Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

38 results about "Digital Signature Algorithm" patented technology

The Digital Signature Algorithm (DSA) is a Federal Information Processing Standard for digital signatures, based on the mathematical concept of modular exponentiation and the discrete logarithm problem. DSA is a variant of the Schnorr and ElGamal signature schemes.

Message encryption method and device based on improved digital signature algorithm, and electronic equipment

The invention discloses a message encryption method and device based on an improved digital signature algorithm, and electronic equipment, and relates to the field of privacy computing or financial science and technology, and the method comprises the steps: carrying out the calculation through employing a hash function and a pre-generated random bit string, and obtaining a preprocessed message, the sum of chain length parameters of positions of all chains in the signature is equal to a natural number parameter, constructing a Hash forest by using an FORS algorithm, generating a one-time signature for each tree, and combining two signatures by using an upper-layer key to obtain a WOTS + signature; and encrypting the financial transaction message and the preprocessed message based on the final signature result, and transmitting an encryption result and the final signature result to the target terminal for verification. According to the method and the device, the technical problems that the encryption speed is low and the encryption operation cannot be completed in time due to the complex algorithm when the financial transaction message is encrypted by adopting a post quantum cryptography encryption mode in the related technology are solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Lightweight block chain encryption method based on hybrid encryption

InactiveCN120934809AKey distribution for secure communicationMultiple keys/algorithms usageAttribute-based encryptionDigital Signature Algorithm
The invention relates to the technical field of block chains, in particular to a lightweight block chain encryption method based on hybrid encryption, and the method comprises the following steps: S1, carrying out the encryption of transaction data in a block chain through employing a lightweight symmetric encryption algorithm, and generating encrypted transaction data; s2, using an asymmetric encryption algorithm and an anti-quantum encryption algorithm to cooperatively encrypt a key of the lightweight symmetric encryption algorithm in the S1 to generate an encrypted key; s3, carrying out signature processing on the encrypted transaction data and the encryption key by adopting a lightweight digital signature algorithm to generate signature information; and S4, setting access authority for the encrypted transaction data by adopting an attribute-based encryption algorithm. According to the invention, the transaction data is encrypted by adopting the lightweight symmetric encryption algorithm, so that the problem that the application is limited in the resource limited scene such as lightweight equipment due to the fact that most of the traditional block chain encryption methods adopt a single encryption mechanism is solved.
Owner:QINGDAO MEIYANG DATA TECHNOLOGY CO LTD

High-precision positioning construction method based on BIM (Building Information Modeling) and building fabricated node

The invention discloses a high-precision positioning construction method based on BIM and building assembly type nodes, and relates to the technical field of building information management, and the method comprises the steps: S1, collecting original coordinate data through a node positioning device, calculating a hash value, obtaining a unique data fingerprint, generating a timestamp record according to the unique data fingerprint in combination with a current system clock, and storing the timestamp record in a database; s2, broadcasting the bound data block to a distributed node by adopting a block chain network to obtain a block index after consensus confirmation, and if the block index is matched with the original coordinate data, adding a private key signature for the data block through a digital signature algorithm to obtain a signature data packet; according to the high-precision positioning construction method based on the BIM and the building fabricated node, the problems of positioning data tampering and loose binding are solved, the reliability and safety of data tracing are remarkably improved, and the method is suitable for a high-precision positioning scene.
Owner:YUAN DINGSHENG (FUJIAN) CONSTRUCTION ENGINEERING CO LTD

Blockchain-based ticket settlement verification method and system

PendingCN122656634AStrengthen compliance management and control capabilitiesBalance processing efficiencyTicketAlgorithm
The application discloses a blockchain-based ticket settlement verification method and system, relates to the technical field of financial transaction safety, and comprises the following steps: S1, receiving a cross-border order submitted by a buyer, verifying the order integrity and the authenticity of the buyer's identity by using a digital signature algorithm, analyzing and extracting the buyer's information, the HS code of the commodity, the payment amount and the currency, and completing the consistency comparison of the ticket basis information in combination with the corresponding tax payment price interval of the HS code; S2, calling an off-chain risk control engine to carry out multi-dimensional compliance verification in parallel, generating a comprehensive risk score and dividing a risk level; after the verification, a preset aggregation template is matched based on the risk level, a unique feature identifier of the order is generated by using a hash algorithm; the risk level is adaptively matched with batch aggregation parameters and on-chain priority, and differentiated dynamic scheduling of off-chain batch evidence is realized. The application realizes full-dimensional pre-checking to avoid false transaction risks, and builds a risk level adaptive adjustment mechanism to balance business processing efficiency and risk control safety.
Owner:SHANGHAI LINGXIA TECHNOLOGY CO LTD

Secure boot method, electronic device, medium, secure boot software, and chip

The application relates to the technical field of computers, in particular to a secure starting method, an electronic device, a medium, secure starting software and a chip. The method can first calculate label data corresponding to a to-be-authenticated object set (for example, a device image set) and obtain repair data by using a private key stored in the electronic device, then obtain authentication data by a first algorithm (for example, a reversible calculation algorithm) based on the label data and the repair data, wherein the calculation amount of the first algorithm is less than that of a digital signature algorithm. Then, whether the device image in the to-be-authenticated object set is trusted is determined by comparing the authentication data with a trusted root stored in the electronic device. In this way, the secure starting method provided in the embodiments of the application does not need to consume a large amount of computing resources or memory resources when comparing the authentication data with the trusted root, and can realize lightweight secure starting, so that the secure starting can be realized on an electronic device with limited resources.
Owner:ARM TECH CHINA CO LTD

Ciphertext data aggregation method for crowd sensing

The invention relates to the technical field of information security, privacy protection and data aggregation, in particular to a ciphertext data aggregation method for crowd sensing, which comprises a user node, an aggregation server and a credible center which cooperate to realize data privacy protection and efficient aggregation, data is encrypted after being collected, and the encrypted data is stored in the credible center. Transmission and aggregation processes are both carried out in a ciphertext form, only a trusted center can decrypt to obtain a plaintext aggregation result, a digital signature technology is combined, data source traceability and integrity verifiability are realized, dynamic adding and exiting of a user node are supported, and through a secret key management and list updating mechanism of the trusted center, the reliability of the user node is improved. The lightweight homomorphic encryption algorithm and the digital signature algorithm are combined, calculation and communication overhead is reduced, mobile equipment with limited resources is adapted, the method can be applied to a large-scale crowd sensing scene, and the overall security of the system is further improved through a hierarchical verification mechanism and layer-by-layer check.
Owner:CHUZHOU UNIV

Software updating method and device for vehicle controller, digital signature system, and computer program product

The present application relates to the technical field of vehicles, and discloses a software updating method and device for a vehicle controller, a digital signature system, and a computer program product. The method comprises: acquiring an identifier of a target controller, an identifier of a target digital signature algorithm, and a digest of a software update package of target software; on the basis of the identifier of the target controller and the identifier of the target digital signature algorithm, searching a first database for a private key in a first key pair, wherein the first database is used for storing private keys in key pairs applied for different controllers and different digital signature algorithms; and generating a first signature file on the basis of the digest of the software update package of the target software and the private key in the first key pair. By performing unified online management on key pairs, private keys in key pairs can be queried online when signature files are generated. Compared with offline management and private key query, the present application improves the efficiency of searching for key pairs, thereby improving the efficiency of generating signature files.
Owner:CHERY AUTOMOBILE CO LTD

Digital signature algorithm for verifying edited data

Embodiments of this disclosure provide, but are not limited to, solutions for protecting, sharing, verifying, and / or generating data resources such as documents. In exemplary embodiments, a data resource is represented, expressed, or defined as a plurality of hashed constituent segments. Using the segment hashes as leaves, a Merkle tree is generated representing the complete original version of the data resource. An edited version of the data resource can be shared, omitting one or more segments that the data administrator wishes to keep secret or does not wish to share in its original form. To verify the authenticity and / or completeness of the edited data resource, a validator is provided with sufficient data (e.g., the hash of each of the non-shared segments) to verify the presence of non-shared segments in the tree representing the complete original version, and an authorized signature that signed the root. In some embodiments, the data resource is a code library, and the segments are parts of computer code that perform specific subtasks. Shared code segments, when executed on a processor, may be selected to combine to perform larger tasks.
Owner:NCHAIN LICENSING AG

Identity authentication method and device, server, storage medium and product

The invention discloses an identity authentication method and device, a server, a storage medium and a product, and the method comprises the steps: determining the head information of a JWT as an identity authentication token and the identity information of a user in response to a login request from a client; determining load information of the JWT based on the identity information; determining a to-be-sent message based on the header information and the load information; determining signature information based on the to-be-sent message and an SM9 digital signature algorithm; and generating a JWT based on the header information, the load information and the signature information, and sending the JWT to the client. After a user logs in by using a client, the SM9 algorithm is used as a signature algorithm of the JWT, and the information in the head and the load of the JWT is signed, so that the security of the JWT is greatly improved based on the algorithm characteristics of the SM9. In this way, the JWT scheme can resist attacks such as bypassing of the one algorithm, sensitive information leakage, algorithm confusion and key exhaustion.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Method and device for hiding secret in check digital signature, and medium

The invention provides a method and device for hiding secrets in a check digital signature and a medium. The method comprises the steps that a signer generates a key pair through a Fiat-Shamir key construction method; wherein the key pair comprises a public key and a private key; obtaining a to-be-signed message; generating a digital signature based on the private key and the to-be-signed message by using a constant convolution sampling method; and transmitting the to-be-signed message, the digital signature and the public key to a verification party, and performing verification by the verification party. According to the novel method for hiding the secret in the lattice digital signature, deep research is carried out on the digital signature algorithm based on the lattice cryptographic algorithm, the limitation on modulus in the prior art is avoided, the signature length is reduced, the parameter selection flexibility is improved, and a signature algorithm with a shorter bandwidth can be designed.
Owner:COMMUNICATION UNIVERSITY OF CHINA

Authentication for non-3gpp access using digital signature

For security mechanisms for non-3GPP access, the present disclosure relates to authentication for non-3GPP access using digital signatures. In an embodiment, a user equipment (UE) is configured to store at least a primary certificate having a primary digital signature algorithm and a secondary certificate having a secondary digital signature algorithm. When accessing a core network via a gateway through a non-3GPP access, the UE is configured to use the primary certificate to perform authentication with the gateway by computing a first digital signature with the primary digital signature algorithm, receive revocation information from the core network revoking the primary certificate, and use the secondary certificate to perform authentication with the gateway by computing a second digital signature with the secondary digital signature algorithm.
Owner:NOKIA TECHNOLOGIES OY

A method to improve the signature verification performance of Edwards curve digital signature algorithm

ActiveCN120675721BUser identity/authority verificationAlgorithmEdwards curve
This application discloses a method, apparatus, and device for improving the verification performance of an Edwards curve digital signature algorithm, belonging to the field of data encryption technology. It includes: determining the relationship between a first modulo result and the latter half of the signature value and a first preset value; when both the first modulo result and the latter half of the signature value are equal to the first preset value, using a first intermediate result calculated using a preset initial intermediate result as an intermediate value; when either the first modulo result or the latter half of the signature value is not equal to the first preset value, further determining whether the values ​​of the first modulo result and the latter half of the signature value at predetermined positions are the same as a second preset value, and obtaining a second judgment relationship; based on the second judgment relationship, calculating the intermediate value using the initial intermediate result, and using any one of the inverse coordinates of the public key coordinates, the base point coordinates, and the newly constructed coordinates; and obtaining the verification result of the signature value by comparing the intermediate value with the first half of the signature value.
Owner:CCORE TECH CO LTD

A conditional traceable ring signature method, system, electronic device and storage medium

This invention discloses a conditionally traceable ring signature method, system, electronic device, and storage medium. The method includes: setting system parameters; generating keys for the user and the anonymous revocation authority based on the digital signature algorithm and system parameters; generating a ring signature based on the keys; verifying the ring signature, outputting a first predetermined result if the verification passes, and outputting a second predetermined result if the verification fails; linking the ring signatures, and determining whether to add the ring signature to a signature list based on the ring signature link; if the ring signature appears in the signature list, and the anonymous revocation authority wants to recover the signing public key using its private key, it substitutes the private key of the anonymous revocation authority into a pre-mixed set of public keys to trace the public key of the actual signer; the ring signature algorithm of this invention incorporates a signature list function, enabling the anonymous revocation authority to revoke the anonymity of ring signatures in the signature list only, thereby reducing the authority of the anonymous revocation authority and achieving partial traceability of the ring signature.
Owner:SHENZHEN UNIV

Identity authentication method and system

The application relates to an identity authentication method and system. In the method, a claiming party determines an asymmetric digital signature algorithm and a post-quantum digital signature algorithm, generates algorithm identifiers corresponding to the asymmetric digital signature algorithm and the post-quantum digital signature algorithm, acquires a time-varying parameter, generates signature data according to the time-varying parameter and an identifier of a verifying party, signs the signature data by using the asymmetric digital signature algorithm to obtain a first signature, signs the signature data by using the post-quantum digital signature algorithm to obtain a second signature, generates an identity authentication string according to the algorithm identifiers, the signature data, the first signature and the second signature, and sends the identity authentication string to the verifying party to instruct the verifying party to perform identity authentication according to the identity authentication string. The method introduces the post-quantum digital signature algorithm capable of resisting quantum computing on the basis of traditional asymmetric password identity authentication, improves the security of communication parties in the identity authentication process, and can resist quantum threats to a certain extent.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

An intelligent driving safety detection system and method based on artificial intelligence

The present application relates to the technical field of image detection, in particular to a driving safety intelligent detection system and method based on artificial intelligence, comprising the following steps: S100: collecting vehicle information and corresponding vehicle trajectory information of illegal driving, collecting vehicle information and collecting image data of a certain time period obtained by a wide-angle camera, forming an image data set; S200: using a digital signature algorithm to encrypt and store the collected data; S300: analyzing the change rule of each image feature point at different times from each image in the image data set, and judging whether the state of each image feature point is static or dynamic; S400: matching the dynamic feature data with the historical trajectory set, and further analyzing the risk degree of the current state of the concerned vehicle; S500: reminding when the risk degree of the concerned vehicle exceeds the threshold value; the present application reduces illegal driving and detects the safety status of people during driving in a timely manner.
Owner:无锡市神韵科技发展有限公司

Identity authentication method and system

The present application relates to an identity authentication method and system. The method comprises: a claimant determining an asymmetric digital signature algorithm and a post-quantum digital signature algorithm; generating an algorithm identifier corresponding to the asymmetric digital signature algorithm and the post-quantum digital signature algorithm; acquiring a time-varying parameter, and generating signature data on the basis of the time-varying parameter and an identifier of a verifier; using the asymmetric digital signature algorithm to perform signing on the signature data, so as to obtain a first signature; using the post-quantum digital signature algorithm to perform signing on the signature data, so as to obtain a second signature; on the basis of the algorithm identifier, the signature data, the first signature and the second signature, generating an identity authentication string; and sending the identity authentication string to the verifier, so as to instruct the verifier to perform identity authentication on the basis of the authentication string. On the basis of conventional asymmetric cryptographic identity authentication, the method introduces a post-quantum digital signature algorithm capable of resisting quantum computation, thereby enhancing the security of two communicating parties during identity authentication and being able to resist quantum threats to a certain extent.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Digital signature algorithm for verifying revised data

Embodiments of the present disclosure provide technical schemes for protecting, sharing, verifying and / or generating data resources (e.g., but not limited to documents). In an exemplary embodiment, the document is expressed or defined as a plurality of composition segments, and then the plurality of composition segments are subjected to hash processing. A Merkel tree representing the document is generated, wherein the hash of the segment is used as a leaf of the Merkel tree. A signer is authorized to sign the root of the tree. The trimmed version of the document may then be shared, thereby omitting one or more segments that a data controller wishes to secure. To verify the authenticity and / or integrity of the revised document, a verifier is provided with sufficient data to check whether there is one or more non-segments in the tree and whether there is the authorized signature that signs the root.
Owner:NCHAIN LICENSING AG

Parallel implementation method and system of hardware acceleration-based quantum-resistant digital signature algorithm

This invention relates to the field of quantum-resistant computing and cryptography, and discloses a hardware-accelerated parallel implementation method and system for quantum-resistant digital signature algorithms. The method includes: mapping a private key matrix to the conductance states of a resistive-switched non-volatile memory array; converting the message to be signed into an input vector and loading it into a row-driven circuit; performing matrix-vector multiplication in situ using the memory array, with the operational current obtained by a column-sensing circuit; performing analog-to-digital conversion, post-processing, and rejection sampling judgment on the current, and outputting the signature result. The system includes a central control module, a resistive-switched memory computing core array, a row-driven circuit module, a column-sensing and conversion module, and a post-processing operator cluster. By adopting the above technical solution, this invention can achieve high-performance, low-power, and low-latency parallel processing of quantum-resistant digital signatures, improving throughput and enhancing deployment feasibility in edge and mobile devices.
Owner:XIAN DEAN INFORMATION TECH CO LTD

Digital signature algorithm for verifying revised data

Embodiments of the present disclosure provide a solution for protecting, sharing, verifying, and / or generating data resources (e.g., but not limited to documents). In an exemplary embodiment, the data resource is expressed, expressed, or defined as a plurality of component segments, which are then subjected to hash processing. A Merkel tree representing a complete original version of the data resource is generated, wherein the hash of the segment is a leaf of the Merkel tree. A signer is authorized to sign the root of the tree. The trimmed version of the data resource may then be shared, thereby omitting one or more segments that a data controller wishes to secure or not share in the original form. To verify the authenticity and / or integrity of the revised data resource, sufficient data (e.g., respective hash of the one or more non-shared segments) is provided to a verifier to verify whether the one or more non-shared segments are present in the tree representing the original complete version, and whether there is the authorization signature that signs the root. In some embodiments, the data resource is a code library, and the segment is a portion of computer code that performs a particular subtask. Shared code segments may be selected such that when executed on a processor, the shared code segments in combination perform a larger task.
Owner:NCHAIN LICENSING AG

Just-in-time post-quantum cryptography (PQC) key expansion

The described techniques address issues associated with current post-quantum cryptography (PQC) algorithms by providing a more efficient means of key expansion. Architectures are provided for both an accelerator and an expander, which may be implemented in accordance with any suitable type of cryptographic algorithm that utilizes key expansion, such as PQC algorithms, a key encapsulation mechanism (KEM) algorithm, a Digital Signature Algorithm (DSA), etc. The accelerator architecture enables portions of the expanded key to be generated only when required by a processing block, allowing for the reuse of memory, which allows for a reduction in memory size and thus a smaller footprint (i.e. physical size) compared to conventional architectures. The expander architecture reduces the required interactions and data transfers between the processing block and the key expansion block, thereby reducing the load on the processing block and system components, such as shared buses and bridges.
Owner:INFINEON TECHNOLOGIES AG

Authentication for non-3gpp access using digital signature

The present disclosure relates to authentication for non-3GPP access using digital signatures. In an embodiment, a user equipment (UE) is configured to store a plurality of certificates having different digital signature algorithms, and when accessing a core network through a gateway via non-third generation partnership project (non-3GPP) access, use a first certificate of the certificates to perform authentication with the gateway by computing a first digital signature using a first digital signature algorithm of the digital signature algorithms associated with the first certificate of the certificates, receive revocation information to revoke the first certificate of the certificates in response to a security event regarding the first digital signature algorithm of the digital signature algorithms, and use a second certificate of the certificates to perform authentication with the gateway by computing a second digital signature using a second digital signature algorithm of the digital signature algorithms associated with the second certificate of the certificates in response to the revocation information.
Owner:NOKIA TECHNOLOGIES OY

Software update method, device and digital signature system for vehicle controller

This application discloses a software update method, apparatus, and digital signature system for a vehicle controller, belonging to the field of vehicle technology. The method includes: obtaining an identifier of the target controller, an identifier of the target digital signature algorithm, and a digest of the software update package of the target software; based on the identifier of the target controller and the identifier of the target digital signature algorithm, searching for a private key in a first key pair from a first database, the first database being used to store private keys in key pairs applied for for different controllers and different digital signature algorithms; and generating a first signature file based on the digest of the software update package of the target software and the private key in the first key pair. This application improves the efficiency of key pair retrieval by providing unified online management of key pairs, enabling online querying of private keys in key pairs when generating signature files, compared to offline management and querying of private keys, thereby improving the efficiency of signature file generation.
Owner:CHERY AUTOMOBILE CO LTD

Supervision submission-oriented data encryption storage method and system

ActiveCN120951361ADigital data protectionRegulatory authorityPseudo data
The invention relates to the field of data encryption, and provides a supervision submission-oriented data encryption storage method and system, and the method comprises the steps: firstly obtaining to-be-encrypted data, and carrying out the preprocessing of the to-be-encrypted data, and obtaining a sensitive field; secondly, performing pseudo data filling and reconstruction on the sensitive field to obtain a pseudo data field and a reconstruction packet, and recording a mapping relation among the sensitive field, the pseudo data field and the reconstruction packet; generating a verification code through a digital signature algorithm and the integrity check bit, and embedding the verification code into the reconstruction packet; and finally, symmetrically encrypting the reconstructed packet embedded with the verification code, and storing the encrypted reconstructed packet into a system database. The system comprises a data preprocessing module, a pseudo data filling module, a reconstruction packet construction module, a verification code generation module and an encryption module, and can realize security encryption storage, source authentication, integrity verification and tamper-proof verification of data on the premise of ensuring that sensitive data is not directly exposed, thereby meeting the requirements of supervision departments on the security and compliance of submitted data.
Owner:JIANGSU GUOXIN DIGITAL INTELLIGENCE SERVICE CO LTD

Virtual cryptographic machine container image protection method based on cryptographic technology

The application discloses a virtual cryptographic machine container image protection method based on a cryptographic technique, and belongs to the technical field of information security, and comprises the following steps: a VSM release image production preparation stage, a VSM release image production stage and a VSM release image import stage; after a conventional VSM container image is produced, the conventional VSM container image is encrypted by using a symmetric block cipher algorithm, the image ciphertext is signed by using a digital signature algorithm, the image ciphertext and the signature value are produced into a container image again, and finally, a VSM release image is obtained; then, the VSM release image import stage is carried out. The application can realize the confidentiality, integrity and source reliability protection of the VSM container image; the VSM release image can only be decrypted and used in a cryptographic machine matched with a key, can effectively prevent the image from being analyzed, tampered and counterfeited in the distribution and use process, and guarantees the operation safety of the cryptographic machine.
Owner:成都国泰网信科技有限公司 +1

Method, electronic device and storage medium for upgrading signed firmware

The application discloses a method for upgrading signed firmware, an electronic device and a storage medium, wherein public key parameter information and a digital signature algorithm type are saved to a secure storage by a trusted operating system, a message digest corresponding to the public key parameter information is calculated by the trusted operating system, the message digest is encrypted, and the encrypted message digest is written into a command line parameter, and the signed firmware to be upgraded is verified based on the public key parameter information and the digital signature algorithm type in the secure storage and the encrypted message digest in the command line parameter, and the upgrading is performed only when the verification is successful, so that the security of the public key information is improved, and the encrypted message digest in the command line parameter is used as a communication credential between the trusted operating system, thereby effectively improving the security of the signed firmware upgrading.
Owner:FUZHOU ROCKCHIP SEMICON

Message negotiation method, secret key downloading method and electronic equipment

The invention provides a message negotiation method, which is applied to electronic equipment, the electronic equipment is connected with key distribution equipment, and the method comprises the following steps: sending a starting message to the key distribution equipment; receiving a binding message and a binding message signature of the key distribution equipment; verifying the binding message signature, and constructing a first exchange message based on the binding message after the verification is passed; the first exchange message is signed by using an encryption algorithm to obtain a first exchange message signature, and the encryption algorithm comprises a lattice-based modular digital signature algorithm; sending the first exchange message and the first exchange message signature to a key distribution device, and receiving a second exchange message and a second exchange message signature sent by the key distribution device; and verifying the second exchange message and the second exchange message signature, and completing message negotiation to obtain the first session key and the first message verification code key after the verification of the second exchange message and the second exchange message signature is passed. According to the invention, the security of the message negotiation process is improved, and quantum attacks are resisted.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

An ultra-high-speed post-quantum cryptosystem security communication method for on-orbit intelligent agents

This invention discloses an ultra-high-speed post-quantum cryptographic secure communication method for on-orbit intelligent agents, belonging to the field of communication technology. The method includes: generating an encryption key pair based on a post-quantum cryptographic algorithm and a signature key pair based on a quantum-resistant digital signature algorithm for each on-orbit intelligent agent node; recording the two public key information in a blockchain ledger through consensus; obtaining the receiver's public key information from the blockchain ledger, generating a session seed using a post-quantum key encapsulation method and encapsulating it into ciphertext, digitally signing the ciphertext-containing information using a quantum-resistant signature private key, and then sending it; upon receiving the information, the receiver verifies the signature, confirms the identity's legitimacy, and decrypts to obtain the session seed; based on the session seed, both communicating parties generate a one-time session key and transmit business data with symmetric encryption; after communication ends, a communication audit log is generated based on the transmitted information. This invention improves the security of on-orbit intelligent agent communication using the above method.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD

Safety management method, device and equipment for operation and maintenance data of railway locomotive and medium

PendingCN121966876AEnable safe sharingImprove the level of intelligent operation and maintenanceKey distribution for secure communicationPublic key for secure communicationByzantine fault toleranceKey (cryptography)
The invention relates to the technical field of data security, and provides a railway locomotive operation and maintenance data security management method, device, equipment and medium, and the method comprises the steps: based on a preset node network, employing a hierarchical network architecture to operate a Byzantine fault-tolerant consensus mechanism, and carrying out the consistency processing of a railway locomotive operation and maintenance data block written into a block chain; the method comprises the following steps: for an entity in a railway locomotive operation and maintenance system, generating a unique decentralized identity identifier (DID) based on a first cryptographic algorithm, and signing a document comprising the DID and an entity public key by using a digital signature algorithm so as to construct a target identity management system; and when a data operation instruction is received, verifying the identity credibility of the operation initiator by using the target identity management system, and performing fine-grained access permission verification on the data operation instruction based on a preset permission rule. According to the invention, safe sharing, credible tracing and efficient cooperation of the operation and maintenance data of the railway locomotive can be realized, and the intelligent operation and maintenance level of the railway locomotive is improved.
Owner:CRRC IND INST CO LTD

A group signature method and a signature center group administrator node

The application provides a group signature method and a signature center group administrator node, and the method comprises the following steps: a signature center member node sends a unique identity identifier ID and a first identifier L of the signature center member node in a distributed system to each group administrator node in a distributed group signature system, so that the group administrator node generates a second identifier h based on the ID and the L and applies an SM2 digital signature algorithm, and each group administrator node generates a corresponding third sub-identifier d' i respectively i ; each d′ generates a third identifier d based on each d′ , and obtains an identifier private key isk containing the L, the h and the d, so as to sign and verify a target message based on the identifier private key isk and a master public key mpk of the group signature system. The application can simultaneously solve the problems of low signature verification efficiency caused by high-time-consuming operation of a bilinear pair and privacy leakage of a signer caused by easy malicious attack on a single group administrator, and can improve the efficiency and privacy of a group digital signature scheme.
Owner:BEIJING UNIV OF POSTS & TELECOMM