Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

34 results about "Cryptographic protocol" patented technology

A security protocol (cryptographic protocol or encryption protocol) is an abstract or concrete protocol that performs a security-related function and applies cryptographic methods, often as sequences of cryptographic primitives. A protocol describes how the algorithms should be used. A sufficiently detailed protocol includes details about data structures and representations, at which point it can be used to implement multiple, interoperable versions of a program.

Methods and Systems for Privacy-Preserving Location Verification

A computer-implemented method and system for privacy-preserving location verification in distributed networks comprises initializing a multi-modal biometric authentication system on a user device, generating cryptographic keys using a distributed key generation protocol, binding the cryptographic keys to biometric templates using a fuzzy vault scheme, constructing and broadcasting encrypted location beacons, and generating zero-knowledge proofs of location claims. The system includes user devices equipped with biometric sensors and verifier devices configured to validate location claims and maintain consensus in a blockchain network. The method implements real-time liveness detection for multiple biometric input types, executes fault-tolerant consensus algorithms with privacy preservation, and maintains a dual-scoring mechanism comprising device trust scores and user reputation scores. The system enables secure location verification while preserving user privacy through cryptographic protocols and biometric authentication in decentralized environments.
Owner:ABDELSAMIE MAHER A

Internet of Things test platform adaptation method, system and device based on post quantum cryptography

The invention discloses an Internet of Things test platform adaptation method, system and device based on post quantum cryptography. The method comprises the following steps: constructing a quantum threat perception model; establishing a multi-dimensional adaptive decision matrix, and generating a candidate post-quantum cryptography algorithm set; dynamic injection of a cryptographic protocol is executed, and lossless replacement of a communication layer encryption suite is achieved; deploying a runtime performance monitoring engine, and collecting encryption and decryption delay, memory occupancy rate and electromagnetic radiation characteristic data in real time; and constructing an algorithm switching decision tree based on reinforcement learning, and when a quantum attack feature or an equipment performance threshold is detected to break through, triggering cryptographic algorithm dynamic migration. A quantum threat perception driven Internet of Things security adaptation system is constructed, and by introducing a dynamic password switching mechanism, a hardware acceleration optimization scheme and a trusted execution environment, the security upgrading problem of traditional Internet of Things equipment in the post-quantum era is solved. According to the invention, the execution efficiency of the PQC algorithm of the resource-constrained equipment can be improved, and the key updating delay is reduced.
Owner:HANGZHOU YUNXIANG NETWORK TECH

Cryptographic algorithm and protocol test system

The invention discloses a cryptographic algorithm and protocol test system, the system is configured into two deployment modes: a transparent mode and a man-in-the-middle mode, the transparent mode can hide an IP or MAC address of a device, and certificate and algorithm information in a cryptographic protocol is identified and analyzed through a passive traffic analysis mode; the man-in-the-middle mode provides a dynamic packet changing function, realizes a dynamic interaction function with a server in an agent mode, can be used for application scenarios such as identity authentication, data encryption and decryption, protocol vulnerability analysis and performance test, can effectively improve the evaluation integrity and accuracy of a cryptographic algorithm and a cryptographic protocol, forms a complete and accurate test evaluation evidence chain, and improves the evaluation efficiency of the cryptographic algorithm and the cryptographic protocol. And the detection evaluation result is effectively supported. The system can be accessed to a production network to capture, identify and analyze network traffic, so that an international / national cryptographic algorithm and protocol security analysis function is realized, and verification and analysis on compliance, correctness, effectiveness and the like of password application in an important network and information system can be realized.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

Distributed private data security aggregation method based on federal learning

The invention relates to the technical field of data security, in particular to a federated learning-based distributed privacy data security aggregation method, which comprises the following steps of: acquiring multi-source heterogeneous data of a leaf supplier node; performing weighted fusion on the multi-source heterogeneous data by using the multi-modal fusion model to generate a health state vector; training by using the health state vector in combination with a blade X-ray defect data set to obtain a local model; calculating a leakage risk score, and performing privacy processing on the local model through a differential privacy mechanism to obtain a noise adding model; calculating the reference data set by using a noise adding model to obtain a performance score, and generating an encryption proof for a calculation process; and the central server receives the zk-SNARK encryption proof submitted by all the nodes, converts the performance score into an aggregation weight, initiates a secure multi-party computing protocol, and performs weighted calculation on the noise adding model by using the aggregation weight to generate a global model. According to the method, multi-party safe and credible collaborative modeling is realized by fusing multiple cryptographic protocols.
Owner:SUZHOU GUANGCHI INFORMATION TECHNOLOGY CO LTD

Agile cryptographic deployment service

Embodiments are directed to methods and systems for crypto-agile encryption and decryption. A computer system can possess a protocol file that identifies one or more cryptographic software modules. Using these cryptographic software modules, the computer system can generate a plurality of shared secrets and a session key, then use the session key to encrypt a message. The message can be sent to a server computer that can subsequently decrypt the message. At a later time, the protocol file can be updated to identify a different set of cryptographic software modules, which can be used to encrypt messages. Further, the server computer can transmit additional cryptographic software modules to the computer system, enabling the computer system to use those cryptographic software modules to generate cryptographic keys. As such, the cryptographic protocol file can be changed in response to changes in the cryptographic needs of the computer system.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

A system for quantum-safe routing via dynamic crypto-switching in the WAN / SD-WAN

ActiveDE202025102839U1Cryptographic attack countermeasuresCryptographic protocolAdaptive routing
A system (100) for quantum-resistant routing via dynamic cryptographic switching in a WAN or SD-WAN environment, the system comprising: (a) a threat intelligence and crypto resilience assessment module configured to monitor cyber threats in real time and assess the security level of active cryptographic protocols; (b) a Dynamic Crypto Switching Module operatively connected to the assessment module and configured to automatically switch between classical cryptographic algorithms and post-quantum cryptographic algorithms based on the assessed threat levels; c) an SD-WAN policy integration and orchestration module configured to enforce organizational policies related to security, compliance, and performance to control cryptographic transitions; (d) an adaptive routing and path selection module configured to select network paths based on real-time security assessments and cryptographic strength; (e) a cryptographic compatibility and interoperability layer configured to manage encryption protocol handshakes and fallback mechanisms and to support communication between classical and post-quantum-enabled endpoints; f) and an audit, compliance and analytics dashboard configured to log cryptographic transitions, generate compliance reports and provide real-time visibility into system operations; g) whereby the system dynamically adapts encryption protocols and routing paths in response to evolving quantum and classical cybersecurity threats, thereby ensuring secure, continuous and compliant data transmission over WAN or SD-WAN networks.
Owner:KASHIV DIPESH JAGDISH FREMONT

Identity-based signature method supporting multi-message aggregation

The invention discloses an identity-based signature method supporting multi-message aggregation. The identity-based signature method comprises the steps of system initialization and key generation, user signature key generation, message signature construction, single signature verification, signature aggregation and aggregation signature verification. Due to the fact that the linear homomorphic signature technology is adopted, the identity-based aggregation signature method is provided, and the technical problems of signature after aggregation, key size expansion and the like in the existing aggregation signature technology are solved. Through the method, a verifier can safely and efficiently merge a plurality of signatures into a signature with a compact size, efficient data source authentication can be realized while the data integrity is guaranteed, and the verification efficiency is remarkably improved. The method has the advantages of high security, low communication cost, small calculation overhead and the like, can be applied to the technical fields of large-scale data authentication, distributed system security, lightweight cryptographic protocols and the like, and is particularly suitable for mobile terminals or Internet of Things equipment scenes with limited calculation resources.
Owner:SHAANXI NORMAL UNIV

A method and apparatus for customizing a cryptographic protocol cluster

The embodiment of the application discloses a self-defined encryption protocol clustering method and device, the method comprises the following steps: obtaining a target encryption protocol to be identified, and extracting traffic data and metadata of the target encryption protocol; constructing a label matrix and a value matrix based on the traffic data; and fusing the label matrix and the value matrix by using a multi-mode matching algorithm to obtain a clustering label. In this way, the self-defined encryption protocol clustering method provided by the application combines double-matrix combination with a pattern matching algorithm to realize clustering of self-defined encryption protocols. The method solves the problem that mixed self-defined protocols cannot be quickly and accurately clustered, and provides support for subsequent protocol analysis by quickly and accurately realizing clustering of self-defined protocols.
Owner:VIEWINTECH

Large language model driven password protocol automatic formalization modeling method and system

PendingCN122433679ALinguistic modelPassword
The present application belongs to the technical field of network security and artificial intelligence, and provides a large language model driven password protocol automatic formalization modeling method and system, acquires a natural language protocol specification document, and performs preprocessing; according to the priority order of a message block, a verification block and a calculation statement, a large language model extracts corresponding semi-structured intermediate representations from text blocks; all intermediate representation statements are scanned at one time by using the large language model, protocol functions and symbols are identified and stored in a knowledge base, the large language model is driven in units of intermediate representation statements to be refined one by one, and global context and local context are extracted; the completely structured intermediate representations, a protocol role set and the updated knowledge base are taken as inputs to perform deterministic one-to-one mapping with formal verification tool code, and conversion is completed. The present application can automatically generate symbol model code which can be directly input into a formal verification tool.
Owner:SHANDONG UNIV

Acceleration of cryptographic operations

A circuit arrangement includes a plurality of cryptographic accelerators. Each cryptographic accelerator is configured to perform cryptographic operations according to a respective cryptographic protocol. A first memory is coupled to the cryptographic accelerators. A first processor is configured to specify, in response to requests to perform the cryptographic operations, parameters to the cryptographic accelerators according to the requests. The first processor is configured to identify, in the first memory, keys that are associated with the cryptographic accelerators, and signal the cryptographic accelerators to commence performing the cryptographic operations according to the parameters and using the associated keys.
Owner:XILINX INC

Password definition security architecture and rule execution method

The invention relates to the technical field of network information security, in particular to a password definition security architecture and a rule execution method, the architecture comprises a device plane, a security plane, a computing plane, a network plane, a data plane, a rule plane and an application plane, and each plane realizes execution of security rules in a password protocol mode. The rule execution method of the password definition security architecture comprises the following steps: after an information system is initialized, planning a routing path, authenticating password definition security equipment on the path, establishing a security access channel by adjacent equipment to ensure the routing security of data on the path, and then packaging each packet of data based on a service data identifier to obtain a password definition security architecture; according to the method, service slicing and protocol filtering based on the authorization credential are realized, and then safe forwarding is performed according to a routing path specified by the authorization credential, so that covert channels and illegal external connection are prevented, and the safety of the whole access request session depends on the safety rule of the authorization credential. According to the invention, the security and compliance of the business data in the circulation process can be ensured.
Owner:ZHENGZHOU XINDA YUNGU TECH CO LTD

A control method of a multi-protocol switching quantum security-resistant gateway

This application relates to a control method for a multi-protocol switching quantum-resistant security gateway. The method includes, after the security gateway powers on, performing a hardware environment security self-test and generating a unique root key based on a physically non-cloning function; continuously collecting and analyzing network traffic characteristics; identifying quantum attack patterns and dynamically deciding on encryption algorithm modes based on a machine learning model; parsing communication data packets; dynamically converting and adapting between traditional and quantum-resistant cryptographic protocols according to instructions and preset rules; calling a quantum-resistant cryptographic engine for encryption or signature operations; dynamically deriving and managing session keys throughout their lifecycle based on the root key; and, based on quantum attack detection results, switching algorithm modes, communication protocols, and keys in a coordinated manner, while also enabling side-channel attack protection and hardware security response. This method achieves proactive protection against quantum attacks, seamless multi-protocol compatibility, and full lifecycle security management of keys for the security gateway.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Password defines security architecture and rule execution method

The present application relates to the technical field of network information security, and particularly relates to a password definition security architecture and a rule execution method, the architecture comprising a device plane, a security plane, a calculation plane, a network plane, a data plane, a rule plane and an application plane, each plane implementing execution of a security rule through a password protocol mode. The rule execution method of the password definition security architecture comprises, after initialization of an information system, planning a routing path, authenticating password definition security devices on the path, establishing a secure access channel between adjacent devices to guarantee routing security of data on the path, then encapsulating each packet of data based on business data identification to implement business slicing and protocol filtering based on an authorized credential, then performing secure forwarding according to a routing path specified by the authorized credential to prevent hidden channels and rule violations, and the security of an entire access request session depends on the security rule of the authorized credential. The present application can ensure security and compliance of business data in a flow process.
Owner:ZHENGZHOU XINDA YUNGU TECH CO LTD

A method and system for detecting and warning of cryptographic protocol anomalies

PendingCN122137619ASecuring communicationHigh level techniquesFeature setCryptographic protocol
This invention provides a method and system for detecting and warning of anomalies in encryption protocols, belonging to the field of network security technology. The method includes: extracting a multimodal feature set from the target encryption protocol communication stream; inputting it in parallel into an adaptive rule engine and an interpretable artificial intelligence model to obtain rule-triggered events and confidence weights, a first anomaly score, and an attribution explanation report, respectively; calculating a second anomaly score based on the above outputs using an improved scoring algorithm; fusing the first and second anomaly scores to obtain a comprehensive anomaly score and generating a warning decision; and uploading the warning information to a federated collaborative node to drive the collaborative evolution of the global rule base and the model. This invention, employing the aforementioned method and system for detecting and warning of anomalies in encryption protocols, solves the collaborative problems of poor interpretability, lagging knowledge updates, and data silos in encryption threat detection through deep collaboration between an interpretable artificial intelligence model and a rule engine, achieving accurate, reliable, and adaptive anomaly warnings.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

A system and a method for distributed data intersection using privacy preserving collaborative detection

A system and method for distributed data intersection using privacy preserving collaborative detection is disclosed The system includes a processor and a memory that causes the processor to verify data sets and configurations from a first and second entity interacting in a distributed data intersection to ensure data integrity and privacy during a data collaboration. The processor enables computations between the first and second entity using cryptographic protocols to identify common data points. The processor allows the first and second entity to retrieve the common data points pertaining to other entity using a oblivious data sharing technique while maintaining confidentiality of the data accessed during the interaction. The processor facilitates validation of data integrity and accuracy without revealing underlying information. The processor controls data-sharing policies ensuring that authorized data is disclosed based on a predefined criteria thereby enabling collaboration of data for re-identification while protecting privacy.
Owner:PRIVASAPIEN TECH PTE LTD

Network telemetry with byte distribution and cryptographic protocol data elements

ActiveUS12719839B2Data packCryptographic protocol
In one embodiment, a method includes receiving a traffic flow including a plurality of packets encrypted using a cryptographic protocol, determining cryptographic protocol data of the traffic flow, and transmitting telemetry data of the traffic flow including the cryptographic protocol data. In another embodiment, a method includes receiving telemetry data of a traffic flow including a plurality of packets encrypted using a cryptographic protocol, the telemetry data including cryptographic protocol data of the traffic flow, classifying the traffic flow based on the cryptographic protocol data using a machine learning classifier; and taking a remedial action with respect to the traffic flow based on the classification of the traffic flow.
Owner:CISCO TECHNOLOGY INC

Anti-quantum enhancement method and device for stock password equipment system

The invention discloses an anti-quantum enhancement method and an anti-quantum enhancement device for a stock password equipment system. On the premise of not changing the hardware architecture of stock classical cryptographic equipment, an anti-quantum cryptographic card or entrance guard type anti-quantum security enhancement equipment is connected with the anti-quantum cryptographic card or entrance guard type anti-quantum security enhancement equipment to provide anti-quantum security enhancement; the stock classical cryptographic equipment system refers to a cryptographic chip, a cryptographic machine, a signature verification machine, a gateway, a software system and the like which are deployed and cannot resist quantum attacks; the anti-quantum cryptographic card is a cryptographic card supporting a classical cryptographic algorithm and an anti-quantum cryptographic algorithm, a classical cryptographic chip, an anti-quantum FPGA chip and other components are arranged on the anti-quantum cryptographic card, and the anti-quantum cryptographic card is connected with stock classical cryptographic equipment through a PCIe interface. The entrance guard type anti-quantum security enhancement equipment is electronic equipment which is deployed between classical cryptographic equipment and a public network and carries out anti-quantum security protection on a Diffie-Hellman type cryptographic protocol, so that a session key cannot be exported even if communication between entrance guard type equipment is acquired by an enemy.
Owner:FUDAN UNIVERSITY

System and method for implementing secure communications for internet of things (IoT) devices

Novel tools and techniques might provide for implementing secure communications for IoT devices. In various embodiments, a gateway or computing device might provide connectivity between or amongst two or more Internet of Things (“IoT”) capable devices, by establishing an IoT protocol-based, autonomous machine-to-machine communication channel amongst the two or more IoT capable devices. For sensitive and / or private communications, the gateway or computing device might establish a secure off-the-record (“OTR”) communication session within the IoT protocol-based, autonomous machine-to-machine channel, thereby providing encrypted machine-to-machine communications amongst the two or more IoT capable devices, without any content of communications that are exchanged amongst the IoT capable devices over the secure OTR communication session being recorded or logged. In some cases, the secure OTR communication session utilizes cryptographic protocols including, without limitation, one or more of AES symmetric-key algorithm, Diffie-Hellman key exchange, SHA-1 hash function, forward secrecy, deniable authentication, malleable encryption, and / or the like.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

VPN Device National Cryptography Testing Method, Device, Electronic Device, Storage Medium

The present application provides a method, device, electronic device, and storage medium for testing a VPN device with national cryptographic algorithms. Among them, the testing method is applied to a testing terminal, and the GMSSL testing tool is pre-installed on the testing terminal. The GMSSL testing tool is used to obtain user login information and simulate a login session based on the user login information. The testing method includes: sending multiple authentication login requests to the VPN device to be tested in a multi-threaded concurrent manner or a multi-process concurrent manner, and maintaining the login session corresponding to each authentication login request; based on the processing results of the VPN device to be tested for the multiple authentication login requests, counting the maximum number of online users of the VPN device to be tested per unit time; calculating the average value of the maximum number of online users obtained from multiple tests; and obtaining a new test value. The present application can be used to simulate and test the usage environment of a VPN device under a real national cryptographic protocol, and then test the VPN device based on the real usage environment of the VPN device, thereby improving the testing accuracy of the VPN device.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Hybrid authentication handshake method fusing anti-quantum algorithm and national cryptographic protocol

The application relates to the technical field of anti-quantum computing, in particular to a mixed authentication handshake method fusing an anti-quantum algorithm and a national secret protocol, acquiring a national secret and an anti-quantum path key segment, extracting a number and a source to write a handshake structure, completing position comparison and chain numbering, adjusting segment positions in the structure and synchronizing fields, executing number checking and data block shifting, promoting content insertion and frame structure updating, and completing the mixed authentication handshake structure. The application marks key segment numbers, sources and stages, binds writing paths in combination with positions and promotion data, introduces chain numbering to control segment sequences in combination with source comparison, adjusts segment distribution in combination with position exchange and field synchronization, enhances structure scheduling capability, processes conflicts and overlaps in combination with number checking and data block shifting, promotes parallel insertion in combination with a handshake identifier written in a channel, and improves structure consistency and data bearing integrity.
Owner:GUANGXI POWER GRID CORP

Electronic signature system and method based on commercial cryptographic technology and storage medium

The application discloses an electronic signing system and method based on commercial cryptographic technology and a storage medium, and particularly relates to the field of distributed storage security technology. The electronic contract signing request is initiated at a first signing node, and the signing data is encrypted using a commercial cryptographic algorithm, and then the encrypted data is distributed to multiple signing nodes using the security channel of the commercial cryptographic protocol. After receiving the signing request, each signing node verifies the signing data and the key state using a distributed consistency algorithm, generates a local signature after verification, and aggregates the local signature to form a final signature result. A fuzzy logic-based analytic hierarchy model and a time series decomposition model are used to analyze the path and response consistency of the signing nodes to determine the credibility of the signature result. When the result is credible, the signed electronic contract is stored in a distributed ledger, and if the result is not credible, a re-verification mechanism is triggered to ensure the security and consistency of the signing data.
Owner:HENAN RONGCHUANGHE TECH CO LTD

Time series data transaction privacy protection method based on quality spot check and identity verification

The invention provides a time series data transaction privacy protection method based on quality spot check and identity verification. The method comprises the following steps: carrying out adaptive partitioning on original time series data of a seller; adding trace noise, and selecting a block to embed a spread spectrum watermark; encrypting the data block and the watermark key; the buyer randomly checks the specified block based on the metadata, the platform verifies the noise consistency through inverse element subtraction, and the transaction is completed if both the buyer and the platform confirm that the noise consistency is correct. According to the method, the attention mechanism is utilized to dynamically block the original data in real time, so that redundancy is reduced, and the processing efficiency is improved; server behaviors are constrained through a cryptographic protocol, the balance of privacy, efficiency and supervision is realized, and whether data are from illegal resale can be verified without decrypting plaintexts through watermark tampering prevention and micro-noise original-sample multiplexing prevention.
Owner:湖南工商大学

Verification method and system for anti-quantum cryptography hybrid programming language program

The invention relates to an anti-quantum cryptography hybrid programming language program verification method and an anti-quantum cryptography hybrid programming language program verification system. The method comprises the following steps: inputting a password protocol program to be verified in Rocq based on a hybrid programming language; subprograms in the cryptographic protocol program are modeled in a formalized mode through a module system, and classic program behaviors and quantum program behaviors in the cryptographic protocol program are described based on a unified grammar framework of a hybrid programming language; performing type checking and grammar checking on a program written based on a unified grammar framework and a module system; generating semantics of the program according to grammar for the program passing the check; protocol properties needing to be proved are described in a formalized mode according to grammar; establishing an inference rule based on program rewriting on the basis of grammar; and carrying out interactive certification on the formally described protocol property in the Rocq by using a certification strategy of the Rocq. According to the method, the security of the complex password protocol can be completely and accurately described and automatically verified, and the verification reliability and efficiency are remarkably improved.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Transaction management method, medium and apparatus for transaction message-based password protocol

The application provides a transaction management method, medium and device of a password protocol based on transaction messages, the method comprising: using an application system of a password protocol and a message middleware, executing the password protocol in the application system, steps A and B of the password protocol having transaction characteristics, and the transaction characteristics of both parties being guaranteed by transaction messages of the message middleware; wherein the application system records transaction information of each execution by establishing a transaction table, and different transactions are distinguished by a transaction ID field in the transaction table. The application can solve the data consistency problem between password protocol steps having distributed transaction characteristics or between two password protocols.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Efficient homomorphic calculation method for neural network privacy reasoning

The invention provides an efficient homomorphic calculation method for neural network privacy reasoning, and belongs to the technical field of cryptographic protocol design in privacy calculation. Through collaborative design of input channel coding in the first step, weight preprocessing in the second step, small-step self-isomorphism in the third step, plaintext and ciphertext multiply-accumulation in the fourth step and large-step self-isomorphism and accumulation in the fifth step, the number of output ciphertexts is remarkably reduced by utilizing the characteristics of self-isomorphism, so that the communication overhead is reduced, efficient communication is realized, and the communication efficiency is improved. And the method has a wide application scene.
Owner:PEKING UNIV

Penetration testing method and device and storage medium

The invention relates to a penetration test method and device and a storage medium, and the method comprises the steps: obtaining the cryptographic algorithm encryption data obtained through the encryption of the cryptographic protocol flow data, and obtaining an opposite-end public key, and the opposite end is a tested system; calculating a home terminal private key according to a preset elliptic curve parameter, and obtaining a shared secret based on the home terminal private key and the opposite terminal public key; performing key derivation processing on the shared secret to generate a target key, and decrypting the national secret algorithm encrypted data based on the target key to obtain decrypted data; performing recombination analysis processing on the decrypted data to obtain application layer analysis data; and analyzing the data according to the application layer, generating an attack load, and performing an attack test on the tested system by using the attack load to obtain a test result. According to the invention, the problems of low test efficiency and high false alarm rate are solved.
Owner:HANGZHOU ZHONGER NETWORK TECH CO LTD

Resource awareness-oriented satellite-ground hybrid cryptographic protocol negotiation method

The invention provides a resource awareness-oriented satellite-ground hybrid cryptographic protocol negotiation method. The method comprises the following steps: when a communication initiator and a communication responder initiate a secure communication connection, mutually exchanging respective negotiation parameter information; the negotiation parameter information comprises cryptographic algorithm support information and real-time resource state information; the cryptographic algorithm support information is a cryptographic algorithm supported by the communication initiator / the communication responder; the communication initiator and the communication responder respectively determine a suggested cryptographic protocol mode locally based on a cryptographic algorithm supported by both parties and real-time resource state information of the communication initiator and the communication responder; the communication initiator and the communication responder exchange respective suggested cryptographic protocol modes with each other, and compare the locally determined suggested cryptographic protocol mode with the received suggested cryptographic protocol mode; and if the comparison result is consistent, establishing a secure communication connection between the communication initiator and the communication responder based on the suggested cryptographic protocol mode.
Owner:SPACE STAR TECH CO LTD

Mobile terminal APP national password HTTPS data transmission method and device, equipment and medium

The invention provides a national password HTTPS data transmission method and device of a mobile terminal APP, equipment and a medium, and is applied to the fields of finance and medical treatment. The method provided by the invention comprises the following steps: after deployment of a signature certificate supporting a national cryptographic algorithm and an encryption certificate supporting an RSA algorithm in a server is completed, introducing a national cryptographic protocol into a mobile terminal APP, loading a national cryptographic trust library, starting an HTTP client, and creating an HTTP client response, so that a protocol layer of the mobile terminal APP supports the national cryptographic protocol; embedding a national cryptographic algorithm in the mobile terminal APP, and introducing a national cryptographic root certificate in the mobile terminal APP, so as to preset the national cryptographic root certificate in the mobile terminal APP; and enabling the mobile terminal APP to send an HTTPS data transmission request to the server, carrying out handshake according to the signature certificate and the encryption certificate, and carrying out HTTPS data transmission after handshake is completed according to the signature certificate and the encryption certificate. According to the method provided by the invention, the national password HTTPS data transmission can be well realized on the mobile terminal APP, and the confidentiality and integrity of the national password HTTPS data transmission can be improved.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD

Device and method for generating locally verifiable aggregate signatures for the generation of attestations in a VNF-FG architecture platform

A method for signing a message mi, by a user device, from a zero-knowledge proof cryptographic protocol defined by an element g belonging to a group G1 of order p, with p designating a prime integer, and elements u, v, r, s, t belonging to a group G2, a hash function H and a current time period w. The method includes: a generating a pair of private and public keys, the private key including an element αi selected from the ring Z / pZ, the public key including a first element and a second element being a zero-knowledge proof of possession generated from the cryptographic protocol; and generating a signature σi of the message mi from the private key and a random variable 6, the signature including a first element σ1i and a second element σ2i.
Owner:ORANGE SA

Packet transfer

Interrelated computing devices and systems require ever more powerful devices to meet growing encryption demands. This is improved by providing a computer-implemented method comprising: receiving a packet (50) from a user equipment (10) through an access network (20) of a telecommunications network (1), the packet (50) having a subscriber identity of said user equipment (10) and a telecom encryption layer (52) compliant with cryptographic protocols of the telecommunications network (1); decrypting the telecom encryption layer (52) of said packet (50) according to protocols of said telecommunications network (1) using said subscriber identity in a network core (30) of said telecommunication network (1); finding a predetermined action stored in an action database (31) of said network core (30) pre-associated with said subscriber identity of said packet (50); and performing said predetermined action on said packet (50) in said network core (30).
Owner:ONOMONDO APS