Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

52 results about "Encryption system" patented technology

An encryption system in which the sender and receiver of a message share a single, common key that is used to encrypt and decrypt the message.

A full-pipelined AES real-time encryption system for high-speed transmission

PendingCN122293307AComputer architectureCarry propagation
This invention discloses a fully pipelined AES real-time encryption system for high-speed transmission, aiming to solve the technical bottlenecks of limited throughput and excessive processing latency in traditional encryption architectures in high-speed networks. The system mainly includes a data input buffer module, a fully pipelined encryption operation module, a round key pre-computation module, and a data output driver module. The core of this invention lies in the operator-level hardware reconstruction of the AES underlying algorithm: the S-box nonlinearity is replaced and embedded in the distributed ROM of the FPGA to achieve zero-clock-cycle asynchronous table lookup, and a carry-free XOR tree architecture based on the XTime operator is used to reconstruct column hybrid operations, eliminating deep carry propagation chains.
Owner:EAST CHINA UNIV OF SCI & TECH

Method for pseudo-random number generation for information encryption

A method of generating at least one encryption key (130) for encrypting data (142), a method of data transmission between at least two communication systems (136, 138), a method of encrypting data (142) and a method of decrypting encrypted data (144) are disclosed. Further disclosed are an encryption key generating device (110), a system (134), a data encryption system (148) and a data decryption system (150). The method of generating at least one encryption key (130) for encrypting data (142), specifically for data transmission over an insecure channel, comprises:blending at least two materials (114) according to at least one item of blending information by using a blending device (112), thereby generating at least one blend (120);ii. detecting at least one material property (124) of the blend (120) by using at least one detector (126); andiii. transforming the material property (124) into the encryption key (130) by using at least one data processing device (132) configured for applying at least one transformation algorithm to the material property (124).
Owner:BASF SE

Secure and Encrypted Garbage Collection in a Chunk Storage System

A system can store a first encryption key for a first data chunk of a log filesystem in a first virtual chunk extent that comprises first virtual pointers that point to the first data chunk, wherein the first data chunk is encrypted with the first encryption key. The system can, based on performing garbage collection on the first data chunk, to produce surviving data that remains from the first data chunk after the garbage collection, move the surviving data to a second data chunk, wherein the surviving data is encrypted in the second data chunk with a second encryption key, wherein the second encryption key is stored in a second virtual chunk extent corresponds to the second data chunk, and delete the first virtual chunk extent while refraining from deleting the first data chunk, wherein, after the deleting, the first encryption key is deleted.
Owner:DELL PROD LP

Proxy interception and double encryption system and methods

A method of enabling custom cryptography is provided. The method can include sending, by a first computing device and to a second computing device, instructions to initiate a proxy. The proxy can be configured to intercept a message of a user agent. The user agent may be associated with the second computing device. The proxy can be further configured to perform custom cryptography based on the message to obtain a modified message. The custom cryptography may comprise post-quantum cryptography. The proxy can be further configured to send the modified message to at least one of the user agent, a reverse proxy, or a third computing device. The post-quantum custom encryption and / or decryption can comprise Quantum Secure Layer (QSL), Post-Quantum Transport Layer Security (PQTLS), Kyber, SABER, Enhanced McEliece, RLCE, or a National Institute of Standards and Technology (NIST) candidate post-quantum algorithm.
Owner:QUSECURE INC

Electromagnetic and power noise injection for hardware operation concealment

A method for operation hiding for an encryption system includes randomly selecting which of at least two encryption operation blocks receives a key to apply an effective operation on data and output a result used for a subsequent operation. Noise can be added by operating other encryption operation blocks of the at least two encryption operation blocks with a modified key. The modified key can be generated by mixing the key with a block unique identifier, a device password, a slow adjustment output of a counter, or a combination thereof. In some cases, input data of the other encryption operation block can be transformed by mixing the input data with the block unique identifier, the device password, the counter output, or a combination thereof, thereby adding noise to the encryption system. An encryption system with operation hiding can also include a distributed (across chip) or interleaved arrangement of sub-blocks of the encryption operation blocks.
Owner:ARM LTD

Systems and methods for selective encryption of sensitive image data

Disclosed is a selective encryption system that selectively encrypts sensitive image data within frames of a video stream and compresses other insensitive image data within the frames in order to generate and distribute a partially encrypted video stream that protects the sensitive image data without the time, energy, resource, and size penalty associated with encrypting all image data in all frames of the video stream. The system parses a video stream image into different regions that each contain different image data. The system detects first regions that contain the sensitive image data, encrypts the sensitive image data in the first regions, and compresses the image data in other second regions without encryption. The system distributes a selectively encrypted frame of the video stream that includes the encrypted image data for the first regions and the compressed image data for second regions.
Owner:RINGCENTRAL INC

A computer technology-based optical communication data security encryption system and method

PendingCN122406929AComputer networkEngineering
This invention discloses a computer-based optical communication data security encryption system and method, including a track plate and a support frame. A working platform is movably mounted on top of the track plate. A set of toothed rods is fixed at each end of the bottom of the working platform. Two sets of gears are installed in the middle of the track plate, with the toothed rods and gears forming a meshing connection. A hook is welded to the middle of the left side of the working platform. A mounting base is fixed to the side of the track plate near the building's exterior wall, and a winch is installed at the mounting base. A steel wire rope is fixed between the winch and the hook. This invention, by incorporating a working platform, toothed rods, gears, mounting base, hook, steel wire rope, and winch, achieves the function of automatically retracting and extending the steel wire rope during the platform's forward and backward movement. This ensures smooth platform movement while providing safety protection, thus improving the construction safety of the building's exterior wall.
Owner:李翔

Communication method, system and associated architecture

PendingFR3170769A1TelecommunicationsEncryption system
Communication Method, System, and Associated Architecture The present invention relates to a communication method between a sending node and a target node, via an encryption system comprising a plurality of gateways directly connected to each other via IPsec tunnels, each node being connected to a gateway. The communication method comprises a transmission phase (P2) including: the sending (S202) of a data packet by the sending node to the gateway to which it is connected, called the sending gateway; the encryption (S206) of the data packet by the sending gateway; and the transmission of the encrypted data packet. The data packet is marked (S204) by the sending gateway with a mark corresponding to an IPsec tunnel to be used, and the transmission (S206) of the encrypted data packet by the sending gateway is carried out through the IPsec tunnel corresponding to the mark of the data packet. Figure for the abstract: Figure 4
Owner:THALES SA

A quantum key cloud-based encryption system unified management and key distribution method

PendingCN122372194ACiphertextEngineering
This invention relates to the field of network security technology, and in particular to a unified management and key distribution method for encryption machines based on quantum key cloud. The method includes: receiving a registration request and extracting the device name, authentication information, and timestamp; completing identity authentication, authorization management, and generating device quantum information; subsequently collecting online status data and determining the device usage status corresponding to the central processing unit, memory, disk, and network port; generating anomaly status judgment results by comparing authentication information and communication status; then outputting alarm information, blocking illegal connections, verifying permissions, matching key identifiers, and distributing quantum ciphertext data; and completing quantum key acquisition, generating acquisition confirmation messages, data encryption and decryption, key update management, and resetting password verification and factory reset processing. This invention significantly improves the security, real-time performance, and closed-loop autonomous capability of unified management of encryption machines.
Owner:CONCAVE SHIELD (BEIJING) TECH CO LTD

Systems and methods using emulation for end to end encryption

ActiveUS12675594B2End-to-end encryptionBusiness data
Methods and system implement solutions for integrating encryption and emulation into native database formats and / or architectures. “Native” database is used to describe a database that has not been designed for end to end encryption, an off the shelf database deployment, and / or a commercially available database. According to some embodiments, various encryption systems and methods employ emulation operations to enable a native database and native database functions to leverage full encryption primitives. Various aspects integrate emulation operations into standard database implementations, where the emulation enables native database functions to operate on entirely encrypted data.
Owner:MONGODB INC

A data security encryption system for passbook printing based on a large model

This invention discloses a data security encryption system for passbook printing based on a large-scale model, comprising: a data acquisition and encapsulation module for acquiring the passbook data to be printed; a semantic parsing and field-level encryption strategy generation module for inputting the data to be encrypted into an LLaMA semantic model for semantic parsing; a session establishment module for two-way authentication; a task context generation and anti-replay management module for constructing a task context; a field-level encryption and binding module for deriving a task key and obtaining ciphertext for sensitive fields; an integrity verification and signature module for generating an integrity verification digest and a print request message; and a device-side verification, decryption, and printing module for decrypting the ciphertext for sensitive fields and executing passbook printing. This invention combines large-scale model semantic analysis technology with multi-channel encryption and anti-replay mechanisms, possessing advantages such as high intelligence, fine-grained encryption, strong anti-attack capabilities, and applicability to multi-terminal scenarios.
Owner:SHENZHEN CATIC INFORMATION TECH IND

A high-value data encryption system and method in a localization environment

This invention discloses a domestically developed encryption system and method for high-value data in the field of data encryption technology, comprising: environment preparation: installing a Docker runtime environment on a Kylin operating system and ensuring that the SELinux security subsystem is in forced mode; encrypted volume preparation: after completing the environment preparation, creating a LUKS encrypted volume for physical storage space on the host machine, initializing the volume using an encryption key, and creating a file system; security policy configuration: after completing the encrypted volume preparation, creating and loading a custom SELinux policy module, wherein the defined security rules are configured to: deny access operations of the host machine process domain to the LUKS encrypted volume device file, while allowing access operations of the Docker container process domain to the LUKS encrypted volume device file. This invention achieves high-value data encryption based on Docker containers and LUKS encrypted volumes in a Kylin operating system environment, realizing strong encrypted data storage.
Owner:SIWEI SHIJING TECH (BEIJING) CO LTD

A method, equipment and medium for supply chain security management in rural cooperatives

PendingCN122316676AAttackFinancial transaction
This application discloses a method, device, and medium for supply chain security management in rural cooperatives. The method includes: dynamically generating temporary access keys by extracting and quantifying business context factors such as season, logistics, transactions, and land status to achieve fine-grained access control; analyzing cross-module business feature tensors using quantum support vector machines to achieve associated abnormal behavior detection and risk classification; triggering a graded collaborative response mechanism based on risk levels to implement precise protection while ensuring business continuity; and finally achieving full-link verifiable auditing based on quantum-secure blockchain. This application deeply integrates a quantum-secure encryption system with multimodal business data in the supply chain, constructing a three-layer closed-loop security architecture of "quantum control, business anomaly detection, and dynamic resource optimization." This architecture can resist quantum computing attacks, achieve synergistic optimization of security strategies and business efficiency, and provide rural cooperatives with a supply chain management platform that offers forward-looking security and high operational availability.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Method for detecting algebraic confusion properties and attack resistance boundaries of cryptographic systems based on topological homology invariants

This invention discloses a method for detecting algebraic confusion characteristics and anti-attack boundaries of cryptographic systems based on topological homology invariants, belonging to the field of cryptographic security technology. The aim is to address the technical problems of existing anti-attack capability detection methods, which rely on empirical testing, cannot quantify algebraic structure characteristics, and cannot predict security boundaries. The method includes: constructing a chain complex topological model of the algebraic structure of the cryptographic system; numerically solving for the homology group and the topological invariant Betti number; determining algebraic confusion characteristics and anti-attack capabilities based on the Betti number; scanning and locating critical points of the anti-attack boundary; and hierarchical triggering of early warning and adaptive structural optimization. This invention provides an independent and controllable quantitative evaluation scheme for compliance testing of national cryptographic algorithms, enabling early prediction and closed-loop protection of the anti-attack boundary of cryptographic systems. It can be modularly embedded into domestic cryptographic testing platforms, adapting to various scenarios such as national cryptographic algorithms and post-quantum cryptography, and has strong engineering applicability.

Method for burning identification code of terminal, burning system, reading method and reading system

ActiveCN114691154BEngineeringSecurity level
This invention relates to the field of terminal security protection technology, providing a terminal identification code burning method, burning system, reading method, and reading system. The terminal identification code burning method includes: encrypting an initial key using an encryption system to obtain a key file; encrypting a plaintext identification code using the initial key to obtain production data; and burning the production data and key file to the terminal. This terminal identification code burning method uses an initial key to encrypt the plaintext identification code and securely burns the encrypted production data to the terminal. Even if an unauthorized user obtains the production data during the burning stage, they cannot decrypt the plaintext identification code, thus ensuring data security during the burning process. Furthermore, the plaintext identification code can only be decrypted by calling the decryption interface after the terminal is powered on. Therefore, this terminal identification code burning method increases the difficulty and cost of reverse engineering, enhancing the security level of the device.
Owner:MIDEA GROUP CO LTD +1

Anti-fake system for color-coated products and double-layer encryption and decryption method thereof

The application discloses a color-coated product anti-counterfeiting system and a double-layer encryption and decryption method thereof, and specifically comprises the following steps: in the encryption process, the first layer uses the SM4 national encryption algorithm to encrypt plaintext; the second layer derives a key based on the PBKDF2, and performs three rounds of confusion encryption on the first layer ciphertext, including character replacement and position replacement, to generate second layer ciphertext; finally, a check code is generated based on the derived key, and the last character of the second layer ciphertext is replaced to form the final ciphertext; in the decryption process, which is the reverse process of the encryption process, the same derived key is generated and the check code is verified, and the first layer ciphertext is obtained through reverse confusion processing, and then the plaintext is restored by using the SM4 decryption. The application constructs a double-layer encryption system of the national encryption algorithm and a self-defined confusion structure, meets the national encryption regulation requirements, greatly improves the randomness and anti-cracking ability of the anti-counterfeiting code through multiple rounds of confusion and integrity check, effectively prevents data forgery and tampering, and the ciphertext length is suitable for two-dimensional code coding.
Owner:SHANGHAI YUANZHI INFORMATION TECH

An Access Control-Based Unmanned Aerial Vehicle (UAV) Communication Link Encryption System

This invention discloses an access control-based encryption system for UAV communication links, comprising: a link establishment request module for initiating a communication link establishment request; an identity authentication module for performing identity authentication; an access decision module for performing pre-access authorization assessment using an improved UCON+ model; a key authorization module for outputting session key authorization credentials and session key materials to establish the communication link; a link encryption module for performing control operations based on the session key authorization credentials and performing encryption and integrity protection; a status verification module for collecting link status and environmental status and generating obligation execution evidence; a continuous control module for performing continuous authorization assessment during use; and a post-use audit module for performing post-use processing. This invention employs access control-driven link encryption to achieve encryption of UAV communication links.
Owner:BEIJING XIONGFENG TECHNOLOGY CO LTD

Method, device, computer device and storage medium for data encryption

The application relates to a data encryption method, device, computer equipment, storage medium and computer program product. The method is applied to a cache node in an encryption system, the encryption system at least comprising the cache node and a cloud server with a cloud port, and the method comprises the following steps: obtaining to-be-encrypted data from the cloud server through the cloud port and caching the to-be-encrypted data; determining a target encryption algorithm set by the cloud port, generating a target key based on the target encryption algorithm, and performing encryption processing on the to-be-encrypted data through the target key to obtain encrypted data; performing key matching on the target key and a to-be-matched key to obtain a key matching result; the to-be-matched key is generated by the cloud port based on the target encryption algorithm; and in the case that the key matching result is key matching success, transmitting the encrypted data to the cloud server through the cloud port, so that the cloud server stores the encrypted data. The method can improve the security of data encryption.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Low resource aes encryption system and method based on heterogeneous computing

This invention discloses a low-resource AES encryption system and method based on heterogeneous computing, belonging to the field of information security hardware acceleration technology. Based on the traditional AES algorithm, a fixed-round multiplexing control module and an external dedicated XOR circuit are introduced. The fixed-round multiplexing control module sequentially executes SubBytes and ShiftRows transformations within the FPGA. By employing in-round operation multiplexing and state register sharing, high-level reuse of logic resources is achieved, significantly reducing the FPGA's lookup table usage. By decomposing the MixColumns operation into a two-stage pipeline structure of internal FPGA xtime transformation and external XOR circuit, and using an external 74LVC574 register to synchronize the data path in real time, precise matching of computational latency and area optimization are achieved. This system implements secure and reliable AES encryption with limited hardware resources. Combined with a dynamic masking mechanism, effective protection of intermediate states is achieved, significantly enhancing the system's resistance to side-channel attacks and reducing hardware costs and resource overhead while ensuring throughput.
Owner:NANJING UNIV OF POSTS & TELECOMM

A software and hardware bidirectional adaptive linkage global private data isolation sandbox system and method

PendingCN122339836AComputer hardwareThird party
This invention discloses a comprehensive private data isolation sandbox system and method with bidirectional hardware and software adaptation, belonging to the field of terminal data security isolation technology. Addressing the shortcomings of traditional isolation solutions—such as hardware-software separation, susceptibility to tampering and circumvention, and lack of closed-loop protection—this invention constructs a bidirectional linkage architecture where hardware constrains software and software adapts to hardware: the hardware provides physical isolation boundaries, a local independent encryption system, and a unique identity trust root; the software adaptively matches hardware characteristics, constructs a closed-loop private network domain based on a unified user identity, automatically distinguishes between internal and external networks, and executes unidirectional flow control over the external network. Time-limited, targeted external transmission is achieved through joint hardware and software authentication, with automatic isolation restoration upon transmission completion. It supports offline operation and unmanned maintenance, privatizes all domain permissions, and blocks third-party control channels. It is compatible with integrated hardware and software and lightweight pure software architectures, offering superior security and versatility compared to existing technologies, and is suitable for data security protection of AI computing clusters, distributed terminals, and classified devices.
Owner:薛梁

Systems, devices, and / or methods for managing cryptography via employing dual independent random coding between sender and receiver

Certain exemplary embodiments provide an unbreakable encryption system and method through the use of dual, independent random coding between sender and receiver and a three-step transmission process. Said system also incorporating within the encryption method the addresses of both sender and receiver such that they are undiscoverable by an unintended party.
Owner:WALSH WILLIAM J +1

Nonlinear optical metasurface and design and preparation method thereof, image encryption system

The application discloses a nonlinear optical superstructure surface and a design and preparation method and an image encryption system thereof. The nonlinear optical superstructure surface comprises a C3 metal layer, a dielectric layer and an ENZ layer; the dielectric layer comprises a dielectric film with multiple step thicknesses; the C3 metal layer comprises a plurality of metal plasmonic superstructure units with three-fold rotational symmetry; the dielectric layer is located on the surface of the ENZ layer, and the C3 metal layer is located on the surface of the dielectric layer. The intensity of nonlinear emergent light is regulated through the dielectric film with multiple step thicknesses, so that an encrypted gray-scale image is read based on the nonlinear emergent light field distribution, and the image encryption application is realized. Moreover, the nonlinear optical superstructure surface provided by the application presents a uniform light field distribution under linear optical measurement, does not leak the encrypted information, and improves the confidentiality and decryption difficulty of the nonlinear optical superstructure surface image encryption.
Owner:SOUTHERN UNIVERSITY OF SCIENCE AND TECHNOLOGY

Parallel implementation method and system of quantum-resistant encryption algorithm based on hardware acceleration

PendingCN122372180AAlgorithmAttack
This invention relates to the fields of information security and quantum-resistant computing, and discloses a hardware-accelerated parallel implementation method and system for quantum-resistant encryption algorithms. The method includes: configuring a parallelized quantum-resistant encryption core computing array; deploying a spiking neural network control module that simulates the random firing behavior of biological neurons, and connecting it to a power-compensating execution unit; monitoring key computing cycles and activating the module; using the non-periodic random pulses generated by the module to drive power consumption perturbation, deeply fusing instantaneous power consumption and noise; and dynamically adjusting neuron parameters through a feedback mechanism to make the total power consumption exhibit random characteristics similar to biological neural electrical signals. Through the above scheme, this invention disguises the encryption power consumption trajectory as random noise, resisting physical attacks such as differential power analysis without sacrificing computational performance, thereby improving the physical layer security and energy efficiency of the quantum-resistant encryption system.
Owner:XIAN DEAN INFORMATION TECH CO LTD

A ste encoding construction method based on proportion philosophy origin and national security encryption system

PendingCN122293406ATimestampAlgorithm
This invention discloses a STE (Spectrum-Tensor-Encoding) encoding construction method and a national security encryption system based on the fundamental principles of proportionality, solving the problems of fixed encryption keys, reproducible encoding, single security levels, and poor chip and AI scenario adaptability in traditional encryption. The technical solution uses the fundamental principles of proportionality as its underlying axiom, defining the golden ratio coefficient α and the fundamental reference P₀ to generate a hierarchical set of fundamental ratio parameters. It combines a unique user identifier with hash operations to generate uncopyable STE encoding primitives, which are then recursively concatenated and checked against CRC to construct multi-level STE encoding. A timestamp and the fundamental ratio are introduced to generate a 128-bit dynamic key, achieving a three-dimensional binding of encoding, key, and time. This invention extends a dedicated encryption instruction set at the chip level and implements weighted encryption and trusted verification of the inference link at the AI ​​large-scale model level. It possesses fundamental uniqueness, dynamic anti-cracking capabilities, hardware-level acceleration, and full-link AI encryption capabilities, supporting national-level information security, vehicle networking, government communications, and large-scale model security deployment. Its security strength and operational efficiency are significantly superior to traditional symmetric / asymmetric encryption systems.
Owner:ZHUHAI GONGZHENG TECHNOLOGY CO LTD

A traffic image low-bandwidth network transmission compression encryption system and method

The application discloses a traffic image low-bandwidth network transmission compression encryption system and method, relates to the technical field of traffic information transmission control, and comprises a traffic image acquisition module, which is used for acquiring continuous traffic image data and organizing time sequence traffic image data in accordance with the time sequence of acquisition. In the application, a structure region division processing is performed on the time sequence traffic image data through a semantic structure separation module, the traffic image is divided into a semantic structure region and a background region, and semantic structure expression data and background texture expression data are respectively constructed in a hierarchical expression construction module. In the semantic structure expression construction process, a skeleton fidelity adjustment coefficient is introduced, a fidelity reconstruction processing is performed on the skeleton geometric description, the spatial consistency of the structure region is kept unchanged in the compression expression process, the corresponding relationship between the structure region and the semantic category is kept unchanged, the structure region boundary definition and the background texture continuity are kept at the same time.
Owner:XINJIANG HENGYE DACHENG SOFTWARE TECH CO LTD

Hybrid hierarchical encryption system

A hybrid cryptographic scheme for a network of nodes, in particular an IoT network, composed of a first subset and a second subset of separate nodes, the computing resources of the nodes of the first subset being greater than the computing resources of the nodes of the second subset, the scheme comprising a first functional cryptographic scheme deployed on the first subset of nodes and a second functional cryptographic scheme deployed on the second subset of nodes, a cryptographic primitive at the root of the second cryptographic scheme generating a pair of private and public master keys from a seed, the seed being obtained by a connection cryptographic primitive from at least the private key of an end node of the first subset, the connection cryptographic primitive being a one-way function.
Owner:COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES

Encryption and decryption method, device and system

The application discloses an encryption and decryption method, device and system, and belongs to the technical field of cryptography; considering that each user in the system is assigned with a specified access control strategy and attribute, the access control strategy of the user determines which type of receiver he can send a message to in the encryption process, and the attribute of the user determines which sender he can receive a message from; the application expresses the access control strategy based on a linear secret sharing matrix (LSSS matrix) to realize flexible expression of an arbitrary access strategy and has strong expression capability; on the basis, the application generates an encryption key embedded with a sender access control strategy for the sender, so that the fine-grained control of information flow in the system is realized by assigning corresponding access control strategies and attributes to different users in the communication process, the flow direction of the information flow of the encryption system can be better controlled, and the behavior of the user can be more conveniently and efficiently managed.
Owner:HUAZHONG UNIV OF SCI & TECH