Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

3606 results about "Common key" patented technology

Safety control method and system for remote control of Internet of Things

The invention relates to the technical field of management of the Internet of Things, and discloses a security control method and system for remote control of the Internet of Things, and the system comprises a security remote control platform, a zero-trust gateway, an authentication module, a security policy engine, edge proxy equipment and an encryption communication module. And the authentication module is used for performing identity authentication on the equipment and the user. The security policy engine dynamic access control table comprises access rule entries and associated signature information, and is issued to the edge proxy device through the zero-trust gateway. And the edge proxy device stores the dynamic access control table, verifies the signature information based on the platform public key, and performs matching and verification according to the access rule entry when receiving the control instruction. And the encryption communication module is used for performing encryption transmission on the access control table, the control instruction and the execution result. According to the invention, the whole process of remote control of the Internet of Things is dynamic, secure and credible, and the anti-attack capability and operation reliability of the system are effectively improved.
Owner:JINLANCHEN (BEIJING) TECHNOLOGY CO LTD

Computer network data secure transmission system and method

The invention discloses a computer network data secure transmission system and method, and particularly relates to the technical field of network data secure transmission, and the system comprises a dynamic key management module which generates a key seed through a quantum random number generator, generates a dynamic key bound with a data packet in combination with a timestamp, and transmits the dynamic key to a server; after being encrypted by a receiving end public key, the data are transmitted through an independent verification channel; the dual-path transmission control module is used for establishing dual channels of a main path and a shadow path, a data packet of the main path is embedded into a random camouflage protocol header to simulate a non-sensitive protocol, and a blank data packet is filled in the shadow path to maintain traffic characteristics; according to the real-time verification engine, a receiving end constructs an encrypted hash tree to achieve fragment-level integrity verification, and meanwhile, requests key state three-state verification from the key management module. Through key dynamic generation and separation transmission, dual-path adaptive fragmentation distribution, fragmentation hash tree reconstruction and key linkage verification, and abnormal triggering fragmentation level retransmission, the problems of long-term effectiveness of a static key, predictable transmission path and verification lag are solved.
Owner:陈俊奕

Securing secrets and their operation

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for providing secure protection of secrets. In some implementations, a passphrase and data corresponding to an authenticatable entity are received. An entropy extender is generated based at least on the data associated with the authenticatable entity. A key pair is generated using the passphrase and the entropy extender, the key pair comprising a public key and a private key. An identifier is generated using data from the public key, wherein the identifier maps to a file for storing content related to the authenticatable entity.
Owner:CHANG MINGTAI +1

Interface authentication method, system and equipment based on national cryptographic algorithm and medium

The invention discloses an interface authentication method, system and device based on a national cryptographic algorithm and a medium, belongs to the technical field of computer security, and aims to solve the technical problem of how to realize identity authentication, data encryption, integrity verification and replay attack protection of interface interaction and meet the security requirement of a key information system. According to the technical scheme, the method comprises the following steps: system initialization: a server and a client respectively generate SM2 key pairs, the client and the server exchange public keys through a secure channel, and a mapping relation between the public key of the opposite side and an identity label is stored; session key negotiation: exchanging a temporary public key based on an SM2-ECDH algorithm, calculating a shared secret value, and deriving an SM4 session key through a KDF; the client side carries out SM3 hash and SM2 signature on request parameters, and the server side verifies the signature and verifies a timestamp and a random number to resist replay attacks; and session key updating: triggering key updating according to a preset condition, and encrypting the new key negotiation message by using the original session key.
Owner:SHANDONG INSPUR DIGITAL BUSINESS TECHNOLOGY CO LTD

Methods, architectures, apparatuses, and systems for decentralized data control and access management

Procedures, methods, architectures, apparatuses, systems, devices, and computer program products for decentralized data control and access management. For example, a data owner may perform a subscription procedure to obtain verification credentials and an index (e.g., address, identifier) to public data control and access information. The data owner may perform a registration procedure to register ownership of data using the public data control and access information. The public data control and access information may include a public key. The public key is paired with a private trapdoor key to form a key pair. The data owner and a data consumer may perform an access procedure to grant access to registered data. For example, the registration procedure may verify collisions between a token hash, a data hash, and a data owner hash based on use of the key pair.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Distributed node unified identity authentication method and system based on QUIC protocol

The invention relates to a QUIC protocol-based distributed node unified identity authentication method and system, belongs to the technical field of network security, is applied to a client, and comprises the following steps: registering a client domain name identity through a certificate authority, obtaining a client certificate, and pre-storing a server certificate chain; generating a QUIC initial data packet according to the target server domain name identifier and the client certificate, and sending the QUIC initial data packet to the server; receiving a QUIC handshake data packet returned by the server; verifying the legality of the server certificate based on the server certificate chain, and if the server certificate is legal, calculating a pre-master key according to the client DH private key and the server DH public key; deriving a 1-RTT session key based on the pre-master key; generating a signature verification message, and sending the client certificate and the signature verification message to a server; and synchronously using the 1-RTT session key to encrypt the application layer data with the server, and transmitting the data to the server in the 1-RTT encryption space of the QUIC protocol. According to the invention, the reliability of node identities and the confidentiality of data are ensured.
Owner:BEIJING LIUJINSUIYUE TECH CO LTD

Multi-party collaborative anti-quantum signature method and system based on homomorphic hash

The invention provides a multi-party collaborative anti-quantum signature method and system based on homomorphic Hash, and relates to the technical field of digital signatures, the system comprises a plurality of participants and a verification party, and the method is specifically as follows: each participant generates a pair of public and private keys, the public key is composed of a total public key, a total signature matrix and a total Hash matrix of all participants; based on the public and private keys, all participants perform multi-party signature on the target message through a homomorphic hash function, and a generated signature is composed of total hash challenge values of all participants, total response vectors of all participants and commitment value high-order difference values of all participants; according to the signature, the verifier recovers the high order of the total commitment value, further calculates the total hash challenge value, and verifies the validity of the signature through comparison of the total hash challenge value; according to the method, multi-user collaborative signature is realized, and the security of resisting malicious opponents under a quantum computer is obtained.
Owner:SHANDONG NORMAL UNIV

Law compliance examination verification method and system based on deep learning and block chain

The invention relates to the technical field of block chains and artificial intelligence, and discloses a legal compliance examination and verification method and system based on deep learning and block chains, and the method comprises the steps: building a mapping relation based on the public key information of an enterprise and a registration database, and marking the identity features of the enterprise; constructing a block chain interaction map according to the enterprise identity features, classifying enterprise nodes in the block chain interaction map, and identifying whether a potential transverse protocol group with a high polymerization degree exists or not; if yes, acquiring historical transaction information recorded in the block chain system by the enterprise, and analyzing the historical transaction information into a feature vector; analyzing time sequence characteristics of interaction behaviors between enterprises, and outputting risk behavior tags; and generating an exception report according to the risk behavior tag, and encrypting and storing the exception report in the supervision side block chain. According to the invention, potential collusion groups with strong connection features are identified, and compliance identification accuracy and report credibility in a block chain environment are improved.
Owner:ZHEJIANG DAGU TECH CO LTD

System and Method for Direct, Structured, and Versioned Data Storage and Retrieval on a Blockchain Network

The present embodiment discloses a novel process and system for storing versioned data on the Bitcoin blockchain network. This process involves generating derived public keys linked to specific versions and data parts using a key tweaking method, and storing each data part on the blockchain using its associated derived public key. Information about versions and parts are stored in root transactions. An API is provided for managing the stored data, with options for encryption, checksums, data anchoring, timestamping, segmentation, and digital signatures. AIDIOS, a data protocol designed for direct storage and retrieval on the Bitcoin blockchain, is also included. This system allows for significant amounts of data to be stored directly on the blockchain.
Owner:DATAFAIR INC

Ciphertext decryption method and related equipment

The application discloses a ciphertext decryption method and related equipment applied to ciphertext encrypted according to an RSA algorithm, and the method comprises the following steps: acquiring a large number in ciphertext and a public key of the ciphertext; selecting a number smaller than the large number as a base of a discrete logarithm problem, selecting 1 as a modulus power operation result corresponding to the base, and converting the base and the modulus power operation result into an initial quantum state; inputting the initial quantum state into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state in which a solution result of the discrete logarithm problem is stored; extracting the solution result from the first target quantum state, and calculating a private key of the ciphertext based on the solution result; and decrypting the ciphertext based on the private key to obtain plaintext of the ciphertext. Through the technical scheme, the private key can be recovered according to the disclosed information in the case that the private key is not disclosed, and then the ciphertext is decrypted, so that the related technical blank is filled.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Block chain-based cross-border e-commerce commodity tracing method and system

The invention relates to the technical field of cross-border logistics, and discloses a cross-border e-commerce commodity traceability method and system based on a block chain, and the method comprises the following steps: generating a unique traceability code for each cross-border e-commerce commodity, extracting an original information field of the cross-border e-commerce commodity, and calculating an anti-counterfeiting hash value; performing structured packaging on the original information field and the anti-counterfeiting hash value according to a preset template, confirming a transaction through a consensus mechanism, writing the transaction into a block chain, and generating a block hash value; operation information of all logistics nodes is collected, abnormity is recognized through an abnormity detection algorithm, and data fingerprints obtained after abnormity recognition are encrypted and stored; the encrypted and signed operation information is submitted to a block chain network, and a block chain node verifies the validity of a digital signature through a public key of a producer and verifies the legality through a consensus mechanism; and proving an aggregation verification result by using zero knowledge. According to the invention, a complete traceability path is displayed, and full-chain transparent management from production to consumption is realized.
Owner:GUANGZHOU DORA TECH CO LTD

Anti-quantum serial digital certificate implementation method and device, equipment and storage medium

The invention discloses an anti-quantum serial digital certificate implementation method. The method comprises the following steps: generating a traditional cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; submitting a certificate request; splicing the traditional cryptographic algorithm public key and the anti-quantum cryptographic algorithm public key to form a dual-cryptographic algorithm public key, and generating a digital certificate according to the dual-cryptographic algorithm public key; signing the digital certificate by using a traditional cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key; and splicing and combining the traditional cryptographic algorithm signature value and the anti-quantum cryptographic algorithm signature value into a dual-cryptographic algorithm signature value, putting the dual-cryptographic algorithm signature value into a signature value item of the digital certificate, so that the digital certificate forms a hybrid serial digital certificate, and returning the hybrid serial digital certificate to the client. The invention further discloses a device for implementing the quantum serial digital certificate implementation method, computer equipment and a storage medium. According to the method, the problems of poor compatibility, low storage efficiency, slow verification speed and the like of the existing digital certificate under the threat of quantum computing are solved.
Owner:KOAL SOFTWARE CO LTD

Anti-quantum composite digital certificate implementation method and device, equipment and storage medium

The invention discloses an anti-quantum composite digital certificate implementation method. The method comprises the following steps: generating a classical cryptographic algorithm key pair and an anti-quantum cryptographic algorithm key pair; combining the classical key algorithm public key and the anti-quantum cryptography algorithm public key to obtain a public key algorithm identifier and a dual-algorithm public key combination; respectively performing signature processing on the certificate request by using a classical cryptographic algorithm private key and an anti-quantum cryptographic algorithm private key, and combining two signature results to obtain a signature algorithm identifier and a dual-algorithm signature value combination; submitting a composite digital certificate application request to a CA certificate authority; and verifying the dual-algorithm signature value combination by using the dual-algorithm public key combination in the composite digital certificate application request through the CA certificate authority, and issuing the digital certificate if the verification is passed. The invention also discloses a device for realizing the anti-quantum composite digital certificate realization method, computer equipment and a storage medium. According to the invention, dual security assurance under the threat of quantum computing is realized.
Owner:KOAL SOFTWARE CO LTD

Systems, methods, and protocols for zero knowledge proof user authentication

Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and / or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.
Owner:T STAMP INC

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI)

Systems and methods for implementing a service identity platform with cloud-based Public Key Infrastructure (PKI) include providing security as a service via a cloud-based system for a plurality of tenants, wherein the cloud-based system includes a plurality of components communicatively coupled and adapted to communicate with one another based on mutual Transport Layer Security (mTLS) authentication; responsive to a new component requiring deployment within the cloud-based system, performing an enrollment process for the new component; and subsequent to the enrollment process, utilizing the new component within the cloud-based system for providing security as a service.
Owner:ZSCALER INC

Block chain-based trusted data space cross-domain access control method, system and device, and medium

The invention relates to the technical field of data cross-domain access control, in particular to a block chain-based trusted data space cross-domain access control method, system and device and a medium, comprising: receiving a data access request, and analyzing a target data identifier, a target heterogeneous system identifier and access scene information; obtaining the data attribute of the target data according to the target data identifier, generating a dynamic access strategy in combination with the access scene information, and deploying the dynamic access strategy into the block chain; mapping the dynamic access strategy into an equivalent access control rule, and converting the data access request into target compatible request data; verifying zero-knowledge proof provided by the user based on an equivalent access control rule and a user public key; after the verification is passed, routing the target compatible request data to the target heterogeneous system; and the target heterogeneous system generates original response data, converts the original response data into user-side compatible response data and returns the user-side compatible response data to the user. According to the invention, cross-system efficient cooperation is realized, and the real-time adaptability and privacy enhancement security of access control can be improved.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Server starting control method and electronic equipment

The invention discloses a server starting control method and electronic equipment, relates to the technical field of computers, is applied to a universal boot loader, and comprises the following steps: obtaining a signature verification public key through an input interface; verifying and decrypting the signed mirror image header of the kernel mirror image by using the signature verification public key so as to recover the original mirror image header of the kernel mirror image; extracting a reference metric value of the kernel mirror image from the head of the original mirror image; calculating a to-be-verified metric value based on the kernel mirror image of which the head of the original mirror image is recovered, and comparing whether the to-be-verified metric value is consistent with the reference metric value or not; and if yes, loading the operating system. On the basis of not modifying the design of the server mainboard, active, complete and efficient trusted measurement of the BMC starting process is realized.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Safety communication method and device for upper computer and ECU, storage medium and program product

The invention provides a secure communication method and device for an upper computer and an ECU (Electronic Control Unit), a storage medium and a program product, which are respectively applied to an upper computer end and an ECU end, and the method comprises the following steps: the upper computer obtains an encryption public key of the ECU and a decryption private key of the upper computer, generates a session key for data encryption and decryption, and sends the session key to the ECU; and the session key is subjected to double encryption by sequentially using an encryption public key of the ECU and a decryption private key of the ECU, and a communication ciphertext is generated and sent to the ECU end. And after receiving the communication ciphertext, the ECU end performs dual decryption by using the encryption public key of the upper computer and the decryption private key of the ECU end in sequence, so that the session key is recovered. And after the key negotiation is completed, the two parties encrypt and decrypt communication data through a symmetric encryption mode based on the session key. According to the invention, a hybrid encryption communication mechanism taking the public key infrastructure as the root of trust is constructed, confidentiality and integrity protection of communication data is realized, and the authentication capability of the identity of the communication entity is remarkably enhanced.
Owner:SHANGHAI GEOMETRICAL PERCEPTION & LEARNING CO LTD

Large model service security verification method and device, medium, equipment and product

A security verification method, apparatus, medium, device and product for a large model service relate to the technical field of computers, receive an encryption service request, acquire a private key of a client from a key management service running in a trusted execution environment through an encryption and decryption service running in the trusted execution environment, decrypt the encryption service request based on the private key, and verify the security of the encryption service request. The method comprises the following steps: decrypting a service request of a user, sending the decrypted service request to a large model service to obtain a reasoning result of the large model service, encrypting the reasoning result through a public key of a client, and returning the encrypted reasoning result to the client, so that the service request of the user can be visible in a plaintext in a trusted execution environment; the security of the user data is greatly ensured, and the problem of user data leakage can be avoided through the public and private key pair of the user dimension. In addition, the key management service and the encryption and decryption service both run in the trusted execution environment, so that attacks from an IaaS layer can be shielded.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Education data adaptive access control method based on block chain and reputation mechanism

The invention relates to the technical field of data sharing and access control, in particular to a block chain and reputation mechanism-based education data adaptive access control method, which comprises the following steps of: firstly, constructing a historical interaction-based credible reputation mechanism: setting default trust and reputation values for an initial visitor by an attribute mechanism; calculating an initial reputation value by combining data of other fields acquired by an oracle machine, and binding public keys and reputation information of participants, a block chain storage address and a data abstract; a data owner encrypts data by using a ciphertext policy attribute-based encryption technology, formulates a policy containing an access matrix, trust and a reputation threshold in combination with a static attribute and a reputation mechanism, and binds own public key and data information to a key list; when a visitor requests, risks are quantified, attributes and reputation are verified based on related intelligent contracts, and tokens are generated if the standards are reached, so that safe and credible sharing and dynamic control of education data are realized, and the safety and flexibility are improved.
Owner:GUANGXI NORMAL UNIV

Cryptographic authentication signatures for verification of streaming data

Systems and techniques are described for signing and verifying a data stream with an encryption signature. An example method includes determining, for a data block group, an initialization vector. The example method also includes generating, based at least in part on the data block group, encrypted hash data. The example method also includes determining an encryption signature based at least in part on the encrypted hash data, a private key, and the initialization vector. The example method also includes inserting the encryption signature into the data block group. The example method also includes causing transmission, by a network interface to a media server, of the data block group and the encryption signature. Finally, the example method includes causing verification, via the media server using a public key and synchronized data, that the data block group was generated by the computing device.
Owner:AMAZON TECH INC

Data sharing method, device and system

The present application relates to the technical field of computers, and provides a data sharing method, a device, and a system. Shared data and a data protocol set by a data owner are bound for encryption protection, ciphertext structured data and retrieval metadata are integrally digitally signed, an encapsulation signature and a signature public key certificate are bound on the ciphertext structured data and the retrieval metadata, so that the data authenticity can be verified during circulation and sharing of encapsulated data, and confidentiality and integrity protection of the shared data and the data protocol during circulation and sharing are realized. In addition, the encapsulated data is generated by a trusted device trusted by the data owner, a shared agent is trusted by a plurality of participants participating in data sharing, and data is transmitted between the trusted device and the shared agent through a secure transmission channel, so that the security, confidentiality and integrity protection of the shared data and the data protocol during exporting are realized.
Owner:HUAWEI TECH CO LTD

Session key generation method and related apparatus

The application discloses a session key generation method and related device, and relates to the technical field of quantum encryption; when a first SIM card needs to interact information with a second SIM card, a private key team and a public key team can be generated; since the first SIM card is pre-configured with a hybrid key encapsulation algorithm, the public key team includes a public key that can resist quantum attacks, so after the public key team is sent to the second SIM card, the second SIM card can generate key generation information by using an encapsulation algorithm in the hybrid key encapsulation algorithm, encrypt the key generation information by using the public key team, obtain ciphertext information, and send the ciphertext information to the first SIM card; in this way, the first SIM card can decrypt the ciphertext information by using the private key team, obtain the key generation information, and thus obtain a session key.
Owner:ORIGIN QUANTUM COMPUTING TECH (HEFEI) CO LTD

Secure Communication for Connected Systems Using Post Quantum Cryptography

Embodiments of the present disclosure provide techniques for providing secure communication for connected systems. The techniques may include receiving a communication session indication associated with a first connected system; authenticating the first connected system based on IAM policy; encrypting a message to generate an encrypted message based on a post quantum cryptography public key associated with the first connected system; and causing transmitting of the encrypted message to a second connected system.
Owner:HONEYWELL INTERNATIONAL INC

Signal transmission method and device based on orthogonal matrix precoding

The invention discloses a signal transmission method and device based on orthogonal matrix precoding. The method comprises the steps that four chaotic sequences X, Y, Z and W are generated through a four-dimensional chaotic model according to a key initial value; performing bit interleaving on the original data by using X and W to obtain first data; performing serial-to-parallel conversion and QPSK mapping to obtain a mapping signal; scrambling the subcarriers and symbols of the mapping signals by using Y and Z to obtain encrypted data; carrying out IFFT (Inverse Fast Fourier Transform) on the encrypted data, adding a cyclic prefix, and carrying out parallel-serial conversion to obtain an encrypted data stream; performing binary conversion and serial-parallel conversion on the key initial value to obtain a square matrix K, and shaping the square matrix K by using a public key to obtain a key matrix; performing serial-to-parallel conversion, QPSK mapping, IFFT, cyclic prefix addition and parallel-to-serial conversion on the key matrix to obtain a key stream; and performing linear superposition on the encrypted data stream and the key stream through power distribution to obtain a power division multiplexing orthogonal frequency division multiplexing signal, and transmitting the power division multiplexing orthogonal frequency division multiplexing signal.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

SM2 collaborative signature, encryption and decryption system and method fusing anti-quantum characteristics

The invention discloses an SM2 collaborative signature and encryption and decryption system and method fusing anti-quantum characteristics, and relates to the field of cryptography and information security. According to the method, an anti-quantum cryptographic algorithm and a national cryptographic SM2 cooperative computing framework are deeply integrated, and a key security system is constructed: SM2 sub-private keys, anti-quantum key pairs and public keys are acquired and generated through an anti-quantum algorithm software and hardware enhancement module, and the private keys are encrypted and stored and are regularly alternated; on the basis of anti-quantum collaborative signature, encryption and decryption modules, an anti-quantum verification mechanism is embedded, and data is transmitted in combination with a national secret TLCP protocol, so that signature, encryption and decryption operations are completed; the equipment integration and dynamic security control unit monitors a security state, calculates a threat index to generate a protection strategy, and dynamically switches a security mode, so that the problems of insufficient security, vulnerability to attacks and data tampering of a traditional SM2 algorithm under the threat of quantum computing are effectively solved; and the long-term anti-attack capability and the operation reliability of the equipment in a high-security demand scene are remarkably improved.
Owner:ZHEJIANG ICINFO TECH

Anti-quantum cryptography migration method and system for power system

The invention relates to the technical field of data security, in particular to a quantum cryptography migration resisting method and system for a power system, and the method comprises the steps: carrying out the quantum threat risk assessment of a communication link based on the layering and partitioning architecture features of the power system; obtaining attribute data of the encryption component, and performing parallel migration risk analysis on the encryption component in combination with a quantum threat risk assessment result to generate an anti-quantum migration risk matrix; carrying out compatibility evaluation on a traditional public key algorithm and an anti-quantum cryptography algorithm based on algorithm features, and constructing a double-track encryption migration strategy; dynamically adjusting a double-track weight ratio, and constructing a double-track encryption hierarchical migration strategy based on a control hierarchy to which a communication link belongs; and executing the double-track encryption layered migration strategy and monitoring the migration effect, and performing self-adaptive correction on the double-track encryption layered migration strategy based on the migration effect. According to the method, a quantum threat assessment and double-track encryption layered migration mechanism is constructed, so that safe and smooth migration of the power system under the threat of quantum computing is realized.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

On-cloud semi-homomorphic encryption method capable of resisting private key tracking

The invention discloses an on-cloud semi-homomorphic encryption method capable of resisting private key tracking, which comprises the following steps of: S1, generating a blind identity based on the real identity of a data user, and performing identity de-association processing; s2, the attribute authority generates a binding key pair based on the blind identity and returns the binding key pair; s3, the data user discloses a real identity and a public key to the data owner; s4, the data owner encrypts the plaintext after verifying the public key to form a ciphertext set; s5, uploading the ciphertext set to a cloud service provider, and performing classified storage; s6, the cloud service provider receives the analysis request and performs homomorphic addition aggregation on the ciphertext set to generate an aggregated ciphertext; and S7, the data user uses the private key to decrypt the aggregated ciphertext, and a plaintext analysis result is recovered. According to the method, the identity privacy of the user is protected while encrypted data analysis is realized, and the method has the characteristics of untraceability and lightweight deployment.
Owner:SHANXI TAIYIAN CRYPTOGRAPHIC TESTING CENTER CO LTD

Decentralized identity verification method, device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a decentralized identity verification method, device, equipment and medium, comprising: generating an asymmetric key pair, generating a decentralized identifier based on a public key and recording the decentralized identifier to a distributed account book, a verifiable certificate containing a declaration is generated by a certificate issuer and signed, a verifiable demonstration satisfying a verification challenge is generated by using a zero-knowledge proof module in response to a verification request, and the verifiable demonstration is signed by using a private key to obtain a signed verifiable demonstration. And sending the signed verifiable demonstration to the verifier, querying the public key verification signature of the voucher issuer and the user side from the distributed account book through the smart contract, and outputting a verification result. According to the invention, the identity verification is realized through the combination of the distributed account book, the zero-knowledge proof and the smart contract, the direct exposure of sensitive information is avoided, and the safety and interoperability of cross-platform identity verification are improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Internet of Things authentication method and electronic equipment

The embodiment of the invention provides an Internet of Things authentication method and electronic equipment, and relates to the technical field of communication security, and the Internet of Things authentication method comprises the steps: obtaining a dynamic key element of terminal equipment; generating a dynamic key of the terminal equipment according to the dynamic key element, the static identity public key of the terminal equipment and the identity identification information; the static identity public key is obtained through calculation based on hardware fingerprint information and identity identification information of the terminal equipment and pre-configured bilinear pair parameters; sending an authentication request to an access point accessed by the terminal equipment; the authentication request carries identity identification information and a dynamic key; and the access point is used for acquiring the static identity public key from the block chain system according to the identity information, and authenticating the dynamic key based on the static identity public key. According to the method and the device, the security of the dynamic key can be ensured from multiple aspects, the authentication process can be accurately and efficiently completed without pre-storing a public key certificate, and the communication security between the terminal equipment and the access point is improved.
Owner:NINGBO TELIAN INFORMATION TECH CO LTD