, modified or forbidden password suite information; starting a new service process based on the updated first local cipher suite library; and sending the update message containing the target password policy to the client, thereby realizing flexible adjustment and instant effectiveness of the target password policy, avoiding terminating an old service process, restarting a system or disconnecting original connection communication, avoiding service data interruption, quickly responding to a security demand, and improving the dynamic instant update capability of the target password policy.
Owner:CHINA MOBILE COMM LTD RES INST +1

Distributed password service system and method based on interlayer interface decoupling

The invention discloses a distributed password service system and method based on interlayer interface decoupling. The distributed password service system comprises a hardware layer, a service layer and an interface layer, the hardware layer comprises a security processor, and the security processor is used for providing business and management capability and externally providing a channel with interaction capability through a hardware interface; the service layer is used for a password operation service, a password management service and a middle layer API (Application Program Interface); and the interface layer is used for providing a password operation service and a password management service provided by the password suite for an external system in a unified interface mode, and when the interface layer interacts with the external system, the interface layer provides a function of processing and authenticating request data so as to ensure the security of interface access. According to the invention, triple technical effects are realized through the architecture of ''interlayer interface decoupling + service separation'', the collaborative breakthrough of safety, performance and expansibility is finally achieved, and a new generation of infrastructure support is provided for high-concurrency and cross-platform distributed password services.
Owner:THE FIRST RES INST OF MIN OF PUBLIC SECURITY

A domain name system (DNS) domain name resolution method and related apparatus

This application discloses a Domain Name System (DNS) domain name resolution method and related apparatus, relating to the field of network security technology, used to improve the security and integrity of data in DNS. The method includes: a root server receiving a domain name query request sent by a DNS server, obtaining multiple cipher suites supported by the DNS server from the domain name query request; then, according to the signature algorithms it supports, selecting a target cipher suite from the multiple cipher suites; filtering out target signature algorithms that meet priority conditions from the target cipher suites, and digitally signing the first-level domain name obtained based on the domain name query request according to the target signature algorithm to obtain the signed first-level domain name; finally, sending the signed first-level domain name and the target cipher suite to the DNS server, so that the DNS server can digitally verify the signed first-level domain name based on the target signature algorithm in the target cipher suite to obtain the verified first-level domain name.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Post-quantum federal learning system and dynamic migration method

The invention provides a post-quantum federal learning system and a dynamic migration method, and relates to the technical field of network security. Dynamic switching between a basic cipher suite and a post quantum cipher suite is realized by introducing a dual-stack communication and cipher agility engine module, and continuous operation and business continuity of the system are ensured. The PQC performance optimizer overcomes the performance bottleneck of the PQC algorithm by reducing the calculation and communication overhead of the PQC algorithm in federated learning, so that the federated learning system can meet the real-time requirement. The hybrid encryption and hierarchical security aggregation module dynamically selects a security level according to a security policy, so that both security and efficiency are considered, and risks possibly existing in a single PQC algorithm are avoided. And the post-quantum security authentication and certification server verifies the integrity and authenticity of the hardware environment and the software environment of the client, a full-stack post-quantum trust chain is constructed, and the overall security of the system is improved.
Owner:GUANGDONG CERTIFICATE AUTHORITY

A hardware configuration designed for the execution of ascon cryptographic methods while defending against side-channel attacks

A low-area hardware architecture to execute the ASCON cipher suite and resist side-channel attacks that have a co-processor having controllers, register file, a permutation operably configured to receive input from a multiplexor structure and execute ASCON permutation, an ASCON state register that can be optionally removed and substituted by the register layer inside the permutation unit, and XOR logic gates that are operably configured to receive input from the register file and the permutation unit and provide input to the multiplexor structure.
Owner:PQSECURE TECHNOLOGIES LLC

Methods and arrangements for encryption of group addressed management frames

Logic for encryption and decryption of group addressed management. Logic to generate a management frame comprising a robust security network (RSN) element (RSNE), the management frame comprising a cipher suite field with a cipher suite used together with a set of one or more keys to encrypt the group addressed management frames. Logic to cause transmission of the management frame to one or more stations (STAs). Logic to receive a management frame comprising a robust security network (RSN) element (RSNE), the management frame comprising a cipher suite field with a cipher suite used together with a set of one or more keys to encrypt the group addressed management frames. And logic to decode the management frame to determine the cipher suite used together with the set of one or more keys for encryption of group addressed management frames.
Owner:INTEL CORP

Device for protecting data and method for protecting data

Apparatus and method for protecting data frames at a transmission side of a frame-based communication link are described. The apparatus includes a cipher suite module. The cipher suite model receives the data frame and protects the data frame based on a first cryptographic key if the data frame is a priority data frame and protects the data frame based on a second cryptographic key if the data frame is a non-priority data frame. The non-priority data frame is a data frame for which transmission can be interrupted by a data frame that is the priority data frame. After protecting the data frame, the cipher suite module provides the protected data frame for transmission over the frame-based communication link.
Owner:RENESAS ELECTRONICS CORP

A communication method, device and equipment suitable for industrial control network and storage medium

PendingCN122660966ATime delaysPassword
The application discloses a communication method and device suitable for an industrial control network, equipment and a storage medium, relates to the technical field of network security, and comprises the following steps: acquiring real-time communication time delay of communication parties in a communication process in a target industrial control system; acquiring the service importance of an industrial control asset corresponding to network congestion occurring in the communication process, and calculating a dynamic time delay threshold corresponding to a preset maximum service time delay based on the service importance; comparing the real-time communication time delay with the dynamic time delay threshold, and if the corresponding comparison result meets a preset trigger condition, generating a target decision instruction by using a preset decision engine; and dynamically adjusting the strength of a corresponding password suite of the communication process according to the target decision instruction, so as to complete a corresponding encryption communication process. By generating the instruction and adjusting the strength of the password suite, the problem that a static configuration cannot adapt to real-time service requirements is solved.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

DEVICE AND METHOD FOR SECURE FRAME-BASED COMMUNICATION WITH PRIORITY FRAME

A method and device for protecting data frames on the transmitting side of a frame-based communication link are described. The device includes a cipher suite module. The cipher suite receives the data frame and protects it based on a first cryptographic key if the data frame is a priority data frame, and based on a second cryptographic key if the data frame is a non-priority data frame. A non-priority data frame is one whose transmission can be interrupted by a priority data frame. After protecting the data frame, the cipher suite module prepares the protected data frame for transmission over the frame-based communication link.
Owner:RENESAS ELECTRONICS CORP

Post-quantum cryptography security networking and data protection device for space-based orbit data center

ActiveCN122001581AMake up for the shortcomings of insufficient trust foundation in distributionSecurity balance against quantum attacksKey distribution for secure communicationRadio transmissionPathPingKey (cryptography)
The invention provides a space-based orbit data center post quantum cryptography security networking and data protection device, and belongs to the technical field of spatial information networks and information security. The device comprises a heterogeneous key fusion management module used for receiving and storing a QKD key and generating a PQC key pair, and generating a session key through a key fusion algorithm; the integrated post quantum cryptography security gateway module is used for acquiring a session key to execute network access authentication and link encryption; a situation awareness unit of the dynamic networking strategy engine module collects a link state and a threat signal, and a strategy decision unit is internally provided with a deep reinforcement learning model to output an optimal networking path and a password suite; the on-satellite data quantum security protection module is used for on-satellite data encryption and trusted execution environment isolation; and the inter-satellite block chain module is used for constructing a block chain network to realize strategy distributed collaboration. According to the method, the QKD and PQC technologies are fused, and dynamic strategy adjustment and satellite data full-life-cycle protection are achieved.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

HTTPS encrypted traffic auditing method, device, system and medium

The invention relates to an HTTPS encrypted traffic auditing method, device and system and a medium. The method comprises: receiving and processing a key packet from a client to obtain a pre-master key and TLS session metadata, the session metadata comprising a client random number, a server random number and a cipher suite identifier; performing key derivation processing on the pre-master key based on the TLS session metadata to obtain a key parameter required for decrypting the HTTPS flow; when the mirrored HTTPS flow is obtained, the secret key parameter is utilized to decrypt the HTTPS flow, and plaintext application layer data is obtained; and performing content auditing on the application layer data. According to the invention, the method effectively avoids the single-point fault and certificate trust risk of a man-in-the-middle agent, overcomes the ineffectiveness of a private key decryption scheme to a forward secrecy algorithm, avoids the system resource occupation and deployment complexity of a client agent, and achieves the efficient, compliant and bypass type auditing of the national secret and standard encrypted traffic including ECDHE and the like.
Owner:HANGZHOU DPTECH TECH

Cryptographic algorithm security negotiation method and apparatus, network function, device, storage medium, and computer program product

The application discloses a password algorithm security negotiation method, device, equipment, network function, storage medium and computer program product, wherein the method comprises the following steps: a first network function receives a first request sent by a first device; wherein the first request at least carries the identification of a password suite and / or a password algorithm, and is used for requesting to query whether the password suite and / or the password algorithm are invalid; a first response is returned to the first device; the first response carries first information, and the first information indicates whether the password suite and / or the password algorithm are invalid or not.
Owner:CHINA MOBILE COMM LTD RES INST +1

Device for protecting data and method for protecting data

The invention relates to an apparatus for protecting data and a method for protecting data. Apparatus and methods are described for protecting data frames at a transmitting side of a frame-based communication link. The apparatus includes a cipher suite module. The cryptographic suite model receives a data frame, and if the data frame is a priority data frame, protects the data frame based on a first cryptographic key, and if the data frame is a non-priority data frame, protects the data frame based on a second cryptographic key. The non-priority data frame is a data frame whose transmission can be interrupted by a data frame as a priority data frame. After protecting the data frame, the cryptographic suite module provides the protected data frame for transmission over the frame-based communication link.
Owner:RENESAS ELECTRONICS CORP

Data transmission method and device based on kTLS, equipment and storage medium

The method comprises the following steps: in the case that a TLS handshake of an application program process is completed, the application program process is used to call a first preset interface to send message data to a ULP framework, and a second preset interface is called to send a cipher suite to a hardware encryption and decryption module; the ULP framework is used to create a data structure, and the message data is stored in the data structure; a protocol stack is used to take the message data from the data structure, and the message data is encapsulated to obtain a corresponding data packet; a network device subsystem is used to store the data packet in a sending queue; a driver is used to take the data packet from the sending queue and store the data packet in a hardware queue; and the hardware encryption and decryption module is used to take the data packet from the hardware queue and encrypt the data packet based on the cipher suite.
Owner:YUSUR TECH CO LTD

A secure SSL VPN gateway communication method incorporating post-quantum cryptography technology

The application discloses a SSL VPN security gateway communication method fusing post-quantum cryptography technology, and comprises the following steps: S1, a client and a server are respectively configured with a series-connection mixed type signature digital certificate, a series-connection mixed type encryption digital certificate and corresponding PQC encryption key pair private keys, PQC signature key pair private keys, SM2 encryption key pair private keys and SM2 signature key pair private keys, wherein the series-connection mixed type signature digital certificate and the series-connection mixed type encryption digital certificate contain SM2 algorithms and PQC algorithms; S2, a mixed algorithm cipher suite using the SM2 algorithm and the PQC algorithm is added in a cipher suite list of the client and the priority thereof is forced to be on top; S3, a message structure in a handshake protocol is reformed to use the series-connection mixed type encryption digital certificate to realize anti-quantum key negotiation by adding the PQC algorithm processing on the basis of the original national secret algorithm. According to the application, the PQC algorithm is added on the basis of the original national secret algorithm and the handshake protocol is reformed, so that anti-quantum attack key negotiation and identity authentication can be realized, the communication security is obviously improved, and meanwhile, the interoperability with the standard SSL VPN is maintained.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Roaming between generations of access points with different security protocols

The present technique allows for efficient re-association of an STA from a first Wi-Fi AP to a second Wi-Fi AP, where each Wi-Fi AP utilizes a different security protocol. Due to the fact that association and key management (AKM) protocols and cryptographic suites among all generations of Wi-Fi technologies are different, the STA usually cannot utilize a fast conversion process. However, since the present technology allows the STA to derive a security key in advance, the STA may perform a fast transition and efficiently roam to a Wi-Fi AP utilizing different association and key management (AKM) versions.
Owner:CISCO TECHNOLOGY INC

A Communication Method for SSL VPN Security Gateway Based on Post-Quantum Cryptography

This invention discloses an SSL VPN security gateway communication method based on post-quantum cryptography, comprising the following steps: S1. The client and server are respectively configured with clean PQC algorithm digital certificates containing PQC encryption key pairs and signature key pairs; S2. A PQC algorithm cipher suite using the clean PQC algorithm is added to the client's cipher suite list and its priority is forcibly set to the top; S3. Quantum-resistant key negotiation is achieved by modifying the message structure in the handshake protocol to replace the SM2-based digital certificate with the clean PQC algorithm digital certificate. This invention, by introducing a clean PQC algorithm digital certificate and modifying the handshake protocol, can achieve quantum-resistant key negotiation and authentication, significantly improving communication security. Simultaneously, it is compatible with existing SSL VPN specifications, only extending PQC-related fields, thus reducing deployment costs.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

An IPv6 encrypted traffic advanced persistent threat attack identification method and system

PendingCN122457381AFeature vectorAttack
The application relates to the technical field of network security, in particular to an IPv6 encrypted traffic advanced persistent threat attack identification method and system; the method comprises the following steps: extracting a cipher suite arrangement sequence, an extended field type set and a cipher library version identifier; performing sequence comparison and tolerance determination with a preset legal client variant fingerprint library to determine a suite arrangement coincidence level; screening out to-be-identified messages with a coincidence level lower than a preset legal threshold to generate a to-be-identified object set; and performing clustering analysis based on the arrangement feature vectors of the to-be-identified object set to identify a homologous concealed imitated traffic subset. In this way, the technical problem that the identification precision of a handshake fingerprint template and the overall identification accuracy are difficult to be considered in the prior art when dealing with the realistic scene of diversified client fingerprints in a signal creation environment is solved, and the accuracy and reliability of encrypted threat identification are improved.
Owner:LISHUI POWER SUPPLY COMPANY OF STATE GRID ZHEJIANG ELECTRIC POWER

A hardware configuration designed for the execution of ascon cryptographic methods while defending against side-channel attacks

PendingUS20260189359A1MultiplexingComputer architecture
A low-area hardware architecture to execute the ASCON cipher suite and resist side-channel attacks that have a co-processor having controllers, register file, a permutation operably configured to receive input from a multiplexor structure and execute ASCON permutation, an ASCON state register that can be optionally removed and substituted by the register layer inside the permutation unit, and XOR logic gates that are operably configured to receive input from the register file and the permutation unit and provide input to the multiplexor structure.
Owner:PQSECURE TECHNOLOGIES LLC