Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

185 results about "Cryptography" patented technology

Cryptography or cryptology (from Ancient Greek: κρυπτός, romanized: kryptós "hidden, secret"; and γράφειν graphein, "to write", or -λογία -logia, "study", respectively) is the practice and study of techniques for secure communication in the presence of third parties called adversaries. More generally, cryptography is about constructing and analyzing protocols that prevent third parties or the public from reading private messages; various aspects in information security such as data confidentiality, data integrity, authentication, and non-repudiation are central to modern cryptography. Modern cryptography exists at the intersection of the disciplines of mathematics, computer science, electrical engineering, communication science, and physics. Applications of cryptography include electronic commerce, chip-based payment cards, digital currencies, computer passwords, and military communications.

Anti-quantum method and system based on stateless signature and execution isomorphism

This invention discloses a quantum-resistant method and system based on stateless signatures and execution isomorphism, belonging to the field of quantum-resistant cryptography. First, the sender generates an mKEM broadcast payload based on a modulus error rounding algorithm and signs it using a stateless hash signature algorithm. The receiver performs microsecond-level verification of the signature at the network card driver layer; if verification fails, the signature is silently discarded. After successful verification, a dedicated PQC hardware engine decapsulates the signature, implicitly outputting a pseudo-random scrap key if verification fails. The operating system executes an I / O-aware microarchitecture with isomorphic execution, forcing subsequent processes to maintain physical isomorphism in system calls, memory accesses, and peripheral bus activities, regardless of whether the key is real or scrap. This invention eliminates the risk of private key leakage caused by cloud-based state management through stateless signatures and completely eliminates distinguishable side-channel fingerprints across the entire link through physical-level execution isomorphism, achieving system-level quantum-resistant security in high-concurrency scenarios.
Owner:BEIJING LANGKONG QUANTUM TECHNOLOGY CO LTD

An outsourcing encrypted database system and method based on a TEE server supporting a secure aggregation operation and a secure query operation

The application discloses an outsourcing encrypted database system and method based on a TEE server supporting a secure aggregation operation and a secure query operation. The system comprises a client and a cloud server configured with a rich execution environment (REE) and a trusted execution environment (TEE). The client generates a key pair, and adopts a Paillier threshold encryption strategy to split the private key into two shards, which are respectively sent to the REE and the TEE, and the data encrypted by the public key is stored in the REE. When responding to a query or aggregation instruction, the REE and the TEE cooperatively execute a cryptography operation protocol by using the private key shards held by each other through a hardware isolation mechanism. In order to further improve the processing efficiency, the application also introduces amortization optimization technology, which uses the property of homomorphic encryption to package multiple independent comparison tasks into a ciphertext for one-time joint decryption, thereby significantly reducing the calculation overhead and communication bandwidth.
Owner:GUANGZHOU RES INST OF XIAN UNIV OF ELECTRONIC SCI & TECH

Vehicle security starting method and system based on post-quantum cryptography

The application provides a vehicle security starting method and system based on post-quantum cryptography, and relates to the technical fields of vehicle electronic control and vehicle network security. The method is applied to an ECU of a vehicle, the ECU is pre-stored with public key information based on a post-quantum cryptographic algorithm and stores an image package containing a post-quantum cryptographic digital signature; the method comprises the following steps: in response to the power-on of the ECU, loading the image package, separating original image data and the digital signature therefrom; determining a cryptographic hash value of the original image data; based on the public key information, performing a signature verification operation of the post-quantum cryptographic algorithm on the hash value and the digital signature; and controlling the starting process of the ECU according to the result of the signature verification operation. The application reconstructs the trust chain of the vehicle by using the post-quantum cryptographic algorithm, and implements quantum security signature verification at the vehicle end, which effectively ensures that the software integrity and authenticity can still be effectively verified under the quantum computing environment, thereby providing full-life-cycle security protection for intelligent networked vehicles.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

Merkle tree integrity protection for stateful hash-based cryptography

A method for verifying the integrity of a binary tree graph structure having "h" layers and a plurality of nodes configured to provide public keys, the method comprising: verifying the integrity of a stored root hash value associated with a root node; obtaining non-root nodes among the plurality of nodes, the "h" layers including leaf layers, and the leaf layers including a plurality of leaf nodes associated with a plurality of one-time signature public keys; obtaining an authentication path associated with the non-root node, the authentication path including other nodes; performing multiple pairwise hash calculations on the non-root node and the other nodes to generate candidate root hash values; comparing the candidate root hash values ​​with the stored root hash values; and determining that the integrity of the binary tree graph passes verification when the candidate root value equals the stored root value.
Owner:NXP BV

Attribute-based searchable encryption method against keyword-guessing attack based on sm9

This invention provides an attribute-based searchable encryption method based on SM9 to resist keyword guessing attacks. It aims to address the security flaws of existing solutions, which are vulnerable to server-side keyword guessing attacks during encrypted retrieval. By cryptographically binding and randomizing user identity identifiers, attribute sets, and keywords, a complete encryption, retrieval, and verification mechanism is constructed. Its core lies in reconstructing the security trapdoor generation and verification process using the SM9 algorithm, preventing the server from offline enumerating and guessing keywords without proper attribute permission verification. This achieves secure, controllable, and efficient encrypted retrieval while ensuring data confidentiality and user privacy, meeting the urgent needs of smart grids for secure and autonomously controllable data sharing technologies.
Owner:GUILIN UNIV OF ELECTRONIC TECH +1

A graphics card hardware security detection method and device based on a blockchain and a medium

PendingCN122263076AImplement trusted anchoringImplement dynamic verificationHardware monitoringDigital data authenticationDigital identityGraphics
The application discloses a graphics card hardware security detection method and device based on a blockchain, and a medium, relates to the technical field of security detection, and comprises the following steps: extracting a hardware fingerprint of a graphics card hardware through a physically unclonable function, and outputting a graphics card private key and a graphics card public key; performing cryptographic binding on a graphics card public key, a graphics card serial number and production information, performing a blockchain transaction chaining operation on a bound data block, and outputting a graphics card digital identity certificate; submitting the graphics card digital identity certificate to the blockchain, verifying and challenging the graphics card hardware through the blockchain, binding the certificate, and outputting cryptographic challenge data; digitally signing the cryptographic challenge data by using the graphics card private key, and outputting digital signature data; performing cryptographic verification and matching on the digital signature data and the graphics card public key stored in the blockchain, and outputting a graphics card hardware security detection result. The application realizes trusted anchoring and dynamic verification of the graphics card hardware identity through the cooperation of the hardware fingerprint extraction and the blockchain verification double mechanisms.
Owner:SICHUAN PINDUOHUI TECHNOLOGY CO LTD

An encryption method based on registration keyword strategy hiding

This invention provides a searchable encryption method based on registered keywords and with hidden policies, belonging to the field of cryptography and information security technology. It solves the risks of key escrow and keyword privacy leakage in existing attribute-based search encryption schemes. The technical solution includes the following steps: S1, system initialization; S2, user key generation; S3, user public key validity detection; S4, generation of the system master public key; S5, trapdoor generation; S6, keywords for the encryption access policy; S7, keyword policy detection. This invention utilizes a set of arithmetic and non-double number sequences to construct system common parameters, shortening the parameter length. Simultaneously, it employs a dual-system encryption mechanism to achieve complete security and hides the keyword policy by embedding subgroup elements in the ciphertext, thereby ensuring keyword privacy. While ensuring data confidentiality, this method enables secure and flexible retrieval of encrypted data.
Owner:NANTONG UNIV

Quantum secure infrastructure system and user terminal access method based on the system

The application discloses a quantum security infrastructure system and a user terminal access method based on the system, belongs to the field of quantum security communication and cryptography, and comprises the following steps: a cryptographic management service platform (CMSP) responds to an access request of a user terminal, determines an identity and access management system (IAM) and a key management system (KMS) that need to be accessed by the user terminal; if the IAM and the KMS belong to the same region, the CMSP sends IAM information of the IAM to the user terminal; the user terminal accesses the IAM based on the IAM information; if the IAM and the KMS do not belong to the same region, the IAM performs a key relay process through the CMSP, generates a service authentication token and access token ciphertext, and sends the service authentication token and the access token ciphertext to the user terminal; and the user terminal accesses the IAM based on the service authentication token and the access token ciphertext. The application improves the resistance to quantum attacks and the security of the system.
Owner:中电信量子信息科技集团有限公司

Distributed control and cross-node auditing method for data security obligations in multi-party computing scenarios

PendingCN122457304AThird partyDigital signature
The application discloses a kind of distributed control and cross-node auditing method of data security obligation under multi-party computing scene.In the scene such as federal learning, secure multi-party computation, task initiator generates obligation agreement voucher based on security semantic knowledge base and is confirmed by the cryptography signature of each participant;Each participant node executes obligation processing to local data through unified obligation execution interface;Each node obligation execution audit log adopts unified format and is continuously associated across nodes through cryptography hash chain;Intermediate result in the calculation process can be passed after obligation compliance verification;After completion of calculation, additional digital signature structured obligation execution proof report is generated, and independent verification by a third party is supported.The application solves the engineering problems that the privacy computing framework lacks unified obligation control mechanism and cross-institution obligation execution cannot form a continuous and verifiable proof chain, enabling multi-party computing scenarios to have cryptography-trusted compliance evidence capabilities.
Owner:SHANGHAI CUSTLE INFORMATION TECH CO LTD

Firmware starting method and device, and computer readable storage medium

This application relates to the field of software technology, providing a firmware boot method, apparatus, and computer-readable storage medium. The method includes: in response to a firmware boot command in a device, acquiring data in a first storage area; the first storage area is used to store the hash value of the firmware; if the data in the first storage area is not empty, determining the current hash value of the firmware; if the current hash value matches the data in the first storage area, booting the firmware; if the current hash value does not match the data in the first storage area, performing cryptographic verification on the firmware; the cryptographic verification includes key verification, signature verification, and / or TLV parsing verification; if the cryptographic verification passes, booting the firmware. This method can improve the efficiency of firmware boot.
Owner:ALLYSTAR TECH SHENZHEN CO LTD

User data encryption based on a user subscription

A data communication system receives a first message from a user communication device that requests a user data session, and in response, determines that the user communication device has a user subscription for encrypted communications. In response to determining that the user communication device has the user subscription for the encrypted communications, the data communication system determines cryptography information for the user data session. The data communication system generates and transfers a second message to the user communication device that indicates the cryptography information for the user data session. The user communication device encrypts user data in response to the cryptography information and transfers the encrypted user data for the user data session. The data communication system generates and transfers a usage record for the user subscription that characterizes the user data session and the user data encryption.
Owner:T MOBILE INNOVATIONS LLC

VPN communication system and method based on quantum server cryptomachine and post-quantum cryptography

This invention provides a VPN communication system and method based on a quantum server cryptography machine and post-quantum cryptography, comprising: a cloud platform and a VPN terminal encryption device; the VPN terminal encryption device is connected to the cloud platform via a network; the cloud platform includes a quantum server cryptography machine, a key management service platform, and a quantum key service platform; the quantum server cryptography machine is used to generate quantum true random numbers and generate quantum keys based on the quantum true random numbers; the key management service platform is used to store and manage quantum keys; the quantum key service platform is used to support the secure distribution of quantum keys to the VPN terminal encryption device through a post-quantum cryptography algorithm; the VPN terminal encryption device is used to obtain quantum keys from the cloud platform as session keys and establish a VPN communication tunnel with the peer VPN terminal encryption device based on the session keys.
Owner:SHANGHAI CIRCULATION QUANTUM TECH CO LTD

A federated learning security three-party aggregation method for industrial internet of things

PendingCN122093035AFacilitate data flowPromote data utilizationKey distribution for secure communicationEncryption apparatus with shift registers/memoriesData streamSecret share
This invention relates to the fields of federated learning and cryptography, specifically to a secure three-party aggregation method for federated learning in the Industrial Internet of Things (IIoT). The method includes an initialization phase, a training phase, an online phase, and a verification phase. By setting up an architecture with one honest server and two aggregation servers, each server receives a portion of the secret share of local model gradient parameters sent by various IoT devices, thus protecting the privacy of local data. The honest server assists the two aggregation servers in interactively executing a three-party weight calculation protocol to calculate the secret share of the aggregation weights. They also interactively execute a three-party multi-weight aggregation protocol to calculate the secret share of the gradient parameters of the current aggregation model. Furthermore, a linear homomorphic hashing method is used to verify the correctness of the gradient parameters of the current aggregation model. This method solves the problems of low efficiency, weak security, and low robustness in federated learning during model training and aggregation, and can promote data flow and utilization in IoT scenarios.
Owner:GUANGXI BEITOU XINCHUANG TECH INVESTMENT GRP CO LTD

An electronic seal analysis and verification method based on AI and cryptography fusion

The application belongs to the technical field of electronic seal security, and more particularly to an electronic seal analysis and verification method based on AI and cryptography fusion. The AI feature extraction and comparison steps locate the seal area and extract multi-dimensional features by means of a pre-trained convolutional neural network model, realize accurate verification at the level of seal visual features, and break through the limitation of single verification dimension of traditional technology. Then, SM2 and SM3 national encryption algorithms are used for signature verification and hash value verification respectively, the signature anti-counterfeiting capability is strengthened, and the risks of forgery and tampering are resisted. Finally, the effectiveness is determined by combining the two-dimensional verification results, the reliability of the verification conclusion is ensured, the security and accuracy of the electronic seal verification are significantly improved, and malicious behaviors such as forgery, tampering and replay attacks are effectively resisted.

A cloud archive destruction and data provenance method and system

PendingCN122153943ADigital data protectionPhysical layerDistributed hash table
The application relates to the technical field of data security, in particular to a cloud file destruction and data tracing method and system, which comprises the following steps: a distributed hash table algorithm is used to analyze a physical storage unit set of a cloud file to be destroyed; a chaotic sequence multiple overwriting operation is used to forcibly clean the physical layer; a storage unit state flip matrix is collected in real time, and a Shannon entropy value is calculated; a cryptography destruction certificate is generated after the Shannon entropy value breaks through a safe destruction baseline; and finally, the certificate is encapsulated into a terminal block of a full life cycle tracing chain. In the application, the chaotic overwriting based on the entropy value detection is executed by analyzing the physical storage unit set, and the residual magnetic characteristics of the data in the physical layer are forcibly destroyed, so that the hidden danger of false deletion in the cloud environment is solved, the unalterable destruction evidence is established in combination with a chain locking mechanism, and the safe closed loop of the data full life cycle is realized.
Owner:NANJING JINGHUI INFORMATION TECH CO LTD

A method for processing sensitive data secured by a trusted third party and a set of sensitive data processing tools adapted for implementing such a method.

The present invention relates to a method for processing sensitive data, particularly biomedical images, securely, automatically, and reproducibly on a cloud computing infrastructure. The invention also discloses the device for implementing this method. The invention relies in particular on cloud computing, cryptography, biomedical imaging, pseudonymization, anonymization, and advanced signal and image processing technologies. The invention also covers a use case for such a method through the secure implementation of image processing technologies (a business application) applied to biomedical images. In one embodiment, these images are obtained from magnetic resonance imaging (MRI), specifically for applying advanced processing with the business application to map the apparent transverse relaxation rate (R2*) and perform quantitative susceptibility imaging (QSM).Figure for the abbreviation: figure 1.
Owner:VENTIO

Proxy interception and double encryption system and methods

A method of enabling custom cryptography is provided. The method can include sending, by a first computing device and to a second computing device, instructions to initiate a proxy. The proxy can be configured to intercept a message of a user agent. The user agent may be associated with the second computing device. The proxy can be further configured to perform custom cryptography based on the message to obtain a modified message. The custom cryptography may comprise post-quantum cryptography. The proxy can be further configured to send the modified message to at least one of the user agent, a reverse proxy, or a third computing device. The post-quantum custom encryption and / or decryption can comprise Quantum Secure Layer (QSL), Post-Quantum Transport Layer Security (PQTLS), Kyber, SABER, Enhanced McEliece, RLCE, or a National Institute of Standards and Technology (NIST) candidate post-quantum algorithm.
Owner:QUSECURE INC

A privacy query method and device for a wireless body area network

The application provides a privacy query method and device for a wireless body area network, and relates to the technical field of encrypted communication, and the method comprises the following steps: a trusted authorization center obtains and discloses public parameters by using elliptic curve cryptography; a server arranges a historical word list set according to corresponding key hash values of historical keywords, and completes user registration according to identity information and the trusted authorization center; a target hash value of a target keyword is obtained, and a blinding factor, an encryption parameter, a blinding point and an anonymous signature are generated according to a generated temporary false identity, identity information, a system registration public key and the public parameters, and a data query request is sent to the server; a second random number and the target keyword are used to decrypt a privacy data set fed back by the server, and a privacy query result is obtained, wherein, after the anonymous signature is verified successfully, the server queries the historical word list set according to the target hash value, and obtains a privacy data set according to a query result, thereby effectively improving the privacy query security.
Owner:CHINA RAILWAY ERYUAN ENGINEERING GROUP CO LTD

Shared ntt hardware optimization method in mixed application scenarios of quantum-resistant password ml-kem and ml-dsa

PendingCN122293306APathPingMultiplexing
This invention discloses a hardware optimization method for shared NTT in a hybrid application scenario of quantum-resistant cryptography ML-KEM and ML-DSA. For the three core basic operators in the NTT module—modular addition, modular subtraction, and modular multiplication—this invention redesigns the corresponding hardware implementation structure. Based on the design of ML-KEM with a smaller modulus bit length, it supports large-bit-width NTT operations by time-division multiplexing small-width arithmetic units, effectively reducing the hardware overhead of the underlying operators. For ML-DSA NTT operations, this invention proposes a dedicated pipeline structure that matches the improved operators. This structure optimizes register overhead through reasonable design of data flow paths and multiplexing mechanisms, further reducing system resource costs. This invention achieves compatibility support for multiple NTT parameters, thereby enabling the simultaneous completion of NTT operation tasks under different algorithms or parameter sets on the same hardware platform.
Owner:BEIJING HUADA INFOSEC TECH

A password algorithm artificial intelligence side channel analysis method based on dimension reduction and clustering

ActiveCN117579244BCryptographic attack countermeasuresEnergy efficient computingCluster algorithmPrincipal component analysis
The present application relates to a kind of password algorithm artificial intelligence side channel analysis method based on dimension reduction and clustering, belong to information security cryptography field.First, the energy trace obtained is analyzed, to determine the area of the energy trace in which the execution of the decryption process is related to secret information operation.Analyze the energy trace of the key operation part, use the method based on sliding window gradient value to divide each operation, obtain energy trace segment.Combined with the implementation of cryptographic algorithm, the energy trace segment is analyzed, and the operation type is identified.Use principal component analysis on energy trace segment for dimension reduction, take the component corresponding to the expected dimension as the principal component of each operation.Combined with the characteristics of energy trace segment, the cluster number obtained by clustering is estimated.Use clustering algorithm to cluster the energy trace segment after dimension reduction, analyze the clustering result to determine the operation type represented by each cluster, obtain the operation type corresponding to the energy trace segment, finally obtain the secret index sequence, realize the efficient analysis of the side channel of cryptographic algorithm.
Owner:BEIJING INST OF TECH +2

Cryptographically anchored public key distribution framework

A public key distribution framework for email addresses comprises Domain Key Authorities (DKAs) designated by Internet domains as authoritative managers of public keys of email addresses belonging to their respective domains. A root DKA (rDKA) anchored to a predetermined root domain serves as a wildcard authority for any email address. To guard against DNS-based attacks, DKAs and the rDKA register signing credentials with a DKA Trust Anchor (DTA). Clients verify signed DKA responses via the signing credentials held by the DTA. This two-layer architecture separates DNS-based service discovery from cryptographic verification, requiring attackers to compromise two independent layers to forge responses. When the DTA's domain is DNSSEC-protected, a single DNSSEC deployment extends cryptographic trust to all DKAs without per-domain DNSSEC. The architecture generalizes to a Domain Trust Propagation (DTP) pattern applicable to multi-domain service frameworks, enabling scalable DNSSEC-backed trust propagation with O(1) rather than O(n) deployment complexity.
Owner:SWAMINATHAN KISHORE

A searchable encryption method based on keyword threshold fault tolerance and collaboration trapdoor

The application discloses a searchable encryption method based on keyword threshold fault tolerance and collaborative trapdoor, initializes a bilinear system parameter, distributes key shares to a data owner and a user group by adopting a threshold mechanism, generates a fault-tolerant keyword set according to a preset fault-tolerant threshold based on a standard keyword, constructs a document return mapping of the fault-tolerant keyword to the standard keyword, performs derivation on all fault-tolerant keywords, generates an encrypted index used for ciphertext retrieval, uploads a document ciphertext, an integrity label and the encrypted index to a cloud server, introduces a cryptographic reverse firewall on a client side, re-randomizes a key interaction message, in a query stage, a user end cooperatively generates a retrieval trapdoor and submits the retrieval trapdoor to the cloud server after satisfying a threshold condition, the cloud server completes matching without decrypting a document content and returns a candidate document ciphertext set, an auditing party verifies the integrity of a returned result, and outputs a final retrieval result to a user after verification.
Owner:CHUZHOU UNIV

Cryptographic processing methods, apparatus, equipment, media and program products

PendingCN122316628AScripting languageSoftware engineering
This application provides a cryptographic operation processing method, apparatus, device, storage medium, and program product, which can be applied to the field of financial technology or other technical fields. The method includes: acquiring a script file, the script file being written in a predefined scripting language and including cryptographic operation description information; compiling the script file to generate an executable cryptographic operation object; in response to an application call, acquiring cryptographic operation data to be processed and passing the cryptographic operation data to the cryptographic operation object; and executing the cryptographic operation object, wherein the cryptographic operation object, based on the cryptographic operation description information, calls an underlying cryptographic operation module to perform cryptographic operations on the cryptographic operation data and returns the operation result.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA