Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

18 results about "Cryptographic primitive" patented technology

Cryptographic primitives are well-established, low-level cryptographic algorithms that are frequently used to build cryptographic protocols for computer security systems. These routines include, but are not limited to, one-way hash functions and encryption functions.

Zero-trust quantum key remote secure injection method and system based on PQC

The invention relates to the technical field of quantum communication, discloses a quantum key remote security injection method and system based on PQC and zero trust, and aims to solve the problems that post-quantum authentication is high in calculation overhead, difficult in terminal adaptation due to resource limitation and lack of continuous verification capability. The method comprises the following steps: presetting a secret seed; the terminal generates a disturbance public key based on the seed and the basic temporary public key and initiates a request; the server carries out implicit authentication by comparing the disturbance public key and executes key encapsulation to generate a session key; the server encrypts the quantum key and signs and sends the quantum key; and after the terminal verifies the signature, the basic private key is used for de-encapsulation to obtain the quantum key. The system comprises a key injection server, a terminal security agent and a disturbance function module. According to the method, authentication logic is integrated into a cryptographic primitive algebraic structure, so that authentication internal biochemistry and light weight are realized, the terminal power consumption and storage occupation are remarkably reduced, the resource exhaustion attack resistance is enhanced, and the continuous authentication requirement of a zero-trust architecture is met.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Anti-collusion low-overhead bidirectional verification privacy protection federated learning method

The invention provides an anti-collusion low-overhead two-way verification privacy protection federated learning method, which specifically comprises the following steps: S1, a trusted third party initializes system parameters, and a server initializes a global model and distributes the global model to a client; s2, the client uses local data to train a global model and carries out compression encryption, signature and share division on an output calculation result; s3, the server reconstructs the client ciphertext by integrating the share shared by the client and verifies the correctness of the reconstruction result; s4, aggregating the ciphertext by the server; and S5, the client decrypts and decompresses the aggregated ciphertext and verifies an aggregation result. The invention provides an anti-collusion low-overhead two-way verification privacy protection federated learning method. According to the method, while bidirectional verification between the client and the server is realized, a scheme is constructed by using a super-incremental sequence and lightweight cryptographic primitive secret sharing, so that the computing load of the system is effectively reduced, and the tolerance of the system to collusion of the client and the server is improved.
Owner:JIANGSU OCEAN UNIV

Bootstrappable fully homomorphic attribute-based encryption method with unbounded circuit depth

Homomorphic attribute-based encryption (HABE) is a useful cryptographic primitive that supports both fine-grained access control and computation over ciphertexts. However, existing HABE schemes are limited to the homomorphic evaluation of circuits with either bounded depth or a restricted number of inputs. To address this problem, the present disclosure introduce a bootstrappable, fully homomorphic attribute-based encryption (FHABE) scheme that supports computations of circuits with unbounded depth over cross-attribute ciphertexts. Compared to state-of-the-art schemes, the proposed scheme also has a more lightweight ciphertext and eliminates the reliance on the random oracle model. Additionally, the present disclosure extend the FHABE to a proxy re-encryption setting, proposing an attribute-based homomorphic proxy re-encryption scheme that facilitates efficient sharing of encrypted data. This scheme is the first lattice-based multi-hop attribute-based proxy re-encryption scheme with unbounded hops of re-encryptions.
Owner:JINAN UNIVERSITY +2

Post-quantum identity signature generation verification method and system based on symmetric cryptographic primitives

This invention relates to a post-quantum identifier signature generation method and system based on symmetric cryptographic primitives. First, based on given security parameters, a master key is obtained, including a master public key and a master private key. Then, based on a given user identity and the master private key, a user private key is generated. Based on the generated user private key and the message, a signature value is obtained. Finally, a verifier performs a zero-knowledge proof on the signature value based on the given message; if successful, the signature is correct; otherwise, the signature is incorrect. Compared with existing technologies, this invention has the following advantages and beneficial effects: With the development of post-quantum signature technology, scholars have proposed lattice-based signature algorithms and homology-based signature algorithms, but no one has yet proposed a post-quantum identifier signature based on symmetric cryptographic primitives. It offers high security, relying on the security of symmetric cryptographic algorithms, without relying on difficult problems such as the RSA problem to construct the signature, requiring fewer cryptographic primitives and offering higher security. The generation of this identifier signature meets post-quantum security requirements.
Owner:WUHAN UNIV

Federated learning method of fault-tolerant layered verifiable secure aggregation based on privacy protection

The application discloses a privacy protection-based fault-tolerant layered verifiable secure aggregation federated learning method, relates to the technical field of information security communication, and comprises an initialization stage, a local model training and signature generation stage, a local model aggregation and secret sharing stage and a global model updating stage. The application uses a three-layer architecture for training without introducing complex cryptographic primitives encryption, thereby achieving a balance between privacy protection and system overhead. The first layer is a user layer mainly performing local training and introducing a blinding technology to protect the local training result. The second layer is an edge server layer mainly realizing local aggregation and share sharing, and encoding the shared shares to avoid direct transmission. The third layer is an aggregation server layer mainly performing parameter reconstruction to update the global model. The application designs an elliptic curve-based digital signature technology, simultaneously introduces a hash chain to protect the integrity of data, can maintain a high training accuracy, and reduces communication and calculation overhead.
Owner:SOUTHWEST PETROLEUM UNIV

Garbling scheme-based secure multi-party computation (MPC)

A novel secure multi-party computation (MPC) protocol that uses a cryptographic primitive known as a garbling scheme is provided. In certain embodiments, this protocol enables a set of N parties (such as nodes in a blockchain network) to execute an arbitrary function (such as a smart contract method) on confidential data, without revealing that confidential data to the parties.
Owner:SODA BUBBLE LABS LTD

Post-quantum non-certificate signature generation method and device based on symmetric cipher primitives

The application provides a post-quantum certificateless signature generation method and device based on symmetric cryptographic primitives. The method comprises steps 1 to 7. The application initiatively proposes a post-quantum certificateless signature based on symmetric cryptographic primitives, generates zero-knowledge proof through secure multi-party computation, can achieve the purpose of resisting quantum, and satisfies the post-quantum security requirement of the generation of the certificateless signature, thereby improving the security of the target to be protected.
Owner:WUHAN UNIV

Lightweight network authentication for resource constrained devices via mergeable stateful signatures

Signature-based authentication is a core cryptographic primitive essential for most secure networking protocols. A new signature scheme, MSS, allows a client to efficiently authenticate herself to a server. The new scheme is modeled in an offline / online model where client online time is premium. The offline component derives basis signatures that are then composed based on the data being signed to provide signatures efficiently and securely during run-time. MSS requires the server to maintain state and is suitable for applications where a device has long-term associations with the server. MSS allows direct comparison to hash chains-based authentication schemes used in similar settings, and is relevant to resource-constrained devices, e.g., IoT. MSS instantiations are derived for two cryptographic families, assuming the hardness of RSA and decisional Diffie-Hellman (DDH) respectively. Then used is the new scheme to design an efficient time-based one-time password (TOTP) protocol.
Owner:RGT UNIV OF CALIFORNIA

A safety prediction method based on binary neural network

This invention provides a secure prediction method based on a binary neural network. For each layer of the binary neural network, while fully utilizing its binary characteristics, a secure and efficient ciphertext evaluation protocol is designed using lightweight low-level cryptographic primitives. Combining these protocols enables end-to-end privacy prediction services. Specifically, for the linear layers in the prediction process, this invention proposes a binary matrix multiplication protocol. For the nonlinear layers in the prediction process, this invention innovatively introduces a secure symbolic protocol with adder logic. All the protocols proposed in this invention can significantly improve the communication and computational efficiency of ciphertext prediction while ensuring security.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Hybrid hierarchical encryption system

A hybrid cryptographic scheme for a network of nodes, in particular an IoT network, composed of a first subset and a second subset of separate nodes, the computing resources of the nodes of the first subset being greater than the computing resources of the nodes of the second subset, the scheme comprising a first functional cryptographic scheme deployed on the first subset of nodes and a second functional cryptographic scheme deployed on the second subset of nodes, a cryptographic primitive at the root of the second cryptographic scheme generating a pair of private and public master keys from a seed, the seed being obtained by a connection cryptographic primitive from at least the private key of an end node of the first subset, the connection cryptographic primitive being a one-way function.
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

A lightweight consensus method for large-scale distributed intelligent computing scenarios

The application belongs to the technical field of block chain, and particularly relates to a lightweight consensus method for large-scale distributed intelligent computing scenarios. The method is as follows: firstly, a threshold key is initialized among replica nodes and a signature share is generated. In the chain consensus stage, the leader node broadcasts a proposal, and the replica verifies and generates a threshold signature share and returns after verification; the leader node aggregates enough shares to form a legal certificate to promote the pipeline. If a certificate is not formed within a timeout, the view synchronization and recovery stage is entered. When adjacent view chain certificates are reached, the final submission can be accelerated; otherwise, the block needs to be submitted after meeting the continuous three-view condition. In abnormal conditions, the view synchronization mechanism is enhanced to aggregate the view switching threshold share, so that the whole network quickly converges to the new view and recovers the consensus. The technical scheme of the application can be widely applied to large-scale distributed sharded block chain networks through the collaborative optimization of the cryptographic primitives and the sharding structure level.
Owner:ZHEJIANG SCI-TECH UNIV +1

Cryptography Bill of Materials (CBOM) Generation from Binary Executables

A software package is received so that functions within the software package that implement or use cryptographic primitives can be identified. Further, a set of calls with each of the identified functions are determined. A call site analysis is performed based on the set of calls to determine cryptographic algorithm parameters. Thereafter, based on the set of calls and the call site analysis, a cryptography bill of materials (CBOM) detailing cryptographic primitives within the software package is generated. This CBOM can be provided to a consuming application or process. Related apparatus, systems, techniques and articles are also described.
Owner:BINARLY INC

Hash-driven multi-layer anti-quantum security protocol generation verification system and method

The application provides a kind of multi-layer anti-quantum security protocol generation verification system and method based on hash drive, defines security target, selects the cryptographic primitive pool with anti-quantum hash function as core, and constructs active network enemy model containing quantum query capability;Based on the cryptographic primitive pool, a multi-layer protocol logic framework is constructed, and specific protocol interaction message sequence is generated;Formal modeling is a computational model that can be processed by automated theorem proving tools;The automated theorem proving tool is used to deduce and verify the computational model, if the verification is not passed, return to iterate and optimize the protocol interaction message sequence, until the final protocol specification that meets all the security targets and can be proved safe is generated.The application integrates protocol design, multi-layer architecture construction and formal verification into one, forms a closed-loop engineering process, and aims to automatically generate and strictly verify security protocols with anti-quantum capability and deep defense characteristics.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Password strategy self-adaptive arrangement method, system, equipment and medium

ActiveCN121750229AMultiple keys/algorithms usagePassword policyPassword
The invention provides a password strategy self-adaptive arrangement method, system and device and a medium, and the method comprises the steps: evaluating a service state according to a collected system architecture, a service interaction path, service interaction information and interaction node information; matching a corresponding baseline password strategy according to the service type; based on a service state and a baseline password strategy, solving an optimal password primitive combination sequence as a final password strategy under the constraint of a planning budget; according to the method, dynamic perception of the composite security target is realized by comprehensively analyzing the service state, and the optimal password primitive combination sequence is solved under the constraint of the planning budget based on the service state and the baseline password strategy to serve as the final password strategy, so that password strategy self-adaptive arrangement is realized; while the encryption protection strength in the business data interaction process is improved, irrelevant resource overhead and related economic investment brought by protection operation are reduced as much as possible, and the method has a good application prospect.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD

A method and system for generating a perceptual pilot based on cryptographic primitives for integrated sensing and communication deterministic sensing

The application discloses a kind of based on cryptography primitive generation perception pilot integrated sensing algorithm integration deterministic perception method and system, belong to 6G integrated sensing algorithm integration technical field.The application makes both sides of communication based on shared cryptography material and time-varying synchronization parameter, same perception pilot is independently generated by cryptography deterministic function, and multi-node zero signaling cooperative perception is realized.Synchronization parameter can use physical layer broadcast timing, the logical state of protocol security state machine output or unified anchor point time T_anchor;Wherein rule D directly uses T_anchor As state value, can generate various communication and perception parameters.The application provides three kinds of implementation paths: path A is compatible with 5G traditional architecture, path B introduces DSF and PSSM, path C uses LPC+PAN decoupling architecture, and introduces two layers of decoupling and centralized clock bias management, and physical layer uncertainty is transparent to node.Through two-step deterministic arbitration and downlink implicit authorization mechanism, multi-node resource conflict is solved in order.The application completely eliminates pilot signaling overhead, reduces external synchronization dependence, tolerates the inconsistency between nodes Physical parameters, applicable to ground network, non-ground network and hybrid networking scene, provides end-to-end deterministic guarantee for integrated sensing algorithm integration.
Owner:SHANGHAI HUAPAITE TECHNOLOGY CO LTD

Federal learning method for fault-tolerant hierarchical verifiable security aggregation based on privacy protection

The invention discloses a federated learning method for fault-tolerant hierarchical verifiable security aggregation based on privacy protection, which relates to the technical field of information security communication and comprises an initialization stage, a local model training and signature generation stage, a local model aggregation and secret sharing stage and a global model updating stage. According to the method, complex cryptographic primitive encryption is not introduced while a three-layer architecture is used for training, so that the balance between privacy protection and system overhead is realized. The first layer is a user layer which mainly executes local training and introduces a blinding technology to protect a local training result. And the second layer is an edge server layer which mainly realizes local aggregation and share sharing and encodes the shared shares to avoid direct transmission. And the third layer is an aggregation server layer which is mainly used for parameter reconstruction so as to update a global model. According to the invention, a digital signature technology based on an elliptic curve is designed, and meanwhile, a hash chain is introduced to protect the integrity of data, so that relatively high training accuracy can be kept, and communication and calculation overhead is reduced.
Owner:SOUTHWEST PETROLEUM UNIV

HYBRID HIERARCHICAL ENCRYPTION SYSTEM

The present invention relates to a hybrid cryptographic scheme for a network of nodes, in particular an IoT network, composed of a first subset and a second subset of disjoint nodes, the computing resources of the nodes in the first subset being greater than the computing resources of the nodes in the second subset. The scheme comprises a first functional cryptographic scheme deployed on the first subset of nodes and a second functional cryptographic scheme deployed on the second subset of nodes. A cryptographic primitive at the root of the second cryptographic scheme generates a private and public master key pair from a seed. The seed is obtained by a cryptographic connection primitive from at least the private key of an extremal node in the first subset. The cryptographic connection primitive is a one-way function. Fig. 5
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

Systems and methods for a multi-system, multi-client, multidirectional, cyber-resilient, permissioned blockchain imaging data exchange platform

ActiveUS12671599B1ConfidentialityEngineering
Techniques are described herein for enhancing the privacy, confidentiality, cyber-resilience, and operational efficiency of multi-system, multi-client, multi-directional image exchanges among client users, devices, servers, cloud environments, or other applications within one network or a system of networks by deploying a permissioned blockchain, that uses threshold cryptographic primitives and the key component of permissioned blockchains called Byzantine fault-tolerant (BFT) protocol, combined with fine-grained access control, publish / subscribe capabilities and a novel use of the private chaincode functionality during image exchange operations, which involves image sharing without sacrificing performance. Techniques, methods, processes, and systems described herein can enhance operational efficiency by increasing operational processing speed and reducing operational processing time for image exchange operations within the platform.
Owner:SOFTHREAD INC