Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Cryptographic protocol" patented technology

A security protocol (cryptographic protocol or encryption protocol) is an abstract or concrete protocol that performs a security-related function and applies cryptographic methods, often as sequences of cryptographic primitives. A protocol describes how the algorithms should be used. A sufficiently detailed protocol includes details about data structures and representations, at which point it can be used to implement multiple, interoperable versions of a program.

Distributed private data security aggregation method based on federal learning

The invention relates to the technical field of data security, in particular to a federated learning-based distributed privacy data security aggregation method, which comprises the following steps of: acquiring multi-source heterogeneous data of a leaf supplier node; performing weighted fusion on the multi-source heterogeneous data by using the multi-modal fusion model to generate a health state vector; training by using the health state vector in combination with a blade X-ray defect data set to obtain a local model; calculating a leakage risk score, and performing privacy processing on the local model through a differential privacy mechanism to obtain a noise adding model; calculating the reference data set by using a noise adding model to obtain a performance score, and generating an encryption proof for a calculation process; and the central server receives the zk-SNARK encryption proof submitted by all the nodes, converts the performance score into an aggregation weight, initiates a secure multi-party computing protocol, and performs weighted calculation on the noise adding model by using the aggregation weight to generate a global model. According to the method, multi-party safe and credible collaborative modeling is realized by fusing multiple cryptographic protocols.
Owner:SUZHOU GUANGCHI INFORMATION TECHNOLOGY CO LTD

Identity-based signature method supporting multi-message aggregation

The invention discloses an identity-based signature method supporting multi-message aggregation. The identity-based signature method comprises the steps of system initialization and key generation, user signature key generation, message signature construction, single signature verification, signature aggregation and aggregation signature verification. Due to the fact that the linear homomorphic signature technology is adopted, the identity-based aggregation signature method is provided, and the technical problems of signature after aggregation, key size expansion and the like in the existing aggregation signature technology are solved. Through the method, a verifier can safely and efficiently merge a plurality of signatures into a signature with a compact size, efficient data source authentication can be realized while the data integrity is guaranteed, and the verification efficiency is remarkably improved. The method has the advantages of high security, low communication cost, small calculation overhead and the like, can be applied to the technical fields of large-scale data authentication, distributed system security, lightweight cryptographic protocols and the like, and is particularly suitable for mobile terminals or Internet of Things equipment scenes with limited calculation resources.
Owner:SHAANXI NORMAL UNIV

A method and apparatus for customizing a cryptographic protocol cluster

The embodiment of the application discloses a self-defined encryption protocol clustering method and device, the method comprises the following steps: obtaining a target encryption protocol to be identified, and extracting traffic data and metadata of the target encryption protocol; constructing a label matrix and a value matrix based on the traffic data; and fusing the label matrix and the value matrix by using a multi-mode matching algorithm to obtain a clustering label. In this way, the self-defined encryption protocol clustering method provided by the application combines double-matrix combination with a pattern matching algorithm to realize clustering of self-defined encryption protocols. The method solves the problem that mixed self-defined protocols cannot be quickly and accurately clustered, and provides support for subsequent protocol analysis by quickly and accurately realizing clustering of self-defined protocols.
Owner:VIEWINTECH

Large language model driven password protocol automatic formalization modeling method and system

PendingCN122433679ALinguistic modelPassword
The present application belongs to the technical field of network security and artificial intelligence, and provides a large language model driven password protocol automatic formalization modeling method and system, acquires a natural language protocol specification document, and performs preprocessing; according to the priority order of a message block, a verification block and a calculation statement, a large language model extracts corresponding semi-structured intermediate representations from text blocks; all intermediate representation statements are scanned at one time by using the large language model, protocol functions and symbols are identified and stored in a knowledge base, the large language model is driven in units of intermediate representation statements to be refined one by one, and global context and local context are extracted; the completely structured intermediate representations, a protocol role set and the updated knowledge base are taken as inputs to perform deterministic one-to-one mapping with formal verification tool code, and conversion is completed. The present application can automatically generate symbol model code which can be directly input into a formal verification tool.
Owner:SHANDONG UNIV

Acceleration of cryptographic operations

A circuit arrangement includes a plurality of cryptographic accelerators. Each cryptographic accelerator is configured to perform cryptographic operations according to a respective cryptographic protocol. A first memory is coupled to the cryptographic accelerators. A first processor is configured to specify, in response to requests to perform the cryptographic operations, parameters to the cryptographic accelerators according to the requests. The first processor is configured to identify, in the first memory, keys that are associated with the cryptographic accelerators, and signal the cryptographic accelerators to commence performing the cryptographic operations according to the parameters and using the associated keys.
Owner:XILINX INC

A control method of a multi-protocol switching quantum security-resistant gateway

This application relates to a control method for a multi-protocol switching quantum-resistant security gateway. The method includes, after the security gateway powers on, performing a hardware environment security self-test and generating a unique root key based on a physically non-cloning function; continuously collecting and analyzing network traffic characteristics; identifying quantum attack patterns and dynamically deciding on encryption algorithm modes based on a machine learning model; parsing communication data packets; dynamically converting and adapting between traditional and quantum-resistant cryptographic protocols according to instructions and preset rules; calling a quantum-resistant cryptographic engine for encryption or signature operations; dynamically deriving and managing session keys throughout their lifecycle based on the root key; and, based on quantum attack detection results, switching algorithm modes, communication protocols, and keys in a coordinated manner, while also enabling side-channel attack protection and hardware security response. This method achieves proactive protection against quantum attacks, seamless multi-protocol compatibility, and full lifecycle security management of keys for the security gateway.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Password defines security architecture and rule execution method

The present application relates to the technical field of network information security, and particularly relates to a password definition security architecture and a rule execution method, the architecture comprising a device plane, a security plane, a calculation plane, a network plane, a data plane, a rule plane and an application plane, each plane implementing execution of a security rule through a password protocol mode. The rule execution method of the password definition security architecture comprises, after initialization of an information system, planning a routing path, authenticating password definition security devices on the path, establishing a secure access channel between adjacent devices to guarantee routing security of data on the path, then encapsulating each packet of data based on business data identification to implement business slicing and protocol filtering based on an authorized credential, then performing secure forwarding according to a routing path specified by the authorized credential to prevent hidden channels and rule violations, and the security of an entire access request session depends on the security rule of the authorized credential. The present application can ensure security and compliance of business data in a flow process.
Owner:ZHENGZHOU XINDA YUNGU TECH CO LTD

A method and system for detecting and warning of cryptographic protocol anomalies

PendingCN122137619ASecuring communicationHigh level techniquesFeature setCryptographic protocol
This invention provides a method and system for detecting and warning of anomalies in encryption protocols, belonging to the field of network security technology. The method includes: extracting a multimodal feature set from the target encryption protocol communication stream; inputting it in parallel into an adaptive rule engine and an interpretable artificial intelligence model to obtain rule-triggered events and confidence weights, a first anomaly score, and an attribution explanation report, respectively; calculating a second anomaly score based on the above outputs using an improved scoring algorithm; fusing the first and second anomaly scores to obtain a comprehensive anomaly score and generating a warning decision; and uploading the warning information to a federated collaborative node to drive the collaborative evolution of the global rule base and the model. This invention, employing the aforementioned method and system for detecting and warning of anomalies in encryption protocols, solves the collaborative problems of poor interpretability, lagging knowledge updates, and data silos in encryption threat detection through deep collaboration between an interpretable artificial intelligence model and a rule engine, achieving accurate, reliable, and adaptive anomaly warnings.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

A system and a method for distributed data intersection using privacy preserving collaborative detection

A system and method for distributed data intersection using privacy preserving collaborative detection is disclosed The system includes a processor and a memory that causes the processor to verify data sets and configurations from a first and second entity interacting in a distributed data intersection to ensure data integrity and privacy during a data collaboration. The processor enables computations between the first and second entity using cryptographic protocols to identify common data points. The processor allows the first and second entity to retrieve the common data points pertaining to other entity using a oblivious data sharing technique while maintaining confidentiality of the data accessed during the interaction. The processor facilitates validation of data integrity and accuracy without revealing underlying information. The processor controls data-sharing policies ensuring that authorized data is disclosed based on a predefined criteria thereby enabling collaboration of data for re-identification while protecting privacy.
Owner:PRIVASAPIEN TECH PTE LTD

Network telemetry with byte distribution and cryptographic protocol data elements

ActiveUS12719839B2Data packCryptographic protocol
In one embodiment, a method includes receiving a traffic flow including a plurality of packets encrypted using a cryptographic protocol, determining cryptographic protocol data of the traffic flow, and transmitting telemetry data of the traffic flow including the cryptographic protocol data. In another embodiment, a method includes receiving telemetry data of a traffic flow including a plurality of packets encrypted using a cryptographic protocol, the telemetry data including cryptographic protocol data of the traffic flow, classifying the traffic flow based on the cryptographic protocol data using a machine learning classifier; and taking a remedial action with respect to the traffic flow based on the classification of the traffic flow.
Owner:CISCO TECHNOLOGY INC

Anti-quantum enhancement method and device for stock password equipment system

The invention discloses an anti-quantum enhancement method and an anti-quantum enhancement device for a stock password equipment system. On the premise of not changing the hardware architecture of stock classical cryptographic equipment, an anti-quantum cryptographic card or entrance guard type anti-quantum security enhancement equipment is connected with the anti-quantum cryptographic card or entrance guard type anti-quantum security enhancement equipment to provide anti-quantum security enhancement; the stock classical cryptographic equipment system refers to a cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, a software system and the like which are deployed and cannot resist quantum attacks; the anti-quantum cryptographic card is a cryptographic card supporting a classical cryptographic algorithm and an anti-quantum cryptographic algorithm, a classical cryptographic chip, an anti-quantum FPGA chip and other components are arranged on the anti-quantum cryptographic card, and the anti-quantum cryptographic card is connected with stock classical cryptographic equipment through a PCIe interface. The entrance guard type anti-quantum security enhancement equipment is electronic equipment which is deployed between classical cryptographic equipment and a public network and carries out anti-quantum security protection on a Diffie-Hellman type cryptographic protocol, so that a session key cannot be exported even if communication between entrance guard type equipment is acquired by an enemy.
Owner:FUDAN UNIVERSITY

System and method for implementing secure communications for internet of things (IoT) devices

Novel tools and techniques might provide for implementing secure communications for IoT devices. In various embodiments, a gateway or computing device might provide connectivity between or amongst two or more Internet of Things (“IoT”) capable devices, by establishing an IoT protocol-based, autonomous machine-to-machine communication channel amongst the two or more IoT capable devices. For sensitive and / or private communications, the gateway or computing device might establish a secure off-the-record (“OTR”) communication session within the IoT protocol-based, autonomous machine-to-machine channel, thereby providing encrypted machine-to-machine communications amongst the two or more IoT capable devices, without any content of communications that are exchanged amongst the IoT capable devices over the secure OTR communication session being recorded or logged. In some cases, the secure OTR communication session utilizes cryptographic protocols including, without limitation, one or more of AES symmetric-key algorithm, Diffie-Hellman key exchange, SHA-1 hash function, forward secrecy, deniable authentication, malleable encryption, and / or the like.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

Hybrid authentication handshake method fusing anti-quantum algorithm and national cryptographic protocol

The application relates to the technical field of anti-quantum computing, in particular to a mixed authentication handshake method fusing an anti-quantum algorithm and a national secret protocol, acquiring a national secret and an anti-quantum path key segment, extracting a number and a source to write a handshake structure, completing position comparison and chain numbering, adjusting segment positions in the structure and synchronizing fields, executing number checking and data block shifting, promoting content insertion and frame structure updating, and completing the mixed authentication handshake structure. The application marks key segment numbers, sources and stages, binds writing paths in combination with positions and promotion data, introduces chain numbering to control segment sequences in combination with source comparison, adjusts segment distribution in combination with position exchange and field synchronization, enhances structure scheduling capability, processes conflicts and overlaps in combination with number checking and data block shifting, promotes parallel insertion in combination with a handshake identifier written in a channel, and improves structure consistency and data bearing integrity.
Owner:GUANGXI POWER GRID CORP

Electronic signature system and method based on commercial cryptographic technology and storage medium

The application discloses an electronic signing system and method based on commercial cryptographic technology and a storage medium, and particularly relates to the field of distributed storage security technology. The electronic contract signing request is initiated at a first signing node, and the signing data is encrypted using a commercial cryptographic algorithm, and then the encrypted data is distributed to multiple signing nodes using the security channel of the commercial cryptographic protocol. After receiving the signing request, each signing node verifies the signing data and the key state using a distributed consistency algorithm, generates a local signature after verification, and aggregates the local signature to form a final signature result. A fuzzy logic-based analytic hierarchy model and a time series decomposition model are used to analyze the path and response consistency of the signing nodes to determine the credibility of the signature result. When the result is credible, the signed electronic contract is stored in a distributed ledger, and if the result is not credible, a re-verification mechanism is triggered to ensure the security and consistency of the signing data.
Owner:HENAN RONGCHUANGHE TECH CO LTD

Time series data transaction privacy protection method based on quality spot check and identity verification

The invention provides a time series data transaction privacy protection method based on quality spot check and identity verification. The method comprises the following steps: carrying out adaptive partitioning on original time series data of a seller; adding trace noise, and selecting a block to embed a spread spectrum watermark; encrypting the data block and the watermark key; the buyer randomly checks the specified block based on the metadata, the platform verifies the noise consistency through inverse element subtraction, and the transaction is completed if both the buyer and the platform confirm that the noise consistency is correct. According to the method, the attention mechanism is utilized to dynamically block the original data in real time, so that redundancy is reduced, and the processing efficiency is improved; server behaviors are constrained through a cryptographic protocol, the balance of privacy, efficiency and supervision is realized, and whether data are from illegal resale can be verified without decrypting plaintexts through watermark tampering prevention and micro-noise original-sample multiplexing prevention.
Owner:湖南工商大学

Verification method and system for anti-quantum cryptography hybrid programming language program

The invention relates to an anti-quantum cryptography hybrid programming language program verification method and an anti-quantum cryptography hybrid programming language program verification system. The method comprises the following steps: inputting a password protocol program to be verified in Rocq based on a hybrid programming language; subprograms in the cryptographic protocol program are modeled in a formalized mode through a module system, and classic program behaviors and quantum program behaviors in the cryptographic protocol program are described based on a unified grammar framework of a hybrid programming language; performing type checking and grammar checking on a program written based on a unified grammar framework and a module system; generating semantics of the program according to grammar for the program passing the check; protocol properties needing to be proved are described in a formalized mode according to grammar; establishing an inference rule based on program rewriting on the basis of grammar; and carrying out interactive certification on the formally described protocol property in the Rocq by using a certification strategy of the Rocq. According to the method, the security of the complex password protocol can be completely and accurately described and automatically verified, and the verification reliability and efficiency are remarkably improved.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Transaction management method, medium and apparatus for transaction message-based password protocol

The application provides a transaction management method, medium and device of a password protocol based on transaction messages, the method comprising: using an application system of a password protocol and a message middleware, executing the password protocol in the application system, steps A and B of the password protocol having transaction characteristics, and the transaction characteristics of both parties being guaranteed by transaction messages of the message middleware; wherein the application system records transaction information of each execution by establishing a transaction table, and different transactions are distinguished by a transaction ID field in the transaction table. The application can solve the data consistency problem between password protocol steps having distributed transaction characteristics or between two password protocols.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Efficient homomorphic calculation method for neural network privacy reasoning

The invention provides an efficient homomorphic calculation method for neural network privacy reasoning, and belongs to the technical field of cryptographic protocol design in privacy calculation. Through collaborative design of input channel coding in the first step, weight preprocessing in the second step, small-step self-isomorphism in the third step, plaintext and ciphertext multiply-accumulation in the fourth step and large-step self-isomorphism and accumulation in the fifth step, the number of output ciphertexts is remarkably reduced by utilizing the characteristics of self-isomorphism, so that the communication overhead is reduced, efficient communication is realized, and the communication efficiency is improved. And the method has a wide application scene.
Owner:PEKING UNIV

Resource awareness-oriented satellite-ground hybrid cryptographic protocol negotiation method

The invention provides a resource awareness-oriented satellite-ground hybrid cryptographic protocol negotiation method. The method comprises the following steps: when a communication initiator and a communication responder initiate a secure communication connection, mutually exchanging respective negotiation parameter information; the negotiation parameter information comprises cryptographic algorithm support information and real-time resource state information; the cryptographic algorithm support information is a cryptographic algorithm supported by the communication initiator / the communication responder; the communication initiator and the communication responder respectively determine a suggested cryptographic protocol mode locally based on a cryptographic algorithm supported by both parties and real-time resource state information of the communication initiator and the communication responder; the communication initiator and the communication responder exchange respective suggested cryptographic protocol modes with each other, and compare the locally determined suggested cryptographic protocol mode with the received suggested cryptographic protocol mode; and if the comparison result is consistent, establishing a secure communication connection between the communication initiator and the communication responder based on the suggested cryptographic protocol mode.
Owner:SPACE STAR TECH CO LTD

Mobile terminal APP national password HTTPS data transmission method and device, equipment and medium

The invention provides a national password HTTPS data transmission method and device of a mobile terminal APP, equipment and a medium, and is applied to the fields of finance and medical treatment. The method provided by the invention comprises the following steps: after deployment of a signature certificate supporting a national cryptographic algorithm and an encryption certificate supporting an RSA algorithm in a server is completed, introducing a national cryptographic protocol into a mobile terminal APP, loading a national cryptographic trust library, starting an HTTP client, and creating an HTTP client response, so that a protocol layer of the mobile terminal APP supports the national cryptographic protocol; embedding a national cryptographic algorithm in the mobile terminal APP, and introducing a national cryptographic root certificate in the mobile terminal APP, so as to preset the national cryptographic root certificate in the mobile terminal APP; and enabling the mobile terminal APP to send an HTTPS data transmission request to the server, carrying out handshake according to the signature certificate and the encryption certificate, and carrying out HTTPS data transmission after handshake is completed according to the signature certificate and the encryption certificate. According to the method provided by the invention, the national password HTTPS data transmission can be well realized on the mobile terminal APP, and the confidentiality and integrity of the national password HTTPS data transmission can be improved.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD

Device and method for generating locally verifiable aggregate signatures for the generation of attestations in a VNF-FG architecture platform

A method for signing a message mi, by a user device, from a zero-knowledge proof cryptographic protocol defined by an element g belonging to a group G1 of order p, with p designating a prime integer, and elements u, v, r, s, t belonging to a group G2, a hash function H and a current time period w. The method includes: a generating a pair of private and public keys, the private key including an element αi selected from the ring Z / pZ, the public key including a first element and a second element being a zero-knowledge proof of possession generated from the cryptographic protocol; and generating a signature σi of the message mi from the private key and a random variable 6, the signature including a first element σ1i and a second element σ2i.
Owner:ORANGE SA

Packet transfer

Interrelated computing devices and systems require ever more powerful devices to meet growing encryption demands. This is improved by providing a computer-implemented method comprising: receiving a packet (50) from a user equipment (10) through an access network (20) of a telecommunications network (1), the packet (50) having a subscriber identity of said user equipment (10) and a telecom encryption layer (52) compliant with cryptographic protocols of the telecommunications network (1); decrypting the telecom encryption layer (52) of said packet (50) according to protocols of said telecommunications network (1) using said subscriber identity in a network core (30) of said telecommunication network (1); finding a predetermined action stored in an action database (31) of said network core (30) pre-associated with said subscriber identity of said packet (50); and performing said predetermined action on said packet (50) in said network core (30).
Owner:ONOMONDO APS

Secure channel establishment

ActiveUS12719663B2Cryptographic protocolTerminal equipment
There is provided a computer-implemented method for establishing a communication channel for exchanging messages securely between an initiator device and an endpoint device using an intermediary server. The initiator device is in communication with the intermediary server via a first session encrypted according to a cryptographic protocol. The endpoint device is in communication with the intermediary server via a second session encrypted according to a cryptographic protocol. A request for a handover token via the first session is sent to intermediary server. The handover token includes data that has been generated at the endpoint device and is configured to be used in setting up the communication channel between the initiator device and the endpoint device. The handover token is received from the intermediary server via the first session encrypted according to a cryptographic protocol. The communication channel is established between the initiator device and the endpoint device.
Owner:MASTERCARD INT INC

Device and method for generating a blind signature of a message

Device and method for generating a blind signature of a message. Method for generating a blind signature of a message from a cryptographic protocol implemented in a Euclidean network comprising a public key formed of at least one matrix A composed of elements of a set and a secret key linked to the public key known exclusively to a signing entity, said method comprising: generation of a first vector r of the ring; determination of a second vector c equal to Ar +f(m); generation of a third vector s of the ring by the signing entity such that c= A.s, with s respecting at least one constraint relative to its norm; generation of the intermediate signature comprising an aggregation vector resulting from a combination of the first and third vectors; decomposition of the aggregation vector into a first part and a second part; generation of a blind signature composed of said first part and a proof of knowledge of the matrix and said second part. Fig. 1.
Owner:ORANGE SA

Acceleration of cryptographic operations

A circuit arrangement includes a plurality of cryptographic accelerators. Each cryptographic accelerator is configured to perform cryptographic operations according to a respective cryptographic protocol. A first memory is coupled to the cryptographic accelerators. A first processor is configured to specify, in response to requests to perform the cryptographic operations, parameters to the cryptographic accelerators according to the requests. The first processor is configured to identify, in the first memory, keys that are associated with the cryptographic accelerators, and signal the cryptographic accelerators to commence performing the cryptographic operations according to the parameters and using the associated keys.
Owner:XILINX INC