Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

183 results about "Encryption system" patented technology

An encryption system in which the sender and receiver of a message share a single, common key that is used to encrypt and decrypt the message.

Collaborative Transformation Matrix Learning for Distributed Data Compression and Encryption Systems

A collaborative transformation matrix learning system extends adaptive compression and encryption architectures through federated, privacy-preserving optimization. Each node analyzes local data distributions to generate anonymized distribution profiles using differential-privacy mechanisms, securely exchanging profiles and validated transformation matrices across a collaborative network. A trust and validation engine verifies mathematical properties and evaluates claimed performance metrics. Validated matrices are integrated into local optimization when trust and performance thresholds are satisfied. The system employs secure multi-party computation, homomorphic encryption, and conflict-resolution logic to ensure integrity of shared insights while preventing exposure of sensitive information. By combining collective learning with local adaptation, the invention accelerates convergence to optimal matrix configurations, mitigates cold-start inefficiencies, and improves compression-encryption efficiency and cryptographic strength across distributed deployments.
Owner:ATOMBEAM TECH INC

Anti-leakage encryption system and method based on power grid data

The invention discloses an anti-leakage encryption system and method based on power grid data, and relates to the technical field of power grid data security encryption, and the method comprises the steps: dividing encryption levels according to power grid data sensitivity levels, and matching algorithms; during service operation, generating a dynamic key seed based on a real-time scene, and binding the dynamic key seed with data transfer node information to generate an initial dynamic key; user permission change is monitored, and the secret key is automatically updated according to the newest role and node information when conditions are met; encrypting each level of data by adopting a corresponding algorithm and a dynamic key to form a ciphertext; and performing permission verification during access, and decrypting the ciphertext by using the corresponding key and algorithm according to the authorized decryption hierarchy. According to the method, the real-time linkage of encryption protection, the data flow state and the user permission change is realized, so that a security mechanism can dynamically adapt to the service scene change, and the active defense capability of power grid data leakage prevention and the immediate effectiveness of permission control are enhanced.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Systems and methods for selective encryption of sensitive image data

Disclosed is a selective encryption system that selectively encrypts sensitive image data within frames of a video stream and compresses other insensitive image data within the frames in order to generate and distribute a partially encrypted video stream that protects the sensitive image data without the time, energy, resource, and size penalty associated with encrypting all image data in all frames of the video stream. The system parses a video stream image into different regions that each contain different image data. The system detects first regions that contain the sensitive image data, encrypts the sensitive image data in the first regions, and compresses the image data in other second regions without encryption. The system distributes a selectively encrypted frame of the video stream that includes the encrypted image data for the first regions and the compressed image data for second regions.
Owner:RINGCENTRAL INC

Image publishing privacy protection method based on attribute encryption

The invention discloses an image release privacy protection method based on attribute encryption, which solves the problems that in the prior art, access control expansibility is poor, an image processing mode damages visibility and a sensitive area is not self-defined, realizes safe image access control, ensures that only an authorized user can decrypt and recover an original image, and improves user experience. Meanwhile, the sensitive area is protected from unauthorized access; the method comprises the following steps: initializing an attribute-based encryption system through a key generation center, and distributing a public key and a user private key to realize fine-grained access control. And an image owner scrambles image color blocks by using DCT (Discrete Cosine Transform), and steganoscopes control parameters in the image to be published. And after the authorized visitor extracts the encryption parameter, the private key is used for decryption to obtain the original key, and the auxiliary information is combined to perform inverse operation on the image sensitive area to accurately recover the original image. In the whole process, flexible access control is achieved, and meanwhile protection and availability of image content are effectively balanced.
Owner:XIDIAN UNIV

An asymmetric color image optical encryption method based on generalized singular value decomposition

The application discloses a kind of asymmetric color image optical encryption methods based on generalized singular value decomposition, including encryption process and decryption process, encryption process: asymmetric optical encryption system of color image, the technical scheme adopted is, in encryption system, a kind of double random phase encoding encryption scheme based on generalized singular value decomposition is designed, color image is first encoded into complex matrix, the complex matrix obtained is modulated with phase plate by generalized singular value decomposition, then encryption is carried out in optical Fourier transform domain using phase truncation technique, finally the ciphertext is received by charge coupled device.The application mainly aims at the problem that existing asymmetric encryption system based on phase truncation cannot resist special attack, a kind of modulation method based on generalized singular value decomposition is designed to image and random phase plate, the encryption algorithm can realize color image encryption, effectively resist shear attack, noise attack, chosen-plaintext attack and special attack.
Owner:CIVIL AVIATION UNIV OF CHINA

Health status system, platform, and method

A health status platform includes a receiving component that receives a test result a test of a biological sample collected from a human patient. The test result includes an indication of a presence of an infectious disease in the patient, and an identification and a verification of the patient. The platform includes a certificate component that issues a certificate of origin of the biological sample; and a data merging component that cooperates with a venue access manager that controls access to a venue. The data merging component implements a distributed ledger system that stores encrypted test results of the patient and the identification and verification of the patient, and an end-to-end encryption system that receives an encrypted venue access request from a venue access manager, decrypts the access request, determines if an access request is valid, and if valid, provides an encrypted certificate of origin to the venue access manager.
Owner:TENSORX INC

Chaotic digital image encryption system performance analysis method and device based on intelligent optimization algorithm

The invention provides a chaotic digital image encryption system performance analysis method and device based on an intelligent optimization algorithm, and belongs to the field of information security and password engineering. The problems that an existing chaotic image encryption method depends on manual parameter adjustment, parameter optimality is difficult to guarantee, confusion and diffusion intensity is insufficient, and statistical safety is unstable are solved. The method comprises the following steps: encrypting a digital image through a chaotic digital image encryption system; an intelligent optimization algorithm is introduced, a target function related to performance indexes is designed, optimal control parameters are automatically searched in a given Lorenz chaotic system parameter domain, and performance analysis is carried out on the chaotic digital image encryption system through a scientific method. The method and the device are suitable for digital image encryption, content security protection, communication privacy protection and multimedia security application scenes.
Owner:SHANXI NORMAL UNIV

Autonomously booting system with encryption of the entire data storage and method for this

Encryption system with an application-specific integrated circuit (ASIC) which has a permanent memory for the non-volatile storage of the operating system (OS) of a processor and software modules for encrypting the data memory of the processor and which has a hardware-implemented encryption algorithm, characterized in that a security module (SM) is integrated in the ASIC for autonomous booting of the operating system (OS), consisting of: - a symmetric cryptosystem (SK) for processing symmetric keys, - an asymmetric cryptosystem (AK) for the use of public and private keys, - a module for generating cryptographic hash functions (KH), - a module for the secure exchange of keys using hardware-implemented key exchange protocols (SP), - a key storage (SS) for the secure storage of root keys (WS), which are protected by appropriate measures in the physical structures of the ASIC and - a key management system (SMS) for the secure introduction of authenticated-encrypted key packets, and that the security module (SM) communicates with a central processing unit (CPU) via a communication interface (CS1), and that the central processing unit (CPU) communicates with at least one internal storage (IS) and one external storage (ES), as well as with at least one internal persistent storage (IP) and one external persistent storage (EP), such that the operating system (OS) is loaded by a second-stage bootloader (SSB) stored in the external persistent storage (EP), and then the operating system (OS) loads the applications, the second-stage bootloader (SSB) itself being decrypted and loaded by a first-stage bootloader (FSB) stored in the internal persistent storage (IP), and a public key (PUBOS) to verify the operating system (OS).and a symmetric key (KOS) to decrypt the operating system (OS), and that the contents of the internal memory (IS) and the external memory (ES) are decrypted by the security module (SM) during read accesses by the central management unit (CMU) or other modules integrated on the ASIC, and re-encrypted during write accesses by the same.
Owner:IAD GESELLSCHAFT FUER INFORMATIK AUTOMATISIERUNG & DATENVERARBEITUNG MBH

A full-pipelined AES real-time encryption system for high-speed transmission

PendingCN122293307AComputer architectureCarry propagation
This invention discloses a fully pipelined AES real-time encryption system for high-speed transmission, aiming to solve the technical bottlenecks of limited throughput and excessive processing latency in traditional encryption architectures in high-speed networks. The system mainly includes a data input buffer module, a fully pipelined encryption operation module, a round key pre-computation module, and a data output driver module. The core of this invention lies in the operator-level hardware reconstruction of the AES underlying algorithm: the S-box nonlinearity is replaced and embedded in the distributed ROM of the FPGA to achieve zero-clock-cycle asynchronous table lookup, and a carry-free XOR tree architecture based on the XTime operator is used to reconstruct column hybrid operations, eliminating deep carry propagation chains.
Owner:EAST CHINA UNIV OF SCI & TECH

Private data protection method and device, equipment, medium and program product

The present disclosure relates to a privacy data protection method, apparatus, device, medium and program product, and relates to the technical field of information security, the method comprising: a group agent node receiving an encrypted data packet sent by a first user, the encrypted data packet comprising a first ciphertext, the first ciphertext is obtained by encrypting private data and signature data of the private data by the first user through a first private key; and re-encrypting the first ciphertext into a second ciphertext through a re-encryption key, so that a second user uses a second private key to extract private data from the second ciphertext, and the re-encryption key is generated by the first user based on the first private key, the second public key and the proxy re-encryption system parameters. The privacy data protection method and device can solve the problem of privacy data leakage caused by key escrow risk, plaintext leakage risk and the like existing in a current privacy data protection scheme.
Owner:SHENHUA HOLLYSYS INFORMATION TECH CO LTD

SEARCH EXECUTION DEVICE, SEARCH EXECUTION PROCEDURE, SEARCH EXECUTION PROGRAM, AND SEARCHABLE ENCRYPTION SYSTEM

Search execution unit comprising: a search query receiver unit for receiving a trapdoor generated on the basis of a secret user key specifying a search helper key and a user attribute, and a search keyword, together with a key identifier (ID) identifying the search helper key; and a search execution unit for decrypting an encrypted tag specifying a user attribute authorized to retrieve and a search keyword, using the trapdoor received by the search query receiver unit and the search helper key specified by the key ID received by the search query receiver unit to identify a tag retrievable for the attribute specified in the secret user key and containing a search keyword corresponding to the search keyword.
Owner:MITSUBISHI ELECTRIC CORP

An encryption system and method for quantum annealers

A computer-implemented method for an encryption for secure communication between devices during quantum annealing or QUBO-based routines, which are executed on a quantum device with configurations determined or supported by at least one classical computing device, wherein the encryption and decryption of data are managed by the classical computing device, the method characterized by within a QUBO based routine that includes set of pre-trained weak learners that provide output for test values and weight adjustment process for these weak learners and after the discretized to model it as a QUBO; using different encoding depths for different weights with the assigning the weights randomly according to the correlation in between the weak learners with the registration of this encoding information; shuffling the order of the variables randomly with the registering this order information; converting the QUBO matrix, which is stored in at least one storage medium and generating a string which includes two different number whose length matches the solution space dimensionality and registering the strings with spin flipping these numbers; decryption of the data which is received from at least one quantum device with encrypted by classical computing device before the transfer procedure with using encoding information, order information, spin flipped result, combination order information or suitable combination of them according to the encryption.
Owner:MULTIVERSE COMPUTING SL

Method for pseudo-random number generation for information encryption

A method of generating at least one encryption key (130) for encrypting data (142), a method of data transmission between at least two communication systems (136, 138), a method of encrypting data (142) and a method of decrypting encrypted data (144) are disclosed. Further disclosed are an encryption key generating device (110), a system (134), a data encryption system (148) and a data decryption system (150). The method of generating at least one encryption key (130) for encrypting data (142), specifically for data transmission over an insecure channel, comprises:blending at least two materials (114) according to at least one item of blending information by using a blending device (112), thereby generating at least one blend (120);ii. detecting at least one material property (124) of the blend (120) by using at least one detector (126); andiii. transforming the material property (124) into the encryption key (130) by using at least one data processing device (132) configured for applying at least one transformation algorithm to the material property (124).
Owner:BASF SE

Secure and Encrypted Garbage Collection in a Chunk Storage System

A system can store a first encryption key for a first data chunk of a log filesystem in a first virtual chunk extent that comprises first virtual pointers that point to the first data chunk, wherein the first data chunk is encrypted with the first encryption key. The system can, based on performing garbage collection on the first data chunk, to produce surviving data that remains from the first data chunk after the garbage collection, move the surviving data to a second data chunk, wherein the surviving data is encrypted in the second data chunk with a second encryption key, wherein the second encryption key is stored in a second virtual chunk extent corresponds to the second data chunk, and delete the first virtual chunk extent while refraining from deleting the first data chunk, wherein, after the deleting, the first encryption key is deleted.
Owner:DELL PROD LP

A cluster data encryption and decryption method, device and system based on double trusted binding and decryption deadline control

The application discloses a cluster data encryption and decryption method, device and system based on double trusted binding and decryption deadline control, relates to the technical field of information security, and comprises the following steps: collecting hardware characteristic information of a cluster terminal node, extracting a certain length of bytes as original machine code after processing; obtaining a dynamic key factor, extracting a specified length of bytes as a data key after processing; splicing the original machine code and certificate validity period information, generating certificate machine code after processing; splicing the original machine code and certificate validity period information, generating a machine envelope key after processing, performing symmetric encryption on the data key to obtain a machine key; generating a key certificate; and encrypting plaintext data by using the data key to obtain data ciphertext. The application introduces a multi-hardware characteristic fusion and multi-level key encryption system, and solves the problems of device identity impersonation, key leakage and uncontrollable data life cycle in a cluster environment.
Owner:JIANGSU SHIDA DIMEI DATA PROCESSING CO LTD

Proxy interception and double encryption system and methods

A method of enabling custom cryptography is provided. The method can include sending, by a first computing device and to a second computing device, instructions to initiate a proxy. The proxy can be configured to intercept a message of a user agent. The user agent may be associated with the second computing device. The proxy can be further configured to perform custom cryptography based on the message to obtain a modified message. The custom cryptography may comprise post-quantum cryptography. The proxy can be further configured to send the modified message to at least one of the user agent, a reverse proxy, or a third computing device. The post-quantum custom encryption and / or decryption can comprise Quantum Secure Layer (QSL), Post-Quantum Transport Layer Security (PQTLS), Kyber, SABER, Enhanced McEliece, RLCE, or a National Institute of Standards and Technology (NIST) candidate post-quantum algorithm.
Owner:QUSECURE INC

Community Governed End to End Encrypted Multi-Tenancy System to Perform Tactical and Permanent Database Operations and Microservices

Multi-tenancy system to perform tactical and permanent database and communication operations including secure handling of personally identifiable and / or health information (PII / PHI), data collection, data management, reporting, data analytics, secure communications, document sharing and microservices (e.g., capturing biomarkers, determining presence of certain conditions by comparing captured biomarkers to biometrics associated with condition). System includes security platform meeting stringent data protection mandates including firewall with extensive security protocols, encrypting communications between components of system (in transit) and information within each of the components (at rest). PII / PHI information is further encrypted and only visible with appropriate decryption key. System utilizes low code / no code database platform to address increasing demand for rapid, iterative and collaborative application development. System includes form builder to easily add dynamic fields. System includes a collaborative database development with a community structure approach of “who” data is needed from rather than “what” data is needed. Community structure controls operation thereof.
Owner:ARDIAN TECH

Electromagnetic and power noise injection for hardware operation concealment

A method for operation hiding for an encryption system includes randomly selecting which of at least two encryption operation blocks receives a key to apply an effective operation on data and output a result used for a subsequent operation. Noise can be added by operating other encryption operation blocks of the at least two encryption operation blocks with a modified key. The modified key can be generated by mixing the key with a block unique identifier, a device password, a slow adjustment output of a counter, or a combination thereof. In some cases, input data of the other encryption operation block can be transformed by mixing the input data with the block unique identifier, the device password, the counter output, or a combination thereof, thereby adding noise to the encryption system. An encryption system with operation hiding can also include a distributed (across chip) or interleaved arrangement of sub-blocks of the encryption operation blocks.
Owner:ARM LTD

Optical encryption method and optical encryption system

The application relates to an optical encryption method and an optical encryption system, the method comprising: loading spatial plaintext information to be encrypted into an optical path to obtain an optical beam carrying the spatial plaintext information; modulating the optical beam into a time-varying optical field through a complex medium, wherein the dynamic characteristics of the complex medium vary with time and repeat in a fixed period, and the periodic variation of the optical field is determined by the fixed period; collecting information of the optical field in a preset time period within the fixed period as time-domain ciphertext data. In the optical encryption, an additional key control parameter, i.e. the optical field information in a specific time period within the selection period, is introduced to generate the ciphertext, the generation of the ciphertext becomes more complex and unpredictable, the key space is expanded, the leakage of the periodic characteristics of the optical field is avoided, and the security of the system is significantly enhanced. Meanwhile, since the encryption no longer depends on complete time sequence data, the requirement for the hardware performance is reduced, the implementation cost is further reduced, and the encryption efficiency is improved.
Owner:ZHEJIANG LAB

Key management method and device, equipment, storage medium and program product

The invention relates to a key management method and device, equipment, a storage medium and a program product. The method is applied to an intermediate layer in a database encryption system, the database encryption system comprises a database kernel, the intermediate layer and at least one key management system, the database kernel interacts with the key management system through the intermediate layer, and the method comprises the following steps: receiving a key decryption request sent by the database kernel, the key decryption request carries identification information of the first target key; acquiring the first target key from the first key management system according to the identification information of the first target key and the first mapping relationship; sending the first target key to a database kernel; the first target key is used for the database kernel to decrypt the ciphertext of the second target key according to the first target key to obtain the second target key, and the second target key is used for encrypting or decrypting the to-be-processed data in the database kernel. By adopting the method, the stability of the data kernel can be improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

A method for access control with distinguished permissions based on attribute-based encryption

The application relates to a kind of attribute-based encryption-based differentiated permission access control methods, and belongs to the field of attribute cryptography and access control technology.The application adopts hybrid encryption mechanism, encrypts shared data using symmetric encryption system, and encrypts symmetric key using attribute-based encryption system, and only when the key associated attributes of a user meet the access control policy, the user can decrypt to obtain the symmetric key, and then decrypt to obtain the shared data plaintext using the symmetric key.In order to ensure the integrity and non-repudiation of shared data, the private key of the data owner is used for signing while the data owner generates the ciphertext.By using symmetric encryption mechanism and attribute-based encryption system, attribute-based, fine-grained permission control is realized, and the encryption and decryption efficiency of data is ensured.
Owner:BEIJING INST OF COMP TECH & APPL

A load management terminal safe and reliable converged communication method, system and medium

The application discloses a kind of load management terminal safe and reliable fusion communication method, and disclosed with the system of load management terminal safe and reliable fusion communication method, wherein load management terminal safe and reliable fusion communication method is converted into feature gene by the intrusion detection data set, and immune cell is generated by gene, the diversity of feature information is improved by cloning variation, to match abnormal data to prevent the possibility of intruder intrusion, also provide synergistic stimulation, further improve the accuracy of system.In addition, adaptive authentication mechanism is also introduced between terminal and main station, through the evaluation of context data, adaptive access authentication strategy arrangement is carried out, and time stamp, digital signature and NTRU encryption system are introduced in communication process, can cope with replay attack, verify the integrity of data, identity authentication and anti-denial, and have the ability of anti-quantum, face mass load management terminal, realize efficient and safe access communication strategy.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +1

Systems and methods for selective encryption of sensitive image data

Disclosed is a selective encryption system that selectively encrypts sensitive image data within frames of a video stream and compresses other insensitive image data within the frames in order to generate and distribute a partially encrypted video stream that protects the sensitive image data without the time, energy, resource, and size penalty associated with encrypting all image data in all frames of the video stream. The system parses a video stream image into different regions that each contain different image data. The system detects first regions that contain the sensitive image data, encrypts the sensitive image data in the first regions, and compresses the image data in other second regions without encryption. The system distributes a selectively encrypted frame of the video stream that includes the encrypted image data for the first regions and the compressed image data for second regions.
Owner:RINGCENTRAL INC

Method and system for protecting cryptographic operations against side-channel attacks

A cryptographic system for executing operations of a cryptographic scheme applied to encrypt a data block is provided. The cryptographic system comprises a first sharing processing unit configured to execute an arithmetic sharing function applied to the data block and providing as an output a first and a second arithmetic share component. The cryptographic system further comprises a second sharing processing unit and a computation processing unit. The second sharing processing unit is configured to determine a random component and to execute a Boolean sharing function applied to the first arithmetic share component and to the random component and providing as an output an intermediate Boolean share component. The computation processing unit is configured to execute a recursive carry computation function configured to compute a first, a second and a third Boolean share component from the second arithmetic share component, the random component and the intermediate Boolean share component.
Owner:SECURE IC

A computer technology-based optical communication data security encryption system and method

PendingCN122406929AComputer networkEngineering
This invention discloses a computer-based optical communication data security encryption system and method, including a track plate and a support frame. A working platform is movably mounted on top of the track plate. A set of toothed rods is fixed at each end of the bottom of the working platform. Two sets of gears are installed in the middle of the track plate, with the toothed rods and gears forming a meshing connection. A hook is welded to the middle of the left side of the working platform. A mounting base is fixed to the side of the track plate near the building's exterior wall, and a winch is installed at the mounting base. A steel wire rope is fixed between the winch and the hook. This invention, by incorporating a working platform, toothed rods, gears, mounting base, hook, steel wire rope, and winch, achieves the function of automatically retracting and extending the steel wire rope during the platform's forward and backward movement. This ensures smooth platform movement while providing safety protection, thus improving the construction safety of the building's exterior wall.
Owner:李翔

An efficient puncturable, revocable attribute-based encryption method and system

The application discloses a high-efficiency puncturable and revocable attribute-based encryption method, and relates to the technical field of data encryption. p The application discloses a high-efficiency puncturable and revocable attribute-based encryption method, and relates to the technical field of data encryption. p The application discloses a high-efficiency puncturable and revocable attribute-based encryption method, and relates to the technical field of data encryption. partly The application discloses a high-efficiency puncturable and revocable attribute-based encryption method, and relates to the technical field of data encryption. partly The application discloses a high-efficiency puncturable and revocable attribute-based encryption method, and relates to the technical field of data encryption. The application discloses a high-efficiency puncturable and revocable attribute-based encryption system, which comprises a parameter setting module, an encryption module, a key generation module, a puncturing module, a pre-decryption module and a decryption module. The application can hide an access strategy and protect user attribute privacy, and realizes efficient revocation under the condition of guaranteeing forward and backward security.
Owner:HUAIBEI NORMAL UNIVERSITY

Communication method, system and associated architecture

Communication Method, System, and Associated Architecture The present invention relates to a communication method between a sending node and a target node, via an encryption system comprising a plurality of gateways directly connected to each other via IPsec tunnels, each node being connected to a gateway. The communication method comprises a transmission phase (P2) including: the sending (S202) of a data packet by the sending node to the gateway to which it is connected, called the sending gateway; the encryption (S206) of the data packet by the sending gateway; and the transmission of the encrypted data packet. The data packet is marked (S204) by the sending gateway with a mark corresponding to an IPsec tunnel to be used, and the transmission (S206) of the encrypted data packet by the sending gateway is carried out through the IPsec tunnel corresponding to the mark of the data packet. Figure for the abstract: Figure 4
Owner:THALES SA

Chaotic image encryption method based on attention mechanism and filter

The invention discloses a chaotic image encryption method based on an attention mechanism and a filter, and the method comprises the steps: inputting and preprocessing, self-attention feature extraction and key generation, chaotic system initialization and sequence generation, DNA coding encryption, and dynamic three-dimensional filtering diffusion. All parameters and sequences need to be reproduced by using the same key vector, inverse permutation, inverse filtering diffusion and DNA decoding are carried out in sequence, and finally an original image is subjected to lossless recovery. The invention relates to the technical field of information security, and in the method, a secret key is dynamically generated from image content through a self-attention mechanism, and a dynamic three-dimensional filtering diffusion mechanism is adopted to realize collaborative encryption and dynamic randomization processing of a color image three-dimensional structure, so that the security, diffusivity and anti-attack capability of an encryption system are remarkably improved.
Owner:CHANGSHA UNIVERSITY OF SCIENCE AND TECHNOLOGY

Quantum encryption system for multi-party mobile communication, quantum key distribution method and encryption method

The application discloses a multi-party mobile communication quantum encryption system, which comprises a first quantum key distribution device arranged in a first region, a first communication server in communication connection with the first quantum key distribution device, and a plurality of first communication terminals in communication connection with the first communication server; a second quantum key distribution device arranged in a second region, a second communication server in communication connection with the second quantum key distribution device, and a plurality of second communication terminals in communication connection with the second communication server; the first quantum key distribution device is in remote communication connection with the second quantum key distribution device, and the first communication server is in remote communication connection with the second communication server. Terminal equipment downloads keys belonging to it from a key pool to a terminal key chip in batches, selects quantum keys from a local terminal key chip for encryption during encrypted communication, and only transmits encrypted data to a target terminal through a communication server, so that the risk of stealing quantum keys during communication is reduced.
Owner:ANHUI QASKY QUANTUM SCI & TECH CO LTD

A quantum key cloud-based encryption system unified management and key distribution method

PendingCN122372194ACiphertextEngineering
This invention relates to the field of network security technology, and in particular to a unified management and key distribution method for encryption machines based on quantum key cloud. The method includes: receiving a registration request and extracting the device name, authentication information, and timestamp; completing identity authentication, authorization management, and generating device quantum information; subsequently collecting online status data and determining the device usage status corresponding to the central processing unit, memory, disk, and network port; generating anomaly status judgment results by comparing authentication information and communication status; then outputting alarm information, blocking illegal connections, verifying permissions, matching key identifiers, and distributing quantum ciphertext data; and completing quantum key acquisition, generating acquisition confirmation messages, data encryption and decryption, key update management, and resetting password verification and factory reset processing. This invention significantly improves the security, real-time performance, and closed-loop autonomous capability of unified management of encryption machines.
Owner:CONCAVE SHIELD (BEIJING) TECH CO LTD