Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Cryptography protocols" patented technology

A cryptographic protocol is a protocol executed by several distant agents through a network where the messages or part of the messages are produced using cryptographic functions (encryption, hashing, etc.).

Verified physical access of telecommunications network subscribers at third-party events or venues

The verification of individuals entering controlled locations such as events and venues is improved by using wireless devices as the entry tickets themselves, verifiable by a telecommunications network. The wireless device provides a network subscriber's identification information (e.g., a phone number) to an access point terminal, in response to an identification / authentication request from the access point terminal. In order to obtain the identification information to provide to the terminal, the wireless device verifies itself via the telecommunications network, which is capable of verifying the device's subscriber identity module (SIM) via cryptographic protocols. Thus, by verifying the device's SIM, the telecommunications network verifies the identity of the network subscriber operating the device, for purposes of sharing a phone number as an entry ticket. Because entry is controlled according to the device's own network-verifiable identity, third-parties that operate events or venues need not distribute entry tickets (e.g., physical or electronic) to individuals.
Owner:T MOBILE US INC

Automobile bus safety detection system and method based on commercial password technology

The invention provides an automobile bus safety detection system and method based on a commercial password technology. The system comprises a bus data acquisition module, a configuration temperature compensation crystal oscillator and a double DDR4 buffer pool; the protocol analysis engine is used for integrating a predefined analyzer and a BiLSTM-based custom protocol recognition model; the cryptographic protocol identification module is used for monitoring and identifying a cryptographic protocol through the protocol characteristic matrix and the Shannon entropy; the password compliance detection module is used for loading a national password GM / T standard library to execute algorithm identifier verification; the key security analysis module is used for implementing key entropy grading detection and life cycle analysis; the simulation attack module is used for dynamically adjusting an attack strategy according to the environmental risk factors; and the auditing and reporting module generates a visual compliance report. According to the method, automatic security detection of automobile bus password communication is realized through seven steps of data acquisition, protocol analysis, password identification, compliance detection, key analysis, attack simulation and report generation, and the problem that a traditional tool cannot detect password compliance and key security is solved.
Owner:CHANGCHUN AUTOMOTIVE TEST CENT

Public verifiable data service method for instrument control system

PendingCN121923921AUser identity/authority verificationCryptography protocolsCloud storage
The invention belongs to the technical field of information security, relates to zero-knowledge proof and block chain technologies, and particularly provides a public verifiable data service method for an instrument control system, so as to solve the technical problem of huge calculation overhead caused by the fact that commitment consistency check of large-scale data needs to be executed in a circuit in an existing zk-SNARK-based scheme. According to the invention, a hybrid proving system based on a cryptographic protocol Plonk and Groth16 is designed, the promise adaptive to the system is designed, and the consistency check of the promise of the database is transferred from the inside of an arithmetic circuit to the outside of the circuit, so that the huge calculation overhead introduced into a zk-SNARK circuit by the promise consistency check of a large-scale database is avoided; and finally, the verifiable execution of safe calling and operation on the data subset from the third-party cloud storage is realized, the accuracy and integrity of industrial data are ensured, and the problem of trust missing in a cross-domain scene is solved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

A general two-party oblivious signature method and system

This invention discloses a general two-party unintentional signature method and system, belonging to the field of cryptographic protocol technology. The method includes: participants P1 and P2 jointly generating a signature public key; participants P1 and P2 jointly calculating a signature of the message, wherein the signature is known only to participant P1, and participant P1 uses the signature public key to verify the signature. This invention can both distribute key storage to avoid the risk of key leakage and prevent additional participants from obtaining the final signature content.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

A method for information hiding and intelligence transmission based on lattice cipher signature fields

This invention discloses a method for information hiding and intelligence transmission based on lattice cipher signature fields. This method allows both communicating parties to simultaneously extract secret information upon correct signature verification, thereby achieving information hiding and communication within the lattice cipher protocol's signature field. This invention records all operations of both communicating parties, ensuring traceable operational traceability. Furthermore, this invention constructs a client and a server, with the server managing the client's information and operations. The client can communicate as both an intelligence sender and receiver. Based on the fault tolerance of lattice ciphers, this invention achieves lossless extraction of secret information and recovery of the carrier without requiring any external information. It also improves upon the classic differential extended steganography scheme, ensuring a high information embedding bit rate even with a small number of carriers.
Owner:JINAN UNIVERSITY

Device and method for generating a blind signature for a message

The invention relates to a method for generating a blind signature for a message based on a cryptographic protocol implemented in a Euclidean network comprising a public key formed of at least one matrix A composed of elements of a set and a secret key linked to the public key and known exclusively to a signatory entity, the method comprising: generating a first ring vector r; determining a second vector c equal to A.r +f(m); the signatory entity generating a third ring vector s such that c= A.s, with s complying with at least one constraint relating to its norm; generating the intermediate signature comprising an aggregation vector resulting from a combination of the first and third vectors; decomposing the aggregation vector into a first part and a second part; generating a blind signature composed of the first part and of a proof of knowledge of the matrix and of the second part.
Owner:ORANGE SA

Light-weight transmission encryption method based on commercial cryptographic algorithm

The invention relates to the technical field of information security, and discloses a lightweight transmission encryption method based on a commercial cryptographic algorithm, which comprises the following steps: two communication parties establish an initial session through a lightweight handshake protocol; collecting a feature vector of the data to be sent and an equipment operation state containing CPU, memory and energy limited parameters; calculating a comprehensive load index according to the acquired parameters, comparing a threshold according to a preset decision function, determining a simplified strength mode when the equipment is in a high-load state and processes non-critical data, and otherwise, determining a standard strength mode; and writing the encryption mode into a message header, and performing block encryption and packaging transmission on the data load by using the session key. According to the method, through a parallel key exchange process, compact key storage and a self-adaptive encryption decision mechanism, the problems of large calculation overhead, high handshake delay and large storage occupation of a commercial cryptographic protocol in a resource-constrained environment are effectively solved, and the equipment energy consumption and the communication delay are reduced while the security of key data is guaranteed.
Owner:CSG EHV POWER TRANSMISSION

Verified physical access of telecommunications network subscribers at third-party events or venues

The verification of individuals entering controlled locations such as events and venues is improved by using wireless devices as the entry tickets themselves, verifiable by a telecommunications network. The wireless device provides a network subscriber's identification information (e.g., a phone number) to an access point terminal, in response to an identification / authentication request from the access point terminal. In order to obtain the identification information to provide to the terminal, the wireless device verifies itself via the telecommunications network, which is capable of verifying the device's subscriber identity module (SIM) via cryptographic protocols. Thus, by verifying the device's SIM, the telecommunications network verifies the identity of the network subscriber operating the device, for purposes of sharing a phone number as an entry ticket. Because entry is controlled according to the device's own network-verifiable identity, third-parties that operate events or venues need not distribute entry tickets (e.g., physical or electronic) to individuals.
Owner:T MOBILE US INC

Key migration method, cryptographic module and live migration method thereof, and related equipment

The embodiment of the invention provides a key migration method, a cryptographic module and a live migration method thereof, and related equipment, the key migration method is applied to a target cryptographic module coupled to a key mirror image import interface, and the key mirror image import interface is an interface which is preset by a target physical host and is only used for transmitting a key mirror image ciphertext. Comprising the following steps: sending a public key certificate and first cryptographic protocol information when a cryptographic module is thermally migrated; receiving a key mirror image ciphertext and second cryptographic protocol information based on the key mirror image import interface, the second cryptographic protocol information being generated by the source cryptographic module; and generating a decryption key for decrypting the key mirror image ciphertext according to the second cryptographic protocol information to obtain a key mirror image, and after the integrity of the key mirror image is verified, outputting an import result, thereby realizing the thermal migration of the cryptographic module.
Owner:HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD

Unmanned aerial vehicle authentication and key negotiation system and method based on PUF and chaotic mapping

The invention discloses an unmanned aerial vehicle authentication and key negotiation system and method based on PUF and chaotic mapping, and relates to the field of information security and cryptographic protocol security. The system generates a unique challenge-response pair through an unmanned aerial vehicle terminal PUF module to complete registration, a four-way handshake mechanism is adopted in the authentication stage, a session key is dynamically generated in combination with Henon chaotic mapping, the number of chaotic iterations is hidden through XOR operation, and identity legality is guaranteed through multi-layer MAC verification. According to the method, secret keys do not need to be pre-stored, the PUF physical unclonability and the chaotic mapping sensitivity are utilized, anonymous authentication and forward security are achieved, lightweight computing adapts to unmanned aerial vehicle resource constraints, various attacks are effectively resisted, and communication security is guaranteed.
Owner:JINLING INST OF TECH

Updating vehicle electronic control unit software

Aspects of the present invention relate to a control system (100) for use in updating software in a plurality of electronic control units, ECUs (112, 114, 116), of a vehicle (200). The control system receives software data (104) comprising software update information (134) associated with one or more of the ECUs (112, 114, 116), verifies the software update information (134) using a cryptographic protocol, and, responsive to successful verification of the software update information (134) according to the cryptographic protocol, outputs a software update (106, 108, 110) for each of the one or more ECUs (112, 114, 116), each software update (106, 108, 10 110) being based on the software update information (134) for the associated ECU (112, 114, 116).
Owner:JAGUAR LAND ROVER LTD

Mobile payments using multiple cryptographic protocols

Systems, methods, and computer readable media are provided for improving the usability of a cryptogram generated in a first cryptographic protocol such as triple-DES. The methods may generate a first cryptogram using a first identifier in a first cryptographic protocol, stored in a key store within an insecure memory of the mobile communication device, generate, within a secure memory of the mobile communication device, a second cryptogram using a second identifier in a second cryptographic protocol, stored in the secure memory, combining, the first cryptogram and a number of characters of the second cryptogram equal to the length of the first cryptogram to generate a third cryptogram and transmitting the third cryptogram to an payment processing network to validate a transaction. A transaction associated with the third cryptogram may be validated by an authorization entity or an issue entity.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Secure Communications Among Multiple Entities Using Quantum Entanglement

Systems and techniques may generally be adapted for establishing secure communications with use of quantum entanglement, including via the use of mesh networks and multiple satellite communication locations. An example technique may include generating a stream of quantum entangled particles, and transmitting at least part of the stream of the quantum entangled particles to at least a first node, a second node, and an intermediate node connected via a satellite communication network. In this context, the intermediate node is located between the first node and the second node, and a secure trusted mesh of entities can be established among the first, second, and intermediate nodes. The stream of the quantum entangled particles can used to derive a quantum entangled value, such as for use with a cryptographic protocol of secure communications between the first node and the second node via the satellite communication network.
Owner:WELLS FARGO BANK NA

An information data operation processing system based on a secure isolation gateway

The application discloses an information data operation processing system based on a security isolation gateway, and relates to the technical field of data communication.The system comprises a security isolation gateway, a global side subsystem and N participant side subsystems, wherein N is a positive integer; the security isolation gateway is connected between the global side subsystem and each participant side subsystem and is configured to establish a controlled one-way data transfer channel between the two; the global side subsystem comprises a global coordination module, a trusted verification module and a security aggregation module; and each participant side subsystem comprises a trusted execution module.The application solves the technical problem that the privacy protection of the existing information data processing process depends on a complex cryptography protocol, is inefficient and is difficult to exclude malicious or low-quality updates, and affects the security and efficiency of cross-domain information processing, and achieves the technical effects of simplifying privacy protection, efficiently excluding malicious updates and improving the security and efficiency of cross-domain information processing by using the security isolation gateway.
Owner:TIANJIN XINSHITONG TECHNOLOGY CO LTD

Handling of sensitive data in a network having multiple security zones

A computer-implemented method is disclosed for handling sensitive data in a network comprising multiple security zones. The method includes sharing a data cleansing ruleset among a plurality of servers that are each within a respective security zone and using a multi-party cryptographic protocol that each of the plurality of servers participates in, to obtain a shared secret. Each server individually cleanses a respective dataset containing sensitive data using the data cleansing ruleset and then hashes the resulting cleansed dataset with a hash function using the shared secret as a salt. This produces a resultant dataset containing hashed representations of the original sensitive data, meaning that the dataset produced by each server can be collated to form a composite dataset without breaching data security requirements. A data operation can then be performed on the composite dataset.
Owner:MASTERCARD INT INC

Information data operation processing system based on security isolation gatekeeper

The invention discloses an information data operation processing system based on a security isolation gatekeeper, and relates to the technical field of data communication, the system comprises the security isolation gatekeeper, a global side subsystem and N participant side subsystems, and N is a positive integer; the security isolation gatekeeper is connected between the global side subsystem and each participant side subsystem, and is configured to establish a controlled one-way data ferry channel between the global side subsystem and each participant side subsystem; the global side subsystem comprises a global coordination module, a credible verification module and a security aggregation module, and each participant side subsystem comprises a credible execution module. The technical problems that privacy protection in an existing information data processing process depends on a complex cryptographic protocol, efficiency is low, malicious or low-quality updating is difficult to eliminate, and the safety and efficiency of cross-domain information processing are affected are solved, and the purposes that privacy protection is simplified through a safety isolation gatekeeper, malicious updating is efficiently eliminated, and the safety and efficiency of cross-domain information processing are improved are achieved. And the safety and efficiency of cross-domain information processing are improved.
Owner:TIANJIN XINSHITONG TECHNOLOGY CO LTD

Systems and methods for the automated integration of cryptographic protocols

The present technology relates to techniques for integrating centralized custodial services and DeFi services. In one aspect of the technology, a platform stores a cryptographic key associated with a user of the platform. The user instructs the platform of a first digital asset to transfer from a centralized custodial service to a DeFi service in exchange for a second digital asset. Based on these instructions, the platform causes the centralized custodial service to transmit the first digital asset to a self-executing computer program of the platform. The platform then transmits the cryptographic key, as well as the instructions, to the self-executing computer program. Upon receipt of the cryptographic key, the instructions, and the first digital asset, the self-executing computer program executes, transmitting the first digital asset to the DeFi service and causing the DeFi service to transmit the second digital asset to the centralized custodial service.
Owner:ROCKO INC

Cryptographic protocol analysis method and device, computer equipment and readable storage medium

The invention relates to a cryptographic protocol analysis method and device, computer equipment and a readable storage medium. The method comprises the following steps: extracting field state features and dependency relationship features from a dynamic field state graph by acquiring the dynamic field state graph constructed for a cryptographic protocol to be analyzed, the features being used for describing the features of state changes under different events and different contexts; and inputting the field state features and the dependency relationship features into a pre-constructed attack prediction model to obtain a potential attack occurrence probability and an attack path of a network using a cryptographic protocol. The method comprises the following steps: acquiring a dynamic field state map, extracting dynamic field state features and dependency relationship features from the dynamic field state map, and inputting the field state features and the dependency relationship features into an attack prediction model for attack prediction, thereby realizing analysis of a cryptographic protocol currently used by a network; and the analysis result accuracy and the environment adaptability are enhanced.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Privacy protection identity registration and authentication method and system compatible with standard sim card

This invention discloses a privacy-preserving identity registration and authentication method and system compatible with standard SIM cards, belonging to the field of cryptographic protocol technology. The system includes three participants: a user terminal, an operator, and an application. It is based on the SIM card issued by the mobile operator and owned by all mobile phone users. The user and the operator collaborate to complete the application's authentication of the user's identity. This invention features high security and efficiency; even if an adversary compromises the operator, they cannot obtain the user's login behavior. It also protects user authentication from man-in-the-middle attacks, is compatible with existing SIM cards, requires no replacement of existing hardware, and is easy to deploy. This invention further enhances privacy protection, ensuring that user access behavior is not tracked, has excellent interoperability, and is suitable for large-scale 5G application deployment.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Data transmission method, device and unit, receiver and storage medium

The embodiment of the invention provides a data transmission method, device and unit, a receiver and a storage medium. The method comprises the following steps: analyzing positioning data generated by a GNSS signal processing unit to obtain receiving end information; wherein the positioning data is obtained by processing satellite signals; based on a cryptographic protocol sub-layer in a bottom layer of the transmission protocol stack, encrypting the positioning data by adopting an encryption strategy in a commercial password security engine to obtain first encrypted data; wherein the first encrypted data comprises an encryption header; transmitting the first encrypted data to an external device according to the receiving end information; wherein the first encrypted data is used for obtaining the positioning data after decryption processing. According to the method, the security of data transmission based on the receiver can be improved, so that the credibility of the data is ensured.
Owner:ZHEJIANG GEELY HLDG GRP CO LTD +1

Agile cryptographic deployment service

Embodiments are directed to methods and systems for crypto-agile encryption and decryption. A computer system can possess a protocol file that identifies one or more cryptographic software modules. Using these cryptographic software modules, the computer system can generate a plurality of shared secrets and a session key, then use the session key to encrypt a message. The message can be sent to a server computer that can subsequently decrypt the message. At a later time, the protocol file can be updated to identify a different set of cryptographic software modules, which can be used to encrypt messages. Further, the server computer can transmit additional cryptographic software modules to the computer system, enabling the computer system to use those cryptographic software modules to generate cryptographic keys. As such, the cryptographic protocol file can be changed in response to changes in the cryptographic needs of the computer system.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Unknown network secret sharing and broadcasting method and system with low communication overhead

The invention discloses an unknown network secret sharing and broadcasting method and system with low communication overhead, and aims to solve the problem of high communication overhead of broadcasting and secret sharing under an unknown network model based on various distributed computing technologies and cryptographic protocols, such as threshold signature, polynomial commitment, erasure code and the like. A broadcast protocol and a secret sharing protocol with linear communication complexity are respectively designed, the protocol efficiency is remarkably improved, communication overhead close to the linear communication complexity is realized, and the method has wide application scenes in the fields of distributed consensus, secure multi-party computing and the like. An erasure code technology in traditional asynchronous consensus, a threshold signature technology in synchronous consensus and a polynomial commitment and Packed technology in asynchronous secret sharing are combined, and a commitment consistency verification protocol is designed, so that the overall communication overhead is optimized, and an important breakthrough is brought to the field of secure multi-party computing.
Owner:WUHAN UNIV

Cryptographic processor device and data processing apparatus employing the same

The present disclosure provides a cryptographic processor device capable of performing the post-quantum cryptographic encryption with in a high speed with low power, allowing a change of encryption parameters, and handling various cryptographic protocols. The cryptographic processor device executing polynomial vector operations required for a post-quantum cryptography includes: a polynomial memory bank configured to store a plurality of polynomial vectors; and an arithmetic and logic operator configured to perform operation on the polynomial vectors. The arithmetic and logic operator includes a transform operation circuit configured to multiply two polynomial vectors read out from the polynomial memory bank by using a predetermined transform operation including a plurality of operation stages, and including a combined operation unit configured to consecutively perform a first stage operation and a second stage operation among the plurality of operation stages without storing a result of the first operation stage in a memory.
Owner:POSTECH ACADEMY INDUSTRY FOUNDATION