Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

19 results about "Forward secrecy" patented technology

In cryptography, forward secrecy (FS), also known as perfect forward secrecy (PFS), is a feature of specific key agreement protocols that gives assurances that session keys will not be compromised even if the private key of the server is compromised. Forward secrecy protects past sessions against future compromises of secret keys. By generating a unique session key for every session a user initiates, the compromise of a single session key will not affect any data other than that exchanged in the specific session protected by that particular key. Forward secrecy further protects data on the transport layer of a network that uses common SSL/TLS protocols, including OpenSSL, which had previously been affected by the Heartbleed security bug. If forward secrecy is used, encrypted communications and sessions recorded in the past cannot be retrieved and decrypted should long-term secret keys or passwords be compromised in the future, even if the adversary actively interfered, for example via a man-in-the-middle attack.

New-generation cryptographic system and method based on physics quantum dynamic public key and cloud entropy synchronous private key, terminal, server and medium

The invention discloses a new-generation cryptographic system and method based on a physics quantum dynamic public key and a cloud entropy synchronous private key, a terminal, a server and a medium, and relates to the technical field of quantum information technology, cryptography and Internet of Things security crossing. The system comprises a terminal, a server and a cloud entropy synchronization private key library, and the terminal is configured to generate a quantum random number by using a quantum random number generation module, generate a synchronization parameter based on the quantum random number, and send the synchronization parameter or a physics quantum dynamic public key exported by the synchronization parameter to the cloud entropy synchronization server; and the terminal and the cloud entropy synchronization server are further configured to determine the same target entropy material from the cloud entropy synchronization private key library by applying the same cloud entropy mapping algorithm based on the synchronization parameter, and generate the same session key based on the target entropy material. According to the key system, non-interactive key establishment, forward secrecy and endogenous quantum computing attack resistance are realized.
Owner:ANHUI YUNXI TECH CO LTD +1

Establishment of forward secrecy during digest authentication

ActiveUS12683772B2Key exchangeDigest access authentication
Mechanisms for establishing forward secrecy during digest access authentication are provided. A method is performed by a client device. The method includes performing digest access authentication with a server device. The digest access authentication includes sending a first request towards the server device for accessing a resource; and receiving a first response. The first response includes a challenge and a public component of an asymmetric key pair for a key exchange with the server device. The digest access authentication includes calculating, using a digest algorithm, a response parameter based at least on the challenge and the public component of the asymmetric key pair; and sending a second request towards the server device for accessing the resource. The second request includes the calculated response parameter. The digest access authentication includes receiving a second response from the server device that indicates successful digest access authentication with the server device.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Intelligent electric meter multi-authentication encryption method based on zero-trust architecture

The invention discloses an intelligent electric meter multi-authentication encryption method based on a zero-trust architecture, and particularly relates to the field of electric meter multi-authentication encryption, and the method specifically comprises the steps: when a client or a third party carries out data communication with an intelligent electric meter, each communication needs identity verification, key negotiation and data encryption, the data encryption adopts an AES-GCM-128 encryption algorithm, a client or a third party sends a ciphertext, an initialization vector, a label and a timestamp to the intelligent electric meter, and the intelligent electric meter decrypts the timestamp after verifying the timestamp and verifies the label to confirm the validity of the data. According to the method, a zero-trust architecture and an encryption protection algorithm are applied to communication between a client or a third party and an electric meter without depending on a traditional trust model, identity verification and key negotiation operation are needed every time data communication is carried out, the security risk is effectively reduced, and good forward confidentiality is ensured.
Owner:QINGDAO ITECHENE TECH CO LTD

Widely applicable communication network encrypted data transmission method

The invention belongs to the technical field of communication engineering and information security, particularly relates to a widely applicable communication network encrypted data transmission method, and aims to solve the problems of fragile key synchronization, high re-synchronization overhead and contradiction between security and performance caused by key management and data stream state separation in the prior art. Establishing an initial key and an updating rule through session initialization; the method comprises the following steps of: segmenting data blocks according to a serial number at a sending end, encrypting by adopting an AEAD algorithm, and executing a deterministic key updating function based on a ciphertext when each data block is encrypted so as to evolve a next key; and a receiving end decrypts in sequence and synchronously updates a decryption key, so that endogenous coupling of a cryptographic state and data stream processing is realized. By adopting the above technical scheme, the secret key state can be implicitly synchronized without out-of-band signaling, and the method has the performance of packet loss resistance, forward secrecy and adaptive security, and is suitable for efficient and secure communication in an unreliable network environment.
Owner:BEIJING PANDUN TECHNOLOGY CO LTD

System and method for implementing secure communications for internet of things (IoT) devices

Novel tools and techniques might provide for implementing secure communications for IoT devices. In various embodiments, a gateway or computing device might provide connectivity between or amongst two or more Internet of Things (“IoT”) capable devices, by establishing an IoT protocol-based, autonomous machine-to-machine communication channel amongst the two or more IoT capable devices. For sensitive and / or private communications, the gateway or computing device might establish a secure off-the-record (“OTR”) communication session within the IoT protocol-based, autonomous machine-to-machine channel, thereby providing encrypted machine-to-machine communications amongst the two or more IoT capable devices, without any content of communications that are exchanged amongst the IoT capable devices over the secure OTR communication session being recorded or logged. In some cases, the secure OTR communication session utilizes cryptographic protocols including, without limitation, one or more of AES symmetric-key algorithm, Diffie-Hellman key exchange, SHA-1 hash function, forward secrecy, deniable authentication, malleable encryption, and / or the like.
Owner:CENTURYLINK INTELLECTUAL PROPERTY LLC

HTTPS encrypted traffic auditing method, device, system and medium

The invention relates to an HTTPS encrypted traffic auditing method, device and system and a medium. The method comprises: receiving and processing a key packet from a client to obtain a pre-master key and TLS session metadata, the session metadata comprising a client random number, a server random number and a cipher suite identifier; performing key derivation processing on the pre-master key based on the TLS session metadata to obtain a key parameter required for decrypting the HTTPS flow; when the mirrored HTTPS flow is obtained, the secret key parameter is utilized to decrypt the HTTPS flow, and plaintext application layer data is obtained; and performing content auditing on the application layer data. According to the invention, the method effectively avoids the single-point fault and certificate trust risk of a man-in-the-middle agent, overcomes the ineffectiveness of a private key decryption scheme to a forward secrecy algorithm, avoids the system resource occupation and deployment complexity of a client agent, and achieves the efficient, compliant and bypass type auditing of the national secret and standard encrypted traffic including ECDHE and the like.
Owner:HANGZHOU DPTECH TECH

Power grid material sample information extranet transmission method and system

The invention provides a power grid material sample information extranet transmission method and system, and belongs to the technical field of power system Internet of Things information security, and the method comprises the steps that a sender splices sample data into a plaintext; dynamically negotiating with a receiver through an ECDH protocol to generate a shared session key; performing bit confusion processing on the plaintext by using the timestamp; encrypting the confused plaintext by using a session key, and digitally signing the hash and timestamp of the original plaintext; packaging the ciphertext, the signature, the timestamp and the public key, and calculating a transmission fingerprint uplink storage certificate; and the receiver decrypts and carries out anti-confusion, verifies the signature and the timestamp, and links the verification result. Through cooperation of the dynamic secret key, bit confusion, digital signature and block chain evidence storage, forward secrecy, anti-flow analysis, identity authentication and strong non-repudiation of data transmission are realized, and the method is especially suitable for transmitting power grid material sample information in a public network environment by resource-constrained terminals such as intelligent safety helmets and the like.
Owner:MATERIAL BIDDING BRANCH OF HUBEI JIJI ELECTRIC POWER GROUP CO LTD

QKD remote key distribution method, system and device based on PQC channel and medium

The invention belongs to the technical field of quantum communication, and particularly relates to a QKD remote key distribution method, system and device based on a PQC channel and a medium. In order to overcome the defect that performance overhead and risk exposure cannot be coordinated in the prior art, the technical scheme adopted by the invention is as follows: the QKD remote key distribution method based on the PQC channel comprises the following steps: completing storage of a mother key in a server in a hardware security module in advance; a temporary PQC authentication key exchange channel with forward confidentiality and quantum attack resistance is established between a client side and a server side, the server side adopts a standard PQC digital signature to perform identity authentication, and the client side indirectly realizes identity authentication on the server side through a key packaging mechanism; the remotely distributed key is a one-time service key; and carrying out encrypted communication between the clients by using the service key. The method has the beneficial effects that the contradiction between the performance overhead and the risk exposure is solved through an asymmetric authentication protocol and a strict risk isolation architecture.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

An OpenVPN security customization method, system and medium

The application belongs to the technical field of network data security transmission, and discloses an OpenVPN security customization method and system and a medium. Through ECC asymmetric encryption, PSK double-factor authentication, AES-256-GCM encryption, sequence number replay defense, forward secrecy and DoS defense strategies, active defense against man-in-the-middle attacks, replay attacks, data tampering, key leakage and denial-of-service attacks is realized. Compared with the original OpenVPN, the method of the application simplifies the protocol stack, improves transmission efficiency while ensuring security, and is suitable for high-performance scenarios such as enterprise branch interconnection and remote office.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Multi-factor group authentication and key agreement protocol method based on certificateless aggregation signature

The invention discloses a multi-factor group authentication and key agreement protocol method based on certificateless aggregation signature. A trusted authentication mechanism generates system parameters and distributes a key to initialize a system; the user and the intelligent equipment node register to the gateway node through a public channel, so that extra overhead caused by establishment of a secure channel is avoided; in an authentication and key negotiation stage, a user only needs to send an authentication request to a gateway node to realize bidirectional authentication and session key negotiation with a group of intelligent device nodes; the protocol adopts an aggregation signature mechanism, so that a user can verify the authenticity and integrity of keys returned by all devices at one time, a negotiated session key has uniqueness, and even if a gateway node key is broken, the key security can still be ensured, and perfect forward secrecy is supported; meanwhile, the protocol dynamically updates the key in the group through the Chinese remainder theorem to realize forward security and backward security; the method has higher safety and efficiency in an industrial internet scene, and is particularly suitable for a multi-device environment.
Owner:XIDIAN UNIV

Qkd remote key distribution method, system, device and medium based on pqc channel

ActiveCN121923817BImplement identity authenticationlower the thresholdRisk exposureHardware security module
The present application belongs to the technical field of quantum communication, and particularly relates to a QKD remote key distribution method, system, device and medium based on a PQC channel. In view of the fact that the prior art fails to coordinate performance overhead and risk exposure, the present application adopts the following technical solution: a QKD remote key distribution method based on a PQC channel, comprising: pre-storing a parent key in a service end in a hardware security module; establishing a temporary, forward-secure, anti-quantum-attack PQC authentication key exchange channel between a client and the service end, the service end performing identity authentication by using a standard PQC digital signature, and the client indirectly implementing identity authentication of the service end through a key encapsulation mechanism; the remotely distributed key is a one-time business key; and the business keys are used for encrypted communication between clients. The present application has the beneficial effect of resolving the contradiction between performance overhead and risk exposure through an asymmetric authentication protocol and a strict risk isolation architecture.
Owner:ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY

Method and system for private decentralized forward-secure confidential transactions

A method for facilitating payments that are executable on a decentralized network platform, such as a blockchain network platform, while providing receiver anonymity and confidentiality of transaction messages is provided. The method includes: receiving, from a payor, first information that relates to an amount of a payment being made to a recipient; receiving, from the payor, second information that relates to a secret key that corresponds to a public key associated with the payor; receiving, from the payor, third information that indicates that the sender has generated a ciphertext message that relates to the payment; and receiving, from the payor, fourth information that proves that the amount of the payment does not exceed an account balance of an account from which the payment is withdrawn. The method further includes a forward secrecy mechanism for updating the key pair of the receiver when the secret key is compromised.
Owner:JPMORGAN CHASE BANK NA

Conditional agent re-encryption method and system with forward confidentiality and collusion resistance

The invention discloses a conditional agent re-encryption method and system with forward confidentiality and collusion resistance, and the method specifically comprises the following steps: S1, system initialization, S2, user key generation, S3, temporary key generation and updating, S4, threshold re-encryption key generation, S5, encryption, S6, re-encryption, and S7, decryption, and relates to the technical field of information security. According to the conditional agent re-encryption method and system with forward confidentiality and collusion resistance, through a key evolution mechanism, even if an attacker obtains a temporary private key of a current period, ciphertext of a past period cannot be decrypted, historical communication data are effectively protected, and through the adoption of a (t, n)-threshold value distributed authority design, the security of the attacker is improved. Unless the attacker simultaneously breaks through at least t authoritative nodes, the effective re-encryption key cannot be forged, and the agency and user collusion or multi-authoritative node collusion attack is resisted.
Owner:ENG UNIV OF THE CHINESE PEOPLES ARMED POLICE FORCE

OpenVPN security customization method and system, and medium

The invention belongs to the technical field of network data security transmission, discloses an OpenVPN security customization method and system and a medium, and realizes active defense of man-in-the-middle attack, replay attack, data tampering, key leakage and denial of service attack through strategies of ECC asymmetric encryption, PSK two-factor authentication, AES-256-GCM encryption, serial number replay defense, forward secrecy, DoS defense and the like. Compared with a native OpenVPN, the method provided by the invention simplifies the protocol stack and improves the transmission efficiency while ensuring the security, and is suitable for high-performance scenes such as enterprise branch interconnection and remote office.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

A High-Security Instant Messaging Method and System

This invention discloses a highly secure instant messaging method and system, relating to the field of instant messaging technology. It establishes a defense-in-depth system through four collaborative steps: Step 1 lays a decentralized foundation to resist topology analysis; Step 2 ensures session confidentiality, achieving forward secrecy; Step 3 destroys metadata value to defend against correlation attacks; and Step 4 disrupts traffic characteristics to completely hide communication patterns. The overall solution of this invention achieves reliable standards in terms of efficiency, security, and robustness. It not only ensures high availability and censorship resistance in a decentralized network environment but also provides end-to-end privacy and security protection across multiple dimensions, including the application layer, key layer, metadata layer, and traffic layer, accurately corresponding to and implementing a highly secure instant messaging method.
Owner:BEIJING YOUREN TECH CO LTD

Intercom quantum encryption session key generation method and system based on NFC "touch-to-touch" trigger

This invention discloses a method and system for generating quantum-encrypted session keys for walkie-talkies based on NFC "tap-to-tap" triggering, belonging to the field of wireless communication security technology. The two walkie-talkies exchange device identifiers and long-term public keys via NFC physical contact; a temporary public key with a digital signature is generated and exchanged within a secure chip based on local quantum true random entropy; a shared secret is calculated through elliptic curve key negotiation, and a session key is derived by combining the identifiers of both parties and timestamps; BLE RSSI ranging is used synchronously to defend against relay attacks; and the key is automatically destroyed after the PTT call ends or the specified time expires. This invention achieves highly secure, forward-confidential end-to-end voice encryption in scenarios such as walkie-talkies without network coverage, effectively solving the problems of easy leakage of fixed keys, susceptibility to man-in-the-middle attacks in wireless pairing, and lack of physical proximity verification in traditional walkie-talkies.
Owner:ZHONGKE WENTIAN QUANTUM TECHNOLOGY (WUHAN) CO LTD

Method and apparatus for dynamic data encryption in a communication system with forward secrecy

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method performed by a terminal for dynamic data encryption in a communication system is provided. The method includes receiving, from a network entity, a list of network public keys including a plurality of network public keys and corresponding key indexes, generating a pair of keys including a user equipment (UE) public key and a UE private key in response to receiving the list of network public keys, randomly selecting a network public key from the list of network public keys received from the network entity, generating a shared secret key corresponding to the UE by using the randomly selected network public key and the UE private key, and encrypting data to be transferred between the UE and the network entity by using the generated shared secret key corresponding to the UE.
Owner:SAMSUNG ELECTRONICS CO LTD

Method and apparatus for dynamic data encryption in a communication system with forward secrecy

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method performed by a terminal for dynamic data encryption in a communication system is provided. The method includes receiving, from a network entity, a list of network public keys including a plurality of network public keys and corresponding key indexes, generating a pair of keys including a user equipment (UE) public key and a UE private key in response to receiving the list of network public keys, randomly selecting a network public key from the list of network public keys received from the network entity, generating a shared secret key corresponding to the UE by using the randomly selected network public key and the UE private key, and encrypting data to be transferred between the UE and the network entity by using the generated shared secret key corresponding to the UE.
Owner:SAMSUNG ELECTRONICS CO LTD

Infrastructure-free security communication method and system based on temporary identity

The invention discloses a temporary identity-based non-infrastructure secure communication method and system, and the method comprises the steps: enabling a device to locally and periodically generate a temporary elliptic curve cryptographic key pair, deriving a temporary identifier which does not contain any persistent identity information, guaranteeing the communication anonymity from the source, and effectively overcoming the limitation of dependence on a preset social chain; the core security mechanism lies in the temporary and short life cycle of session keys: all keys are only stored in an equipment memory and are automatically destroyed after communication is finished or overtime, and perfect forward secrecy is realized in combination with periodic updating of temporary key pairs, so that decryption cannot be performed even if the keys are leaked in the future for a long time and historical sessions cannot be performed; a one-time random number verification mechanism is introduced in the key negotiation stage, and replay attacks are effectively resisted; the method does not depend on fixed infrastructures such as a base station and the Internet, a point-to-point or mesh network is constructed through a wireless module of equipment, and a communication link can still be kept available in an extreme environment that the infrastructures are paralyzed.
Owner:王义珂