Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

509 results about "Encryption system" patented technology

An encryption system in which the sender and receiver of a message share a single, common key that is used to encrypt and decrypt the message.

Method and system for encrypting sensitive data based on large model

The invention discloses a method and system for encrypting sensitive data based on a large model, relates to the field of data security, and solves the problem that a traditional fixed encryption strategy lacks dynamic adaptability. An encryption strategy container is generated through a data evaluation server, an evaluation module analyzes data content characteristics through a large model, a multi-dimensional sensitivity evaluation matrix and a use scene-risk level association model are established, and meanwhile the performance of an encryption module is tested; calculating a risk level according to a data sensitivity weight and a scene risk coefficient, triggering an alarm if the risk level exceeds a threshold value, otherwise, comparing a standard scene risk model to adjust encryption algorithm parameters, and generating a scene self-adaptive dynamic encryption strategy in combination with an encryption efficiency curve after performance compensation; and finally, the encryption gateway executes encryption. The method can improve the resource utilization rate through dynamic adaptive encryption, guarantees the stable efficiency through real-time performance compensation, improves the perspectiveness through intelligent prediction, reduces the safety risk and management cost through whole-process protection, and is suitable for a multi-industry sensitive data protection method.
Owner:SICHUAN UNIV JINCHENG INST

Adaptive encryption system based on AI intelligent safety management

The invention discloses a self-adaptive encryption system based on AI intelligent security management, which relates to the technical field of information security, and comprises a data acquisition module, a risk assessment module, an encryption algorithm selection module, a key generation and management module, an encryption execution module and an encryption effect feedback module, the data collection module is used for collecting various data in a system operation environment, including but not limited to network flow data, equipment state data and user behavior data; and the risk assessment module analyzes the collected data based on an AI algorithm and assesses the security risk level faced by the current system. The operation environment data is comprehensively collected through the data acquisition module, the security risk level is evaluated in real time through the risk evaluation module based on the AI algorithm, the adaptive encryption algorithm can be dynamically selected according to the risk, the defect that a traditional encryption system is fixed in strategy is overcome, and encryption pertinence and effectiveness are improved.
Owner:HEBI CRYPTOADVANCED TECH RES INST

Multi-party collaborative signature management method and system based on key segmentation technology

The invention discloses a multi-party collaborative signature management method and system based on a key segmentation technology, and relates to the technical field of fragmentation encryption, and the method comprises the steps: initializing data in an encryption system, collecting behavior data when a key anomaly occurs in history, deploying an AI anomaly detection model, generating a master key through a distributed key generation protocol, and generating a multi-party collaborative signature in the encryption system; deriving time by using a hierarchical deterministic algorithm, segmenting a master key to form key fragments, and distributing each fragment to different nodes; formulating a periodic rotation triggering mechanism; calculating an abnormal score of each node, judging whether each node has an abnormal risk or not, and marking the abnormal risk; for the marked nodes with the abnormal risk, fragments are redistributed for alternation; dynamically adjusting the threshold according to the abnormal score; a client initiates a signature request, abnormal nodes are eliminated, fragment node aggregation is screened, and collaborative signature is carried out.
Owner:GLANCE DIGITAL TECH (JIANGSU) CO LTD

Short video active defense encryption system based on device fingerprint and dynamic confusion field

The invention relates to the technical field of short video encryption, and discloses a short video active defense encryption system based on a device fingerprint and a dynamic confusion field, and the key point of the technical scheme is that the system comprises a device fingerprint generation module, a mother video encryption module, a slice encryption module, a behavior recognition and defense module and an encryption logic update regulation and control module. The system generates a unique device fingerprint hash value through a multi-modal feature, generates a dynamic confusion field in combination with a chaotic system and a quantum random number, realizes differential encryption of a mother video and slices, and is embedded with zero-knowledge consanguinity proof to support traceability verification. The behavior recognition and defense module monitors user behaviors in real time and dynamically adjusts a confusion strategy or triggers an active defense mechanism, and the encryption logic updating regulation and control module optimizes the updating frequency according to playing data and reduces the batch crawling risk. According to the invention, the security and anti-attack capability of the short video content can be effectively improved.
Owner:HANGZHOU POPCORN EAGLE EYE TECH CO LTD

Data encryption system for evidence collection and storage based on block chain technology

The invention relates to the technical field of block chains, and discloses a data encryption system for evidence collection and storage based on a block chain technology. According to the data encryption system for evidence collection and storage based on the block chain technology, a hash value can be generated based on a timestamp of data chaining, so that integrity of storage data is regulated and controlled, data tampering detection is realized, a user permission access range can be regulated and controlled in combination with a key distribution mechanism, sensitive data leakage is effectively prevented, and user experience is improved. The consistency of the encryption step is verified according to the intelligent contract execution logic, the multi-node synchronization error is eliminated, the error of the encrypted data storage link is verified through the Hash verification algorithm, and the consistency of the block data is ensured.
Owner:薄同言

Image encryption system and method in smart power grid environment

The invention discloses an image encryption system and method in an intelligent power grid environment, and aims to solve the problem that an encryption strategy is static and lacks self-adaptive capability in the prior art. The image encryption system comprises terminal equipment, edge equipment and central equipment, and a dynamic key generation unit on the terminal equipment generates a dynamic key by cooperatively utilizing a physical unclonable feature (PUF) of the equipment and a real-time load of a power grid; the hierarchical encryption unit performs encryption of different intensities based on image content complexity. A topology sensing transmission module of the system analyzes power grid topology by using a graph neural network (GNN) and dynamically optimizes transmission. In addition, the image encryption system further integrates low-density parity check code encoding and decoding and a self-adaptive decryption strategy so as to enhance the anti-interference capability. According to the invention, by constructing a sensing, decision-making and execution integrated adaptive security system, the security, high efficiency and robustness of smart grid image data transmission are significantly improved.
Owner:EASTERN GANSU UNIVERSITY

Contextual orchestration and scoped memory protocol with decentralized memory wallet for adaptive artificial intelligence systems

The embodiments disclose a cryptographically governed system for contextual memory management in artificial intelligence including a Contextual Orchestration and Scoped Memory Protocol (COSMP) and a Decentralized Memory Wallet (DMW), which enforce secure, auditable, and policy-driven access to AI memory. Traditional token-based memory tracking is replaced by memory capsules secure data units with embedded access policies and tamper-evident logs 5400 organized via a distributed ledger. Access control is managed through decentralized identifiers (DIDs) and private cryptographic keys, ensuring that all memory interactions are signed, verifiable transactions. This architecture establishes a universal trust layer for AI, enabling post-hoc compliance checks and privacy-preserving audits. Applicable across domains such as national security, healthcare, and autonomous systems, the invention enforces rigorous behavioral constraints and access governance within AI memory and decision-making processes.
Owner:LEWIS SADEIL JAMES +1

Education robot-based intelligent system and method for fusing mental health evaluation in interest scene

PendingCN120636769AEnsemble learningDigital data protectionNumber generatorPsychometric testing
The invention discloses an intelligent system and method for fusing mental health evaluation in an interest scene based on an education robot. The system realizes non-intrusive mental health assessment by constructing a technical architecture of'multi-modal biological feature anonymization-quantum hybrid encryption-federated learning privacy protection-dynamic risk assessment '. The method is characterized by comprising the following steps of: (1) generating irreversible biological characteristic codes by adopting a chaos random number generator, and realizing anonymized association by combining a double hash chain technology; (2) designing a quantum enhanced hybrid encryption system, fusing an SM4 algorithm, NTRU post quantum cryptography and quantum key distribution; (3) developing a dynamic scene generator, and naturally fusing psychological test questions into interest topics by using a generative adversarial network (GAN) and a curiosity engine; (4) constructing a multi-modal emotion analysis system, and combining an LSTM + CNN hybrid model to realize physiology-behavior-voice data fusion analysis; and (5) deploying a federated learning framework, and protecting model training data through differential privacy noise injection (epsilon = 0.5).
Owner:张景飞

Lightweight hopping key encryption system based on national cryptographic algorithm

The invention discloses a lightweight hopping key encryption system based on a national cryptographic algorithm, relates to the technical field of data communication encryption, and solves the problem that an initial key and a hopping key are difficult to generate; a key hopping mode is difficult to analyze so as to detect an abnormal state; intelligent contract automatic key management is difficult to carry out; plaintext data is difficult to encrypt according to the analysis security index; the data verification index is difficult to analyze for data verification after the hopping key is decrypted; the operation state is difficult to monitor in real time to detect an attack mode; and the defense capability and the key hopping validity are difficult to assess, and the overall security assessment value is difficult to assess. According to the method, the state cryptographic algorithm is applied, the hopping key mechanism is combined, the key hopping rule is automatically executed by using the intelligent contract, and the overall security assessment value is comprehensively assessed by monitoring the running state.
Owner:NAVAL UNIV OF ENG PLA +1

Systems and methods for threshold cryptography for cloud-based software-implemented hardware security modules

Disclosed herein are systems and methods for threshold cryptography for cloud-based software-implemented hardware security modules. In an embodiment, an encryption system collects at least a decryption-threshold number of private-key shares from a secure store, where the private-key shares correspond to a public key generated in a first secure enclave as part of a secret key set, which also includes a first plural quantity of the private-key shares. The encryption system obtains an ephemeral-hardware-security-module-(eHSM)-encryption key by decrypting the collected private-key shares. The encryption system initializes, in a second secure enclave, a second instance of a first eHSM. The initialized second instance of the first eHSM is encrypted with the obtained eHSM-encryption key.
Owner:ASSA ABLOY AB

Distributed data security storage and encryption system based on AI technology

The invention relates to a distributed data security storage and encryption system based on an AI technology. The system comprises a data acquisition and preprocessing layer used for acquiring original data and preprocessing the original data to obtain an identifiable data object; the AI identification and strategy decision layer is used for identifying data features of identifiable data objects based on an interpretable AI model to obtain an encrypted instruction packet; the encryption execution and distributed storage layer is used for performing encryption storage processing on the original data content according to an encryption instruction packet to obtain data access interface information; and the dynamic access control layer is used for obtaining user information in response to a data access request instruction of a user, recombining and decrypting the data by using the data distribution mapping index based on the access control strategy table, and returning a plaintext data fragment. By adopting the system, a high-strength, differentiated and multi-level security mechanism can be realized through the AI, intelligent encryption strategy decision is carried out, and the security requirements of multiple scenes and multiple types of data are met.
Owner:HEFEI CITY UNIV

Encryption transmission and self-healing control cooperation system facing virtual power plant terminal

The invention discloses a virtual power plant terminal-oriented encryption transmission and self-healing control cooperative system, which comprises a dynamic encryption module, a hierarchical encryption system is constructed on the basis of a quantum chaos sequence and a national secret SM9 algorithm, a dynamic session key is generated in real time through an edge node, and terminal power data is subjected to hierarchical encryption; the self-healing control module integrates a block chain distributed account book and a deep reinforcement learning model, constructs a health degree portrait of the terminal equipment in real time, monitors a link state through a topology sensing algorithm, predicts a fault propagation path, and triggers communication link reconstruction and computing resource elastic scheduling for self-healing; the collaborative optimization module constructs an optimization objective function, balances encryption strength and self-healing efficiency, adopts a quantum topology photonic crystal optimization algorithm to determine a weight coefficient in the optimization objective function, and realizes global optimal matching of an encryption-self-healing strategy; and the edge computing node performs terminal-edge cloud cooperative training according to the global optimal matching strategy of the encryption-self-healing strategy.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Equipment identity authentication and data encryption method and related equipment thereof

The invention discloses an equipment identity authentication and data encryption method and related equipment thereof, and the comprehensive effects of identity credibility, key security superposition and channel encryption capability enhancement are realized by introducing a mixed key system and a double digital signature mechanism into an equipment identity authentication and data encryption process. Meanwhile, a national cryptographic algorithm and a post-quantum algorithm are adopted, and the two cryptographic systems cooperate in parallel in an authentication and encryption link, so that the whole system has a robust anti-attack ability in both a traditional computing environment and a potential quantum computing environment, the accuracy of identity authentication is ensured by a dual signature mechanism, and the counterfeiting difficulty and tampering detection ability are remarkably improved. According to the method, the bidirectional verification chain is constructed in the authentication process, the safety is guaranteed by using the mixed key in the session stage, the safety robustness and the expandability of the system are improved through multi-layer protection, and the whole-process protection of the identity, the key and the data is realized, so that the safety robustness and the expandability of the system are integrally improved.
Owner:SHENZHEN DIGITAL CERTIFICATE AUTHORITY CENT CO LTD

Low-power-consumption hardware encryption system based on geological disaster monitoring scene

The invention relates to the field of hardware encryption, and discloses a geological disaster monitoring scene-based low-power-consumption hardware encryption system, which comprises a layered architecture module for constructing a terminal sensing layer and a cloud platform layer, generating a three-dimensional risk thermodynamic diagram, and carrying out short-term early warning model and emergency deduction; the encryption and decryption module is used for carrying out multi-dimensional identity verification based on protocol layering and national secret algorithm fusion, carrying out dynamic management and eavesdropping monitoring on a secret key, optimizing a data processing flow, and establishing a secure channel to dynamically negotiate whether encryption or decryption is needed; the key management module is used for implementing a triple binding mechanism, carrying out processing and risk assessment on the monitoring data, and carrying out key backup and recovery by adopting a dynamic key period according to a generated risk level; and the safety protection module is used for performing intelligent management on the power consumption of the system based on the active state of the system, selecting a compression strategy according to the data type by adopting a dynamic compression algorithm, performing safety monitoring on hardware and firmware, performing intrusion monitoring on the system and performing automatic repair.
Owner:中国地质环境监测院(自然资源部地质灾害技术指导中心)

Wireless transmission anchor rod multipoint stress sensor system

The invention discloses a wireless transmission anchor rod multipoint stress sensor system, which relates to the technical field of intelligent monitoring of geotechnical engineering and comprises a data sensing and acquisition module, a data processing and transmission module, a data receiving and storage module, a data analysis and decision module and a user interaction and management module. The technical key points are as follows: multi-protocol adaptive communication and quantum encryption are carried out, a multi-protocol adaptive communication stack is based on an improved near-end strategy optimization algorithm, intelligent switching of communication protocols can be completed in an extremely short time according to an actual environment, and the intelligent switching of the communication protocols can be completed in scenes such as mountainous area tunnels with complex and changeable signals. The problem that transmission of a traditional single protocol is prone to being interrupted is effectively avoided, continuity of data transmission is guaranteed, meanwhile, the integrated quantum key distribution unit adopts a BB84 protocol and is combined with a two-factor encryption system, data transmission safety is remarkably improved, quantum attacks can be effectively resisted in a monitoring scene with the extremely high requirement for data safety in confidential work, and the security of data transmission is improved. And the data leakage risk is avoided.
Owner:李涛

Network security protection system and method based on electric power emergency communication environment

The invention belongs to the technical field of network security, and particularly relates to a network security protection system and method based on an electric power emergency communication environment, and the system comprises a quantum-classical hybrid encryption system which is used for generating a dynamic key in real time; the biological characteristic driven dynamic trust ring is used for equipment identity authentication; the unmanned aerial vehicle relay network protocol is used for data transmission; the secret key after-reading burn-down protocol is used for information secret key after-reading burn-down; a key output by the quantum-classical hybrid encryption system is used for authentication encryption of a biological characteristic driven dynamic trust ring, an unmanned aerial vehicle relay network protocol transmits data encrypted by the quantum key, and a key burn-down protocol is used for reading encrypted data to trigger a key burn-down mechanism. According to the method, the key security is improved, the network attack difficulty is increased, the communication delay in a disaster is reduced, man-in-the-middle capture and attack can be immunized, and the problem of contradiction between the encryption strength and the real-time performance is solved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Novel ARE cryptosystem of infinite dimension key space for resisting ADC attack on finite dimension cryptosystem

Due to the appearance of dynamic structured mathematics responded by a global coupling structure, a great threat is generated to a traditional password system represented by AES-256 and information security. Most of current mainstream symmetric cryptographic systems such as AES and post-quantum encryption candidate schemes are based on discrete key space and structure modeling operation, the security of the current mainstream symmetric cryptographic systems depends on exhaustion infeasibility or mathematical difficulty complexity, and the current mainstream symmetric cryptographic systems and post-quantum encryption candidate schemes are difficult to resist attacks of adaptive dynamic coupling such as ADC. Therefore, the invention provides a novel ARE encryption system which is constructed by taking'non-modeling property 'as a core principle. A system key is generated by a non-numerable dimension perturbation function, has unique attributes of no structure, non-derivation, non-periodicity and the like, and is combined with an encryption method of a key function which cannot be covered, physical noise perturbation and a quantum random source to construct a new generation of ARE password architecture; the method has the capability of being incapable of being deduced, reduced in order, incapable of being converged to a key space and extremely high in structural modeling attack resistance, any analyzable optimization path can be blocked from the source, and it is ensured that ADC evolution attacks are completely resisted.
Owner:李海全

Adaptive Data Compression and Encryption System Using Reinforcement Learning for Pipeline Configuration

A system and method for optimizing data compression and encryption using reinforcement learning. The system analyzes incoming data streams to extract statistical features and data characteristics, which are processed by a reinforcement learning engine to automatically configure a multi-stage compression pipeline. Each compression stage transforms data into optimized distributions, applies Huffman coding, and maintains full encryption using homomorphic operations. A performance monitor tracks compression efficiency, processing speed, and output quality in real-time, providing feedback to continuously improve the reinforcement learning model's decisions. The system can dynamically adjust between one to five compression stages and select appropriate compression methods, including traditional algorithms or neural network-based approaches, based on data characteristics and performance requirements. All processing occurs on encrypted data without requiring decryption, ensuring complete data security throughout the pipeline. The adaptive nature of the system enables optimal compression performance across diverse data types while maintaining encryption integrity.
Owner:ATOMBEAM TECH INC

Mobile payment encryption system based on data random algorithm

The invention discloses a mobile payment encryption system based on a data random algorithm, and the system comprises a collection module which is used for collecting multi-modal data, and constructing a cross-modal entropy source pool; the random seed generation module is used for extracting feature vectors from the cross-modal entropy source pool and generating initial random seeds; the time sequence self-adaptive random chain module is used for generating a random factor sequence based on the initial random seed recursion and forming a random chain structure; the encryption module is used for jointly encoding the random factor sequence and transaction data to be encrypted, generating a dynamic encryption parameter set and encrypting the transaction data; and the chain type updating module is used for collecting network environment parameters, updating the time sequence self-adaptive random chain and generating a new dynamic encryption parameter set so as to form a chain type evolved encrypted data sequence. According to the method, the cross-modal entropy source and the time sequence random chain are utilized to realize dynamic encryption of the mobile payment data, and the method has the advantages of high entropy randomness, strong attack resistance and high transmission security.
Owner:YANGO UNIV

Collaborative Transformation Matrix Learning for Distributed Data Compression and Encryption Systems

A collaborative transformation matrix learning system extends adaptive compression and encryption architectures through federated, privacy-preserving optimization. Each node analyzes local data distributions to generate anonymized distribution profiles using differential-privacy mechanisms, securely exchanging profiles and validated transformation matrices across a collaborative network. A trust and validation engine verifies mathematical properties and evaluates claimed performance metrics. Validated matrices are integrated into local optimization when trust and performance thresholds are satisfied. The system employs secure multi-party computation, homomorphic encryption, and conflict-resolution logic to ensure integrity of shared insights while preventing exposure of sensitive information. By combining collective learning with local adaptation, the invention accelerates convergence to optimal matrix configurations, mitigates cold-start inefficiencies, and improves compression-encryption efficiency and cryptographic strength across distributed deployments.
Owner:ATOMBEAM TECH INC

Security coprocessor hybrid encryption method and system based on SM2 / 3 / 4 domestic cryptographic algorithm

According to the safety coprocessor hybrid encryption method based on the SM2 / 3 / 4 domestic cryptographic algorithm, a novel hybrid encryption system based on the SM2 / 3 / 4 and considering encryption safety, efficiency and key management convenience is constructed on the basis of the characteristics of the SM2 algorithm, the SM3 algorithm and the SM4 algorithm, and the encryption / decryption and signature / verification process is achieved. And aiming at the efficiency problem of a domestic SM algorithm, an encryption / decryption and signature / verification scheme is designed and realized through pure software analysis and software and hardware (SW / HW) collaboration, so that optimal division of software and hardware is realized, and the algorithm efficiency is greatly improved.
Owner:ANHUI NORMAL UNIV

Quantum resistance data encryption system and method based on biological characteristics

The invention discloses a quantum resistance data encryption system and method based on biological characteristics, and the method comprises the steps: a data collection module obtains various biological characteristics and environment data of a user in real time, carries out the filtering of a preprocessing module, achieves the optimal fusion of multi-dimensional biological information through a multi-modal fusion module, and carries out the encryption of the multi-dimensional biological information; and the feature extraction module dynamically adjusts an extraction strategy to generate a biological feature template. And the key generation module generates a dynamic key in real time according to the template, and performs quantum resistance encryption fragmentation on the original data through the data encryption module. And the fragment recombination module completes data restoration after verifying the consistency of the biological characteristics and the secret key. According to the method, multi-source biological and environmental information is fully fused, highly personalized and dynamic data encryption and secure recombination are realized, the data confidentiality and the anti-attack ability under the background of quantum computing are effectively improved, and the method is suitable for a data protection scene with a high security requirement.
Owner:ENLOG (WUHAN) SEMICONDUCTOR DESIGN CO LTD

Cryptographic system and method for dynamic and automated secure preshared key rotation and distribution

A method and apparatus are provided for automatically distributing pre-shared keys (PSKs) in a secure communication network. A first security association (SA) or secured message (SM) is created between two endpoints based on a first PSK. Then, one or more subsequent PSKs are distributed between the endpoints with secure communication support by the first SA or SM. Based on one of the subsequent PSKs, a second security association is formed between the endpoints. Messages between the endpoints can then be transmitted with secure communication support by the second SA or SM.
Owner:NOKIA SOLUTIONS & NETWORKS OY

Multi-layer encryption system for electronic bidding document

The invention discloses a multi-layer encryption system for an electronic bidding document, particularly relates to the technical field of bidding document encryption, and is used for solving the problems that advanced decryption of an encrypted bidding document is difficult to detect, and a leakage path is difficult to efficiently trace to the source. Comprising a secret key segmentation module, a false quotation generation and binding module, an advanced decryption verification module, a leakage traceability module and a sequential decryption module, a real electronic bidding document is encrypted to generate an encrypted bidding document, a main secret key is segmented by adopting a threshold encryption scheme, a Hash function and random disturbance are combined, a surface bidding document is generated according to the real electronic bidding document, and the surface bidding document is encrypted. The method comprises the following steps: calculating a false quotation of a surface bidding document according to different sub-key combinations used for advanced decryption, generating a sub-key combination-false quotation mapping, carrying out matching evaluation on whether the false quotation of the surface bidding document is decrypted in advance by combining abnormal quotation detection and quotation mode robustness, determining a suspicious key combination used for advanced decryption, and judging whether the false quotation of the surface bidding document is decrypted in advance. And the encrypted bidding document is decrypted in a time window allowed by bid opening.
Owner:GUANGDONG ZHILIAN IND TECHNOLOGY CO LTD

Dynamic hierarchical encryption system for multi-tenant e-commerce data

The invention discloses a dynamic hierarchical encryption system for multi-tenant e-commerce data, and relates to the technical field of multi-tenant data security, the system comprises an encryption management center, the encryption management center is in communication connection with the following modules: a data sensing and grading module, which is used for collecting multi-source context data of an e-commerce platform, and sending the multi-source context data to the encryption management center; performing basic sensitivity level division on the context data; and the multi-tenant knowledge graph construction module is used for constructing a multi-tenant knowledge graph based on the tenant-data-authority association network in combination with the multi-source context data. According to the method, dynamic self-adaptive adjustment of encryption strength is realized through cooperation of the fruit fly algorithm and the knowledge graph, the system dynamically optimizes combination of key length and the encryption algorithm based on data grading labels and real-time context data, and the fruit fly algorithm searches an optimal solution through iteration, so that the system has high encryption efficiency while ensuring compliance. And encryption delay is controlled within a real-time requirement range, so that the user experience in a multi-tenant scene is remarkably improved.
Owner:YUNNAN HUAWU TECHNOLOGY CO LTD

Authenticated encryption apparatus, authenticated decryption apparatus, authenticated encryption system, method, and non-transitory computer readable medium

A plaintext division unit divides a plaintext into a first plaintext and a second plaintext at a predetermined ratio. A first encryption unit acquires a first ciphertext by an encryption function by using a mask value obtained based on a first value and a plurality of plaintext blocks, respectively. A second encryption unit acquires a second ciphertext by using, among encryption results output from the encryption function in the encryption of the first plaintext, a value other than a value used for the encryption of the first plaintext and a second plaintext. An authentication tag generation unit generates a first tag. The authentication tag generation unit generates a second tag. The authentication tag generation unit generates an authentication tag.
Owner:NEC CORP

Data encryption and decryption method and device, equipment and storage medium

The embodiment of the invention provides a data encryption and decryption method and device, equipment and a storage medium, and relates to the technical field of data security. The method comprises the following steps: generating a corresponding encryption public key, an encryption private key and a mask parameter according to a public parameter, encrypting target data by using the encryption public key to obtain encrypted data, sending the mask parameter, the encryption public key and the encrypted data to server equipment, expanding the encrypted data by using the encryption public key by the server equipment to obtain an expanded ciphertext, and sending the expanded ciphertext to the server equipment. And performing homomorphic addition calculation on the extended ciphertext based on the encryption public key and the mask parameter, sending an obtained addition ciphertext to the user side equipment, and performing partial decoding on the addition ciphertext by using the encryption private key to obtain a decoded plaintext. According to the multi-key encryption method, each user side device generates a corresponding mask parameter, in the homomorphic addition process, the mask parameters are utilized to ensure that ciphertexts from different sources can be safely combined, a calculation result keeps semantic security, sensitive information is prevented from being leaked, and the security of a multi-key encryption system is enhanced.
Owner:PENG CHENG LAB

Iris template multi-level life cycle management and dynamic drift elimination algorithm

The invention discloses a multi-level life cycle management and dynamic drift elimination algorithm for an iris template, and relates to the technical field of biological feature recognition and information security. A three-layer hierarchical storage architecture of a module layer, an edge layer and a cloud layer is constructed, and a dual-index decision-making mechanism of drift accumulation monitoring and activeness assessment is combined, so that the multi-level life cycle management and dynamic drift elimination algorithm for the iris template is realized. The intelligent life cycle management of the iris template is realized, a differential chain synchronization technology and a hierarchical key pool encryption system are adopted, the access performance and the storage cost are optimized while the data security is guaranteed, and a dynamic elimination algorithm processes the life cycle of the iris template through a self-destruction countdown mechanism according to the user activeness difference, so that the safety of the iris template is improved. The method effectively solves the limitation of a traditional fixed expiration strategy, achieves the remarkable improvement in the aspects of recognition accuracy, response speed and safety protection, and is particularly suitable for application scenes with extremely high requirements for real-time performance and safety.
Owner:WUHAN HONGSHI TECH

Data encryption system and method based on 5G communication module

The invention relates to the technical field of 5G communication modules, in particular to a data encryption system based on a 5G communication module and a method thereof.The data encryption system comprises a terminal device module, a power private network eSIM, an X.509 digital certificate issued by a CA and a private key are pre-installed in a terminal device and stored in a trusted execution environment or a trusted platform module, firmware integrity verification can be completed after power-on, and the terminal device module is connected with the terminal device module. TLS bidirectional handshake with an identity authentication gateway is initiated through the eSIM and the digital certificate so as to establish an encryption channel with a session identifier; and the identity authentication gateway is used for receiving and verifying eSIM authentication information and an equipment certificate from the terminal equipment, and generating a unique session identifier after finishing TLS bidirectional authentication. In the invention, through combining the eSIM network authentication of the electric power private network and the X.509 certificate issued by the CA, TLS bidirectional handshake between the equipment and the identity gateway is realized, and dual authentication between a physical link layer and an application link layer is realized; and risks of equipment counterfeiting, malicious man-in-the-middle access and the like are completely eradicated.
Owner:JIANGSU FULIAN COMM TECH CO LTD

Anti-frequency analysis searchable encryption method and system

According to the anti-frequency analysis searchable encryption method and system, a certificateless encryption system is introduced, for a scene with limited computing resources, the scheme is ensured to be safe and suitable for the scene with the limited computing resources, meanwhile, a trap door algorithm is designed based on a probability trap door generation algorithm, and the security of the scheme is improved. The method improves the resistance of a system to frequency analysis attacks, solves the problem of secret key trusteeship due to the fact that identity information and secret key distribution are concentrated in a private key generation center in a traditional encryption scheme, and improves the encryption efficiency. The technical problem that malicious users are easy to obtain the privacy information of the target keyword by performing frequency analysis on trap doors and initiating keyword guessing attacks is solved.
Owner:GUIZHOU UNIV