Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1994 results about "Common key" patented technology

Systems, methods, and protocols for zero knowledge proof user authentication

Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and / or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.
Owner:T STAMP INC

Large model service security verification method and device, medium, equipment and product

A security verification method, apparatus, medium, device and product for a large model service relate to the technical field of computers, receive an encryption service request, acquire a private key of a client from a key management service running in a trusted execution environment through an encryption and decryption service running in the trusted execution environment, decrypt the encryption service request based on the private key, and verify the security of the encryption service request. The method comprises the following steps: decrypting a service request of a user, sending the decrypted service request to a large model service to obtain a reasoning result of the large model service, encrypting the reasoning result through a public key of a client, and returning the encrypted reasoning result to the client, so that the service request of the user can be visible in a plaintext in a trusted execution environment; the security of the user data is greatly ensured, and the problem of user data leakage can be avoided through the public and private key pair of the user dimension. In addition, the key management service and the encryption and decryption service both run in the trusted execution environment, so that attacks from an IaaS layer can be shielded.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Server security authentication system based on block chain trusted computing

The invention relates to the field of network and information security, and discloses a server security authentication system based on block chain trusted computing. Comprising a block chain network, an intelligent contract module, an authentication service module, a verification node and a to-be-authenticated server. The intelligent contract module records a registration index, a certification public key, a policy version number, a baseline commitment value and a revocation state. The authentication service module generates a challenge parameter and a challenge value based on the block height and the block hash digest. The trusted agent module collects a measurement abstract and forms a certification packet, and the trusted root module derives a staging certification key in a protected environment and signs the certification packet. And the verification node reads the data on the chain to complete signature verification, challenge value re-calculation, window verification and compliance proof verification, and generates an authentication bill containing an effective height range for resource access judgment after passing the verification.
Owner:EASY POINT GEEK (BEIJING) TECHNOLOGY CO LTD

Verification system, method, and recording medium

To verify the identity and non-alteration of a document prepared in relation to a prescribed activity or operation by a qualified person in a certain site or organization in another site or organization.SOLUTION: A system according to claim 1, further comprising: a first device configured to execute a process of acquiring biometric information; and a second device configured to execute a process of performing biometric authentication using the biometric information and a process of determining whether or not a person authenticated as the principal is qualified to perform a predetermined activity or an operation, wherein the first device performs an authentication process on a document created in relation to the predetermined activity or the operation of the person determined to be qualified by the second device. The information processing apparatus further includes a third apparatus that further executes a process of creating a signature using the biometric information for signature of the individual and executes a process of registering the document and the signature created by the first apparatus in a first storage unit, and a fourth apparatus that executes a process of verifying correctness of a set of the document and the signature registered in the first storage unit of the third apparatus using a public key for verifying the signature.SELECTED DRAWING: Figure 1
Owner:NEC CORP

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Method and system for implementing a privacy preserving, face-based protected public key infrastructure

A computer-implemented method of registering a user identifier in a public key infrastructure comprising a trusted device and a server is provided. The method includes the steps: receiving the user identifier as an input to the trusted device; obtaining a hash value of the user identifier; the trusted device obtaining biometric data comprising a facial image of the user; generating a public key and a privacy preserving data structure using the biometric data, encrypting the user identifier using the public key, and storing the encrypted user identifier as metadata in the privacy preserving data structure, wherein a private key for decrypting the encrypted user identifier can be generated from the privacy preserving data structure using subsequently acquired biometric data comprising the facial image of the user; generating a device token corresponding to the trusted device and obtaining a hash value of the device token, the server storing the privacy preserving data structure uniquely indexed by the hash value of the device token while using the hash value of the user identifier as a primary key, and the trusted device storing the device token.
Owner:SEVENTH SENSE ARTIFICIAL INTELLIGENCE PTE LTD

Certificateless post-quantum TLS handshake method based on KEM and IBE

The invention discloses a certificateless post-quantum TLS handshake method based on a KEM and an IBE. According to the method, the IBE public key is adopted to encrypt the temporary KEM public key, the key negotiation function and the identity authentication function are integrated in the single calculation operation, the protocol interaction structure is simplified, and certificateless two-way implicit authentication and forward security key negotiation are achieved. In a two-way identity authentication scene, the client can send the application data only by one round-trip delay, so that the connection establishment efficiency is effectively improved. By adopting the method disclosed by the invention, the attack of a quantum computer can be resisted, and the technical defects of the traditional and existing post-quantum TLS protocol in the aspects of quantum security resistance, communication overhead and handshake delay are overcome.
Owner:HANGZHOU POLYTECHNIC

Method and device for dynamic secure communication between micro-services based on chaos cryptography

The invention provides an inter-micro-service dynamic secure communication method and device based on chaos cryptography. The method comprises the steps that a service provider instance registers a public key and chaos initial parameters to a service registration center; before calling, the service consumer instance acquires a public key and a chaos initial parameter of a target service provider instance from a service registration center; the service consumer instance performs key negotiation with the acquired public key by using a private key of the service consumer instance to determine a shared key; performing key derivation on the shared key and the chaotic initial parameter to generate an initial key; respectively using the initial keys to initialize the chaotic system so as to generate synchronous encryption key streams; and the two communication parties perform real-time stream encryption and decryption on the communication data between the micro-services by using the encryption key stream. The unpredictability of a chaotic system and modern cryptography can be combined, and a micro-service design mode is deeply integrated, so that a lightweight and high-security communication security mechanism which does not need to share a key in advance and can be adaptive to dynamic change of service is realized.
Owner:浪潮智能终端有限公司

Quantum lattice signature method and device without error correction based on second power modulus, and storage medium

The invention discloses a secondary power modulus-based post-error-correction-free quantum lattice signature method, which comprises a counter, and comprises the following steps of: S1, sampling a random seed, and expanding the seed through a hash function to obtain a byte stream element I, a byte stream element II and a byte stream element III; s2, calculating and generating a public key and a private key based on the throttling element I, the byte stream element II and the byte stream element III; s3, assigning initial values to the counter and the signature, and calculating and generating a hash value I and a hash value II based on the private key and the signature message; s4, performing signature loop calculation based on the hash value I, the hash value II, the private key and the initial value of the counter to generate a legal signature final value, and returning the legal signature final value; s5, a signature verification variable is generated through calculation based on the public key and the signature final value, if the signature verification variable meets a verification condition, signature verification is passed, otherwise verification is not passed, the post-quantum lattice signature calculation efficiency, bandwidth optimization and stability are greatly improved, and a more efficient solution is provided for practical application.
Owner:HANGZHOU POST QUANTUM CRYPTOGRAPHY TECH CO LTD

Utilizing Digital Certificates Generated Based On Security Tokens To Establish Trust For Initiating Secure Connections

A system establishes a secure connection between a first entity and a second entity upon validating a digital signature of a digital certificate. The digital signature is validated utilizing a trust anchor public key corresponding to a security token issued by a trust anchor that is trusted by the first entity and the second entity. In response to a request to establish the secure connection, the system validates the security token issued by the trust anchor to establish trust between the first entity and the second entity. Upon validating the security token, the system validates the digital signature of the digital certificate utilizing an entity public key embedded in the security token. Based on the trust established by the security token, the digital certificate is trusted upon validating the digital signature. Upon validating the digital signature, the system establishes the secure connection between the first entity and the second entity.
Owner:ORACLE INT CORP

System and method for privacy-preserving electric-vehicle charging using artificial intelligence integrated blockchain and homomorphic encryption

The present invention relates to a privacy-preserving EV charging authorization and billing system, and a method for the same. The proposed system is configured to integrate permissioned blockchain with fully homomorphic encryption. The present invention aims to eliminate plaintext exposure mitigates single point of failure, by performing all authorization and billing computations on encrypted data and recoding transactions immutably, wherein an EV user securely generates encrypted authorization and billing requests using FHE-based public keys. The charging station routes these encrypted requests to the blockchain network, which records immutable encrypted transactions and verifies them via consensus. The FHE computation layer performs secure operations on the encrypted data for authorization and billing, while smart contracts execute automated verification and billing computations, ensuring transparency and auditability.
Owner:KING KHALID UNIV +1

Secure key injection method and system

The invention discloses a secure key injection method and system, which are applied to electronic equipment with a rich execution environment and a secure virtual machine environment, and the method comprises the following steps: receiving a key injection request in the rich execution environment, and loading and starting the secure virtual machine environment; forwarding the key injection request to a secure virtual machine environment; generating a key pair in the secure virtual machine environment, and sending a public key certificate and an identity certificate of the key pair to a key management background through a rich execution environment; the key management background returns response data after verification is passed, and the response data is forwarded to the secure virtual machine environment through the rich execution environment; verifying the response data in the secure virtual machine environment; and after the verification is passed, storing the to-be-injected key material in the response data in the secure virtual machine environment. According to the invention, end-to-end security protection of the key material is realized through dual-environment cooperation, and the anti-attack capability and the data confidentiality of the injection process are effectively improved.
Owner:FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD

Executing cryptographic operations in a secure element platform runtime environment

A system performs a set of cryptographic operations at least by utilizing an API to cause execution of a set of one or more secure element (SE) applications within the SE platform runtime environment of a first computing entity. The set of cryptographic operations include generating a first shared secret, generating a ciphertext at least by encapsulating the first shared secret with a first public key associated with a second computing entity in accordance with an encapsulation algorithm, and transmitting the ciphertext from the first computing entity to the second computing entity. The second computing entity derives the first shared secret by decapsulating the ciphertext with a private key corresponding to the first public key. The first computing entity and the second computing entity then exchange at least one encrypted message, encrypted with an encryption key that includes, or is based at least in part on, the first shared secret.
Owner:ORACLE INT CORP

Firmware package generation method, secure starting method, verification method, device and medium

The invention relates to the technical field of system security, and discloses a firmware package generation method, a secure starting method, a verification method, a device and a medium, the starting method is suitable for a vehicle-mounted SoC system without OTP / eFuse and with a BootROM unmodifiable, and complementary building of a trusted root is achieved in a software mode. In response to the starting instruction, the BootROM loads a security bootstrap program; during first deployment, a secure storage area is created in a nonvolatile memory, and an initial root public key and an abstract thereof are written in to complete initialization of a trust chain. In the subsequent starting process, after the security bootstrap program verifies the integrity of the root public key, the mirror image public key, the abstract and the signature of the mirror image to be started are verified, and it is ensured that the source is legal and the data is complete. On-line updating of a root public key through a chain signature mechanism is supported, that is, a current effective root private key is used for carrying out abstract signature on a new public key, and the new public key can be replaced after the signature verification of an old public key is passed, so that key rotation and trust anchor migration without hardware modification are realized.
Owner:BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI

Decentralized identity permissioned privacy enhancing technology

This disclosure provides techniques to utilize decentralized identifiers (DIDs) and verifiable credentials for secure, privacy-preserving transactions. In one aspect, a method is provided that includes: receiving user information; determining a DID based on the information; providing the DID to a user device; verifying the user's identity by validating the DID and associated verifiable credentials; and performing a transaction based on the verified DID. Other aspects are provided, such as generating a public-private key pair for the user, associating the DID with the public key, and / or creating a DID document stored on a distributed ledger accessible to authorized entities. Further aspects include processing transactions through smart contracts on a blockchain network, which may involve converting central bank digital currency to fiat currency while maintaining user privacy, applying transaction limits based on verified identity attributes, and providing zero-knowledge proofs to auditors to verify compliance without accessing underlying transaction details.
Owner:HSBC SOFTWARE DEV (GUANGDONG) LTD

Tamper protection for the clock of a field tool

PendingDE102024122454A1Programme controlTime-division multiplexTamper resistancePublic key certificate
Method (100) for operating a field device (1) comprising an adjustable clock (2), at least one non-volatile CA memory (3) containing a public key certificate (3a) of a trusted certification authority, CA, at least one non-volatile time memory (4) for recording a date and / or time (4a) and at least one interface (5), comprising the steps: • A current date and / or time (7a) is received via the interface (5) (170); • this current date or time (7a) is compared with the date or time (4a) in the time memory (4) (180); and • In response to the fact that the current date or time (7a) is later (190) than the date or time (4a) in the time memory (4), the adjustable clock (2) of the field device (1) is set to the current date or time (7a) (200).
Owner:VEGA GRIESHABER GMBH & CO

Data management method and system for trusted data delivery platform

The invention discloses a data management method and system for a data credible delivery platform. Access is realized through symmetric encryption of source data, and credible right confirmation is realized by relying on identities of owners and users of alliance chain evidence storage, source data hash and authorization rules; adding a timestamp to the encrypted data stream verified by the certificate to form a traceability mark, and encrypting or desensitizing privacy data; the trusted computing is provided with three modes: a local mode executes an algorithm in an ownership party isolation environment and records a log on a chain, a third-party mode constructs a trusted sandbox based on TEE, executes computing and links log hash after remote certification, and an algorithm privacy mode realizes cooperative computing through a Shamir secret sharing splitting algorithm in combination with MPC, a confusion circuit and zero-knowledge certification; and the result delivery adopts public key encryption, a decryption key is issued after the receipt of the user is verified, and the result hash and the receipt are linked for evidence storage, so that the problems that the existing trusted platform cannot support the execution of various algorithms and is lack of effective supervision are solved.
Owner:GUIZHOU DIGITAL INNOVATION HLDG (GRP) CO LTD

Secure data transmission over constrained one-way channel

The sender stores a pair of sender's public and private keys and a public key of the receiver, and carries out the steps of:A—generating a master key, that is a secret shared with the receiver, by key derivation from a current root key and using the sender's private key and the receiver's public key, and updating the root key with the generated master key;B—generating, by key derivation from said master key, a chain of message keys for securing messages to communicate to the receiver;C—generating a next pair of sender's public and private keys, sending the next sender's public key to the receiver and executing again the steps A andB using the next sender's private key and the same receiver's public key;wherein the current root key used in the step A isat a first iteration of step A, an initial root key prestored in the sender, said initial root key being a secret shared with the receiver, andat each subsequent iteration of the step A, the root key that has been updated at the preceding iteration of step A.
Owner:NAGRAVISION SRL

Power distribution authorization method and device based on certificate file, equipment and medium

The invention provides a power distribution authorization method and device based on a certificate file, equipment and a medium, and relates to the technical field of cross of power distribution automation and information security. A certificate generation end formats authorization information such as equipment unique identification, validity period and operation authority into an XML plaintext, randomly generates a one-time RSA key pair, and sends the one-time RSA key pair to a server; encrypting the segmented plaintext by using a public key to obtain a ciphertext, and carrying out BASE64 coding; and meanwhile, coding the private key through BASE64, performing equal-length segmentation and cross mixing on the private key and the ciphertext to form a mixed character string, adding a private key coding length identifier at the tail part, and finally outputting. And text certificates. And the verification end can perform reverse splitting only according to the length identifier, restore the ciphertext and the private key, complete BASE64 decoding and RSA decryption, analyze the XML, compare the SN and determine whether to open the configuration permission after the validity period.
Owner:XIAMEN FOUR-FAITH SMART POWER TECH CO LTD

SM9-based identity-based searchable public key encryption method and system

The invention provides an SM9-based identity-based searchable public key encryption method and an SM9-based identity-based searchable public key encryption system. The system comprises a key generation center, a cloud storage server and a file sending and receiving party. A secret key generation center generates system public and private keys by using an SM9 algorithm, and generates a private key for a user in combination with identity information of the user. The file sender uses the user identity of the receiver and the file keyword to generate a keyword index and uploads the keyword index to the cloud server; when a receiver retrieves the file, the auxiliary parameters in the index are firstly obtained from the cloud server, then a keyword trap door is generated through a private key of the receiver, and the keyword trap door is uploaded to the cloud server; and the server compares the index with the trap door through a matching algorithm, and returns a corresponding ciphertext file to a receiver for decryption if matching succeeds. The secret key generation method is consistent with an SM9 algorithm, the application field of SM9 is expanded, and the safe and efficient searchable public key encryption method which does not need certificate management and can effectively resist internal keyword guessing attacks is achieved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Data security storage system and method suitable for resource-constrained network node

The invention discloses a data security storage system and method suitable for a resource-constrained network node, and relates to the technical field of data security storage, and the method comprises the steps: carrying out the homomorphic encryption of to-be-transmitted data through employing an elliptic curve public key, packaging a homomorphic ciphertext pair through employing a session key, obtaining a transmission message, and transmitting the transmission message to a network node; transmitting the transmission message to a relay node; determining a target storage node by calculating the distance between the storage node and the aggregated ciphertext pair, performing secondary packaging on the aggregated ciphertext pair by using a storage key, performing disk falling on the target storage node, generating a Verkle proof, and establishing a data storage index; and the secondary ciphertext load is unpacked by using the storage private key, and decryption is performed by using the elliptic curve private key to obtain plaintext data. According to the method, distributed mapping is carried out, secondary packaging is carried out through a storage key derived by homology, lightweight verifiable disk falling and multi-copy redundancy are completed in combination with Verkle certification, and single-node indexing and certification expenses are reduced.
Owner:SUZHOU GUANWEN STORAGE TECH CO LTD

Safe acquisition method and device of BMC information, equipment and medium

The invention relates to the technical field of BMC security, and provides a security acquisition method and device of BMC information, equipment and a medium, and the method comprises the steps: generating a one-time public key and a one-time private key for a single communication session according to a self MAC address and real-time time; performing hash operation on the one-time public key to obtain a one-time public key hash value; sending the one-time public key hash value to a key management server, so that the key management server signs the one-time public key hash value by using a preset private key, and receiving a returned signature result; packaging the one-time public key and the signature result into a request message, and broadcasting the request message to a local area network to enable the BMC to generate and return an encrypted response message after signature verification; and monitoring and receiving an encrypted response message returned by the BMC, decrypting the encrypted response message by using the one-time private key, and extracting and displaying BMC information. According to the technical scheme, confidentiality, safety and integrity of the response information in the transmission process are guaranteed.
Owner:NINGCHANG INFORMATION TECH (HANGZHOU) CO LTD

Vehicle remote upgrading method and device and vehicle

The invention provides a vehicle remote upgrading method and device and a vehicle, which are applied to the technical field of automobile information security, and the method comprises the following steps: firstly encrypting an original upgrading package through a dynamic symmetric algorithm key to obtain an encrypted upgrading package, carrying out Hash algorithm operation on the original upgrading package to obtain a first Hash value, and then, carrying out Hash algorithm operation on the original upgrading package to obtain a second Hash value; performing asymmetric algorithm private key encryption on spliced data of the symmetric algorithm secret key and the first hash value to obtain a digital signature, encrypting the digital signature and the symmetric algorithm secret key by using a vehicle-side asymmetric algorithm public key to obtain a digital envelope, packaging the digital envelope and an encrypted upgrade package into a transmission data package, and finally, sending the transmission data package to the vehicle-side asymmetric algorithm public key. And the transmission data packet is transmitted to the vehicle-mounted networking terminal, so that the vehicle-mounted networking terminal performs asymmetric signature verification and symmetric decryption based on the transmission data packet, and software upgrading corresponding to the upgrading packet is realized. According to the method, the symmetric algorithm key and the hash value digital signature are jointly packaged into the digital envelope, so that the tampering risk of the upgrade package is reduced.
Owner:SANY SPECIAL PURPOSE VEHICLE CO LTD

System and method for enforcing PII segregation in a distributed data 1 processing system for Privacy-preserving AI corpus generation

A system and method are disclosed for generating a privacy-preserving data corpus for Artificial Intelligence (AI) training. The system comprises a relying partner (RP) computing environment and a trusted, independent identity provider (IdP) computing system. Upon a user authentication request, the IdP provides the RP with only a PII-free, persistent pseudonymous identifier (gUserID) for the user. Any authentication artifacts containing Personally Identifiable Information (PII), such as an OAuth token, are programmatically neutralized by the IdP. This is achieved by generating a transient public-private encryption key pair, immediately destroying the private key, and encrypting the PII-laden artifact with the remaining public key, rendering the PII therein permanently irrecoverable. This enforcement of “PII unknowability” at the RP enables the aggregation of pseudonymous user data, linked by the persistent gUserID, from multiple independent RPs into a rich, cross-organizational corpus for AI training, without ever exposing user PII to the RP.
Owner:NEMA WALEED S

Remote office dynamic authority management method and system

The invention relates to a remote office dynamic authority management method and system, and belongs to the technical field of authority management. Comprising the steps of obtaining global attribute data of employees; based on the global attribute data, constructing an authority control chart model adaptive to the remote office scene; generating attribute-based encryption parameters based on the global attribute data, including an employee attribute private key and an ABE public key, and issuing the attribute-based encryption parameters to the authority control chart model; encrypting the resource files by using the ABE public key and setting an access strategy of each resource file; receiving an employee access request, and completing authentication based on a hidden attribute mechanism; dynamically adjusting the access authority of the employee in combination with the real-time behavior data, and updating an employee attribute private key according to the adjusted access authority; generating a transaction according to the change result and broadcasting the transaction to the whole network through a consensus mechanism; resource decryption is completed based on the updated private key; and after the session is finished, automatically recovering the temporary authority and updating the on-chain record.
Owner:CHINA DATACOM CORP LTD

Device binding using cryptographic keys

A method is disclosed. The method includes receiving, from a user device storing a private key of a public-private key pair, a first attestation message comprising a first attestation data packet, the public key, a user device identifier for the user device, and a credential. The method also includes binding the credential to the user device identifier, and transmitting, to a token service computer, the first attestation data packet. The token service computer previously bound a first token from a first token requestor interacting with the user device to the user device identifier. The method includes receiving, from a second token requestor interacting with the user device, a second attestation message comprising a second attestation data packet, verifying, the second attestation data packet using the public key, and transmitting, verification data to the second token requestor. The second token requestor transmits the verification data to the token service computer.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Hybrid collaborative signature method fusing SM2 and post quantum cryptography algorithm

The invention belongs to the technical field of information security, and discloses a hybrid collaborative signature method fusing SM2 and a post-quantum cryptography algorithm, and the method comprises the steps that a client generates a first session key based on a first post-quantum signature key pair and a first post-quantum asymmetric encryption and decryption key pair, generating a first public key ciphertext corresponding to the first public key parameter based on the first session key; the server decrypts the first public key ciphertext based on the first session key, and applies for obtaining a digital signature certificate after generating a common public key through an SM2 algorithm; performing collaborative signature according to a second session key generated by a second post-quantum signature key pair and a second post-quantum asymmetric encryption and decryption key pair, calculating by the server to obtain a first signature component intermediate value, and calculating by the client to obtain a second signature component; the client calculates a target signature value according to the second signature component, the first signature component intermediate value ciphertext and the digital signature certificate; through the method, the safety of the hybrid collaborative signature is improved.
Owner:GUANGDONG CERTIFICATE AUTHORITY

Anti-quantum computing IPSEC key exchange method

The invention relates to an IPSEC (Internet Protocol Security) key exchange method resistant to quantum computing. According to the invention, based on a lattice cryptographic algorithm and improved SM4-256 symmetric encryption, secure communication between a master mode and a fast mode is realized; in the main mode, an initiator sends an IKE first message through a UDP (User Datagram Protocol), negotiates SA parameters with a responder and exchanges a lattice password certificate; the two parties encapsulate a temporary 32-byte secret key by using the public key of the opposite party, generate a 512-bit random number through SM4-256 encryption, and sign and transmit the 512-bit random number to realize secure random number exchange and certificate verification; and the two parties calculate a first session key based on a PRF (Pseudo Random Function), and encrypt an exchange data HASH value to complete main mode key consistency confirmation. And after entering the fast mode, taking the main mode session key as an SM4-256 symmetric key to continue communication, sending an SA message carrying a 512-bit random number by the two parties, calculating to obtain a second session key, and establishing an ESP tunnel. According to the method, the security of IPSEC under the threat of quantum computing is improved through the lattice password.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Securing blockchain transaction based on undetermined data

Computer-implemented methods for locking a blockchain transaction based on undetermined data are described. The invention is implemented using a blockchain network. This may, for example, be the Bitcoin blockchain. A locking node may include a locking script in a blockchain transaction to lock a digital asset. The locking script includes a public key for a determined data source and instructions to cause a validating node executing the locking script to verify the source of data provided in an unlocking script by: a) generating a modified public key based on the public key for the determined data source and based on data defined in the unlocking script; and b) evaluating a cryptographic signature in the unlocking script based on the modified public key. The blockchain transaction containing the locking script is sent by the locking node to the blockchain network. The lock may be removed using a cryptographic signature generated from a private key modified based on the data.
Owner:NCHAIN LICENSING AG